Overview
ISO 20215:2015 - “Space data and information transfer systems - CCSDS cryptographic algorithms” - is an ISO adoption of the CCSDS Recommended Standard (CCSDS 352.0-B-1) that specifies recommended cryptographic algorithms and modes for use on space missions. The standard targets confidentiality, authentication, and authenticated confidentiality for space data (e.g., telemetry, telecommand, science data, voice, and video) across the forward and return space links and ground data networks. It recommends a single symmetric encryption algorithm and defined modes of operation, while leaving key distribution and management practices out of scope.
Keywords: ISO 20215, CCSDS cryptographic algorithms, space data security, spacecraft encryption, telemetry authentication, space mission cybersecurity
Key Topics
- Scope and applicability
- Recommended for civilian space missions with confidentiality or authentication needs.
- Applicable to on‑board, link, and ground storage protections.
- Encryption
- Recommends a single symmetric encryption algorithm and a specific mode of operation for interoperability.
- Addresses algorithm mode of operation and notes the importance of appropriate cryptographic key sizes (detailed guidance provided in the document).
- Authentication and integrity
- Presents multiple authentication alternatives to fit mission requirements, including:
- Hash-based message authentication
- Cipher-based authentication
- Digital-signature–based authentication
- Discusses authenticated encryption (combined confidentiality and integrity).
- Security considerations
- Emphasizes that using the recommended algorithms does not eliminate all risks; mission-specific risk assessment is required.
- Notes that key management is essential but outside the standard’s scope.
Applications
ISO 20215 is intended for:
- Spacecraft system architects and security engineers designing protection for telecommand and telemetry links.
- Mission planners evaluating requirements for confidentiality and authentication.
- Ground segment operators and network engineers securing data flows and storage.
- Suppliers and manufacturers producing cryptographic modules or secure communication products for space applications.
Practical uses include securing telecommand to prevent unauthorized control, authenticating telemetry to ensure data integrity, protecting payload science data, and encrypting stored on‑board or ground data.
Related Standards
- CCSDS 352.0-B-1 (original Recommended Standard / Blue Book)
- Space Missions Key Management Concept (reference [B22]) - for key management guidance
- Space Data Link Security Protocol (reference [B23])
- Security Architecture for Space Data Systems (reference [B17])
- The Application of CCSDS Protocols to Secure Systems (reference [B1])
Using ISO 20215 helps ensure interoperable, standardized cryptography across missions and supports procurement of off‑the‑shelf solutions aligned with CCSDS/ISO space data security practices.