Microsoft: ‘We respect and accept’ DOD decision to move on from JEDI
Microsoft has said that it will “respect and accept” a decision by the Department of Defense to scrap the $10 billion Joint Enterprise Defense Infrastructure (JEDI) procurement contract and instead proceed with a new multi-vendor cloud acquisition for the U.S. military.
In a blog post on Tuesday, Toni Townes-Whitley, Microsoft president of U.S. regulated industries, said that the company understands the Pentagon’s rationale and that it would continue to support them with technology JEDI would have provided.
Amazon Web Services said also in an emailed statement that it understood and agreed with the government’s decision to scrap the contract.
“The DoD faced a difficult choice: Continue with what could be a years-long litigation battle or find another path forward,” said Microsoft’s Townes-Whitley. “The security of the United States is more important than any single contract, and we know that Microsoft will do well when the nation does well.”
Townes-Whitley continued: “The 20 months since DoD selected Microsoft as its JEDI partner highlights issues that warrant the attention of policymakers: when one company can delay, for years, critical technology upgrades for those who defend our nation, the protest process needs reform. Amazon filed its protest in November 2019 and its case was expected to take at least another year to litigate and yield a decision, with potential appeals afterward.”
She was writing after the Pentagon earlier today announced its decision to move on from the program.
A spokesperson for AWS said: “Unfortunately, the contract award was not based on the merits of the proposals and instead was the result of outside influence that has no place in government procurement,” maintaining the company’s stance that political foul play led to Microsoft’s award, though that allegation was never proven.
“Our commitment to supporting our nation’s military and ensuring that our warfighters and defense partners have access to the best technology at the best price is stronger than ever. We look forward to continuing to support the DoD’s modernization efforts and building solutions that help accomplish their critical missions,” they added.
Along with the cancellation, the DOD announced a new direction for its enterprise cloud effort called the Joint Warfighter Cloud Capability (JWCC), a multi-cloud, multi-vendor contract. The department intends to solicit proposals from Microsoft and Amazon Web Services through the contract as “as available market research indicates that these two vendors are the only Cloud Service Providers (CSPs) capable of meeting the Department’s requirements,” the release states.
The Pentagon will also engage industry more broadly in its procurement process to determine whether any other U.S.-based hyperscale vendors can also meet the DOD’s requirements.
This story was updated to include comment from Amazon Web Services.
DOD cancels $10B JEDI contract
The Pentagon announced Tuesday it has canceled the $10 billion Joint Enterprise Defense Infrastructure (JEDI) cloud procurement, nearly two years after awarding the contract to Microsoft.
In a release, the Department of Defense said it has “initiated contract termination procedures” for the JEDI contract and is planning to replace it with a new contract that better fits the department’s cloud needs today. “The Department has determined that, due to evolving requirements, increased cloud conversancy, and industry advances, the JEDI Cloud contract no longer meets its needs,” it said.
The move comes after the department has been hinting for months that it might have to move in a different direction than planned with JEDI if the contract continued to be held up in court. Amazon has protested the award of JEDI to Microsoft since late 2019.
Acting DOD CIO John Sherman told reporters Tuesday that while JEDI was conceived in 2017 with “noble intent,” it was “developed at a time when the department’s needs were different and our cloud conversancy less mature.”
Microsoft said in a blog post after DOD’s announcement that it will “respect and accept” the decision. As the department finalizes termination of the contract, it may owe Microsoft some money under the initial task order it awarded.
With the cancellation of the JEDI procurement, Amazon’s protest of the contract in the Court of Federal Claims will soon follow suit. In a statement, the company maintained its belief that political interference led to Microsoft’s win, an allegation that was never ruled upon but at least held enough water for the court to decide to continue hearing the case earlier this year.
“We understand and agree with the DoD’s decision,” said a company spokesperson. “Unfortunately, the contract award was not based on the merits of the proposals and instead was the result of outside influence that has no place in government procurement. Our commitment to supporting our nation’s military and ensuring that our warfighters and defense partners have access to the best technology at the best price is stronger than ever. We look forward to continuing to support the DoD’s modernization efforts and building solutions that help accomplish their critical missions.”
