The quantum-resistant cryptographic layer of the Enkidu stack — hybrid post-quantum key establishment, quantum-resistant signatures, and fleet-wide crypto-agility. Enforced by Origi, operated by Helios Grid.
Every promise the Enkidu stack makes rests, in the end, on cryptography: Origi's chain of custody is signatures, Helios's artifact admission is signatures, every mesh link and reachback spoke is a key exchange. Against a cryptanalytically relevant quantum computer, today's public-key primitives break outright — and the harvest now, decrypt later attack means traffic recorded off a link today can be read retroactively the day such a machine exists. For a fabric carrying Protected B data with multi-decade sensitivity, the adversary needs no quantum computer now — only patience and storage.
The urgency is asymmetric: a signature forged in the future does not falsify the past, but a key exchange broken in the future retroactively exposes everything it protected. That is why Aegis's first wave is hybrid key establishment on links — and why the mandate horizon is not the quantum computer's arrival date, but the recording adversary's patience, subtracted from your data's lifetime.
Aegis is not a new plane of components; it is the cryptographic substance of the planes that exist. Origi's secured links, custody chain, and admission checks are Aegis algorithms; Helios's identities, signed desired state, and signed runbooks are Aegis signatures. Aegis defines the suite and the change discipline; Origi enforces them at every boundary; Helios distributes them to every node.
Where does work happen, and under what boundary conditions?
May this action happen, and can we prove what happened?
Is the fabric healthy, current, and recoverable?
Will every key, signature, and link still hold when the adversary has a quantum computer?
What Aegis is not: no key escrow, no bespoke primitives, no unstandardised algorithms, no cryptography invented in-house. Its value is disciplined selection, correct binding, and operable migration — not novelty. In cryptography, novelty is risk.
Finalised NIST standards, deployed in hybrid constructions, with a designated backup on different mathematics behind every primary — so a cryptanalytic surprise is a policy flip, not a crisis program.
Profiles: the standard profile follows NIST Level 3 and Cyber Centre guidance for Protected B; the defence ceiling follows CNSA 2.0. FN-DSA (Falcon) is tracked for the most bandwidth-starved links once FIPS 206 finalises. And no algorithm outside the NIST process appears at all.
Aegis is a substitution of cryptographic substance, not an addition of moving parts. It changes what every existing handshake, signature, and boot check is made of.
Every mesh link, reachback spoke, and control channel: TLS/DTLS 1.3 with hybrid X25519+ML-KEM groups, hybrid SSH for administration. The recording adversary gains nothing.
Node, hub, and operator certificates move to ML-DSA chains — hybrid during transition so a fleet mid-migration interoperates without downgrade ambiguity. Hardware-rooted keys where the tier supports them.
Custody records, telemetry, and every registry artifact ML-DSA-signed; base-system artifacts dual-signed with LMS. Verification runs at the last trust boundary before use — a compromised cache can deliver nothing a node will accept.
A quantum-resistant fabric booted by a quantum-forgeable loader is a contradiction. The boot chain is LMS/XMSS-signed — the slot that fails Aegis verification is the slot that never boots.
The active suite is declared per fleet segment in a signed, versioned crypto-policy artifact, distributed by Helios Grid exactly like a model: staged waves, health gates, automatic rollback, full custody. Flipping a fleet from ML-KEM-768 to ML-KEM-1024 — or, in the surprise scenario, from lattices to codes — is an operations task.
The fleet's Cryptographic Bill of Materials is a query over Helios node twins, not a manual audit — the compliance evidence for every mandate milestone. And deprecation is enforced to the strict standard: a vulnerable algorithm is first non-default, then tunnelled, then removed from the build — so "prove RSA is gone" is answered from the record.
A hybrid handshake costs tens of microseconds of compute but kilobytes of bandwidth — so Aegis budgets bytes explicitly: long-lived, resumed sessions amortise handshakes across hours; hubs verify node signatures locally and forward hub-signed aggregates, so per-node signatures never transit the reachback link individually — composing exactly with Helios's signal-not-data reduction.
Compute concentrates where the fabric's compute already is: ARM-optimised embedded PQC on the node and hub tiers; GPU-accelerated batched verification (cuPQC-class, millions of operations per second) at the fusion-centre tiers. And a definite position: no QKD on this fabric — special-purpose optics, unfit for tactical topologies, no authentication, and excluded by allied national-security guidance.
NIST finalised the post-quantum standards in August 2024; the allied mandates set the schedule. A fabric fielded for Canadian defence sits under the strictest reading of all three — so Aegis takes CNSA 2.0 parameters as the ceiling profile and ITSM.40.001 as the binding schedule. Aegis exists so that Northwind never ships a quantum-vulnerable link in the first place.
Book a briefing — we'll walk your data lifetimes against the mandate clock and show a crypto-policy rollout crossing its health gates.