End-to-end encryption and segmentation in satellite links for sensitive operations
Satellite links employed in sensitive operations — defence, critical infrastructure management, emergency response — present a distributed attack surface encompassing the space segment, uplinks and downlinks, and ground terminals. Unlike switched terrestrial networks, the broadcast nature of the satellite medium exposes the channel to passive interception at any point within the coverage footprint. For this reason, the application of end-to-end encryption is not an architectural option but a functional requirement, regardless of whether the space segment operator operates in Ka, Ku or L band. The technical implementation of encryption in these environments must distinguish between the link layer and the application layer. Link-level encryption, common in certified satellite modems, protects traffic between the terminal and the hub, but leaves the signal exposed across terrestrial network segments if it is not complemented by upper-layer mechanisms. Transport and application layer encryption standards, managed through robust PKI infrastructures, allow the confidentiality of content to be maintained independently of intermediate nodes. Key lifecycle management, including periodic rotation and revocation procedures, constitutes one of the points of greatest operational fragility in prolonged deployments. Logical network segmentation is the indispensable architectural complement to encryption. In environments where multiple users or missions share satellite capacity, the absence of adequate segmentation can permit lateral movement in the event of a terminal being compromised. VLAN techniques over DVB-RCS2, or separation via IPsec tunnels with strict routing policies, reduce the exposure radius in the event of a security incident. On HAPS platforms or LEO constellations with on-board processing, segmentation must extend to the space segment itself, which adds complexity to the management of security policies on nodes with limited computing resources. From a European regulatory perspective, the certification schemes of the EUCS framework and the guidelines of the European Union Agency for Cybersecurity establish reference criteria for cloud services and critical communications, although their specific transposition to the satellite domain remains an area of active normative development. Operators and integrators working with institutional clients must anticipate requirements for configuration auditing, vulnerability management in terminal firmware, and access traceability — elements that condition both the technical design of the system and the operational procedures associated with the service lifecycle.
NASSAT - Network Satellite Systems