Lincoln Laboratory’s new key-management architecture solves dilemma of how to refresh cryptographic keys securely, quickly, and widely for U.S. forces.
an illustration shows a server tower labeled KMS connecting to an antenna, connecting to a satellite, which sends keys out to a variety of military plaftforms pictured (from drones, to submarines, to vehicles).
As the cryptographic core of the SATCOM architecture, PATS KMS enables secure, resilient communications across a globally distributed ecosystem of satellites, ground infrastructure, and terminals, even in contested environments. Illustration: Tammy Ko

At any given moment, an Air Force pilot may be maneuvering an aircraft mid-mission, a Navy officer resurfacing a submarine after weeks undersea, or an Army technician offloading drone data in a combat zone. Each operation depends on satellite communications (SATCOM) and, specifically, on cryptographic keys that allow terminals to communicate securely while keeping adversaries locked out.

At the scale of modern operations, managing these keys is a technical challenge. Every terminal needs to have the right keys at the right time, quickly and securely, and if any keys are compromised, they need to be refreshed without leaving out devices that may be offline, disconnected, or under attack.

MIT Lincoln Laboratory researchers have now solved this challenge with the Protected Anti-Jam Tactical SATCOM (PATS) Key Management System (KMS) Prototype. This new architecture enables keys to refresh rapidly across terminals dispersed worldwide, even in contested or bandwidth-constrained environments.

"We're enabling the nation to achieve highly assured, highly available communications. Even when adversaries know where forces are operating and are trying to stop them from communicating, they're unable to do so because we've built in smarts across this entire system to keep talking,” says Joseph Sobchuk, a principal investigator of the PATS KMS Prototype program and researcher in the Secure Resilient Systems and Technology Group.

This architecture is being adopted as the cryptographic backbone of the U.S. Space Force's next-generation SATCOM system, PATS. The KMS Prototype serves as the gold-standard reference implementation for the industry-built operational KMS, which will be integrated across the PATS ecosystem, encompassing satellites, user terminals on military platforms, and ground-based communication hubs.

Developed under sponsorship of the Space Force’s Space Systems Command (SSC), the KMS Prototype reflects Lincoln Laboratory's end-to-end approach to technology development, from shaping the core key-management concepts, to putting them into practice in a prototype, to transitioning a technical baseline to government and industry. For this transitioned innovation, the SSC and Lincoln Laboratory team received a 2025 R&D 100 Award, recognizing the KMS Prototype among the year’s most impactful new technologies.

Managing key challenges

Cryptographic keys are foundational to secure communications. These keys, strings of random characters used by cryptographic algorithms, help protect communications by encrypting data and supporting protected transmission patterns, such as frequency hopping. Without key protection, the communications sent and received by terminals are more susceptible to eavesdropping and interference.

Historically, operators manually uploaded keys to terminals before missions. More recently, some systems have supported over-the-air key updates, but bandwidth constraints, security concerns, and operational complexity have limited real-time, wide-scale refresh.  

"Key management is the linchpin that turns advanced, anti-jam hardware and waveforms into a usable mission capability," says Roger Khazan, leader of the Secure Resilient Systems and Technology Group. "Without a scalable way to deliver the right keys to the right systems at the right time, protected SATCOM cannot operate reliably across a dynamic force."

One primary threat to SATCOM is signal jamming, where adversaries flood specific frequencies with noise. To resist jamming, PATS uses frequency hopping, in which signals jump rapidly between frequencies in a pattern that looks random to anyone without the key. This hopping only works when every legitimate terminal holds current keys and stays in sync. Keeping all those terminals correctly keyed is the KMS's job. "Designing a system to handle that coordination efficiently, without breaking the conversation, is incredibly difficult," Sobchuk says.