Goodbye JEDI, hello JWCC
Now the DOD is headed in a new direction with its enterprise cloud effort, launching the Joint Warfighter Cloud Capability (JWCC) — a multi-billion-dollar, multi-cloud, multi-vendor contract. The department intends to solicit proposals from at least Microsoft and Amazon Web Services through the contract “as available market research indicates that these two vendors are the only Cloud Service Providers (CSPs) capable of meeting the Department’s requirements,” the release states.
The department will also engage industry more broadly over the next several months in its procurement process to “determine whether any other U.S.-based hyperscale CSPs can also meet the DoD’s requirements,” the release says. “If so, the Department will also negotiate with those companies.”
The initial plan is to make awards to vendors around April 2022.
Sherman said he had plans to immediately contact other top cloud providers IBM, Google and Oracle to see where they could potentially fit into the department’s plans.
The DOD has a variety of existing vehicles to work with each of these cloud providers in place, like milCloud 2.0 and others, but Sherman said there’s “nothing to the extent and reach that the enterprise capability we’re seeking to acquire from this will provide through JWCC — truly from the headquarters to the tactical edge in all three security levels at scale.”
As the DOD launches into the new JWCC procurement effort, it’s shying away from getting too caught up on a specific price tag, at least from the start. Sherman said it will be in the billions but a specific figure will be decided upon later, referencing how much of the discourse around JEDI was fixated on its $10 billion ceiling. The new contract is also noticeably shorter than JEDI at five years total — a three-year base with two one-year options.
While the continued protests of JEDI undoubtedly impacted DOD’s decision to cancel it, Sherman said even if it had gone into operation as intended after award, “we would have been having this multi-cloud discussion right about now anyway” due to the evolving needs of the department.
He added that he wouldn’t call JEDI “in any way a mistake.”
“We’re now in 2021, not in 2018, and the factors surrounding all this have evolved and so must we in our approach,” Sherman said, pointing to needed support to enable Joint All-Domain Command and Control and the department’s new Artificial Intelligence and Data Accelerator initiative. He later added: “The landscape has continued to shift during the timeframe, both on the private sector side with the cloud service providers, as well as how our users have become more conversant on some of the cloud capabilities.”
Sherman said that every day that DOD goes without this enterprise cloud capability is a wasted opportunity, or “day too long.”
“If we’re talking about body armor, other protective gear, hypersonic weapons or whatever we need to win our future fight, so goes it for JWCC,” he said, equating them in importance to the larger warfighting mission of the department.
Marine Corps targeting completion of wargaming center for summer 2023
Construction of a new wargaming center that will test future battle strategies and tech for the Marine Corps will be completed by the summer of 2023, the service has announced.
To accommodate wargames that will incorporate a range of future battlefield scenarios, the facility will include new modeling and simulation, visualization, immersive and analytical tools, according to a news release. The facility was first envisioned by then-Commandant Robert Neller in 2017 to help the corps’ “ability to make analytically-informed decisions” about its weapons and capabilities.
Located in Marine Corps Base Quantico, Virginia, the center is slated to open in 2024 and should be fully equipped by 2025.
“This facility is a big deal to us,” said Lt. Gen. Eric Smith, deputy commandant for the Marine Corps Combat Development and Integration. “There are a bunch of officer candidates training right now who have no idea what is going on here today. But they will benefit [from this facility].”
The facility intended to give senior leaders a more immersive understanding of what future battlefields may look like, and what capabilities future Marines will need. The Marine Corps has been on a journey to remake its force design to focus on deterring great power conflict by relying more on long-range precision fires, unmanned systems and advanced reconnaissance technology — all tech that the corps plans to test in a virtual scenario at the wargaming facility.
“These tools will enable wargame participants to work through complex problems or develop fully informed, data-enabled decisions to support the Marine Corps planning process,” said Sharleene Prieur, acting program manager of the Marine Corps Systems Command’s Wargaming Capability Program Office.
Huntington Ingalls to acquire cybersecurity, R&D company Alion for $1.7B
Shipbuilding defense contractor Huntington Ingalls will pay $1.7 billion to acquire cybersecurity and research and development company Alion.
In a statement, Huntington said the deal would allow it to expand its work to support Navy simulation and training work, as well as operations that support military intelligence, surveillance and reconnaissance.
