As quantum computing nears commercialization, hardware roots of trust may be an early beneficiary of post-quantum security deployment
AI summary card
As quantum computing nears commercialization, hardware roots of trust may be an early beneficiary of post-quantum security deployment
The report expects commercially meaningful quantum-computing applications around 2030; PQC migration and “harvest now, decrypt later” risks will drive early demand for PUFs, hardware roots of trust, and semiconductor security IP.
- Under the base case, the PUF-enabled PQC IP market could reach US$310 million by 2030; under the bull case, it could reach US$600 million if expanded to CPUs, GPUs, and ASICs.
- The report expects PQC penetration in the semiconductor industry to reach approximately 25% by 2030, while security-sensitive applications such as automotive ADAS and defense semiconductors could exceed 50%.
- eMemory is viewed as a core beneficiary and is initiated at Overweight; Synopsys, Aspeed, and others are also identified as beneficiaries or adopters.
- Hardware deployment typically precedes broad adoption by 3–5 years, making the current period a critical window for migration to quantum security.
Report interpretation
Overview
Morgan Stanley believes fault-tolerant quantum computing could reach a commercially meaningful stage around 2029–2030 and may undermine existing public-key cryptographic systems such as RSA and ECC. Given “harvest now, decrypt later” risks, regulatory migration roadmaps, and infrastructure replacement cycles, post-quantum security construction needs to begin before Q-Day. The report focuses on hardware roots of trust at the server and chip levels, viewing them as foundational to PQC implementation.
Core views
The report sees PQC as the primary entry path for post-quantum security, but PQC addresses only algorithmic resistance to quantum attacks; key generation, storage, and protection still depend on hardware roots of trust. PUFs can use inherent physical characteristics of chips to generate device-unique keys, reducing the risk of key cloning or extraction while potentially easing the performance, power, and area burden associated with PQC deployment. The commercial PUF market is relatively concentrated, with Synopsys and eMemory among the key participants; advanced process nodes and larger key requirements may increase the appeal of oxide-based PUFs.
Analysis framework
Using quantum-computing industry roadmaps, government PQC migration requirements, and chip-application penetration rates, the report combines PQC adoption rates across chip types, PUF adoption rates across PQC solutions, and encryption-processor adoption rates to develop scenario estimates for the PUF-PQC semiconductor IP market, while assessing investment implications for IP vendors and adopters.
Methodology notes
Base, bull, and bear cases
Estimates the hardware quantum-security IP market based on varying assumptions for PQC penetration, PUF adoption, and chip coverage.
PQC and RoT are complementary
PQC protects cryptographic algorithms, while hardware roots of trust protect keys, device identity, secure boot, and firmware validation.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- eMemory (3529.TWO)PUF IP vendor
- Strengths
- The report believes NeoPUF has potential advantages in advanced-process scalability, low power consumption, and next-generation hardware-root-of-trust applications; it receives an initial Overweight rating.
- Weaknesses
- PUF remains a relatively emerging and small-scale IP market.
- Comparison
- Compared with SRAM PUFs, oxide-based PUFs may offer lower area and power overhead while improving scalability at advanced nodes.
- Risks
- Quantum-computing progress falls short of expectations, competition among PUF solutions intensifies, or customers shift to in-house development or alternative technologies.
- Synopsys (SNPS.O)Semiconductor IP and EDA vendor
- Strengths
- It has a broad IP portfolio, customer relationships across chip-design workflows, and hardware-security integration capabilities; it has acquired PUF IP vendor Intrinsic ID.
- Weaknesses
- PUF is expected to make only a limited near-term contribution to overall earnings.
- Comparison
- Its scale, product breadth, and bundling capabilities may be superior to those of focused vendors.
- Risks
- Competitors such as eMemory could reshape the competitive landscape, although the report considers the financial impact on Synopsys limited.
