Reference card.

Downloads ▾
← Back to course
TLP:GREEN Limited Disclosure · SCORP² community members only
Exported by: verifying identity… Exported at:
Distribution notice. This document is for active SCORP² community members only. Unauthorized distribution will result in revocation of community membership.

Kestrel Orbital Day-1 CONOPS

Enumerated Taxonomic Element Nomenclature (ETEN) reference

An Enumerated Taxonomic Element Nomenclature (ETEN) names one real element on a platform, in five fields.

ETEN Example

Layer
PCE
Tag
TE
Label
Terrestrial
Ordinal
00
Description
Reston, Virginia land site hosting the primary mission-operations complex, its control facilities, and the network operations center.

The enumeration that produces every ETEN is governed by the normative process: the scope bounds what is enumerated, the taxonomy supplies the tag and label, the ontology links the parent, and the description states the instance.

ETEN Process

Step 01
Set the scope, from the resilience objective and the requirements that drive the decomposition; an element outside the scope is not enumerated. Kestrel’s scope is the telecommand path.
Step 02
Select the layer, working top down through the taxonomy’s structural layers, and confirm the element passes that layer’s definition gate before proceeding. The gates are the taxonomy’s layer definitions, verbatim:
  • PCEPrimary Capability Environment. “Operational zone in which a capability primarily exists or is exercised.” The gate: you are naming a WHERE, a zone, not a thing in it.
  • SEGSegment. “Service and asset enclaves that compose the system across environments.” The gate: you are naming an ENCLAVE, a grouping of services and assets, not the zone it sits in and not the hardware inside it.
  • SVCService. “Functional planes that organize control and data responsibilities.” The gate: you are naming a functional RESPONSIBILITY, what the platform does, not what it is built from.
  • ASTAsset. “Asset classes composing the system and its interfaces.” The gate: you are naming a CONCRETE ELEMENT, a real component the platform is built from.
Tiebreak for the recurring trap: PCE and SEG share tag names (Orbital and Space, Aquatic, Deep Space) but are different things. Ask: am I naming a zone, or a group of services and assets? Zone means PCE; group means SEG. An element that fails its layer’s gate is not enumerated at that layer; reclassify and re-enter at Step 02. Enrichment (AN) follows in Functions 02 through 05.
Step 03
Select the tag from the taxonomy for that layer; never invent one.
Step 04
Write the label exactly as the taxonomy publishes it for that tag.
Step 05
Assign the ordinal, two digits from 00, counted per tag.
Step 06
Link the parent one layer up. This link is the ontology: every child names its parent, PCE is the root, and no element is an orphan. The parent chain enforces the layer gates structurally: a segment names one or more environments, a service names one or more segments, and an asset names exactly one service, never zero, never two. An enrichment element takes no parent; it anchors through its target field.
Step 07
Set the optional fields: a service marks DISTRIBUTED when it spans more than one segment; an asset may carry a SUBSYSTEM grouping; an enrichment element carries its TARGET and SOURCE.
Step 08
Write the description, one plain sentence stating what this exact instance is on this platform, at its own layer: a zone for an environment, an enclave of services and assets for a segment, a responsibility for a service, a concrete element for an asset. The layer gate from Step 02 applies again here: a segment description never describes the hardware inside the enclave; a service description begins “The service that …”; an asset description begins with its element class (“The physical …”, “The embedded …”, “The flight software …”, “The stored …”, “The transmitted …”). An instance described at the wrong layer is non-compliant.

The Kestrel Enumeration

You had eight hours with the Security Operations Center, Satellite Operations Center, and Satellite Design & Engineering. The scope came first, under Function 01, Concept of Operations: the telecommand path, the command-and-control scope Executive Order 14144 and the NIS2 Directive hold Kestrel to.

Eight hours across three departments does not exhaust a platform, and this enumeration is not exhaustive. It is enough: 55 elements that demonstrate to management that the three departments decompose one platform against one taxonomy, one ontology, and one process. The Day-1 CONOPS below is the result.

