Skip to content

What is Quantum Helix?

Quantum Helix (QHx) is a workload identity and post-quantum-safe secure communications solution which can be installed on any standard Kubernetes cluster, whether on-premises or in the cloud.

Quantum Helix is based around the following premises:

  • Workload identity. All workloads in the compute environment (for example, a Kubernetes pod) should be bound to a unique, cryptographically verifiable identity.

  • Secure inter-workload communication. Communications between workloads such as Kubernetes pods should be secured based on those workload identities, meaning that every compute payload in a Kubernetes environment communicates securely with the clients which depend on it and on the services on which it depends in turn. Every compute payload knows what it is connected to, and this identity is verified.

  • Transparency, compatibility and ease of adoption. Wherever possible, securing communications between workloads should be done transparently to an application so as to minimise the need for application changes. This allows existing applications to take advantage of the security advantages provided by QHx without requiring modification.

Quantum Helix facilitates its goal of ease of adoption by providing application-specific protocol modules (ASPMs) which provide intermediation and optional policy controls for common application protocols such as HTTP.

This enables workloads which already support those protocols to communicate with peers in a way that is secured in a way which is transparent to the application, avoiding the need for application changes or or the cost of spending engineer time on retrofitting applications.

This enables existing applications to take advantage of post-quantum-safe secure communications without requiring application modification or expertise in post-quantum-safe cryptography.

Contemporary cloud and Kubernetes environments provide the infrastructure for scheduling workloads, and provide network fabrics which enable those workloads to communicate with one another within a cluster. While these network fabrics (such as contemporary Kubernetes CNIs or hyperscaler networking solutions such as AWS VPC) are highly sophisticated in their own right, they do not provide the tools to facilitate secure, end-to-end encrypted communication between workloads in a way that is cryptographically bound to a workload identity.

QHx is predicated on a belief that workloads — whether that means east-west communications within a cluster of microservices, or communications between workloads in different clusters entirely — should be secured by default, and in a way that is secure, encrypted, post-quantum safe, and identity bound based on strong, unforgeable identities.

Securing that traffic by default means delivering on that vision without requiring application modificatoin or bespoke integrations. Every application, whether a proprietary solution specific to your use case, or an unmodified piece of common, off the shelf (COTS) open source software (OSS), should be able to take advantage of a secure workload communications fabric in cloud and on-premises environments.