Cybersecurity in the AI and Quantum Era
Based on the key findings of The Next Security Shift White Paper authored by Loic Hamon, COO, SEALSQ USA.
Executive Summary
Artificial Intelligence is accelerating cyberattacks. Quantum computing will eventually break today's most widely deployed public-key cryptography. At the same time, connected devices are becoming increasingly exposed to both cyber and physical attacks.
The question organizations must answer is no longer simply "Which cryptographic algorithm should we use?" The real question is: Where does trust begin?
According to Loic Hamon, trust cannot rely solely on software. It must be anchored in certified hardware capable of protecting identities, cryptographic keys and critical security functions throughout the entire lifecycle of a connected device.
What Is Changing in Cybersecurity?
Cybersecurity is entering a new phase.
Vehicles, medical devices, industrial systems, robots, smart meters, payment terminals, satellites and billions of connected devices increasingly depend on software updates, digital identities and trusted communications to operate securely.
A successful attack may no longer result only in data theft. It can disrupt operations, compromise safety, or manipulate critical systems at scale
Key Message #1: Security Is at a Fundamental Turning Point
Modern attackers do not necessarily need to break encryption itself.
Instead, they often target the chain of trust through:
- Software vulnerabilities
- Weak communication channels
- Physical access to devices
- Side-channel attacks
- Fault injection techniques
As described in the white paper, once cryptographic keys are compromised, attackers can impersonate legitimate devices, electronic control units, software updates or cloud services. The impact can extend across entire fleets of products sharing the same architecture.
Cybersecurity is therefore not simply an IT challenge. It is fundamentally a trust challenge. Trust in the device. Trust in the software. Trust in every interaction with the outside world.
Is Quantum Computing the Biggest Security Threat?
The cybersecurity industry is investing heavily in Post-Quantum Cryptography because future quantum computers are expected to break widely deployed asymmetric cryptographic algorithms such as RSA and Elliptic Curve Cryptography.
Migrating to quantum-resistant cryptography is essential.
However, new algorithms alone do not solve the complete security problem.
Key Message #2: Post-Quantum Cryptography Is Essential, But AI May Be an Even Bigger Threat
The white paper argues that Artificial Intelligence is rapidly becoming a force multiplier for attackers. AI accelerates vulnerability discovery, reverse engineering and attack automation, reducing both the time and expertise required to identify weaknesses.
As AI capabilities continue to evolve, attackers gain access to tools that can analyze software and hardware architectures faster and more systematically than traditional approaches.
As Loic Hamon notes:
"A security solution that is not strong enough will have its weaknesses found. AI makes this faster and easier."
Organizations therefore face a dual challenge:
- Prepare for the transition to Post-Quantum Cryptography.
- Build security on trusted hardware foundations capable of resisting both classical and AI-assisted attacks.
Why Does Trust Start with Hardware?
Every security architecture ultimately depends on where cryptographic keys are generated, stored and protected.
Encryption algorithms are only effective if the associated keys remain secure.
Key Message #3: Trust Starts with Hardware
The white paper identifies Hardware Roots of Trust as the foundation of modern device security. These technologies establish trusted environments for:
- Key generation
- Key storage
- Device identity protection
- Secure boot
- Authentication
- Attestation
Examples include:
- Secure Elements
- Trusted Platform Modules (TPMs)
- Hardware Security Modules (HSMs)
- Dedicated security processors
These components create an independent hardware layer that remains trusted even if higher software layers are compromised.
The white paper further highlights that trust must extend throughout the entire lifecycle of a product, including manufacturing, provisioning, deployment and operation in the field. Cryptographic keys must remain protected across every stage of the supply chain.
Why Is Hardware Certification Becoming Critical?
Modern processors often include secure enclaves and isolated execution environments designed to strengthen security.
These technologies provide valuable protection, particularly in cloud and enterprise environments.
However, connected devices deployed in the physical world face a different threat model.
Key Message #4: Certified Hardware, Proven by Formal Methods, Is Becoming a Requirement
The white paper draws a clear distinction between security features and certified security. Simply implementing security mechanisms is not equivalent to independently validating their effectiveness.
Certified security components typically undergo:
- Formal or semi-formal verification
- Rigorous threat analysis
- Independent evaluation
- Resistance testing against physical attacks
- Certification processes such as Common Criteria
These assessments provide confidence that security claims have been independently validated against real-world attack scenarios
As AI-powered attacks become more sophisticated, the white paper argues that independently evaluated and certified hardware protection is increasingly becoming a requirement rather than an option
The Next Security Architecture: Certified HSM Chiplets
Beyond evolving threats, semiconductor architectures are also changing.
The industry is increasingly moving toward chiplet and advanced System-in-Package approaches where multiple specialized dies operate together within a single package.
What Could This Look Like?
The architecture described in the white paper combines:
- High-performance processors
- AI accelerators
- Secure enclaves
- Dedicated certified HSM chiplets
In this model, the certified HSM chiplet independently protects cryptographic keys, device identities, secure boot mechanisms and attestation functions, while the main processor focuses on performance and application workloads.
The two environments are cryptographically bound together to create a unified chain of trust while preserving their distinct roles.
This approach aims to combine:
- Advanced computing performance
- Artificial Intelligence processing
- Independent hardware security
- Long-term cryptographic agility
Frequently Asked Questions
What is a Hardware Root of Trust?
A Hardware Root of Trust is a security component that establishes and protects the foundational trust of a device by securing cryptographic keys, identities and critical security functions. Examples include Secure Elements, TPMs and HSMs.
Is Post-Quantum Cryptography sufficient on its own?
No. The white paper states that while Post-Quantum Cryptography is necessary, cryptographic keys and implementations still require a trusted hardware foundation.
Why is AI changing cybersecurity?
According to the white paper, AI accelerates vulnerability discovery, reverse engineering and attack automation, reducing the effort and expertise required to conduct sophisticated attacks
Why does certification matter?
Certification provides independent validation that security mechanisms have been evaluated against defined threat models and attack scenarios. The white paper specifically references Common Criteria evaluations as an example of this process.
Which industries are most concerned?
The paper highlights environments where attackers may gain physical access to devices, including automotive, industrial systems, medical devices, robotics, payment systems and IoT deployments.
Read the Full White Paper
This article summarizes the four key messages presented in The Next Security Shift White Paper by Loic Hamon.
The complete white paper explores:
- Why cybersecurity is reaching a fundamental turning point.
- Why AI may become a greater challenge than quantum computing.
- Why trust must start with certified hardware.
- How HSM chiplets could shape future secure architectures.
About the Author
Loic Hamon is COO, SEALSQ USA. The paper examines the convergence of Artificial Intelligence, Post-Quantum Cryptography, Hardware Roots of Trust, Common Criteria certification and emerging semiconductor security architectures.
Conclusion
Cybersecurity is entering a new era defined by three simultaneous shifts: the expansion of connected systems, the transition toward Post-Quantum Cryptography and the rise of Artificial Intelligence as an offensive force multiplier.
The organizations best positioned for this future will not rely solely on stronger algorithms. They will build trust from the hardware up, using independently evaluated and certified security foundations capable of protecting identities, cryptographic assets and digital trust throughout the lifecycle of connected systems.
Authored by Loic Hamon
