Saturday 30 May, 2026
[email protected]
Resilience Media
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
  • News
    • Events
    • Interview
    • Startups
    • Venture
    • Weekly Digest
  • Resilience Conference
    • Resilience Conference Warsaw 2026
    • Resilience Conference Copenhagen 2026
    • Resilience Conference London 2026
  • About
  • Guest Posts
    • Author a Post
  • Subscribe
No Result
View All Result
Resilience Media
No Result
View All Result

Signal Steps up to the Post-Quantum Battlefield with Hybrid Cryptographic Ratchet

Signal has unveiled a new post-quantum cryptographic ratchet designed to safeguard against future ‘harvest now, decrypt later’ attacks

Resilience MediabyResilience Media
October 6, 2025
in Startups
Photo by Markus Spiske on Unsplash

Photo by Markus Spiske on Unsplash

Share on Linkedin

The Signal Foundation has unveiled a new cryptographic ratchet scheme called the Sparse Post-Quantum Ratchet (SPQR), a major step toward shielding its protocol suite from the future threat of quantum computing.

You Might Also Like

Hermeus logs first supersonic flight for the uncrewed Quarterhorse Mk 2.1 jet

Quaze deal gives Red Cat wireless power for drones and robots

New cameras from Odd Systems are making drones faster, smarter, and more accurate

The Signal Protocol – long seen as the gold standard for end-to-end encrypted messaging across civilian, military and government use – currently relies on a “Double Ratchet” design, in which symmetric-key updates and elliptic-curve Diffie-Hellman (ECDH) exchanges secure message streams. While the hash functions it uses remain safe from quantum attacks, ECDH would be vulnerable to a powerful enough quantum computer.

To tackle that risk, Signal previously added PQXDH, a hybrid handshake that introduces quantum-resistant key exchange when a session begins, blocking “harvest now, decrypt later” tactics. SPQR takes that protection further by adding a post-quantum ratchet that runs continuously throughout a conversation, not just at setup.

The new design combines state machine logic, erasure-code chunking, and hybrid key derivation, ensuring that each message refreshes shared secrets in a manner that resists both backwards and forward compromise – even if an attacker later gains access to one side’s device. In effect, Signal now has a “Triple Ratchet”: the existing Double Ratchet runs alongside the SPQR ratchet, with both outputs combined through a key derivation function. An adversary would have to break both the classical and quantum-resistant layers to read any messages.

Balancing this new protection with performance has been a challenge. Quantum-safe key encapsulation mechanisms (KEMs) produce larger ciphertexts and require precise message ordering – a poor fit for the messy, asynchronous reality of internet messaging, where packets can be delayed or dropped. Signal’s solution uses erasure coding, which splits large cryptographic blobs into smaller chunks, only some of which need to arrive to reconstruct the data. This tolerates network hiccups and even limited interference, though an attacker blocking most chunks would cause a visible denial-of-service rather than a silent failure.

Signal’s engineers also explored different state-machine strategies for deciding which side should send key material at any moment. Their simulations showed that some faster, parallel key-generation methods created unacceptable exposure if one device were briefly compromised; therefore, the final design takes a more cautious, serial approach.

Because many users and devices won’t support SPQR immediately, Signal is deploying it with a fallback: sessions can temporarily “downgrade” to the older ratchet when necessary. But crucially, once a conversation starts in SPQR mode, an attacker can’t force it back to classical mode mid-session. Over time, as users upgrade, older sessions will be phased out.

The design is grounded in formal, peer-reviewed cryptography. Academic and industry partners, including PQShield, AIST, and NYU, used ProVerif models to validate its properties, and Signal’s Rust implementation is directly linked to those proofs. Code is also translated into F* using the “hax” toolchain for further verification, ensuring the implementation matches its mathematical design.

For defence, intelligence, and government users, SPQR has clear implications. It shows that mainstream secure-messaging platforms are already preparing for a post-quantum future, and legacy systems in military or diplomatic contexts will need to do the same. It also raises transitional questions for coalition networks or cross-domain messaging tools that interoperate with Signal, as well as for adversaries hoping to stockpile today’s encrypted traffic for future decryption.

SPQR and the broader Triple Ratchet architecture are not cure-alls. Their strength depends on flawless implementation, complete rollout, and the continuing resilience of the underlying KEMs. Quantum-safe cryptography is still evolving, and future advances could shift the landscape again. But Signal’s move demonstrates a serious, technically rigorous commitment to keeping communications secure under even the harshest future threat models.

