Interviews

Carlos Moreira, CEO and Founder of SEALSQ – Interview Series

mm
Add Unite.AI to your preferred sources on Google

Carlos Moreira, CEO and founder of SEALSQ, is a veteran cybersecurity and digital trust executive with decades of experience spanning secure semiconductors, digital identity, telecommunications, and emerging technologies. He is also the founder, chairman, and CEO of WISeKey, which he established in 1999, and serves as Secretary General of the OISTE Foundation. Earlier in his career, Moreira spent more than 15 years working with the United Nations and related international organizations on telecommunications, e-security, e-commerce, and secure information networks. His broader technology ventures include WISeSat.Space and SEALCOIN, while his work has also included advisory and leadership roles with the World Economic Forum and participation in the MIT Media Lab’s global community, where SEALSQ is exploring security, privacy, quantum resilience, and human-centered innovation.

SEALSQ is a publicly traded semiconductor and cybersecurity company focused on securing connected devices and digital infrastructure against both conventional and emerging quantum threats. Listed on Nasdaq under the ticker LAES, the company develops secure microcontrollers, secure elements, RISC-V-based security platforms, Public Key Infrastructure (PKI), device provisioning, and digital identity technologies. Its expanding post-quantum portfolio integrates NIST-standardized cryptography directly into silicon, including technologies designed to provide hardware roots of trust for IoT devices, automotive systems, industrial infrastructure, smart homes, and edge computing. SEALSQ is also expanding its custom semiconductor capabilities through IC’Alps and developing a broader integrated security architecture spanning secure chips, digital identity, trusted communications, post-quantum cryptography, and emerging quantum technologies.

You founded WISeKey in 1999 and later created SEALSQ as a dedicated semiconductor and post-quantum security company. What convinced you that digital trust could no longer be addressed through software and public key infrastructure alone, and needed to extend directly into silicon?

When I started WISeKey, most digital trust challenges were centered around identities, certificates and securing communications. Software and public key infrastructure were the right foundation because most systems were connected through servers and enterprise networks.

Over time, computing moved to the edge. Today, billions of connected devices make security decisions independently. Cars, medical devices, industrial controllers and smart infrastructure all need to know whether the code they are running is authentic and whether the device communicating with them can be trusted.

That level of trust has to begin before software even starts. A hardware Root of Trust provides a secure foundation for identity, key storage and secure boot that software alone cannot provide if the underlying platform has already been compromised.

Quantum computing accelerated that thinking. The industry is preparing for new cryptographic standards while connected devices are expected to remain in service for decades. That made secure semiconductors a natural extension of our work in digital trust. We saw an opportunity to bring identity, cryptography and hardware together so trust begins inside the chip and continues throughout the device lifecycle.

Much of the post-quantum discussion focuses on “Harvest Now, Decrypt Later” attacks against stored data. Why do you believe the more urgent threat may involve connected physical systems such as vehicles, medical devices, industrial equipment, and critical infrastructure?

Harvest Now, Decrypt Later is a real concern because sensitive information stolen today could be decrypted in the future once large-scale quantum computers become available.

At the same time, connected physical systems present a different challenge. These devices control processes in the real world. They operate factories, support healthcare, manage transportation and help run energy infrastructure. Many remain in operation for fifteen or twenty years and cannot be replaced or upgraded quickly.

If those devices cannot authenticate software updates, verify commands or establish trusted identities using quantum-resistant security; the operational risks grow over time. Organizations may discover that replacing or recertifying deployed systems takes far longer than updating enterprise software.

Preparing these systems for the post-quantum transition requires planning years in advance because the hardware decisions made today will still matter well into the next decade.

Organizations are being encouraged to inventory their cryptography, but many may not have a complete inventory of the chips and embedded systems using it. How should they identify which long-lifecycle devices create the greatest quantum risk?

The first step is understanding where cryptography is embedded, not only in software but also in hardware. Many organizations have a reasonable inventory of servers and applications, but much less visibility into the secure elements, microcontrollers and embedded systems operating throughout their business.

