Filed under:
News
Date:
23-09-2026
Filed under:
News
Date:
23-09-2026
In the first article in this series, I argued that the performance of a space edge computer should be measured by how efficiently it can refine raw data into useful information. In the second, I explored how a standardized platform can still adapt to mission-specific payloads and requirements. In essence: How can as much data as possible be funneled into the system, and how can that data be turned into end-user value in the most efficient way? But there is one more condition: To become useful, information must also be trustworthy.
A spacecraft may process a sensor stream in real time and reduce it to a concise operational insight. But what is that insight worth if the recipient cannot verify where it came from, whether it was altered or whether the system producing it was un-compromised?
Cybersecurity therefore contributes directly to Value Throughput. It preserves the confidentiality, integrity, authenticity and availability of information as it moves from sensor to processor and ultimately to the user.

Cybersecurity was not absent from traditional space activities. High-value missions protected command links, ground infrastructure and access to operations. But security was often treated as a communications issue rather than an intrinsic property of the onboard computing platform.
For many years, spacecraft also benefited from substantial barriers to entry. Their electronics were custom, their protocols specialized and their software known to relatively few people. Access to spacecraft required suitable ground infrastructure and detailed mission parameters, and hence both expertise and money. These conditions made an attack difficult before it had even reached the space system.
In that sense, the old paradigm was sometimes like protecting a door with an obscure antique lock. An ordinary burglar carrying a collection of modern keys might have no idea how to open it, but unfamiliarity does not make the lock inherently strong. Once a skilled attacker understands the mechanism and obtains the right tools, its obscurity provides little protection.
Traditional spacecraft benefited from similar unfamiliarity. This was not necessarily naive engineering. The security model reflected the technology, threats and operating practices of its time. Reliability, radiation tolerance, and fault recovery rightly dominated computer design. Physical isolation and specialist knowledge provided additional practical protection.
The problem is that those assumptions no longer describe much of the space industry.
Modern spacecraft increasingly use more ground-like computing like commercial processors, familiar operating systems, IP-based communications, cloud-connected ground infrastructure and software that can be updated in orbit. Satellite-as-a-Service offerings require payload computers to host applications from several suppliers. Commercial ground-station networks and service providers connect more organizations to the mission.
At the same time, spacecraft are becoming more autonomous. They can form images, detect objects, prioritize observations and distribute insights without waiting for every decision to pass through a mission control centre. The same capabilities that create more operational value also expand the attack surface.
The 2022 attack on Viasat’s KA-SAT network showed how directly space infrastructure can become involved in conflict. The attack disrupted satellite broadband at the start of Russia’s invasion of Ukraine and affected users beyond the intended theatre. The satellite itself was not compromised. The attackers targeted terrestrial infrastructure and user terminals instead. That distinction is important: a space-based service can be denied without anyone taking control of the spacecraft.
The complete system must therefore be considered. The attack surface includes the supply chain, ground segment, communication links, spacecraft platform, payload computer, applications and the data itself. An adversary will not necessarily attack the most essential node of the architecture. It will attack the most accessible weakness that can produce the desired effect.

