HP introduced its new business PCs equipped with quantum-resistant chips at the company's annual Partner Conference 2024. The company built its upgraded Endpoint Security Controller (ESC) chip into select PCs to protect firmware against potential quantum computer attacks.

The potential introduction of cryptographically relevant quantum computers has been a growing concern for cybersecurity experts. According to recent research, 27% of experts predict a 50% likelihood of a cryptographically relevant quantum computer emerging by 2033, challenging the security of existing digital signatures on firmware and software and dissolving digital trust.

Government and industry are making progress in moving the digital world to a new cryptographic standard. For example, the U.S. government has outlined specific recommendations around migrating to quantum-resistant cryptographic algorithms for firmware signing, recommending that post-quantum cryptography (PQC) be used from 2025. The National Institute of Standards and Technology (NIST) is expected to release the PQC standard this year.

However, “while software can be updated, hardware can’t. And that includes some of the cryptography that protects PC firmware,” HP warns. “With no cryptographic protections in place, no device would be safe – attackers could access and modify the underlying firmware and gain total control.”

Introducing 5th generation ESC chip

In response to these challenges, HP launched its 5th generation ESC chip. This upgraded chip is designed to protect PC firmware integrity with quantum-resistant cryptography and provide a foundation for software PQC upgrades on PCs in the future, the company claims.

“The ESC is a chip that implements HP’s platform root of trust, designed to protect platform firmware integrity and provide a range of other security capabilities,” Boris Balacheff, chief technologist for security research and innovation at HP Inc., told SDxCentral.

The ESC chips are isolated from the CPU and operating systems, which offers a hardware platform root of trust designed to reduce risks of breaches and improve productivity by preventing downtime, Balacheff explained. “The ESC firmware signatures, including those using new quantum-resistant cryptographic algorithms, are validated by the hardware before the firmware can run. Thus, a quantum computer attacker cannot defeat the signature protection to run modified firmware.”

HP’s upgraded ESC chips use quantum-resistant cryptography

The upgraded ESC chips do not use quantum technology itself, but quantum-resistant cryptography instead, according to Balacheff. The chips have adopted the standardized quantum-resistant Leighton-Micali Signature algorithm to protect firmware integrity by verifying a digital signature.

This is in addition to the RSA cryptography already in hardware in previous chip generations, resulting in two parallel digital signature mechanisms being used to protect the integrity of HP PC firmware.

This move ensures HP will be able to maintain the hardware maturity and Federal Information Processing Standards (FIPS)-certified protection provided by the RSA (Rivest-Shamir-Adleman) public-key cryptosystem, while offering security against “a future attacker equipped with a sufficiently powerful quantum computer to break classical asymmetric cryptography like RSA,” Balacheff explained.

“This will prevent that platform firmware [from being] maliciously modified, helping protect the rest of the PC software, security functionality and sensitive data – both now and in the future,” he added.

Building the foundation to support software PQC updates

The quantum-resistant chips also established a hardware foundation to support the PQC migration strategy and ensure the migration can be treated as a software update problem, Balacheff said.

Then, “customers will be able to plan, according to their own use-case priorities and timeline, working with software vendors who are themselves planning migration to post-quantum cryptography,” he added.

“Without the innovation introduced by HP this year, customers would have to plan a full hardware change in order to implement a migration to post-quantum cryptography, since a software update alone would remain undermined by risks to their PC firmware, which could lead to compromise of the whole device software and data if an attacker becomes equipped with a sufficiently powerful quantum computer,” Balacheff said.