Europe funds G+D in uPQComing project to shield IDs from quantum attacks

The Chips Joint Undertaking is funding the uPQComing project, directly investing in a proactive defense against threats posed by quantum computing to digital infrastructure. SecurityTech company Giesecke+Devrient (G+D) will focus on integrating post-quantum cryptography into the resource-constrained embedded secure elements found in modern identity cards. This work addresses a shift from viewing quantum computing as a distant threat to an upcoming reality demanding immediate preparation of critical systems. “Anyone who wants to safeguard trust in digital identities tomorrow must lay the technological groundwork today,” said Gabriel von Mitschke-Collande, Group Chief Digital Officer at G+D.

uPQComing Project Integrates PQC into Embedded Secure Elements

The uPQComing project directly addresses the practical challenges of implementing post-quantum cryptography within the tight constraints of embedded systems, specifically targeting the security of modern identity cards. Giesecke+Devrient (G+D) is developing quantum-resistant technologies for identity card operating systems, a move beyond theoretical research toward deployable solutions for secure digital identities. This work focuses on integrating post-quantum cryptographic algorithms into resource-constrained environments where processing power and memory are limited, a significant hurdle for widespread adoption.

Key tasks for G+D include adapting existing authentication methods and creating crypto-agile system architectures, allowing for flexible updates to cryptographic algorithms as the quantum threat evolves. Optimizing post-quantum cryptography for security-critical hardware demands careful consideration of performance and secure communication, as well as limited computing power and memory resources. The project team is integrating their approaches as prototypes into a Java Card chip operating system developed by G+D, with validation focused on security, efficiency, and interoperability.

This Java Card OS is a testbed for evaluating the feasibility and performance of various post-quantum algorithms in a real-world application, Giesecke+Devrient says. Hybrid approaches, combining classical and quantum-safe methods, are also under investigation to ensure robust security during the transition period and in the initial years of post-quantum cryptography deployment.

The consortium, comprised of industry partners, research institutes, and universities across Europe, is developing innovative security architectures and applications specifically for the post-quantum era. The project builds upon previous work, including a feasibility study and proof of concept for the German national ID card conducted with Bundesdruckerei, which demonstrated the practical application of post-quantum cryptography in highly secure identity documents.

With uPQComing, the team aims to expand on these findings and establish the foundations for the next generation of quantum-safe identities, strengthening Europe’s technological sovereignty in this critical security field, according to Giesecke+Devrient. The resulting technologies are intended to provide long-term security, privacy, and reliability for applications requiring robust protection against future quantum attacks, ensuring continued trust in digital identity systems.

The quantum era is fundamentally changing the requirements for digital security.

Gabriel von Mitschke-Collande, Group Chief Digital Officer at G+D
Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Dr. Donovan, Quantum Technology Futurist

Latest Posts by Dr. Donovan: