Platform Architecture

Keys delivered by physics, not algorithms

Every bit of key material from Pramatra Space begins as a single photon in orbit. The laws of quantum mechanics guarantee that any interception attempt collapses the photon state and becomes immediately detectable.

The BB84 Protocol

Four stages from photon to key

BB84, published in 1984 by Bennett and Brassard, is the founding protocol of quantum key distribution. Pramatra's satellite implementation extends it to orbital distances.

01
Photon Emission
The satellite's quantum source emits single photons, each encoded in one of four polarization states using two non-orthogonal bases. Each photon carries one qubit of raw key material.
02
Basis Measurement
The ground station measures each arriving photon by randomly selecting a measurement basis. Approximately half the measurements match the satellite's encoding basis.
03
Sifting and Reconciliation
The satellite and ground station compare basis choices over an authenticated classical channel. Mismatched measurements are discarded. The remaining bits form the raw key.
04
Privacy Amplification
Statistical error analysis reveals any eavesdropping. If error rates exceed threshold, the session is discarded. Otherwise, privacy amplification compresses the raw key into a provably secure final key.
BB84 Basis Encoding Table

Rectilinear and diagonal bases: four polarization states

Basis Bit 0 Bit 1 Symbol
+ Rectilinear 0° (horizontal) 90° (vertical) → ↑
x Diagonal 45° (diagonal) 135° (anti-diag) ↗ ↖
Wrong basis random result random result DISCARD

An eavesdropper measuring with the wrong basis introduces a statistically detectable 25% error rate in the sifted key. QBER above 11% triggers automatic session abort.

AI Orchestration

Routing intelligence built for live orbital conditions

Satellite pass windows, atmospheric turbulence, and key buffer levels change constantly. Static routing rules cannot maintain guaranteed delivery SLAs. Pramatra's orchestration layer tracks every variable in real time.

  • Pass-window prediction Orbital mechanics models predict ground visibility windows 72 hours ahead, pre-positioning key buffers before the satellite rises.
  • Atmospheric adaptation Atmospheric scintillation and cloud cover reduce photon link budget. The AI layer dynamically adjusts transmission parameters to maintain target QBER.
  • Buffer-level management Ground station key buffers are monitored continuously. The router pre-fetches from the nearest available satellite before buffers reach threshold.
  • Multi-path redundancy When a primary satellite is unavailable, the orchestration layer reroutes through a relay satellite or a secondary ground station without operator intervention.
Integration Guide

Designed for existing network infrastructure

Pramatra Space keys arrive as standard ETSI-compatible key material. Your KMIP-speaking application does not need to change to consume quantum-safe keys.

ETSI QKD API
Keys are served over the ETSI GS QKD 014 REST interface. Any existing KMIP or KMS integration can consume Pramatra keys without a protocol change.
SDK and Client Libraries
Python, Java, and C libraries provide type-safe wrappers. Optional TLS 1.3 with hybrid PQC mode bundles a CRYSTALS-Kyber key exchange alongside the QKD key for defense-in-depth.
On-Premises Key Manager
The Pramatra KMA appliance accepts satellite key material and distributes it to local applications over an encrypted internal bus. No cloud dependency for key consumption.
// ETSI GS QKD 014 -- get_key endpoint
GET /api/v1/keys/{master_sae_id}/enc_keys
 
// Response
{
  "keys": [{
    "key_ID": "a3f8-...7c2d",
    "key": "<base64-encoded 256-bit QKD key>"
  }]
}
Security Posture

Every layer defended independently

QKD provides unconditional security for the key exchange channel. Pramatra's broader architecture layers additional controls at the authentication, transport, and key storage layers.

Unconditional key secrecy
QKD security derives from quantum measurement laws, not computational hardness. No future computer can recover a key from captured photons.
Eavesdrop detection
Any interception attempt collapses the quantum state, elevating the QBER above the eavesdropping threshold. Affected sessions are automatically invalidated.
PQC hybrid transport
The classical reconciliation channel uses TLS 1.3 with ML-KEM (NIST FIPS 203) hybrid mode. Both the quantum channel and classical channel must be compromised simultaneously.
HSM-backed storage
Ground station key material is stored in FIPS 140-2 Level 3 validated hardware security modules. Keys never exist in plaintext outside HSM boundaries.
Get Started

Ready to bring quantum-safe keys into your network?