The Space Reviewin association with SpaceNews
 


 
satellite telemetry
Satellites log activities and transmit those data to Earth, but often rely on encryption systems vulnerable to hacking by quantum computers. (credit: L3Harris)

Who will believe the space logs in 2040?

Space governance and the quantum audit problem


Space operations have become exercises in relentless logging. Every thruster firing, every conjunction warning, every proximity operation, and every anti-satellite test generates a stream of telemetry that is meticulously recorded. Today, these logs are operational necessities, but decades from now they will become critical geopolitical evidence. If a state actor claims in 2037 that a commercial satellite intentionally interfered with its military asset, the resolution of that crisis will depend entirely on the historical data recorded today.

But how will we know that those logs are authentic and unaltered? The answer is cryptographic signatures. Unfortunately, this is precisely where the foundation of space governance begins to crack.

Directing engineers to use new algorithms for new satellites solves only half the problem. The unresolved crisis in space governance is what happens to the historical records.

Currently, the cryptographic locks securing space records rely overwhelmingly on classical algorithms like the Elliptic Curve Digital Signature Algorithm (ECDSA). These algorithms are mathematically sound today, but they have a strictly limited shelf life. In August 2024, the National Institute of Standards and Technology (NIST) finalized its first post-quantum cryptographic standards, and its companion transition roadmap, NIST IR 8547, sets a hard deadline. Classical algorithms like ECDSA are slated to be “deprecated” by 2030 and entirely “disallowed” by 2035.

Directing engineers to use new algorithms for new satellites solves only half the problem. The unresolved crisis in space governance is what happens to the historical records.

“Harvest now, verify/forge later” and the silent vulnerability

The defense community is rightly focused on the “harvest now, decrypt later” threat, where adversaries intercept encrypted communications today to decrypt them when quantum computing matures. However, space audit trails face a more insidious variation of this threat. We must confront the reality of “harvest now, forge later.”

In this scenario, an adversary collects publicly broadcast or intercepted signed records today. When cryptographically relevant quantum computers arrive, the adversary uses them not to read secrets, but to break the underlying signature scheme. Once the signature is broken, the adversary can retroactively forge historical records. They could alter the telemetry of a 2026 orbital maneuver and present it in 2032 to claim that a specific action never occurred, or that a completely different, hostile maneuver took place.

This is not science fiction. According to NIST’s own definitions, a “disallowed” signature scheme must be assumed vulnerable to forgery. Technically speaking, any space record signed with ECDSA will be considered vulnerable to retroactive forgery after 2035.

The space domain is uniquely exposed to this vulnerability for three reasons. First, space records have exceptionally long lifespans. A satellite may remain in orbit for 15 to 20 years, and the legal and operational value of its records lasts even longer. Second, these records are the primary mechanism for attribution. Attribution is the cornerstone of space security, and it is exactly what an adversary would want to manipulate. Third, there is no opportunity for “re-measurement” in space. If the telemetry of a specific orbital event is compromised, the only proof of that event is lost forever. The challenge is not merely encrypting the future. It is securing the integrity of the past in a post-quantum world.

Why simply changing the algorithm is not enough

The seemingly obvious solution is to abandon ECDSA and mandate the immediate use of new, quantum-resistant signatures like ML-DSA. While necessary, this approach is structurally incomplete for several reasons.

What space governance needs is not just a new algorithm, but a layered, crypto-agile architecture.

Relying exclusively on a single new algorithm introduces a new single point of failure. Algorithms like ML-DSA rely on complex lattice mathematics. If future cryptanalysis breaks that specific mathematical foundation, the space industry will have repeated the exact mistake it is currently trying to fix. Leaning on one pillar is a dangerous architecture for multi-decade records.

Furthermore, the transition period itself constitutes a massive vulnerability. Without a clear architecture dictating how and when legacy systems migrate to post-quantum standards, records generated during the transition remain exposed.

Finally, historical records are already signed and sealed. You cannot simply go back and “re-sign” decades of telemetry with a new key without fundamentally breaking the chain of custody and the trust inherent in the original record.

This is precisely why NIST IR 8547 supports hybrid approaches. During a transition, utilizing both classical and post-quantum algorithms simultaneously ensures that if one fails, the other maintains the integrity of the data. What space governance needs is not just a new algorithm, but a layered, crypto-agile architecture.

