All techniques
REC-0001.03
ST0001Reconnaissance
sub-technique

Cryptographic Algorithms

Parent: REC-0001

Description

Adversaries look for the complete crypto picture: algorithms and modes, key types and lifecycles, authentication schemes, counter or time-tag handling, anti-replay windows, link-layer protections, and any differences between uplink and downlink policy. With algorithm and key details, a threat actor can craft valid telecommands, masquerade as a trusted endpoint, or degrade availability through replay and desynchronization. Sources include interface specifications, ground software logs, test vectors, configuration files, contractor laptops, and payload-specific ICDs that reuse bus-level credentials. Particular risk arises when command links rely on authentication without confidentiality; once an adversary acquires the necessary keys or counters, they can issue legitimate-looking commands outside official channels. Programs should assume that partial disclosures, MAC length, counter reset rules, or key rotation cadence, aid exploitation.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    derived

    Manufacturers must protect the confidentiality of stored, transmitted or processed data, including by encrypting cryptographic-state data such as keys and counter material; this constrains the leakage of crypto-algorithm and key-lifecycle details that algorithm-reconnaissance targets when it can probe a deployed product.

  • craAnnex I, Part I, (2)(f)
    addresses
    moderate
    derived

    Annex I, Part I, (2)(f) requires manufacturers to protect the integrity of stored, transmitted and processed data, commands, programs and configuration; reconnaissance of cryptographic algorithms and modes loses operational value when integrity protection is properly enforced.

  • eu-space-actArt. 80(3)
    addresses
    high
    direct

    Crypto algorithm/key documentation is high-confidentiality operator information that 80(3) requires to be categorized accordingly.

  • eu-space-actArt. 85(1)
    addresses
    high
    direct

    The cryptographic concept that 85(1) requires the operator to define is exactly the artifact (algorithms, modes, key types, anti-replay windows, link-layer protections) reconnaissance against cryptographic algorithms targets — its existence and protection are the cyber resilience measure.

  • eu-space-actArt. 85(2)
    addresses
    high
    direct

    85(2)'s cryptographic-key lifecycle policy governs the protection of key types and lifecycles that REC-0001.03 reconnaissance seeks to enumerate.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Here cryptography is the subject of reconnaissance (algorithms, key handling, parameters gathered from specifications, logs and hardware); Art. 21(2)(h) does not interdict the information gathering, which is countered by information protection and OPSEC. Addresses (domain relevance).

  • nis2Art. 21(2)(i)
    addresses
    moderate
    direct

    Keys, counters, and MAC parameters are first-class access-controlled assets; Art. 21(2)(i) constrains who can read, transport, or load them through the integration and operations chain.

  • nis2-implAnnex 11.3.1
    addresses
    moderate
    derived

    Custodians of cryptographic algorithm and key documentation are privileged-account holders by definition; the privileged-account policy bounds the population that can access COMSEC documentation.

  • nis2-implAnnex 12.1.1
    addresses
    high
    derived

    Cryptographic algorithm details, key types and key lifecycles are top-classification assets under any plausible asset-classification framework, which is the lever that drives strict need-to-know storage and handling.

  • nis2-implAnnex 6.2.1
    addresses
    moderate
    derived

    Crypto implementations live in the secure-development pipeline; the rules for source review, build provenance and artefact protection determine whether algorithm specifics leak through code-tree exposure.

ENISA controls

  • Cryptography and key management directly governs the algorithms, key types, lifecycles, counters, and anti-replay rules that REC-0001.03 attempts to enumerate.

  • Information classification and labelling governs the protection of cryptographic materials and ICDs REC-0001.03 targets, setting handling rules rather than actively defending against collection.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, REC-0001.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.