CyberWire Daily - Building a secure space internet. [T-Minus: Space-Cyber Briefing]
Episode Date: August 23, 2026As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits ...down with Filip Rezabek, co-founder and CTO of Space Computer, to talk about some of the technologies being created to secure space infrastructure in orbit. The two discuss the importance of establishing a chain of trust in space and the challenges of securing hardware against supply chain attacks. Like what you heard? Be sure to subscribe to our free Signals and Space Briefing, our Sunday newsletter covering the intersection of cybersecurity and space. Subscribe at: https://thecyberwire.com/newsletters/signals-and-space Is there a topic or person you’d like to hear on our show? You can send your questions and feedback to space@n2k.com. You can also fill our our audience survey: https://www.surveymonkey.com/r/NJYCN2P T-Minus: Space-Cyber Briefing is a production of N2K CyberWire. N2K is your nexus for discovery and connection for people, technology, and ideas shaping the future of secure innovation. Learn how at n2k.com.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Social engineering attacks look trustworthy, a routine request, an internal email, a familiar face on a call.
But Dopple sees through the disguise.
Their AI-native platform detects and disrupts attacks across every channel,
trains employees to recognize deepfakes and deception,
and investigates every fish to take down the campaign behind it.
They fight relentlessly to protect you.
your business, brand and people.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's d-O-p-p-e-l.com.
As an example, what we are the current timelines we see on Earth deployments,
we are usually talking about 2009, 2030,
as the part where most of the aspects of the critical infrastructure
will be shifting to post-contemporatography as well.
And if you consider the lifetime of a satellite,
plus the design lead time, sometimes for something,
especially for larger missions, you definitely want to consider a post-comicography as a part of the solution.
Welcome. I'm Maria Vermazes, and you're listening to T-Minus Space Cyber Briefing.
In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure
that powers, protects, and connects our lives.
Hi and welcome, everybody. As I said, at the top of this show,
T-minus is all about learning how people are building and securing orbital and.
infrastructure. Now, usually, I prefer to interview experts who can tell us all about the broad
landscape, some of the specific challenges and opportunities ahead, but sometimes it is also
illuminating to talk directly to the builders, the people who are actually right now building,
future, secure orbital infrastructure, and hear about what they envision and how they're making
it all happen. So in light of that, my interview today is with Philip Rezobach, who is the
CTO and co-founder of Space Computer. His company has the explicit goal of building secure
end-to-end infrastructure for the space internet, as it's often being called, which will work
across both ground and space segments, of course. So to do all that, they are working on a payload
architecture called Space Fabric that enables multi-tenant workloads on a single satellite,
all without requiring the tenants to actually trust each other or even the operator, all using
hardware-backed security. Yeah, it's pretty fascinating stuff, and he will walk us through it.
First, let's hear a bit about Philip.
So, great to be here. My name is Philip Rezabek, and I'm one of the co-pounders of space
computer, and also the CTO, so trying to use my previous experience with building secure systems
currently on achieving what we try to do with space computer, which is to provide secure
infrastructure for these space internet.
As a part of my background, I am currently in the last phase of completing my PhD in the area
of the computing at the Technical University of Munich.
So I'm currently living in Germany, where I originally moved to from Czech Republic, where I was born.
And I had been living here since 2017, doing my master as a typical story and continuing with
staying in academia, but always interested in the industrial application and always keen to bring
the research background basically to industry.
is basically the part where when we were co-founding Space Computer together with my co-founder, Daniel,
was a great mix, basically, of seeing how we can bring both of these flows together
and now being actively building on the activities and expertise I have from the previous activities.
Excellent. Well, thank you so much for joining me, Philip. It's really nice to meet you.
And I was telling you before we were starting to record, when I heard about what your company is doing,
the technology that you all are building, I said that is right on for our show.
show and I really want to learn more about it.
So please tell me about space computer and also space fabric because the story for this
sounds just really fascinating.
So tell me more, please.
Definitely.
So as a company, as a space computer, we have been around for roughly two years.
So we are rather an early stage startup.
And we are bringing to the area of space, which basically both components, which is both
the ground segment and the space segment.
and we are trying to provide a holistic end-to-end system
where the motivation for what we try to see
is that currently, when looking at the space,
we see there is a bit of a friction
with respect to communicating to your spacecraft,
but also at the same time,
the spacecraft is usually built as a purpose-built silo
that is operated by a single party.
Sometimes, of course, you can still have multiple payloads on board,
but usually you don't want to be sharing the payloads
with other people on board,
which of course means that it's naturally bringing
limitation to the scalability of the overall solution.
