Home/Technology/Aegis Defence
Framework · Cryptography

Aegis Defence

The quantum-resistant cryptographic layer of the Enkidu stack — hybrid post-quantum key establishment, quantum-resistant signatures, and fleet-wide crypto-agility. Enforced by Origi, operated by Helios Grid.

Aegis Defence
Hybrid
By default — classical + PQC on every link
NIST-final
FIPS 203 · 204 · 205 — standards only
Reserve
A backup on different mathematics, always
2031
Canada's high-priority migration deadline
The threat

Not a future problem. A present recording problem.

Every promise the Enkidu stack makes rests, in the end, on cryptography: Origi's chain of custody is signatures, Helios's artifact admission is signatures, every mesh link and reachback spoke is a key exchange. Against a cryptanalytically relevant quantum computer, today's public-key primitives break outright — and the harvest now, decrypt later attack means traffic recorded off a link today can be read retroactively the day such a machine exists. For a fabric carrying Protected B data with multi-decade sensitivity, the adversary needs no quantum computer now — only patience and storage.

The urgency is asymmetric: a signature forged in the future does not falsify the past, but a key exchange broken in the future retroactively exposes everything it protected. That is why Aegis's first wave is hybrid key establishment on links — and why the mandate horizon is not the quantum computer's arrival date, but the recording adversary's patience, subtracted from your data's lifetime.

    What it provides
  • Hybrid post-quantum key establishment on every link
  • Quantum-resistant signatures on every artifact & custody record
  • A hash-based-signed boot chain — the root of the argument
  • Crypto-agility as a fleet operation, not a rebuild
  • Compliance evidence generated from the fleet itself
Position in the stack

The fourth framework — the substance of the other three

Aegis is not a new plane of components; it is the cryptographic substance of the planes that exist. Origi's secured links, custody chain, and admission checks are Aegis algorithms; Helios's identities, signed desired state, and signed runbooks are Aegis signatures. Aegis defines the suite and the change discipline; Origi enforces them at every boundary; Helios distributes them to every node.

Structure
Tangram

Where does work happen, and under what boundary conditions?

Trust
Origi

May this action happen, and can we prove what happened?

Operations
Helios Grid

Is the fabric healthy, current, and recoverable?

Cryptography
Aegis Defence

Will every key, signature, and link still hold when the adversary has a quantum computer?

What Aegis is not: no key escrow, no bespoke primitives, no unstandardised algorithms, no cryptography invented in-house. Its value is disciplined selection, correct binding, and operable migration — not novelty. In cryptography, novelty is risk.

The suite

One primary, one reserve — per function

Finalised NIST standards, deployed in hybrid constructions, with a designated backup on different mathematics behind every primary — so a cryptanalytic surprise is a policy flip, not a crisis program.

Function
Primary
Reserve
Key establishment
Hybrid X25519 + ML-KEM-768
ML-KEM-1024 at the defence ceiling
HQC — code-based, non-lattice
Signatures — custody, telemetry, verdicts
ML-DSA-65
ML-DSA-87 at the defence ceiling
SLH-DSA — hash-based
Signatures — firmware & boot chain
LMS (SHA-256) · XMSS
Verify-only builds on constrained nodes
Symmetric & hashing
AES-256-GCM · SHA-384/512 · SHA-3
Sized, not replaced — Grover answered by key size
Certificates / PKI
ML-DSA chains · hybrid in transition
Classical chains tunnelled until withdrawn

Profiles: the standard profile follows NIST Level 3 and Cyber Centre guidance for Protected B; the defence ceiling follows CNSA 2.0. FN-DSA (Falcon) is tracked for the most bandwidth-starved links once FIPS 206 finalises. And no algorithm outside the NIST process appears at all.

The layer architecture

Four binding points, zero new components

Aegis is a substitution of cryptographic substance, not an addition of moving parts. It changes what every existing handshake, signature, and boot check is made of.

Links

Every mesh link, reachback spoke, and control channel: TLS/DTLS 1.3 with hybrid X25519+ML-KEM groups, hybrid SSH for administration. The recording adversary gains nothing.

Identity

Node, hub, and operator certificates move to ML-DSA chains — hybrid during transition so a fleet mid-migration interoperates without downgrade ambiguity. Hardware-rooted keys where the tier supports them.

Integrity

Custody records, telemetry, and every registry artifact ML-DSA-signed; base-system artifacts dual-signed with LMS. Verification runs at the last trust boundary before use — a compromised cache can deliver nothing a node will accept.

Boot

A quantum-resistant fabric booted by a quantum-forgeable loader is a contradiction. The boot chain is LMS/XMSS-signed — the slot that fails Aegis verification is the slot that never boots.

Crypto-agility

Changing cryptography
is a rollout, not a program.

The active suite is declared per fleet segment in a signed, versioned crypto-policy artifact, distributed by Helios Grid exactly like a model: staged waves, health gates, automatic rollback, full custody. Flipping a fleet from ML-KEM-768 to ML-KEM-1024 — or, in the surprise scenario, from lattices to codes — is an operations task.

The fleet's Cryptographic Bill of Materials is a query over Helios node twins, not a manual audit — the compliance evidence for every mandate milestone. And deprecation is enforced to the strict standard: a vulnerable algorithm is first non-default, then tunnelled, then removed from the build — so "prove RSA is gone" is answered from the record.

The cost, budgeted

PQC's tax is bytes,
not cycles.

A hybrid handshake costs tens of microseconds of compute but kilobytes of bandwidth — so Aegis budgets bytes explicitly: long-lived, resumed sessions amortise handshakes across hours; hubs verify node signatures locally and forward hub-signed aggregates, so per-node signatures never transit the reachback link individually — composing exactly with Helios's signal-not-data reduction.

Compute concentrates where the fabric's compute already is: ARM-optimised embedded PQC on the node and hub tiers; GPU-accelerated batched verification (cuPQC-class, millions of operations per second) at the fusion-centre tiers. And a definite position: no QKD on this fabric — special-purpose optics, unfit for tactical topologies, no authentication, and excluded by allied national-security guidance.

The mandates

The standards are final.
The clock is running.

NIST finalised the post-quantum standards in August 2024; the allied mandates set the schedule. A fabric fielded for Canadian defence sits under the strictest reading of all three — so Aegis takes CNSA 2.0 parameters as the ceiling profile and ITSM.40.001 as the binding schedule. Aegis exists so that Northwind never ships a quantum-vulnerable link in the first place.

The mandate clock
Aug 2024FIPS 203 / 204 / 205 finalised (NIST)
Apr 2026GC migration plans due (ITSM.40.001)
End 2031High-priority systems migrated (Canada)
Early 2030sCNSA 2.0 product-class deadlines (NSA)
End 2035Full migration (Canada · U.K.)
Enkidu

What you encrypt today is already at stake

Book a briefing — we'll walk your data lifetimes against the mandate clock and show a crypto-policy rollout crossing its health gates.

Request a briefingTalk to the teamDownload the architecture ↓