I would prioritize devices based on three questions. How long will the device remain in service? How difficult will it be to update or replace? What would be the operational impact if its identity or communications could no longer be trusted?

That naturally brings attention to sectors such as automotive, healthcare, industrial automation, defense and critical infrastructure where equipment often operates for many years under strict certification requirements.

Organizations should also work closely with semiconductor suppliers and equipment manufacturers to understand which devices already support cryptographic agility and which will ultimately require hardware replacement.

What can a hardware root of trust accomplish that a software-based post-quantum upgrade cannot, particularly when a device must authenticate itself, validate firmware, or reject malicious commands?

A hardware Root of Trust establishes trust before the operating system and application software begins running. It securely stores cryptographic keys, verifies the integrity of firmware during boot and provides a trusted identity that remains protected even if higher software layers are compromised.

Software updates remain essential and post-quantum algorithms will certainly be delivered through software where appropriate. However, software depends on an underlying trusted platform to verify that those updates are authentic and have not been modified.

For connected devices operating in critical environments, hardware-backed identity also enables secure authentication between machines and helps ensure that commands originate from trusted sources.

That foundation becomes increasingly important as connected systems become more autonomous and remain deployed for many years.

SEALSQ’s QS7001 integrates post-quantum algorithms into a RISC-V secure microcontroller. What performance, power consumption, memory, and interoperability challenges arise when moving post-quantum cryptography from software into constrained hardware?

Post-quantum algorithms generally require more memory, greater computational resources and different optimization techniques than traditional public key cryptography. Those constraints are especially important in embedded devices where power consumption, silicon area and processing capacity are limited.

The QS7001 addresses this as a 32-bit secure RISC-V microcontroller with a hardware Root of Trust and cryptographic acceleration. It integrates the NIST-standardized ML-KEM for key establishment and ML-DSA for digital signatures. Keeping sensitive operations and private keys inside the protected hardware boundary strengthens resistance to key extraction, side-channel analysis and fault-injection attacks while dedicated acceleration reduces the burden on the main processor.

Memory management is also important because ML-KEM and ML-DSA use larger keys and intermediate data structures than ECC. Optimizing across hardware, firmware and secure memory helps control data movement, peak memory use and energy consumption, especially for battery-powered or intermittently connected devices. Exact latency, memory and energy figures depend on the security parameter set and application profile and should be reported from validated silicon under defined test conditions.

Interoperability matters because classical and post-quantum cryptography will coexist for years. The QS7001 supports a migration path that remains compatible with today’s PKI and protocols while adding quantum-resistant key establishment, signatures, secure boot and firmware verification. Crypto-agility and authenticated firmware updates allow implementations to evolve without replacing the hardware Root of Trust.

Post-quantum standards and implementation guidance will continue to evolve. How can manufacturers build cryptographic agility into devices expected to remain operational for 10 to 20 years without creating new vulnerabilities or requiring hardware replacement?

Cryptographic agility should be designed into the architecture from the beginning. Manufacturers need secure hardware capable of supporting authenticated updates, multiple algorithms and controlled migration as standards mature.

That does not mean every future change can be solved through software alone. Hardware still needs sufficient processing capability, secure key management and an architecture designed for long-term evolution.

The goal is to minimize the number of situations where replacing physical hardware becomes necessary while maintaining strong security throughout the product lifecycle.

Standards bodies will continue refining guidance over time, so flexibility combined with hardware-based trust gives manufacturers the best opportunity to adapt responsibly.

Millions of potentially vulnerable connected devices have already been deployed. Where can retrofit approaches such as trusted platform modules, secure gateways, firmware updates, or network-level protections help, and where will replacing the underlying hardware be unavoidable?

There is no single answer because deployed devices vary widely.

Firmware updates can address many software vulnerabilities when devices already have a trusted update mechanism. Secure gateways and network-level protections can also reduce exposure to legacy systems that cannot easily support modern cryptography.

