A look at Chang’e 5 telemetry
destevez.net
destevez.net
Glad to see some actually good telemetry for once.
I assumed it would take 3 days to get to the moon. I think that’s how long Apollo took. But they launched on Monday, and won’t get into lunar orbit until Saturday, which is 5 days.
But being that this is a robotic mission, that expediency wasn’t as important. And to save fuel, they might have circled around the Earth a few times to get a gravitational assist to launch to the moon.
Asking for a friend: A lunar flight planning physicist
The Hohmann transfer does not include the capture burn that is required to enter a sustained orbit around the Moon.
Disclaimer, I'm just a KSP fan, so feel free to correct any of the above. Had to make an effort to use Moon, not Mun.
I had not seen the CCSDS coding before, the seems like a bit of overkill for from the moon to here but perhaps they had too much signal fade on Tianwen-1 ?
Which leads me to think that the uplink transmission is not encrypted either.
I wonder what how capable it is for an amateur (hacker) to send a malicious command to their space craft.
That would be a shame, since China might begin to do some serious ground breaking science on the moon, that will eventually bring benefits to mankind.
Maybe they didn't encrypt downlink because they may need to work well with 3rd party telemetry partners? Nothing classified for a moon probe as well.
And I would be very surprised if commands were not at least signed/verified. That's one function call with a modern crypto library.
It might be easier to send slightly plausible noise (right frequency/modulation) to jam it.
Spacecraft are power and compute limited. It's entirely possible the designers chose not to spend the resources to encrypt a downlink that isn't sending anything that needs to be kept secret. In contrast, it's reasonable to assume that the uplink is at least protected by a HMAC, because the consequences of an adversary exploiting the uplink are so great.
The Chinese are well aware that the US security establishment is petty enough to interfere with a scientific probe purely for its own amusement. They will have taken precautions to deter this.
(And particularly in context of a high-profile mission like this, they definitely would want to keep telemetry open for third parties, to ensure their achievement is independently verified and recognized by the international community.)
Keep in mind that "encryption" bundles together four different concepts: confidentiality, data integrity, authentication, and non-repudiation. To successfully do space science, data integrity is suuuuuuuuper important. Like if you send a command to the spacecraft to fire the engines for (binary) 000000010110010 milliseconds, and a cosmic ray happens and the spacecraft receives a command to fire the engines for 001110010110010 milliseconds, congratulations, your mission is totally fucked. Voyager was launched with Reed Soloman error correction before fundamental cryptography fundamentals like DES, DH or RSA were published.
Confidentiality is kind of a non-issue with spacecraft. If ground control says, "Fire the thrusters for 174 seconds, authentication code 0x8d0a8fc7" or whatever there are no secrets. Non-repudiation is also a non-issue: NASA doesn't need to prove to NASA that it never sent the self destruct command. NASA already knows what commands it sent.
Authentication is the bit that prevents unauthorized commands, and honestly, the authentication tech is not that complicated. We need 128 bit keys (or 256 if you're paranoid) to do confidentiality correctly, but we use 64 bit keys with "known broken" algorithms like MD5 to do authentication, and that's known to be totally safe.
So of the four pillars of encryption, one of them had to be built in from day 1, or you'd never accomplish anything. One of them is kinda of an easy problem actually, even with old technology. The other two aren't part of the attack surface.
Spacecraft also have a HUGE advantage built in: shared secrets. Ground control can program a secret key into the spacecraft before it's launched. After it's flying around you can leverage stuff off of that shared secret to authenticate communications. This totally sidesteps all of the hard parts of TLS, which involve certificate authorities, certificate revocation lists, etc.
And, in all likelihood, there is either a common command protocol or a family of protocols for all Chinese spacecraft. Designing a brand new protocol for each class of spacecraft would be time consuming and add complexity to space operations.
It is easier to have just one command protocol, or just slight variations thereof, and use it for connection with all hardware out there.
I disagree with that. Using 64-bit authentication tags is fine, since they can only be attacked by sending guesses to the target system. 64-bit however are too weak, since they can be attacked using same offline brute-force attacks used against confidentiality. They have the advantage that an attacker needs to break them before they're changed/the project ends, while confidentiality can be important for many decades after that. But even then, I'd say 96 bits is the minimum authentication key size for a high value system, while I'd go with 128 bits.
Honestly, I'd be extremely impressed if hackers managed to issue a command to a spacecraft.
Some hobbyists tried to salvage an old NASA probe (with NASA approval): http://spacecollege.org/isee3/ and they were able to fire thrusters once.