Modernization of crypto isn’t the core mission for DoD and the IC, it’s what enables the mission – Breaking Defense
Image courtesy of General Dynamics Mission Systems.
In this Q&A with Brian Morrison, Cyber Systems vice president and general manager for General Dynamics Mission Systems, we discuss cost-effective strategies for crypto mod, how Layer 2 encryption will enable missions such as the Joint Warfighting Cloud Capability, and how organizations can keep cryptographic systems compliant with NSA requirements.
Breaking Defense: Lets set the scene. What is the steady state right now in cryptographic solutions? Where is modernization needed?
Brian Morrison, Cyber Systems vice president and general manager for General Dynamics Mission Systems.
Morrison: At a threshold level, NSA is the standard-setting organization and the certifier for all cryptographic equipment across the National Security Enterprise. Its fair to say that crypto modernization for NSA has always been viewed as a continuous process.
That is to say, you and I have email accounts that we originally set up with a strong password. But since then, maybe we used that password on other accounts, or there was a penetration somewhere, or compute power has increased such that password crackers are more capable today. So what was once a strong password ends up being a really weak one and a vulnerability.
Thats an oversimplification, but whats true for passwords is true for crypto gear. You can build the strongest crypto gear that exists but over time the security of that device, of the algorithms that underlie that device, of the protections that are wrapped around that device, all erode over time. Our adversaries get better at doing what they do. And were seeing new, persistent attacks due to network vulnerabilities.
Under the leadership of the NSA, we, as a National Security Enterprise, must continually refresh our crypto gear. That means discreet gates for Advanced Cryptographic Capability prescribed by NSA. It also means continuing to patch, maintain, and update all of our gear over time. And then at certain points in time, NSA says a particular family of cryptographic gear has to come offline because it has aged out; it cant be secure anymore.
Thats the way I look at crypto modernization: from new crypto boxes to upgrading existing crypto boxes, to removing legacy crypto boxes from a network. All of that is the process of crypto mod. Our reason for being at General Dynamics Mission Systems is to make sure that our customers and the national security establishment have the most secure crypto that American ingenuity can provide.
Breaking Defense: How should organizations approach crypto mod? Is it akin to a software patch or a new iOS update that downloads in the background while were asleep?
Morrison: I wish it were that easy. There are two aspects. One is we know, without speaking to crypto gear specifically, that the overwhelming majority of cyber-security penetrations happen because somebody has not patched and updated, or they have been phished.
Our customers operate in vast networks, widely dispersed networks, high-latency networks, and in tactical, DIL (disconnected, intermittent, limited) environments. Its very difficult for those networks with many pieces of gear to stay patched and updated all the time. At General Dynamics Mission Systems, we have what we call the GEM One Encryptor Manager, which is a software package that manages and updates all of the Type 1 crypto in the enterprise, including crypto devices made by other manufacturers. Remote management improves the health of the network and eases maintenance.
The second part of the problem is that our customers have thousands and thousands of cryptographic units in their inventory. The ongoing process of crypto mod, including the periodic deadlines that the NSA rightfully imposes, is difficult to manage from both a budgetary and a logistics perspective.
So were encouraging our customers to think proactively about what their needs are going to be for crypto in 6, 12, 18, 24, 36 months out. That helps them plan from a budget perspective so that we are able to plan from a manufacturing-capacity perspective so that when the time comes to switch out boxes, theyve got the budget for it and were ready to satisfy their demand on time and within their budget. Thats easy to say and hard to do because theyre substantial investments. At the same time, theyre investments in the security of the most important secrets the nation has.
Breaking Defense: Is crypto mod more of a hardware or a software modification, or both?
Morrison: When we talk about crypto mod, were normally talking about updates to the hardware. But there are major software updates that we can do to provide compliance with crypto mod gates from the NSA. For example, our TACLANE-FLEX, TACLANE-10G, TACLANE-Nano, TACLANE-Micro, and Sectra vIPer phones have all been software upgraded to the NSAs Advanced Cryptographic Capabilities standard of modernization.
