Modern drones rarely operate alone. They connect to ground control stations (GCS), sensors, other aircraft, tactical networks, edge infrastructure, satellite communications (SATCOM), 3G/4G/5G cellular networks, and more. In defense applications, those connections also have to work in environments where communications infrastructure may be unreliable, degraded, jammed, or even where traditional IPsec may simply be unavailable. That makes resilient COMSEC, not just connectivity, a core platform requirement. If the network can’t adapt, the mission pays for it.
That changes how manufacturers should think about networking. A drone may move between coverage areas, switch communications methods mid-flight, lose its preferred path, or operate alongside systems from different manufacturers. As fleets become more autonomous and distributed, secure connectivity has to adapt alongside the aircraft rather than becoming another operational constraint.
That direction lines up with the broader quantum push that recently came out of Washington. The White House released Executive Order 14412 in late June, which called for faster development and deployment of quantum computing, sensing, and networking. Following the order, the Department of War subsequently announced it was moving toward quantum-resistant cryptography across high-impact systems by 2030, and the broader force by 2031. Several European countries, including France, have also announced preparations for the same transition, with their national cybersecurity roadmap beginning post-quantum inventories now and targeting implementation starting this decade.
Design for Changing Connections
For drone manufacturers, that means designing networks that can move, adapt, and keep working when conditions change.
Traditional networking can become a liability when the platform’s constantly changing location and communications paths. Fixed routes, centralized VPN infrastructure, and networking tied to a single transport can create complexity when a drone transitions between line-of-sight (LOS), cellular, SATCOM, or other IP connections.
Those transitions manifest as distinct handover protocols. A horizontal handoff may move a drone between different access points or coverage zones using the same type of network. A vertical handoff moves it between entirely different transports, such as switching from cellular to SATCOM when terrestrial connectivity becomes unavailable.
From the UAV’s perspective, those changes should be as uneventful as possible. The mission shouldn’t have to stop because the underlying network changed. Connection persistence should just continue. No interruptions.
That makes fast failover increasingly important. If one communications path degrades or disappears, another needs to be ready to take over quickly. Instead of discovering and establishing a backup only after the primary link fails, networking architectures can be designed to keep multiple potential connections available, or “hot,” so the platform has options when conditions change.
Multipathing extends that idea further. Rather than relying on deterministic point-to-point routing (i.e. from point A to B to C), systems can account for multiple available paths and transports. A drone might have access to terrestrial wireless like Wi-Fi HaLow, cellular, SATCOM, or LOS connections through nearby aircraft at different points in the same flight. Designing with those paths in mind creates more room to route around disruption instead of treating every lost link as a lost connection. So, if one path goes down, the network continues over other established paths that are already available and can be used simultaneously.
Another layer of resilience? Wireless Mesh Network (WMN) connectivity, which allows for decentralized traffic forwarding. In a drone fleet, individual aircraft don’t need to depend on one central communications path for every interaction. Authorized drones, controllers, sensors, and ground systems can form a broader peer-to-peer network, creating direct connections where possible. This gives the overall flight architecture more ways to communicate as aircraft move.
ZeroTier is built around that kind of model. It creates an encrypted, software-defined network connecting authorized devices across the underlying IP transports available to them. For defense platforms, that helps maintain secure COMSEC even as those transports change. Each device is instantiated with a unique, immutable cryptographic identity, facilitating policy-based access control that strictly authorizes inter-deployment communications.
By decoupling the logical overlay from the underlying physical transport, the network architecture achieves persistence across dynamic topological changes. A drone can move between communications paths without requiring operators to redesign the network every time its transport changes.This security posture stays consistent across the entire tactical ecosystem, keeping policy enforcement intact even in high-mobility and contested environments.
For manufacturers, this signifies an architectural shift toward transport-agnostic connectivity that persists independently of the underlying physical layer. Instead of designing around one perfect communications path, they can design for the reality that paths will change, links will fail, and contested environments will rarely behave exactly as expected.
Thinking Beyond Today’s Encryption
Drone platforms today need to be usable in the field for years, maybe even a decade or more. The security choices made during development need to account for that lifecycle, including cryptographic standards that will continue changing long after a platform enters live service.
Consequently, integrating cryptographic agility and post-quantum readiness is imperative for long-term security. OEMs and platform providers thus require modular security capabilities that support algorithmic updates, allowing for future-proofed cryptographic advancements. This should be without necessitating costly, high-friction hardware or firmware re-engineering.
ZeroTier Quantum brings post-quantum cryptography (PQC) to the networking layer by combining ZeroTier’s encrypted peer-to-peer architecture with quantum-resistant cryptography. That gives drone makers a path to protect communications today while preparing for emerging government requirements, including the CNSA 2.0 cryptographic suite.
It also gives manufacturers a cleaner way to evolve security as requirements change. That can matter when platforms need to remain deployable for years, operate across different mission environments, or adapt to new government security standards over time.
And because that capability remains software-defined, manufacturers don’t need to add another proprietary networking appliance to every platform, an important consideration when size, weight, power, and cost all matter and are designed upfront for scalable production.
With federal post-quantum deadlines getting closer, Executive Orders accelerating action, and CNSA 2.0 requirements already shaping procurement and platform decisions, the time to build quantum readiness in is now, not after deployment. ZeroTier is helping embed quantum-secure networking into the systems being built today. Contact sales to learn more about bringing quantum-secure networking into your platform.