All techniques
EXF-0002
ST0008Exfiltration

Side-Channel Exfiltration

Description

Information is extracted not by reading files or decrypting frames but by observing physical or protocol byproducts of computation, power draw, electromagnetic emissions, timing, thermal signatures, or traffic patterns. Repeated measurements create distinctive fingerprints correlated with internal states (key use, table loads, parser branches, buffer occupancy). Matching those fingerprints to models or templates yields sensitive facts without direct access to the protected data. In space systems, vantage points span proximity assets (for EM/thermal), ground testing and ATLO (for direct probing), compromised on-board modules that can sample rails or sensors, and remote observation of link-layer timing behaviors.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    Side-channel exfiltration attacks the confidentiality property (2)(e) covers; state-of-the-art mechanisms include not just encryption but constant-time crypto, masked implementations, and shielding — the side-channel-resistance disciplines.

  • craAnnex I, Part I, (2)(k)
    addresses
    high
    direct

    Side-channel countermeasures (masking, hiding, dual-rail logic, EM shielding, blinded crypto) are exploitation-mitigation mechanisms (2)(k) requires manufacturers to apply at design and production time.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Side-channel exfiltration parent (primary mapping: Annex I, Part I, (2)(k)) cascades to (3) — side-channel countermeasures (masking, blinded crypto, EM shielding) require regular validation through dedicated side-channel testing.

  • eu-space-actArt. 76(6)
    addresses
    moderate
    direct

    Side-channel testing efficacy (primary: Art. 88(1)) requires effectiveness assessment per 76(6) — periodic verification that operator measurement equipment matches adversary capabilities.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    direct

    Side-channel exfiltration is defeated by the cryptographic concept 85(1) requires — including constant-time, masked, and emanation-resistant implementations.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    Side-channel exfiltration parent (primary: Art. 85(1)) cascades to 85(2) — key rotation discipline limits the value of side-channel-recovered keys.

  • eu-space-actArt. 88(1)
    addresses
    moderate
    direct

    88(1)'s testing programme can include side-channel and fault-injection testing — surfacing leakage and glitch susceptibility in operator products.

  • eu-space-actArt. 88(3)
    addresses
    moderate
    direct

    Side-channel exfiltration testing (primary: Art. 88(1)) cascades to 88(3) — TLPT 3-yearly cadence covers side-channel and emanation testing as part of broader penetration testing.

  • nis2Art. 21(2)(e)
    addresses
    moderate
    direct

    Hardening of crypto modules, SDR/FPGA pipelines, bus controllers, and bootloaders against side-channel leakage and fault injection is part of secure development and maintenance under Art. 21(2)(e), including disclosed-weakness handling on the side-channel surface.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h)'s policy on the use of cryptography is domain-relevant, but a crypto-use policy does not interdict physical-byproduct (power, EM, timing) extraction of secrets; the actual mitigation is implementation and physical side-channel resistance such as masking and shielding.

  • nis2-implAnnex 13.2.1
    addresses
    high
    derived

    Side-channel exfiltration observes physical byproducts of computation; protection-against-physical-and-environmental-threats obligations cover the design measures (shielding, balanced power, emission management) that reduce side-channel leakage.

  • nis2-implAnnex 6.2.1
    addresses
    moderate
    derived

    Secure-development discipline includes constant-time, branch-balanced cryptographic implementations and side-channel-resistant coding patterns that reduce timing- and power-channel leakage at source.

ENISA controls

  • Hardware-level power-system noise injection masks power-consumption variation, raising the cost/difficulty of side-channel exfiltration.

  • Tamper protection is a physical-hardware-protection control loosely relevant to the hardware EXF-0002 targets, but the shipping and receiving tamper-proofing and inspection excerpt does not actively counter operational side-channel emission observation, which needs shielding or masking.

  • Power masking is the canonical control against partial-key inference from electromagnetic leakage that defines passive side-channel exfiltration.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0002 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.