Blog

U.S. Aircraft Communications Still Lack Basic Authentication. Aviation Cybersecurity Has a Trust Problem.

Commercial aviation is built around trust. Pilots trust that instructions came from air traffic controllers. Controllers trust that information associated with an aircraft accurately represents the aircraft they are managing. Airlines depend on communications between ground operations and crews to coordinate increasingly complex transportation systems.

A new Government Accountability Office report has highlighted how much of that trust still depends on communications technology designed before modern cybersecurity became a central requirement.

The GAO reported on September 21 that key aviation communications systems remain exposed to interception, spoofing, denial-of-service attacks and electromagnetic interference. Two widely used applications, Aircraft Communications Addressing and Reporting System, or ACARS, and Controller Pilot Data Link Communications, or CPDLC, generally lack encryption and authentication. GAO warned that malicious actors could potentially send fraudulent messages appearing to originate from legitimate air traffic control or airline operations sources. 

FAA agreed with all nine recommendations made by GAO. The report does not suggest that aircraft are routinely being hijacked through these systems, nor does it claim that every theoretical attack can be executed easily. It does demonstrate something more fundamental: parts of one of the world’s most sophisticated transportation infrastructures still depend on digital communications in which identity and authenticity are not cryptographically established to the degree modern cybersecurity would typically expect.

That gap is a security problem today and a modernization problem for the future.

Aviation Shows What Happens When Infrastructure Outlives Its Security Assumptions

Infrastructure is difficult to modernize precisely because it works.

An aviation communications system that has operated reliably for decades becomes embedded in aircraft fleets, airports, air traffic facilities, airline operations centers, training programs, international standards and regulatory processes. Replacing one component may require coordination across an ecosystem that spans manufacturers, airlines, governments and jurisdictions around the world.

That makes change extraordinarily difficult.

A consumer technology company may replace an application every few years. Commercial aircraft can remain in service for decades, and the communications standards supporting them may remain relevant across multiple generations of aircraft.

Security assumptions therefore age at a different speed from the physical infrastructure.

Technology that was designed when sophisticated cyberattacks were less central to the threat model may continue performing its operational function perfectly while lacking protections that would be standard in a newly designed digital system.

This is one of the defining problems of critical-infrastructure security. The equipment may not be broken. The trust model around it may be outdated.

Authentication Matters Because Information Can Be Correctly Formatted and Still Be False

Encryption and authentication solve different problems.

Encryption helps prevent unauthorized parties from reading information. Authentication provides evidence about who or what created the information.

The distinction is particularly important in aviation.

A fraudulent message does not necessarily need to contain malicious software. It may simply need to look sufficiently legitimate that the recipient believes it came from the expected source.

GAO describes the possibility of spoofed messages appearing to originate from air traffic control or airline operations. Executing such an attack would require technical knowledge, correct timing and knowledge of aviation procedures, but the underlying vulnerability exists because the communications environment does not always provide strong cryptographic proof of origin.

This turns cybersecurity into an information-integrity problem. The system needs confidence not only that a message arrived intact, but that the identity attached to that message actually generated it.

Digital signatures and stronger cryptographic authentication can provide that evidence, but deploying those controls inside existing aviation infrastructure is substantially more difficult than adding them to a new application.

The modernization challenge is therefore operational as much as technical.

Jamming and Spoofing Are Different Problems With the Same Operational Consequence

The GAO report also examines threats occurring across the electromagnetic spectrum.

Jamming attempts to overwhelm or deny legitimate communications or navigation signals. Spoofing introduces false information that appears to be legitimate. Both can degrade situational awareness and create additional workload for pilots and controllers.

FAA has identified increasing GPS and GNSS interference on international flight routes, particularly around conflict areas including the Middle East, Eastern Europe and the Baltic region. GAO notes that military jammers and counter-unmanned-aircraft systems operating in conflict zones can create interference affecting civilian aviation well beyond the immediate military objective. 

The distinction matters because cryptography cannot eliminate every spectrum attack.

Encryption does not stop someone from transmitting enough interference to block a radio signal. Authentication does not prevent an attacker from attempting to deny communications entirely.

