ETSI report highlights security limitations of quantum random number generators
ETSI’s new technical report provides implementation guidance for protecting quantum random number generators against weaknesses that could affect the security and reliability of their outputs.
The European Telecommunications Standards Institute (ETSI) has published a new technical report examining security and implementation challenges affecting quantum random number generators (QRNGs). ETSI TR 104 171 provides guidance on reducing weaknesses that could undermine the quality and security of QRNG outputs.
Random number generators are an important component of modern cryptography because encryption systems rely on unpredictable values to generate keys and other security parameters. QRNGs use quantum phenomena as a physical source of randomness, rather than relying solely on deterministic algorithms.
However, the use of a quantum source does not by itself guarantee secure randomness. According to ETSI, an attacker with access to relevant side information could gain additional predictability from the system and potentially undermine its outputs. The report therefore considers security across the entire QRNG implementation rather than focusing only on the quantum source.
The guidance covers the QRNG lifecycle, including modelling and validating the quantum entropy source, applying randomness extraction and monitoring entropy quality during operation. It also addresses the detection of drift, bias and hardware failures, as well as protection against tampering and side-channel attacks.
A central concept introduced in the report is ‘Entropy Zero Trust’. This approach treats every stage of the entropy pipeline as potentially vulnerable and requires verification rather than assuming that any individual component can be trusted. The proposed controls span the quantum source, hardware, interfaces, operational monitoring and shared computing environments.
ETSI also calls for greater consistency in how QRNG implementations are assessed. The report identifies factors including trust level, throughput, power consumption, size, weight, interface requirements and scalability as characteristics that could provide a common basis for comparing different implementations and understanding their deployment trade-offs.
The report identifies several areas for future standardisation, including attestation and logging protocols, stronger security certification models and guidance on combining QRNGs with post-quantum cryptography. ETSI said the guidance is intended to help ensure that quantum-generated entropy remains trustworthy from its source through to the applications that use it.