Breaking Defense: What is involved in keeping data-protection solutions up to date. Im assuming were talking about NSA requirements and certifications.
Morrison: Yes, the NSA is the certification authority for Type 1 crypto. If you want to pass classified information across the network, youve got to do it over a piece of crypto that the NSA has certified. For the vendors and programs that develop new crypto, that certification process is every bit as rigorous, complicated, and demanding as you would imagine. And, frankly, as rigorous as you would hope as these are high-stakes networks. For the missions that consume the crypto, the fact that NSA has certified the encryptor makes the long-term management of the crypto infinitely simpler and more stable.
Today, the NSA is in the midst of introducing a new specification for what we call Layer 2 encryption. This is a new standard for encryption at a different network layer that is intended to deliver much higher speeds over the next few years. Were very much a part of that effort and have made significant investments in delivering some mind-boggling speeds.
Breaking Defense: Speeds for what exactly?
Morrison: For the defense and intelligence establishments migration to the cloud. With defense networks operating in cloud environments, you have data center to data center transfers that have to happen at a very high rate of speed because those data center to data center transfers are aggregated traffic.
These transfers must be as bandwidth efficient as possible while keeping high security standards. When you move to Layer 2, you open up the possibility of much higher speeds at any given compute power. At the same time, we are pushing the boundaries of what compute power is available. Were always looking for more compute power to deliver higher and higher speeds.
As we address the data center market for government data centers, we need to be able to deliver speeds that there isnt even a market for today, but we know there will be tomorrow.
Breaking Defense: It almost sounds like the future of cloud computing in the DoD, particularly the Joint Warfighting Cloud Capability, is dependent on Layer 2 encryption. Is that an oversimplification?
Morrison: I dont think it is. The cloud providers likely can, with their existing or soon-contemplated infrastructure, handle what is already within the boundaries of their clouds. But as we know, defense customers are going to require hybrid clouds. Theyre going to require data transitioning from cloud to cloud, and thats where we really need those higher speeds.
Breaking Defense: What do you see as hindrances to proper crypto modernization?
Morrison: Im always sympathetic to the fact that the business Im in, the crypto business, is often perceived by some of our customers as an unfunded mandate. Its a real challenge.
That often stands in the way, even though nobody wants their systems to not be secure. Their number one concern is the life of their soldiers, sailors, airmen, and Marines. That necessitates the security of national security information traveling across their networks. But for many missions, crypto is not the core mission, its the thing that enables the mission.
As new requirements come online and as standards for crypto mod continue to evolve, tactical units might want to upgrade their crypto but just dont have the budget or logistics bandwidth. In response to that, we have added more remote management features to ease the logistics burden of crypto mod. And a couple of years ago, we introduced the smallest, lightest, least expensive Type 1 crypto in its class the TACLANE-Nano which brought affordable crypto to the tactical market.
Breaking Defense: Your point about crypto enabling the mission and not being the mission is well taken. Can you offer a scenario where TACLANE-Nano is particularly valuable to a warfighter and also an affordable and effective crypto solution?
Morrison: Sure. The last decade or more has seen a large increase in the use of unmanned and unattended systems. The nice thing about the TACLANE-Nano is that it is at a price point where you can put it on an unmanned or unattended system, insert it into your adversarys territory, for example, and not worry if it is lost or you lose connectivity; you can remotely zeroize that device. That means that if the cryptographic unit falls into the hands of our adversaries, it cant be used against us.
You cant do that with a big, heavy piece of crypto or one that costs $60,000 because thats not the way those types of unmanned missions run by and large. Were talking about much smaller, lighter airframes. We dont think of those classes of UAVs as attritable, but it may be approaching the attritable market.
Breaking Defense: Final thoughts?
Morrison: Any customer in the national security space has to be thinking about, worrying about, and planning for crypto mod. It is not something that any of us can ignore and then play catch up later on. The planning and logistics behind replacing legacy gear and modernizing a network cryptographic solution is complicated and long tailed.