Trusted platform modules and external secure elements may extend the useful life of some equipment where integration is practical.

There will also be situations where the original hardware simply lacks the processing capability, secure storage or architectural support needed for post-quantum security. In those cases, replacement becomes part of the long-term modernization strategy, particularly for systems expected to remain operational for another decade or more.

SEALSQ’s acquisition and integration of IC’Alps added custom application-specific integrated circuit design capabilities across automotive, healthcare, industrial, and Internet of Things markets. How does designing security into a custom chip from the beginning change the development process compared with adding a separate security component later?

Security becomes a design requirement instead of an integration task.

When security is considered from the earliest stages of ASIC development, engineers can optimize architecture, memory, power consumption and physical protections together rather than adapting an existing design later. That generally leads to better performance, stronger resilience and a more efficient certification process.

Our integration of IC’Alps gives us the ability to work with customers much earlier in the development cycle and embed post-quantum security directly into custom silicon for demanding applications across automotive, healthcare, industrial systems and IoT.

That approach also gives manufacturers greater control over long-term product roadmaps because security becomes part of the chip’s foundation rather than an external component added later.

Through SEALSQ’s work with the MIT Media Lab, you are exploring trust in human-AI interaction and next-generation systems. As AI becomes embedded in vehicles, robots, industrial equipment, and autonomous devices, how should hardware-based identity and attestation be used to verify which machines and AI agents can be trusted?

As AI moves into physical systems, trust becomes just as important as intelligence. Organizations will need confidence that an AI system is running authorized software on authentic hardware and communicating with verified devices. Hardware-based identity and attestation provide that foundation by showing that a device is genuine and its firmware has not been modified.

SEALSQ’s work with the MIT Media Lab explores these questions at the intersection of security, privacy, quantum resilience and human-centered innovation. The collaboration looks beyond a single product to the future of digital trust and human-AI interaction, recognizing that trustworthy AI also requires understandable behavior, governance and clear accountability.

In practice, each machine can receive a unique identity whose private keys remain inside a tamper-resistant Root of Trust. It can then present signed evidence about its secure-boot status, firmware, software configuration and, where supported, its approved AI model or agent runtime. A verifier can use that evidence to decide whether to grant access, accept a command or place the machine in a safe operating mode.

The same principle applies to AI agents. An agent should have a verifiable credential tied to an accountable operator, defined role and limited permissions. Commands should be signed, time-bound and auditable, with policy checks or human authorization for high-impact actions. Our WISeRobot proof of concept illustrates this direction by combining secure identity, protected communications and trusted machine-to-machine interaction.

What would meaningful post-quantum preparedness look like over the next three to five years, and which actions should device manufacturers, infrastructure operators, regulators, and enterprise buyers begin taking now?

Meaningful preparedness means moving from awareness to implementation.

Manufacturers should begin designing new products with post-quantum security and cryptographic agility in mind rather than assuming hardware can always be upgraded later.

Infrastructure operators should identify long-life assets, understand where cryptography is embedded and develop realistic migration plans based on operational priorities.

Regulators can continue supporting common standards and encouraging long-term planning, particularly for sectors where public safety and critical services depend on connected devices.

Enterprise buyers should begin asking suppliers practical questions about post-quantum readiness, hardware Roots of Trust and long-term support. Procurement decisions made today will influence security for many years.

The transition to post-quantum security will take time. Organizations that begin preparing now will have greater flexibility, lower operational risk and a more manageable path as standards and deployments continue to mature.

Thank you for the great interview, readers who wish to learn more should visit SEALSQ.

Antoine is a visionary leader and founding partner of Unite.AI, driven by an unwavering passion for shaping and promoting the future of AI and robotics. A serial entrepreneur, he believes that AI will be as disruptive to society as electricity, and is often caught raving about the potential of disruptive technologies and AGI.

As a futurist, he is dedicated to exploring how these innovations will shape our world. In addition, he is the founder of Securities.io, a platform focused on investing in cutting-edge technologies that are redefining the future and reshaping entire sectors.