

Security and Resiliency Services
Securing Storage from Silicon to Software: Dell’s Layered Approach to PQC Readiness
Key takeaways:
-
- PQC isn’t a single upgrade — storage security spans hardware, firmware, software and data, each with its own cryptographic dependencies.
- Two risks demand action now — future decryption (HNDL) and forged trust (TNFL), with integrity failures often the more immediate threat.
- Authentication must lead — compromised signatures and firmware trust chains can break systems faster than encrypted data is decrypted.
- Coordination is the advantage — a phased, full-stack approach reduces gaps that emerge when vendors transition to PQC on different timelines.
- Learn how Dell AI Factory with NVIDIA delivers a comprehensive and secure AI solution customizable for any business.
Post-quantum cryptography readiness is often discussed as if it were a single upgrade — swap the algorithm, update the certificate, move on. In storage, that framing falls apart immediately.
A modern storage platform is not a single system. It is a layered architecture where hardware, firmware and software each carry their own cryptographic dependencies — and each must evolve on its own timeline. Dell’s approach to PQC readiness reflects this reality by engineering the transition across six distinct security layers, coordinated but not dependent on any single release.
Layer 1: Hardware supply chain and platform integration
PQC begins before a storage system is ever powered on. The components that go into a platform — processors, controllers, network interface cards, storage media — must be sourced from suppliers who are themselves transitioning to quantum-resistant cryptographic primitives.
Dell works directly with silicon and component providers to align PQC enablement at the hardware level. This includes next-generation trust anchors such as Data Center Secure Control Modules (DC-SCM) and Trusted Platform Modules (TPM) that support PQC-aware key generation and attestation. The goal is to establish a quantum-resistant foundation before firmware ever executes.
Layer 2: Secure manufacturing and code signing
Every piece of firmware and software that runs on a Dell storage platform must be signed and validated. Today, that signing relies on classical algorithms. The transition to PQC means updating the signing infrastructure itself — the keys, the certificates and the validation chains used during manufacturing and deployment.
Dell is migrating its firmware signing infrastructure to support NIST-standardized algorithms. For firmware signing, platforms are adopting the Leighton-Micali Signature (LMS) algorithm, specified in SP 800-208 and CNSA 2.0 approved. For software and code signing, Dell is transitioning to ML-DSA (FIPS 204). This work is already underway, with quantum-resistant firmware validation being delivered to production PowerEdge platforms starting in 2026.
This layer directly addresses the Trust Now, Forge Later (TNFL) threat — the risk that quantum computers could forge digital signatures on firmware, software updates or certificates. While the Harvest Now, Decrypt Later (HNDL) threat produces a delayed confidentiality loss once a cryptographically relevant quantum computer (CRQC) exists, a forged firmware signature produces an immediate integrity crisis: malicious code executing on trusted hardware. Both threats demand urgent action and firmware signing is among the layers requiring early transition, because a compromised code-signing chain undermines every layer above it.
Layer 3: Platform root of trust
Secure boot is the mechanism that ensures only authenticated code runs when a system starts. It depends on a chain of trust that begins in hardware and extends through BIOS, baseboard management controllers (BMC) and into the storage operating environment.
Dell is evolving this chain to support PQC-based verification at every link — from Dell’s Integrated Dell Remote Access Controller — iDRAC firmware authentication to BIOS integrity validation. For storage platforms built on PowerEdge foundations, this means the root of trust itself becomes quantum-resistant, not just the applications running above it.
The industry is converging on a critical insight: as Q-Day estimates accelerate, post-quantum authentication becomes a higher priority than post-quantum encryption. Broken authentication is catastrophic — any overlooked quantum-vulnerable signing key becomes an access point for attackers. Any automatic software update mechanism secured by a forgeable signature becomes a remote code execution vector.
Layer 4: Platform software and cryptographic services
The operating system and cryptographic libraries that underpin storage software must also evolve. This includes migration to OpenSSL 3.5 and higher with PQC FIPS providers and Dell’s BSAFE cryptographic toolkit with ML-KEM and ML-DSA support, along with alignment with FIPS 140-3 validation requirements. Similar transitions are underway across other language ecosystems, including Java and Go-based cryptographic toolkits used in Dell products.
For products built on SUSE Linux Enterprise Server (SLES), this means coordinating the SLES 16 migration – a significant effort that Dell is centralizing across its storage and data protection portfolio to reduce duplication and accelerate delivery.
Layer 5: Secure system communications
Storage platforms communicate constantly — with management consoles, identity providers, telemetry services, and enterprise directories. Every one of these communication paths relies on TLS, SSH or certificate-based authentication.
Dell is embedding cryptographic agility into these communication layers, which is being delivered in phases with PQC-capable TLS, LDAP, MFA and SSO support. This ensures that the control plane — often the most overlooked attack surface — evolves alongside the data plane.
Layer 6: Customer workload and data security
This is where PQC meets the data that customers care about most. Data-at-rest encryption, data-in-flight protection for replication and backup traffic and key lifecycle management all depend on cryptographic algorithms that must transition to quantum-resistant equivalents.
Dell’s approach supports hybrid cryptographic models — where classical and PQC algorithms coexist — ensuring backward compatibility during migration. Key management integration, including both symmetric key management via KMIP and asymmetric key management through enterprise PKI, is being aligned with PQC timelines, recognizing that customers’ key management infrastructure may transition at different speeds than their storage platforms.
Why the layered approach matters
No single layer can make a storage system quantum-safe. The quantum threat operates on two axes simultaneously: confidentiality (the risk of future decryption through Harvest Now, Decrypt Later) and integrity (the risk of forged signatures through Trust Now, Forge Later). If the firmware is PQC-signed but the key management system still relies on RSA, the system has a confidentiality gap. If the data plane is encrypted with ML-KEM for session key agreement but the firmware signing chain uses classical algorithms, the system has an integrity gap that is arguably more dangerous.
Dell’s six-layer framework ensures that PQC is not a checkbox on a feature list. It is an architectural transition that evolves across the entire system lifecycle — from the supply chain to the customer’s data.
Because Dell designs and integrates the full stack — from server platforms through storage controllers to the software that manages data protection — these layers can be coordinated rather than left to independent vendor timelines. That is the structural advantage of an integrated approach to PQC readiness.
What this means for customers
For organizations evaluating PQC readiness, the question should not be “is this vendor PQC ready?” but rather “does this vendor have a credible plan across every layer?”
Dell’s answer is a coordinated, phased transition that prioritizes the highest-risk layers while systematically evolving software, communications and data protection in parallel. It is not a single announcement. It is an engineering program designed to deliver quantum resilience without disrupting the environments customers depend on today.