The company added that the transaction is expected to expand Huntington’s technical solutions division, which was launched in 2016 to focus on cybersecurity and autonomous systems. Alion has a $3 billion contract backlog and employs 3,500 staff, of whom 80% have security clearance.
Huntington Ingalls provides professional services to the government and private sector and is also the largest military shipbuilding company in the U.S. It has expanded its cybersecurity and digital intelligence practice amid growth in the demand for such services from the federal government.
Commenting on the transaction, Huntington President and CEO Mike Peters said: “Today’s announcement, coupled with our previous investments in leading edge technologies, such as cybersecurity and autonomous systems, reflects our commitment to stay on the cutting edge of critical, high-growth national security solutions and generate significant long-term value for our shareholders.”
The transaction is likely to close in the second half of 2021, subject to regulatory approval.
DARPA makes hardware bug bounty platform open source
Defense Advanced Research Projects Agency (DARPA) has made its hardware vulnerability disclosure platform for white-hat hackers open source.
The platform, known as Finding Exploits to Thwart Tampering (FETT), was first launched last year, and the agency hopes that moving to an open-source structure will help ethical hackers to spot flaws with chip design and aid the creation of new processor prototypes.
The system virtualizes hardware and firmware, giving hackers a full range of access to chip designs before they are produced and installed into agency systems.
“We see value in making this research available to the broader [research and development] community for testing and evaluating processor designs to ensure they are robust and secure,” said Keith Rebello, the DARPA program manager leading FETT’s parent program, System Security Integration Through Hardware and firmware (SSITH). “Our aim is for researchers and developers to leverage the SSITH security evaluation framework to help create a common security benchmark that can be used to compare secure processor designs.”
DARPA teamed up with penetration testing company Synack to supply and vet hackers and software company Galois to build the platform. DARPA called the platform a “first-of-its-kind infrastructure” to virtually crowdsource the analysis of future processor technologies and find security gaps before chips are finalized as a means to break the so-called “patch-and-pray” cycle.
The types of exploits the program hopes ethical hackers will find before adversaries do are common classes of hardware vulnerabilities exploited through software that target electronic systems in a chip.
“It’s not about patching the vulnerabilities, it’s about preventing the exploit,” Synack CTO Mark Kuhr told CyberScoop when the program launched.
DARPA has also moved to an open-source structure for the baseline RISC-V processor designs used by the SSITH program. The designs provide a jumping-off point for developers and allow prototypes to be tested in a virtual environment before being produced.
GAO issues AI accountability framework for agencies
The Government Accountability Office has released its much-anticipated artificial intelligence accountability framework in an effort to oversee how agencies are implementing the emerging technology.
GAO‘s framework describes key practices across four parts of the development life cycle — governance, data, performance and monitoring — to help agencies, industry, academia and nonprofits responsibly deploy AI.
Agencies’ inspectors general (IGs), legal counsels, auditors and other compliance professionals needed a framework to conduct their own credible assessments of AI notwithstanding congressional audit requests.
“The only way for you to verify that your AI, in fact, is not biased is through independent verification, and that piece of the conversation has been largely missing,” Taka Ariga, chief data scientist at GAO, told FedScoop. “So GAO, given our oversight role, decided to take a proactive step in filling that gap and not necessarily wait for some technology maturity plateau before we addressed it.”
GAO would always be playing catch-up, given the speed AI is advancing, otherwise, Ariga added.
AI systems are made up of components like machine-learning models that must operate according to the same mission values. For instance, self-driving cars with their cameras and computer vision are systems of systems all working to ensure passenger safety, and it falls not only to auditors but ethicists and civil liberties groups to discuss both their performance and societal impacts.
“We want to make sure that oversight is not being treated as a compliance function,” Ariga said. “There are complicated risks around privacy, complicated risks around technology, around procurement and around disparate impacts.”
GAO’s framework, released Wednesday, is a “forward-looking” way to address those risks absent a standard risk-management framework specific to AI, he added. The agency wants to ensure risk management, oversight and implementation co-evolve as the technology advances to what the Defense Advanced Research Projects Agency calls Wave 3: contextual adaptation, where AI models explain their decisions to drive further decisions.
