11.07.2015 Views

PMA209 2012 Core Avionics Master Plan - NAVAIR - U.S. Navy

PMA209 2012 Core Avionics Master Plan - NAVAIR - U.S. Navy

PMA209 2012 Core Avionics Master Plan - NAVAIR - U.S. Navy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Core</strong> <strong>Avionics</strong> <strong>Master</strong> <strong>Plan</strong> <strong>2012</strong> Appendix A-2approved crypto security algorithms for voice/data encryption. Current radios are limitedto operating at one level of security. HAIPE is an NSA trademarked IP Security (IPSEC)Type I encryption standard mandated for encryption of classified information traversingIP networks. The current HAIPE standard is version 1.3.5.Current systems are now also capable of Multiple Independent Levels of Security(MILS) architecture. MILS is a high-assurance security accreditation allowing multiplesecurity levels on the same terminal at separate times. When simultaneous operation isnecessary, singular systems must operate within one security controlled boundary. Datais moved between security domains through trustworthy monitors such as accesscontrol guards, "down-grader" cross-domain tools, or crypto devices. Any MILS versusMultiple Level Security (MLS) accreditation comparison should consider whether thesystem can be limited to one security domain per single device, or if the applicationrequires the accreditation of a single, more complex MLS kernel connecting multipledomains. The benefit of MILS accreditation is that most applications do not requiremaximal assurance between internal components because they are in the samesecurity domain.Existing algorithms currently support secure communications, but are being phasedout because they are no longer compliant with NSA requirements. Many embeddedCOMSEC radios and stand-alone encryption devices are being upgraded to utilizemodern cryptographic algorithms. The Air Force’s Cryptologic Systems Group (CPSG)is developing VINSON (KY-57/58) and ANDVT (Advanced Narrow-band Digital VoiceTerminal) Crypto Modernization (VACM) devices to replace KY-57, KY-58, KY-99, KY-100 and KYV-5 stand-alone encryption devices. VACM devices will be developed inaccordance with the Tactical Secure Voice Cryptographic Interoperability Specification(TSVCIS). The ARC-210’s embedded COMSEC will be upgraded to meet TSVCIS.Other applications will require other modern encryption standards, such as the LinkEncryption Family Interoperability Specification (LEFIS) used by the KIV-7M and theHAIPE Interoperability Specification (HAIPE-IS).2. Funded Enhancements and Potential Pursuits.Embedded Programmable Encryption. (<strong>2012</strong>) NSA/Central Security Service(CSS) Cryptographic Modernization initiative requirements for Type 1 cryptographicproducts and NSA Information Assurance (IA) Directorate policy expect thatcryptographic engines for DoD equipment will have a software re-programmablecapability. In order to enable timely and affordable upgrades and modernization, futuresystems must eliminate the need to completely replace hardware. New programmableencryption devices will feature modular architectures with the programmability andscalability to accommodate a wide range of link and IP encryption applications.Stand-alone Encryption (VACM). (2014) VACM development is an Air Force ledeffort to provide a Cryptographic Modernization compliant, drop in (Form, Fit &Function) replacement for the KY-57, KY-99A, KY-58, KY-100 and CV-3591/KYV-5stand alone encryption devices. NSA certification is expected to be complete in theFY13/14 timeframe.A-2 Information Exchange 9

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!