Quantum random number generators (QRNGs) are meant to provide the unpredictable numbers that cryptographic systems rely on, but new guidance from the European Telecommunications Standards Institute (ETSI) stresses that the quantum source is only part of the story. The technical report, ETSI TR 104 171, examines weaknesses in the devices and their supporting systems, arguing that secure randomness depends on the integrity of the entire implementation—from the source through processing and delivery to the application.
A central concern is that a QRNG's output can pass standard statistical tests while still giving an attacker clues about future numbers. Components such as sensors, power supplies, and signal processors can add predictable noise to the output, and AI could help an attacker analyze large volumes of data to find those patterns. The report also notes that physical signals like power use or electromagnetic emissions may leak information, and that similar risks apply to other types of random number generators using comparable components.
For high-security and regulated settings, ETSI recommends an approach called entropy zero trust. This involves verifying the quantum source, monitoring the device during operation, shielding sensitive hardware, and protecting the output as it travels to applications. It also calls for separate safeguards in multi-user systems, plus records that trace generated numbers to their source and show which software was running. Finally, ETSI asks for more consistent ways to compare QRNGs, including security features, speed, power use, size, and ease of integration.