Validating a Post-Quantum Root of Trust: SEALSQ QVault TPM and wolfTPM
Executive Summary
The transition to post-quantum cryptography is moving beyond research and standardization into hardware security architectures. SEALSQ's QVault TPM implements the post-quantum capabilities introduced in the Trusted Computing Group TPM 2.0 Library Specification v1.85, including ML-DSA, Hash-ML-DSA and ML-KEM.
Independent validation performed through the wolfTPM ecosystem demonstrated these capabilities operating on real hardware, with post-quantum keys generated and protected inside the TPM. Testing on a Raspberry Pi 5 connected to the QVault TPM over SPI measured ML-DSA-65 verification at approximately 161 ms, ML-DSA-65 key generation at approximately 769 ms, ML-KEM-768 encapsulation at approximately 210 ms and ML-KEM-768 decapsulation at approximately 424 ms.
Key Findings
- ML-DSA-65 verification: ~161 ms
- ML-DSA-65 key generation: ~769 ms
- ML-KEM-768 encapsulation: ~210 ms
- ML-KEM-768 decapsulation: ~424 ms
The results demonstrate that post-quantum cryptographic operations can already be integrated into TPM-based hardware Roots of Trust, enabling OEMs, device manufacturers and enterprise platform architects to evaluate post-quantum trusted computing architectures today.
Bringing Post-Quantum Cryptography into the TPM
The QVault TPM implements the TPM 2.0 v1.85 post-quantum command set while maintaining compatibility with established cryptographic functions.
Supported Algorithms
- ML-DSA
- Hash-ML-DSA
- ML-KEM
- RSA
- ECC
- AES
- SHA-2
The device also incorporates a SHA-384 PCR bank for platform integrity measurements.
One of its most significant architectural characteristics is on-chip key custody. ML-DSA private key material remains inside the TPM throughout the lifecycle of the cryptographic operation. Applications receive only public keys, signatures and cryptographic outputs, preserving the hardware isolation model that has long underpinned trusted computing.
This approach allows organizations to evaluate post-quantum cryptography while maintaining the security principles already used for platform identity and credential protection.
Independent Validation Through wolfSSL
A hardware Root of Trust is only valuable if it can interoperate with the software ecosystems used by developers and platform manufacturers.
To validate the implementation, the QVault TPM was integrated with the wolfTPM framework from wolfSSL, a portable TPM 2.0 stack designed for environments ranging from Linux platforms to embedded systems.
Partner Resources
- https://www.wolfssl.com/wolftpm-adds-post-quantum-support-for-the-sealsq-qvault-tpm/
Validation Scope
- ML-DSA key generation
- ML-DSA signing
- ML-DSA signature verification
- Hash-ML-DSA operations
- ML-KEM key generation
- ML-KEM encapsulation
- ML-KEM decapsulation
- TPM capability discovery
- PCR operations
- TPM self-test functions
- Random-number generation
WolfSSL also developed dedicated validation utilities capable of exercising the complete ML-DSA, Hash-ML-DSA and ML-KEM parameter sets exposed through the TPM interface.
This provides independent validation of interoperability between post-quantum TPM hardware and real-world software environments.
References
Authored by N.Pangaud