Keep every update provably genuine and the system current for its whole operational life, through a cryptographic break and normal operation alike, built on information-theoretically secure cryptography.
A mission-critical system must be kept current for its whole life, and every update it accepts has to be provably genuine, because a single forged update can take over or disable it. Today those updates are authenticated with standardised digital signatures such as RSA and ECDSA, based on computational hardness: a computational assumption, not a proof. A quantum computer breaks both of them, while AI and new cryptanalysis may break any computational scheme, the post-quantum signatures included, so the algorithm authenticating your updates has a limited lifetime.
QuBalt delivers secure remote software updates through QURSUS, its Quantum- and Cryptanalysis-Secure Remote Software Update System, built on QuBalt's authentication core.
QURSUS authenticates every update package with information-theoretic security, manages the updates, and controls their installation on the device, so the device installs only updates it can prove are genuine, and that guarantee does not weaken over the mission. It is a higher level of security than the cryptography standardised today, on every update in normal operation and not only after a break.
Every update package, and the command to apply it, carries an information-theoretically secure tag, so the device installs only what it can prove is genuine. This authentication is a core part of QURSUS, and it protects its crypto-agility in the same way.
QURSUS is delivered as a building block that integrates into your existing systems, at both ends of the update path. Device-side, the QURSUS software stack and its pre-shared keys run on the deployed device. Operations-side, QURSUS runs as a software stack on the operations computer, fitting into the existing operations toolchain. QURSUS is validated to TRL 4 under the ESA GSTP programme and is adapted to each customer's specific requirements and hardware environment.
Truly random keys are consumed on use, so the key budget is provisioned before deployment, sized with margin to outlast the mission, monitored in operation, and fails secure if ever spent: the system stops authenticating rather than accept unverified traffic. Unlike systems that stay secure only by rekeying reusable keys over the air, QURSUS needs no such channel: its keys are one-time, and its authentication guarantee rests on no channel a future computer could break. Any replenishment is by offline transfer or one-time-pad-encrypted delivery, so it never weakens that guarantee.
Secure remote software updates keep a deployed system's software current, so it stays cyber-resilient long after it is out of reach. We bring this to the systems that must stay trustworthy for their entire operational lifetime:
Satellites, constellations, CubeSats, probes and rovers, ground stations, and their payloads that operate for years and can never be recalled.
Ships, missiles, remote sensors, wind turbines, and critical infrastructure deployed far from maintenance.
Cryptographic devices, communication modules, TPMs, HSMs, and QKD nodes that must stay mission-grade across a long fielded life.
For the deployed system, QURSUS keeps mission-critical software current and provably authentic for the whole mission:
For mission-critical updates, the security basis decides how long every update stays provably genuine: authentication that weakens over the mission eventually lets a forged one through.
State-of-the-art update systems authenticate with digital signatures such as RSA and ECDSA, and the post-quantum standards, all standardised and all based on computational security: their security rests on a problem staying too hard to solve, an assumption that has never been proven. A quantum computer breaks RSA and ECDSA, while AI and new cryptanalysis may break the post-quantum standards too. QURSUS instead uses information-theoretic authentication: provably secure under its stated assumptions of truly random, single-use keys and a correct implementation, and independent of any attacker's computing power, now or in the future. That proof covers the authentication algorithm; full system security also rests on key management and implementation assurance.
QURSUS therefore rests on a different security basis, one that stays secure against quantum computers, AI, and future cryptanalysis, suited to keeping deployments patchable throughout their entire operational life.
Whether you are updating a satellite payload, a remote sensor fleet, or a critical-infrastructure controller, we can scope a provably authentic update path around your hardware, operations, and compliance constraints. Talk to our team about your programme.