How the Swarm SDK manages cryptographic identity for drone fleets: on-device ML-KEM-768 + X25519 keypair generation at provisioning, three-tier fleet CA hierarchy (Root → Fleet CA → device certificate), pre-provisioned mission cert bundles for offline authentication, signed prekey rotation every 7 days over the gossip mesh, in-flight device revocation via poison-pill RevocationMessage, and emergency wipe on tamper detection.
March 2026
5 dated technical articles. These pages record the methods and claims as published; follow each article's source links and update notes for its current scope.
How a Swarm SDK drone goes from factory state to trusted mesh participant: factory-provisioned ML-KEM-768 + X25519 keypairs, CSR generation and Fleet CA signing, USB and RF enrollment paths, gossip mesh announcement with SignedPreKeyBundle, pioneer bootstrap for the first device, and re-enrollment at certificate expiry.
How we designed the Swarm SDK: ML-KEM-768 + X25519 hybrid post-quantum key exchange, Double Ratchet forward secrecy, gossip mesh routing with bounded fanout, and the path to CNSA 2.0 compliance.
How the Swarm SDK protects drone mesh communications against traffic analysis — six fixed message size bins, ±15% transmission timing jitter, store-and-forward ring buffer for burst smoothing, degraded-channel operational mode, and RF fingerprint resistance on STM32H7.
How the Swarm SDK wraps post-quantum encrypted mesh traffic in MAVLink v2 SWARM_MESH_FRAME messages — 18-byte fragment header design, per-message reassembly buffer with 5-second TTL, PX4 and ArduPilot integration, MAVSDK passthrough, and why ML-KEM-768 Sealed Sender envelopes always require 6 frames.