This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Tempest (project) | |
|---|---|
![]() | |
| Name | Tempest |
Tempest (project) Tempest is an electronic emissions surveillance and shielding initiative that addresses unintentional signals from Enigma machine, Colossus computer, Bletchley Park, British Intelligence, MI5, MI6, GCHQ. It encompasses standards, countermeasures, testing protocols, and hardware practices used by actors such as National Security Agency, Central Intelligence Agency, Federal Bureau of Investigation, Department of Defense, Lockheed Martin, Northrop Grumman to protect sensitive information in computational and communications systems. The project interrelates with historical signals intelligence programs and modern cybersecurity operational doctrines in allied states including United Kingdom, United States, Canada, Australia.
Tempest focuses on compromising emanations—unintended electromagnetic, acoustic, and optical signals—from electronic equipment and the countermeasures designed to reduce such vulnerabilities. It formalizes testing methods, emission limits, shielding techniques, and evaluation criteria used in procurement and accreditation processes by agencies like National Institute of Standards and Technology, Defense Advanced Research Projects Agency, European Commission, NATO and corporations such as Raytheon Technologies. The initiative is relevant to platforms ranging from tactical radios used by Royal Air Force and United States Air Force to industrial control systems deployed by Siemens and Schneider Electric.
Origins trace to mid-20th-century signals intelligence breakthroughs at sites including Bletchley Park and operations by MI5 and MI6, which recognized that electromechanical devices emitted exploitable signatures. During the Cold War, agencies like KGB, Stasi, GRU and NSA expanded research into electromagnetic intelligence exploiting emissions from terminals and printers used by institutions such as United Nations and European Parliament. Standards development accelerated with contributions from Bell Labs, IBM, Hewlett-Packard, and academics at Massachusetts Institute of Technology, Stanford University, Imperial College London leading to formalized criteria later codified by bodies including IEEE, International Electrotechnical Commission, Underwriters Laboratories.
Milestones include laboratory techniques adapted from work at Lawrence Livermore National Laboratory and field-testing protocols influenced by electronic warfare lessons learned from conflicts like the Falklands War and Gulf War. Commercialization and industrial adoption rose with threats documented in reports from Congressional Research Service and memoranda by Office of the Director of National Intelligence.
The project specifies technical elements such as shielding enclosures, filtered power entry modules, grounded cabling, waveguides beyond cutoff, and Faraday cages constructed per guidelines from National Physical Laboratory and NIST. Hardware components include shielded displays, encrypted signal processors, TEMPEST-hardened power supplies, and fiber-optic interfaces developed by vendors like Corning Incorporated and Finisar. Testing infrastructure comprises anechoic chambers, spectrum analyzers from Keysight Technologies and Rohde & Schwarz, near-field probes, and automated measurement suites used in laboratories at institutions including Lawrence Berkeley National Laboratory.
Protocols integrate with secure architectures from Microsoft, Red Hat, Oracle Corporation and employ formal methods influenced by research at Carnegie Mellon University and ETH Zurich. Standards alignment uses frameworks from ISO, IEC, IEEE and compliance guidance by NIST and National Cyber Security Centre. Certification processes are performed by accredited labs affiliated with Underwriters Laboratories and national test centers such as Government Communications Headquarters in the United Kingdom.
Tempest mitigations intersect with operational security doctrines articulated by NATO, DHS, Secret Service, CIA and privacy regimes in jurisdictions governed by laws like General Data Protection Regulation and Freedom of Information Act. Balancing emission security with interoperability raises tensions managed by procurement offices in Pentagon and executive agencies including Homeland Security. Insider threats, supply-chain risks involving suppliers such as Foxconn and foreign investment concerns involving firms from People's Republic of China prompt regulatory scrutiny by bodies like Committee on Foreign Investment in the United States.
Adversarial capabilities exemplified by research from universities like University of Cambridge and Technische Universität München demonstrated exfiltration vectors using acoustic, optical, and electromagnetic side channels, prompting mitigation strategies incorporated into accreditation by NSA and operational doctrine in US Cyber Command.
Primary use cases include protection of processing systems in embassies of United Kingdom Foreign Office, United States Department of State consular facilities, and command centers of NATO and United Nations peacekeeping operations. Financial institutions such as Goldman Sachs and JPMorgan Chase and critical infrastructure operators like Exelon and National Grid plc adopt hardened equipment to mitigate risks to transactional and supervisory control and data acquisition assets. Scientific facilities including CERN and defense contractors like BAE Systems employ Tempest-aligned practices for classified research and design. Telecom carriers such as AT&T and Vodafone incorporate aspects into secure site designs.
Adoption often follows threat assessments produced by agencies including NSA, NCSC, CERT-EU and national security directives issued by heads of state in United States and United Kingdom. Procurement requirements embed certification prerequisites for suppliers including HP Enterprise and Dell Technologies. International cooperation in adoption occurs through forums like Five Eyes and standardization efforts at ISO/IEC JTC 1 working groups. Testing and accreditation are provided by laboratories in national metrology institutes such as NPL and PTB.
Critics from civil liberties organizations such as Electronic Frontier Foundation and think tanks like Brookings Institution argue that stringent emission controls can impede transparency in public-sector procurement and burden small suppliers including SMEs in Silicon Valley and Cambridge. Industry voices at trade groups like CTIA and TechUK note cost, interoperability, and innovation constraints tied to certification. Allegations of classification and secrecy practices have provoked debate in legislatures such as United States Congress and Parliament of the United Kingdom over oversight, while security researchers at institutions like University of California, Berkeley have highlighted residual vulnerabilities and research ethics concerns.
Category:Emissions security