The U.S. Army is buying up to 265,000 of a new device called the Next Generation Load Device-Medium, which replaces the aging Simple Key Loader. Both devices do the same job. A person carries the device to a radio, plugs it in, and loads the secret keys that let that radio talk to other radios. The new device is faster and better built. The job it does is unchanged.That job is where the operational limits come from. The strength of Type 1 encryption is not in question. What matters day to day is how the keys get onto the radios, because that determines who can talk to whom, when that can be decided, and how long a unit is degraded after something goes wrong. Autonomous Key Management™ changes how the keys get there, and three things follow from that.
Can two radios connect in the middle of a mission?
Under Type 1, no. Two radios can talk only if both were loaded with matching keys before anyone left. The connection has to be planned, the keys have to be generated and issued through the COMSEC supply chain, and a person has to load them at both ends. A requirement that comes up after the aircraft is airborne cannot be met with keys that were never issued.
AKM works differently. Two AKM endpoints can set up a protected connection between themselves while the mission is running, with nothing issued in advance for that specific pair. An F-35 that needs to pass data to a soldier on the ground sets up that link at the moment the requirement appears.
Each connection is set up between those two endpoints and verified on its own. Adding one does not give any other endpoint new access.
What about coalition partners?
Type 1 equipment and the keys it uses are not released to most coalition partners. Where release does happen, it happens under agreements negotiated months or years ahead of an operation. Partners outside those agreements work around the gap. They run on a separate network with weaker protection, or they stay off the network and pass information by voice through a liaison officer.
Both workarounds slow the operation down, and both leave a partner acting on older information than everyone else has.
With AKM, a coalition partner running the same software joins the network the way any other endpoint joins. The link is set up when the mission calls for it and removed when it is no longer needed. Who gets access becomes a decision a commander can make during the operation.
What happens when one radio is captured?
A company deploys with 300 radios. One is captured. Those radios all hold the same keys, so the problem does not stop at the radio that was taken. Every radio holding those keys is now at risk.
The fix is to load new keys into the other 299 by hand. A COMSEC operator carries a fill device to every radio in the unit, one at a time. Any radio not yet reached has to come off the network. The unit operates degraded until the last radio is done, which takes hours, and the mission waits on it.
AKM keeps the problem on the radio that was taken. That radio is removed from the network, and the rest shift to their next set of keys on their own. That takes milliseconds. Nobody carries a device to a radio, and nothing has to reach back to a central system that may be out of range.
The captured radio is also worth little to whoever has it. AKM keys are generated for a single session, replaced constantly, and never leave the protected hardware inside the radio. Holding the radio does not mean holding the keys for the rest of the unit.
How does AKM do this?
Every AKM endpoint runs the same four steps. It starts with a small shared seed value, which the software uses to generate an unlimited supply of new keys. Those keys are replaced for every session, automatically. Each packet is checked for tampering without checking back with a central authority. If a session is disrupted, the endpoint restores it on its own.
The practical effects matter more than the mechanism. Setting up a protected connection between two endpoints takes under a millisecond, fast enough that nothing in the mission waits on it. The software is under 1MB, small enough to sit inside a handheld radio or an embedded processor. It runs air-gapped, meaning it needs no connection back to a central server to keep working.
This is also what Zero Trust looks like when it is built into the protocol. Nothing is trusted because it was trusted yesterday. Every session is verified on its own, and no long-lived credential sits on the device waiting to be stolen and reused. DoD Zero Trust guidance and NIST SP 800-207 describe that behavior, and AKM delivers it in places where those architectures normally assume network connectivity that is not there.
What this means for a program office
Key distribution stops being a logistics problem. A unit deploying with AKM does not need a re-key plan, a count of fill devices, or a COMSEC operator whose availability determines whether the network stays up.
The support costs go with it. A unit that is not re-keying by hand does not need a fill device for every formation, does not schedule COMSEC operator time around re-key events, and does not absorb the hours a unit spends degraded while a re-key runs. Once an endpoint is provisioned, key refresh is unlimited. Provision once, runs forever.
AKM installs as software into existing hardware, so a program does not have to replace fielded radios to get any of this. The open question for a program office is whether the key management inside those radios should still require a person with a fill device.
About AKMSecure
AKMSecure delivers a patented Autonomous Key Management™ protocol built to replace outdated PKI approaches with a dynamic, quantum-secure, air-gapped-capable architecture. Instead of relying on persistent credentials that can be stolen, reused, or abused, AKM enables independently verified sessions with no standing privileges left behind. The result is a model that better aligns with Zero Trust principles, reduces certificate-based risk, and supports resilient operations across enterprise IT, OT and Tactical Edge environments. Built to NSA-grade security standards and deployable as a lightweight SDK, AKMSecure helps organizations modernize trust at the protocol layer without rebuilding everything around it.

