The security technology company Giesecke+Devrient (G+D) participates in the European research project uPQComing, developing technologies for the next generation of digital identity documents prepared to cope with quantum computing. The project, funded by the Chip Joint Undertaking (Chips JU), aims to prepare critical digital infrastructures for the challenges of the quantum era and accelerate the transition towards post-quantum cryptography (PQC) in security-relevant applications, including digital identity systems.
The uPQComing (Enhancing Cyber-Resilience for the upcoming Post-Quantum era) project responds to the challenge posed to current cryptographic methods by the development of increasingly powerful quantum computers. Applications that require long-term security, privacy, and reliability, such as identity documents and digital identity solutions, need future-proof protection mechanisms. In this context, reinforcing digital identity is key to guaranteeing trust in services and systems that manage sensitive information. uPQComing brings together European industrial partners, research institutes and universities to develop solutions that increase the resilience of critical systems against future quantum attacks.
Secure digital identity applications in the post-quantum era
As part of the project, G+D develops technologies for identity document operating systems adapted to quantum computing, laying the foundation for secure digital identity applications in the post-quantum era. The focus is on integrating post-quantum cryptography into embedded secure elements, such as those used in modern identity documents and which constitute a fundamental piece to protect digital identity.
Thus, G+D is developing cryptographic protocols resistant to quantum computing, adapting existing authentication and security mechanisms and implementing crypto-agile system architectures. These capabilities allow cryptographic algorithms to be updated and adapted with greater flexibility to respond efficiently to constantly evolving security requirements. The ability to update these mechanisms will be especially relevant to preserving digital identity as threats and attack technologies evolve.
G+D is also investigating hybrid approaches that combine classical and quantum-resistant methods to ensure robust digital identity security during the transition to post-quantum cryptography and in the first years after the deployment of new PQC algorithms. This strategy will allow maintaining high levels of protection in digital identity applications while organizations advance towards new cryptographic standards.
Another focus of the project is the optimization of PQC methods for use on safety-critical hardware. Key considerations include limited computing capacity, restricted memory resources, and secure performance and communication between the ID and the terminal. These factors are especially important in solutions intended to manage digital identity, where security must be combined with efficiency, interoperability and ease of use.
The resulting approaches are being integrated as prototypes into an operating system (OS) for Java Card chips for identity documents, developed by G+D, and are being validated in terms of security, efficiency and interoperability. The objective is to contribute to an infrastructure capable of supporting future digital identity needs and offering protection guarantees against the capabilities of quantum computing.
According to Gabriel von Mitschke-Collande, Chief Digital Officer of the G+D Group, “the quantum era is fundamentally transforming the requirements of digital security and whoever wants to safeguard trust in digital identities tomorrow must lay the necessary technological foundations today.”
G+D is also investigating hybrid approaches that combine classical and robust methods for quantum computing.
The feasibility study and proof of concept for the German national identity card, he adds, carried out together with the Bundesdruckerei, have shown that post-quantum cryptography is already viable for high-security identity documents. “With uPQComing we take the next step, working together with our partners to lay the foundations for the next generation of identities resistant to quantum computing. In this way,” von Mitschke-Collande concludes, “we also contribute to strengthening Europe’s technological sovereignty in a critical security area that will gain importance in the coming years.”
The uPQComing consortium brings together industrial partners, research institutes and universities from all over Europe. Together, the partners are working to develop innovative security architectures and applications for the post-quantum era, with the goal of ensuring that digital identity can continue to offer long-term trust, privacy and protection in the face of evolving technological threats.
