• 7 mins read
  • Published

ETSI Warns That Quantum Randomness Can Become Predictable

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

ETSI Warns That Quantum Randomness Can Become Predictable Science.Report © science.report
ETSI Warns That Quantum Randomness Can Become Predictable © science.report

ETSI's technical report TR 104 171 argues that quantum random-number generators require continuous validation across the full entropy chain because detector dead time, noise and side-channel leakage can reintroduce predictability.

Quantum randomness can lose its security value before it reaches an application. In a technical report published on September 24, 2026, the European Telecommunications Standards Institute (ETSI) says detector dead time, thermal noise and side-channel leakage can make the output of a Quantum Random Number Generator predictable when the hardware is not properly audited and conditioned. The report presents recommendations for modeling, validating and monitoring the generator across its full lifecycle; its ETSI technical briefing frames the issue as an end-to-end engineering problem rather than a property guaranteed by quantum physics alone.

  • Where Randomness Fails

    ETSI Technical Report ETSI TR 104 171 addresses implementation rather than treating a quantum entropy source as automatically trustworthy. The underlying physical process may be non-deterministic, but the practical device includes sensors, detectors, electronics, drivers, firmware, software and an application interface. Each layer can introduce bias, reduce usable entropy or expose information about the generated sequence.

    The report therefore covers the entire QRNG lifecycle, from the physical source through the user-facing interface. It calls for physical modeling of the Quantum Entropy Source and real-time estimation of conditional min-entropy, a measure of how much uncertainty remains when relevant side information is considered. Randomness must then be conditioned through extraction methods such as seeded Toeplitz hashing or multi-source extractors before it is supplied to cryptographic systems. In this framework, extraction is not a substitute for an accurate threat model: an extractor can strengthen a characterized source, but it cannot compensate for an entropy estimate that ignored an attack channel.

    That distinction matters because statistical randomness alone does not prove that a device is secure. A sequence can pass routine tests while an attacker influences the detector, exploits a period of detector dead time, couples energy into the electronics or observes a physical leakage channel. ETSI's emphasis on continuous min-entropy estimation is intended to make changes in operating conditions visible rather than treating a one-time laboratory test as permanent evidence of security.

  • The EZT Architecture

    ETSI's proposed response is the Entropy Zero Trust framework. It treats every stage in the entropy pipeline as untrusted until verified and requires hardware checks, runtime attestation, cryptographic signing and provenance auditing rather than accepting the quantum source as a trusted black box. The approach extends the familiar zero-trust principle from network identity to the origin, transformation and delivery of entropy.

    The controls address specific attack surfaces. Optical isolators are intended to reduce the risk of photodetector blinding through injected light, while electromagnetic and magnetic shielding limit RF and EMI interference. Voltage-regulation monitoring and active power and voltage fault detection target electrical manipulation and power-analysis probing. Continuous statistical sampling is also included as an operational health check, although such sampling should be understood as one monitoring layer rather than conclusive evidence that all physical attacks have been eliminated.

    The framework is deliberately broader than the quantum device itself. It extends through the hardware Root of Trust, drivers and API, with TPM or eFuse mechanisms proposed for boot attestation. In that respect, the report's logic resembles the layered verification needed elsewhere in quantum infrastructure; quantum network context shows why specialized quantum hardware still depends on conventional control and monitoring systems.

    The report's scope also helps distinguish it from a peer-reviewed performance paper in Nature or a facility-specific validation associated with CERN or MIT. Its purpose is to define an engineering vocabulary and a security workflow that can be applied across different QRNG architectures, not to declare one device universally secure.

  • Engineering Classes

    ETSI places platforms into trust levels. TL-0 describes a raw, unverified source, TL-2 an EZT-compliant platform and TL-3 a critical or military-grade system. These labels are paired with engineering controls rather than presented as a single universal measure of quantum quality.

    The report also classifies practical constraints through throughput and power. Throughput runs from Class I at up to 100k to Class V at 1G or more. Power categories range from Class A at up to 100mW to Class D at 2-10W. The document proposes a common command interface and op-codes for the control plane, alongside architectures that combine QRNG entropy pools with post-quantum cryptography. It also identifies trust level, throughput, power consumption, size, weight, interface requirements and scalability as comparison parameters for different implementations.

    Those figures describe design categories, not a performance result from one named QRNG. They give implementers a vocabulary for comparing entropy systems while keeping resource limits visible. A high-throughput source that lacks attestation or tamper resistance would not satisfy the report's zero-trust premise simply because it produces more bits, just as a compact low-power design may require additional controls if its physical environment is difficult to monitor.

  • From Guidance To Standards

    Chaired by Mark Pecen of ETSI TC Quantum, the committee identifies several priorities for later normative Technical Specifications. They include standardized API command sets, logging protocols, alignment with Common Criteria and FIPS 140-3, and integration models that pair certified QRNG entropy pools with post-quantum algorithms such as ML-KEM and ML-DSA. ETSI also points toward stronger security-certification models and possible standards for attestation and audit logging.

    The wording matters. ETSI TR 104 171 is a Technical Report that sets implementation guidelines and priorities for subsequent specifications. The material supplied here does not establish independent certification of every QRNG, a measured security level for a particular product or a completed integration with ML-KEM or ML-DSA.

    It does establish a useful engineering boundary: quantum origin is not the same as end-to-end trust. A QRNG should be judged by the entropy source, extraction process, monitoring, boot state, interfaces and resistance to physical interference as one system. That is the report's strongest contribution, because it shifts attention from the word quantum to the points where real hardware can reintroduce predictability.

    Conditional min-entropy is the uncertainty that remains in a source when an observer may possess relevant side information. It is not identical to the output of a basic randomness test, which can miss correlations caused by hardware behavior or an active disturbance. An extractor compresses a suitably characterized source into output with stronger statistical guarantees, but it does not repair an entropy model that ignored an attack channel. For QRNG users, the practical lesson is direct: quantum physics may supply the raw unpredictability, while security depends on measurement, conditioning and continuous verification across the device.

  • Related articles