Cryptographic controls can, however, strengthen the system’s ability to determine which information should be believed when multiple signals or messages compete for trust.

That makes cybersecurity part of a broader resilience architecture rather than a standalone solution to every threat.

Aviation Is Becoming a Machine-Identity Environment

Modern flight is increasingly dependent on systems communicating with other systems.

Aircraft exchange data with ground infrastructure. Airline operations centers communicate with fleets. Navigation technologies receive signals from external systems. Maintenance platforms interact with aircraft data. Air traffic infrastructure coordinates enormous numbers of movements continuously.

Humans remain essential to aviation safety, but much of the information supporting their decisions originates from machines.

That creates a machine-identity problem.

The receiving environment needs confidence that a message truly came from the expected aircraft, ground station or authorized system. The identity needs a credential capable of being verified. That credential needs a lifecycle governing how it is created, stored, rotated and eventually revoked.

As aviation becomes more digitally interconnected, static assumptions about where a message came from become increasingly insufficient.

Trust needs stronger evidence.

Long-Lived Aircraft Make Crypto-Agility Especially Important

The aviation sector also demonstrates why cryptographic modernization cannot be reduced to installing a new algorithm.

Aircraft remain operational for years. Ground infrastructure can remain in use for even longer. International aviation requires compatibility across countries, manufacturers, airlines and generations of equipment.

A cryptographic change that breaks interoperability can create serious operational consequences. That makes crypto-agility particularly important. An agile architecture allows organizations to change cryptographic algorithms, credentials and policies without rebuilding the underlying platform every time security requirements evolve.

The principle has immediate value when vulnerabilities emerge. It also matters for post-quantum migration. Aviation systems deployed today may remain operational during the period when organizations are transitioning away from public-key cryptography expected to become vulnerable to sufficiently capable quantum computers. Designing systems with the ability to change their cryptography therefore provides value regardless of exactly when that transition becomes necessary.

This is why post-quantum readiness should be understood as an architectural capability rather than a future software patch.

The Quantum Connection Is About Lifecycles, Not the Current FAA Report

The vulnerabilities identified by GAO are not quantum attacks, and quantum computing is not responsible for the authentication and encryption limitations described in the report.

The relevance to quantum security comes from the modernization problem aviation illustrates.

NIST has finalized post-quantum cryptographic standards and encourages organizations to begin transition planning. The challenge for industries such as aviation is that cryptography exists inside systems whose operational lifetimes are much longer than typical enterprise software.

Organizations therefore need to understand where current algorithms are embedded before migration becomes urgent.

Which communication protocols depend on public-key cryptography?

Which certificates authenticate infrastructure?

Which aircraft or ground systems cannot easily support new algorithms?

Which suppliers control the cryptographic implementations?

How can security be upgraded without reducing interoperability or aviation safety?

These are inventory, dependency and lifecycle questions before they become algorithm questions. The industries with the longest-lived assets may ultimately have the most difficult transitions.

Modernization Has to Preserve the Mission

Critical infrastructure operates under a constraint that ordinary enterprise IT does not always face.

The system cannot simply stop.

Air traffic controllers still need to communicate with aircraft while new technology is introduced. Airlines need global interoperability. Pilots cannot operate with communications standards that work in one jurisdiction but fail in another.

Security modernization therefore has to coexist with operational continuity.

GAO’s report highlights the challenge directly. Some aviation communication vulnerabilities cannot be resolved by FAA acting alone because industry stakeholders, manufacturers and other governments participate in the same systems. 

That reality makes phased adoption important.

Organizations may need hybrid cryptographic environments in which old and new technologies operate simultaneously while migration occurs. They need visibility into which systems have moved and which remain dependent on legacy controls.

They also need auditability so security teams can prove which policies are active across complex environments.

Aviation therefore provides an unusually clear example of why cybersecurity architecture has to support transition rather than simply define an ideal end state.

Where QVH Fits

Quantum Vision Holdings does not manufacture aviation communications equipment and has no disclosed involvement with FAA systems. The relevance of QVH’s technology strategy lies in the modernization architecture that the aviation problem exposes.

