Encrypted transport
Browser-to-edge communication uses TLS. Node-to-node peer sessions derive fresh keys and protect frames with authenticated encryption.
QSCS anchors identity to cryptographic keypairs. Protected requests are signed, checked for freshness, carried through encrypted channels, and accepted only within the identity, node, and origin boundaries they belong to.
CLIENT IDENTITY
Illustrative identity, not an active credential.
The UUID is a public client identifier. QSCS binds it and the relevant origin to the client’s Ed25519 public key.
Your browser generates and retains an Ed25519 private key. The saved identity is encrypted with AES-GCM, and protected requests are signed locally without sending the private key to the server.
After authentication, QSCS binds a client UUID and Ed25519 public key to an origin. Protected requests must carry a valid signature, proving possession of the matching private key.
TRUST BOUNDARIES
QSCS carries trust through encrypted transport, configured peer relationships, cluster membership, and origin-scoped identity. Each boundary must be satisfied before protected state is allowed to move.
Browser-to-edge communication uses TLS. Node-to-node peer sessions derive fresh keys and protect frames with authenticated encryption.
Nodes register a UUID and license token with the control plane. Peer admission also checks configured addresses and domain membership.
Identity bindings are scoped to (UUID, origin). Trust is not automatically shared across origins: sharing requires an explicitly configured federation relationship.
DETERMINISTIC SECURITY
Retries and conflict resolution complicate execution paths under load. QSCS moves shared-state coordination into defined state and delta mechanics, reducing the exceptional paths an application has to manage.
Nodes follow deterministic rules instead of independent retry and conflict paths.
Deltas relate to a specific state. Transitions must match the current state.
Nodes re-align via defined state and delta mechanics.
THE RESULT
See how QSCS combines a smaller network surface with deterministic infrastructure, and how the QSCS Trust Layer establishes cryptographic identity across the remaining boundaries.