The Institute for Security and Technology designs and advances solutions to the world’s toughest emerging security threats. It is a nonpartisan, nonprofit network based in the San Francisco Bay Area dedicated to solving critical international security challenges through better technology and policy. For more information, visit securityandtechnology.org.
In this podcast “Security Through Simplicity,” Eric Grosse joins Philip Reiner and Peter Hayes to detail the trade-offs of prioritizing security, reliability, and efficiency in the CATALINK system. This includes a primer on how a sender and receiver will exchange cryptographic keys to ensure they are communicating securely. The episode also discusses the reasoning for Grosse's proposed technical baseline solutions. Music by Punch Deck
This week’s episode of The Fourth Leg, “The Mathematics of Trust and Betrayal,” features experienced cryptographer and owner and founder of Anagram Laboratories, Dr. Tom Berson. Dr. Berson joins Tech4GS’ Philip Reiner to discuss how lessons from the Advanced Encryption Standard (AES) competition can aid the development of international standards and potentially serve as an example for collaborative, transparent efforts for the creation of the CATALINK system. Music by Punch Deck
This week’s episode of The Fourth Leg, "Assume Vulnerability", features the High Priest of Coreboot, Ron Minnich. We dive deep into the substance of his paper, “Hardware that is Less Untrusted: Open Source Down to the Silicon” and discuss software, firmware, and hardware vulnerabilities and the value of open source code. Music by Punch Deck
This week's episode of The Fourth Leg, “Targeting Communications and Escalation,” features the return of one of the “NC3 originals,” Paul Bracken from Yale University. We dive deep into the substance of his paper, “Communication Disruption Attacks on NC3,” which argues that states must do more to delineate intentions in attacking communications systems in order to avoid inadvertent nuclear conflict. Dr. Bracken also shares insight into the beginnings of his career and how he came to work for Herman Kahn for a decade at the Hudson Institute. Music by Punch Deck
Welcome back to The Fourth Leg, a series of podcasts focused on one of the most complex systems in the world today - nuclear command and control - and its increasingly complicated future. Here in season two, we will discuss the necessity for a secure, global crisis communications capability. This is the first episode of our second series, where we discuss the need for a better communication system between nuclear powers with Philip Reiner, Peter Hayes, Eric Grosse, Rear Admiral John Gower, and Subrata Banik. Music by Punch Deck
In this week's segment, we sat down with Dr. James Acton regarding the paper he wrote for our workshop back in January. Throughout the discussion, James shares with us how he evaluates the risk of inadvertent escalation arising from attacks on dual-use (nuclear and conventional warfare) command, control, communication, and intelligence (C3I) capabilities in a conventional war because such attacks would degrade the target’s nuclear command-and-control system.
We sat down with Dr. Ronald Schouten about a paper he wrote for our workshop back in January. Among other topics, we discussed insider threats to nuclear command, control and communications. The breadth of this topics is enormous, and yet the space for its discussion remains relatively limited.
In this segment, Bill Boothby observes: “For all States, there is an obligation to take constant care in nuclear operations to spare civilians and civilian objects. More detailed precautionary rules apply to all States with certain additional rules only applying to States that are party to API and that made no nuclear statement. States adopt numerous measures to disseminate this body of law. International engagement seems to be the best approach for promoting international compliance.”
In this segment Paul Davis suggest that U.S. NC3 modernization “should place increased emphasis on assuring control, avoiding accidents, and avoiding ill-informed or unwise employment of nuclear weapons.”
The segment conceptualizes desirable attributes of nuclear command, control, and communications. Much of what is ordinarily front and center in such discussions has been omitted within this report. In particular, Paul does not address the myriad of structural and technical issues associated with mod¬ern¬izing the system's personnel, procedures, facilities, equipment, and communications. Instead, this report asks what core functionality should be demanded, and how those demands should differ from those of the Cold War. Doing so raises provocative issues of which readers, and practitioners, may disagree, but that point back to critical first-order questions that must be asked at the outset of reconstituting the aging NC3 architecture.
In this segment Daryl Press focuses on the growing threats to nuclear command and control and communication (NC3) systems around the world and the links between vulnerable NC3 and strategic instability due to the risky steps that nuclear weapons states may adopt to protect their arsenals during crises or wars.
