Army UxV Data-at-Rest Protection for Uncrewed Systems

Conner Crisafulli
September 22, 2026
16 minute read

Army UxV data-at-rest protection is becoming increasingly important as uncrewed and autonomous systems carry more sensing, computing, storage, and mission capabilities into contested environments.

The Army is developing and fielding a growing ecosystem of uncrewed aircraft, Launched Effects, autonomous ground vehicles, reconnaissance systems, electronic-warfare capabilities, and other systems designed to sense, communicate, maneuver, and support missions across the battlefield. The U.S. Army describes Future Tactical Uncrewed Aircraft Systems (FTUAS), for example, as providing brigade combat teams with organic reconnaissance and surveillance capabilities that collect, develop, and report actionable intelligence.

As these platforms become more capable, protecting the data stored on them becomes a system-design requirement. This article explains what Army UxVs can retain, how physical capture changes the security problem, why the entire supporting ecosystem matters, and how data-at-rest protection and CSfC DAR can address classified information on uncrewed and autonomous systems.

Key Takeaways

What Is an Army UxV?

An Army UxV is an uncrewed vehicle or system that can operate remotely, autonomously, or with varying levels of human control. These systems can operate in the air, on the ground, or in other environments and support missions including reconnaissance, surveillance, sensing, electronic warfare, logistics, communications, targeting, and other functions.

Army UxVs include systems with very different missions, capabilities, storage requirements, and risk profiles. A small expendable drone carrying limited data presents different data-at-rest considerations from a larger tactical UAS conducting persistent reconnaissance or an autonomous ground vehicle operating alongside a formation.

The systems requiring particular attention are those carrying substantial compute, storage, or mission information.

The U.S. Army states that FTUAS provides brigade combat teams with organic reconnaissance and surveillance capability and allows them to collect, develop, and report actionable intelligence. Army Launched Effects can also support reconnaissance, electronic warfare, and kinetic missions.

As those capabilities expand, the information stored and processed by the platforms becomes an important part of the security architecture.

Not Every UxV Presents the Same Data-at-Rest Risk

Army UxVs present different data-at-rest risks based on their mission, architecture, information, storage, and likelihood of leaving authorized physical control.

A small system designed for an attritable mission may retain relatively little information. A larger platform supporting ISR, electronic warfare, autonomy, targeting, or command and control may contain substantially more operational and technical data.

Programs should therefore begin by determining what information the system actually stores rather than treating every UxV as having the same protection requirement.

Relevant questions include:

Understanding the data is the first step toward determining the appropriate DAR architecture.

Why Is the Modern UxV a Computing and Storage Environment?

Modern UxVs can combine sensors and mobility with processors, storage devices, operating systems, mission applications, communications capabilities, and autonomy software. That makes the protection of their stored information a significant system-design consideration.

Depending on the platform and mission, stored information could include:

The significance of this information extends beyond an individual mission. A recovered platform may potentially provide information about how a system is configured, how its software functions, or how its sensors and mission applications operate.

Programs should therefore evaluate both the operational information stored on a UxV and technical information associated with the system itself.

Why Should UxVs Be Designed With Loss of Physical Control in Mind?

UxVs can operate in environments where continued physical control of the platform cannot be assumed. DAR architecture should therefore address what happens to stored information if the system is lost, disabled, abandoned, recovered by an unauthorized party, or captured.

This consideration follows directly from the operational role of many uncrewed systems. Their value can come from sending sensors, computing capabilities, or other mission functions into environments where placing personnel may be difficult or undesirable.

That can expose the equipment itself to conditions where recovery is uncertain.

The security architecture should therefore address two different objectives: reducing the likelihood of losing the platform and protecting the information if physical control is lost.

For DAR, the second objective is critical.

The architecture needs to answer a straightforward question: If an unauthorized party physically obtains the platform, what information can they access?

What Data Could Be Exposed on a Captured UxV?

