SEALSQ and wolfSSL Add wolfTPM Support for QVault Post-Quantum TPM

Insider Brief
- SEALSQ and wolfSSL have announced wolfTPM support for the SEALSQ QVault TPM, adding software support for post-quantum algorithms implemented in the TPM hardware.
- The integration supports ML-DSA, Hash-ML-DSA and ML-KEM parameter sets, with testing performed on physical QVault hardware and wolfSSL’s firmware TPM environment.
- wolfTPM includes QVault-specific support, a new
pqc_ctrltool, post-quantum examples, build instructions and hardware benchmarks for embedded development.
PRESS RELEASE — SEALSQ Corp (NASDAQ: LAES) (“SEALSQ” or “Company”), a company that focuses on developing and selling Semiconductors, PKI, and Post-Quantum technology hardware and software products, and wolfSSL Inc., a recognized leader in embedded cryptography, today announced wolfTPM support for the SEALSQ QVault TPM.
Market First
The SEALSQ QVault TPM is on track to be the first shipping TPM 2.0 device on the market to implement in silicon the post-quantum algorithms introduced in the Trusted Computing Group’s latest TPM 2.0 v1.85 specification. wolfTPM gives developers a direct path to use QVault’s ML-DSA and ML-KEM capabilities in embedded applications.
Perfect Interoperability and Scalability
This integration demonstrates the perfect interoperability of QVaultTPM with the TPM 2.0 standard and with widespread components like wolfTPM that follow this standard, thereby facilitating the market launch and scalability of QVaultTPM based quantum resistant solutions to protect connected devices.
“QVault implements post-quantum algorithms directly in TPM hardware, while wolfTPM provides the embedded software support needed to use them,” said Jean Pierre Enguent, CTO at SEALSQ. “Together, SEALSQ and wolfSSL are bringing hardware-based post-quantum security closer to deployment and scale.”
Bringing Post-Quantum TPM Support to Embedded Development
The integration adds dedicated SEALSQ QVault support to wolfTPM, including manufacturer detection and device-specific SPI configuration. For development and testing, the integration includes a new pqc_ctrl tool. Developers can examine supported algorithms, run self-tests, generate random data, work with PCRs, and test the supported ML-DSA, Hash-ML-DSA, and ML-KEM parameter sets from one interface.
Tested on QVault Hardware
The integration was tested on physical SEALSQ QVault TPM hardware and in wolfSSL’s firmware TPM environment. It passed all wolfSSL PQC testing, using the same tests developed for the wolfTPM Firmware TPM PQC v1.85 release.
Testing included ML-DSA signing and verification and ML-KEM encapsulation and decapsulation at all key strengths.
“Post-quantum algorithms only solve half the problem. If an attacker can extract the private key from the device, the strength or type of the algorithm is irrelevant,” said Todd Ouska, CTO and co-founder of wolfSSL. “Running ML-DSA and ML-KEM inside the SEALSQ QVault TPM means the private keys are generated and used in hardware and never leave the TPM boundary. wolfTPM is how developers leverage those operations from their application.”
The integration includes QVault build instructions, post-quantum examples, hardware benchmarks, and the new pqc_ctrl tool. It is available on https://github.com/wolfSSL/wolfTPM/pull/570#issuecomment-5287784621
