European standards body warns that quantum random number generators have real hardware weaknesses hackers could exploit

Started by Modric, Today at 02:58 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: European standards body warns that quantum random number generators have real hardware weaknesses hackers could exploit   Views(Read 48 times)
Active members in this topic:
Modric(1) Cass64(1)

Modric

The European Telecommunications Standards Institute's Technical Committee Cyber Security, chaired by Mark Pecen, has published ETSI TR 104 171, a technical report on implementation guidelines for quantum random number generators that identifies a range of genuine hardware level vulnerabilities in these systems. Despite the underlying quantum processes themselves being genuinely non-deterministic, the report finds that hardware limitations including detector dead times, thermal noise and side channel leakage can reintroduce real predictability into the numbers these devices actually output.

Specific attack vectors identified in the report include optical injection blinding attacks, radio frequency electromagnetic interference, and power analysis probing, all of which could potentially be used by an attacker to manipulate or predict the output of a quantum random number generator despite its theoretically unpredictable quantum foundation. To address these weaknesses, the report proposes a framework called Entropy Zero Trust, which treats every single stage of the entropy generation pipeline as inherently untrusted and subject to continuous hardware verification, real time attestation and cryptographic signing rather than simply trusting the quantum source at face value.

The report also lays out a tiered classification system for these devices, ranging from TL-0 for a raw, unverified entropy source up to TL-2 for a fully Entropy Zero Trust compliant platform and TL-3 for critical or military grade applications, alongside technical requirements covering real time conditional min-entropy estimation and randomness extraction methods such as seeded Toeplitz hashing. Future standardisation priorities flagged in the report include standardised API command sets and logging protocols, alignment with Common Criteria and FIPS 140-3 certification standards, and integration with the post quantum cryptography standards ML-KEM and ML-DSA.
I put the "ring" in debugging, mostly screaming

Cass64

The core irony here is genuinely striking, the underlying quantum physics is theoretically perfectly unpredictable, yet ordinary hardware level engineering flaws can still reintroduce exploitable predictability into the final output regardless of that theoretical guarantee.

Save money on everyday spending Free cashback on thousands of retailers
View offer