Thats what General Dynamics Mission Systems is all about. We are a leader in crypto mod and are ready for both todays gates and tomorrows gates from the NSA. Our goal is to partner with our customers, help them understand and implement their modernization needs, and ensure their networks and communications are as secure as anyone can keep them.
- US NSA lauds Ajit Doval for pivoting ties to advanced future tech - The Times of India - January 9th, 2025 [January 9th, 2025]
- Auto insurtech Clearcover expands into Texas NSA market with CGA launch - Re-Insurance.com - January 9th, 2025 [January 9th, 2025]
- "Cannot Think Of A Better Way To End My Tenure": US NSA On His India Visit - NDTV - January 9th, 2025 [January 9th, 2025]
- Heightened Security At U.S. Naval Academy And NSA Annapolis: Public Access Suspended Amid Increased Force Protection Measures - Bay Net - January 9th, 2025 [January 9th, 2025]
- From The Seabed To The Stars: 10 Takeaways From U.S. NSA Sullivans Visit - Strategic News Global - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan to visit India to finalise important ongoing initiatives: White House - The Hindu - January 9th, 2025 [January 9th, 2025]
- What NSA Jake Sullivans India Visit Signals For Nuclear And Tech Ties As US Lifts Curbs On Indian Entities - Swarajya - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan arrives today, seeks to strengthen AI, space, tech ties - The Tribune India - January 9th, 2025 [January 9th, 2025]
- CISA, NSA, and Partners Issue Annual Report on Top Exploited Vulnerabilities - HSToday - December 5th, 2024 [December 5th, 2024]
- Where Will The Top Amateurs at NSA Yamaha Land After the Team Closes? - Vurbmoto - December 5th, 2024 [December 5th, 2024]
- CISA, NSA, FBI and International Partners Publish Guide for Protecting Communications Infrastructure - HSToday - December 5th, 2024 [December 5th, 2024]
- Main players backing Syrian government have been weakened by other conflicts, NSA Sullivan says - NBC News - December 5th, 2024 [December 5th, 2024]
- Trump's incoming NSA Mike Waltz wants US to dance cheek-to-check with India - The Times of India - November 14th, 2024 [November 14th, 2024]
- What Trump's NSA Nominee Said On India's Pivotal Role In The 21st Century - NDTV - November 14th, 2024 [November 14th, 2024]
- Exclusive: Nakasone on exploding pagers, life after the NSA and another possible government job - The Record from Recorded Future News - November 14th, 2024 [November 14th, 2024]
- FBI, CISA, and NSA reveal most exploited vulnerabilities of 2023 - BleepingComputer - November 14th, 2024 [November 14th, 2024]
- CISA, NSA, and Partners Issue Annual Report on Top Exploited Vulnerabilities - National Security Agency - November 14th, 2024 [November 14th, 2024]
- 6 Principles of Operational Technology Cybersecurity released by joint NSA initiative - Security Intelligence - November 14th, 2024 [November 14th, 2024]
- It's official FBI, CISA, and NSA reveal the most exploited vulnerabilities of 2023 - TechRadar - November 14th, 2024 [November 14th, 2024]
- Donald Trump picks Mike Waltz as US NSA: What it means for China and India - The Times of India - November 14th, 2024 [November 14th, 2024]
- Who is Mike Waltz, Donald Trump's new NSA pick? What are his ties to India Caucus? - Firstpost - November 14th, 2024 [November 14th, 2024]
- NSA should not oversee the management of national facilities RexDanquah - Citi Sports Online - November 14th, 2024 [November 14th, 2024]
- Trudeaus NSA admits to leaking secret intel alleging Indias interference to Washington Post - Firstpost - October 31st, 2024 [October 31st, 2024]
- White House dials NSA Ajit Doval: Here's what happened in the call - The Economic Times - October 31st, 2024 [October 31st, 2024]
