A post-quantum secure channel, containment for untrusted and AI-generated code, and encrypted storage, tested against an adversary who records everything today and may hold a quantum computer later.
For quantum sensors this matters because navigation and defence sensor data is exactly what an adversary would record today to decrypt later.
Shor’s algorithm, run on a large quantum computer, solves the factoring and discrete-logarithm problems that RSA, Diffie–Hellman and elliptic-curve cryptography rest on.1 Those are the methods most links use to agree on a key.
Traffic recorded today can be decrypted once a large quantum computer exists. An adversary only has to copy the ciphertext now and keep it. This is called harvest now, decrypt later.
Navigation and defence sensor data stays sensitive for years: routes, positions, gravity maps of where a vessel has been. Data that must stay secret for longer than the migration will take is exposed already.
Post-quantum standards were published in 2024: NIST’s FIPS 203 (ML-KEM) for key encapsulation, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures.2 Governments have set migration deadlines.
The core. A classical and a standardised post-quantum key exchange in every session, and both kinds of signature. Authenticated encryption, forward secrecy and key renewal.
An optional layer: files of any size in bounded memory. Truncation, reordering, splicing and substitution are refused.
Runs untrusted or AI-generated code in a confined process. Every capability request is checked against a policy, and confinement is verified against the operating system, never taken from the code’s own report.
Per-record keys, identity binding, a tamper-evident history, equality-only search tokens and rotatable keys. Restoring an old but authentic record, such as a revoked privilege, is detected.
Pools many sources behind authentication and quality gates, and every output also draws fresh operating-system randomness.
Varies its own configuration per installation and over time, never below a minimum level of filtering, so reconnaissance against one installation does not describe another.
Decoy ports, channels and credentials that no legitimate user touches. A trip raises a high-signal alarm and can block the source and renew keys.
| Common alternatives | BlackPhantom | |
|---|---|---|
| The connection | A dedicated secure link or trusted relays; quantum key distribution needs its own fibre or satellite link | A direct connection over an ordinary, unsecured network |
| Keys in advance | Pre-shared keys delivered to both ends before they can talk | None. The key is agreed during the handshake |
| Hardware | Quantum key distribution terminals, security appliances or hardware modules | Software only, with no extra hardware |
| Key lifetime | Long-lived keys kept on the device | Session keys disposed after use |
9 security properties of the handshake proven by a symbolic prover under an active network attacker: secrecy, authentication, key agreement, harvest-now-decrypt-later resistance and forward secrecy. Two deliberately broken controls fail as they must, which shows the post-quantum half really carries the session.
1,705 external known-attack vectors from Project Wycheproof: 0 failures.
203,000 fuzzed inputs: 0 uncontrolled failures.
1,116,000 messages at 55,772 per second: 0 failures; memory grew by 0.1 MB.
14 adversary techniques from a public tactics catalogue run inside containment during a live encrypted transfer: all confined; 3,005 of 3,005 messages delivered intact; no plaintext leaked.
Randomness. 3 sources pass all 6 NIST SP 800-22 tests; a deliberately biased control fails all 6, as it must. With an attacker in total control of the pool’s internal state, all 200 outputs were still unique and uniform.
Code. 188 automated tests; 85 % coverage of the shipped security code (99 % on the encryption core); 0 high-severity static-analysis findings. A second, separately written battery of 38 checks: 0 bypasses.
Tested against a quantum-capable, state-level adversary model; no known weakness found at the cryptographic and implementation level.
1. P. W. Shor, polynomial-time algorithms for prime factorisation and discrete logarithms on a quantum computer (1994).
2. NIST, FIPS 203, FIPS 204 and FIPS 205, published August 2024.
The x + y > z framing follows Michele Mosca’s inequality.