Art. 85(3)
Mapped SPARTA techniques (18)
Techniques referencing this article
Crypto-mode flipping that requests clear telemetry or selects unmonitored profiles attacks 85(3)(a)/(b)'s end-to-end authentication and telecommand encryption obligations.
85(3)(a)'s end-to-end authentication between satellite control centres and space segment is the cryptographic discipline that prevents masqueraded telecommands from being accepted regardless of RF correctness.
85(3)(b)'s telecommand-encryption obligation, paired with anti-replay counters that 85(3) presumes, is the cryptographic discipline that defeats RF and crosslink replay.
Replay of authenticated telecommands is defeated by 85(3)(a)'s end-to-end authentication and 85(3)(b)'s telecommand-encryption with anti-replay counters.
85(3)(a)'s end-to-end authentication and 85(3)(b)'s telecommand encryption are the cryptographic disciplines this technique attacks; tamper-resistance of the verifier is part of the broader cryptographic concept under 85(1).
85(3)(b)'s ensure-encryption-of-telecommands obligation is the binary requirement EX-0006 attacks — the operator must prevent operational modes that downgrade or skip TC encryption.
85(3)(a)'s end-to-end authentication between satellite control centres and space segment is the cryptographic posture that defeats RF-layer spoofing.
85(3)(a)/(b)'s end-to-end authentication and telecommand encryption — paired with anti-replay counters that 85(3) presumes — are the cryptographic discipline that defeats replay.
85(3)(b)'s telecommand encryption obligation reduces the value of intercepted command traffic; 85(3)(a)'s end-to-end authentication limits replay/clone scenarios that capture enables.
85(3)(b)'s ensure-encryption-of-telecommands obligation is the precise countermeasure against uplink interception — encrypted command traffic limits what intercepted material reveals.
85(3)(a)'s end-to-end-authentication-between-satellite-control-centres-and-space-segment obligation extends to crosslink mediated control where applicable.
85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment obligation must extend to backup receive paths to prevent adversary injection on alternate hardware/waveforms.
85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment is the cryptographic discipline that defeats traffic from any node not holding valid mission credentials.
End-to-end authentication under 85(3)(a) between satellite control centres and space segment is the cryptographic posture that defeats rogue-station injection regardless of RF correctness.
85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment obligation extends to crosslink-mediated control paths.
85(3)(c)'s availability-of-cryptographic-keys-and-parameters clause (with redundant cryptographic equipment) is the operator-side counterpart that prevents adversary key-replacement from leaving the legitimate operator stranded.
85(3)(a) requires end-to-end authentication of links between satellite control centres and the space segment; 85(3)(b) requires telecommand encryption based on risk assessment — both directly counter eavesdropping.
Uplink interception captures telecommand traffic; 85(3)(a)/(b) require end-to-end authentication and encryption of telecommands — directly defeating uplink eavesdropping.