All techniques
DE-0003.07
ST0006Defense Evasion
sub-technique

Cryptographic Modes

Parent: DE-0003

Description

Many missions separate authentication from confidentiality and allow on-orbit selection of algorithms, keys, profiles, or “crypto off/clear” states. Adversaries manipulate these mode controls and selectors to desynchronize ground and space or to hide content: flipping to a profile that the ground is not using, requesting clear telemetry while maintaining authenticated uplink, or rotating key IDs so frames validate internally but appear undecodable to external tools. Mode indicators and status words can also be biased so ground displays show expected settings while the link actually operates under attacker-chosen parameters, masking command and data exchanges within normal-looking traffic.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    direct

    Crypto-mode manipulation including authentication-bypass selection (e.g., turning to a profile the ground does not validate against) is the precise attack (2)(d)'s authentication obligation requires the product to resist.

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Manipulating cryptographic mode controls — flipping profiles, requesting clear telemetry, rotating key IDs — directly attacks the confidentiality obligation under (2)(e), including its state-of-the-art encryption requirement.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Cryptographic-mode manipulation directly attacks the cryptographic concept 85(1) requires the operator to define — including which algorithms, modes, and key profiles are valid for the mission.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Cryptographic-mode manipulation (primary: Art. 85(1)/(3)) cascades to 85(2)'s key lifecycle — generation, use, and rotation discipline limits adversary ability to flip to attacker-favored profiles.

  • eu-space-actArt. 85(3)
    addresses
    high
    direct

    Crypto-mode flipping that requests clear telemetry or selects unmonitored profiles attacks 85(3)(a)/(b)'s end-to-end authentication and telecommand encryption obligations.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    direct

    Cryptographic mode controls, algorithm selectors, key IDs, and 'crypto off/clear' states are precisely the surface cryptography policy at Art. 21(2)(h) is meant to govern — including the ground/space synchronisation that the technique attacks.

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Crypto-mode selectors and algorithm-profile registers are access-controlled assets; Art. 21(2)(i)'s access-control + asset-management obligation governs which sessions and roles can alter them.

  • nis2-implAnnex 11.3.1
    addresses
    high
    derived

    Authority to switch crypto profiles, select keys or enter clear-mode is privileged-account authority; the privileged-account policy is the procedural lever that prevents single-actor downgrade-to-clear.

  • nis2-implAnnex 3.2.1
    addresses
    high
    derived

    Monitoring-and-logging procedures must surface crypto-state transitions (algorithm changes, key-set switches, encryption-off states) as high-severity logging events.

  • nis2-implAnnex 6.4.1
    addresses
    moderate
    derived

    Cryptographic mode changes are change-management events with significant security consequences; documented procedures with review and authorization govern such transitions.

ENISA controls

  • Configuration management of crypto-profile selectors and key-ID rotation surfaces unauthorised mode flips.

  • Communications security ensures secure protocols persist regardless of cryptographic-mode selectors, denying the desynchronisation attack.

  • Cryptography and key management mandates that the spacecraft cannot disable cryptography on TT&C — directly defeating crypto-mode obfuscation that selects 'crypto off' or null cipher profiles.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, DE-0003.07 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.