Stealth AES / deterministic security

AES256, without Key Exchanges

Pantherun Stealth AES is a hardware-accelerated security architecture for data in motion. Authorized endpoints derive matching AES keys locally, allowing key rotation without exchanging the key across the network.

AES128 / 192 / 256
0Keys exchanged
0Format change
01No key exchange

Endpoints derive the same key locally.

02Zero format change

Protected data retains its structure and size.

03Hardware accelerated

FPGA engines offload encryption from the CPU.

04Flexible delivery

Silicon IP, software IP or inline hardware.

PQS: Post-quantum
Stealth encryption

The security model uses previous data as synchronized context. The key is computed at both ends instead of being transported between them.

Post Quantum Encryption

Stealth AES can encrypt the packet payload or the entire frame, hiding packets inside a continuous stream of rotating encryption keys.

Observe the shared stream

Each authorized endpoint uses agreed positions in previous data to build the state for the next encryption operation.

Derive locally

The source and destination independently derive the same key. Key material does not need to travel between them.

Rotate and protect

AES protection can rotate by packet or configured packet count while the protected data keeps its original format and size.

Standard AES.
A different key path.

Implementations support recognized AES modes while adding a compact, configurable approach to key management and acceleration.

CTR / encryption IP

AES-CTR

  • 128, 192 and 256-bit keys
  • NIST FIPS 197
  • Compact FPGA footprint under 4K LUTs
  • Hardware acceleration for streaming data
Authenticated mode

AES-GCM

  • 128, 192 and 256-bit keys
  • NIST SP 800-38D
  • FPGA footprint under 9K LUTs
  • Encryption and integrity protection
Integration targets

Flexibile development

  • FPGA with ARM or RISC-V cores
  • SoC and custom silicon
  • Software endpoints
  • Inline switching

Protect the data.
Keep the system.

Stealth AES can sit inside a new product or be added at the network edge without redesigning the application around a new data format.

Cameras + imaging

Protect high-volume visual data from the sensor through storage.

Industrial IoT

Secure telemetry and control without changing the application protocol.

Security Overlays

Add hardware-accelerated encryption on top of existing networks without replacing or redesigning the underlying infrastructure.

Unique key per packet

Configure Stealth AES to derive a unique AES key for every packet, limiting exposure without exchanging key material across the network.

Delivery / choose the boundary

IP core, software
or inline hardware.

Deploy at the silicon level, integrate a software endpoint or secure an existing link with an inline appliance or SFP+ module.

Plan a Stealth deployment
CIP-AES-1Chip with Stealth IP

Integrated 10/100/1G AES for one port.

NIP-AES-1Stealth silicon IP

Encryption IP for FPGA or SoC integration.

SIP-AES-1Soft Stealth IP

Software delivery for compatible endpoints.

BLAZE SFP+Inline encryption module

1Gbps or 10Gbps protection in an industrial SFP+ form factor.