Dummy Process - Aggregator Node

In spacecraft architectures containing aggregator or relay nodes, observable computation and communication patterns may reveal valid aggregation cycles and traffic-flow relationships involving critical nodes, root nodes, or ground termination points. This countermeasure is applicable when the threat model identifies a credible adversary capability to observe node power or electromagnetic activity and correlate those observations with RF transmission activity. While camouflaging all network traffic through constant high-power transmission is energy-prohibitive, selectively obscuring aggregator node behavior through dummy process execution provides a practical alternative. This countermeasure requires aggregator nodes to execute dummy workloads whose observable characteristics are sufficiently similar to genuine aggregation cycles to make reliable classification difficult within the mission-defined adversary model. Evaluation should consider applicable power, electromagnetic, execution-duration, processor-activity, memory-access, and RF-correlated features rather than matching only an average power-consumption curve. Two properties are essential for effectiveness: first, dummy processes must vary in their execution pattern, using a different dummy process each time or maintaining a low repetition rate, to prevent adversaries from identifying a distinguishable signature that differentiates dummy from genuine execution; second, timing of dummy execution must be carefully controlled, with a dummy process executed every time the aggregator receives a transmission and randomly during idle periods, to prevent adversaries from correlating the presence or absence of radio frequency (RF) transmissions with power consumption curves to identify and discard dummy activity. Together, these properties are intended to reduce an observer’s ability to distinguish valid aggregation cycles and infer traffic flow toward a critical root or base-station node. They do not guarantee that aggregator nodes, network topology, or the base station cannot be identified through other observations.

Sources

ID: CM0062
Tier: III
Onboard SV CM 
Created: 2022/10/19
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition requirements should address dummy process execution as a traffic flow obfuscation capability for aggregator nodes in spacecraft sensor networks or constellation architectures where base station identification represents a significant operational security risk. Requirements should define the observable features and adversary capabilities against which genuine and dummy aggregation activity must be difficult to distinguish. The design must incorporate sufficiently variable dummy execution and the required combination of transmission-correlated and idle-period execution so that the presence or absence of RF activity does not provide a reliable means of discarding dummy observations. Contract language should require that the dummy process design be documented as a controlled deliverable, including the method for generating varied dummy processes, the statistical properties of the idle-period random execution schedule, and the power consumption fidelity of the dummy process relative to genuine aggregation cycles. Evaluation criteria should assess offerors' proposed dummy process architecture, their analysis of the power profile fidelity between dummy and genuine operations, and their approach to validating that the implementation prevents traffic flow identification under realistic adversary observation conditions. Verification should include power trace analysis comparing dummy and genuine execution profiles, and adversarial simulation exercises that attempt to identify aggregation cycles and base station location under the implemented scheme.

Pre-Operations Developer/Supplier

Dummy process design must begin with a characterization of the genuine aggregation cycle power consumption profile, establishing the target power curve that dummy processes must replicate with sufficient fidelity to defeat statistical discrimination by an adversary collecting power traces over extended periods. Dummy execution must provide sufficient variation to avoid a repetitive signature while remaining statistically consistent with genuine aggregation activity. Variation may use randomized execution paths, workload parameters, or selection among validated templates, but variable duration or computation must not introduce features that make dummy activity easier to classify. Repetition rate and distinguishability must be evaluated over the observation duration and measurement capability defined by the threat model. Timing control logic must implement the approved transmission-correlated and idle-period dummy schedule, including dummy execution for each applicable received-transmission event required by the design. Scheduling must preserve safety- and mission-critical timing, power, and thermal limits and must address whether an adversary could generate transmissions that force excessive dummy execution. Unpredictable idle-period scheduling must use an approved random or pseudorandom mechanism with properties appropriate to the threat model. Power budget analysis must account for the sustained overhead of dummy process execution across all operational modes, as the requirement to execute dummy processes upon every received transmission and randomly during idle periods represents a non-trivial continuous power cost that must be within the aggregator node's energy margin. The fidelity of the dummy power profile relative to genuine aggregation should be validated through hardware-level power measurement rather than simulation alone, as hardware-level power consumption behavior may deviate from model predictions in ways that inadvertently create discriminating signatures.