SEALSQ is pairing its QVault TPM with wolfTPM, enabling developers direct access to post-quantum cryptography in embedded applications, the company says. The SEALSQ QVault TPM is on track to be the first shipping device implementing the post-quantum algorithms within the Trusted Computing Group’s TPM 2.0 version 1.85 specification. “QVault implements post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to use them,” said Jean Pierre Enguent, CTO at SEALSQ, as the companies bring hardware-based post-quantum security closer to deployment and scale.
QVaultTPM Achieves First TPM 2.0 Implementation of Post-Quantum Algorithms
The QVaultTPM meets the version 1.85 specification, positioning it as the first shipping device to implement post-quantum algorithms in silicon according to that standard. This achievement builds on the QVaultTPM’s core function by integrating it with wolfTPM, a widely used component for embedded systems, and enabling developers to directly access the post-quantum cryptographic capabilities within the hardware. Testing confirmed successful ML-DSA signing and verification, alongside ML-KEM encapsulation and decapsulation, across all supported key strengths using the same tests applied to the wolfTPM Firmware TPM PQC v1.85 release.
The integration includes a new tool, pqc_ctrl, designed for development and testing, allowing developers to examine supported algorithms, run self-tests, and work with PCRs. Dedicated SEALSQ QVault support added to wolfTPM, including manufacturer detection and device-specific SPI configuration, facilitates this interoperability.
The combined system addresses a critical vulnerability in post-quantum cryptography; as Todd Ouska, CTO and co-founder of wolfSSL, explains, “Post-quantum algorithms only solve half the problem. If an attacker can extract the private key from the device, the strength or type of the algorithm is irrelevant.” Running ML-DSA and ML-KEM inside the QVault TPM ensures private keys are generated and used in hardware, remaining within the secure boundary of the TPM itself.
Ouska added that “wolfTPM is how developers leverage those operations from their application.” The integration, available on GitHub, includes QVault build instructions, post-quantum examples, hardware benchmarks, and the pqc_ctrl tool, streamlining the process for developers to incorporate quantum-resistant security into embedded applications. The system was tested on physical SEALSQ QVault TPM hardware and within wolfSSL’s firmware TPM environment, demonstrating a functional and scalable pathway for secure embedded systems.
QVault implements post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to use them.
Jean Pierre Enguent, CTO at SEALSQ
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.




