quantropi

Quantropi to Show Software-Only Quantum-Safe Security for IoT DevicesĀ 

Quantropi Inc. plans to demonstrate four software-based tools for securing internet-connected devices against future quantum computing attacks at Embedded World North America 2026, the company said in a news release, part of a broader industry push to retrofit quantum-resistant cryptography onto hardware that manufacturers already have in the field.

The company will present the tools, delivered through its QiSpace platform, at Booth 6808 during the trade show. Quantropi said the offerings, covering random number generation, secure boot, network security and application-level cryptography, are designed to run on existing microcontrollers and chipsets from vendors including STM32, Renesas and Microchip, without requiring new hardware.

The push toward quantum-resistant cryptography has taken on new urgency since President Trump signed Executive Order 14409 in June, which set federal deadlines for migrating sensitive government systems to post-quantum standards. Agencies must transition high-value assets and high-impact systems to quantum-resistant key establishment by December 31, 2030, and to quantum-resistant digital signatures by December 31, 2031, according to the order.

Those deadlines apply directly to federal agencies, and the Federal Acquisition Regulatory Council is expected to extend related cybersecurity requirements to government contractors. Quantropi argues the effects will reach further still, into the IoT and embedded suppliers that serve those contractors and critical infrastructure operators, though that broader supply-chain exposure is the company’s characterization rather than a requirement spelled out in the order itself.

Separately, the National Institute of Standards and Technology’s updated entropy source requirements under FIPS 140-3 are raising the bar for what qualifies as cryptographically strong randomness, a foundational element of any encryption scheme.

Underlying both developments is the so-called harvest-now, decrypt-later threat, in which adversaries collect encrypted data today with the expectation that future quantum computers will be able to break it. Embedded devices with long field lifespans are considered especially exposed, since equipment installed now may still be transmitting data a decade or more from now, well after quantum computers capable of breaking current encryption could plausibly exist.

Four Technologies

Quantropi will demonstrate four different technologies.

  • Its TRNG offering draws randomness from timing variations already present in standard processors, the company said, spanning low-power Cortex-M0-plus microcontrollers up to higher-performance embedded chips. Quantropi said internal testing across more than 100 million samples found the output statistically indistinguishable from ideal randomness, and that the tool is built toward NIST’s SP 800-90B guidance and the newer FIPS 140-3 entropy validation requirements.
  • A Secure Boot tool verifies firmware integrity at power-on, according to the company, and can run on its own or alongside Arm’s TrustZone and TF-M security frameworks, extending to over-the-air firmware updates and cloud-based signing.
  • A Secure Network tool integrates post-quantum cryptography into the Mbed TLS and OpenSSL libraries commonly used for device-to-cloud communication, which Quantropi said allows manufacturers to harden network connections without swapping out existing networking software.
  • The fourth offering, an application security software development kit, combines post-quantum asymmetric and symmetric cryptographic functions with Quantropi’s own proprietary lightweight algorithms, the company said, aiming to let manufacturers support NIST-standardized algorithms alongside other options as standards continue to evolve.


Quantropi said its platform has been evaluated by organizations including NATO’s DIANA innovation accelerator and Siemens, and that the company holds 13 granted patents along with more than 45 peer-reviewed publications. Those figures come from the company and were not independently verified for this article.

Security researchers have generally described embedded and IoT systems as more difficult to update than conventional enterprise infrastructure. Constrained processing power, long deployment cycles that can stretch a decade or more, limited or nonexistent remote update mechanisms and widely distributed hardware all complicate efforts to swap in new cryptographic algorithms after a device has already shipped. That combination of factors is a central reason vendors like Quantropi are marketing software-only upgrades that avoid redesigning silicon or replacing deployed hardware altogether.

Quantropi is offering a free trial of QiSpace for IoT to manufacturers interested in testing the platform ahead of the federal deadlines. The company’s booth presence at embedded world North America, running alongside the broader post-quantum migration timeline set by Executive Order 14409, is likely to be one of several such vendor showcases as the 2030 and 2031 deadlines approach and pressure builds across the supply chain that serves federal and critical infrastructure customers.

.

Leave a Comment

Your email address will not be published. Required fields are marked *