• 4 mins read
  • Published

Quantum eMotion's Entropy Module Enters NIST Validation Process

Daisy Shearer Physics and quantum technology editor Science.Report

Post by Daisy Shearer

Quantum eMotion's Entropy Module Enters NIST Validation Process Science.Report © science.report
Quantum eMotion's Entropy Module Enters NIST Validation Process © science.report

Quantum eMotion Corp. has submitted its eCore-Q PCIe Quantum Entropy Module for independent validation under the NIST SP 800-90B standard, a key step for cryptographic certification in regulated sectors

Quantum eMotion Corp. has initiated formal validation of its eCore-Q PCIe Quantum Entropy Module under the National Institute of Standards and Technology (NIST) SP 800-90B standard, a process that determines whether the device's quantum random number generation meets the statistical and physical unpredictability requirements for use in high-security cryptographic systems. The submission, conducted by the independent cybersecurity laboratory Lightship Security Inc., is a prerequisite for further certification under the Federal Information Processing Standard (FIPS) 140-3, which governs cryptographic modules in government and regulated industries.

Quantum Entropy Source and Device Architecture

The eCore-Q module is built around an electron-tunneling quantum random number generator (QRNG) chiplet, designed to produce high-rate streams of quantum entropy. Electron tunneling is a quantum process in which electrons pass through a potential barrier that would be insurmountable in classical physics, resulting in fundamentally unpredictable outcomes. The module is implemented as a PCIe card, allowing integration into standard server and enterprise hardware. According to the company, the device is intended to supply entropy for cryptographic key generation, secure communications, and other applications where unpredictability is critical.

Validation and Testing Framework

NIST SP 800-90B sets out mathematical and statistical tests for non-deterministic random number generators (NRNGs), requiring evidence that the entropy source is physically unpredictable and robust against environmental or implementation-based attacks. The validation process involves both statistical analysis and physical characterization of the entropy source. Lightship Security's assessment included submission through the Entropy Source Validation Test System (ESVTS), which is required for NIST to issue an official entropy validation certificate. This certificate is a mandatory component for subsequent FIPS 140-3 cryptographic module certification, which is necessary for deployment in U.S. federal, healthcare, and financial systems.

Integration and Commercial Implications

Once validated, the eCore-Q module could be integrated into regulated hardware products, supporting compliance with cryptographic standards in sectors such as government, finance, and enterprise IT. Quantum eMotion's broader security stack includes the eFlux-Q entropy stream, the eShield-Q runtime memory protection platform, and the SecureKey zero-exposure credential architecture. The company's approach reflects a trend toward combining quantum entropy sources with layered security solutions, as seen in recent industry developments where AI-based decoders and quantum error correction have been benchmarked against established protocols-for example, in a recent report on AI-driven quantum error correction outperforming traditional matching algorithms on Google's surface-code data (see coverage here).

Technical Evidence and Remaining Challenges

While the eCore-Q module's electron-tunneling QRNG is designed to deliver high-rate, pure quantum entropy, the NIST validation process will scrutinize both the statistical quality of the output and the physical unpredictability of the underlying process. The company has not disclosed detailed performance metrics such as entropy rate, bit generation speed, or robustness under varying environmental conditions. Independent laboratory assessment is a critical step, but full FIPS 140-3 certification will require further integration and system-level testing. As with all quantum entropy sources, long-term reliability, resistance to side-channel attacks, and reproducibility across devices remain important engineering challenges.

Quantum random number generators (QRNGs) exploit fundamental quantum processes-such as electron tunneling or photon detection-to produce sequences of bits that are unpredictable even in principle. Unlike pseudo-random number generators, which rely on deterministic algorithms, QRNGs derive their unpredictability from the inherent randomness of quantum measurement outcomes. For cryptographic applications, the quality of entropy is crucial: insufficient or biased randomness can undermine the security of encryption keys and protocols. NIST SP 800-90B provides a framework for evaluating whether a device's entropy source is genuinely non-deterministic and robust against manipulation, forming the basis for trust in cryptographic hardware deployed in sensitive environments.

Related articles