Another goal of the framework is to include a human-centered element in AI deployment.
With agencies already procuring AI solutions, GAO’s framework makes requirements, documentation and evaluation inherently governmental functions. That’s why every practice outlined includes a set of questions for oversight bodies, auditors and third-party assessors to ask, in addition to procedures for the latter two groups.
The rights to audit AI, inspect models and access data are critical to their efforts.
“It will be detrimental long term if vendors are able to shield the intellectual property aspects of the conversation,” Ariga said.
Attempts to audit AI have already occurred, most notably the Department of Defense‘s effort when the Joint AI Center was created in 2018. But DOD ran into issues because there was no standard definition of AI, and it lacked AI inventories to assess. Fast forward to the present day, and many companies now offer AI and algorithmic assessments.
GAO is already using its new framework to investigate various AI use cases, and other agencies’ IGs have expressed interest in using it, too.
“The timing is great because we actually have a number of ongoing engagements in national security, in homeland security, in the justice domain that involve AI,” Ariga said.
The framework will evolve over time, possibly into an AI scorecard for agencies — an idea proposed by former Rep. Will Hurd, R-Texas, in September.
Google and the JAIC are considering AI model or data cards, while nonprofits have proposed something more akin to a nutrition label, but GAO’s framework doesn’t prescribe a particular accountability method— rather it evaluates the rationale behind whatever mechanism is chosen.
Future iterations of the framework will also ask what transparency and explainability mean for different AI use cases. From facial recognition to self-driving cars to application-screening algorithms to drug development, each carries with it varying degrees of privacy and technology risk.
People won’t need a justification for every turn a self-driving car makes, but they’ll eventually want to know why, to the nth degree, and algorithm is flagging an MRI as anomalous in a cancer diagnosis.
“We knew having to do individual use case nuances would’ve taken us decades before we could ever issue something like this,” Ariga said. “So we decided to focus on common elements of all AI development.”
At the same time departments like Transportation and Veterans Affairs have started collaborating to develop their AI strategies, even though the former’s focus is safety and the latter’s customer service — given their shared workforce, infrastructure, development and procurement issues.
In developing the framework, Ariga said he was “surprised” to find not everyone in government is on board with the notion of accountable AI.
Undergraduate data scientists don’t always receive ethics training and are instead taught to prioritize accuracy, performance and confidence. They carry that perspective with them into government jobs developing AI code, only to have people tell them to eliminate bias for the first time, Ariga said.
At the same time a competing camp argues data scientists shouldn’t shape the world that should be but reflect the one they live in, and AI bias and disparate impacts are someone else’s problem.
Ariga’s team kept that disagreement in mind, while engaging with government and industry AI experts and oversight officials, to avoid placing an undue onus on any one group while developing GAO’s framework.
Government will eventually need to provide additional AI ethics training to data scientists as part of workforce and implementation risk management, training that academic institutions will likely adopt — much the same way medical ethicists came about, Ariga said.
“Maybe not tomorrow but certainly in the near future because, at least in the public sector domain, our responsibility to get it right is so high,” he said. “A lot of these AI implementations actually do have life or death consequences.”
Oak Ridge National Lab appoints Dilling as director of strategic planning
Oak Ridge National Laboratory has appointed Jens Dilling as director of strategic planning.
He joins on August 9 from Canada’s particle accelerator center, TRIUMF, where he currently works as associate laboratory director. Previously, he served as deputy head of TRIMF’s science division, and led the department of nuclear physics and isotope separator and accelerator science.
In the new role, Dilling will guide the development of laboratory strategies, strategic investments and annual planning, as well as manage the facility’s discretionary investment portfolio. He will also manage ORNL’s research library, which equips staff with the tools needed for research and development.
He has been an adjunct professor at the University of British Columbia since 2004. He received his doctorate and undergraduate degrees in physics from the University of Heidelberg, Germany.
Dilling’s research focuses on characterizing the strong force using precise mass measurements, in particular investigating atomic physics techniques applied to nuclear physics using particle accelerators.
