AC-3(13) - Access Enforcement | Attribute-based Access Control

Enforce attribute-based access control policy over defined subjects and objects and control access based upon [Assignment: organization-defined attributes to assume access permissions].


ID: AC-3(13)
Enhancement of : AC-3

Space Segment Guidance

Attribute-Based Access Control (ABAC) can be challenging on orbit because real-time retrieval of attributes from the ground is often infeasible, especially if the spacecraft only has short contact windows or limited bandwidth. Nonetheless, systems with multiple hosted payloads and complex operational rules may benefit from a lightweight ABAC solution where the spacecraft periodically receives "attribute packages" from a central authority—potentially via another satellite in a constellation. These attribute sets could describe constraints (e.g., permitted data rates, command privileges) that apply to each payload or user group. The onboard OS or firmware then evaluates these attributes before granting a request. This arrangement preserves ABAC's flexibility without requiring a constant data link to ground services. Although it adds design complexity and demands robust key management for attribute updates, such an approach can help unify dynamic mission needs—like changing priority levels among different payload owners—while maintaining strong, policy-driven access protections.