IA-7 - Cryptographic Module Authentication

Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, executive orders, directives, policies, regulations, standards, and guidelines for such authentication.


ID: IA-7
Enhancements: 

Space Segment Guidance

Cryptographic module authentication ensures that only a legitimate, initialized crypto device accepts keys or participates in link setup. The spacecraft typically hosts a Type 1 or Suite B unit that supports a unique hardware key and a factory-installed certificate. On the first contact each day, the ground station performs a challenge-response exchange, records the result in the mission log, and includes the session identifier in the telemetry header so that analysts can confirm the link was not spoofed during playback. If authentication fails, the spacecraft drops to beacon-only mode and waits for a secure rekey command containing a fresh challenge from an alternate ground site.