And as a part of the vision that we want to focus on is to provide the infrastructure,
the trust layer, to enable these space internet infrastructure.
And for that, we want to, of course, have the seamlessness of being able to interoperability,
interoperate with different type of parties, make sure that actually you can do it in a
trust minimized fashion without either trusting the operator, the other users on the payload,
and also make sure that you can have a seamless integration with respect to the ground station,
and other components of the overall end-to-end system.
And as a part of the overall story is the space fabric,
which is the architecture that we envisioned to deploy on the space component,
and it's also accelerated by the Earth ground segment as well,
which is mainly enabled hardware that will be deployed on the spacecraft itself,
which we are currently working on as a part of the payload development.
And this particular payload enables you to run on a single satellite,
your solution, your workloads, your sensitive workloads,
and a multi-tenant solution,
without needing to trust the other parties
that I have access to the same physical infrastructure in space.
And this is basically the part that we see,
like it's very important not to only get the,
so-to-speakal assurances,
but actually you are also getting cryptographic assurance
that your particular system that you are running
is secure and has clearly defined boundaries
between the other users in the system,
and you are getting also lithographic proof as a part of the overall story.
So you can have this end-to-end attestation from the spacecraft all the way, basically,
to consuming the data or any type of other interactions as a user on the Earth as well.
Yeah, okay.
So I'm going to ask if you can give me sort of a comparison to typically how payloads would be run right now,
just so we can contrast with what you all are building just to understand.
So at least the war that we currently see that usually the one payload equals,
to one user.
And the reasoning for that, of course, is the sensitivity.
Sometimes you don't want to have access,
provide access to other parties,
because inherently maybe you are running your sensitive workloads,
your sensitive code that you maybe don't want the other people to have the option to share.
And we basically want to find means on how can you actually share the particle
access to the payload by, to multiple parties,
without the need of trusting any of the other tenants on the same spacecraft.
So this is the way on, which of course can later on unlock
many new use cases as well because of course the barrier to entry later on become lower
and you can basically easily also share the cost for having access to such network infrastructure
and you can do it not only on the let's say as we know for example right share options
or they try to do this on the same space here but having multiple payloads that are not easily
integrated together I don't really communicate to each other we really want to focus on it from
the payload level and of course afterwards also scale it to the other payloads on the same
bus system so to speak as well okay so
something that I was reading that was very important to what you're building is the idea of physically isolated secure elements.
Can you tell me a bit more about what that means here?
Yeah. So as a part of the crucial and core component of the space fabric architecture,
is the reliance on the technology that is called trusted execution environment.
And this technology, it's not something new that we'll say we are bringing it to the table because it has been existing already for some time.
We can see it actually in majority of our phones.
It's also currently being actively pushed by major silicon providers like Intel or AMD.
And Evida as well as a part of their overall story.
And we are relying on this technology to bring it to space.
This technology, however, if you look at the on-earve deployments, have several fundamental issues.
Either is the supply chain, it attacks the route of trust that is usually coming to the respective silicon manufacturer.
Or also what we see is a single point of failure with respect to,
having, for example, only a single reliance on a single route of trust.
And the other part is the physical isolation.
So in case there were recently several academic papers,
the case you have physical access to the silicon that is equidvised technology,
you can actually compromise the respective hardware,
which is, of course, if you consider sensitive computation,
sensitive workload, it's not ideal.
Right.
And with respect to sending these components,
not only the traditional one,
but actually we are trying to enhance them by additional,
challenges that we try to mitigate, such as the supply chain attacks along the way,
we are able to achieve the physical isolation provided once it's deployed in space,
because it's very hard currently.
At least we see, as of now, I think for the short to medium term, it's going to be the case.
It's very hard to go and catch your respective satellite and be able to extract
and physically compromise the respective infrastructure.
So we are relying basically on this aspect of the physical isolation to provide
very good security guarantees with respect to having basically.
basically an error gap system, which is very hard to physically compromise.
Tell me a bit about how the key signing works with your solution.
My understanding is this is a sort of unique angle that you all are using.
Can you tell me a bit about that?
As a part of the process of getting this cryptographic proof,
as I was mentioning over the overall software stack,
that is actually running full in space.
You have to generate your respective keeper.
You have the public key that, of course,
we are running on public key cryptography,
that the public key can be shared to everyone.
You want to, of course, share it to everyone.
But that private key is the sensitive component that you don't want to leak to anyone.
Because, of course, once you leak it, you have a problem.
