Modernization of crypto isn’t the core mission for DoD and the IC, it’s what enables the mission – Breaking Defense
Image courtesy of General Dynamics Mission Systems.
In this Q&A with Brian Morrison, Cyber Systems vice president and general manager for General Dynamics Mission Systems, we discuss cost-effective strategies for crypto mod, how Layer 2 encryption will enable missions such as the Joint Warfighting Cloud Capability, and how organizations can keep cryptographic systems compliant with NSA requirements.
Breaking Defense: Lets set the scene. What is the steady state right now in cryptographic solutions? Where is modernization needed?
Brian Morrison, Cyber Systems vice president and general manager for General Dynamics Mission Systems.
Morrison: At a threshold level, NSA is the standard-setting organization and the certifier for all cryptographic equipment across the National Security Enterprise. Its fair to say that crypto modernization for NSA has always been viewed as a continuous process.
That is to say, you and I have email accounts that we originally set up with a strong password. But since then, maybe we used that password on other accounts, or there was a penetration somewhere, or compute power has increased such that password crackers are more capable today. So what was once a strong password ends up being a really weak one and a vulnerability.
Thats an oversimplification, but whats true for passwords is true for crypto gear. You can build the strongest crypto gear that exists but over time the security of that device, of the algorithms that underlie that device, of the protections that are wrapped around that device, all erode over time. Our adversaries get better at doing what they do. And were seeing new, persistent attacks due to network vulnerabilities.
Under the leadership of the NSA, we, as a National Security Enterprise, must continually refresh our crypto gear. That means discreet gates for Advanced Cryptographic Capability prescribed by NSA. It also means continuing to patch, maintain, and update all of our gear over time. And then at certain points in time, NSA says a particular family of cryptographic gear has to come offline because it has aged out; it cant be secure anymore.
Thats the way I look at crypto modernization: from new crypto boxes to upgrading existing crypto boxes, to removing legacy crypto boxes from a network. All of that is the process of crypto mod. Our reason for being at General Dynamics Mission Systems is to make sure that our customers and the national security establishment have the most secure crypto that American ingenuity can provide.
Breaking Defense: How should organizations approach crypto mod? Is it akin to a software patch or a new iOS update that downloads in the background while were asleep?
Morrison: I wish it were that easy. There are two aspects. One is we know, without speaking to crypto gear specifically, that the overwhelming majority of cyber-security penetrations happen because somebody has not patched and updated, or they have been phished.
Our customers operate in vast networks, widely dispersed networks, high-latency networks, and in tactical, DIL (disconnected, intermittent, limited) environments. Its very difficult for those networks with many pieces of gear to stay patched and updated all the time. At General Dynamics Mission Systems, we have what we call the GEM One Encryptor Manager, which is a software package that manages and updates all of the Type 1 crypto in the enterprise, including crypto devices made by other manufacturers. Remote management improves the health of the network and eases maintenance.
The second part of the problem is that our customers have thousands and thousands of cryptographic units in their inventory. The ongoing process of crypto mod, including the periodic deadlines that the NSA rightfully imposes, is difficult to manage from both a budgetary and a logistics perspective.
So were encouraging our customers to think proactively about what their needs are going to be for crypto in 6, 12, 18, 24, 36 months out. That helps them plan from a budget perspective so that we are able to plan from a manufacturing-capacity perspective so that when the time comes to switch out boxes, theyve got the budget for it and were ready to satisfy their demand on time and within their budget. Thats easy to say and hard to do because theyre substantial investments. At the same time, theyre investments in the security of the most important secrets the nation has.
Breaking Defense: Is crypto mod more of a hardware or a software modification, or both?
Morrison: When we talk about crypto mod, were normally talking about updates to the hardware. But there are major software updates that we can do to provide compliance with crypto mod gates from the NSA. For example, our TACLANE-FLEX, TACLANE-10G, TACLANE-Nano, TACLANE-Micro, and Sectra vIPer phones have all been software upgraded to the NSAs Advanced Cryptographic Capabilities standard of modernization.
