A leading A&D prime contractor supporting the U.S. Missile Defense Agency (MDA) was developing next-generation defense capabilities. The customer faced the critical challenge of securely delivering cryptographic key material and mission-critical firmware directly to deployed devices – while eliminating human touchpoints, reducing risk of compromise, and aligning with STIG compliance mandates. Traditional models depended on manual processes, air gaps, and on-prem security protocols that could no longer scale to the desired automation, assurance, and operational tempo.
ISS Solution
ISS deployed its Secure Platform for Aerospace & Defense (SPAD) – a hardened cryptographic distribution solution combining its Digital Lifecycle Management (DLM) appliances that generate, deliver, and secure cryptographic materials. This enabled end-to-end integrity across a secure software supply chain. Key highlights:
- Integration of DLM signing and distribution appliances into a SCIF-compliant architecture.
- Development of an embedded communication layer for direct key and firmware retrieval from the device.
- Implementation of SPAD capabilities:
- Authenticates sites, users, and devices
- Validates and transports software packages securely
- Automates delivery of mission-critical updates to FPGA-based systems (e.g., UltraScale MPSoC).
- STIG-hardening to government standards with remote update mechanisms, enabling the system to operate in fully airgapped environments without ISS access.
Results
- Eliminated human-in-the-loop steps for cryptographic provisioning and firmware delivery
- Delivered proof-of-concept enabling secure software signing and deployment to embedded missile subsystems
- Delivered edge encryption to protect mission software from factory to target system in the field.
- Demonstrated ability to operate in a SCIF with no external connection or vendor presence
- Positioned the contractor to meet emerging MDA standards for lifecycle cryptographic integrity