Imagine a military satellite reconnecting after hours without a ground link. An update arrives bearing a valid digital signature. During the blackout, however, the credential behind that signature was revoked on Earth. The signature still checks out. Should the satellite install the update?
That is the overlooked test for the Pentagon’s postquantum transition. Stronger cryptography can establish the origin and integrity of a message. It cannot, on its own, tell a disconnected receiver whether the sender’s permission to issue that command has since been withdrawn.
The policy window is open. On Oct. 1, the National Security Agency reaffirmed its national security migration timetable, with quantum-resistant support expected in new commercial National Security Systems from 2027. On Tuesday, a newly announced SpaceWERX industry research agreement included the evaluation of postquantum risks in Space Force software. That agreement is a research effort, not a fielded fix. It shows why operational testing belongs alongside cryptographic modernization.
The Pentagon’s postquantum strategy explicitly covers space systems, tactical radios, data links, and edge devices. It calls for maintaining warfighting capability while retiring vulnerable cryptography. And as the Washington Examiner reported this week, U.S. Space Command is working to connect its Colorado and Alabama centers of space defense. In a contested environment, the harder problem is what those systems can still trust when they cannot communicate at all.
NASA has already solved a related communications problem. Its Delay/Disruption Tolerant Networking program stores information until a link returns and then forwards it. The Plankton, Aerosol, Cloud, Ocean Ecosystem spacecraft has successfully transmitted more than 34 million data bundles using that approach. Delayed delivery works. Delayed authorization is harder.
A spacecraft may hold a cached credential, an approved mission plan, or an old but correctly signed update. During disconnection, ground controllers could revoke the credential, replace the plan, or rotate a trust anchor. The spacecraft cannot learn a change that has not reached it. A system that treats every cryptographically valid message as permanently authorized is exposed even if its algorithms withstand a future quantum computer.
The fix begins before launch with an offline authority horizon: a preapproved limit on which commands, peers, and functions remain permissible without fresh status information, and for how long. The limit should reflect mission hazards and the earliest relevant expiry. Trusted local time and rollback-resistant state matter because an attacker must not be able to regain authority simply by resetting a clock or loading an older image.
Delivery and permission need separate checks. The Bundle Protocol is designed to move data across interrupted networks, and Bundle Protocol Security provides mechanisms for protecting bundle integrity and confidentiality. Neither makes a late-arriving instruction automatically current or authorized. Its cryptographic profile must also be checked for quantum resistance rather than inferred from the presence of the protocol.
When fresh evidence is unavailable, a system should narrow its actions according to the mission’s preapproved fallback. A satellite may continue collecting measurements while declining a new remote configuration. A tactical radio may sustain local communications while refusing to install unfamiliar software. Safety-critical functions need separately engineered continuity, because indiscriminately shutting down a platform can create danger of its own.
Reconnection should trigger a new trust decision. A previously signed command should be checked against current policy, revocation status, and version history before execution. Recovery from an older software image should be tested for rollback of cryptographic protections, credentials, and security state. Availability restored with yesterday’s vulnerable configuration would be a poor trade for quantum resistance.
These controls can be specified as acceptance tests now. On an isolated space or tactical-edge testbed, delay revocation notices, rotate a trust anchor, inject an old but authentic update, and restore an earlier image. Measure which actions remain possible during the outage, whether a stale command is rejected on reconnection, and how long permissions remain usable after their local freshness limits expire. No classified operational mission is needed to learn whether the rules work.
BEFORE TRUMP’S NEXT WAR WITH IRAN: DON’T SAVE TOMORROW’S AUTOCRATS
A previous op-ed in these pages argued that migration percentages are no substitute for mission readiness. Disconnected trust is one of the places where that distinction becomes operational. The United States can meet every algorithm deadline and still leave a satellite unable to tell whether yesterday’s permission should govern today’s command.
Space forces cannot abolish radio silence, orbital geometry, or an adversary’s jamming. They can decide in advance how long old evidence deserves authority. As America moves its military systems toward postquantum security, the Pentagon should require a demonstration that the mission remains useful and safely bounded when the link to Earth goes dark.
Burak Oktenli is a graduate student in applied intelligence at Georgetown University and an independent researcher focused on trustworthy artificial intelligence, cybersecurity, autonomous systems, and high-consequence technology governance. He holds a bachelor’s degree in computer science and engineering from the University of South Florida and a master’s in business administration.