And as a part of the overall story that we try to, the solution we try to provide,
we want to make sure that at a no point in time, we are actually generating these private keys on Earth before they are being shipped to space.
So once you are actually in space and you have this perfect physical isolation,
we actually have the process in place that will generate the private keys only on board of the security.
elements that are on board of a satellite.
And afterwards, we are using it, for example,
for signing whatever information
the users aim to provide. But also,
for example, we are using it to sign
the information about the software
as well. So, for example, what I mean by that,
you can sign what is the operating system
we are using. And it's only that you are signing it
for the aspect of you
as a owner of the infrastructure, you want to have
the confidence. You can actually create an
other station that can be shared with any
other third party that, hey, this
actually the respective operating system,
I can go and publicly verify this is the respective software stack that I'm interacting with.
So that way it can provide to the user the assurance that they actually can see that this is the
respective system where I'm later on comfortable to, for example, deploy methodative application
as well because you are building the attestation from the ground up from the basic components
of the operating system, the software stack, all the way basically to the application layer as well.
Okay. How different is that from sort of the standard operating procedure right now?
So the main difference with respect to that is that if you look at the standard operating procedure,
you can start your operating system, but you are actually not getting any aspect of the hardware and force attestation.
So maybe you can measure certain aspects of the operating system by software,
but it means that the software itself has to be trusted as well.
It's a little bit like the chicken and egg problem, right, because I am measuring the operating system,
which I have to be trusting.
And since we are shifting the layer of the trust, one layer basically below to the hardware,
we are able to not only attest to the hardware state,
but also to the software state.
Let's take a quick break now.
We'll be back in a few moments with Philip Rezebeck of Space Computer.
And we're back now with my interview with Philip Rezebeck of Space Computer.
As we're talking about hardware,
the question that is for anything related to spaces,
so what happens when we need to upgrade that hardware?
Given how much cryptography is evolving right now,
by the moment seemingly with quantum in the mix.
So how does your solution sort of stand up to that with, you know, again, air-gapped hardware?
Great question.
I think the answer to it is actually we rely on a mix of software and hardware for the upgradeability.
So, for example, what we can do, the secure components we are using also support the transition to post-quant computer photography.
So if you assume that okay, I want to upgrade the firmware that is deployed on the part,
hardware component chip, I actually can go and deploy the particular upgraded
firmware that is of course being signed and it's being verified and so and so forth to
basically provide the guarantees and as a part of the overall story actually the
technology of trust execution environments can also help to ensure the software
you are running is also providing additional isolation on the process level on
the software level between the individual parties. So you can actually also go and
for example have your private key for this post-contum cryptography secure
and ready, you can actually run it
during the runtime because you don't always need to
store it on the chip itself because you are
having this additional runtime security assurances as well.
But overall, we try to make sure that the hardware
that is provided as the fundamental components,
so to speak, has the post-contacted photography readiness path
moving forward, but also we can do additional security
but provide additional security guarantees
on board of the runtime as well.
where we can later on ensure the cryptographic agility as well for the solution as well.
Really glad you mentioned post-quantum.
I feel like that is the phrase that gets mentioned in the same breath as crypto pretty much all the time when we talk in the space realm.
Tell me a bit more about that, please, just looking towards post-Q-day.
Definitely. So what we see is, of course, in the design or space,
will definitely take some time, right?
Even if we start to design the satellite, for example, today, it might take a couple of
years before they materialize and before they're really being deployed.
And of course, by then, we have to already consider that quantum computer might be around.
As an example, what we are the current timelines we see on Earth deployments.
We are usually talking about 2009, 2030, as the part where most of the aspects of the
critically infrastructural will be shifting to post-content cryptography as well.
And if you consider the lifetime of a satellite, plus the design lead time,
sometimes especially for larger missions, you definitely want to consider post-content
of as a part of the solution.
And we end to provide the answer to that by ensuring that actually we already have the
Postcontent cryptographic libraries in place that are currently following mainly the NIST
standardization for both key exchange mechanisms and signing from basically day one.
And we are currently actively developing of also providing this accessibility to the users
that can later on take these libraries and integrate them.
And what does is something that makes us very excited, that these solutions, even though we are a young
startup, we will be actually having a space heritage rather soon with our upcoming commission
later on this year, where we plan to test that all of the aspect of the hardware and the
software stack that I'm currently discussing are actually tested and have flew to space.
So this is something that you are very, very excited about.
I was going to, that was going to be the next thing I was going to ask about.
I'm glad you mentioned it.
I'm curious, what are you hoping to learn from this demo mission?
So I think there will be a lot of components we want to unfold.