Maintaining synchronization becomes even more critical when devices are compromised. Terminals share keying material so they can communicate as a group and follow protected hopping patterns. If an adversary captures a device, such as a downed drone, and extracts its keys, the exposure can extend beyond that one device. Depending on what keying material is exposed, an adversary may gain access to protected communications or help a jammer follow the hopping pattern. Restoring security means refreshing keys for legitimate terminals — including those that may be offline or operating in contested conditions — while locking the captured device out.

But here's the catch: to send new keys, you need to establish a secure link to terminals, and to establish a secure link, terminals need valid keys. This situation creates a longstanding "chicken-or-egg" problem for key management.

Solving the chicken-or-egg problem

The Laboratory's solution is a hybrid key distribution method using a "pull-and-push" approach. Each month, each terminal "pulls" a package of keys tailored to that terminal over the SATCOM link. Then, daily, the satellite "pushes" a smaller key to every terminal. The monthly keys encrypt the daily keys, creating layered security. The daily key determines the unpredictable frequency-hopping patterns. Even if an adversary captures today's key, tomorrow's will be different and encrypted to exclude them.

"This way of sending keys hadn't existed before," Sobchuk says, adding that Laboratory researchers have been pioneering this key-management technology for more than a decade. "The combination of pull and push, monthly and daily, is the magic behind all of it."

This hybrid approach also solves the issue of leaving out devices that were disconnected during a key refresh. For instance, if a submarine submerges for six months, it can request keys for the entire period in advance. Even if keys are refreshed while it's offline, the submarine can immediately reconnect when it resurfaces because the monthly keys provide access to the daily key.

"Submarine crews want to log on to the satellite and talk right away, not wait to get back to shore for new keys. They want to turn on their system and have it work," Sobchuk says.

Monthly and daily key broadcasts must reach thousands of devices spanning the globe. To enable this large-scale sharing, the team adapted theoretical algorithms from academia to create the first operational-scale implementation of broadcast encryption for such a protected SATCOM application. Broadcast encryption is a method for securely sending information to many users at once. These algorithms encrypt each daily key using just a small subset of keys instead of separately encrypting the daily key for every terminal. This implementation preserves communication bandwidth that would otherwise be consumed just by sending keys.

"The point isn't just stronger cryptography. It's making secure communications usable at operational scale, in contested conditions, without imposing a crippling burden on the warfighters and operators who depend on them," says Sean O'Melia, an assistant leader in the Secure Resilient Systems and Technology Group.

Six researchers stand in a lab, showing computer screens, monitors, and a rack of hardware.
Lincoln Laboratory researchers demonstrate the PATS Key Management System Prototype, showing its rackmount server integration and graphical interfaces for managing cryptographic keys. Photo: Glen Cooper

Transitioning to operations

Lincoln Laboratory has transitioned the KMS Prototype to multiple government and industry partners developing PATS components across service branches. To facilitate this coordination, the team has supported dozens of integration events and produced in-depth technical documentation. The prototype is allowing developers to test and validate their components while defense contractors build the operational version of KMS.

The Laboratory's work is also enabling contractors to achieve National Security Agency (NSA) certification of end cryptographic units (ECUs), the hardware devices within a terminal that transmit, receive, or store keys. Last year, the first PATS ECU — the space-hub ECU that goes on the satellite — earned NSA certification. Achieving this certification is an arduous process requiring proof that the design, implementation, and supporting processes are all secure.

After years of work, the team is grateful to have helped lay a foundation for the future of secure SATCOM, both through the KMS Prototype and the larger PATS technical vision, Khazan says. The effort brought together expertise from across the Laboratory’s Cyber Security and Information Sciences Division and Communication Systems Division.

"PATS KMS is the kind of problem Lincoln Laboratory was built to solve: high-risk research, rigorous engineering, and transition into a national-security capability. Working with Space Systems Command and the PATS community, our team helped turn advanced key-management ideas into a technical baseline that industry can build on and the government can use. The result is a more resilient SATCOM architecture that can scale across a complex operational ecosystem," he says.