The collaboration of your local team or teams is vital: it is what lets you adopt the Resilient Cyber Operations framework in the way that works best for you. Adoption is also the essence of space collective defense: every organization that enumerates against the same taxonomy and ontology can exchange enrichment machine to machine, and each new adopter makes that exchange easier. The machine-readable releases under Downloads exist for that purpose.

Why two orbital environments but one space inventory: the teams enumerated PCE:OR:Orbital:00 (GEO) and PCE:OR:Orbital:01 (MEO) separately, because regime-specific enrichment (space weather, contact geometry, radiation) attaches at the environment layer. They ruled one Space segment with one shared set of services and assets across both regimes, sized to the current workload: the fleet flies as one commanded constellation through one telecommand path, and splitting every flight service per regime would have roughly doubled the space-segment inventory before anyone knew whether the split earned its keep. The plan of record is to track the SDA (space domain awareness) to measure how much operational activity is specific to MEO versus GEO, then use that evidence to build the longer-term plan for coordinating enumeration of the entire platform.

Kestrel Orbital Day-1 CONOPS PCE:OR:Orbital:00 · Orbital environment (GEO)PCE:OR:Orbital:01 · Orbital environment (MEO) SEG:SP:Space:00 · Space segment (spans Orbital:00 GEO and Orbital:01 MEO)two regimes, one segment: one shared service and asset set (scoping decision) SVC:CP:Control Plane:00 ADCS AST:HW:Hardware:00 AST:SW:Software:00 SVC:HY:Hybrid:00 C&DH AST:HW:Hardware:06 AST:FW:Firmware:01 AST:SW:Software:06 SVC:DP:Data Plane:00 Comms AST:FW:Firmware:02 SVC:CP:Control Plane:01 Crypto (Space) AST:DA:Data:03 SVC:CP:Control Plane:02 EPS AST:HW:Hardware:01 SVC:DP:Data Plane:01 Payload AST:HW:Hardware:07 SVC:CP:Control Plane:03 FTS AST:HW:Hardware:02 AST:FW:Firmware:00 SVC:CP:Control Plane:04 TCS AST:HW:Hardware:03 SEG:LI:Link:00 · Link segment (spans Orbital and Terrestrial) physical RF link, spans PCE:OR:Orbital:00, PCE:OR:Orbital:01, and PCE:TE:Terrestrial (space and ground) SVC:CP:Control Plane:05 ACA (Link) AST:DA:Data:00 SVC:HY:Hybrid:01 Error Handling (FEC) AST:SI:Signal:00 SVC:CP:Control Plane:06 Attack Det / Rec AST:SW:Software:05 SVC:CP:Control Plane:07 Payload Command AST:SW:Software:01 SVC:HY:Hybrid:02 T2 Track & Tlm AST:SI:Signal:01 PCE:TE:Terrestrial:00 · Terrestrial environment (Reston mission ops) SEG:GR:Ground:00 · Ground segment (Reston) SVC:CP:Control Plane:08 Crypto (Ground) AST:HW:Hardware:05 SVC:CP:Control Plane:09 ACA (Ground) AST:SW:Software:02 AST:DA:Data:01 SVC:CP:Control Plane:10 Launch Control AST:SW:Software:07 SVC:CP:Control Plane:11 AFSS AST:FW:Firmware:03 SVC:CP:Control Plane:12 Patch Updates AST:DA:Data:02 AST:SW:Software:03 SVC:CP:Control Plane:13 Satellite Console AST:HW:Hardware:04 AST:SW:Software:04 PCE:TE:Terrestrial:01 · Terrestrial environment (Kiruna TT&C station) SEG:GR:Ground:01 · Ground segment (Kiruna) SVC:HY:Hybrid:03 Ground Terminal (antenna / RF) AST:HW:Hardware:08 PCE SEG SVC AST 4 environments · 4 segments · 20 services · 27 assets = 55 elements. Scope: the telecommand (command-and-control) path EO 14144 and NIS2 hold Kestrel to, a first pass at the key elements, not the whole platform. Single-parent tree; the RF link is the one physical medium that spans two environments. Each code is one enumerated ETEN in LAYER:TAG:Label:Ordinal form. Blue chips are assets, nested under their green parent service. The two regimes share one Space segment and service and asset set by scoping decision.

