Critical Infrastructure
Grid SCADA, pipeline telemetry, water treatment: all run on vulnerable encryption
Industrial control systems for power grids, gas pipelines, and water networks transmit encrypted telemetry over protocols that rely on RSA and ECDH. Harvest-now attacks capture this traffic today; a cryptographically relevant quantum computer decrypts it later.
Threat Surface
Three critical exposures in industrial networks
OT networks were designed for availability, not confidentiality. Their encryption layers are thin, and their replacement cycles are measured in decades.
Power Grid SCADA
SCADA systems for generation, transmission, and distribution use DNP3 and IEC 61850 over VPNs secured with RSA key exchange. Long operational lifetimes mean hardware changes come slowly.
Gas and Oil Telemetry
Pipeline control systems transmit pressure, flow, and valve state data over encrypted WAN links. Adversarial knowledge of grid topology and switching logic constitutes a serious operational risk.
Water and Waste
Municipal water treatment SCADA communicates over encrypted channels. Decrypted historical telemetry reveals operational patterns, treatment schedules, and control sequences.
Pramatra Capabilities
Quantum-safe encryption for OT environments
- VPN key injection Pramatra's KMA appliance feeds quantum-generated keys directly into your existing IPsec or MACsec VPN infrastructure via ETSI QKD API without protocol changes.
- OT-compatible deployment The KMA appliance operates in air-gapped or minimally networked environments. No cloud connectivity required for key consumption once the satellite downlink is established.
- High-frequency rotation Keys can rotate on configurable schedules -- per hour, per shift, or per session -- limiting the telemetry volume decryptable from any single compromised key.
- Redundant delivery paths Multiple satellite passes and optional relay architecture ensure continuous key supply even during maintenance windows or adverse atmospheric conditions.
From the Field
"Our biggest concern was disruption to live telemetry during integration. The KMA appliance fits into our existing IPsec infrastructure through the ETSI API, and nothing on the OT side needed to change. The proof-of-concept ran for six weeks without a single telemetry gap attributable to the key delivery layer."
Critical Infrastructure