Podcast | NVIDIA Architect Warns We Might Need to Rip and Replace Hardware for PQC – with TCG

3 min read

Quantum technical debt is the idea that some devices cannot be upgraded to PQC. In this episode, Thorsten Stremlau, a Systems Principal Architect at NVIDIA and Co-Chair of the Trusted Computing Group (TCG) Marketing Work Group, joins host Konstantinos Karagiannis to discuss the critical role of hardware roots of trust in protecting against the quantum computing threat. Stremlau outlines the challenges of integrating heavier PQC algorithms into resource-constrained chips like the Trusted Platform Module (TPM), highlighting technical hurdles such as increased computational intensity, memory bloat, and heightened vulnerability to side-channel and denial-of-service attacks. To counter these quantum threats while maintaining historical stability, the TCG has released the TPM 2.0 library version 1.85 paired with the platform specification 107. This combination leverages built-in crypto-agility to implement mature algorithms like ML-KEM and ML-DSA, while still supporting hybrid classical-quantum models to ensure a smoother migration path for enterprises.

However, Stremlau issues a stark warning regarding the industry's timeline and the reality of quantum technical debt, revealing that achieving full PQC readiness will require a complete hardware replacement rather than simple in-field firmware updates. Government entities are aggressively mandating PQC compliance for procurement by 2027. But the enterprise sector, particularly critical infrastructure and server environments, faces an incredibly long transition cycle due to a traditional preference for operational stability over rapid upgrades. While a PQC-ready TPM is a foundational piece of the puzzle that secures firmware signing, boot processes and platform attestation, it is not a silver bullet. True quantum resilience requires a defense-in-depth strategy where the entire software and data ecosystem, including AI workloads, edge networks and data pipelines, is systematically upgraded alongside the hardware foundation.

For more information on Trusted Computing Group, visit https://trustedcomputinggroup.org/.

Visit Protiviti at https://www.protiviti.com/us-en/quantum-computing-services to learn more about how Protiviti is helping organizations get post-quantum ready.

The Post-Quantum World on Apple Podcasts

Quantum computing capabilities are exploding, causing disruption and opportunities, but many technology and business leaders don’t understand the impact quantum will have on their business. Protiviti is helping organizations get post-quantum ready. In our bi-weekly podcast series, The Post-Quantum World, Protiviti Associate Director and host Konstantinos Karagiannis is joined by quantum computing experts to discuss hot topics in quantum computing, including the business impact, benefits and threats of this exciting new capability.

Subscribe
Loading...