Breaking Defense: What is involved in keeping data-protection solutions up to date. Im assuming were talking about NSA requirements and certifications.
Morrison: Yes, the NSA is the certification authority for Type 1 crypto. If you want to pass classified information across the network, youve got to do it over a piece of crypto that the NSA has certified. For the vendors and programs that develop new crypto, that certification process is every bit as rigorous, complicated, and demanding as you would imagine. And, frankly, as rigorous as you would hope as these are high-stakes networks. For the missions that consume the crypto, the fact that NSA has certified the encryptor makes the long-term management of the crypto infinitely simpler and more stable.
Today, the NSA is in the midst of introducing a new specification for what we call Layer 2 encryption. This is a new standard for encryption at a different network layer that is intended to deliver much higher speeds over the next few years. Were very much a part of that effort and have made significant investments in delivering some mind-boggling speeds.
Breaking Defense: Speeds for what exactly?
Morrison: For the defense and intelligence establishments migration to the cloud. With defense networks operating in cloud environments, you have data center to data center transfers that have to happen at a very high rate of speed because those data center to data center transfers are aggregated traffic.
These transfers must be as bandwidth efficient as possible while keeping high security standards. When you move to Layer 2, you open up the possibility of much higher speeds at any given compute power. At the same time, we are pushing the boundaries of what compute power is available. Were always looking for more compute power to deliver higher and higher speeds.
As we address the data center market for government data centers, we need to be able to deliver speeds that there isnt even a market for today, but we know there will be tomorrow.
Breaking Defense: It almost sounds like the future of cloud computing in the DoD, particularly the Joint Warfighting Cloud Capability, is dependent on Layer 2 encryption. Is that an oversimplification?
Morrison: I dont think it is. The cloud providers likely can, with their existing or soon-contemplated infrastructure, handle what is already within the boundaries of their clouds. But as we know, defense customers are going to require hybrid clouds. Theyre going to require data transitioning from cloud to cloud, and thats where we really need those higher speeds.
Breaking Defense: What do you see as hindrances to proper crypto modernization?
Morrison: Im always sympathetic to the fact that the business Im in, the crypto business, is often perceived by some of our customers as an unfunded mandate. Its a real challenge.
That often stands in the way, even though nobody wants their systems to not be secure. Their number one concern is the life of their soldiers, sailors, airmen, and Marines. That necessitates the security of national security information traveling across their networks. But for many missions, crypto is not the core mission, its the thing that enables the mission.
As new requirements come online and as standards for crypto mod continue to evolve, tactical units might want to upgrade their crypto but just dont have the budget or logistics bandwidth. In response to that, we have added more remote management features to ease the logistics burden of crypto mod. And a couple of years ago, we introduced the smallest, lightest, least expensive Type 1 crypto in its class the TACLANE-Nano which brought affordable crypto to the tactical market.
Breaking Defense: Your point about crypto enabling the mission and not being the mission is well taken. Can you offer a scenario where TACLANE-Nano is particularly valuable to a warfighter and also an affordable and effective crypto solution?
Morrison: Sure. The last decade or more has seen a large increase in the use of unmanned and unattended systems. The nice thing about the TACLANE-Nano is that it is at a price point where you can put it on an unmanned or unattended system, insert it into your adversarys territory, for example, and not worry if it is lost or you lose connectivity; you can remotely zeroize that device. That means that if the cryptographic unit falls into the hands of our adversaries, it cant be used against us.
You cant do that with a big, heavy piece of crypto or one that costs $60,000 because thats not the way those types of unmanned missions run by and large. Were talking about much smaller, lighter airframes. We dont think of those classes of UAVs as attritable, but it may be approaching the attritable market.
Breaking Defense: Final thoughts?
Morrison: Any customer in the national security space has to be thinking about, worrying about, and planning for crypto mod. It is not something that any of us can ignore and then play catch up later on. The planning and logistics behind replacing legacy gear and modernizing a network cryptographic solution is complicated and long tailed.