In short, SPQR strengthens Signal without reinventing it. It’s a careful upgrade that brings post-quantum defences into one of the world’s most widely trusted encryption protocols – and a sign that the race to quantum-harden secure systems is already well underway.

Tags: Signal
Previous Post

Force Multipliers: Why National Security and Defence Veterans Can Excel in European Venture

Next Post

Helsing Acquires Blue Ocean to Rev Up Its Marine Business

Resilience Media

Resilience Media

Start Ups. Security. Defense.

Related News

Hermeus logs first supersonic flight for the uncrewed Quarterhorse Mk 2.1 jet

Hermeus logs first supersonic flight for the uncrewed Quarterhorse Mk 2.1 jet

byJohn Biggs
May 29, 2026

Atlanta-based Hermeus announced that its Quarterhorse Mk 2.1 experimental aircraft has completed its first supersonic flight, reaching Mach 1.21 during...

Quaze deal gives Red Cat wireless power for drones and robots

Quaze deal gives Red Cat wireless power for drones and robots

byJohn Biggs
May 27, 2026

Red Cat Holdings has acquired Québec-based Quaze Technologies, adding wireless charging capability to its growing portfolio of autonomous systems. The...

New cameras from Odd Systems are making drones faster, smarter, and more accurate

New cameras from Odd Systems are making drones faster, smarter, and more accurate

byJohn Biggs
May 27, 2026

https://youtu.be/-uqLiaA65Pk   Ukrainian defence startup Odd Systems is building a line of mission-specific camera systems designed for drones operating in...

Corsair is a 24' Autonomous Surface Vessel capable of carrying up to 1,000 lbs over 1,000 NM.

The sea change in defence tech

byPaul Sawers
May 20, 2026

Warships are expensive, slow to build, and difficult to replace. At the same time, navies are being pushed to patrol...

Helsing, on the cusp of a $1.2B raise, forms space JV with OHB to build AI-based targeting systems

Helsing, on the cusp of a $1.2B raise, forms space JV with OHB to build AI-based targeting systems

byIngrid Lunden
May 19, 2026

Helsing, the European defence tech startup on the cusp of closing a $1.2 billion funding round at an $18 billion...

UK AI chip challenger Fractile secures $22.5M from NATO-backed venture fund

Fractile raises $220 million to build powerful AI chips

byJohn Biggs
May 16, 2026

UK AI hardware startup Fractile has raised $220 million in funding to build so-called "AI inference chips," specially designed chips...

person holding pencil near laptop computer

Multiverse raises $70M to help future-proof workforces in areas like AI

byIngrid Lunden
May 15, 2026

A UK company that has built a platform to help train people and organisations to future-proof them against technology evolutions...

SFC Energy AG contracted to supply field batteries to Ukraine

SFC Energy AG contracted to supply field batteries to Ukraine

byJohn Biggs
May 14, 2026

German fuel cell maker SFC Energy AG has received a €42.7 million order to supply “combat-proven” hybrid energy supply systems...

Load More
Next Post
Helsing Acquires Blue Ocean to Rev Up Its Marine Business

Helsing Acquires Blue Ocean to Rev Up Its Marine Business

Dispatches from Finland – Defence Tech Meetup 2025

Dispatches from Finland - Defence Tech Meetup 2025

Most viewed

InVeris announces fats Drone, an integrated, multi-party drone flight simulator

Uforce raises $50M at a $1B+ valuation to build defence tech for Ukraine

Auterion, the drone software startup, eyes raising $200M at a $1.2B+ valuation

Palantir and Ukraine’s Brave1 have built a new AI “Dataroom”

Twentyfour Industries emerges from stealth with $11.8M for mass-produced drones

Senai exits stealth to help governments harness online video intelligence

Resilience Media is an independent publication covering the future of defence, security, and resilience. Our reporting focuses on emerging technologies, strategic threats, and the growing role of startups and investors in the defence of democracy.

  • About
  • News
  • Resilence Conference
    • Resilience Conference Copenhagen 2026
    • Resilience Conference Warsaw 2026
    • Resilience Conference 2026
  • Guest Posts
  • Subscribe
  • Privacy Policy
  • Terms & Conditions
  • Mission Statement & Code of Practice
  • Press

© 2026 Resilience Media

No Result
View All Result
  • Home
  • About
  • Subscribe
  • Events
  • Guest Posts
  • Interview
  • News
  • Resilience Conference London 2026
  • Resilience Conference Copenhagen 2026
  • Resilience Conference Warsaw 2026

© 2026 Resilience Media

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.