eu-space-act

Art. 85(3)

Full text: this article's wording is third-party regulatory text. See the official source for the authoritative provision.

Mapped SPARTA techniques (18)

Techniques referencing this article

  • DE-0003.07Cryptographic ModesST0006
    addresses
    high
    direct

    Crypto-mode flipping that requests clear telemetry or selects unmonitored profiles attacks 85(3)(a)/(b)'s end-to-end authentication and telecommand encryption obligations.

  • DE-0004MasqueradingST0006
    addresses
    high
    direct

    85(3)(a)'s end-to-end authentication between satellite control centres and space segment is the cryptographic discipline that prevents masqueraded telecommands from being accepted regardless of RF correctness.

  • EX-0001ReplayST0004
    addresses
    high
    direct

    85(3)(b)'s telecommand-encryption obligation, paired with anti-replay counters that 85(3) presumes, is the cryptographic discipline that defeats RF and crosslink replay.

  • EX-0001.01Command PacketsST0004
    addresses
    high
    direct

    Replay of authenticated telecommands is defeated by 85(3)(a)'s end-to-end authentication and 85(3)(b)'s telecommand-encryption with anti-replay counters.

  • EX-0003Modify Authentication ProcessST0004
    addresses
    high
    direct

    85(3)(a)'s end-to-end authentication and 85(3)(b)'s telecommand encryption are the cryptographic disciplines this technique attacks; tamper-resistance of the verifier is part of the broader cryptographic concept under 85(1).

  • EX-0006Disable/Bypass EncryptionST0004
    addresses
    high
    direct

    85(3)(b)'s ensure-encryption-of-telecommands obligation is the binary requirement EX-0006 attacks — the operator must prevent operational modes that downgrade or skip TC encryption.

  • EX-0014SpoofingST0004
    addresses
    high
    direct

    85(3)(a)'s end-to-end authentication between satellite control centres and space segment is the cryptographic posture that defeats RF-layer spoofing.

  • EXF-0001ReplayST0008
    addresses
    high
    direct

    85(3)(a)/(b)'s end-to-end authentication and telecommand encryption — paired with anti-replay counters that 85(3) presumes — are the cryptographic discipline that defeats replay.

  • EXF-0003Signal InterceptionST0008
    addresses
    moderate
    direct

    85(3)(b)'s telecommand encryption obligation reduces the value of intercepted command traffic; 85(3)(a)'s end-to-end authentication limits replay/clone scenarios that capture enables.

  • EXF-0003.01Uplink ExfiltrationST0008
    addresses
    high
    direct

    85(3)(b)'s ensure-encryption-of-telecommands obligation is the precise countermeasure against uplink interception — encrypted command traffic limits what intercepted material reveals.

  • IA-0003Crosslink via Compromised NeighborST0003
    addresses
    moderate
    direct

    85(3)(a)'s end-to-end-authentication-between-satellite-control-centres-and-space-segment obligation extends to crosslink mediated control where applicable.

  • IA-0004.02ReceiverST0003
    addresses
    moderate
    direct

    85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment obligation must extend to backup receive paths to prevent adversary injection on alternate hardware/waveforms.

  • IA-0008Rogue External EntityST0003
    addresses
    high
    direct

    85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment is the cryptographic discipline that defeats traffic from any node not holding valid mission credentials.

  • IA-0008.01Rogue Ground StationST0003
    addresses
    high
    direct

    End-to-end authentication under 85(3)(a) between satellite control centres and space segment is the cryptographic posture that defeats rogue-station injection regardless of RF correctness.

  • LM-0003Constellation Hopping via CrosslinkST0007
    addresses
    moderate
    direct

    85(3)(a)'s end-to-end-authentication-between-SCC-and-space-segment obligation extends to crosslink-mediated control paths.

  • PER-0004Replace Cryptographic KeysST0005
    addresses
    moderate
    direct

    85(3)(c)'s availability-of-cryptographic-keys-and-parameters clause (with redundant cryptographic equipment) is the operator-side counterpart that prevents adversary key-replacement from leaving the legitimate operator stranded.

  • REC-0005EavesdroppingST0001
    addresses
    high
    direct

    85(3)(a) requires end-to-end authentication of links between satellite control centres and the space segment; 85(3)(b) requires telecommand encryption based on risk assessment — both directly counter eavesdropping.

  • Uplink interception captures telecommand traffic; 85(3)(a)/(b) require end-to-end authentication and encryption of telecommands — directly defeating uplink eavesdropping.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.