L3Harris Technologies

Mission-Ready Security, Measured Innovation

Mike Kurdziel is Senior Fellow in Cryptography and leader of the Systems Engineering Group at L3Harris Corporation, with 33 years of experience in secure communications. He has held key leadership roles in tactical communications, networking, and cryptographic development. Holding a Ph.D. in Electrical Engineering, 21 patents, and 33 publications, he brings deep expertise in cryptography, systems architecture, and network security.

Can you walk us briefly through your leadership role as Director and Senior Fellow? What are your key responsibilities and areas of focus?

As Director and Senior Fellow at L3Harris Corporation, I lead the Systems Engineering Group and bring over 33 years of experience to my role. My key responsibilities include overseeing the systems engineering organization, guiding the development and implementation of advanced cryptographic solutions, and ensuring the secure integration of communications across various projects.

My areas of focus encompass system architecture, network security, and the development of robust encryption methodologies. Additionally, I chair the Intellectual Property Management Committee (IPMC) and the Information Assurance Working Group (IAWG), where I contribute to advancing information assurance and secure communications within the L3Harris Communication Systems sector. My background in both practical and theoretical aspects of cryptography and systems engineering enables me to lead with a solid understanding of the field and a commitment to innovation and excellence.

Cybersecurity in defense often demands both innovation and reliability. How do you strike the right balance between adopting cutting-edge solutions and ensuring proven, mission-ready performance?

Cybersecurity in defense often demands both innovation and reliability. Striking the right balance between innovation and reliability is crucial in communication system cybersecurity. To achieve this, we adopt a rigorous approach to research and development, where new technologies are thoroughly vetted and tested in controlled environments before deployment. We prioritize solutions that offer improvements and can be integrated seamlessly with existing systems.

“We prioritize solutions that offer improvements and can be integrated seamlessly with existing systems.”

Additionally, we maintain a close feedback loop with end-users to ensure that our innovations address real-world challenges and meet mission-critical requirements. Furthermore, it is essential to maintain robust cybersecurity measures while ensuring ease of use for communication systems. By designing user-friendly interfaces and minimizing complexity, we enable users to operate securely without hindrance. By combining cutting-edge research and development with a commitment to reliability, performance, and user-friendly design, we ensure that our solutions are both innovative and mission-ready.

Emerging threats such as quantum computing and AI-driven cyberattacks are reshaping the security landscape. What do you consider the most pressing challenges and opportunities for defense communications in the next decade?

The most pressing challenges for defense communications in the next decade include the threat of quantum computing, which poses a significant threat to current cryptographic standards, and the rise of AI-driven cyberattacks that can outpace traditional defense mechanisms. Addressing these challenges requires a proactive approach to developing and implementing quantum-resistant cryptographic algorithms and standards and leveraging AI for predictive threat detection and response. Traditional public-key cryptographic systems are set to be deprecated by 2030 and eliminated by 2035, to be replaced by FIPS-203, 204, and/or 205. The opportunities lie in applying these advanced technologies to create more resilient and adaptive defense systems. By staying ahead of the curve in research and development, we can turn these emerging threats into opportunities for strengthening our cybersecurity posture.

As both a practitioner and an educator of cryptography, what do you believe are the biggest misconceptions about encryption and its role in protecting systems-at-scale?

One of the biggest misconceptions about encryption is that it is the only important component needed to ensure that a communication system is secure. While encryption is a critical element in protecting data, it is not sufficient on its own. Effective cybersecurity requires a comprehensive approach that includes several additional components:

Strong Cryptographic Primitives: Beyond just cryptographic algorithms, using well-established and secure primitives is essential.

Message Integrity and Authentication: Ensuring that messages are not tampered with and are from verified sources.

Access Control and Physical Security: Protecting hardware and physical infrastructure from unauthorized access, theft, or damage through measures like surveillance, access controls, and secure facilities.

Network Security: Properly designing network infrastructure, secure network architecture, and secure communication protocols.

Formal Verification and Vulnerability Management: Regularly assessing and managing vulnerabilities through formal verification methods.

Secure Key Management: Ensuring the secure generation, storage, distribution, and destruction of cryptographic keys.

Minimal Attack Surface: Keeping protocol design as simple as possible to minimize the attack surface and avoid unnecessary complexity that can introduce vulnerabilities.

Another misconception is that stronger encryption always equates to better security. The implementation and management of encryption play a crucial role in its effectiveness. Proper implementation of encryption algorithms is required to eliminate the risk of introducing side-channel vulnerabilities. Educating users about the complexities and best practices of cryptography is essential to ensure that encryption is used effectively to protect systems-at-scale.

What advice would you give to young engineers and cybersecurity professionals who aspire to innovate, lead, and make an impact in this rapidly evolving field?

My advice to young engineers and cybersecurity professionals is to stay curious and continuously enhance your skills. The field of cybersecurity is dynamic, and staying up to date with the latest developments is crucial. New threats and mitigation techniques emerge constantly. Pursue a multidisciplinary approach. Gaining an understanding of related fields such as computer science and mathematics, in addition to engineering, can provide valuable insights.

Focus on developing both technical and soft skills, as leadership and effective communication are essential for driving innovation and making a significant impact. Seek out mentors and engage with the cybersecurity community to build a strong network and gain diverse perspectives. By remaining dedicated and adaptable, you can make substantial contributions to the field and achieve meaningful impact.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.