Documentation
¶
Overview ¶
Example: Encrypting and authenticating a link
Every other example here sends plaintext. Anyone with a dish can read a downlink, and worse, anyone with a transmitter can forge an uplink. SDLS is the layer that fixes both.
Downlink (clause E1 baseline): AES-256-GCM. The telemetry is encrypted and authenticated together. Uplink (clause E2 baseline): AES-CMAC. The telecommand travels in the clear but cannot be forged, which is what commanding actually needs. Three attacks that fail: 1. A flipped bit in the ciphertext 2. A replayed frame 3. A valid frame injected on the wrong virtual channel
SDLS protects the data field of a frame. The carrier packages need no changes: this package builds the protected data field and the frame constructor takes it as ordinary octets.
Click to show internal directories.
Click to hide internal directories.