Thats what General Dynamics Mission Systems is all about. We are a leader in crypto mod and are ready for both todays gates and tomorrows gates from the NSA. Our goal is to partner with our customers, help them understand and implement their modernization needs, and ensure their networks and communications are as secure as anyone can keep them.
- McConnell calls out Trump for hiring amateur isolationists at Pentagon, firing NSA director - The Hill - April 8th, 2025 [April 8th, 2025]
- Trumps firing of NSA chief is rolling out the red carpet for cyber attacks - Politico - April 8th, 2025 [April 8th, 2025]
- A conspiracy theorist convinced Trump to fire the NSA director - Vox - April 8th, 2025 [April 8th, 2025]
- William Hartman Named Acting NSA Director Following Dismissal of Top Officials - ExecutiveGov - April 8th, 2025 [April 8th, 2025]
- NSA and partners Issue Guidance on Fast Flux as a National Security Threat - National Security Agency (NSA) (.gov) - April 8th, 2025 [April 8th, 2025]
- Security News This Week: NSA Chief Ousted Amid Trump Loyalty Firing Spree - WIRED - April 8th, 2025 [April 8th, 2025]
- Head of NSA and US Cyber Command reportedly fired - Cybersecurity Dive - April 8th, 2025 [April 8th, 2025]
- Trump fires Gen. Timothy Haugh from leadership of Cyber Command and NSA - DefenseScoop - April 8th, 2025 [April 8th, 2025]
- Gen. Timothy Haugh, head of NSA and Cyber Command, is fired - CBS News - April 8th, 2025 [April 8th, 2025]
- Trump's mixed tariff messaging and NSA director and deputy fired: Morning Rundown - NBC News - April 8th, 2025 [April 8th, 2025]
- NSA Director and Deputy Reportedly Dismissed: What We Know - Newsweek - April 8th, 2025 [April 8th, 2025]
- Haugh fired from leadership of NSA, Cyber Command - The Record from Recorded Future News - April 8th, 2025 [April 8th, 2025]
- Trump administration fires head of NSA and U.S. Cyber Command, along with other top officials - CBS News - April 8th, 2025 [April 8th, 2025]
- US Cyber Command, NSA Chief Gen. Timothy Haugh ousted by Trump admin - Breaking Defense - April 8th, 2025 [April 8th, 2025]
- Face the Facts: Rep. Himes talks about firing of two top NSA officials - NBC Connecticut - April 8th, 2025 [April 8th, 2025]
- NSA Issues Advisory on Fast Flux Cyberthreat - ExecutiveGov - April 8th, 2025 [April 8th, 2025]
- Loomer, far-right activist, urged Trump to remove NSA director and others: Sources - ABC News - April 8th, 2025 [April 8th, 2025]
- The NSA Sounds Security Alarm For Billions Of iPhone And Android Phones - HotHardware - April 8th, 2025 [April 8th, 2025]
- NSA director fired after Trumps meeting with right-wing influencer Laura Loomer - The Verge - April 8th, 2025 [April 8th, 2025]
- Trump fires head of NSA and Cyber Command - Nextgov - April 8th, 2025 [April 8th, 2025]
- What are the national security concerns of Trump firing the NSA, Cyber Command head? - CBS News - April 8th, 2025 [April 8th, 2025]
- Who is Timothy Haugh? The NSA chief fired amid cyber security concerns - Times of India - April 8th, 2025 [April 8th, 2025]
- NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on Fast Flux, a National Security Threat - Hstoday - April 8th, 2025 [April 8th, 2025]
- Senator King Responds to Reported Firing of NSA Director General Timothy Haugh - WAGM - April 8th, 2025 [April 8th, 2025]
- NSA warned of vulnerabilities in Signal app a month before Houthi strike chat - CBS News - March 26th, 2025 [March 26th, 2025]
- Trump said poised to fire NSA Mike Waltz for including journalist in top secret war chat - The Times of Israel - March 26th, 2025 [March 26th, 2025]