Israel is a unique case among the current nine nuclear weapons states. It is the sixth state—and the first and only one in the Middle East—to develop, acquire, and possess nuclear weapons. And yet, to this day, it has never openly acknowledged its nuclear weapons-state status. Nor has the outside world, friends or foes alike, pressed Israel to come clean publicly about its nuclear status.
As a long-held policy, Israel neither confirms nor denies possession of nuclear weapons. Instead, ever since the mid-1960s—a time in which Israel did not yet possess nuclear weapons capability—Israel has declared, first privately and then publicly, that “it will not be the first to introduce nuclear weapons to the Middle East.” This formula became the essence of Israel’s policy of nuclear opacity.
In this segment Avner Cohen traces and exposes Israel’s two most fundamental principles of the Israeli NC3 thinking: first, insisting on strict physical and organizational separation between nuclear (e.g., pits) and non-nuclear assets (e.g., military delivery platform); second, creating a two- tier governance architecture at various levels.
The Pakistani command and control (C2) system evolved over a four-decade period following a national consensus that deemed the development of a nuclear deterrent a critical component of national security. Until the 1998 tests, Pakistan insisted its program was for peaceful purposes only; even two decades later, a culture of secrecy and deliberate ambiguity continues to surround the program. Pakistan political governance vacillates between a presidential system and parliamentary system under constitutional amendments, which has affected the credibility of political control over national security. Military the strongest institution in the country is the keeper of national security. The nuclear domain is the exclusive purview of the Strategic Plans Division (SPD) at the Joint Service Headquarters (JSHQ). After the passage of National Authority Act in 2010, JSHQ and SPD were bestowed with powers as the de jure and de facto authority on all nuclear matters on behalf of the Prime Minister. Providing a fresh historical perspective, Feroz Khan illustrates the unique challenges facing Pakistan's NC3 systems. When considering the rapid pace of technological advancements, Khan concludes, "as NC3 gains sophistication, control of partial or full pre-delegation regimes would likely be refined to overcome the never/always dilemma of deployed arsenals in the field."
The brain of a state’s nuclear force structure is its command and control architecture and systems (NC3). Much of the proliferation and strategy literature focuses on the hardware of nuclear weapons—the actual production of warheads and delivery systems, ranges, accuracy, basing modes, payloads, MIRVs, missile defenses, and so on. But the software—the NC3 architecture that is charged with managing command, control, and communication under potentially extreme circumstances—is often overlooked or simply assumed or inferred, since much of it is unobservable because states (thankfully) rarely emerge from their peacetime postures.
In this segment, Dr. Vipin Narang challenges the delegative/assertive binary, arguing that, while conceptually important, it has hamstrung our thinking of regional powers’ NC3 by forcing them into one bin or another when it is in fact a time-dependent spectrum: all states delegate—that is, cede the ability to use nuclear weapons, irrespective of the authority to do so—at some point. Dr. Narang concludes that: "states may not only shift from assertive to delegative postures as a crisis or conflict evolves, but may also have variable NC3 postures for different legs of its force."
The United Kingdom formally became a nuclear weapon state in 1952, with operational systems from 1955. The UK's strategic deterrent has evolved over the past 66 years of it being a nuclear armed state. Nuclear weapon system information, particularly the detail of national command, control and associated communications systems and protocols, are among the most tightly guarded and classified secrets of any nation. The UK is no exception to this, and until the decision to release some of the protocols and procedures as part of the Cabinet Office co-operation with a BBC Radio programme in 2008, every facet of current national arrangements was classified.
In this segment, Rear Admiral Gower states that the UK Nuclear Weapon Command Control and Communications (UK NC3) architecture is designed and operated to support SSBN strategic nuclear deterrence in all foreseeable circumstances from peacetime to nuclear conflict. “Through multiple paths and frequencies, fall-back and alternative systems and with dedicated and unique encryption and processes it delivers continuous availability for the Prime Minister should a decision to launch be made.”
This segment goes into further detail regarding the multiple communication paths, frequencies, fall-back systems, and encryption needed to continuously enable the UK's Prime Minister to act on a nuclear launch decision.
In this episode, Elsa Kania assesses how emerging technologies--including artificial intelligence, cloud computing, fifth-generation telecommunications, and quantum communications--may affect China’s NC3. Kania concludes: “Although certain of these technologies could enhance China’s confidence in its NC3 in ways that may prove stabilizing, there are also reasons for concern that the potential introduction of such complex, untested technologies could also create new risks and exacerbate the threat of miscalculation.”