So first it will be the first mission that will be actually implementing the space fabric in place.
So this is something that of course is the fundamental buildings that we are relying on.
So we don't want to see that even though space can be quite adversarial due to radiation and temperature and so on,
we can actually do quite deep and sophisticated cryptographic operations on a trusted hardware in space
because this is something that is at least to the best of our knowledge wasn't done in such a fashion.
And we of course want to make sure that all components are surviving the whole mission, of course,
that there will be no bit flips because of course with respect to cryptography, everything
is very sensitive to radiation and others.
So this is basically really just making sure that the hardware software stack is above enough.
And of course, the other part is the whole aspect of the assurance regarding the protocol
we are building on top of that, regarding the communication, the endorsements to be actually
really attesting that the execution is happening in space, and doing also a couple of
POC mission that we are currently finalizing with our partners along the way.
Makes sense.
That is, that's fantastic.
And I'm zooming out a little bit from, you know, what you've been working on lately and
the demo that's coming up.
I imagine you all are incredibly busy right now.
So thank you for taking the time.
I can only begin to imagine.
Given your company's mission, you know, essentially is securing and helping to build out
space internet infrastructure, which is, I mean, just something that is so fascinating.
to me. When I think about, you know, the vision that I've heard from many sectors in the space industry
about what internet and space is going to look like when, you know, interconnected, mesh, you know,
networks, orbital networks, that kind of thing. I'm curious about how what you're building,
how you envision it will scale, especially on a constellation level. What's your vision for that?
Great question. I think there is a lot of things to unfold, so I will try to keep it at least to the core
components. So one part we try to take the parallel and the inspiration from is how internet
on earth has been developed. So it started more as a, let's say, purpose-billity silos, right?
We had like a few labs that have certain activities, then you had more private sector coming
into place, building up their individual components. But eventually, the internet emerged by
defining set of open protocols where everyone who wants to join the internet is able to communicate
in the same fashion and try to find the right matters of obstruction.
so that you can easily integrate all of the complex systems together
into more of a coherent system that is able to communicate to each other
and provide all of the cool services and applications we see nowadays.
So we try to draw a parallel from that and try to do something similar.
So we want to operate heavily in an open source mount.
So that way you actually can have open protocols, open libraries virtually the users can go
and deploy and use them for the communication.
But also we see that the internet itself,
needs some developments.
And we definitely want to also, for example,
consider some of the modern requirements
that we see specially, for example,
against images that are being generated by AI
or information that basically are being very easily tempered with.
And we really want to provide this end-to-end attestation
and data provenance from day one
as a part of the infrastructure we are building.
So kind of thinking on how the development
will be coming forward,
where, of course, providing smooth
operations on open protocols can unlock many interesting use cases for the future, while also
considering security and data provenance as a unique feature.
So that way you can have different parties, easily consuming data, without the need of
trusting all of the individual parties involved in the process.
That's fascinating.
Philip, this has been super neat to hear about.
So thank you so much for taking the time.
And what I can only begin to imagine must be a very busy time for you, Philip.
All the best success to you.
And I look forward to hearing how the demo mission went.
If you're interested, we'll be in the Silicon Valley Space Week later on this year.
So we'll be definitely happy to catch up with some of you during the time.
It's at the end of October.
And in general, if you're interested on what we are building, follow our social media and hit us up looking forward.
Thank you so much. Thank you.
And that's T-minus space cyber briefing brought to you by N2K Cyberwire.
If you like what you heard today, you will also enjoy our newsletter, signals and space.
You'll get research and notes pulled together by our producer Ethan Cook and me.
along with this week's top space cyber news stories.
Subscribe by visiting thecyberwire.com slash newsletters.
As always, we would love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead
in the rapidly changing cybersecurity landscape.
If you like the show, please share a rating and review in your podcast app.
Please also fill out the survey in the show notes
or send an email to space at n2K.com.
We are proud that N2K Cyberwire is part of the daily routine of the most
influential leaders and operators in the public and private sector, from the Fortune 500 to many
of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals
grow, learn, and stay informed. As the next is for discovery and connection, we bring you the
people, technology, and ideas shaping the future of secure innovation. Learn how at n2K.com.
Thank you for listening to T-minus. I am your host, Maria Vermazas. The show is produced by Ethan
Cook and Liz Stokes. We're mixed by Elliot Peltzman and Trey Hester with original music by
Elliot Peltzman. Our executive producer is Jennifer Ibin, with content strategy by Mayan Plout.
Peter Kilfey is our publisher. See you next week.
