IA-3(1) - Device Identification and Authentication | Cryptographic Bidirectional Authentication

Authenticate [Assignment: organization-defined devices and/or types of devices] before establishing [Selection (one or more): local; remote; network] connection using bidirectional authentication that is cryptographically based.


ID: IA-3(1)
Enhancement of : IA-3

Space Segment Guidance

Cryptographic, bidirectional authentication for commanding/telemetry and select on-board services benefits from anti-replay tied to time and sequence counters, with behavior defined for safe mode and degraded clocks. Consider how keys/certificates are pre-placed, rotated on-orbit, and retired; how partner stations are added/removed from whitelists; and how authentication remains credible during partial outages, handovers, or drift, while clearly signaling accept/reject outcomes to operators.