EONCORE

Eon Path

X25519ML-KEMone channel
Hybrid Braid X25519 + ML-KEM-768 · study № 02
X25519ML-KEMone channel
Hybrid Braid — X25519 + ML-KEM-768
 X25519 ●╮   ╭─╮   ╭──────────────
        ╰─╳─╯ ╰─╳─╯
 ML-KEM ●╯   ╰─╯   ╰──────────────● one channel
        └ classic ┘└ post-quantum ┘  └ hybrid session key ┘
// hybrid braid — X25519 + ML-KEM-768

Turnkey Post-Quantum Protection — No Code Changes Required

Adversaries are harvesting your encrypted data today, confident they'll decrypt it the moment quantum computing matures. This "harvest now, decrypt later" threat is real, and it may arrive this decade. Eon Path stops it — starting today.

Eon Path is the fastest, lowest-risk path to quantum resilience. It deploys as a transparent proxy between your applications and the network, seamlessly upgrading standard TLS to quantum-safe cryptography. Your applications never notice. Your developers never touch a line of code. Your organization is protected in hours, not months.

The EONCORE Advantage

Under the Hood

Deployment

Quantum-safe encryption for apps you already run.

Attackers can copy your encrypted traffic now and decrypt it later, once quantum computers are strong enough. It's called "harvest now, decrypt later." Eon Path blocks it without touching your code.

How it works

Eon Path sits as a transparent proxy between your app and the network. It intercepts normal TLS, swaps in quantum-safe crypto, and passes the traffic on. The app doesn't know. Developers don't change code.

Why it's useful

Under the hood

Setup

Ride the wave before it catch you.

Quantum-safe crypto. Apps you already run. No code change.

Bad guy grab your data now. Decrypt later when quantum come. Call it "harvest now, decrypt later." Threat real — maybe this decade. Eon Path stop it. Today.

How it work

Eon Path sit as transparent proxy between app and network. It catch normal TLS, swap in quantum-safe crypto, pass traffic on. App never know. Dev never touch code.

Why good

Under hood

Set up

Eon Path — NIST-standardized hybrid post-quantum key exchange and signatures. Drop-in; no application code changes.

Cryptography

KEMML-KEM (FIPS 203) — 512 / 768 / 1024
KEM defaultML-KEM-768 (NIST level 3)
signatureML-DSA (FIPS 204) — 44 / 65 / 87
signature defaultML-DSA-65 (NIST level 3)
key exchangehybrid: curve25519 (ECDH) + ML-KEM, combined via KDF
alt KEMFrodoKEM-640 (conservative)
fallbackclassical, for backward compatibility
crypto backendOpenSSL 3.5+ (statically linked)

Architecture

Two tunnelling methods:

Defaults

proxy address127.0.0.1:9999
ssh address127.0.0.1:2022
pqc-mlkemtrue
pqc-ordermlkem
platformsWindows · macOS · Linux
configflags > YAML > env > defaults

Deploy