L1PCE · Environments (4)

PCE Key Points

Key point
What was missing: security frameworks carried no taxonomy and no ontology for the environment; where a platform operates was prose context, not an element that threats, detections, and resilience measures could anchor to.Recommendation: enumerate every distinct operational zone as its own PCE, one per physical site; a new site is a new ordinal, no restructuring.Kestrel: PCE:TE:Terrestrial:00 Reston, Virginia and PCE:TE:Terrestrial:01 Kiruna, Sweden, so enrichment lands at the location level (terrestrial weather over the site, possible positioning of mobile electronic-warfare apparatus near it) while the set of environments preserves the global view.
Key point
What was missing: aerial, aquatic, orbital, and deep space were one undifferentiated environment, so there was no way to enrich by taxonomy and ontology for space domain awareness.Recommendation: one PCE per orbital regime, never a generic orbital; the taxonomy already carries Terrestrial, Aquatic, Aerial, Orbital, and Deep Space, so the model extends without change.Kestrel: the fleet spans two regimes, so it carries two orbital environments, PCE:OR:Orbital:00 GEO and PCE:OR:Orbital:01 MEO, aligning space-weather enumeration to each regime.
Key point
What was missing: a rule for whether a fleet spanning two regimes needs its inventory split per regime or shared across them.Recommendation: enumerate the environments separately, share one segment and one service and asset set while the workload supports it, and let evidence, not habit, decide a future split.Kestrel: two orbital environments, one Space segment: one shared service and asset set sized to current workload; the teams track the SDA (space domain awareness) to measure what is MEO-specific versus GEO-specific, then build the longer-term plan to coordinate enumerating the entire platform.
The 4 enumerated PCE environments, click to expand or collapse
PCEOrbital00
ETEN nomenclaturePCE:OR:Orbital:00:The geostationary orbit regime (~35,786 km) part of the fleet flies in, fixing its coverage geometry, contact windows, and radiation exposure.
Layer
PCE Primary Capability Environment (L1)
Tag
OR
Label
Orbital
Ordinal
00
Parent
none, root element
Description
The geostationary orbit regime (~35,786 km) part of the fleet flies in, fixing its coverage geometry, contact windows, and radiation exposure.
PCEOrbital01
ETEN nomenclaturePCE:OR:Orbital:01:The medium Earth orbit regime (~8,000 km) part of the fleet flies in, with its own orbital periods, contact windows, and radiation environment.
Layer
PCE Primary Capability Environment (L1)
Tag
OR
Label
Orbital
Ordinal
01
Parent
none, root element
Description
The medium Earth orbit regime (~8,000 km) part of the fleet flies in, with its own orbital periods, contact windows, and radiation environment.
PCETerrestrial00
ETEN nomenclaturePCE:TE:Terrestrial:00:Reston, Virginia land site hosting the primary mission-operations complex, its control facilities, and the network operations center.
Layer
PCE Primary Capability Environment (L1)
Tag
TE
Label
Terrestrial
Ordinal
00
Parent
none, root element
Description
Reston, Virginia land site hosting the primary mission-operations complex, its control facilities, and the network operations center.
PCETerrestrial01
ETEN nomenclaturePCE:TE:Terrestrial:01:Kiruna, Sweden polar TT&C ground-station site (67.9°N) that carries the command path into the link; a separate site with its own ordinal for clean failover and jurisdiction analysis.
Layer
PCE Primary Capability Environment (L1)
Tag
TE
Label
Terrestrial
Ordinal
01
Parent
none, root element
Description
Kiruna, Sweden polar TT&C ground-station site (67.9°N) that carries the command path into the link; a separate site with its own ordinal for clean failover and jurisdiction analysis.

