All techniques
EX-0015
ST0004Execution

Side-Channel Attack

Description

Adversaries extract secrets or steer execution by observing or perturbing physical byproducts of computation rather than the intended interfaces. Passive channels include timing, power draw, electromagnetic emissions, acoustic/optical leakage, and thermal patterns correlated with operations such as key use, counter updates, or parser activity. Active channels deliberately induce faults during runtime, e.g., voltage or clock glitches, electromagnetic/laser injection, or targeted radiation, to flip bits, skip checks, or bias intermediate values. On spacecraft, prime targets include crypto modules, SDR/FPGA pipelines, bootloaders, and bus controllers whose switching behavior or error handling reveals protocol state or key material. With sufficient samples, or with repeated fault attempts, statistical features emerge that reduce entropy of the sensitive variable under study; in effect, a successful fault campaign turns into information leakage comparable to a passive side channel. Collection vantage points range from on-orbit proximity (for EM/optical), to ATLO and ground test (for direct probing), to instrumented compromised hardware already in the signal path.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    derived

    Confidentiality obligation covers data leaked through physical byproducts of computation (timing, power, EM); manufacturer-side TEMPEST hardening, balanced power and constant-time crypto are how (2)(e) is operationalized against side-channel attacks.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    derived

    Effective and regular tests and reviews include side-channel-resistance testing (DPA/SPA, EM probing, timing analysis) as part of the manufacturer's security-testing program.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    Side-channel attacks recover secrets via physical byproducts; 85(1)'s cryptographic concept must include constant-time, masked, and emanation-resistant implementations to defeat passive and active side channels.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Side-channel attack (primary: Art. 85(1)) cascades to 85(2) — key rotation limits the value of keys recovered through side channels.

  • eu-space-actArt. 88(1)
    addresses
    moderate
    direct

    88(1)'s testing programme can include side-channel and fault-injection testing during integration — surfacing leakage and glitch susceptibility.

  • eu-space-actArt. 88(3)
    addresses
    moderate
    direct

    Side-channel testing (primary: Art. 88(1)) cascades to 88(3) — periodic side-channel and fault-injection testing falls within the TLPT 3-yearly framework.

  • nis2Art. 21(2)(e)
    addresses
    moderate
    direct

    Hardening of SDR/FPGA pipelines, bootloaders, and bus controllers against fault injection is part of secure development and maintenance under Art. 21(2)(e), including disclosed-vulnerability handling on the side-channel/fault surface.

  • nis2Art. 21(2)(h)
    addresses
    low
    inferred

    NIS2 Art. 21(2)(h) cryptography policy is relevant to the crypto material targeted, but does not interdict physical side-channel or fault-injection extraction; the operative mitigation is physical hardening, shielding and masking. Mapped as addresses (domain relevance).

  • nis2-implAnnex 13.2.1
    addresses
    high
    derived

    Side-channel attacks observe physical byproducts (power, EM, timing); the protection-against-physical-and-environmental-threats obligation covers the design measures (shielding, balanced power, emission-control) that reduce side-channel leakage.

  • nis2-implAnnex 6.2.1
    addresses
    moderate
    derived

    Constant-time, branch-balanced cryptographic implementations are part of secure-development discipline; these implementation choices reduce timing-channel leakage at the source.

ENISA controls

  • Hardware-level power-system noise injection masks power-consumption variation, raising the cost/difficulty of power-analysis side-channel attacks.

  • Power masking is the canonical control against partial-key inference from electromagnetic leakage that defines passive side-channel attacks.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0015 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.