Quantum-Resistance for a Crypto Infrastructure


Available as: Hardware on-premise

Q-safe – Applying Quantum-Resistance to Applications and Use Cases

  • Firmware extension module for installation on SecurityServer Se and SecurityServer CSe series HSMs
  • Applies quantum-resistance to a crypto infrastructure
  • Includes a Software simulator for evaluation and integration testing
  • Supports PQC algorithms recommended by NIST & BSI: CRYSTALS-KYBER, CRYSTALS-Dilithium, XMSS, XMSS-MT, and HSS
Key Benefits

Key Benefits


Post Quantum Cryptography (PQC) Algorithms

PQC algorithms for signature creation and key encapsulation can be applied to an existing cryptographic infrastructure.


Evaluation of a Cryptographic Infrastructure

Prepare for future challenges by using the Q-safe simulator and evaluating the performance and usability of quantum-resistant algorithms within crypto infrastructure


Retrofittable Firmware Module

Q-safe enables an additional layer of PQC security as an in-field upgrade for SecurityServer general-purpose HSMs.



Q-safe – Adding Quantum-Resistance to Applications and Use Cases



Q-safe from UTIMACO is a future-proof firmware extension enabling organizations to  prepare for the era of quantum computing - a serious threat to traditional cryptographic algorithms that has the potential to decimate the future security infrastructure of the digital economy.

By integrating post-quantum cryptography into business applications and IT infrastructures, Q-safe enables organizations to address this challenge immediately. Q-safe adds the extra layer of quantum-safe security to digital processes such as document signing or code signing, issuing of PQC or hybrid certificates for public key infrastructures (PKI), or key injection and chip personalization by executing quantum-safe crypto algorithms within the secure boundaries of the HSM.

The algorithms used by Q-safe are amongst the finalists of the ongoing NIST standardization process. Some of them have recently been endorsed by BSI (Federal Office for Information Security, Germany). These algorithms are the building blocks for quantum-safe infrastructures and for hybrid crypto schemes that will be deployed in a transition phase to defend against the threat to traditional asymmetric cryptography posed by the emergence of quantum computing.

Because the Q-safe firmware module is retrofittable, it can be easily added to the SecurityServer Se series HSM firmware. It is also available as a simulator extension, which makes evaluation and integration testing of Q-safe with business applications simple.


Easy integration

  • Application integration using PKCS #11 “Vendor Defined Mechanisms”
  • Firmware module for in-field upgrade on your installed base of SecurityServer Se series HSMs
  • Library for upgrade of SecurityServer simulators, for evaluation, development, and integration testing

Secure backup and restore functionality

  • Available for stateful schemes

Technical Specifications

Support for various cryptographic algorithms

  • Digital signature algorithms CRYSTALS-Dilithium, HSS, XMSS and XMSS-MT
  • Key encapsulation algorithm CRYSTALS-KYBER



Our on-premise options allow hosting the product directly on-site in your own network or data center.

  • Firmware Extension

As a service

Our as-a-service options are hosted by Utimaco in certified datacenters and include everything from set-up to deployment to maintenance.

Related to this product



Find more details

Contact us

We look forward to answering your questions.

How can we help you?

Talk to one of our specialists and find out how Utimaco can support you today.
You have selected two different types of downloads, so you need to submit different forms which you can select via the two tabs.

Your download request(s):

    By submitting below form you will receive links for your selected downloads.

    Your download request(s):

      For this type of documents, your e-mail address needs to be verified. You will receive the links for your selected downloads via e-mail after submitting below form.

      Your collection of download requests is empty. Visit our Downloads section and select from resources such as data sheets, white papers, webinar recordings and much more.