Oak Ridge is a multiprogram science and technology laboratory that is sponsored by the U.S. Department of Energy. It is at the center of a push to develop a new exascale computing system called frontier, which will be eight times faster than the nation’s current most powerful supercomputer, Summit, which is also housed at the laboratory.
It is one of 17 laboratories run by the Department of Energy, including the Argonne National Laboratory in Illinois, and Ames Laboratory in Iowa. They work on a combination of enterprise research and the work that must be carried out for the safe management of the country’s nuclear weapons stockpile.
DHS awards $395.5M data center support contract to General Dynamics
The Department of Homeland Security has awarded a data center support services contract to General Dynamics Information Technology.
In a notice on Sam.gov the agency announced the details of the contract, which has an 18-month ordering period, and a maximum ceiling value of $395.5M.
Through the contract, General Dynamics will continue to provide existing DC1 services, which consist of a government-owned contractor-operated enterprise data center, infrastructure-as-a-service environments, and co-location facilities.
The services will be provided on an interim basis until a Data Center and Cloud Optimization contract is awarded in the fourth quarter of fiscal 2021 and a contractor is in place.
It is the latest contract win by General Dynamics, which late last year was re-awarded the Defense Enterprise Office Solution (DEOS) contract for cloud-based email and collaboration tools across the DOD, following a drawn-out procurement battle.
DARPA commissions research into neural network camera technology
The Defense Advanced Research Projects Agency (DARPA) has selected three companies to work on a research program that could dramatically lower the amount of bandwidth used by networks of cameras.
The program, which is called Fast Event-based Neuromorphic Camera and Electronics (FENCE), aims to develop cameras that sense motion, but which are able also to determine what motion is important and represents a threat. According to the agency, the new technology could reduce latency and the usage of network capacity by transmitting only necessary information.
Raytheon, BAE Systems and Northrup Grumman are the three defense contractors that have been chosen to work on the research project.
Neuromorphic computer systems refers to silicon circuits that mimic brains. Other research arms of the military have been on the hunt for neuromorphic computing systems that multiply the power that conventional AI systems have to churn through data.
Cameras that are able to operate with less bandwidth and lower latency are especially important to the U.S. military, because they must operate in theaters of war, where networks are often unreliable.
“The goal is to develop a ‘smart’ sensor that can intelligently reduce the amount of information that is transmitted from the camera, narrowing down the data for consideration to only the most relevant pixels,” Whitney Mason, the program manager leading the FENCE program said in a news release.
“Event-based cameras operate under these same principles when dealing with sparse scenes, but currently lack advanced ‘intelligence’ to perform more difficult perception and control tasks,” she added.
Cameras can already do some of this type of work in scenes that have few changes in the camera’s field of vision, but their capabilities become less reliable in complex or cluttered scenes.
DIU approves cloud management tools from Google, Zscaler and McAfee
The Defense Innovation Unit on Thursday said it has cleared new secure cloud management tools from three non-traditional defense companies that will facilitate video teleconferencing and cloud file sharing.
DIU is running its pilot with Google Cloud, Zscaler and McAfee Public Sector, all of which received “success memos” following a year of initial testing. The memos allow any DOD organization to use the SCM prototypes. Eventually, one company will be selected for a larger, long-term contract, likely by September, DIU said.
“These solutions simplify engagement with non-traditional technology vendors by allowing DIU users to collaborate in real time. The solutions provide equivalent security and control to the DoD’s Cloud Access Point (CAP) while delivering real-time performance, which is critical for such things as videoconferencing and file sharing,” John Chen, interim CIO for DIU, said in a release.
The Department of Defense currently has an acute need for cloud management tools for use in projects including its Joint All-Domain Command and Control (JADC2) program.
According to the DIU, technology from the three companies embraces zero trust principles, in line with the May 2021 Executive Order that is focused on improving the nation’s cybersecurity and DOD’s recent Zero Trust Reference Architecture. DIU hopes the way it prototyped the new tech can serve as a guide for other organizations throughout the department looking to implement zero trust principle.
“We have seen widespread interest in our SCM effort from Services and DOD agencies that are looking for solutions to similar challenges,” said Rick Simon, contractor and DIU project lead. “These successful prototypes will give services and agencies several independently-assessed choices, especially as they implement zero trust architectures.”