A captured UxV can potentially expose operational and technical information stored on the platform. The specific exposure depends on the mission, system architecture, classification, and information retained by the device.

Mission information could include:

Technical information could include system configurations, software, sensor-processing capabilities, autonomy functions, operating-system information, and other details associated with how the platform operates.

The distinction matters because the security impact of physical capture may extend beyond the replacement cost of the vehicle itself. The stored information can have separate operational or technical value.

That makes protection of the data an independent requirement from protection of the physical platform.

Why Does the Entire UxV Ecosystem Need Data-at-Rest Protection?

DAR protection needs to follow classified information across the UxV ecosystem rather than focusing exclusively on the vehicle.

Army uncrewed and autonomous systems can depend on supporting equipment including:

FTUAS demonstrates this broader system architecture. During developmental testing, the Army described each prototype set as including two air vehicles, two ground control stations, two ground data terminals, an On the Move kit, and associated ground support equipment.

Protecting the aircraft while leaving classified information exposed on a supporting system does not resolve the overall DAR requirement.

Programs should identify where classified information is created, stored, copied, transferred, maintained, and retained throughout the system lifecycle. The appropriate protections can then be applied wherever that information resides.

Why Isn’t Encryption Alone Enough for Classified Data?

Encryption is an important component of DAR protection, but classified information requires evaluation of the complete security architecture.

A system can use strong encryption while still requiring controls governing authentication, cryptographic keys, startup behavior, implementation, configuration, and independent protection layers.

For applicable Cigent CSfC DAR architectures, the two protection layers are:

  1. An encrypted drive with pre-boot authentication as the hardware layer.
  2. Independent software full drive encryption as the second layer.

The encrypted drive and pre-boot authentication constitute one layer. PBA controls access to the encrypted drive and is not counted as a separate third layer.

This distinction matters when evaluating a captured system. Programs should determine not only whether information is encrypted, but also what controls must be satisfied before protected storage becomes accessible.

Why Does Authentication Matter on an Autonomous System?

Authentication determines when an encrypted system is permitted to make protected storage accessible. Autonomous systems create an additional architecture challenge because a person may not always be physically present to provide credentials during startup.

A conventional laptop can require an authorized user to authenticate before protected storage becomes available. An autonomous UxV may need to initialize, operate, or resume a mission without someone physically present at the platform.

The architecture therefore needs an authentication mechanism appropriate to the system’s operational requirements.

This can require programs to consider how the system establishes that access is authorized, what conditions permit protected storage to become available, and what happens when those conditions are no longer satisfied.

Autonomous operation should not be treated as equivalent to unrestricted access to protected storage. Authentication requirements need to be incorporated into the system architecture early enough to support both the mission and the applicable security requirements.

What Is Headless Authentication?

Headless authentication is an approach that allows a system to establish authorization and access protected resources without requiring a person to physically enter credentials at the device.

This capability can be relevant to UxVs and other autonomous systems that need to initialize or operate without personnel physically present.

The specific implementation depends on the system architecture and applicable requirements. Potential mechanisms may involve trusted hardware, cryptographic credentials, platform state, or other security controls.

The fundamental design question is whether the system can support autonomous operation while maintaining appropriate control over access to protected information.

Programs should address this requirement during system architecture rather than waiting until final cybersecurity or authorization testing.

How Does CSfC DAR Apply to Army UxVs?

NSA’s Commercial Solutions for Classified program provides Capability Packages for implementing commercial technologies within defined architectures to protect classified information. For stored classified information, NSA publishes the Data-at-Rest Capability Package.

The current CSfC Data-at-Rest Capability Package is v5.1.0, dated March 2026.

NSA describes the DAR Capability Package as providing solution designs for implementing independent layers of encryption to protect classified information at rest.

For Army UxVs carrying classified information, the applicable architecture needs to account for the operational characteristics of the system, including circumstances in which the platform may be powered off, unauthenticated, disconnected, or outside authorized physical control.

