Quantum Random Numbers: How They Can Pass Tests Yet Leak Security Risks
The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, provides detailed guidance for designing and assessing quantum random number generators (QRNGs).
The European Telecommunications Standards Institute’s (ETSI) technical report
The document highlights vulnerabilities in the devices and their supporting infrastructure that could compromise the security of the random numbers they produce. A QRNG functions by measuring quantum phenomena and converting raw data into usable random values. Cryptographic systems depend on these unpredictable sequences to create keys and execute security protocols. If adversaries can anticipate these values, the effectiveness of the security mechanisms they support may be undermined.
The report traces the flow of random numbers
The report traces the flow of random numbers from their origin to the applications that utilize them. It outlines methods for manufacturers to confirm the authenticity of the quantum source, process its raw output, and detect anomalies during operation. The document also examines risks such as physical tampering, data leakage, and the transmission channels that transport numbers to other systems. A critical issue identified is that numbers may pass statistical randomness tests while still providing attackers with hints about future outputs.
Artificial intelligence could expose weaknesses in QRNGs
Artificial intelligence could expose weaknesses in QRNGs. AI tools might enable attackers to identify patterns stemming from a QRNG’s sensors, power systems, or signal processing units. These elements can introduce noise into the output, some of which may exhibit predictability. An adversary could analyze extensive datasets to detect correlations that reveal insights into the device’s output. The report notes that exploiting such vulnerabilities would require significant time and resources. Devices might also inadvertently disclose information through variations in power consumption or electromagnetic emissions. AI could assist in linking these signals to the generated random numbers. This risk extends to other random number generators utilizing similar hardware components.
Comprehensive verification at each stage
The guidelines suggest implementing physical shielding for critical hardware, employing robust techniques to process raw outputs, and conducting continuous pattern analysis during operation. Ongoing monitoring allows operators to identify faults or potential interference before relying on compromised outputs.
Entropy zero trust for high-security environments
For QRNGs deployed in regulated or high-security environments, the report advocates an approach termed entropy zero trust. This methodology mandates validation of the quantum source and continuous surveillance of the device throughout its lifecycle. Hardware and software safeguards prevent tampering, while encrypted connections protect the output as it transitions to applications. The framework also addresses systems shared by multiple users. Additional protections can help prevent unauthorized access. Devices must log timestamps of number generation, details of active software, and metadata tracing outputs to their origin. These records aid in investigating anomalies and demonstrating the device’s operational state when generating numbers used by security systems.
ETSI emphasizes standardized evaluation criteria
ETSI emphasizes the need for standardized evaluation criteria for QRNGs, including security capabilities, performance metrics, power consumption, physical dimensions, and integration complexity.
