Based on the key findings of The Next Security Shift White Paper authored by Loic Hamon, COO, SEALSQ USA.
Artificial Intelligence is accelerating cyberattacks. Quantum computing will eventually break today's most widely deployed public-key cryptography. At the same time, connected devices are becoming increasingly exposed to both cyber and physical attacks.
The question organizations must answer is no longer simply "Which cryptographic algorithm should we use?" The real question is: Where does trust begin?
According to Loic Hamon, trust cannot rely solely on software. It must be anchored in certified hardware capable of protecting identities, cryptographic keys and critical security functions throughout the entire lifecycle of a connected device.
Cybersecurity is entering a new phase.
Vehicles, medical devices, industrial systems, robots, smart meters, payment terminals, satellites and billions of connected devices increasingly depend on software updates, digital identities and trusted communications to operate securely.
A successful attack may no longer result only in data theft. It can disrupt operations, compromise safety, or manipulate critical systems at scale
Modern attackers do not necessarily need to break encryption itself.
Instead, they often target the chain of trust through:
As described in the white paper, once cryptographic keys are compromised, attackers can impersonate legitimate devices, electronic control units, software updates or cloud services. The impact can extend across entire fleets of products sharing the same architecture.
Cybersecurity is therefore not simply an IT challenge. It is fundamentally a trust challenge. Trust in the device. Trust in the software. Trust in every interaction with the outside world.
Is Quantum Computing the Biggest Security Threat?
The cybersecurity industry is investing heavily in Post-Quantum Cryptography because future quantum computers are expected to break widely deployed asymmetric cryptographic algorithms such as RSA and Elliptic Curve Cryptography.
Migrating to quantum-resistant cryptography is essential.
However, new algorithms alone do not solve the complete security problem.
The white paper argues that Artificial Intelligence is rapidly becoming a force multiplier for attackers. AI accelerates vulnerability discovery, reverse engineering and attack automation, reducing both the time and expertise required to identify weaknesses.
As AI capabilities continue to evolve, attackers gain access to tools that can analyze software and hardware architectures faster and more systematically than traditional approaches.
As Loic Hamon notes:
"A security solution that is not strong enough will have its weaknesses found. AI makes this faster and easier."
Organizations therefore face a dual challenge:
Why Does Trust Start with Hardware?
Every security architecture ultimately depends on where cryptographic keys are generated, stored and protected.
Encryption algorithms are only effective if the associated keys remain secure.
The white paper identifies Hardware Roots of Trust as the foundation of modern device security. These technologies establish trusted environments for:
Examples include:
These components create an independent hardware layer that remains trusted even if higher software layers are compromised.
The white paper further highlights that trust must extend throughout the entire lifecycle of a product, including manufacturing, provisioning, deployment and operation in the field. Cryptographic keys must remain protected across every stage of the supply chain.
Modern processors often include secure enclaves and isolated execution environments designed to strengthen security.
These technologies provide valuable protection, particularly in cloud and enterprise environments.
However, connected devices deployed in the physical world face a different threat model.
The white paper draws a clear distinction between security features and certified security. Simply implementing security mechanisms is not equivalent to independently validating their effectiveness.
Certified security components typically undergo:
These assessments provide confidence that security claims have been independently validated against real-world attack scenarios
As AI-powered attacks become more sophisticated, the white paper argues that independently evaluated and certified hardware protection is increasingly becoming a requirement rather than an option
Beyond evolving threats, semiconductor architectures are also changing.
The industry is increasingly moving toward chiplet and advanced System-in-Package approaches where multiple specialized dies operate together within a single package.
What Could This Look Like?
The architecture described in the white paper combines:
In this model, the certified HSM chiplet independently protects cryptographic keys, device identities, secure boot mechanisms and attestation functions, while the main processor focuses on performance and application workloads.
The two environments are cryptographically bound together to create a unified chain of trust while preserving their distinct roles.
This approach aims to combine:
A Hardware Root of Trust is a security component that establishes and protects the foundational trust of a device by securing cryptographic keys, identities and critical security functions. Examples include Secure Elements, TPMs and HSMs.
No. The white paper states that while Post-Quantum Cryptography is necessary, cryptographic keys and implementations still require a trusted hardware foundation.
According to the white paper, AI accelerates vulnerability discovery, reverse engineering and attack automation, reducing the effort and expertise required to conduct sophisticated attacks
Certification provides independent validation that security mechanisms have been evaluated against defined threat models and attack scenarios. The white paper specifically references Common Criteria evaluations as an example of this process.
The paper highlights environments where attackers may gain physical access to devices, including automotive, industrial systems, medical devices, robotics, payment systems and IoT deployments.
This article summarizes the four key messages presented in The Next Security Shift White Paper by Loic Hamon.
The complete white paper explores:
About the Author
Loic Hamon is COO, SEALSQ USA. The paper examines the convergence of Artificial Intelligence, Post-Quantum Cryptography, Hardware Roots of Trust, Common Criteria certification and emerging semiconductor security architectures.
Cybersecurity is entering a new era defined by three simultaneous shifts: the expansion of connected systems, the transition toward Post-Quantum Cryptography and the rise of Artificial Intelligence as an offensive force multiplier.
The organizations best positioned for this future will not rely solely on stronger algorithms. They will build trust from the hardware up, using independently evaluated and certified security foundations capable of protecting identities, cryptographic assets and digital trust throughout the lifecycle of connected systems.