{"id":586754,"date":"2026-04-05T09:18:19","date_gmt":"2026-04-05T09:18:19","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/586754\/"},"modified":"2026-04-05T09:18:19","modified_gmt":"2026-04-05T09:18:19","slug":"esp32-s3-gets-post-quantum-encryption-with-aethyr-edge-node-open-source-firmware","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/586754\/","title":{"rendered":"ESP32-S3 gets post-quantum encryption with Aethyr Edge Node open-source firmware"},"content":{"rendered":"<p>Aethyr Research has released post-quantum encrypted IoT edge node firmware for ESP32-S3 targets that boots in 2.1 seconds and supports full PQC (Post Quantum Cryptography) handshakes in 35ms.<\/p>\n<p>Public-key cryptographic algorithms such as RSA and ECC will soon have to be replaced due to the advance of quantum computers that will be able to crack such encryption within a few hours to days using <a href=\"https:\/\/grokipedia.com\/page\/Shor&#039;s_algorithm\" rel=\"nofollow noopener\" target=\"_blank\">Shor\u2019s algorithm<\/a>. While there\u2019s still time, <a href=\"https:\/\/blog.google\/innovation-and-ai\/technology\/safety-security\/cryptography-migration-timeline\/\" rel=\"nofollow noopener\" target=\"_blank\">Google recently updated its timeline<\/a> for post-quantum cryptography migration to 2029, mostly because it\u2019s possible to store data now for an attack once sufficiently powerful quantum computers become available, and the NIST FIPS 203 standard (ML-KEM-768) mandates quantum-resistant security by 2035.<\/p>\n<p><a href=\"https:\/\/www.cnx-software.com\/wp-content\/uploads\/2026\/04\/ESP32-S3-Post-quantum-encryption.jpg\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-168301\" title=\"ESP32-S3 post quantum encryption\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/04\/ESP32-S3-Post-quantum-encryption-720x406.jpg\" alt=\"ESP32-S3 post quantum encryption\" width=\"720\" height=\"406\"  \/><\/a><\/p>\n<p>The Aethyr Edge Node open-source firmware relies on formally verified ML-KEM-768 (FIPS 203) post-quantum key exchange, BLAKE3 integrity, and XChaCha20-Poly1305 encryption to implement post-quantum encryption to connect to a server over the AethyrWire Protocol (AWP).\u00a0 It\u2019s a building block of the Aethyr distributed agent mesh, aiming to deploy autonomous AI agents over a mesh network with small nodes running TinyML and larger nodes for more complex reasoning without having to rely on the cloud. The only part of the project that\u2019s open source for now is the ESP32-S3 firmware, and the rest of the Aethyr agent operating system remains proprietary.<\/p>\n<p><a href=\"https:\/\/www.cnx-software.com\/wp-content\/uploads\/2026\/04\/Aethyr-dashboard.webp\" rel=\"nofollow noopener\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-168306 lazyload\" title=\"Aethyr dashboard\" alt=\"Aethyr dashboard\" width=\"720\" height=\"513\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/04\/Aethyr-dashboard-720x513.webp.webp\"  data- data-eio-rwidth=\"720\" data-eio-rheight=\"513\"\/><\/a>Aethyr dashboard<\/p>\n<p>The post-quantum resistant algorithms will introduce some delays, but based on the benchmarks released for an ESP32-S3-WROOM-1 module with a CPU clocked at\u00a0 240MHz (50 iterations,\u00a0 mean and standard deviation), it does not look too bad.<\/p>\n<p>\tOperationMeanStdDevMinMax<\/p>\n<p>\tBLAKE3 (1KB)255us102us238us969us<\/p>\n<p>\tML-KEM keygen9,052us164us8,986us9,558us<\/p>\n<p>\tML-KEM encap10,070us11us10,058us10,146us<\/p>\n<p>\tML-KEM decap12,197us11us12,192us12,275us<\/p>\n<p>\tXChaCha20 encrypt243us46us235us564us<\/p>\n<p>\tBLAKE3 KDF49us60us40us472us<\/p>\n<p>\tAWP frame enc+dec363us95us346us1,030us<\/p>\n<p>The firmware has an 833KB footprint, and the free heap is 157KB out of 512KB SRAM at runtime. The firmware has also been tested with 410,000 fuzz iterations (AddressSanitizer + UBSan) with zero crashes and 100,000 single-bit-flip tests, all detected. It also runs 13 self-tests on every boot.