Giesecke+Devrient has joined a European project to retrofit smart card chips and eID operating systems with post-quantum cryptography, exposing the technical and policy hurdles of securing digital identity against future quantum attacks
Europe's plan to defend digital identity systems against quantum-enabled attacks is colliding with the physical limits of today's smart card chips. Giesecke+Devrient (G+D), a major supplier of secure elements, has joined the uPQComing consortium to retrofit electronic identity (eID) operating systems with post-quantum cryptography. The move signals a shift from theoretical cryptanalysis to the practical engineering challenge of squeezing quantum-resistant algorithms into resource-constrained silicon.
Smart Card Hardware Constraints
Unlike cloud servers or desktop computers, eID smart cards operate with strict limits on memory, processing power, and energy. The uPQComing project targets Java Card chip operating systems-ubiquitous in European ID cards and passports-where every byte of RAM and flash storage is contested. Lattice-based post-quantum algorithms, such as those standardized by NIST, require much larger key sizes and more computation than classical RSA or elliptic-curve cryptography. Integrating these primitives risks slowing authentication at terminals and exceeding the available memory footprint, especially in legacy devices.
G+D's technical approach involves prototyping native Java Card OS builds that embed post-quantum cryptographic primitives, optimizing instruction execution and memory allocation to preserve rapid authentication. The company is also developing crypto-agile firmware layers, allowing secure elements to update or swap cryptographic algorithms as standards evolve or new vulnerabilities emerge. Hybrid authentication protocols-combining classical and post-quantum schemes-are being implemented to maintain backward compatibility during the transition period.
Migration and Policy Alignment
The uPQComing initiative is co-funded by the European Union's Chips Joint Undertaking, reflecting a policy mandate to secure public digital infrastructure before large-scale quantum computers threaten current cryptography. G+D's participation builds on a feasibility study with Germany's Bundesdruckerei, which demonstrated that post-quantum cryptography could be executed on the German national ID card platform. The current project aims to scale these prototypes across EU member states, seeking standardized, quantum-resistant digital identity architectures.
However, the migration timeline remains uncertain. While the technical roadmap calls for crypto-agile, updatable secure elements, the installed base of eID cards is vast and heterogeneous. Many deployed cards lack the hardware headroom for post-quantum primitives, and field upgrades are often impossible. This creates a multi-year window where hybrid protocols must bridge the gap, and where the weakest link in the infrastructure could undermine the entire security model.
Performance and Security Trade-Offs
Measured performance data from early prototypes highlight the engineering challenge. Lattice-based key exchange and signature schemes can require several kilobytes of RAM and non-volatile storage per operation-an order of magnitude above classical algorithms. Authentication times at verification terminals risk exceeding user-acceptable thresholds, especially under real-world conditions with variable terminal hardware and network latency. Side-channel resistance, always a concern in smart card environments, becomes more complex as algorithmic complexity increases.
These constraints are not unique to Europe. As reported earlier, US agencies face similar bottlenecks as they attempt to migrate federal identity systems to post-quantum standards. The technical evidence so far suggests that while post-quantum cryptography is mathematically mature, its deployment in embedded secure elements will require significant hardware and firmware redesign, not just software updates.
Standardization and Future Risks
Standardization efforts are underway, but the lack of uniform hardware capabilities across the EU complicates implementation. The uPQComing consortium's work may inform future procurement and certification requirements, but it cannot retroactively upgrade millions of cards already in circulation. The risk is that a patchwork of partially upgraded systems will persist for years, with attackers targeting the slowest-to-migrate endpoints. The promise of crypto-agility-updating cryptographic primitives in the field-remains limited by the physical constraints of existing hardware.
Giesecke+Devrient's involvement in uPQComing marks a necessary step toward quantum-safe digital identity, but the technical and policy evidence points to a long, uneven transition. The engineering reality is that post-quantum security for eID systems will be defined as much by hardware bottlenecks and legacy constraints as by cryptographic theory. Until the installed base is fully replaced or upgraded, the security of European digital identity will depend on the weakest, least updatable card in the system.
Post-quantum cryptography refers to cryptographic algorithms designed to resist attacks from quantum computers, which could break widely used public-key schemes such as RSA and elliptic-curve cryptography. Unlike quantum key distribution, which relies on quantum physics for security, post-quantum algorithms run on conventional hardware but require larger keys and more computation. In embedded systems like smart cards, these requirements strain available memory and processing resources, making practical deployment a significant engineering challenge. The transition to quantum-resistant infrastructure will depend not only on algorithmic strength but also on the ability to retrofit or replace billions of constrained devices worldwide.