L2SEG · Segments (4)

SEG Key Points

Key point
What was missing: enterprise models carried no enclave that spans environments, so jurisdiction and failover lived outside the model.Recommendation: one segment per enclave of services and assets; each physically or jurisdictionally distinct enclave takes its own ordinal, and a cross-environment segment names every parent.Kestrel: SEG:GR:Ground:00 Reston, Virginia under US authorities, SEG:GR:Ground:01 Kiruna under Sweden and the EU, and the Link naming both the Orbital and Terrestrial environments.
Key point
What was missing: models described the enterprise a company has today, so growth broke them.Recommendation: the segment taxonomy already carries Launch, Link, Ground, User, Aquatic, Low Altitude, High Altitude, Near Space, Space, and Deep Space, so Resilient Cyber Operations is future proof by construction: a merger, an acquisition, or a new market enumerates into existing tags with new ordinals, never a remodel.Kestrel: a downrange tracking ship enumerates as SEG:AQ:Aquatic:00, a stratospheric relay as SEG:NE:Near Space:00, and a cis-lunar mission as SEG:DE:Deep Space:00, the day the business needs them.
SEGSpace00
ETEN nomenclatureSEG:SP:Space:00:The on-orbit enclave: the flight services and their assets operating on the constellation spacecraft, beyond physical reach.
Layer
SEG Segment (L2)
Tag
SP
Label
Space
Ordinal
00
Parent
PCE:OR:Orbital:00 + PCE:OR:Orbital:01
Description
The on-orbit enclave: the flight services and their assets operating on the constellation spacecraft, beyond physical reach.
SEGLink00
ETEN nomenclatureSEG:LI:Link:00:The link enclave: the services and assets carrying telecommand up and telemetry and mission data down across the RF and optical signal path between space and ground.
Layer
SEG Segment (L2)
Tag
LI
Label
Link
Ordinal
00
Parent
PCE:OR:Orbital:00 + PCE:OR:Orbital:01 + PCE:TE:Terrestrial:00
Description
The link enclave: the services and assets carrying telecommand up and telemetry and mission data down across the RF and optical signal path between space and ground.
SEGGround00
ETEN nomenclatureSEG:GR:Ground:00:The Reston, Virginia mission-operations enclave: the control, crypto, access-control, patch, and console services that command the constellation.
Layer
SEG Segment (L2)
Tag
GR
Label
Ground
Ordinal
00
Parent
PCE:TE:Terrestrial:00 + PCE:TE:Terrestrial:01
Description
The Reston, Virginia mission-operations enclave: the control, crypto, access-control, patch, and console services that command the constellation.
SEGGround01
ETEN nomenclatureSEG:GR:Ground:01:Kiruna, Sweden polar TT&C ground-station enclave; the second terrestrial ground segment, distinct from Reston, hosting the site RF ground terminal.
Layer
SEG Segment (L2)
Tag
GR
Label
Ground
Ordinal
01
Parent
PCE:TE:Terrestrial:01
Description
Kiruna, Sweden polar TT&C ground-station enclave; the second terrestrial ground segment, distinct from Reston, hosting the site RF ground terminal.

L3SVC · Services (20)

SVC Key Points

Key point
What was missing: no plane-level taxonomy: command and mission traffic blurred together, and a cross-segment service was filed in one box, hiding the surface an adversary crosses.Recommendation: classify every service by what actually flows through it, Control Plane, Data Plane, or Hybrid when both, and mark DISTRIBUTED with every parent segment named.Kestrel: SVC:HY:Hybrid:00 C&DH carries commands and mission data, so it is Hybrid by classification, not by guess.

Space segment services · parent SEG:SP:Space:00

SVCControl Plane00
ETEN nomenclatureSVC:CP:Control Plane:00:The service that determines and controls spacecraft orientation (ADCS).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
00
Parent
SEG:SP:Space:00
Description
The service that determines and controls spacecraft orientation (ADCS).
SVCHybrid00
ETEN nomenclatureSVC:HY:Hybrid:00:The service that executes commands and moves data across the vehicle, on both the control and data planes (C&DH).
Layer
SVC Service (L3)
Tag
HY
Label
Hybrid
Ordinal
00
Parent
SEG:SP:Space:00
Description
The service that executes commands and moves data across the vehicle, on both the control and data planes (C&DH).
SVCData Plane00
ETEN nomenclatureSVC:DP:Data Plane:00:The service that carries telemetry and payload product to the ground (Comms).
Layer
SVC Service (L3)
Tag
DP
Label
Data Plane
Ordinal
00
Parent
SEG:SP:Space:00
Description
The service that carries telemetry and payload product to the ground (Comms).
SVCControl Plane01
ETEN nomenclatureSVC:CP:Control Plane:01:The service that encrypts and authenticates on board, including telecommand authentication (Crypto, space).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
01
Parent
SEG:SP:Space:00
Description
The service that encrypts and authenticates on board, including telecommand authentication (Crypto, space).
SVCControl Plane02
ETEN nomenclatureSVC:CP:Control Plane:02:The service that generates, stores, and distributes electrical power (EPS).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
02
Parent
SEG:SP:Space:00
Description
The service that generates, stores, and distributes electrical power (EPS).
SVCData Plane01
ETEN nomenclatureSVC:DP:Data Plane:01:The service that produces the mission product the satellite exists to deliver (Payload).
Layer
SVC Service (L3)
Tag
DP
Label
Data Plane
Ordinal
01
Parent
SEG:SP:Space:00
Description
The service that produces the mission product the satellite exists to deliver (Payload).
SVCControl Plane03
ETEN nomenclatureSVC:CP:Control Plane:03:The service that performs command-received flight termination for range safety (FTS).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
03
Parent
SEG:SP:Space:00
Description
The service that performs command-received flight termination for range safety (FTS).
SVCControl Plane04
ETEN nomenclatureSVC:CP:Control Plane:04:The service that holds every component within its temperature limits (TCS).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
04
Parent
SEG:SP:Space:00
Description
The service that holds every component within its temperature limits (TCS).

Link segment services · parent SEG:LI:Link:00

SVCControl Plane05
ETEN nomenclatureSVC:CP:Control Plane:05:The service that authenticates command sources and enforces command acceptance on the uplink (ACA, link).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
05
Parent
SEG:LI:Link:00
Description
The service that authenticates command sources and enforces command acceptance on the uplink (ACA, link).
SVCHybrid01
ETEN nomenclatureSVC:HY:Hybrid:01:The service that detects or corrects bit errors on the link (FEC/ECC error handling).
Layer
SVC Service (L3)
Tag
HY
Label
Hybrid
Ordinal
01
Parent
SEG:LI:Link:00
Description
The service that detects or corrects bit errors on the link (FEC/ECC error handling).
SVCControl Plane06
ETEN nomenclatureSVC:CP:Control Plane:06:The service that detects hostile command or state manipulation on board and recovers from it.
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
06
Parent
SEG:LI:Link:00
Description
The service that detects hostile command or state manipulation on board and recovers from it.
SVCControl Plane07
ETEN nomenclatureSVC:CP:Control Plane:07:The service that tasks and configures the payload.
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
07
Parent
SEG:LI:Link:00
Description
The service that tasks and configures the payload.
SVCHybrid02
ETEN nomenclatureSVC:HY:Hybrid:02:The service that tracks the vehicle and returns telemetry across the control loop and the data path (T2).
Layer
SVC Service (L3)
Tag
HY
Label
Hybrid
Ordinal
02
Parent
SEG:LI:Link:00
Description
The service that tracks the vehicle and returns telemetry across the control loop and the data path (T2).

Ground segment services (Reston) · parent SEG:GR:Ground:00

SVCControl Plane08
ETEN nomenclatureSVC:CP:Control Plane:08:The service that protects commands before uplink and data after downlink (Crypto, ground).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
08
Parent
SEG:GR:Ground:00
Description
The service that protects commands before uplink and data after downlink (Crypto, ground).
SVCControl Plane09
ETEN nomenclatureSVC:CP:Control Plane:09:The service that decides who may command and which commands are released to the link (ACA, ground).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
09
Parent
SEG:GR:Ground:00
Description
The service that decides who may command and which commands are released to the link (ACA, ground).
SVCControl Plane10
ETEN nomenclatureSVC:CP:Control Plane:10:The service that conducts and monitors launch-phase operations (Launch Control).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
10
Parent
SEG:GR:Ground:00
Description
The service that conducts and monitors launch-phase operations (Launch Control).
SVCControl Plane11
ETEN nomenclatureSVC:CP:Control Plane:11:The service that terminates flight autonomously by rule, without a human in the loop (AFSS).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
11
Parent
SEG:GR:Ground:00
Description
The service that terminates flight autonomously by rule, without a human in the loop (AFSS).
SVCControl Plane12
ETEN nomenclatureSVC:CP:Control Plane:12:The service that delivers and installs software and firmware updates under control (Patch Updates).
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
12
Parent
SEG:GR:Ground:00
Description
The service that delivers and installs software and firmware updates under control (Patch Updates).
SVCControl Plane13
ETEN nomenclatureSVC:CP:Control Plane:13:The service that gives operators the mission-ops console: telemetry monitoring and command issue.
Layer
SVC Service (L3)
Tag
CP
Label
Control Plane
Ordinal
13
Parent
SEG:GR:Ground:00
Description
The service that gives operators the mission-ops console: telemetry monitoring and command issue.

Ground segment services (Kiruna) · parent SEG:GR:Ground:01

SVCHybrid03
ETEN nomenclatureSVC:HY:Hybrid:03:The service that transmits the command uplink and receives the downlink at the Kiruna ground station (RF ground terminal).
Layer
SVC Service (L3)
Tag
HY
Label
Hybrid
Ordinal
03
Parent
SEG:GR:Ground:01
Description
The service that transmits the command uplink and receives the downlink at the Kiruna ground station (RF ground terminal).

L4AST · Assets (27)

AST Key Points

Key point
What was missing: asset inventories stopped at "the satellite" or "the ground system," and a bundle cannot carry a threat anchor.Recommendation: one asset per concrete element under exactly one parent service, split to the depth you defend; a new asset slots under its service without renumbering.Kestrel: AST:SI:Signal:00 the TC uplink waveform, AST:DA:Data:03 the on-board key store, and AST:FW:Firmware:01 the OBC boot firmware are separate elements, so a threat anchors to the exact asset it exploits, never a bundle.

