ETSI flags weak spots in quantum random number generators

Understand this faster with AI
A new technical report, ETSI TR 104 171, details how adversaries exploiting side-information can undermine the randomness of Quantum Random Number Generators (QRNGs) even when their output appears statistically sound. The report from ETSI delivers implementation guidance to address these weaknesses in QRNGs, a critical component for modern cryptographic systems that rely on unpredictable values for security. ETSI introduces the concept of asserting that every stage of the entropy pipeline must be verified, rather than assuming inherent trustworthiness. “While quantum physics is adept at providing genuine unpredictability, secure randomness rests on the integrity of the entire implementation,” said Mark Pecen, Chair of ETSI TC Quantum. ETSI TR 104 171 Details Lifecycle Weaknesses ETSI TR 104 171 establishes a framework for evaluating QRNGs based on trust level, throughput, power consumption, size, weight, interface requirements, and scalability, offering a standardized approach to comparing diverse implementations. This detailed assessment allows developers and purchasers to better understand the trade-offs inherent in different QRNG designs, facilitating more informed deployment decisions and promoting interoperability across systems. The report moves beyond simply assessing the quantum source itself, recognizing that a QRNG’s overall security is dependent on a thorough evaluation of its components and operational environment. This approach proposes layered controls spanning the quantum source, hardware platform, interfaces, operational monitoring, and even shared computing environments, acknowledging that vulnerabilities can emerge at any point in the process. No component is considered secure without explicit validation, a departure from traditional models that often rely on implicit trust in foundational elements. This vulnerability highlights the importance of protecting against tampering and side-channel attacks, as well as securing the entire data path from the entropy source to the application utilizing the random numbers. ETSI TR 104 171 encapsulates the complete QRNG lifecycle, from initial modeling and validation of the quantum entropy source, through randomness extraction, to continuous monitoring for drift, bias, and hardware failures. “These guidelines arrive at a critical moment as organizations need to understand how to validate the quantum source and ensure that entropy is properly extracted, monitored, protected and securely delivered to the applications that depend on it,” Pecen added. The report also outlines future standardization priorities, including attestation and logging protocols, and stronger security-certification models, alongside guidance for integrating QRNGs with post-quantum cryptography. While quantum physics is adept at providing genuine unpredictability, secure randomness rests on the integrity of the entire implementation. Mark Pecen, Chair of ETSI TC Quantum Source: https://www.etsi.org/deliver/etsi_tr/104100_104199/104171/01.01.01_60/tr_104171v010101p.pdf More like thisQuantum TechnologyQuantum Flagship seeks feedback on complete SRIA documentQuantum AlgorithmsKey decoupling boosts security for remote quantum computationsQuantum SecurityKrown browser aims for Web3 access with post-quantum securityQuantum SecurityGartner highlights QuSecure’s platform for quantum-safe dataStay currentSee today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals. Tags: Ivy Delaney Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing.
For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.
Source Information
Discussion
0 professional contributions
Sign in to join this professional discussion.
Be the first to add a constructive contribution.