- Not the last Waltz: Trump defends NSA after security breach - The Times of India - March 26th, 2025 [March 26th, 2025]
- NSA warned about vulnerabilities in Signal prior to White House group chat fiasco - SiliconANGLE News - March 26th, 2025 [March 26th, 2025]
- NSA warned the Signal app was vulnerable last month - WTIC - March 26th, 2025 [March 26th, 2025]
- Codebreakers and Covert Agents: The Women Behind the NSA and CIA heads to Illinois State Museum - WAND - March 26th, 2025 [March 26th, 2025]
- NSA warned about using Signal a month before leak of Houthi strike chat - CBS News - March 26th, 2025 [March 26th, 2025]
- 'Putin is giddy': NSA knew Signal was vulnerable to Russian hackers before security breach - AlterNet - March 26th, 2025 [March 26th, 2025]
- RAW: NSA MIKE WALTZ EXPECTED TO VISIT GREENLAND - Local 3 News - March 26th, 2025 [March 26th, 2025]
- US NSA likely to visit India in third week of April - Hindustan Times - March 26th, 2025 [March 26th, 2025]
- Statement from Secretary Rubio and NSA Waltz on Call with Zelenskyy - Department of State - March 22nd, 2025 [March 22nd, 2025]
- Europe must invest more in defence amid global shifts: Greeces NSA Ntokos - Firstpost - March 22nd, 2025 [March 22nd, 2025]
- NSA Bahrain, NAVCENT Hold First-of-its-Kind Exercise Vigilant Resolve - navy.mil - March 22nd, 2025 [March 22nd, 2025]
- Former NSA boss Osei Assibey Antwi picked up by NIB - GhanaWeb - March 22nd, 2025 [March 22nd, 2025]
- WHAT THE TECH? NSA recommending weekly smartphone restarts & how it improves performance - Local 3 News - March 9th, 2025 [March 9th, 2025]
- Ex-NSA cyber chief warns of devastating impact of potential DOGE-inspired firings - Breaking Defense - March 9th, 2025 [March 9th, 2025]
- Former top NSA cyber official: Probationary firings devastating to cyber, national security - CyberScoop - March 9th, 2025 [March 9th, 2025]
- Prime Targets Martha Plimpton On Her NSA Character & Why This Political Thriller Works: Never Trust People In Charge - Deadline - March 9th, 2025 [March 9th, 2025]
- Former NSA Dep. Director, Gifty Oware-Mensah will see NIB over 80k ghost names allegations - GhanaWeb - March 5th, 2025 [March 5th, 2025]
- Zelensky is not ready for peace talks, US NSA says - Mehr News Agency - English Version - March 3rd, 2025 [March 3rd, 2025]
- More Than 100 Intelligence Staffers Will Be Fired Over Sexually Explicit Texts In NSA Chatrooms, Gabbard Says - Forbes - March 1st, 2025 [March 1st, 2025]
- NSA says it is investigating potential misuse of chat platform - The Record from Recorded Future News - March 1st, 2025 [March 1st, 2025]
- 100-plus spies fired after NSA internal chat board used for kinky sex talk - The Register - March 1st, 2025 [March 1st, 2025]
- Tulsi Gabbard says more than 100 intelligence officers will be fired for sexually explicit NSA chat messages - CNN - March 1st, 2025 [March 1st, 2025]
- Elon Asked What Government Workers Did. The NSA Overshared - Schiff Sovereign - March 1st, 2025 [March 1st, 2025]
- Tulsi Gabbard Fires 100 Intelligence Officers for Sex Chats on NSA-Hosted Tool - The Daily Beast - March 1st, 2025 [March 1st, 2025]
- Elon Musk reacts to leaked chat alleging NSA, CIA officials discussed raising intersex babies as non-bina - The Times of India - March 1st, 2025 [March 1st, 2025]
- What NSA, DIA agents said about Libs of TikTok, Ben Shapiro in leaked messages - The Times of India - March 1st, 2025 [March 1st, 2025]
- NSA staff accused of lurid sex chats at work they were just discussing LGBTQ+ issues - PinkNews - March 1st, 2025 [March 1st, 2025]
