Secure Workload-to-Workload Authenticator Function
Parent: GR
Description
The mission should define policy and procedures to ensure that the developed or delivered systems do not embed unencrypted static authenticators in applications, access scripts, configuration files, nor store unencrypted static authenticators on function keys.
Mapped SPARTA techniques
3 techniques
The practice forbids embedding unencrypted static authenticators in delivered systems, which removes the most direct route by which an adversary obtains cryptographic keys from a fielded artifact. [Curation] RD-0003.02 is the adversary obtaining cryptographic keys by any means, including theft from personnel, cryptanalysis, and insider access. Forbidding embedded static authenticators closes one acquisition route out of many, and the corpus rule against mitigates on resource-development techniques applies.
Reconnaissance of cryptographic algorithms is a different objective from harvesting an embedded key, but the two share the artifact: a delivered image that carries neither an embedded authenticator nor the configuration around it yields less to inspection. Recorded at low confidence because the excerpt is about authenticators rather than algorithm disclosure.
Harvesting credentials from scripts and configuration files is precisely what a prohibition on embedded static authenticators interdicts. [Curation] The closest of the three reconnaissance calls, since a prohibition on embedded static authenticators genuinely removes a location credentials are harvested from. It is still a reconnaissance technique whose scope covers credential gathering by every other route, and the corpus rule against mitigates on reconnaissance holds, so addresses.
Cite as SafeMode Space, nasa-bpg GR-AUTH-03.