Extend a deployed system's operational life and keep it in service when its cryptography breaks, and replace its algorithms on schedule across the whole mission, built on information-theoretically secure cryptography.
Crypto-agility means replacing the cryptographic algorithms on a deployed device at any point in its life. The hard part is not changing an algorithm; it is delivering that change over a channel an adversary cannot forge, because the update channel itself depends on cryptography. Once the deployed cryptography is broken, that channel can no longer be trusted.
QuBalt delivers crypto-agility through QURSUS, its Quantum- and Cryptanalysis-Secure Remote Software Update System, built on QuBalt's authentication core.
QURSUS authenticates each algorithm-replacement package with information-theoretic security, manages the replacement, and controls its installation on the device, so deployed algorithms can be replaced remotely, with no dependence on the cryptography being replaced. This is a higher level of security than the cryptography standardised today, in place throughout the mission and not only after a break.
Every algorithm-replacement package and the command that drives it carries an information-theoretically secure tag, so the device installs only what it can prove is genuine. This authentication is a core part of QURSUS, and it protects its software updates in the same way.
QURSUS is delivered as a building block that integrates into your existing systems, at both ends of the update path. Device-side, the QURSUS software stack and its pre-shared keys run on the deployed device. Operations-side, QURSUS runs as a software stack on the operations computer, fitting into the existing operations toolchain. QURSUS is validated to TRL 4 under the ESA GSTP programme and is adapted to each customer's specific requirements and hardware environment.
Truly random keys are consumed on use, so the key budget is provisioned before deployment, sized with margin to outlast the mission, monitored in operation, and fails secure if ever spent: the system stops authenticating rather than accept unverified traffic. Unlike systems that stay secure only by rekeying reusable keys over the air, QURSUS needs no such channel: its keys are one-time, and its authentication guarantee rests on no channel a future computer could break. Any replenishment is by offline transfer or one-time-pad-encrypted delivery, so it never weakens that guarantee.
Crypto-agility keeps a deployed system's cryptography current, so it stays cyber-resilient long after the algorithms it was fielded with are broken, and lets you refresh those algorithms on schedule in normal operation before any break. We bring this to the systems that must stay trustworthy for their entire operational lifetime:
Satellites, constellations, CubeSats, probes and rovers, ground stations, and their payloads that operate for years and can never be recalled.
Ships, missiles, remote sensors, wind turbines, and critical infrastructure deployed far from maintenance.
Cryptographic devices, communication modules, TPMs, HSMs, and QKD nodes that must stay mission-grade across a long fielded life.
For the deployed system, that means protection kept current and an asset kept in service:
For crypto-agility, the security basis is decisive: an update channel built on the same kind of cryptography it replaces cannot be trusted to deliver the fix once that cryptography is broken.
State-of-the-art update systems authenticate with digital signatures such as RSA and ECDSA, and the post-quantum standards, all standardised and all based on computational security: their security rests on a problem staying too hard to solve, an assumption that has never been proven. A quantum computer breaks RSA and ECDSA, while AI and new cryptanalysis may break the post-quantum standards too. QURSUS instead uses information-theoretic authentication: provably secure under its stated assumptions of truly random, single-use keys and a correct implementation, and independent of any attacker's computing power, now or in the future. That proof covers the authentication algorithm; full system security also rests on key management and implementation assurance.
QURSUS therefore rests on a different security basis, one that stays secure against quantum computers, AI, and future cryptanalysis, suited to protecting deployments throughout their entire operational life.
Whether you are fielding a satellite, a constellation, or a long-life critical-infrastructure asset, our team will work with you to plan crypto-agility that fits your platform and your threat model. Contact us to discuss your mission.