Space segment assets · each parents to a service within SEG:SP:Space:00

ASTHardware00
ETEN nomenclatureAST:HW:Hardware:00:The physical attitude sensors: star trackers, sun sensors, gyros, magnetometers.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
00
Parent
SVC:CP:Control Plane:00
Description
The physical attitude sensors: star trackers, sun sensors, gyros, magnetometers.
ASTSoftware00
ETEN nomenclatureAST:SW:Software:00:The flight software that runs the ADCS control algorithms.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
00
Parent
SVC:CP:Control Plane:00
Description
The flight software that runs the ADCS control algorithms.
ASTHardware01
ETEN nomenclatureAST:HW:Hardware:01:The physical power chain: solar arrays, batteries, power distribution.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
01
Parent
SVC:CP:Control Plane:02
Description
The physical power chain: solar arrays, batteries, power distribution.
ASTHardware02
ETEN nomenclatureAST:HW:Hardware:02:The physical FTS receiver and ordnance that carry out termination on valid command.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
02
Parent
SVC:CP:Control Plane:03
Description
The physical FTS receiver and ordnance that carry out termination on valid command.
ASTFirmware00
ETEN nomenclatureAST:FW:Firmware:00:The embedded FTS firmware that interprets safety commands and drives the destruct sequence.
Layer
AST Asset (L4)
Tag
FW
Label
Firmware
Ordinal
00
Parent
SVC:CP:Control Plane:03
Description
The embedded FTS firmware that interprets safety commands and drives the destruct sequence.
ASTHardware03
ETEN nomenclatureAST:HW:Hardware:03:The physical thermal hardware: heaters, radiators, coatings, insulation.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
03
Parent
SVC:CP:Control Plane:04
Description
The physical thermal hardware: heaters, radiators, coatings, insulation.
ASTHardware06
ETEN nomenclatureAST:HW:Hardware:06:The physical on-board computer and OBDH bus on each constellation spacecraft.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
06
Parent
SVC:HY:Hybrid:00
Description
The physical on-board computer and OBDH bus on each constellation spacecraft.
ASTFirmware01
ETEN nomenclatureAST:FW:Firmware:01:The embedded OBC boot firmware, the root of trust that runs first at power-on.
Layer
AST Asset (L4)
Tag
FW
Label
Firmware
Ordinal
01
Parent
SVC:HY:Hybrid:00
Description
The embedded OBC boot firmware, the root of trust that runs first at power-on.
ASTSoftware06
ETEN nomenclatureAST:SW:Software:06:The flight software that executes commands and runs FDIR for C&DH.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
06
Parent
SVC:HY:Hybrid:00
Description
The flight software that executes commands and runs FDIR for C&DH.
ASTHardware07
ETEN nomenclatureAST:HW:Hardware:07:The physical payload electronics that generate and format the mission product.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
07
Parent
SVC:DP:Data Plane:01
Description
The physical payload electronics that generate and format the mission product.
ASTFirmware02
ETEN nomenclatureAST:FW:Firmware:02:The embedded repeater firmware that governs receive, process, and retransmit on the link.
Layer
AST Asset (L4)
Tag
FW
Label
Firmware
Ordinal
02
Parent
SVC:DP:Data Plane:00
Description
The embedded repeater firmware that governs receive, process, and retransmit on the link.
ASTData03
ETEN nomenclatureAST:DA:Data:03:The stored flight keys and certificates the space cryptographic service encrypts and authenticates with.
Layer
AST Asset (L4)
Tag
DA
Label
Data
Ordinal
03
Parent
SVC:CP:Control Plane:01
Reference
CCSDS 355.0-B (SDLS); CCSDS 357.0-B; NIST SP 800-57
Description
The stored flight keys and certificates the space cryptographic service encrypts and authenticates with.

Link segment assets · each parents to a service within SEG:LI:Link:00

ASTSignal00
ETEN nomenclatureAST:SI:Signal:00:The transmitted telecommand uplink waveform that carries commands from ground to spacecraft.
Layer
AST Asset (L4)
Tag
SI
Label
Signal
Ordinal
00
Parent
SVC:HY:Hybrid:01
Description
The transmitted telecommand uplink waveform that carries commands from ground to spacecraft.
ASTData00
ETEN nomenclatureAST:DA:Data:00:The stored link ACA credentials the access-control service checks.
Layer
AST Asset (L4)
Tag
DA
Label
Data
Ordinal
00
Parent
SVC:CP:Control Plane:05
Description
The stored link ACA credentials the access-control service checks.
ASTSoftware01
ETEN nomenclatureAST:SW:Software:01:The software encoder that builds payload telecommand messages before uplink.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
01
Parent
SVC:CP:Control Plane:07
Description
The software encoder that builds payload telecommand messages before uplink.
ASTSoftware05
ETEN nomenclatureAST:SW:Software:05:The flight software that detects hostile command or state manipulation in flight and recovers.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
05
Parent
SVC:CP:Control Plane:06
Reference
NIST IR 8270; Falco et al. 2024
Description
The flight software that detects hostile command or state manipulation in flight and recovers.
ASTSignal01
ETEN nomenclatureAST:SI:Signal:01:The transmitted telemetry and ranging waveform: the modulated downlink signal, its framing, coding, and ranging tones.
Layer
AST Asset (L4)
Tag
SI
Label
Signal
Ordinal
01
Parent
SVC:HY:Hybrid:02
Reference
CCSDS 132.0-B (TM Space Data Link); CCSDS TT&C
Description
The transmitted telemetry and ranging waveform: the modulated downlink signal, its framing, coding, and ranging tones.

