Based in Huntsville, Alabama, Grady Paul Gaston, III, is an experienced software engineer and entrepreneur with more than three decades of work in technology and defense systems. In 1990, he co-founded a defense contracting company that later became well known in the technology field. In 1995, he also co-founded a digital signature company. He served as an officer of both companies for more than 16 years. During that time, government agencies and commercial clients relied on his companies to solve difficult technical problems and manage large projects.
While studying for his Bachelor’s degree, Grady worked as a courier for Computer Sciences Corporation. That role introduced him to the world of computers and technology. Between deliveries, he spent time with computer operators who taught him programming concepts and system operations. Over time, he became skilled enough to handle emergencies when they occurred. His ability and determination eventually earned him a programming position, and his interest in technology continued to grow.
Later, Gaston joined the United States Army Corps of Engineers. While still a college junior, he became the youngest software analyst at the USACE. He quickly built a reputation as a highly capable programmer and analyst within the organization.
Gaston earned a dual Bachelor of Science degree in Finance and Management from the University of Alabama Huntsville. He later completed a Master of Science degree in Software Engineering from Southeastern Institute of Technology. In addition, he became a Certified Data Processor through the Institute for the Certification of Computer Professionals.
In 2002, Grady received the University of Alabama Huntsville Life-Time Achievement Award. That same year, he served on the University of Alabama Huntsville Capital Management Board. In 2006, he became President of the University of Alabama Huntsville Alumni Association. In 2007, he also served on the Board of Trustees of the Alabama School Systems.
One of Gaston's most important accomplishments was helping develop a financial management system selected as the Defense Department standard. It became the only economic system to pass the CFO Act of 1990 for 15 consecutive years without exception.
He is also recognized for early work involving digital signatures and smart card technology. In 1991, he helped implement this technology in cooperation with the National Institute of Standards and Technology (NIST) and the Governmental Accountability Office (GAO). His copyrighted digital signature software later became the most widely used solution within the Department of Defense, serving more than four million users.
Grady Gaston's goal in creating the two companies was to provide effective software solutions for emerging technologies. This included building custom systems such as Engineering Change Proposal (ECP) systems, Data Dictionaries, and Configuration Management Systems before similar commercial software products existed.
Because much of the work was completed under Defense Department contracts, the software belonged to the DoD and could not be sold commercially. However, while working on the electronic signature challenge, he retained ownership of his digital signature technology.
One of his proudest achievements was pioneering digital signatures during the development of a financial management system for the US Army Corps of Engineers. At the time, waiting for paper signatures caused major delays in financial processing. In some cases, signed documents took up to six months to arrive through the mail system.
The United States Army Corps of Engineers is a large organization with a long history of significant projects, including involvement in the Manhattan Project. Because of the agency's size and importance, introducing a new financial signature process required support from senior leadership and congressional oversight groups.
USACE is also unique because it receives both military and civil funding. As a result, the agency answers to both the Governmental Accountability Office and the Office of Management and Budget.
Gaston met with the Deputy Director of the GAO while his government client worked with the OMB. The central issue was whether digital signatures could legally replace handwritten signatures. Before approval could proceed, NIST needed to establish standards for USACE to follow.
At that time, NIST was developing FIPS Pub 140-1, a Federal Information Processing Standard focused on ensuring the authenticity of digital messages. The standards required that the signer control the signing process, review all signed data, verify the signature, and ensure verification failed if any information changed.
By late 1991 and early 1992, the USACE financial system included an electronic signature prototype known as “ESIG.” In 1993, GAO approved the implementation as legally binding.
Grady Paul Gaston’s discussions with GAO established the conditions needed for legal approval. Fraud prevention became a primary concern. The ESIG solution used symmetric key technology, meaning the same key was used for both encryption and decryption.
The document being signed was reduced to a small hash, which was then encrypted with a symmetric key. GAO required a “split-knowledge, dual-control” process. This prevented a single individual from creating a signature. Two separate keys are combined into a third key that completes the signing process.
Because the system handled billions of taxpayer dollars, simple password protection was not enough. A stronger security process was necessary.At the time, Europe had begun using plastic smart cards containing computer chips. These smart cards became the basis for the solution, even though the technology was not common in the United States.
NIST released technical requirements, and vendors created cryptographic board prototypes that connected computers to smart card readers. The system required the computer to pass a challenge test before granting access. Passwords were never allowed to pass through the computer’s CPU because that could expose them to spying software. Instead, a keyboard intercept cable routed password data directly through the cryptographic board.
The cryptographic board itself included tamper protection that immediately erased keys upon detection of interference.
The login process required two smart cards. One belonged to the Security Administrator, and the other belonged to the user. The keys from both cards are combined using XOR logic to create a unique encryption key. That key encrypted the document hash.
Smart cards, passwords, and encryption keys were created through a highly secured “Key Translation Center.” Signature verification required the same XOR-generated key to confirm authenticity. Grady Gaston's team eventually built two Key Translation Centers to support approximately 30,000 USACE smart card users.
NIST also required passwords to be memorable and never written down. The system generated six-character, pronounceable passwords and delivered them through sealed envelopes. Some unintentionally offensive password combinations occasionally appeared during this process.
Timing again played an important role in the technology's growth. After the USACE financial system deployment in 1996, the US State Department developed a new financial system for embassies worldwide. When the State Department sought guidance from GAO on electronic signatures, GAO directed them to follow USACE's implementation.
When the State Department contacted Gaston, he already understood the broader possibilities of the technology. However, the existing system still required expensive cryptographic boards, keyboard intercept devices, and Key Translation Centers. Laptop users also required a separate “Signet” device developed by his company. The device, connected externally to laptop ports, often caused delays during airport security inspections.
The ESIG implementation for the State Department took about six months. Soon after, the US Census Bureau requested a similar system for its travel operations ahead of preparations for the year 2000. Because lessons had already been learned from previous deployments, the Census Bureau implementation took only three months. Even so, he wanted to create a simpler and more scalable solution.
An algorithm created during the 1970s by MIT professors eventually provided the answer. The RSA algorithm, named after Rivest, Shamir, and Alderman, used one key for encryption and another for decryption. This public-private key structure allowed users to distribute one key publicly while keeping the other private.
This approach eliminated the need for costly cryptographic hardware, keyboard-interception systems, and Key Translation Centers. As a result, the cost per user dropped from hundreds of dollars to only pennies.
By combining the ESIG process with RSA technology, Grady's team created a product called “DBsign,” short for “Database Signing.” The software signed data directly in the database rather than signing formatted documents. This ensured the information remained verifiable regardless of how it was displayed.
He also preferred the term “digital signature” because it specifically referred to encrypted signature methods rather than the broader category of electronic signatures.
When Northrop Grumman selected DBsign for the Defense Travel System, it became the de facto digital signature standard across the Department of Defense.
Grady Gaston's accomplishments extend beyond pioneering digital signatures. He provided key input to the DoD Public Key Infrastructure Roadmap in 2000. In 2001, his solution received the first Joint Interoperability Test Command certification for a digital signature system.
In 2003, the solution was selected for DoD-wide deployment. In 2005, it received the first National Information Assurance Partnership Common Criteria Evaluation and Validation Assessment. The solution was revalidated by NIAP CCEVS in 2011.
Gaston continued advancing the technology by developing digital signatures for mobile devices in 2016 and deploying digital signature solutions to cloud technologies in 2018. In 2023, the work also received the Cybersecurity Maturity Model Certification Level 2 Assessment.
One of Gaston's personal interests is restoring and maintaining the Sim Corder/Harrison Mill, which he restored in 2005. The mill was originally built by Sim Corder in the early 1900s and operated by his great-grandfather, George Harrison. After being decommissioned, the waterwheel was sold in 1939.
He later located the original waterwheel, repurchased it, and returned it to the mill in its original position. The restored mill was featured in the October 2009 issue of Alabama Living in an article written by freelance writer David Haynes.
Another hobby is fitness and strength training. During elementary school, he was runner-up for Athlete of the Year, and later joined the high school wrestling team. At a body weight of only 120 lbs, he could bench press 175 lbs.
More recently, after learning that only 17% of gym-goers can bench press 225 lbs, Grady made it a personal goal to reach that milestone. He believes consistency played a major role in maintaining his strength over the years. At age 30, he committed to completing his age in push-ups every birthday and continued doing so successfully, even after recovering from a shoulder injury in his mid-50s.
He also values the health benefits connected to physical fitness. According to a 2019 Harvard School of Public Health article, men who can complete 40 push-ups have a significantly lower risk of cardiovascular disease. Grady Paul Gaston continues to balance his professional legacy with personal interests centered on history, restoration, and long-term health.
Portfolio 1: gradypaulgaston.com
Portfolio 2: gradypgaston.com
Portfolio 3: gradygaston.com
Grady Paul Gaston on What Real Leadership Looks Like in Software Development
Grady Paul Gaston on the Foundations of Secure Systems
Discover how the Sim Corder Harrison Mill used waterpower and craftsmanship to influence early engineering and industrial progress.
Read More