Quantum-Resistant Communication for Autonomous Mobile Robots (AMRs)

Motivation & challenges

In the industrial automation sector, cybersecurity is not just about protecting data—it is about physical safety . Unlike traditional IT systems, a breach in a robotic fleet can have immediate kinetic consequences, leading to operational halts or even life-threatening collisions in shared human-robot workspaces. The primary challenge is protecting these fleets from the future threat of quantum computing without sacrificing real-time performance. Robots operate on millisecond-level control loops; any security overhead must be virtually “zero-lag” to ensure that obstacle detection and path planning remain safe and agile.

Current landscape

Today, Autonomous Mobile Robot (AMR) fleets—such as our TIAGo OMNI Base —predominantly rely on network-layer defenses like VPNs. However, this creates a “flat trust” environment: once the perimeter is breached, internal communications (often via ROS 2) are frequently transmitted in plaintext. This makes entire fleets vulnerable to eavesdropping and command injection. Furthermore, current identity management relies on classical cryptography (RSA/ECC) that is susceptible to future quantum attacks, putting proprietary industrial data, such as high-resolution facility maps and operational logs, at risk.

Use Case description, goals and objectives

Within PiQASO, PAL Robotics leads the Automation Use Case to design and validate the next generation of quantum-secure fleet architectures. By integrating the PiQASO SDK and utilizing FPGA-based hardware acceleration, we are embedding Post-Quantum Cryptography (PQC) directly into the heart of robotic operations.

Our key objectives include:

- Quantum-Secure Communications: Implementing end-to-end PQC encryption for real-time ROS 2 traffic, ensuring mission-critical commands remain untamperable.

- Hardware-Accelerated Safety: Offloading cryptographic tasks to a Quantum-Resistant Trusted Computing Base (QR-TCB) to maintain ultra-low latency for navigation.

- Granular Data Protection (ABE): Using Attribute-Based Encryption to ensure that sensitive facility maps and rosbags are only accessible to authorized roles (e.g., Admins vs. Operators).

- ASSIST (Secure Remote Intervention): Creating a verified “emergency tunnel” for human technicians to securely take manual control of a robot, protecting the intervention from cyber-kinetic hijacking.

About PAL Robotics

PAL Robotics S.L. is an R&D SME founded in 2004, specialized in applied robotics products and services.

PAL Robotics’ research efforts have led to the development of various humanoid and service robot models, with the aim of providing advanced technological solutions that support work across different sectors and contribute to a more efficient, safer, and human-centered society.

The company is internationally recognized for its research activities and development of advanced robotic solutions supporting multiple sectors. Its portfolio includes humanoid and service robots designed to improve efficiency, safety, and human-centered environments.

PAL Robotics has extensive experience in bipedal humanoid platforms such as TALOS, and KANGAROO, widely used in leading European research labs and industrial applications. In parallel, the company develops application-oriented robots, including the TIAGo family of mobile manipulators for human–robot collaboration, STOCKBOT for retail inventory, and ARI and TIAGo Head for social interaction. It also offers the TIAGo Base family of AMRs for intralogistics. PAL Robotics provides a broad range of robotic components and capabilities, including actuation, manipulation, perception, and custom platform development.

The company is actively involved in major European and national robotics associations and participates in numerous EU- and nationally funded collaborative projects across sectors such as manufacturing, retail, healthcare, and research.

The project funded under Grant Agreement No. ​101190366​ is supported by the European Cybersecurity Competence CentreFunded by the European Union.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Cybersecurity Competence Centre.
Neither the European Union nor the granting authority can be held responsible for them.