Quantum NetworkQuantum Network

The solution

Two gateways. One encrypted line. Nothing else changes.

One at each end of the connections that matter. An active subscription keeps the algorithms current on the same hardware.

Two gateways. One encrypted line. Nothing else changes.

01 · What changes, what stays

Your routing stays. Your design stays. The encryption wraps around both.

The gateway is added to your network, not swapped into it. A site running hardware too old for your vendor’s latest firmware becomes quantum-safe without replacing that box. Your team keeps the routing and the network design it already has.

What you keep

Your central firewall keeps doing deep packet inspection and anti-virus on the traffic it can read.

QPN encrypted traffic cannot be inspected, so the gateway goes in front of the firewall when that inspection has to stay.

Your switches, cabling and network design stay as they are. The gateway sits alongside them, so rip-and-replace is not necessary.

What you add

Quantum-safe encryption on the connections you choose, in two layers: classical and post-quantum.

If one of the two algorithms is later broken, the other layer keeps protecting the traffic and you switch to another algorithm on the same hardware.

ML-KEM and Classic McEliece are already in the product.

What you never do again

Rip out working equipment because the cryptography moved on.

The next algorithm is already in the product. Switching to it is a configuration change on the same hardware, not a purchase order.

A switch done by hand costs up to two minutes of interruption per site, or a few seconds through the command line.

Settings panel for choosing the post-quantum encryption algorithm, with ML-KEM active and Classic McEliece and FrodoKEM available, and a confirmation that the algorithm was updated across ten endpoints

02 · Built for the day algorithms change

Replace the post-quantum algorithm without changing your infrastructure.

The gateway is crypto-agile by design. Protection runs in two independent layers: a classical handshake and a post-quantum handshake, with the NIST-standardised ML-KEM and the ISO-standardised Classic McEliece in the standard product. When standards evolve, you choose the new algorithm in the product and apply it. That is a configuration change, not a migration project.

Never worse off

Two independent layers, post-quantum next to proven classical encryption. If one is broken the other still protects the traffic, and you switch to another algorithm on the same hardware. Risk does go up once half the cryptography is broken, which is why switching has to be simple.

Authentication included

Peers authenticate each other with static Curve25519 public keys. Without a valid quantum public key exchange during setup and a regular valid quantum session key exchange, the connection cannot be established.

03 · Security properties

Seven security properties on every QPN connection

ChaCha20-Poly1305Confidentiality

What your site is doing stays between the site and the control room. Setpoints, levels, meter readings and camera feeds are not readable by anyone on the line.

All payload traffic inside the connection is encrypted with ChaCha20-Poly1305. The networks at both ends are not exposed to the internet.

Poly1305 tagsIntegrity

A command arrives as it was sent, or it does not arrive at all. A packet altered in transit is discarded instead of executed.

Every packet carries a cryptographic seal that proves it was not modified in transit (Poly1305 authentication tags).

Curve25519Authenticity

The gateway only talks to peers it already knows. A device that appears on the path and claims to be your control room is dropped immediately.

Both ends prove their identity to each other with pre-installed keys (static Curve25519 public keys).

Ephemeral session keysForward secrecy

A key exposed in three years does not open the traffic you sent last year. In an estate where hardware is swapped and decommissioned, that matters.

Each connection gets its own short-lived key that is never reused (unique ephemeral session keys from an asymmetric handshake).

Monotonic counterReplay protection

A recorded valid command cannot be sent again later. Duplicated packets are rejected, so a captured instruction is not a reusable one.

Each packet carries a number that must always increase, so a recorded packet sent again is recognized and rejected (monotonic counter check per session, stateful handshake design).

Noise_IKMan in the middle resistance

Nobody can insert themselves between the control room and the site and quietly pass traffic through. There is no silent relay position on the link.

The key exchange itself is authenticated, so an unknown party can never join it (the Noise_IK handshake framework).

ML-KEM or Classic McElieceHarvest now, decrypt later resistance

A recording made today does not become readable later.

The public key exchange that would make a stored recording readable later is replaced by quantum-resistant mathematics.

04 · From order to live

Hours of work, not a migration project.

The cloud side is a virtual machine in your own data centre or cloud, with an internal and an external network card, running the same web interface as the gateways at your sites.

After that it is one visit per site, set up from a laptop.

30minPer site, on siteGive or take, depending on your environment and on how well your team knows its own addressing.
MinutesOf downtimeDowntime is only needed when the gateway replaces equipment that requires reconfiguring networks or clients. Then it is typically a few minutes.
Internal portYour own networkExternal portThe link between sitesGatewayencryptedGreen when the connection is livePower

From order to live

  1. 01Order placed.
  2. 02Optional: we load a connection profile for each edge gateway.
  3. 03On site, connect the external port, the internal port and power.
  4. 04With a profile loaded it connects by itself, otherwise from a laptop.
  5. 05Green LED on the front. The connection is live.

What we prepare

The cloud gateway, the routing parameters and, when you want it, a connection profile loaded in the factory for each edge gateway, so the unit connects by itself when it is installed on site.

What your team does

Place the unit, connect the external and internal port, connect power. The gateway starts by itself and restarts by itself after a power failure.

How you know it works

A green LED on the front when a connection is live, and a dashboard showing the algorithm in use and both handshake timers renewing every two minutes.

05 · The boundary

It secures your data in transit. Your firewall keeps guarding what is inside.

Quantum Gateway

The Quantum Gateway has one job: protecting the data that travels between your own endpoints, today and against future quantum computers.

Your existing security

Security inside your network stays with the systems you already run. Web filtering, email malware scanning and antivirus remain on your central firewall, which the gateway works alongside. Compromised devices behind the gateway and denial of service attacks are outside its task.

Upgrade to quantum-safe protection

See which gateways you need and where they go, in a few questions.

Answer a few questions about your locations and connections. You see an indicative configuration straight away: which gateways, and where they sit in your existing network.

Manage risk. Reduce your exposure.

No contact details needed to see your configuration.

Rather talk it through? Book a 30-minute call

Public internet now quantum-safeAny public networkQUANTUM GATEWAYControl sideQUANTUM GATEWAYField sideCONTROL CENTEROperators and SCADAYOUR SITEPLCs, sensors, cameras
Copyright 2026 - All rights reserved - Quantum NetworkKnowledge-base