For applicable Cigent CSfC DAR architectures, the encrypted drive with PBA forms the hardware layer, while independent software full drive encryption provides the second layer.

The objective is defense in depth. Protection of the classified information does not depend entirely on one encryption mechanism.

What Should Authorizing Officials Ask About UxV Data at Rest?

Authorizing Officials and program teams should evaluate how DAR protection behaves under the actual operating conditions of an uncrewed or autonomous system.

Relevant questions include:

These questions should be addressed throughout system design, integration, testing, authorization, fielding, and sustainment.

Why Should DAR Be Addressed Early in UxV Development?

DAR should be addressed during system design because storage, compute, boot, authentication, and autonomy architectures can be established well before a platform reaches authorization testing.

Adding DAR requirements after those architecture decisions have been made can require changes to hardware, software, authentication, storage, or system integration.

Early planning allows programs to identify what classified information the system will retain, determine which DAR requirements apply, select appropriate components, and incorporate authentication requirements into the system’s operating concept.

This is particularly important for autonomous systems because authentication must support both security requirements and the platform’s need to operate without a person physically present.

DAR should therefore be treated as an architecture requirement rather than an encryption feature added near the end of the authorization process.

UxV Data-at-Rest Protection Checklist

Design Question What the Program Should Determine
Stored information What sensitive or classified information will reside on the platform?
Physical storage Which drives, modules, or other media retain the information?
Capture scenario What happens to the stored information if physical control of the system is lost?
Authentication What must occur before encrypted storage becomes accessible?
Headless operation How does authentication work without personnel physically present?
Encryption layers Are the required independent DAR protection layers correctly implemented?
Key protection How are cryptographic keys generated, protected, stored, and authorized?
Supporting systems Where else does the UxV ecosystem store the same classified information?
Component status Are applicable components listed for their intended CSfC role?
Lifecycle Does protection remain appropriate through integration, fielding, maintenance, and sustainment?

Public Validation and Policy Basis

The U.S. Army states that FTUAS provides brigade combat teams with organic reconnaissance and surveillance capabilities for collecting, developing, and reporting actionable intelligence. The Army also identifies on-the-move command and control and a Modular Open Systems Approach as FTUAS capabilities. The Modular Open Systems Approach supports rapid capability insertion as technology evolves.

Army developmental testing has demonstrated that FTUAS extends beyond the aircraft itself. In 2025, the Army reported that each prototype set delivered for developmental testing included two air vehicles, two ground control stations, two ground data terminals, an On the Move kit, and associated ground support equipment.

The Army also describes Launched Effects as a family of uncrewed or autonomous and semi-autonomous systems that can support missions including reconnaissance, electronic warfare, and kinetic effects.

NSA publishes the CSfC Data-at-Rest Capability Package v5.1.0, dated March 2026. Programs implementing CSfC DAR should verify current Capability Package requirements and applicable component status against NSA’s live public resources during architecture and procurement decisions.

Army uncrewed and autonomous systems are expanding the amount of sensing, computing, software, and mission information operating outside traditional physical security boundaries. Protecting those systems requires understanding not only how the vehicle operates, but also what information it stores and what happens to that information if physical control of the platform is lost.

DAR protection should extend across the full UxV ecosystem, including the vehicle, ground-control equipment, tactical computing, maintenance systems, servers, and other devices that retain classified information. For systems operating autonomously, programs also need to address authentication requirements early enough to support headless operation without weakening protection of stored information.

For Army programs evaluating classified data-at-rest requirements for UxVs and supporting systems, take the CSfC DAR Readiness Assessment to identify architecture considerations and areas that may require further review.

Take the CSfC DAR Readiness Assessment

Frequently Asked Questions

What is an Army UxV?

An Army UxV is an uncrewed vehicle or system that can operate remotely, autonomously, or with varying levels of human control. These systems can support reconnaissance, surveillance, sensing, logistics, electronic warfare, targeting, communications, and other missions. Their DAR requirements depend on the information they store and applicable security requirements.

