TokenSec s.r.o. · Prague, Czech Republic

Deep security and cryptography engineering.

For vendors and enterprises with serious assurance requirements, TokenSec engineers the critical low-level components of the security stack: smart card middleware, cryptographic providers, kernel modules, and hardware-backed key management. Beyond building these components, we keep them secure: our AI-driven agentic pipeline continuously evaluates newly reported vulnerabilities and CVEs against our codebase, so emerging threats are assessed and addressed as they surface.

About

Who we are

Founded and led by Jan Puskar, former Chief Development Engineer at Charismathics GmbH (Munich, Germany), TokenSec has since 2019 focused on the parts of systems where there is no margin for error: cryptographic engines, smart card and token middleware, authentication subsystems, kernel drivers, and trusted hardware.

Our work is embedded in critical systems at global scale: middleware deployed to roughly 500,000 users across two of the world's largest aircraft manufacturers, government agencies, and a Chrome extension that lets tens of thousands of Chromebook users sign in with a smart card every day. TokenSec is a focused, senior, hands-on consultancy with no layers between you and the engineering.

Jan Puskar, Founder & Principal Engineer of TokenSec
Jan Puskar
Founder & CEO

Services

What we do

Specialised, senior engineering across the cryptography and authentication stack — from filesystems to post-quantum cryptography.

Smart Cards & Tokens

PKCS#11 engines and middleware for PIV, IAS-ECC, PKCS#15, GlobalPlatform and proprietary card profiles covering major market share of card vendors.

Cryptographic Engineering

Cryptographic engines, Symmetric/asymmetric crypto schemes, multi-party/homeomorphic cryptography; protocol design and reference implementations.

PKI & Authentication

Windows certificate logon, Credential Providers, Key Storage Providers, 802.1X, and custom TLS authentication.

Low-Level & Kernel

Drivers and security modules for any platform, Side-channel mitigation in severely limited environments.

Trusted Computing

Trusted Platform Module development, Trusted Boot integration, HSM-backed cryptographic modules and Intel Secure Enclave isolation.

Consulting & Troubleshooting

Architecture review, hard-to-diagnose authentication and crypto issues, reverse engineering issues and proof-of-concept development with a clear path to production.

Selected Work

A sample of delivered projects

Cross-platform smart card filesystem explorer

Forensics tool for inspection of all card file system objects and their attributes for PIV, CAC, IAS-ECC, PKCS#15 and GlobalPlatform profiles.

Smart card middleware for all major OS platforms

PKCS#11 modules, MS minidrivers with WHQL certification, CNG/KSP providers. Customized certificate propagation and enrollment functionality.

Chrome OS Smart Card Extension

Joint development with the Chrome OS vendor. Whitelisted for OS login, built as a WASM security engine with JavaScript wrappers.

Hardware-backed ECC encryption toolkit

Minimal ECIES library (X25519 and NIST curves, AES-256-GCM, HKDF-SHA256) for YubiKey and ECC capable devices over the PC/SC interface.

Cloud HSM cryptographic module

Custom OpenSSL engine and a Windows Key Storage Provider driving an HSM in a financial institution's cloud.

Virtual smart card in a secure enclave

A Windows virtual smart card running entirely inside an Intel Secure Enclave, memory-isolated from the host OS.

Java Card applet development

Custom Java Card applets: on-card key generation, PIN/PUK lifecycle, secure messaging and GlobalPlatform loading, plus the host-side PKCS#11 middleware to drive them in production.

Post-quantum migration & crypto agility

Migrating products to NIST post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) with hybrid classical/PQC schemes and crypto-agile designs that let customers swap algorithms as the quantum threat evolves — without re-engineering.

Biometric & second-factor OS login

Biometric and second-factor authentication for OS login: fingerprint and hardware-token unlock integrated with Windows Credential Providers and smart-card logon.

Stack

Technologies & standards

Languages & Runtimes

CC++Java CardNode.jsWebAssembly

PKCS & Encodings

PKCS#1PKCS#5PKCS#7 / CMSPKCS#8 PKCS#11PKCS#12PKCS#15X.509 ASN.1 / BER-TLV

FIPS & NIST

FIPS 140-3FIPS 186 (ECDSA)FIPS 197 (AES) FIPS 198 (HMAC)FIPS 180 (SHA-2)FIPS 202 (SHA-3) PIV / FIPS 201SP 800-56ASP 800-90ASP 800-108

Post-Quantum (FIPS)

ML-KEM · FIPS 203ML-DSA · FIPS 204SLH-DSA · FIPS 205 LMS / XMSS · SP 800-208

Smart Cards, Hardware & Platforms

ISO/IEC 7816PC/SCIAS-ECCTPM 2.0HSM UEFIWindows CNG / KSPFreeBSD kernel

Protocols & Assurance

RFC 5280TLSEAP-TLS / 802.1X FIDO2 / WebAuthn / CTAP2 Common Criteria · ISO/IEC 15408eIDAS

Contact

Work with us

TokenSec takes on a small number of focused engagements. If you need senior, hands-on work on cryptography, smart cards, authentication or low-level security, get in touch with our team.