SEALSQ and wolfSSL bring quantum-safe security to devices

SEALSQ is pairing its QVault TPM with wolfTPM, enabling developers direct access to post-quantum cryptography in embedded applications, the company says. The SEALSQ QVault TPM is on track to be the first shipping device implementing the post-quantum algorithms within the Trusted Computing Group’s TPM 2.0 version 1.85 specification. “QVault implements post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to use them,” said Jean Pierre Enguent, CTO at SEALSQ, as the companies bring hardware-based post-quantum security closer to deployment and scale.

QVaultTPM Achieves First TPM 2.0 Implementation of Post-Quantum Algorithms

The QVaultTPM meets the version 1.85 specification, positioning it as the first shipping device to implement post-quantum algorithms in silicon according to that standard. This achievement builds on the QVaultTPM’s core function by integrating it with wolfTPM, a widely used component for embedded systems, and enabling developers to directly access the post-quantum cryptographic capabilities within the hardware. Testing confirmed successful ML-DSA signing and verification, alongside ML-KEM encapsulation and decapsulation, across all supported key strengths using the same tests applied to the wolfTPM Firmware TPM PQC v1.85 release.

The integration includes a new tool, pqc_ctrl, designed for development and testing, allowing developers to examine supported algorithms, run self-tests, and work with PCRs. Dedicated SEALSQ QVault support added to wolfTPM, including manufacturer detection and device-specific SPI configuration, facilitates this interoperability.

The combined system addresses a critical vulnerability in post-quantum cryptography; as Todd Ouska, CTO and co-founder of wolfSSL, explains, “Post-quantum algorithms only solve half the problem. If an attacker can extract the private key from the device, the strength or type of the algorithm is irrelevant.” Running ML-DSA and ML-KEM inside the QVault TPM ensures private keys are generated and used in hardware, remaining within the secure boundary of the TPM itself.

Ouska added that “wolfTPM is how developers leverage those operations from their application.” The integration, available on GitHub, includes QVault build instructions, post-quantum examples, hardware benchmarks, and the pqc_ctrl tool, streamlining the process for developers to incorporate quantum-resistant security into embedded applications. The system was tested on physical SEALSQ QVault TPM hardware and within wolfSSL’s firmware TPM environment, demonstrating a functional and scalable pathway for secure embedded systems.

QVault implements post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to use them.

Jean Pierre Enguent, CTO at SEALSQ
Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: