Infineon’s Bet on Whole-Stack PQC

Infineon built its quantum-security reputation on certified security controllers. Now it is embedding post-quantum cryptography into the microcontrollers that power motors, manage OTA updates, and guard the boot process of the software-defined vehicle — and that changes everything.

For years, post-quantum cryptography in silicon was largely the preserve of dedicated security controllers — specialist chips sitting at the edge of a system, guarding keys and signing credentials, while the rest of the device ran on classical algorithms. Infineon Technologies was a leader in precisely that space, earning the world’s first Common Criteria EAL6+ certification for a security controller implementing a PQC algorithm. It was an impressive achievement, but it was also, in a sense, a controlled environment: a hardened island of quantum resistance inside a sea of classical hardware.

What the company has been doing since mid-2025, and with particular intensity into early 2026, is something architecturally different. Infineon is pushing PQC out of that island and into general-purpose microcontrollers — the PSOC Control MCUs used in industrial power conversion and motor control, and the AURIX and TRAVEO families used throughout the automotive supply chain. The implication is a shift from quantum security as a point solution to quantum security as a property of the entire infrastructure and trust stack.

THE PRODUCTS DRIVING THE SHIFT

The clearest signal came in August 2025, when Infineon announced that its PSOC Control C3 Performance Line MCUs would comply with the post-quantum requirements for firmware protection set out in the NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0). These are not security controllers. They are real-time control chips designed for power conversion and motor control — devices deployed in EV charging systems, data centre power infrastructure, and industrial drives.

KEY PRODUCTS IN THE PQC PORTFOLIO
PSOC Control C3CNSA 2.0–compliant industrial MCU with LMS firmware verification for secure boot and OTA updates. PSA Certified Level 3. Supports hybrid PQC/ECC.AURIX TC49Automotive MCU (Feb 2026) with native PQC enablement. Dedicated CPU, NVM, and hardware accelerators for PQC secure boot in software-defined vehicles.
TEGRION SLC27Security controller with CC EAL6+-certified ML-KEM and ML-DSA support. The trust anchor at the apex of the wider quantum-resistant stack.TRAVEO T2GAutomotive body and cluster MCU family. PQC-readiness being extended across range in 2026, with ISO/SAE 21434 and CATARC compliance.

On the automotive side, the March 2026 announcement covering the AURIX TC4x and TRAVEO T2G families made the breadth of the programme explicit. PQC-readiness is being extended across entire MCU families — not as an optional feature flag, but as an embedded capability built from dedicated CPUs, non-volatile memory partitions, and hardware accelerators. The AURIX TC49, launched in February 2026, arrived already PQC-enabled. ISO/SAE 21434 compliance and CATARC certification for China are being delivered in the same breath as PQC, signalling that Infineon is treating quantum resilience as one pillar of a unified regulatory and security posture.

PQC is coming hard and strong. We believe the state of the art right now is truly five years from now. That means we have a responsibility to react.”

— Erik Wood, Senior Director of Security Technical Marketing, Infineon

WHY THIS ARCHITECTURE MATTERS

The move matters because of what it reveals about where the attack surface actually lies. A security controller is a strong root of trust, but it cannot protect what the rest of the system does on its own authority. If a vehicle’s domain controller, zone controller, or ADAS MCU performs its own firmware verification using classical ECDSA or RSA, a future adversary with a cryptographically relevant quantum computer (CRQC) could forge a firmware signature and compromise the vehicle even if the security controller itself is quantum-resistant. The weakest link is not the vault; it is every other lock on every other door.

This is particularly acute for automotive applications, where vehicles on the road today may be receiving over-the-air software updates well into the 2030s and 2040s. The timelines of vehicle lifespans and quantum computing progress are uncomfortably close. The challenge is how to transition to quantum-resistant cryptography within long product lifecycles, complex supply chains, and heterogeneous embedded platforms — ranging from high-end to severely resource-constrained ECUs.

Infineon’s answer is to push PQC capability down into the MCUs themselves, so that each device in the system can independently verify its own firmware using a quantum-resistant signature scheme — Leighton-Micali Signatures (LMS) today, with the design built to migrate to ML-DSA and ML-KEM as those algorithms mature. The PSOC Control C3 introduces a new Low-Cost Crypto Subsystem (LCSS) hardware engine precisely to make this computationally viable without crippling the real-time performance that motor control and power conversion demand.

HYBRID TRANSITIONS AND CRYPTO AGILITY

One of the more sophisticated aspects of Infineon’s approach is its explicit accommodation of the transition period itself. Deploying PQC does not mean ripping out classical cryptography overnight; the industry will run hybrid schemes — simultaneously signing firmware with both classical ECC and a PQC algorithm — for years, allowing legacy verifiers and new ones to coexist. Infineon’s toolchain (Edge Protect Tools and ModusToolbox) is designed to provision both LMS and ECC keys and to let customers choose their hybrid configuration.

Equally important is the crypto-agility built into the architecture. Developers invoke cryptographic services through key identifiers rather than direct algorithm calls, meaning the firmware layer does not need to be rewritten as the underlying algorithm evolves. The roadmap already anticipates moving from LMS to ML-DSA for on-device signing and adding ML-KEM for key encapsulation in TLS-based communications.

WHAT IT MEANS FOR THE INDUSTRY

Stepping back, Infineon’s trajectory over the past eighteen months describes a coherent industrial logic. The Common Criteria EAL6+ certification for the TEGRION security controller established credibility at the apex of trust. The PSOC Control C3 brought PQC into industrial MCUs. The AURIX TC49 and the broader AURIX TC4x and TRAVEO T2G PQC rollout extends it into automotive. The effect is a portfolio where quantum resistance is available — and increasingly expected — at every tier of the embedded hierarchy.

  • The trust stack argument: securing only the security controller leaves every other MCU in the system as a potential point of quantum-era compromise. Whole-stack PQC closes those gaps.
  • Regulatory pressure is a tailwind: CNSA 2.0, UNECE R155/R156, ISO/SAE 21434, and China’s CATARC requirements are all converging. PQC-ready devices give OEMs a single compliance pathway across geographies.
  • Long-life products demand decisions now: vehicles, industrial systems, and IoT devices deployed today will still be operating when CRQCs become a realistic threat. The design-in window for quantum resistance is closing.
  • Competitive gap is real and growing: Infineon and Microchip are clear early movers. NXP is positioning with roadmap signals. STMicroelectronics, Renesas, and Texas Instruments remain largely quiet.

Whether or not a cryptographically relevant quantum computer arrives within ten years, the embedded industry is being reshaped by the possibility that it might. Infineon is betting that the customers who build long-life products — automotive OEMs, industrial automation companies, smart infrastructure operators — will pay a premium for silicon that does not ask them to gamble on that timeline. The bet looks increasingly well-placed.


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading