Skip to content

What is Quantum Helix?

Quantum Helix (QHx) is a lightweight workload identity, policy enforcement, and post-quantum secure communications technology that can be deployed across arbitrary compute environments and workload types.

Kubernetes provides the most complete managed deployment model, with full-service orchestration, operational control, and ease of use. However, the core QHx capabilities are not limited to Kubernetes and can be applied in narrower or more tailored forms across bare metal, edge systems, legacy services, and other non-cloud-native environments.

Quantum Helix is based around the following premises:

  • Workload identity. All workloads in the compute environment (for example, a Kubernetes pod) should be bound to a unique, cryptographically verifiable identity.

  • Secure inter-workload communication. Communications between workloads such as Kubernetes pods should be secured based on those workload identities, meaning that every compute payload in a Kubernetes environment communicates securely with the clients which depend on it and on the services on which it depends in turn. Every compute payload knows what it is connected to, and this identity is verified.

  • Transparency, compatibility and ease of adoption. Wherever possible, securing communications between workloads should be done transparently to an application so as to minimise the need for application changes. This allows existing applications to take advantage of the security advantages provided by QHx without requiring modification.

Quantum Helix facilitates its goal of ease of adoption by providing application-specific protocol modules (ASPMs) which provide intermediation and optional policy controls for common application protocols such as HTTP.

This enables workloads which already support those protocols to communicate with peers in a way that is secured in a way which is transparent to the application, avoiding the need for application changes or or the cost of spending engineer time on retrofitting applications.

This enables existing applications to take advantage of post-quantum-safe secure communications without requiring application modification or expertise in post-quantum-safe cryptography.

Contemporary cloud and Kubernetes environments provide the infrastructure for scheduling workloads, and provide network fabrics which enable those workloads to communicate with one another within a cluster. While these network fabrics (such as contemporary Kubernetes CNIs or hyperscaler networking solutions such as AWS VPC) are highly sophisticated in their own right, they do not provide the tools to facilitate secure, end-to-end encrypted communication between workloads in a way that is cryptographically bound to a workload identity.

QHx is predicated on a belief that workloads — whether that means east-west communications within a cluster of microservices, or communications between workloads in different clusters entirely — should be secured by default, and in a way that is secure, encrypted, post-quantum safe, and identity bound based on strong, unforgeable identities.

Securing that traffic by default means delivering on that vision without requiring application modification or bespoke integrations. Every application, whether a proprietary solution specific to your use case, or an unmodified piece of common, off the shelf (COTS) open source software (OSS), should be able to take advantage of a secure workload communications fabric in cloud and on-premises environments.