QVH’s current platform is designed around security-focused hardware roots of trust, NIST-informed post-quantum technologies, cryptographic lifecycle and identity management and software-defined architecture intended to integrate with existing systems rather than requiring wholesale replacement. 

Thymos is under development to assess environments for cryptographic vulnerabilities and areas where post-quantum transition planning may be required. That discovery capability addresses the first modernization problem: understanding where cryptography exists and which systems depend on it.

Enqrypta is available for prospective pilot integration and is being developed around cryptographic lifecycle management, policy enforcement, agility and audit visibility. The platform is designed to support phased adoption, hybrid cryptographic models and interoperability with current technologies, all of which are important considerations in operational environments that cannot simply be replaced at once. 

At the hardware layer, the R1 Chip is designed as a device-level root of trust supporting isolated key storage, cryptographic identity and system integrity. PhotonFlux remains under development as hardware-grade entropy technology intended to support secure randomness and key generation. 

None of these technologies should be interpreted as a proposed fix for the specific aviation communications systems identified by GAO.

The connection is architectural.

Aviation cybersecurity demonstrates what happens when critical infrastructure remains operational longer than the security assumptions under which it was originally designed. Replacing everything at once is impractical, but leaving identity and authentication weaknesses indefinitely is increasingly difficult to justify.

The challenge is therefore to create security infrastructure capable of evolving while the mission continues.

That problem extends far beyond aviation.

It is likely to define much of the post-quantum transition as well.

Sources

U.S. Government Accountability Office, “Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications” (September 21, 2026) GAO
GAO Aviation Cybersecurity report

Reuters, “US Aircraft Communications With FAA ‘Incredibly Insecure,’ Senator Says” (September 21, 2026) Reuters

National Institute of Standards and Technology, “Post-Quantum Cryptography” NIST Post-Quantum Cryptography

Quantum Vision Holdings, “Technology” Quantum Vision Holdings


Quantum Vision Holdings, “Infrastructure for the Quantum Era” Quantum Vision Holdings

Forward Looking Statement

This article contains forward-looking information within the meaning of applicable Canadian securities laws, including statements regarding the development of post quantum security infrastructure, anticipated industry migration toward post quantum cryptography, and the potential impact of evolving computational capabilities on cybersecurity frameworks.

Forward-looking information reflects management’s current expectations, estimates, projections, and assumptions as of the date of publication and is subject to known and unknown risks and uncertainties that could cause actual results to differ materially from those expressed or implied. Such risks include, but are not limited to, technological development risks, regulatory developments, adoption timelines for post-quantum standards, competitive factors, supply chain considerations, capital requirements, and general economic conditions.

Readers are cautioned not to place undue reliance on forward-looking information. Quantum Vision Holdings undertakes no obligation to update or revise forward looking information except as required by applicable securities laws.

more news

Quantum technology news you don't want to miss.

Content

Home

Company

Platform

Technology

Industries

News & Insights

Contact

Legal

Privacy Policy

Disclaimer

Terms Of Use

Contact

Mail

info@qvhinc.com

Address

Quantum Vision Holdings Inc.

36 Toronto Street, Suite 701,

Toronto, ON M5C 2C5 Canada

Corporate Entities Established in: 

United States

© 2026 Quantum Vision Holding Inc. All Rights Reserved.

Quantum technology news you don't want to miss.

Content

Home

Company

Platform

Technology

Industries

News & Insights

Contact

Legal

Privacy Policy

Disclaimer

Terms Of Use

Contact

Mail

info@qvhinc.com

Address

Quantum Vision Holdings Inc.

36 Toronto Street, Suite 701,

Toronto, ON M5C 2C5 Canada

Corporate Entities Established in:  United States

© 2025 Quantum Vision Holding Inc. All Rights Reserved.

Quantum technology news you don't want to miss.

Content

Home

Company

Platform

Technology

Industries

News & Insights

Contact

Legal

Privacy Policy

Disclaimer

Terms Of Use

Contact

Mail

info@qvhinc.com

Address

Quantum Vision Holdings Inc.

36 Toronto Street, Suite 701,

Toronto, ON M5C 2C5 Canada

Corporate Entities Established in: 

United States

© 2025 Quantum Vision Holding Inc. All Rights Reserved.