All techniques
RD-0003.02
ST0002Resource Development
sub-technique

Cryptographic Keys

Parent: RD-0003

Description

Adversaries seek any cryptographic material that confers command or decryption authority: uplink authentication/MAC keys and counters, link-encryption/session keys and KEKs, loading/transfer keys for HSMs, PN/spreading codes, modem credentials, and station or crosslink keys. Acquisition routes include compromised ground systems and laptops, misconfigured repositories and ticket systems, memory/core dumps, training datasets and screenshots, contractor support channels, and poorly controlled key-loading or recovery procedures. Because some missions authenticate uplink without encrypting it, possession of the right keys/counters may be sufficient to inject accepted commands outside official channels or to desynchronize anti-replay.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(d)
    addresses
    high
    derived

    Manufacturer obligation to provide authentication and access-management mechanisms determines the value of obtained cryptographic keys: well-designed products bind keys to product-side verification (counters, factor binding, hardware-backed identity) so adversary-acquired keys do not directly yield operational access.

  • craAnnex I, Part I, (2)(e)
    addresses
    high
    derived

    Manufacturer obligation to protect confidentiality of stored data covers cryptographic key material as the highest-classification data class; encrypted, hardware-bound key storage on the product is the procedural defense that resists key acquisition.

  • eu-space-actArt. 81(1)
    addresses
    moderate
    direct

    Operator IAM protocols under 81(1) restrict access to HSMs, key-loading tools, and key-recovery procedures — limiting the population that can abscond with cryptographic material.

  • eu-space-actArt. 81(4)
    addresses
    moderate
    direct

    Cryptographic-key acquisition by adversaries (primary: Art. 81(1) on key-loading IAM) cascades to 81(4) — credential audit on HSM and key-management identities limits exposure window.

  • eu-space-actArt. 85(2)
    addresses
    high
    direct

    Cryptographic-key acquisition from operator-controlled sources (compromised ground systems, repositories, contractor channels) directly attacks the lifecycle 85(2) places on the operator — generation, use, storage, distribution, and disposal disciplines limit key exposure.

  • nis2Art. 21(2)(d)
    addresses
    moderate
    direct

    Keys flow through contractor support channels, training datasets, and key-loading procedures involving suppliers; supplier-relationship security under Art. 21(2)(d) bounds where they may be exposed.

  • nis2Art. 21(2)(h)
    addresses
    high
    direct

    Cryptography policy under Art. 21(2)(h) is the precise obligation that defines key generation, storage, transport, loading, KEK hierarchy, and rotation — depriving an adversary of stable key material to acquire.

  • nis2Art. 21(2)(i)
    addresses
    high
    direct

    Keys, KEKs, key-loading tools, HSMs, and recovery procedures are first-class access-controlled assets; Art. 21(2)(i) is the obligation that constrains who can read, transport, or operate them.

  • nis2Art. 21(3)
    addresses
    moderate
    derived

    Primary mapping to Art. 21(2)(d) covers the supplier relationship that exposed the cryptographic-key material (key-management vendor, COMSEC custodian, HSM/CA provider). Art. 21(3) procedurally extends to assessment of that supplier's secure-development and key-handling quality, the procedural instrument addressing supplier-side key compromise.

  • nis2-implAnnex 11.3.1
    addresses
    moderate
    derived

    COMSEC custodians and key-management operators are privileged accounts under Annex 11.3; the privileged-account policy bounds the population that can ever extract live key material.

  • nis2-implAnnex 11.5.1
    addresses
    moderate
    derived

    Identity life-cycle management governs how cryptographic identities (uplink-MAC keys, link-encryption keys, certificate-bound operator identities) are issued, rotated and revoked; weak life-cycle is the precondition for adversary key acquisition.

  • nis2-implAnnex 11.6.1
    addresses
    high
    derived

    Secure-authentication procedures bind cryptographic material to its intended use; strong procedures keep adversary-acquired keys from becoming functional in the entity's command path.

  • nis2-implAnnex 12.1.1
    addresses
    moderate
    derived

    Cryptographic key material is the highest-classification asset the entity holds; its classification and the controls that flow from it determine whether key acquisition is possible at all.

ENISA controls

  • Forbidding embedded static authenticators in scripts and configuration files limits one of the principal acquisition paths for cryptographic keys.

  • Cryptography and key management interdicts a partial set of RD-0003.02's key-acquisition routes (onboard key handling and the telecommand-read restriction) and limits the lifetime of obtained keys through rotation, but the dominant acquisition routes are ground-side and non-crypto: compromised ground systems and laptops, misconfigured repositories, memory and core dumps, and contractor or human channels. Crypto covers the minority of routes, so the relationship is addresses.

  • Authentication-information management governs the allocation, handling, and revocation of credential material, relevant to the cryptographic keys and counters RD-0003.02 seeks to acquire.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, RD-0003.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.