Editorial boundary: This public alpha is generated from version-controlled source without third-party application or build packages. It is not the reviewed 1.0 corpus: 60 Academy lessons are substantive editorial drafts, 0 remain foundation outlines, and independent domain review remains open.
Current state
- Space, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance.
- Secure-update patterns, attestation, delay-tolerant networking, formally assessed kernels, software bills of materials, and reproducible-build practices exist in different contexts. Availability does not establish compatibility, flight qualification, century maintenance, or safe integration.
- Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment.
Major unknowns
- Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth.
- Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control.
- Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats.
Failure modes
- A compromised build, spare, model, credential, or maintenance interface crosses isolation boundaries.
- Cryptography, identity, or recovery procedures become obsolete while privileged operators lose the ability to re-establish trust.
Useful precursors
- Secure-by-design operational technology, reproducible builds, signed evidence graphs, and offline recovery media.
- Long-horizon incident exercises that include insider risk, degraded communications, hardware loss, and cryptographic migration.
Decision gate
Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely.
Claim records
- Generation-ship security protects a civilization’s ability to operate, repair, govern, learn, and recover without an external rescuer—not merely its secrets. (normative · early-research · strong; two independent reviewers required for cybersecurity, life-support-continuity, governance; current review: pending-two-person-required)
- Space-sector guidance and protocol-security reports, operational-technology, software-supply-chain, zero-trust, post-quantum, and cyber-resilience standards provide relevant but fragmented reference points; their existence does not establish integration or assurance. (observed · major-scale-up · strong; two independent reviewers required for cybersecurity, spacecraft-safety, dual-use; current review: pending-two-person-required)
- Secure firmware-update patterns, platform recovery, software-component inventories, bundle-layer security for disrupted networking, and a publicly described CCSDS-oriented space-data-link cryptography library exist in different contexts. Availability does not establish compatibility, conformance, flight qualification, safe integration, or century maintenance. (observed · early-research · supported; two independent reviewers required for cybersecurity, software-supply-chain, spacecraft-safety, dual-use; current review: pending-two-person-required)
- Within the public sources sampled for this foundation draft, we did not identify a generation-ship cybersecurity standard or a demonstrated century-scale cryptographic deployment. (observed · no-known-path · supported; two independent reviewers required for cybersecurity, cryptography, spacecraft-safety; current review: pending-two-person-required)
- Trust anchors, identity, secure time, revocation, incident command, threshold recovery, crypto-agile migration, anti-rollback, and archival signature interpretation must work locally after permanent loss of Earth. (normative · early-research · supported; two independent reviewers required for cybersecurity, governance; current review: pending-two-person-required)
- Insiders, collusion, governance capture, compromised suppliers, corrupted hardware, malicious maintenance, radiation faults, operator error, and generational loss of expertise must be addressed without turning safety monitoring into surveillance or political control. (normative · early-research · supported; two independent reviewers required for cybersecurity, governance, privacy, human-rights, life-support-continuity; current review: pending-two-person-required)
- Onboard manufacturing makes malicious designs, poisoned toolchains, compromised metrology, counterfeit replacement parts, and configuration drift cyber-physical threats. (modeled · early-research · supported; two independent reviewers required for cybersecurity, supply-chain, spacecraft-safety; current review: pending-two-person-required)
- Disconnected trust fabrics, update airlocks, recovery vaults, and cyber ranges benefit critical infrastructure and remote industry. (proposed · early-research · tentative; two independent reviewers required for cybersecurity, critical-infrastructure, dual-use; current review: pending-two-person-required)
- Crypto agility and toolchain escrow reduce obsolescence risk in medical, energy, transport, and public systems. (proposed · major-scale-up · supported; two independent reviewers required for cybersecurity, critical-infrastructure, software-supply-chain; current review: pending-two-person-required)
- Mixed crews must repeatedly isolate a compromised zone, maintain life support, investigate locally, rebuild from known-good material, and rejoin safely. (normative · early-research · supported; two independent reviewers required for cybersecurity, spacecraft-safety, life-support-continuity, governance, dual-use; current review: pending-two-person-required)
Context sources—not claim citations
Foundation system synthesis · Linked claims editorially assessed · Independent system review pending · Suggest a correction