DOI: 10.1002/dac.70617 ISSN: 1074-5351

An Empirically Validated, Resilient SDR‐Based CubeSat Communication Architecture Featuring Dynamic AES‐256 and Deterministic Frequency Hopping

Mert Karahan, Arif Semih Barin

ABSTRACT

CubeSats are widely used in low‐cost space missions, but their dependence on commercial off‐the‐shelf (COTS) components and limited onboard resources creates security challenges for telemetry, command, and mission‐data links. This study presents a Software‐Defined Radio (SDR)‐based secure communication architecture evaluated in laboratory conditions for resource‐constrained CubeSat applications. The prototype combines dynamic AES‐256 key rotation, a deterministic 58‐channel Dynamic Channel Switching (DCS) protocol, and a mutual authentication (MuA) mechanism over LoRa modulation. A STRIDE‐based threat model is used to identify relevant attack surfaces and examine the proposed countermeasures for spoofing, replay, information disclosure, and denial‐of‐service scenarios. The system was evaluated through simulation, SDR‐based radio‐frequency (RF) laboratory tests, and hardware‐in‐the‐loop power profiling. The software implementation of AES‐256 required a processing window of 327 μs and accounted for less than 0.02% of the measured packet‐transmission energy. In the tested Partial‐Band Noise Jammer (PBNJ) scenario, where 6 of 58 messaging channels were jammed, the packet error rate remained close to 10%, consistent with the fraction of jammed channels. These results show that dynamic key rotation and channel switching can be implemented in a laboratory CubeSat communication prototype with low processing and energy overhead.