ZeroTier and Carahsoft have announced a partnership to distribute a software-defined networking platform with post-quantum cryptographic features to US government and defense agencies, aiming to address future cryptographic risks in critical infrastructure
ZeroTier, a developer of software-defined networking (SDN) platforms, has entered a distribution agreement with Carahsoft Technology Corp. to make its post-quantum secure networking software available to US public sector and defense organizations. The partnership positions Carahsoft as the Master Government Aggregator for ZeroTier, enabling federal agencies to access the ZeroTier Quantum platform through established procurement channels, including the NASA Solutions for Enterprise-Wide Procurement (SEWP V) contract vehicles.
Hybrid Cryptography and Architecture
The ZeroTier Quantum platform integrates post-quantum cryptographic resilience directly into its transport layer using the ZeroTier Transport Protocol (ZTP), which is implemented in the memory-safe Rust programming language. The system employs a hybrid key exchange protocol that combines ML-KEM-1024-a NIST-standardized module-lattice-based key encapsulation mechanism-with the established ECDH P-384 elliptic curve Diffie-Hellman method. This hybrid approach is designed to mitigate the risk of "harvest now, decrypt later" attacks, in which encrypted data is collected today for decryption once large-scale quantum computers become available. The architecture is intended to comply with National Security Agency Commercial National Security Algorithm Suite 2.0 (NSA CNSA 2.0) requirements and NIST post-quantum migration guidelines.
Deployment Across Legacy and Edge Systems
ZeroTier Quantum is engineered as an infrastructure-agnostic overlay, allowing organizations to secure legacy infrastructure, high-value assets, and edge platforms-including uncrewed aerial vehicles, tactical sensors, and software-defined vehicles-without replacing existing hardware or reconfiguring network routes. The platform supports deployment across multi-cloud, sovereign, air-gapped, and offline environments, providing encrypted mesh networking and zero trust network access (ZTNA) for sensitive federal operations. According to the companies, the software is capable of encapsulating legacy high-value assets and supporting public cloud, edge, tactical, and air-gapped deployments while maintaining compliance with NSA CNSA 2.0 and FIPS standards.
Technical Features and Standards Alignment
The platform's technical features include a hybrid key exchange layer, memory-safe Rust architecture, and encapsulation of legacy assets. The use of ML-KEM-1024 aligns with NIST's ongoing post-quantum cryptography standardization, while the inclusion of ECDH P-384 provides backward compatibility with existing asymmetric cryptographic systems. The overlay model is designed to function in environments where traditional network upgrades are impractical, aiming to extend post-quantum security to operational technology and mission-critical systems. While the company reports compliance with relevant standards, independent verification of system performance and security claims has not yet been published in peer-reviewed literature.
Context in Quantum Security Migration
The announcement comes as government agencies and critical infrastructure operators accelerate planning for post-quantum cryptography migration. The US National Institute of Standards and Technology (NIST) has finalized several post-quantum cryptographic algorithms, and federal agencies face deadlines for transitioning to quantum-resistant protocols. The ZeroTier Quantum platform is positioned as a software-based solution for organizations seeking to address these requirements without large-scale hardware replacement. For comparison, recent efforts to integrate quantum and classical security approaches in high-performance computing environments, such as the hybrid quantum-classical testbed at the Pittsburgh Supercomputing Center, highlight the broader trend toward hybrid security architectures in anticipation of future quantum threats.
Post-quantum cryptography refers to cryptographic algorithms designed to remain secure against attacks from both classical and quantum computers. Unlike quantum key distribution, which relies on quantum physical principles for security, post-quantum algorithms are implemented on conventional hardware and are intended to replace or supplement existing public-key systems vulnerable to quantum attacks. The transition to post-quantum cryptography involves not only algorithm selection and standardization but also practical challenges in software integration, hardware compatibility, and operational deployment across diverse and legacy systems. Hybrid cryptographic models, which combine classical and post-quantum algorithms, are currently favored to ensure backward compatibility and to provide defense-in-depth during the migration period.