MTG PQC Developments
Today, our PQC portfolio already enables data to be protected against future decryption attempts by quantum computers. To achieve this, existing MTG ERS® components have been specifically enhanced with PQC algorithms.
MTG ERS® Platform Architecture
New cryptographic standards, regulatory requirements, and relevant developments from research and standardization are systematically incorporated into the ongoing advancement of ERS® technology. This ensures that the platform can be gradually adapted to new cryptographic requirements and enables organizations to prepare their systems early for the challenges of the quantum era.
ERS® and Post-Quantum Cryptography
MTG identified post-quantum cryptography as a strategic priority early on and has been working since 2018 on implementing quantum-resistant cryptographic methods in ERS® components (PKI, CLM, and KMS). New approaches and standards are evaluated and practically tested both within research activities and as part of product development. At the same time, MTG closely follows international standardization processes and regulatory requirements, incorporating relevant developments early into the ongoing evolution of ERS® technology.
MTG PQC Milestones
In the Use-A-PQClib research project, Darmstadt University of Applied Sciences and MTG AG are developing a user-friendly API for post-quantum cryptography. The goal is to create a unified abstraction layer for both classical and PQC methods, enabling cryptographic algorithms to be exchanged more flexibly in the future and improving crypto-agility in security products.
MTG demonstrates to IT security experts from around the world how critical infrastructures can already be protected today against future threats posed by quantum computers.
This year, MTG presented the quantum-secure online PKI platform MTG CARA at the RSA Conference. The platform was demonstrated using certificates issued by MTG CARA, based on an open-source browser and an email application. To our knowledge, this was the world’s first fully functional browser and email client supporting post-quantum cryptography.
As part of developing the MTG ERS® solution, several PQC methods were integrated. A browser based on Mozilla Firefox (Sunray) and a web server based on Apache Tomcat were implemented with integrated support for PQC-TLS. To our knowledge, this was the world’s first fully functional browser supporting post-quantum cryptography.
For email encryption and signing, an extension of the mail program Mozilla Thunderbird and the S/MIME format was developed.
The resulting application, Sunbeam, allows users to encrypt emails using Classic McEliece and sign them using SPHINCS+. The encryption process is hybrid: The message and any attachments are encrypted using a symmetric key. This key is then encrypted with a public Classic McEliece key. To our knowledge, this was the world’s first fully functional email client supporting post-quantum cryptography.
MTG has developed PQC solutions that can already be used and tested today. With the online demo, interested users can experience firsthand that quantum-secure applications can already be implemented in practice today.
A scientific paper describes a memory-optimized implementation of Classic McEliece for embedded systems. By generating and streaming the public key on demand, memory requirements are significantly reduced. The results enable efficient use of the algorithm and allow TLS implementations on ARM Cortex-M4 systems.
A joint draft by MTG AG, the Federal Office for Information Security, and Proton AG proposes a future-proof approach for securing email communication with post-quantum cryptography. The draft is publicly available for review and comments.
MTG and Cryspen launch JZLint 2.0, an enhanced tool for analyzing post-quantum certificates and public keys.
With the free PQC PKI, users can test post-quantum cryptography within a fully functional PKI environment. Use current NIST-standardized PQC algorithms and start free with up to 50 active PQC certificates to gain practical experience with quantum-secure applications and security scenarios.
Together with CryptoNext Security, MTG is launching a new three-year research project to develop the next generation of crypto inventory — evolving from a static asset list into an active tool for automation, risk management, and post-quantum migration. Funded by Germany's Central Innovation Program for SMEs (ZIM) and France's Bpifrance.