Secure communication is often discussed as if it were a single technology.
In reality, it is an architectural discipline.
Encryption is important, but it is only one part of the trust model. A communication system also depends on identity, authentication, key management, certificates, software integrity, monitoring, logging, access control, operational procedures and the ability to recover when something goes wrong.
If these elements are treated as separate afterthoughts, the result is usually complexity. If they are designed together from the beginning, security becomes easier to manage, test and maintain.
This is the principle behind secure by design.
For space research, the principle is particularly important. Research environments often connect multiple organisations, specialised systems, distributed infrastructure and long-lived data. Communication may take place across partner networks, cloud services, ground systems, laboratories and operational platforms. In such an environment, trust cannot rely on informal assumptions.
It must be engineered.
Start with what needs to be protected
A secure-by-design approach starts with a clear understanding of what needs to be protected. Not every communication path has the same risk profile. Some channels carry public information. Others may carry sensitive research data, operational details, technical documentation, authentication material or long-term strategic knowledge.
Before designing the technical controls, organisations need to understand the value of the information, who needs access to it, how long it must remain protected and what could happen if confidentiality, integrity or availability were compromised.
This risk understanding should shape the architecture.
Identity and authentication
Identity is one of the first foundations. A system must know which users, services, devices and organisations it is communicating with. Weak identity controls can undermine even strong encryption, because a protected channel is only useful if the parties at each end can be trusted.
Authentication must therefore be robust, consistent and appropriate for the environment. In multi-partner research settings, this may involve federated identity, certificate-based authentication, hardware-backed credentials or carefully governed access models.
Key management
The next foundation is key management.
Cryptographic keys are at the heart of secure communication. If they are poorly generated, stored, rotated or revoked, the security of the system can fail even when the underlying algorithms are strong. Secure-by-design systems need clear key-management processes from the start, including ownership, lifecycle management, access controls and recovery procedures.
This becomes even more important in the context of post-quantum security. As organisations prepare for new cryptographic standards, they will need systems that can support change without losing operational stability. Key management cannot be an improvised layer added late in deployment. It must be part of the design.
Protocols and crypto-agility
Protocol choices also matter.
Secure communication depends on using well-understood, properly implemented and maintainable protocols. Custom or poorly documented mechanisms can create hidden risk. In long-life systems, protocol decisions should also consider future upgrade paths. A design that is secure today but impossible to update tomorrow may become a liability.
This is where secure by design connects directly with crypto-agility.
A secure system should not assume that today’s cryptographic choices will remain sufficient forever. It should allow algorithms, certificates, keys and configurations to be updated in a controlled way. This is especially relevant for space research environments, where systems may remain in use for years and where disruption can be costly.
Monitoring, logging and resilience
Monitoring and logging are another essential part of trusted communication.
Security is not only about preventing incidents. It is also about detecting unusual behaviour, understanding what happened and responding effectively. Communication systems should provide the visibility needed to identify anomalies, investigate events and support accountability across the environment.
In collaborative research settings, this visibility must be handled carefully. Logging should support security and auditability without creating unnecessary exposure of sensitive information. The design should define what is logged, who can access it, how long it is retained and how it is protected.
Resilience must also be considered early.
A secure communication system should be able to handle failure, degradation and recovery. This includes backup communication paths, certificate renewal processes, key-rotation procedures, incident response workflows and continuity planning. If these mechanisms are missing, even a technically secure system can become fragile in real operational conditions.
Supply chain and governance
Supply-chain dependencies are another reason why secure by design matters.
Modern communication environments rarely consist of one self-contained system. They include software components, hardware platforms, cloud services, network equipment, identity providers, certificate authorities and external suppliers. Each dependency can influence the overall trust model.
A secure-by-design approach therefore needs to include supplier assessment, update mechanisms, vulnerability management and contractual requirements for security maintenance. This is particularly important where systems are expected to operate over a long lifecycle.
For space research, the organisational dimension is just as important as the technical one.
Security decisions must be owned. Responsibilities should be clear. Architecture choices should be documented. Change management should be controlled. Partners should understand shared assumptions. Without governance, even good technical controls can become inconsistent over time.
Secure by design is not about making systems complicated. It is about avoiding uncontrolled complexity later.
When security is included from the beginning, the architecture can be cleaner. Controls can be aligned with real risks. Operational teams can understand what they are managing. Future upgrades can be planned rather than improvised. Partners can collaborate with clearer trust boundaries.
The COSMOS-SECURE perspective
COSMOS-SECURE is focused on secure communication in space research with this perspective in mind.
The project recognises that trusted communication is not delivered by encryption alone. It requires an architecture that brings together cryptographic protection, identity, key management, resilience, operational visibility and long-term adaptability.
This is especially relevant as organisations prepare for the post-quantum transition. Future-ready communication systems must be able to protect against current threats while remaining capable of evolving as cryptographic standards and security requirements change.
For organisations involved in space research, secure by design should become a baseline expectation.
Start by identifying the communication paths that matter most. Define the trust model. Build strong identity and key-management foundations. Choose protocols with maintainability in mind. Design for monitoring and recovery. Assess supplier dependencies. And ensure that governance is in place from the beginning.
Security added late is often expensive, incomplete and difficult to operate.
Security designed early becomes part of the system’s strength.
For COSMOS-SECURE, this is the direction of travel: communication systems for space research should be trusted by design, resilient in operation and ready for the future.