<\/p>\n<p>Aethyr tested it on ESP32-S3-WROOM-1 modules with 8MB PSRAM and an <a href=\"https:\/\/www.cnx-software.com\/2024\/12\/18\/249-nvidia-jetson-orin-nano-super-developer-kit-targets-generative-ai-applications-at-the-edge\/\" rel=\"nofollow noopener\" target=\"_blank\">NVIDIA Jetson Orin Nano Super<\/a> acting as a 2.4 GHz WiFi access point running the upstream NODE. It should work on any ESP32-S3 boards, and you can check out the code, configure, build, and flash the firmware to your board as follows (ESP-IDF v5.4+ required):<\/p>\n<p>\ngit clone https:\/\/github.com\/aethyrai\/esp32-awp-edge&#13;<br \/>\ncd esp32-awp-edge&#13;<br \/>\n&#13;<br \/>\n# Configure WiFi and upstream node&#13;<br \/>\nidf.py menuconfig&#13;<br \/>\n# \u2192 AWP Edge Node Configuration&#13;<br \/>\n#   WiFi SSID \/ Password&#13;<br \/>\n#   Upstream host IP and port&#13;<br \/>\n&#13;<br \/>\nidf.py build&#13;<br \/>\nidf.py -p \/dev\/ttyUSB0 flash monitor<\/p>\n<p>git clone https:\/\/github.com\/aethyrai\/esp32-awp-edge<\/p>\n<p>cd esp32-awp-edge<\/p>\n<p>\u00a0<\/p>\n<p># Configure WiFi and upstream node<\/p>\n<p>idf.py menuconfig<\/p>\n<p># \u2192 AWP Edge Node Configuration<\/p>\n<p>#\u00a0\u00a0 WiFi SSID \/ Password<\/p>\n<p>#\u00a0\u00a0 Upstream host IP and port<\/p>\n<p>\u00a0<\/p>\n<p>idf.py build<\/p>\n<p>idf.py -p \/dev\/ttyUSB0 flash monitor<\/p>\n<p>The output from the terminal should look like:<\/p>\n<p>\nCrypto Self-Test Suite&#13;<br \/>\n  [1] BLAKE3: empty input&#8230;                           PASS&#13;<br \/>\n  [2] BLAKE3: 251 sequential bytes&#8230;                  PASS&#13;<br \/>\n  [3] BLAKE3: derive_key (KDF mode)&#8230;                 PASS&#13;<br \/>\n  [4] XChaCha20-Poly1305: encrypt\/decrypt round-trip&#8230;PASS&#13;<br \/>\n  [5] XChaCha20-Poly1305: tamper detection&#8230;          PASS&#13;<br \/>\n  [6] XChaCha20-Poly1305: wrong key rejection&#8230;       PASS&#13;<br \/>\n  [7] XChaCha20-Poly1305: nonce uniqueness&#8230;          PASS&#13;<br \/>\n  [8] ML-KEM-768: keygen + encap\/decap round-trip&#8230;   PASS&#13;<br \/>\n  [9] ML-KEM-768: wrong secret key rejection&#8230;        PASS&#13;<br \/>\n  [10] INTEROP: BLAKE3 KDF matches Python&#8230;           PASS&#13;<br \/>\n  [11] INTEROP: decrypt Python-produced ciphertext&#8230;  PASS&#13;<br \/>\n  [12] AWP: frame encode\/decode round-trip&#8230;          PASS&#13;<br \/>\n  [13] AWP: BLAKE3 checksum tamper detection&#8230;        PASS&#13;<br \/>\n  ALL 13 TESTS PASSED (226ms)&#13;<br \/>\n&#13;<br \/>\nML-KEM-768 keypair ready&#13;<br \/>\nWiFi connected&#13;<br \/>\nTCP connected to upstream&#13;<br \/>\nPQC session established<\/p>\n<p>1<\/p>\n<p>2<\/p>\n<p>3<\/p>\n<p>4<\/p>\n<p>5<\/p>\n<p>6<\/p>\n<p>7<\/p>\n<p>8<\/p>\n<p>9<\/p>\n<p>10<\/p>\n<p>11<\/p>\n<p>12<\/p>\n<p>13<\/p>\n<p>14<\/p>\n<p>15<\/p>\n<p>16<\/p>\n<p>17<\/p>\n<p>18<\/p>\n<p>19<\/p>\n<p>20<\/p>\n<p>Crypto Self-Test Suite<\/p>\n<p>\u00a0\u00a0[1] BLAKE3: empty input&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 PASS<\/p>\n<p>\u00a0\u00a0[2] BLAKE3: 251 sequential bytes&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[3] BLAKE3: derive_key (KDF mode)&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 PASS<\/p>\n<p>\u00a0\u00a0[4] XChaCha20-Poly1305: encrypt\/decrypt round-trip&#8230;PASS<\/p>\n<p>\u00a0\u00a0[5] XChaCha20-Poly1305: tamper detection&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[6] XChaCha20-Poly1305: wrong key rejection&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 PASS<\/p>\n<p>\u00a0\u00a0[7] XChaCha20-Poly1305: nonce uniqueness&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[8] ML-KEM-768: keygen + encap\/decap round-trip&#8230;\u00a0\u00a0 PASS<\/p>\n<p>\u00a0\u00a0[9] ML-KEM-768: wrong secret key rejection&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[10] INTEROP: BLAKE3 KDF matches Python&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 PASS<\/p>\n<p>\u00a0\u00a0[11] INTEROP: decrypt Python-produced ciphertext&#8230;\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[12] AWP: frame encode\/decode round-trip&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0[13] AWP: BLAKE3 checksum tamper detection&#8230;\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0PASS<\/p>\n<p>\u00a0\u00a0ALL 13 TESTS PASSED (226ms)<\/p>\n<p>\u00a0<\/p>\n<p>ML-KEM-768 