This broader view is increasingly reflected in policy and standards. The United States issued Space Policy Directive 5 in 2020, calling for cybersecurity to be integrated throughout the lifecycle of space systems. NASA followed with its Space Security Best Practices Guide in 2023. NIST has developed guidance for commercial satellites and their command-and-control infrastructure, while CCSDS has standardized authentication and encryption at the space data-link layer. In Europe, the Cyber Resilience Act and the proposed EU Space Act point toward stronger lifecycle and sector-specific requirements.
Recognition has nevertheless advanced faster than implementation. In 2024, the US Government Accountability Office found that NASA’s space-security guidance had not yet been fully incorporated into mandatory spacecraft acquisition policies. Across the commercial market, cybersecurity maturity still varies between missions, suppliers and operators.
Encryption of a radio link remains essential, but it cannot answer every question. Was the onboard software authentic when it created the data product? Could another application modify the data? Did the information originate from the claimed sensor? Has the platform recorded unauthorized changes? Can it recover to a trusted state after a failed or malicious update?
The emerging model must establish trust throughout the processing chain, from boot and data acquisition to application execution, storage, delivery and recovery.
A value throughput pipeline continuously transforms high-rate sensor data into smaller, denser and more useful information. Security must operate at the same speed.
If signing or encryption cannot keep pace with the data stream, security becomes a bottleneck. If security consumes too much of the processing budget, operators face pressure to reduce or bypass it. If the platform cannot recover securely, a single compromised component can remove the entire pipeline from service at the moment its output matters most.
This is why security affects the value of the output rather than simply protecting the computer around it. Authenticity establishes who or what created the information. Confidentiality prevents it from reaching an unauthorized recipient. Integrity shows that it has not been altered. Availability ensures that the system can create and deliver it when the end user needs it and an adversary wants to disrupt it the most.
For Earth observation and intelligence missions, provenance is becoming especially important. A user may soon need to verify not only which satellite collected an image, but also which sensor, platform configuration, preprocessing chain and AI model produced a particular conclusion. As more analysis moves onboard, trust must embark with it.

We developed Unibap SEQR to make security part of the space edge-computing architecture. It focuses on three distinct aspects of space-based cybersecurity: the platform, the data that runs through it, and the organization responsible for maintaining them.
Secure Platform establishes a hardware-backed chain of trust from the FPGA and firmware, through the operating system, to the application. Layered secure boot, compartmentalization and controlled permissions help ensure that only authorized components operate and that an application receives access only to the resources it has been offered. Signed updates, protected audit logs and recovery mechanisms allow the system to evolve while retaining the ability to return to a known and verified state.
Secure Data protects information throughout its lifecycle. Sensor data can be signed in the FPGA before it reaches the application, creating verifiable provenance as close to the source as possible. Hardware-rooted keys, encryption and high-throughput hashing protect data during processing, storage and dissemination. Cryptographic acceleration allows these functions to operate without undermining the throughput that the mission depends on.
Secure Organization addresses a less visible but equally important part of the problem. A secure product depends on how it is developed, delivered, updated and supported. Unibap SEQR and the wider iX20 platform are backed by cybersecurity processes aligned with frameworks and requirements including ISO 27001, NIST, CMMC and the EU Cyber Resilience Act. This supports long-term assurance rather than treating security as a configuration completed before launch.
A spacecraft may operate for many years while threats, vulnerabilities and cryptographic expectations continue to change. The better it works, and the more strategic its services become, the likelier it will be targeted. Security by design cannot mean freezing the system at launch. It must include secure updates, controlled recovery, replaceable keys and the ability to adopt new protections without losing control of the platform.
This will become more important as missions rely on distributed processing, intersatellite communication and autonomous coordination. Future spacecraft may need to detect abnormal behaviour, isolate affected functions and recover without immediate ground intervention. Long-lived platforms will also need cryptographic agility and a path toward post-quantum protection.
Onboard AI adds another layer. Operators will need to know whether a model has been modified, whether its input data is authentic and which software and configuration produced a specific result. The provenance of an insight may become as important as the insight itself.

Defense and national-security missions are likely to become some of the strongest drivers of space-system requirements in the coming years. They operate with large and time-sensitive sensor streams, changing payload needs and adversaries that actively seek to deceive or disrupt the system and its services.
These missions need onboard processing because raw data can lose its operational relevance while waiting for downlink and ground analysis. They need adaptability because sensors, communication methods, algorithms and threats will change faster than traditional spacecraft-development cycles. They need security because information used for surveillance, targeting or situational awareness must remain trustworthy in a contested environment.
This is where the three themes in this series come together. Value throughput converts raw sensor data into timely information. Standardized adaptability allows the value throughput pipeline to support new payloads and capabilities without repeatedly redesigning its core. Security by design protects the platform and preserves trust in the information it produces.
Together, these capabilities position the Unibap iX20 as a computing foundation for increasingly software-defined, autonomous and security-critical space infrastructure. Future space defense will depend on platforms that can process more data, adapt as requirements change and remain trusted under attack. Those are the requirements the iX20 has been designed to meet.
Anders Persson , Head of Strategy and Products