ETSI Publishes Guidance for Secure Quantum Random Number Generators

ETSI QRNG
Hub Hub

Insider Brief

  • ETSI has published Technical Report TR 104 171 with implementation guidance for improving the security and quality of Quantum Random Number Generator outputs.
  • The report covers the QRNG lifecycle, including quantum entropy-source validation, randomness extraction, operational monitoring, tamper protection, side-channel security and output provenance.
  • ETSI introduces an “Entropy Zero Trust” approach and identifies future standardization priorities including attestation, logging, security certification and QRNG integration with post-quantum cryptography.

PRESS RELEASE — ETSI announces its Technical Report, ETSI TR 104 171, which delivers much needed implementation guidance to mitigate weaknesses that could undermine the quality and security of Quantum Random Number Generator (QRNG) outputs.

Random number generators are a critical feature of modern security as cryptographic systems rely on unpredictable random values to generate encryption keys and other security parameters. QRNGs exploit quantum phenomena as a source of randomness, offering an approach based on physical processes that are inherently unpredictable rather than deterministic algorithms. However, while output may appear statistically random an adversary with access to relevant side-information adds a layer of predictability which they can exploit, undermining its randomness.

The Report encapsulates the complete QRNG lifecycle, from modelling and validating the quantum entropy source and applying appropriate randomness extraction, through to monitoring entropy quality during operation and detecting drift, bias and hardware failures. In this context, entropy refers to the amount of unpredictability available to generate secure random numbers. The Report also highlights how to protect QRNGs against tampering and side-channel attacks, secure the path from the entropy source through to the consuming application, and establish the provenance, attestation and auditability needed to demonstrate that random outputs remain trustworthy throughout their lifecycle.

Introducing TQI 2.0Introducing TQI 2.0

It introduces the idea of Entropy Zero Trust, a concept that reflects the need to treat every stage of the entropy pipeline as potentially vulnerable rather than assuming that any individual component can be inherently trusted. Under this approach, no part of the entropy pipeline is trusted without verification. It proposes layered controls spanning the quantum source, hardware platform, interfaces, operational monitoring and shared computing environments.

ETSI also makes the argument for a common basis for comparing QRNG implementations by trust level, throughput, power consumption, size, weight, interface requirements and scalability. Greater consistency in how these characteristics are assessed could help developers and buyers understand the trade-offs between different implementations and make more informed decisions about their deployment.

“While quantum physics is adept at providing genuine unpredictability, secure randomness rests on the integrity of the entire implementation,” said Mark Pecen, Chair of ETSI TC Quantum. “These guidelines arrive at a critical moment as organisations need to understand how to validate the quantum source and ensure that entropy is properly extracted, monitored, protected and securely delivered to the applications that depend on it.”

As ETSI continues its research into quantum cryptography, the Report outlines priorities for future standardisation, including attestation and logging protocols, stronger security-certification models and guidance for combining QRNGs with post-quantum cryptography.

For more information, please visit: Implementation Guidelines for Quantum Random Number Generators

Keep track of everything going on in the Quantum Technology Market. In one place.

Share

Stay Ahead of Quantum

Get the latest research, company news, and market intelligence every week.

MENTIONED IN THE ARTICLE

More in Research

Related Articles