ETSI Identifies Technical Limitations and Implementation Vulnerabilities in Quantum Random Number Generators (ETSI TR 104 171)
AI-summarised brief · reviewed before publication
The European Telecommunications Standards Institute’s Cyber Security Technical Committee released ETSI TR 104 171, a set of implementation guidelines for Quantum Random Number Generators (QRNGs). The report highlights how practical hardware issues—detector dead time, thermal noise, and side‑channel leakage—can undermine the inherent unpredictability of quantum processes. It introduces the Entropy Zero Trust (EZT) framework, requiring continuous hardware verification, runtime attestation, and cryptographic signing at every stage of the entropy pipeline. The document also outlines future normative specifications, including standardized APIs, logging protocols, and alignment with Common Criteria/FIPS 140‑3 and post‑quantum cryptography standards such as ML‑KEM and ML‑DSA.
💡 Why It Matters
- · By formalizing rigorous safeguards for QRNGs, the guidelines aim to prevent subtle hardware flaws from eroding quantum‑based security, ensuring that emerging quantum cryptographic systems remain truly random and trustworthy.