Skip to content
Use case 093

Military Tactical Edge Computers

A deployment concept for Defence programme offices buying rugged tactical computing systems; Rugged computer manufacturers integrating execution platforms into equipment; Mission-system primes adapting applications for disconnected field operation.

Proposed deployment · Compatibility assessment required
Government, Public Safety and Defence

Why this environment matters

A tactical edge computer may operate with intermittent links and an increased risk of physical capture. It must make useful local decisions without assuming that a central identity or update service is reachable. This concept examines how a mission-scoped execution environment could constrain access while making its disconnected limits explicit.

The security challenge

Before deployment, an authorised process could provision a defined set of mission applications, datasets and temporary permissions. A candidate NØNOS runtime would admit only the approved capsules and expose the devices needed for that task. A communications decoder would not automatically obtain the authority to modify mission data or approve an outgoing command.

How the capsule model could help

The hard question is how permissions age without connectivity. The design would specify what continues, what expires and which local authority may approve an exception. It would also identify how the device detects clock uncertainty. Simply caching an online login and treating it as permanent would leave the mission boundary undefined. RAM-resident operation might limit some persistent application residue, but it does not make captured hardware self-protecting. Keys can remain exposed during an active session, and firmware, peripherals or retained storage may hold relevant material. The hardware trust base and key-handling design would therefore be explicit assessment items. On reconnection, the device should reconcile mission events and revocation information rather than silently extending yesterday’s permissions. An evaluation could exercise these transitions with synthetic mission data, while keeping operational authorisation, classified material and deployment approval outside the prototype.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

Military accreditation, approval for classified processing and resistance to physical capture have not been established. Drivers, cryptographic provisioning, secure boot, hardware behavior and mission-specific operating procedures would need independent assessment. Evaluation requirements: Remove connectivity across a permission-expiry boundary and verify the documented continuation or refusal behavior. Introduce clock uncertainty and demonstrate that the device does not silently extend time-bounded authority. Revoke a provisioned application while the device is offline, then check the defined reconciliation behavior on return.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

Carry a bounded authority into a disconnected period

Before deployment, an authorised process could provision a defined set of mission applications, datasets and temporary permissions. A candidate NØNOS runtime would admit only the approved capsules and expose the devices needed for that task. A communications decoder would not automatically obtain the authority to modify mission data or approve an outgoing command.

The hard question is how permissions age without connectivity. The design would specify what continues, what expires and which local authority may approve an exception. It would also identify how the device detects clock uncertainty. Simply caching an online login and treating it as permanent would leave the mission boundary undefined.

Plan for capture and for lost state separately

RAM-resident operation might limit some persistent application residue, but it does not make captured hardware self-protecting. Keys can remain exposed during an active session, and firmware, peripherals or retained storage may hold relevant material. The hardware trust base and key-handling design would therefore be explicit assessment items.

On reconnection, the device should reconcile mission events and revocation information rather than silently extending yesterday’s permissions. An evaluation could exercise these transitions with synthetic mission data, while keeping operational authorisation, classified material and deployment approval outside the prototype.

Who could buy or integrate it?

  • Defence programme offices buying rugged tactical computing systems
  • Rugged computer manufacturers integrating execution platforms into equipment
  • Mission-system primes adapting applications for disconnected field operation

Industry examples: Curtiss-Wright, Mercury Systems. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$1.77 billion

Military embedded systems

Global · 2023 · annual market estimate

Embedded military computing across air, ground and naval platforms, including upgrades; not total defence expenditure or all military desktops.

Modelled global devices
100K–3M

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$15M–$1.8B

USD / year at full model coverage

Device scenario × assumed US$150–$600 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 5,000–30,000 military units with tactical digital command equipment × 20–100 candidate OS endpoints per site/asset = 100,000–3,000,000 endpoints. Counting unit: tactical edge computers; radio-only devices excluded. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Military embedded systems market report ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.