SEALSQ Corp and wolfSSL Inc integrate post-quantum algorithms into QVault TPM technology
News provided bySEALSQ Corp · 2 min read
On September 3, 2026, SEALSQ Corp (NASDAQ: LAES) and wolfSSL Inc. announced the integration of wolfTPM support for SEALSQ’s QVault TPM technology. This development is significant as it marks a step forward in the implementation of post-quantum algorithms in hardware and software solutions.
SEALSQ, a company that specializes in developing and selling semiconductors, public key infrastructure (PKI), and post-quantum technology, has positioned QVault TPM as the first shipping TPM 2.0 device to incorporate post-quantum algorithms as per the Trusted Computing Group’s latest TPM 2.0 v1.85 specification. wolfSSL, a leader in embedded cryptography, has provided the necessary software support for this integration.
"This integration demonstrates perfect interoperability with the TPM 2.0 standard and with popular components like wolfTPM," stated Jean Pierre Enguent, CTO of SEALSQ. "Together, we are bringing hardware-based post-quantum security closer to real-world deployment and scale."
The integration adds dedicated QVault support to wolfTPM, including manufacturer detection and specific SPI configuration. For development and testing, a new tool called pqc_ctrl has been introduced. This tool allows developers to examine supported algorithms, run self-tests, generate random data, interact with PCRs, and test the supported ML-DSA, Hash-ML-DSA, and ML-KEM parameter sets from a single interface.
The integration was rigorously tested on physical SEALSQ QVault TPM hardware and in wolfSSL’s firmware TPM environment. It passed all wolfSSL Post-Quantum Cryptography (PQC) testing, including ML-DSA signing and verification and ML-KEM encapsulation and decapsulation at all key strengths.
According to Todd Ouska, CTO and co-founder of wolfSSL, "Post-quantum algorithms only solve half the problem. If an attacker can extract the private key from the device, the strength or type of the algorithm is irrelevant. Running ML-DSA and ML-KEM inside the SEALSQ QVault TPM means the private keys are generated and used in hardware and never leave the TPM boundary. wolfTPM is how developers leverage these operations from their applications."
The integration includes QVault build instructions, post-quantum examples, hardware benchmarks, and the new pqc_ctrl tool. It is available on the wolfSSL GitHub repository at <https://github.com/wolfSSL/wolfTPM/pull/570#issuecomment-5287784621>.
SEALSQ Corp's QVault TPM is designed to implement post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to utilize these algorithms. The combined solution is expected to facilitate the market launch and scalability of quantum-resistant solutions, ensuring the security of connected devices.
"This integration is a significant milestone in the development of post-quantum security solutions," Enguent added. "By working together, we are addressing the urgent security challenges posed by quantum computing and ensuring that our technology is future-proof."
WolfSSL, known for its high-performance, lightweight security solutions, has a track record of delivering secure designs across industries such as government, automotive, and avionics. SEALSQ Corp, on the other hand, is a leading innovator in post-quantum technology, with a focus on developing robust, future-proof protection for sensitive data in various applications.