keypair ready<\/p>\n<p>WiFi connected<\/p>\n<p>TCP connected to upstream<\/p>\n<p>PQC session established<\/p>\n<p>The code and instructions can be found <a href=\"https:\/\/github.com\/aethyrai\/esp32-awp-edge\" rel=\"nofollow noopener\" target=\"_blank\">on GitHub<\/a>. However, there\u2019s just a little problem. I couldn\u2019t find an OS image or software to install on the Jetson board, so it\u2019s not super useful at this point. The documented Jetson and Demo directories have not yet been uploaded to GitHub:<\/p>\n<p>\n\u2500\u2500 jetson\/&#13;<br \/>\n\u2502   \u251c\u2500\u2500 setup-mesh-ap.sh       Create dedicated WiFi AP on Jetson&#13;<br \/>\n\u2502   \u251c\u2500\u2500 stop-mesh-ap.sh        Stop mesh AP&#13;<br \/>\n\u2502   \u2514\u2500\u2500 aios-node.service      systemd service for AWP node&#13;<br \/>\n\u251c\u2500\u2500 demo\/&#13;<br \/>\n\u2502   \u2514\u2500\u2500 run_demo.py            Scripted 2-minute demo<\/p>\n<p>\u2500\u2500 jetson\/<\/p>\n<p>\u2502\u00a0\u00a0 \u251c\u2500\u2500 setup-mesh-ap.sh\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Create dedicated WiFi AP on Jetson<\/p>\n<p>\u2502\u00a0\u00a0 \u251c\u2500\u2500 stop-mesh-ap.sh\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Stop mesh AP<\/p>\n<p>\u2502\u00a0\u00a0 \u2514\u2500\u2500 aios-node.service\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0systemd service for AWP node<\/p>\n<p>\u251c\u2500\u2500 demo\/<\/p>\n<p>\u2502\u00a0\u00a0 \u2514\u2500\u2500 run_demo.py\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0Scripted 2-minute demo<\/p>\n<p>Maybe the post-quantum encryption implementation can serve as a base for other PQC-resistant projects. A\u00a0<a href=\"https:\/\/web.archive.org\/web\/20260405041940\/https:\/\/aethyrresearch.com\/blog\/post-quantum-esp32-edge-node\" rel=\"nofollow noopener\" target=\"_blank\">related blog post<\/a> has a few more details. (Internet Archive link, because the website won\u2019t work from Thailand, except when using a US VPN).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"100\" height=\"100\" alt=\"Jean Luc Aufranc\" itemprop=\"image\" src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2025\/11\/Jean-Luc-Aufranc.webp.webp\" class=\"lazyload\" data-eio-rwidth=\"180\" data-eio-rheight=\"180\"\/><\/p>\n<p>Jean-Luc started CNX Software in 2010 as a part-time endeavor, before quitting his job as a software engineering manager, and starting to write daily news, and reviews full time later in 2011.<\/p>\n<p>Support CNX Software! Donate via <a href=\"https:\/\/www.cnx-software.com\/donate-cryptocurrencies\/\" rel=\"nofollow noopener\" target=\"_blank\">cryptocurrencies<\/a>, <a href=\"https:\/\/www.patreon.com\/cnxsoft\" target=\"_blank\" rel=\"nofollow noopener\">become a Patron<\/a> on Patreon, or purchase goods on <a href=\"https:\/\/amzn.to\/3SXubZ0\" rel=\"nofollow noopener\" target=\"_blank\">Amazon<\/a> or <a href=\"https:\/\/s.click.aliexpress.com\/e\/_DmGIIRT\" rel=\"nofollow noopener\" target=\"_blank\">Aliexpress<\/a>. We also use affiliate links in articles to earn commissions if you make a purchase after clicking on those links.<\/p>\n","protected":false},"excerpt":{"rendered":"Aethyr Research has released post-quantum encrypted IoT edge node firmware for ESP32-S3 targets that boots in 2.1 seconds&hellip;\n","protected":false},"author":2,"featured_media":586755,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[64,63,261,17717,31808,2292,4206,105],"class_list":["post-586754","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-au","tag-australia","tag-edge-ai","tag-esp32","tag-mesh-networking","tag-quantum-computing","tag-security","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/586754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=586754"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/586754\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/586755"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=586754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=586754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=586754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}