Post-quantum cryptography

Attacks on a cipher begin from a structure that holds still.
We build ciphers that are assembled as they run.

For systems where a compromise cannot be allowed to spread: sovereign networks, regulated operators, infrastructure that cannot extend trust to every machine it runs on.

Ousia SA · Geneva, Switzerland

The approach

A theory of cognition and language, and what it produced.

The work began outside cryptography, in a programme on how generative processes produce observable form: semiotics, category theory, the geometry of interactions. What it produced was a class of functions where the path taken decides what happens next.

Cryptography turned out to be where that mattered, and the people who might have found it were looking elsewhere. That it would make a good cipher was clear early. How good was not.

  1. 2017

    Ousia SA founded in Geneva.

  2. 2017–2018

    The theory formalised.

  3. 2019–2020

    A cipher built. The patent filed in October 2019, published as US 2022/0382521 A1 and readable today.

  4. 2020–2026

    The single cipher became a class.

    • The class established in theorems.
    • Every bound derived and priced, with the condition it rests on named.
    • Forty classes of attack worked through, across classical, quantum and side-channel models.
    • New classes of attack devised against it. A fixed-structure cipher never faces them, so nobody had written them. Each one found is why the next version was stronger.

That work is complete.

The claim

Under complete compromise of the machine, the key holds.

Memory and registers included: cold boot, a hypervisor snapshot, a hostile host, a neighbour in shared tenancy. The compromise stops at the session being watched: other sessions stay closed, and traffic recorded earlier does not become readable: the harvest-now-decrypt-later case.

A machine may also be watched: power analysis, timing, emissions. The same structure answers. That analysis isolates a fragment of the key behind each leaked value; here there is no fragment to isolate, because what determines each step is the whole history that produced it. The setup that consumes the key is a conventional target, and is protected as one.

Sessions protected by one key, after a complete capture of the machine.

The decision

One decision, and what follows from it.

The structure is not fixed in advance. It is assembled as the message is read.

Everything below follows from that. None of it is bolted on afterwards.

A secure channel needs Conventionally Here
EncryptionA block cipher and a modeThe construction
Message authenticationA separate MACBuilt in
Ordering, anti-replayRecord-layer counters and windowsBuilt in
Key derivationA separate derivation stepThe construction is its own
Padding, framingProtocol-specificNot needed
Side-channel resistanceMasking, added around the cipher Built in
Key agreement, peer identityCertificates and an authority chain Not covered

Once certification supports deployment, the construction replaces the cipher suite and the key-derivation step in an existing stack, and the protocol above it does not change. Some deployments already run without public-internet certificate authorities: pre-shared keys, a private authority, sovereign internal networks. There it replaces the encryption stack entirely.

The limits

Where it is the wrong tool.

Stated before being asked, because a construction that cannot say where it fails is not worth reading further.

Bulk encryption On hardware with AES acceleration, and where side channels are not in scope, far behind AES. AES has instructions built into the processor. We run in software, and that gap does not close. Where side channels are in scope, high-order masking costs AES that hardware path and the comparison is much closer.
High parallelism The property that produces the guarantees is the same one that forbids the parallelism. The two are inseparable.
The handshake How parties first prove who they are. The cipher does not cover it. A second programme addresses it, and is not ready.

We are not an alternative to the standardised algorithms. For traffic in volume, AES is the right answer.

The window

The migration is mandated, and the dates are fixed.

2027 First acquisition gate
US national security
2030 High-risk systems
European roadmap
2035 Full transition
Both

What sets those dates is what is already being recorded. Traffic captured today can be kept and opened later, so anything with a long confidentiality life is already exposed, well before the deadline.

Not resting everything on one family of assumptions is the stated position of the organisations writing the standards: NIST has added a fifth algorithm from a different mathematical family, Germany's BSI recommends code-based options alongside the lattice ones, and France's ANSSI requires hybrid constructions beyond 2030.

The construction absorbs a post-quantum key-exchange secret directly, and works alongside that migration.

The programmes

Two programmes, and where each one stands.

Theory Construction Independent audit Peer review and publication Agency qualification Common Criteria The symmetric cipher Identity and the handshake

complete under way next

The symmetric cipher encrypt(key, iv, message) → ciphertext That is the whole interface: no mode to select, no authenticator to attach, no derivation step, no padding. For infrastructure where a machine may be taken whole: secure elements, confidential computing, shared tenancy, long-lived archives.
Identity and the handshake Identity derived rather than certified, with no hierarchy of authorities to maintain or trust. Under construction; it is what would carry the work across the whole channel.

The aim

Cryptography assumes a hostile channel and a safe machine. For most of the world it is now the other way round.

Those assumptions came from military communication: operators who do not know one another, equipment expected to be captured, secrets that expire on a schedule, and an organisation standing behind all of it. Civilian infrastructure has none of that. Identities persist, records keep their value for decades, and the machine holding them is usually someone else's.

The aim is cryptography built for whoever holds the data, not for whoever issues the keys. That is a long piece of work, and it is the one we are doing.

Contact

Partnerships.

Ousia works with independent auditors, certification bodies and silicon partners along the path to deployment. Enquiries from cryptographers, integrators and agencies are welcome.

Email
info@ousia-sa.ch
Address
Ousia SA · 1285 Avusy — Geneva, Switzerland