Secure Command Mode(s)

Secure command modes provide additional layers of restriction on spacecraft command acceptance beyond standard authentication and encryption, constraining when, where, and under what operational conditions the spacecraft will process commands. These supplemental controls reduce the window of opportunity for unauthorized commanding by limiting command receptivity to defined parameters that an adversary would need to satisfy simultaneously with authentication requirements, substantially increasing the difficulty of a successful command injection attack. Specific implementations include geographic restriction, in which the spacecraft accepts commands only when in contact with designated ground station locations; operational mode restrictions, in which special flight software (FSW) modes must be active before certain command categories are accepted; and temporal controls, in which the spacecraft enforces time-bounded windows during which commands are valid. These mechanisms complement command authentication, integrity protection, anti-replay controls, and authorization and do not replace them. Encryption should also be applied where command confidentiality is required. Secure command modes may combine geographic, temporal, operational-state, source, or other mission-defined conditions according to the active command policy. Secure command modes helps create a multi-dimensional command acceptance policy that an adversary must defeat in its entirety to achieve unauthorized command execution.

ID: CM0055
Tier: II
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should address secure command modes as design options to be evaluated and selected based on the mission's threat environment, operational concept, and the commanding authority policy defined by the mission owner, with the selected modes documented in the system security requirements before flight software design begins. Requirements should specify that secure command restrictions be enforced by a trusted command-processing mechanism outside the control of ordinary command applications. Changes to, suspension of, or emergency override of the restriction policy must use a separately authorized, authenticated, integrity-protected, and audited management process. The process must prevent a command source from weakening the restrictions that govern its own authority without additional mission-approved authorization. Contract language should require that secure command mode configurations be documented as controlled baseline parameters subject to government review and approval, and that the FSW implementation of each mode be verified through testing that confirm that commands are rejected when applicable restrictions are not satisfied. Testing should include simulated or representative unauthorized ground-station identities, security associations, contact geometries, spacecraft position or ephemeris states, time conditions, and operational modes, together with attempts to manipulate the inputs used by the restriction logic. Evaluation criteria should assess offerors' proposed secure command mode architectures, their approach to ensuring that restriction enforcement cannot be bypassed, and their experience implementing command policy enforcement in spacecraft FSW. Verification should include scenario-based testing that exercises each restriction type under realistic conditions and confirms correct rejection of commands that do not satisfy the active restriction policy.

Pre-Operations Developer/Supplier

Secure command mode selection and design must be informed by the mission CONOPS, including nominal contacts, contingency commanding, ground-station diversity, autonomy, communication delays, maintenance, and emergency operations. The design must balance reduction of unauthorized command opportunity with continued commandability and provide controlled recovery procedures for erroneous or unavailable restriction inputs. Geographic command restrictions must use trusted inputs appropriate to the architecture. These may include authenticated ground-station or command-source identity, approved security associations, expected visibility or contact geometry, antenna or receiver context, spacecraft position and ephemeris, and mission schedule. Navigation or ephemeris information used in the decision must have sufficient integrity, validity, and uncertainty assessment, and no single spoofable input should be assumed to prove that a command originated from an authorized geographic location. Temporal restrictions must account for authoritative-time integrity, clock accuracy, drift, holdover uncertainty, communication delay, contact prediction error, and permitted correction behavior. The spacecraft must define how command acceptance operates when time is unavailable, inconsistent, or of uncertain integrity. Temporal windows must supplement, not replace, command anti-replay and freshness controls. FSW mode-based restrictions should be designed so that the transition into and out of special commanding modes is itself a protected operation requiring the same or higher level of authorization as the commands the mode enables, preventing an adversary from using a mode transition command to open a less-restricted commanding context. All secure command mode configurations, including geographic designations, time window parameters, and mode transition requirements, should be version-controlled and included in the FSW configuration baseline so that changes are tracked and reviewed through the configuration management process.