Ground segment assets (Reston) · each parents to a service within SEG:GR:Ground:00

ASTSoftware02
ETEN nomenclatureAST:SW:Software:02:The ground software that enforces command acceptance before release to the link (ACA).
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
02
Parent
SVC:CP:Control Plane:09
Description
The ground software that enforces command acceptance before release to the link (ACA).
ASTData01
ETEN nomenclatureAST:DA:Data:01:The stored ACA credentials the ground authentication service relies on.
Layer
AST Asset (L4)
Tag
DA
Label
Data
Ordinal
01
Parent
SVC:CP:Control Plane:09
Description
The stored ACA credentials the ground authentication service relies on.
ASTData02
ETEN nomenclatureAST:DA:Data:02:The stored patch binaries, firmware and software, staged for deployment.
Layer
AST Asset (L4)
Tag
DA
Label
Data
Ordinal
02
Parent
SVC:CP:Control Plane:12
Description
The stored patch binaries, firmware and software, staged for deployment.
ASTSoftware03
ETEN nomenclatureAST:SW:Software:03:The software pipeline that builds, signs, distributes, and installs patches.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
03
Parent
SVC:CP:Control Plane:12
Description
The software pipeline that builds, signs, distributes, and installs patches.
ASTHardware04
ETEN nomenclatureAST:HW:Hardware:04:The physical operator workstation from which telemetry is monitored and commands are issued.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
04
Parent
SVC:CP:Control Plane:13
Description
The physical operator workstation from which telemetry is monitored and commands are issued.
ASTSoftware04
ETEN nomenclatureAST:SW:Software:04:The software C2 application on the operator console, the ground command-and-control suite.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
04
Parent
SVC:CP:Control Plane:13
Description
The software C2 application on the operator console, the ground command-and-control suite.
ASTHardware05
ETEN nomenclatureAST:HW:Hardware:05:The physical ground cryptographic module (HSM) that stores ground keys and performs encryption, decryption, signing, and verification.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
05
Parent
SVC:CP:Control Plane:08
Reference
CCSDS 355.0-B (SDLS); NIST SP 800-57
Description
The physical ground cryptographic module (HSM) that stores ground keys and performs encryption, decryption, signing, and verification.
ASTSoftware07
ETEN nomenclatureAST:SW:Software:07:The software that sequences, conducts, and monitors launch-phase operations.
Layer
AST Asset (L4)
Tag
SW
Label
Software
Ordinal
07
Parent
SVC:CP:Control Plane:10
Reference
NASA-STD-8719.25
Description
The software that sequences, conducts, and monitors launch-phase operations.
ASTFirmware03
ETEN nomenclatureAST:FW:Firmware:03:The embedded flight-safety firmware: the rule set and decision logic that uses vehicle sensors to decide termination without ground command.
Layer
AST Asset (L4)
Tag
FW
Label
Firmware
Ordinal
03
Parent
SVC:CP:Control Plane:11
Reference
NASA AFSS (NTRS); NASA-STD-8719.25
Description
The embedded flight-safety firmware: the rule set and decision logic that uses vehicle sensors to decide termination without ground command.

Ground segment assets (Kiruna) · each parents to a service within SEG:GR:Ground:01

ASTHardware08
ETEN nomenclatureAST:HW:Hardware:08:The physical Kiruna antenna, feed, and low-noise / high-power RF front end.
Layer
AST Asset (L4)
Tag
HW
Label
Hardware
Ordinal
08
Parent
SVC:HY:Hybrid:03
Reference
NIST IR 8401; CCSDS TT&C
Description
The physical Kiruna antenna, feed, and low-noise / high-power RF front end.