In this segment, Dr. Alex Wellerstein sketches a framework for thinking about how concentrated nuclear use authority should be at the top. While he discusses specific U.S. proposals for reform in response to recent domestic debates, the scope of his analysis is uniquely global, and includes a comparative analysis of the approach of all nine nuclear weapons states.
Global NC3 systems are historically constituted and contextualized, the result of considerable debate and experimentation over time within nuclear states. This fact points to their necessary adaptability, and to the opportunity for novel approaches going forward. Using a global perspective, the framework presented by Dr. Wellerstein within this segment could provide inspiration for alternative, perhaps less risky nuclear command and control arrangements.
In this segment, Nancy Leveson argues that using conservative techniques and avoiding unnecessarily complex software in critical functions in NC3 systems circumvented nuclear catastrophe in the past. Today, she concludes, a new approach is needed that avoids gratuitous complexity; emphasizes less not more technology; and improves NC3 systems by developing “more powerful, socio-technical and system engineering and risk management approaches that involve paradigm changes from the approaches that are no longer working. These are only now coming into existence and will need technical advances and refinement.”
In this episode, Fiona Cunningham describes the origins of China’s NC3 system and its primary role in supporting China’s land-based missile force. She outlines recent developments including mobility, “informatization” and automation of parts of the NC3 system, pending deployment of nuclear missile submarines, early warning systems, evolving organizational structure, and cultural factors that shape China’s NC3 system and its orientation towards negative versus positive control.
Dr. Jon Lindsay argues that: “As NC3 increasingly uses digital technologies to enhance efficiency and reliability, the cybersecurity of NC3 becomes a pressing concern. Adversaries have incentives to penetrate NC3 for intelligence in peacetime and for counterforce in wartime. Given the broad diffusion of cyber capabilities, furthermore, most nuclear weapon states also have some ability to do so, although the operational difficulties of gaining remote access to and covert control over NC3 cannot be overstated. Offensive cyber operations targeting NC3 introduce a number of under-appreciated risks of organizational breakdown, decision making confusion, and rational miscalculation in a nuclear crisis.”
In this segment, Dr. Eric Grosse argues: “Much of the security progress over the past decade has been at large-scale, finding and patching vulnerabilities in widely used applications or defending networks of millions of machines containing high-value data. The lessons there may help military systems, but for the very highest security needs such as NC3, we ought to return to basics and harden small-scale systems. And we ought to do it as a joint effort, even between adversaries.”
This segment presents an intriguing and critical assertion for those involved not just in the design and development of NC3 related systems - his assertions and ideas are of relevance across the security spectrum, from Homeland Defense to tactical comms.
We hope you all enjoy this piece as much as we have, and we look forward to your feedback and thoughts.
Dr. Eric Grosse was Google's VP of Security & Privacy Engineering, having just recently retired in 2017. Before Google, Eric was a Research Director and Fellow at Bell Labs. He has a Ph.D. in Computer Science from Stanford University.
In this podcast Dr. John Harvey asserts that the US NC3 system “must seek vastly improved senior leader conferencing capabilities to support decisions that go beyond what some of us call the Cold War’s “multiple choice test”—that is, which major attack option to execute. To support consultations among allies, partners and potentially adversaries, in addition to senior military and advisors in complex conflict scenarios involving, say, combined offense and defense, nuclear and conventional operations—that is, the “essay test”—will require global, secure, high-quality voice, video and data transmissions that are resilient in stressed nuclear environments and go well beyond what was required for the Cold War mission.”
Welcome to The Fourth Leg, a series of podcasts focused on one of the most complex systems in the world today - nuclear command and control - and its increasingly complicated future.
Within this series we go straight to the experts, across multiple sectors, to discuss the modernization of nuclear command and control systems.
Along with colleagues from the Nautilus Institute and the Preventive Defense Project, Tech4GS recently hosted over 50 international experts at Stanford University to anticipate technical challenges that will arise from the modernization of complex nuclear command and control systems.
Keep an eye on Tech4GS, as we will begin additional podcast series in the coming months focused on how to fix the internet, AI and global stability, and other critical tech and security issues- for now, we have so much more to talk about, so let’s get started.