
Cryptography and Post Quantum Security
Quantum computing will fundamentally change how systems need to be protected, and bad actors may already be harvesting data that they will decrypt when large-scale quantum computers are available. Organisations aiming to protect their critical systems must work today to secure the future. Yet migrating to new encryption schemes is a major challenge.
Applied cryptography solutions
TNO is an expert partner in solving the challenges of post-quantum cryptography (PQC). We provide research, advice, and development services that ensure your systems are secure today, and well into the future, whatever challenges may come. Whether you have just begun to evaluate your system’s security, or have already developed a post-quantum encryption solution, we can help you ensure it is robust and applicable.
TNO fulfils a different role than consultants or evaluation labs. We offer tangible solutions and technological development to address sector- and system-specific cryptographic vulnerabilities. We focus on challenges that general-purpose solutions do not address, and that require cryptographic engineering. We help ensure security will remain effective for decades – or even centuries. We assist in the complex task of migrating systems to PQC solutions, and work with policymakers to create awareness of the urgency and societal benefit of PQC migration.
Driving societal change
The PQC transition will take governments and businesses years to complete. So, the time for action is now. TNO brings key public and private stakeholders together to explore the challenges of migration and develop strategic roadmaps for successful transitions. For example, as one of the organisers of the European Conference on PQC Migration, we bring experts together with industry, government, and private sector partners to prepare for PQC migration and its impact on organisations and businesses.
Post-quantum cryptography
Our primary focus is developing cryptographic solutions that use conventional technology to resist quantum attacks. For example, our PQC solutions can be run on today’s standard laptop or web server, and yet still resist quantum attacks. We develop novel cryptography that can replace cryptography based on the factorisation or discrete logarithm problem. We can offer hybrid crypto solutions that blend traditional and novel (PQC) cryptographic schemes into a single system.
We also orchestrate partnerships and collaborations that disseminate this crucial expertise to as many organisations as possible, and share our knowledge to advance the development of increasingly robust cryptographic solutions.
Powerful PQC partnerships
TNO is contributing to several large consortia dedicated to a quantum-safe digital society. In HAPKIDO, we offer our knowledge and expertise to advance quantum-safe Public Key Infrastructure (PKI) development and migration. HAPKIDO aims to deliver sector-based plans for those migrations, as well as governance models to guide organisations toward a quantum-safe future.
As core partners of the Partnership for Cyber Security Innovation (PCSI), we are fostering key relationships to drive further innovation in the field. In PCSI, we performed PQC benchmarking in several critical applications. We are also part of a PQC workgroup dedicated to continued, structured collaboration to accelerate PQC innovation and implementation.
Quantum-safe architectures
Developing system-specific, quantum-safe algorithms is only the first challenge. Implementing them within an existing system and ensuring their sustainability and performance is another. TNO helps organisations implement PQC across sectors, from the public sector requiring advanced security to energy and other advanced operational technology developers. We guide them on architecture, remediation, and the transition to PQC.
Our solutions aim for crypto agility – the ability for systems to easily transition from one cryptographic solution to another. We help organisations understand how to embed PQC by examining existing systems and identifying weak cryptographic algorithms that need to be replaced.
We offer training for cryptographers and engineers so they can build their own solutions, or we provide development services directly. Our mathematical proofs and technical support help to ensure secure implementations and obtain critical certifications.
Migration made manageable
TNO offers extensive expertise and state-of-the-art tools to support organisations in the challenging task of migrating to PQC solutions:
- Advanced Secure Proxy: protects legacy systems without major modifications.
- Quantum-Safe VPN: Secures connections against quantum attacks.
Quantum Risk Methodology (pdf) (in Dutch only): a risk score system that helps organisations evaluate their current vulnerabilities.
PQChoiceAssistant: select the most suitable PQC scheme.
Post-Quantum Cryptography Migration Handbook (pdf) (together with the Netherlands’ General Intelligence and Security Service (AIVD)): with insights and advice for a smooth migration.
Advanced cryptographic support
High-assurance markets, like governments and defence, develop highly customised systems that require maximum security. Similarly, high-tech industrial manufacturers strive to protect their intellectual property at all costs. When public safety or highly confidential proprietary data is on the line, nothing short of ultimate security will do. TNO is the key player in the Netherlands capable of delivering security guarantees.
We use formal methods, sometimes referred to as computer-aided cryptography, to validate or identify problems with security protocol designs and implementations. In this way, we can detect flaws at the earliest stages of development, even before solutions are implemented. Formal methods produce mathematical arguments that confirm whether a solution’s design meets its security goals. We apply protocol analysis to catch logical flaws and use proof assistants to formalise and verify cryptographic proofs. Once these security protocols and proofs are verified and the implementation phase of developments starts, we can employ tooling that analyses security properties, such as correctness and timing-attack resistance, using a different set of formal methods.
Accelerating time to market
In addition to our broader-scale work in consortia and collaborations, TNO partners with start-ups, scale-ups and individual organisations that are developing post-quantum security solutions. Fortaegis, a rapidly growing scale-up, aimed to translate its unique hardware security feature into a design for secure networks – a process historically prone to errors. TNO leveraged its expertise in formal methods to model Fortaegis’ security protocol design. We successfully completed a reproducible formal analysis of the protocol. The results will help Fortaegis accelerate its time to market.
Preparing for tomorrow, today
It’s not a question of whether bad actors will use quantum computers to compromise your system. It’s a question of when. If you want to protect your essential digital ecosystem from the advanced attacks of the future, the time to act is now. Contact TNO to learn how our interim and long-term solutions can save you time, money, and effort as you prepare for our post-quantum future.
Get inspired
Cybersecurity by design: our vision


Industrial Product Security


Secure Public Sector IT Systems


Cybersecure Energy Systems


TNO and Jungle AI collaborate to detect cyberattack on wind turbine and improve detection capabilities


