Eon Path
X25519 ●╮ ╭─╮ ╭──────────────
╰─╳─╯ ╰─╳─╯
ML-KEM ●╯ ╰─╯ ╰──────────────● one channel
└ classic ┘└ post-quantum ┘ └ hybrid session key ┘
// hybrid braid — X25519 + ML-KEM-768Turnkey Post-Quantum Protection — No Code Changes Required
Adversaries are harvesting your encrypted data today, confident they'll decrypt it the moment quantum computing matures. This "harvest now, decrypt later" threat is real, and it may arrive this decade. Eon Path stops it — starting today.
Eon Path is the fastest, lowest-risk path to quantum resilience. It deploys as a transparent proxy between your applications and the network, seamlessly upgrading standard TLS to quantum-safe cryptography. Your applications never notice. Your developers never touch a line of code. Your organization is protected in hours, not months.
The EONCORE Advantage
- Deploy in hours, not months.
- Zero developer effort — no application rewrites, no re-architecture.
- Zero downtime — protection without business disruption.
- Compliance-ready — meet emerging post-quantum mandates now.
Under the Hood
- ML-KEM-768 (Kyber) in hybrid mode with X25519.
- ML-DSA for public-key authentication.
- Runs on Windows, macOS, and Linux.
- Centralized, API-driven key management.
- Built-in failover and crypto-agility modes.
Deployment
- 1. Install the server component.
- 2. Roll out client applications.
- 3. Activate protection.
Quantum-safe encryption for apps you already run.
Attackers can copy your encrypted traffic now and decrypt it later, once quantum computers are strong enough. It's called "harvest now, decrypt later." Eon Path blocks it without touching your code.
How it works
Eon Path sits as a transparent proxy between your app and the network. It intercepts normal TLS, swaps in quantum-safe crypto, and passes the traffic on. The app doesn't know. Developers don't change code.
Why it's useful
- Deploys in hours, not months.
- No developer work.
- No app downtime.
- Ready for emerging post-quantum requirements.
Under the hood
- ML-KEM-768 (Kyber) hybrid with X25519.
- ML-DSA for public-key auth.
- Runs on Windows, macOS, Linux.
- Central, API-driven key management.
- Failover and crypto-agility modes.
Setup
- 1. Install the server piece.
- 2. Deploy client apps.
- 3. Turn protection on.
Ride the wave before it catch you.
Quantum-safe crypto. Apps you already run. No code change.
Bad guy grab your data now. Decrypt later when quantum come. Call it "harvest now, decrypt later." Threat real — maybe this decade. Eon Path stop it. Today.
How it work
Eon Path sit as transparent proxy between app and network. It catch normal TLS, swap in quantum-safe crypto, pass traffic on. App never know. Dev never touch code.
Why good
- Deploy in hours, not months.
- Zero developer work.
- No app downtime.
- Compliance ready — now.
Under hood
- ML-KEM-768 (Kyber) hybrid with X25519.
- ML-DSA for public key auth.
- Runs on Windows, macOS, Linux.
- Central API-driven key management.
- Failover + crypto-agility modes.
Set up
- 1. Install server piece.
- 2. Deploy client apps.
- 3. Turn protection on.
Eon Path — NIST-standardized hybrid post-quantum key exchange and signatures. Drop-in; no application code changes.
Cryptography
Architecture
Two tunnelling methods:
- Proxy — HTTP CONNECT proxy fronting an SSH server; hybrid PQC key exchange,
ML-DSAhost keys, per-userauthorized_keys. - Routing (VPN) — WireGuard with IPv4-over-IPv6 (464XLAT / SIIT) translation; key exchange ML-KEM-1024 + ML-DSA-87, PQC-derived pre-shared key.
- API-driven public-key lookup (PQKS); TOFU host-key verification; failover + crypto-agility modes.
Defaults
127.0.0.1:9999127.0.0.1:2022truemlkemDeploy
- 1. Install the server component.
- 2. Deploy client apps.
- 3. Enable protection.