About
Founded and led by Jan Puskar, former Chief Development Engineer at Charismathics GmbH (Munich, Germany), TokenSec has since 2019 focused on the parts of systems where there is no margin for error: cryptographic engines, smart card and token middleware, authentication subsystems, kernel drivers, and trusted hardware.
Our work is embedded in critical systems at global scale: middleware deployed to roughly 500,000 users across two of the world's largest aircraft manufacturers, government agencies, and a Chrome extension that lets tens of thousands of Chromebook users sign in with a smart card every day. TokenSec is a focused, senior, hands-on consultancy with no layers between you and the engineering.
Services
Specialised, senior engineering across the cryptography and authentication stack — from filesystems to post-quantum cryptography.
Smart Cards & Tokens
PKCS#11 engines and middleware for PIV, IAS-ECC, PKCS#15, GlobalPlatform and proprietary card profiles covering major market share of card vendors.
Cryptographic Engineering
Cryptographic engines, Symmetric/asymmetric crypto schemes, multi-party/homeomorphic cryptography; protocol design and reference implementations.
PKI & Authentication
Windows certificate logon, Credential Providers, Key Storage Providers, 802.1X, and custom TLS authentication.
Low-Level & Kernel
Drivers and security modules for any platform, Side-channel mitigation in severely limited environments.
Trusted Computing
Trusted Platform Module development, Trusted Boot integration, HSM-backed cryptographic modules and Intel Secure Enclave isolation.
Consulting & Troubleshooting
Architecture review, hard-to-diagnose authentication and crypto issues, reverse engineering issues and proof-of-concept development with a clear path to production.
Selected Work
Cross-platform smart card filesystem explorer
Forensics tool for inspection of all card file system objects and their attributes for PIV, CAC, IAS-ECC, PKCS#15 and GlobalPlatform profiles.
Smart card middleware for all major OS platforms
PKCS#11 modules, MS minidrivers with WHQL certification, CNG/KSP providers. Customized certificate propagation and enrollment functionality.
Chrome OS Smart Card Extension
Joint development with the Chrome OS vendor. Whitelisted for OS login, built as a WASM security engine with JavaScript wrappers.
Hardware-backed ECC encryption toolkit
Minimal ECIES library (X25519 and NIST curves, AES-256-GCM, HKDF-SHA256) for YubiKey and ECC capable devices over the PC/SC interface.
Cloud HSM cryptographic module
Custom OpenSSL engine and a Windows Key Storage Provider driving an HSM in a financial institution's cloud.
Virtual smart card in a secure enclave
A Windows virtual smart card running entirely inside an Intel Secure Enclave, memory-isolated from the host OS.
Java Card applet development
Custom Java Card applets: on-card key generation, PIN/PUK lifecycle, secure messaging and GlobalPlatform loading, plus the host-side PKCS#11 middleware to drive them in production.
Post-quantum migration & crypto agility
Migrating products to NIST post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) with hybrid classical/PQC schemes and crypto-agile designs that let customers swap algorithms as the quantum threat evolves — without re-engineering.
Biometric & second-factor OS login
Biometric and second-factor authentication for OS login: fingerprint and hardware-token unlock integrated with Windows Credential Providers and smart-card logon.
Stack
Languages & Runtimes
PKCS & Encodings
FIPS & NIST
Post-Quantum (FIPS)
Smart Cards, Hardware & Platforms
Protocols & Assurance
Contact
TokenSec takes on a small number of focused engagements. If you need senior, hands-on work on cryptography, smart cards, authentication or low-level security, get in touch with our team.