- NSA Doval Stresses Need For Stable Indo-Pacific In Phone Call With US Counterpart Sullivan - News18 - October 31st, 2024 [October 31st, 2024]
- Director-General of NSA calls for continued support from government - GhanaWeb - October 21st, 2024 [October 21st, 2024]
- 5G Non Standalone Nsa Architecture Market to Reach USD 240.0 - openPR - October 21st, 2024 [October 21st, 2024]
- NSA meets with Minister Muir and DAERA to discuss industry concerns - Meat Management - October 21st, 2024 [October 21st, 2024]
- NSA cyber chief: Espionage is now Russias focus for cyberattacks on Ukraine - The Record from Recorded Future News - October 11th, 2024 [October 11th, 2024]
- NSA Investigating If Chinese Hackers Breached US Telecoms - Yahoo Finance - October 11th, 2024 [October 11th, 2024]
- NSA Issues Updated Guidance on Russian SVR Cyber Operations - National Security Agency - October 11th, 2024 [October 11th, 2024]
- News - Honoring the Stars and Stripes: NSA Philadelphia Hosts Dignified Flag Disposal Ceremony - DVIDS - October 11th, 2024 [October 11th, 2024]
- NSA's Program for Nursing Mothers in the Workplace Considered a Model for USG - National Security Agency - October 11th, 2024 [October 11th, 2024]
- NSA investigating hack of three major telecommunications companies - Baltimore Sun - October 11th, 2024 [October 11th, 2024]
- Honoring the Stars and Stripes: NSA Philadelphia Hosts Dignified Flag Disposal Ceremony [Image 8 of 8] - DVIDS - October 11th, 2024 [October 11th, 2024]
- NSA Hiring Over a Thousand in the Next Year - ClearanceJobs - October 4th, 2024 [October 4th, 2024]
- What Its Really Like to Work at NSA - National Security Agency - October 4th, 2024 [October 4th, 2024]
- US Elections: Former NSA John Bolton Claims Both Harris And Trump Do Not Qualify To Be President | NewsX Exclusive - NewsX - October 4th, 2024 [October 4th, 2024]
- Honoring the fallen: Bells toll for Americas heroes at NSA Mechanicsburg - American Military News - October 4th, 2024 [October 4th, 2024]
- How often should you turn off your phone? Heres what the NSA says - PCWorld - October 4th, 2024 [October 4th, 2024]
- NSA and Allies Issue Advisory about PRC-Linked Actors and Botnet Operations - HSToday - September 28th, 2024 [September 28th, 2024]
- NSA warns that Active Directory is an "exceptionally large and difficult to defend" attack surface - The Stack - September 28th, 2024 [September 28th, 2024]
- News - Honoring the Fallen: Bells Toll for Americas Heroes at NSA Mechanicsburg - DVIDS - September 28th, 2024 [September 28th, 2024]
- National Storage Affiliates Trust (NYSE:NSA) Given Average Recommendation of "Reduce" by Brokerages - MarketBeat - September 28th, 2024 [September 28th, 2024]
- Lack of Standard Stadiums: NSA boss sacked, facilities closed - What has been said and done so far - GhanaWeb - September 21st, 2024 [September 21st, 2024]
- NSA and Allies Issue Advisory about PRC-Linked Actors and Botnet Operations - National Security Agency - September 21st, 2024 [September 21st, 2024]
- UTEP Establishes Collaboration with DoD, NSA to Help Enhance U.S. Semiconductor Workforce - The University of Texas at El Paso - September 21st, 2024 [September 21st, 2024]
- The NSA advises you to turn off your phone once a week - here's why - ZDNet - September 21st, 2024 [September 21st, 2024]
- NSA Publishes Cyber Advisory on China-Linked Threat Actors - Executive Gov - September 21st, 2024 [September 21st, 2024]
- Former NSA Director Nakasone opens new institute at Vanderbilt to train right type of leader - Washington Times - September 21st, 2024 [September 21st, 2024]
- ACR lauds legislation that would fine insurers for delayed NSA payments - AuntMinnie - September 16th, 2024 [September 16th, 2024]
- NSA threatens lawsuit over election rigging allegation, demands apology - Pulse Nigeria - September 16th, 2024 [September 16th, 2024]
