All techniques
EXF-0002.02
ST0008Exfiltration
sub-technique

Electromagnetic Leakage Attacks

Parent: EXF-0002

Description

Switching activity in chips, buses, and clocks radiates EM energy that can be captured and analyzed to reveal internal computation. Near-field probes (in test) or proximity receivers (on-orbit assets) can observe harmonics and modulation tied to cipher rounds, key schedules, or protocol framing, sometimes with finer granularity than power analysis. Coupling paths include packages, harnesses, SDR front ends, and poorly shielded enclosures. By training on known operations and comparing spectra or time-domain signatures, an adversary can recover keys or reconstruct processed data without touching logical interfaces.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    direct

    EM emanations leaking key schedules and protocol framing defeat (2)(e)'s confidentiality property; state-of-the-art mechanisms include shielding, decorrelation, and constant-power design.

  • craAnnex I, Part I, (2)(k)
    addresses
    high
    direct

    EM-leakage countermeasures (TEMPEST-grade shielding, harness routing, package selection) are the manufacturer-side exploitation-mitigation mechanisms (2)(k) requires.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Electromagnetic-leakage attacks (primary mapping: Annex I, Part I, (2)(k)) cascade to (3) — TEMPEST shielding requires regular validation by near-field probe testing in the security review.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    direct

    EM-leakage countermeasures (TEMPEST shielding, harness routing, decorrelation) are part of the cryptographic concept 85(1) places on the operator.

  • eu-space-actArt. 85(2)
    addresses
    moderate
    direct

    EM-leakage attacks (primary: Art. 85(1)) cascade to 85(2) — key rotation limits exposure window.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) crypto policy does not interdict EM-emanation key recovery; the operative mitigation is TEMPEST shielding and emission control, not use-of-cryptography policy. Addresses (domain relevance).

  • nis2-implAnnex 13.2.1
    addresses
    high
    derived

    Electromagnetic leakage is exactly the unintentional emission class the protection-against-physical-and-environmental-threats obligation is established to govern; chassis shielding, harness routing and TEMPEST-style controls reduce EM-channel leakage.

ENISA controls

  • Hardware power-system design with switching-noise obfuscation reduces EM emissions correlated with cipher-round activity.

  • Tamper protection is a physical-hardware-protection control relevant to the hardware EXF-0002.02 targets, but the shipping and receiving tamper-proofing and inspection excerpt does not actively counter operational electromagnetic-leakage observation, which needs shielding or masking.

  • Power masking is the named control against EM-leakage-based partial-key recovery — the EXF-0002.02 vector.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0002.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.