All techniques
EX-0008.01
ST0004Execution
sub-technique

Absolute Time Sequences

Parent: EX-0008

Description

Execution is keyed to a fixed wall-clock timestamp or epoch, independent of current vehicle state. The implant watches a trusted time source, GNSS-derived time, crosslink-distributed network time, oscillator-disciplined UTC/TAI, or mission elapsed time anchored at activation, and triggers exactly at a programmed date/time. Absolute triggering supports coordinated multi-asset actions and allows long dormancy with a precise activation moment. Variants incorporate calendar logic (e.g., “first visible pass after YYYY-MM-DD hh:mm:ss”) or guard bands to fire only if the clock is within certain tolerances, ensuring the event occurs even with minor drift yet remains rare enough to blend with scheduled operations.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(l)
    addresses
    moderate
    derived

    Logging/monitoring obligation captures absolute-timestamp activations that are observable signatures of wall-clock-keyed triggers.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    derived

    Regular security testing is the manufacturer-side discipline that uncovers absolute-time dormant-trigger code in the product before release.

  • nis2-implAnnex 3.2.1
    addresses
    moderate
    derived

    Monitoring procedures should surface anomalous activations correlated with absolute timestamps and shared time-source events.

  • nis2-implAnnex 6.9.1
    addresses
    moderate
    derived

    Code that watches a wall-clock time source for activation is unauthorized software; the malware-protection obligations cover detection-or-prevention measures appropriate to the asset.

ENISA controls

  • A documented secure development lifecycle is relevant to reviewing code paths that consume trusted time, but the generic secure-engineering-principles excerpt does not actively prevent the deliberately inserted absolute-time trigger EX-0008.01 uses.

  • Long-duration testing — explicit on time-based attacks — is the named control against absolute-time-keyed implants that lie dormant for long periods.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0008.01 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.