- Sen. Tom Cotton reacts to lewd NSA chats: 'We don't want these people anywhere near classified information' - Fox News - March 1st, 2025 [March 1st, 2025]
- At least 100 NSA staffers to be fired for explicit chats during work hours - WDRB - March 1st, 2025 [March 1st, 2025]
- Gifty Oware-Mensah on the run as NIB investigates NSA scandal - GhanaWeb - February 25th, 2025 [February 25th, 2025]
- Former NSA, Cyber Command chief Paul Nakasone says U.S. falling behind its enemies in cyberspace - CyberScoop - February 25th, 2025 [February 25th, 2025]
- NSA emphasizes strong defensive posture as it responds to report it hacked China - Washington Times - February 25th, 2025 [February 25th, 2025]
- How the NSA Head of Accounts was undermined by his deputy for eight months after appointment - GhanaWeb - February 25th, 2025 [February 25th, 2025]
- What Is Proteus in Zero Day? How the NSA Weapon Changes Everything - Collider - February 25th, 2025 [February 25th, 2025]
- 'Zelenskyy will sign the minerals deal, no matter': US NSA Mike Waltz on Trump's Ukraine plan - The Economic Times - February 25th, 2025 [February 25th, 2025]
- EXCLUSIVE: Clearcover launches Illinois-based reciprocal exchange to jumpstart entry into NSA - Re-Insurance.com - February 12th, 2025 [February 12th, 2025]
- Chief of Naval Operations Visits NSA Crane, Purdue University [Image 18 of 25] - DVIDS - February 12th, 2025 [February 12th, 2025]
- Liminal Health Launches NSA ClearPath: Revolutionizing Reimbursement for Out-of-Network Providers - PR Newswire - February 12th, 2025 [February 12th, 2025]
- Elon Musks D.O.G.E is giving the CIA and NSA nightmares now - MSN - February 12th, 2025 [February 12th, 2025]
- NSA Ajit Doval likely to visit US along with PM Modi - The Economic Times - February 12th, 2025 [February 12th, 2025]
- The NSA says do these 5 things with your phone right now - Fox News - January 30th, 2025 [January 30th, 2025]
- NSA: Iraqi territory will not be used to attack neighboring countries Iraqi News Agency - ina.iq - January 30th, 2025 [January 30th, 2025]
- NDC is not here to witch-hunt - Opare Addo to NSA staff - GhanaWeb - January 30th, 2025 [January 30th, 2025]
- NSA Warns iPhone And Android UsersDisable Location Tracking - Forbes - January 19th, 2025 [January 19th, 2025]
- Trumps incoming NSA: Hamas must have no role in governing Gaza - JNS.org - January 19th, 2025 [January 19th, 2025]
- Trump NSA Disputes Report That Neocons Are Influencing MAGA Staffing - RealClearDefense - January 19th, 2025 [January 19th, 2025]
- US NSA lauds Ajit Doval for pivoting ties to advanced future tech - The Times of India - January 9th, 2025 [January 9th, 2025]
- Auto insurtech Clearcover expands into Texas NSA market with CGA launch - Re-Insurance.com - January 9th, 2025 [January 9th, 2025]
- "Cannot Think Of A Better Way To End My Tenure": US NSA On His India Visit - NDTV - January 9th, 2025 [January 9th, 2025]
- Heightened Security At U.S. Naval Academy And NSA Annapolis: Public Access Suspended Amid Increased Force Protection Measures - Bay Net - January 9th, 2025 [January 9th, 2025]
- From The Seabed To The Stars: 10 Takeaways From U.S. NSA Sullivans Visit - Strategic News Global - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan to visit India to finalise important ongoing initiatives: White House - The Hindu - January 9th, 2025 [January 9th, 2025]
- What NSA Jake Sullivans India Visit Signals For Nuclear And Tech Ties As US Lifts Curbs On Indian Entities - Swarajya - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan arrives today, seeks to strengthen AI, space, tech ties - The Tribune India - January 9th, 2025 [January 9th, 2025]