STMicroelectronics Bets on Hardware-Based Post-Quantum Cryptography with ST54M
I'm LongbridgeAI, I can summarize articles.STMicroelectronics launched the ST54M, the first secure element in its family to integrate dedicated hardware-based post-quantum cryptography (PQC). Combining NFC, eSIM support, and a PQC accelerator for NIST-standardized ML-KEM and ML-DSA algorithms, the chip addresses 'harvest now, decrypt later' threats. It supports hybrid cryptography alongside classical methods, aiming to help OEMs future-proof devices against quantum computing risks while meeting strict security standards.
//php echo do_shortcode('[responsivevoice_button voice="US English Male" buttontext="Listen to Post"]') ?>
Practical quantum computers capable of breaking today’s public-key cryptography may still be years away, but STMicroelectronics said device manufacturers cannot afford to wait.
The chipmaker has introduced the ST54M, the first member of its decade-old ST54 secure element family to integrate dedicated hardware-based post-quantum cryptography (PQC). The device combines Near Field Communication (NFC), a secure element, embedded Subscriber Identity Module (eSIM) support, and a PQC hardware accelerator on a single die.
In an interview with EE Times, Laurent Degauque, Connected Security Business Lines director at STMicroelectronics, said the company’s strategy is driven less by the arrival of quantum computers than by the need to protect data with long-term value.
“Globally, the industry, and not only the mobile industry but every electronic market we address, recognizes that quantum computers will eventually become a threat,” he said. “Everyone wants to be prepared in advance.”
Although practical quantum computers capable of breaking classical encryption may still be five to seven years away, Degauque said the larger concern is the “harvest now, decrypt later” scenario.
He continued, “Someone can collect encrypted data today without being able to read it. However, if quantum computers become capable of breaking that encryption in five or six years, and those secrets are still valuable at that time, the data will be exposed.”
He said this is driving OEMs to integrate PQC-ready hardware now so devices can support future cryptographic deployments without requiring hardware redesigns.
Another factor, he said, is the maturity of standards. “We are no longer discussing pre-standard versions that could change; OEMs can now deploy solutions based on established standards,” he said.
First ST54 with hardware-based PQC
The ST54 family has been widely deployed across the Android ecosystem for more than a decade, combining NFC and a secure element on a single die. Previous generations relied on classical cryptography and are still in production.
“The real breakthrough is that this is the first ST54 to support PQC,” Degauque said.
Unlike software-only implementations, the ST54M performs ML-KEM and ML-DSA operations using a dedicated K-Check hardware accelerator integrated into the secure element.
The accelerator supports module-lattice-based key-encapsulation mechanism (ML-KEM) and module-lattice-based digital signature algorithm (ML-DSA), the two algorithms standardized under the NIST Federal Information Processing Standards (FIPS) 203 and 204.
According to Degauque, the choice reflects the requirements of modern secure transactions.
“Most secure transactions require both key exchange and digital signatures,” he said. “Therefore, these are the two PQC algorithms needed for almost every type of secure transaction and application.”
Degauque said the dedicated hardware narrows the performance gap between classical and post-quantum cryptography, delivering stronger security without affecting the user experience.
In addition to PQC support, the new device offers higher memory capacity, improved radio frequency (RF) performance, and enhanced security.
The secure element is built around an Arm Cortex-M35P processor and integrates dedicated hardware engines for symmetric cryptography, public-key cryptography, and STMicroelectronics’ K-Check post-quantum cryptography accelerator. In its official data brief, the company stated that the device also includes up to 4.5 MB of secure nonvolatile memory and up to 800 kB of RAM to support increasingly complex security applications. The secure element is designed to meet Common Criteria EAL6+ and EMVCo security requirements while supporting payment, identity, and eSIM applications on a single chip.
The latest ST54M integrates an on-chip DC-DC converter that previously required an external component, simplifying smartphone integration while improving efficiency and reducing system cost. The company also improved interoperability, reading distance, and overall user experience with different NFC readers and antenna designs.
“They also allow OEMs to adopt new generations of antennas, including smaller antennas and frame antennas, while maintaining the same RF performance,” he said.
The arrival of PQC does not mean classical cryptography disappears overnight. Instead, STMicroelectronics expects both approaches to coexist for years.
“The chip continues to support all traditional cryptographic algorithms from previous generations alongside PQC,” Degauque said. “We have not replaced classical cryptography. We support both, so the chip fully supports hybrid cryptography.”
The company said the device was developed in response to customer demand.
“This new ST54 addresses requests we have received from OEMs,” Degauque said. “Several of them want to integrate PQC protection into their devices as soon as possible, either to protect their own platforms or to prepare for future services that will benefit from PQC.”
One example is the GSM Association’s (GSMA’s) ongoing work on PQC-enabled eSIM standards.
“If an OEM adopts the ST54 with PQC today, it will be ready to benefit from the hardware acceleration in this chip when the GSMA finalizes its PQC standards for future embedded SIMs,” Degauque said.
Degauque also cited government initiatives across the U.S., Europe, and other regions encouraging migration to standardized PQC as another factor accelerating adoption.
Engineering around PQC overhead
Supporting PQC requires larger keys and more computation than classical cryptography, increasing demands on processing, memory, and power consumption. Degauque said the challenge was to integrate PQC without compromising smartphone battery life or driving manufacturing costs beyond what OEMs would accept.
“We have aimed for a good balance between performance and power consumption while keeping the additional memory footprint, mainly in random access memory, as small as possible.”
Degauque acknowledged that PQC adds silicon complexity and cost but said the tradeoff is justified.
“PQC is not a feature that comes at no cost,” he added. “It is an additional capability that requires extra implementation effort. We believe the impact on power consumption is well under control, and the additional cost is very limited compared to the benefits it brings to OEMs and end users.”
Hardening against physical attacks
For STMicroelectronics, implementing PQC algorithms was only part of the challenge. The hardware must also resist side-channel and fault injection attacks that attempt to recover secret data during computation.
“PQC provides very strong mathematical protection for encrypted data against quantum computers,” he said. “However, implementing the algorithm alone is not enough.”
Degauque said attackers can exploit power consumption, electromagnetic emissions, or induced faults to infer cryptographic keys if the implementation itself is not protected.
“We have not simply implemented the PQC algorithms according to the standards,” he said. “We have implemented highly secure versions that are protected against external attacks and certified by independent laboratories. Our objective is to provide a secure black box that cannot be observed or compromised.”
The implementation builds on STMicroelectronics’ secure microcontroller portfolio, which already protects against simple power analysis (FPA), differential power analysis (DPA), electromagnetic attacks, and laser attacks.
Preparing for broader deployment
While smartphones are the first target, STMicroelectronics sees PQC becoming a requirement across multiple product categories. The company already supplies the ST54 family to many Android handset makers, making migration to ST54M a natural upgrade.
As smartphones increasingly become repositories for digital credentials, OEMs are preparing for two parallel transitions: protecting sensitive information already stored on devices and ensuring future compatibility with external services such as digital identity programs.
“I would expect PQC to appear first in premium smartphones before progressively expanding across the full product range,” he said.
For Degauque, however, security should ultimately be independent of smartphone price.
“Regardless of the price, customers still expect their credentials to be protected in the same way,” he said.
As a result, he said he expects post-quantum protection to become a standard capability across future smartphones rather than a premium feature.
Outside mobile devices, STMicroelectronics has already introduced software-based PQC support for its ST33 Trusted Platform Module (TPM) family targeting PCs and data centers.
Degauque said he expects automotive to be another early adopter. “Vehicles typically remain in service for five, 10, or even 15 years. Quantum computers are likely to become available before many of those vehicles reach the end of their life.”
The chipmaker is now preparing PQC-enabled versions of other secure microcontroller families for automotive and additional embedded applications.
According to Degauque, the long-term objective is to extend PQC across most of STMicroelectronics’ secure product portfolio, with exceptions where cost or application requirements make it impractical.
“If we look 10 to 15 years ahead, I expect PQC to be included in the vast majority of our secure microcontroller portfolio,” he said.
Read also:
Indian Startup Vimag Labs Develops Wirelessly Excited Motor Without Rare-Earth Magnets
Adaptive Hardware Could Change How EV Chargers Are Designed
India Adds Pieces to Strengthen Its Electronics Supply Chain Puzzle
AI AND BIG DATA, CYBERSCURITY, ENCRYPTION, POST-QUANTUM CRYPTOGRAPHY, PQC, SEMICONDUCTORS
STMICROELECTRONICS