- CadenceEDA and hardware-security IP platform
- Strengths
- Its acquisition of Secure-IC strengthened embedded-security, hardware-root-of-trust, and PUF capabilities; its customer base supports the promotion of security IP.
- Weaknesses
- The revenue contribution from post-quantum security has not yet been clarified.
- Comparison
- It may expand coverage through system-level integration and design-tool bundling.
- Risks
- Uncertainty remains around sources of PUF technology, alternative solutions, and the pace of customer adoption.
- Aspeed (5274.TWO)Post-quantum security adopter
- Strengths
- Identified by the report as a key adopter and assigned an Overweight view.
- Weaknesses
- The report does not provide a quantified contribution from quantum-security revenue.
- Comparison
- Compared with pure-play IP vendors, its benefit path depends more on product adoption and end-market deployment.
- Risks
- PQC standards deployment and downstream demand may fall short of expectations.
- IBMParticipant in quantum computing and quantum-security services
- Strengths
- It has a full-stack quantum roadmap and can support enterprise PQC migration through software, consulting, and hybrid cloud.
- Weaknesses
- Standalone quantum-hardware revenue may remain limited before breakthroughs in fault tolerance, logical qubits, and practical workloads.
- Comparison
- Its business is more diversified than that of pure-play quantum companies, while quantum-security migration provides an earlier and less binary monetization path.
- Risks
- Quantum-related revenue may still represent only a very small share of the overall business initially.
- Quantinuum、IonQDirect quantum-computing exposure
- Strengths
- Could benefit from growth in government, research, and commercial demand if technology roadmaps and commercialization execution succeed.
- Weaknesses
- They carry greater technology and execution risk than diversified technology companies.
- Comparison
- They offer more direct upside exposure to quantum computing, but performance is more sensitive to technology timelines.
- Risks
- Uncertainty remains around logical-qubit quality, error rates, system reliability, customer utilization, order-to-revenue conversion, and continued cash investment.
Key data
- Quantum infrastructure market size forecastUS$110 billion in 2040The report's forecast for quantum-infrastructure TAM.
- PUF-PQC IP market sizeUS$310 million in 2030Base case.
- PUF-PQC IP market sizeUS$600 million in 2030Bull case, assuming adoption expands to CPUs, GPUs, and ASICs.
- PUF-PQC IP market sizeUS$4 million in 2025Current market size used by the report for comparison.
- PQC penetration in the semiconductor industryApproximately 25%The report expects overall penetration by 2030; automotive ADAS, defense, and similar applications could exceed 50%.
- Quantum-computing commercialization timing2029–2030Industry roadmaps point to an inflection point for commercially meaningful fault-tolerant quantum computing.
Impact & implications
The investment implication is that the monetization window for quantum security may precede revenue from general-purpose quantum-computing hardware. Regulatory compliance, long-term key-protection needs, and server-refresh cycles could create multiyear migration demand; however, for large platform companies, quantum security is more likely to strengthen product portfolios and customer stickiness in the near term than to materially alter overall profitability.
Risks
- Quantum-computing commercialization and the development of fault-tolerant capabilities proceed more slowly than expected.
- Competition intensifies in foundational PUF solutions and post-quantum security technologies.
- New quantum cryptographic technologies or alternative security architectures emerge.
- PQC standards migration, customer budgets, and hardware-refresh cycles may be delayed.
- Technology milestones may not translate into near-term commercial revenue or profitability.
What to watch
- Progress by IBM, Quantinuum, and others in logical qubits, error correction, and reliability.
- PQC migration rules, compliance deadlines, and implementation pace in the United States, the United Kingdom, and other regions.
- Actual adoption rates of PQC and hardware roots of trust across semiconductors, cloud, networking, and data centers.
- PUF design wins, licensing, and royalty progress at vendors such as eMemory, Synopsys, and Cadence.
- Expanded adoption in security-sensitive applications such as automotive ADAS, defense, CPUs, GPUs, and ASICs.