- NSA explains its work with private sector on election security and fighting foreign cyber threats - Washington Times - September 16th, 2024 [September 16th, 2024]
- NSA to debut podcast to boost public awareness of classified missions - Nextgov/FCW - August 31st, 2024 [August 31st, 2024]
- In Beijing, Bidens NSA Calls Out Chinas Destablising Actions, Openly Supports Philippines - Hindustan Times - August 31st, 2024 [August 31st, 2024]
- Why the NSA advises you to turn off your phone once a week - ZDNet - August 31st, 2024 [August 31st, 2024]
- Getting into rhythm: NSA places high expectations on themselves for 2024 - Suffolk News-Herald - August 31st, 2024 [August 31st, 2024]
- NSA readying podcast to share untold stories of codebreakers missions - Washington Times - August 31st, 2024 [August 31st, 2024]
- Trump govt stopped aid to Pakistan over ISI's 'undeniable complicity' with terrorists: Ex-US NSA - Hindustan Times - August 31st, 2024 [August 31st, 2024]
- Top NSA researcher tapped to lead Pentagons UAP investigation hub - DefenseScoop - August 27th, 2024 [August 27th, 2024]
- NSA Releases Guide to Combat Living Off the Land Attacks - Infosecurity Magazine - August 27th, 2024 [August 27th, 2024]
- With a little help from the National Archives, NSA finally releases Grace Hopper lecture. Watch it here. - MuckRock - August 27th, 2024 [August 27th, 2024]
- Trump administration NSA H.R. McMaster says there was "inconsistency" in foreign policy - CBS News - August 25th, 2024 [August 25th, 2024]
- 'Putin exploited Trump's ego and insecurities': Former NSA in new book - The Times of India - August 25th, 2024 [August 25th, 2024]
- NSA calls for urgent Government action on illegal sheep imports - Meat Management - August 14th, 2024 [August 14th, 2024]
- Sheikh Hasina Resignation LIVE Updates: Ex Bangladesh PM Sheikh Hasina Meets NSA Ajit Doval At Hindon Airbase - NDTV - August 5th, 2024 [August 5th, 2024]
- NSA Claims It Cant Watch an Important Tape It Recorded in the 1980s - Gizmodo - July 17th, 2024 [July 17th, 2024]
- Letter to NSA Sullivan Requesting Assessment of Information Russia Has Shared with the PRC on U.S. Weapons Capabilities in Ukraine - Select Committee... - July 17th, 2024 [July 17th, 2024]
- The NSA Is Defeated By A 1950s Tape Recorder. Can You Help Them? - Hackaday - July 17th, 2024 [July 17th, 2024]
- Letter to NSA on Microsoft's Billion Dollar Partnership with UAE Firm G42 - Select Committee on the CCP | - July 17th, 2024 [July 17th, 2024]
- NSA Fast Pitch World Series kicks off with Skills Competition & Heavy Hitters Camp, featuring College World Series Champions from the University... - July 17th, 2024 [July 17th, 2024]
- NSA contractor bilked government for hundreds of hours she never worked - Washington Times - July 6th, 2024 [July 6th, 2024]
- Signals intelligence has become a cyber-activity - The Economist - July 6th, 2024 [July 6th, 2024]
- OpenAI adds former NSA chief to its board - CNBC - June 15th, 2024 [June 15th, 2024]
- Former head of NSA joins OpenAI board - The Verge - June 15th, 2024 [June 15th, 2024]
- Former NSA Head Joins OpenAI Board and Safety Committee - RetailWire - June 15th, 2024 [June 15th, 2024]
- Former NSA head joins OpenAI board and safety committee - TechCrunch - June 15th, 2024 [June 15th, 2024]
- OpenAI Appoints Cybersecurity Expert And Retired US Army Genera With NSA Pedigree To Board, Enhancing AI ... - Benzinga - June 15th, 2024 [June 15th, 2024]
- Former NSA head Paul Nakasone to helm national security institute at Vanderbilt - The Record from Recorded Future News - May 15th, 2024 [May 15th, 2024]
- US is still chasing down pieces of Chinese hacking operation, NSA official says - The Record from Recorded Future News - March 18th, 2024 [March 18th, 2024]