A layered solution for deep defense in space records

Securing the long-term integrity of space records requires a defense-in-depth approach. This aligns with the authority architectures I have previously argued for in these pages regarding on-orbit servicing and the AUTHREX Space Vehicle framework (see “Space autonomy needs an authority architecture before 2027”, The Space Review, June 22, 2026). To protect audit chains against quantum adversaries, we must divide the space record system into three distinct cryptographic layers.

Layer 1 is the Entry Commitment. At the moment a record is generated, it must be sealed with two signatures simultaneously. One signature is classical (compatible with today’s infrastructure), and the other is post-quantum. During the transitional decade, both protect the record. An adversary in 2026 cannot break the classical signature because they lack a quantum computer, and by 2032, even if they possess quantum capabilities, the post-quantum signature remains intact.

Layer 2 is the Chain Binding. Individual records must be linked together in a continuous hash chain, where every new record carries the digital fingerprint of the previous one. Crucially, this chain must explicitly tag which algorithm was used at every step. This concept, known as “algorithm agility,” ensures that even if algorithms change in the future, older records can still be verified using their original, securely recorded parameters.

In the event of a conflict, an orbital collision, or a liability dispute, the deciding factor will be the reliable data logged at the moment of the event.

Layer 3 is the Archival Anchor, which provides the long-horizon guarantee. At specific intervals, perhaps annually, a summary digest of the entire record chain is sealed with a stateless, hash-based signature like SLH-DSA. The critical feature of hash-based signatures is that they rely solely on the security of the hash function itself, rather than breakable mathematics like lattices or elliptic curves.

The strategic result of this architecture is profound. In the absolute worst-case scenario where all lattice-based cryptography is broken, the assurance that a space record has not been altered reduces to the security of a single hash function. Hash functions are highly resistant to quantum attacks. Quantum computers only halve their effective strength; they do not shatter them entirely.

Implementing this layered defense is remarkably inexpensive. My own testing of this prototype architecture demonstrates that sealing a record takes roughly a thousandth of a second, processing over 600 records per second on a single standard processor core. Generating a 30-year archival anchor requires only a few megabytes of storage and seconds of processing time. Long-horizon security is, operationally speaking, practically invisible.

The governance gap and the 2030 horizon

Current international space governance discussions within the UN Committee on the Peaceful Uses of Outer Space (COPUOS) focus heavily on debris mitigation, anti-satellite testing norms, and the “due regard” principles of Outer Space Treaty Article IX. However, these discussions are ignoring the long-term integrity of the records that make these norms enforceable.

Article IX of the Outer Space Treaty requires states to conduct activities with due regard for the corresponding interests of others. This principle is entirely dependent on the existence of reliable, unalterable logs. If we accept that post-quantum adversaries can retroactively forge space records, the entire attribution mechanism of international space law collapses.

The 2030 algorithm deprecation date is approaching rapidly. Cryptographic transitions in complex infrastructure typically take five to ten years. An agency or commercial operator that does not begin this migration by 2027 will find its operational margins severely depleted. A comprehensive breakdown of this timeline is available in this analysis of NIST IR 8547.

To bridge this governance gap, I propose four immediate actions. First, state and commercial space operators must design their logging systems today to be crypto-agile. Second, the use of hash-based archival anchors must become a mandated standard for any long-lived space record. Third, COPUOS and related international norm-setting bodies must formally address record integrity through a long-horizon perspective. Fourth, the space industry must align its cryptographic migration strategy with a strict milestone plan tied directly to the NIST 2030 and 2035 deadlines.

Conclusion

In the space domain, power is increasingly tied to who holds the correct records. In the event of a conflict, an orbital collision, or a liability dispute, the deciding factor will be the reliable data logged at the moment of the event. The quantum era threatens to unlock these records, placing not only future operations but our current historical telemetry at risk.

The 2030 and 2035 deadlines are not distant theoretical concepts. They are imminent operational realities. If the space community intends for its records to remain credible decades into the future, the foundational architecture must be built now. A record whose lock can be broken loses its value the moment the lock fails.

The question is not whether space records will outlive their cryptographic locks. They already are designed to. The question is whether we will give them locks worth keeping.


Note: we are now moderating comments. There will be a delay in posting comments and no guarantee that all submitted comments will be posted.

Home