Annex 11.6.1
Mapped SPARTA techniques (21)
Techniques referencing this article
Secure-authentication procedures bind activity to verifiable identities; properly implemented authentication denies an adversary the ability to credibly present as an authorized origin without valid keys or factors.
Authentication based on access control is domain relevant but does not interdict replay; anti-replay freshness (counters, timestamps, nonces) is the control that converts a captured-and-replayed message into a rejected one.
Authentication based on access control is domain relevant but does not interdict whole-PDU replay; anti-replay freshness (monotonic counters and timestamp windows enforced at acceptance) is the control that defeats re-sent stale telecommands.
Authentication procedures with rate-limiting and per-counter validation reduce the resource cost of valid-command flooding because each replay or duplicate command is rejected at minimal expense.
Secure-authentication procedures bind inputs to verifiable identities; spoofed inputs that lack the required authentication tags or counters are rejected by subsystems applying these procedures.
Authentication on time-distribution paths (signed PTP/NTP, authenticated cross-link time tags) reduces the success of forged time inputs to onboard consumers.
Authentication based on access control is domain relevant but does not interdict replay; anti-replay freshness (monotonic counters, nonces, timestamp validation) is the control that rejects re-sent valid commands.
Secure authentication on backup paths must match the primary; the implementing regulation requires authentication strength appropriate to the asset, with no carve-out for contingency channels.
Secondary on-board receivers must enforce the same secure-authentication procedures (TC frame MAC, counters) as the primary path; the implementing regulation calibrates authentication strength to asset classification, not to channel role.
Authentication procedures across OSAM/docking interfaces (rendezvous tokens, capture-permission exchanges, post-dock command channel handshakes) must satisfy the implementing regulation's secure-authentication requirements.
Secure-authentication procedures on the uplink (cryptographic command authentication, counters, replay protection) reduce a rogue external transmitter to noise — without valid authentication tags the spacecraft does not accept commands.
A rogue ground station with steerable apertures and accurate timing is defeated by uplink command authentication binding commands to per-counter MACs the rogue cannot forge without valid keys.
Authentication on crosslink and proximity-domain interfaces converts a rogue spacecraft into an unauthenticated peer; without valid keys it cannot establish a privileged conversation with the target vehicle.
Telemetry-deception relies on falsifying inputs that subsystems treat as authoritative; secure-authentication procedures bind data to verifiable identities and resist forged or modified telemetry being accepted as true.
Authentication on crosslink peer exchanges (routing, time, ephemeris distribution) reduces the value of forged inter-satellite traffic to subscribers applying the secure-authentication obligations.
Authentication on rendezvous, capture-permission and post-dock command channels is the secure-authentication obligation that resists forged interface signaling during attach events.
Secure-authentication procedures (key binding, counters, certificate validation) reduce the trust placed on credentials alone — the assumption credentialed traversal exploits.
Secure-authentication procedures bind cryptographic material to its intended use; strong procedures keep adversary-acquired keys from becoming functional in the entity's command path.
Telecommand authentication procedures (MAC keys, authentication tags, command counters) are the secure-authentication mechanisms the implementing regulation requires the entity to implement; their design quality is what determines whether commanding-detail reconnaissance can be turned into command injection.
Secure authentication procedures determine the value of any harvested credentials; if the entity authenticates with state-of-the-art methods bound to device or context, intercepted secrets are not directly usable.
Authentication based on access control is domain relevant but does not interdict passive interception or traffic analysis; encryption and COMSEC with traffic-flow security are the controls that deny the captured uplink its intelligence value.