What data can an Army UxV store?

An Army UxV can store ISR imagery, video, mapping information, targeting data, mission plans, routes, sensor logs, communications information, software, configurations, and other mission information. More sophisticated platforms may also retain autonomy software, AI models, mission datasets, or other technical information associated with how the system performs its mission.

Why is data-at-rest protection important for uncrewed systems?

Uncrewed systems can operate where continued physical control of the equipment cannot be assumed. If a platform is lost, abandoned, disabled, or captured, an unauthorized party may gain physical access to its storage. DAR protection addresses how stored information remains protected when the physical endpoint leaves authorized control.

Do all Army UxVs require the same DAR protection?

No. DAR requirements depend on factors including the information stored on the platform, its classification, system architecture, mission, operating environment, and applicable security requirements. A small system retaining limited information can present a different risk from an ISR or autonomous platform containing substantial mission and technical data.

Why isn’t an encrypted SSD enough for classified data?

An encrypted SSD provides an important security function, but classified DAR requires evaluation of the complete architecture. Programs also need to address authentication, cryptographic key protection, startup behavior, configuration, and independent protection layers. Applicable NSA requirements determine how these functions are combined for classified data-at-rest protection.

What is headless authentication for an autonomous system?

Headless authentication allows a system to establish authorization without requiring a person to physically enter credentials at the device. This can be relevant when an autonomous UxV must initialize or operate without personnel present. The implementation depends on the system architecture, mission requirements, and applicable security requirements.

How many protection layers does CSfC DAR use?

NSA’s CSfC DAR architecture uses independent encryption layers. For applicable Cigent architectures, an encrypted drive with pre-boot authentication forms the hardware layer, while independent software full drive encryption provides the second layer. The encrypted drive and its PBA constitute one layer rather than being counted as two separate layers.

Does DAR protection apply only to the uncrewed vehicle?

No. Classified information can also reside on ground-control stations, tactical computers, servers, maintenance systems, removable media, mission-planning equipment, and other supporting devices. Programs should identify where information resides throughout the UxV ecosystem and apply appropriate DAR protections wherever applicable classified information is stored.

When should a UxV program address DAR requirements?

UxV programs should address DAR during system architecture and design. Storage, compute, boot, authentication, and autonomy decisions can be established well before authorization testing begins. Identifying applicable DAR requirements early allows programs to incorporate the necessary components and security functions before major system-design decisions become difficult to change.

What should an Authorizing Official evaluate for UxV DAR?

An Authorizing Official should evaluate what classified information the system stores, where it resides, how encryption and authentication are implemented, how cryptographic keys are protected, how authentication functions without personnel present, what happens when physical control is lost, and whether the architecture and applicable components meet current DAR requirements.

Conner Crisafulli

Conner Crisafulli is a solutions engineer and cybersecurity professional at Cigent with a unique background bridging elite military operations and advanced data security. Before joining Cigent, Conner served six years as a U.S. Air Force Combat Controller, where he specialized in high-stakes mission planning, communication systems, and joint operations coordination/execution. Drawing from his experience in complex, contested environments, Conner now helps federal agencies and enterprise clients strengthen their data-at-rest protection strategies. At Cigent, he focuses on practical applications of self-encrypting drives (SEDs), pre-boot authentication (PBA), and various CSfC (commercial solutions for classified) technologies to safeguard sensitive data against evolving cyber threats.

More from Cigent

UAS Data-at-Rest Protection for Classified Data
Blog
16 minute read
September 23, 2026

UAS Data-at-Rest Protection for Classified Data

DLP vs. Data-at-Rest Protection for National Security Systems
Blog
14 minute read
September 21, 2026

DLP vs. Data-at-Rest Protection for National Security Systems

Marine Corps Data at Rest Protection for Classified Data
Blog
15 minute read
September 17, 2026

Marine Corps Data at Rest Protection for Classified Data