All techniques
EX-0002
ST0004Execution

Position, Navigation, and Timing (PNT) Geofencing

Description

Malware or implanted procedures execute only when the spacecraft’s state meets geometric and temporal criteria. Triggers can be defined in orbital elements, inertial or Earth-fixed coordinates, relative geometry, lighting conditions, or time references. The code monitors on-board navigation solutions, ephemerides, or propagated TLEs and arms itself when thresholds are met (e.g., “only fire over region X,” “only activate during LEOP,” or “only run within N seconds of a scheduled downlink.”) Geofencing reduces exposure and aids deniability: triggers are rare, aligned with mission cadence, and hard to reproduce on the ground. More elaborate variants require conjunctions of conditions (position + attitude + clock epoch) or incorporate drift so the trigger slowly evolves with the orbit. The result is effect-on-demand: execution occurs precisely where and when the actor intends, while remaining dormant elsewhere.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    derived

    Manufacturer logging/monitoring obligation surfaces anomalous activations correlated with orbital state transitions, the observable signature of geofenced trigger logic.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    derived

    Effective and regular tests and reviews of product security surface dormant geofenced trigger logic before release; static analysis, taint analysis and behavior-state testing are within the scope of (3).

  • eu-space-actArt. 78(1)
    addresses
    moderate
    direct

    PNT-geofenced payloads embed conditional triggers in flight code — 78(1)(c)'s identify-cybersecurity-vulnerabilities obligation covers detection of conditional malicious behavior during code review and runtime analysis.

  • eu-space-actArt. 88(1)
    addresses
    moderate
    direct

    88(1)'s testing programme and 88(3)'s Threat Led Penetration Testing can include behavioral testing across the orbital trajectory — surfacing geofenced triggers that fire only at specific positions or times.

  • eu-space-actArt. 88(3)
    addresses
    moderate
    direct

    PNT-geofenced malware detection (primary: Art. 88(1)) cascades to 88(3) — TLPT can include orbital-trajectory behavioral testing across the 3-year cadence.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring procedures must surface anomalous activation events keyed to orbital state; correlation between attitude/ephemeris transitions and unexpected behaviour is the observable signature of geofenced triggers.

  • nis2-implAnnex 6.9.1
    addresses
    moderate
    derived

    Geofenced trigger logic embedded in flight code is malicious and unauthorized software; protection-against-malicious-and-unauthorized-software obligations require detection and prevention measures appropriate to the asset.

ENISA controls

  • A documented secure development lifecycle governs engineering practice and is relevant to code integrity, but the generic secure-engineering-principles excerpt does not actively prevent a deliberately inserted geofence-conditional implant, which is not a defect class secure coding removes.

  • Resilient PNT including GNSS authentication mechanisms and fault-tolerant time sourcing is the named defense against geofence-conditional malware that triggers on PNT inputs.

  • End-to-end testing including negative/abuse cases surfaces conditional behavior tied to navigation/time inputs that defines PNT geofencing.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.