ETSI TR 104 171, Announced 24 September 2026, Sets Entropy Zero Trust and Four Trust Levels for Quantum Random Number Generators: What Its Side-Channel Catalog Means for Military Key Generation
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 28, 2026.

On September 24, 2026, the European Telecommunications Standards Institute announced a technical report on how to build a quantum random number generator that deserves the trust its physics implies. The document, ETSI TR 104 171 version 1.1.1, was published in March 2026 by Technical Committee Cyber Security and carries 44 pages of implementation guidelines, a side-channel catalog, four trust levels and classification tables for throughput, power, volume and weight. Its central argument is easy to state and uncomfortable for a buyer: quantum measurement yields unpredictability in principle, and every classical component around that measurement can hand some of it back to an adversary.
A defense reader should care because these devices already sit at the base of the key hierarchy. The report's introduction lists the uses: key generation for RSA, AES and elliptic curves as well as for the post-quantum algorithms ML-KEM, ML-DSA and SLH-DSA, basis choice in quantum key distribution, and entropy for hardware security modules in government communications. The full report is public, and the ETSI press release quotes Mark Pecen, chair of the separate Technical Committee on Quantum Technologies, saying that secure randomness rests on the integrity of the entire implementation. This post reads what the report establishes, where it stops, and what a program office can do with it.
What the report establishes: uniform is not unpredictable, and a worked example where full statistical entropy carries zero secrecy against side information
Clause 4 sets out the theory in three toy examples that explain everything that comes after. A generator prepares a qubit in an equal superposition and measures it. In the ideal case the outcome is a perfect coin and no eavesdropper can know it. Now let the preparation suffer depolarizing noise the manufacturer cannot control. The outcomes remain a fair coin, so every statistical test passes and the unconditional min-entropy stays at one bit per outcome. The conditional min-entropy, the quantity that matters for cryptography, falls toward zero as the noise grows, because the report refuses to assume that noise the manufacturer cannot control is also noise an adversary cannot control. With the measurement also noisy, the secret content reaches zero once the noise parameter passes roughly 0.29 while the output still looks uniform.
That distinction drives clause 5. A vendor should publish a physical model of its quantum entropy source and rest the security claim on that model rather than on test suites. The device should estimate conditional min-entropy online, at runtime, so it knows when the source has drifted outside the parameters under which the claim holds. Extraction should use seeded two-universal hashing such as a Toeplitz extractor or a two-source extractor, with output length tied to the min-entropy bound. Statistical monitoring should run at one sample per second or faster, with logging, isolation of a suspect stream and a fallback source.
The report then defines the Entropy Zero Trust profile, five layers a generator in a regulated or high-security domain should carry: a provable quantum source with source-level attestation, continuous health monitoring, a hardware root of trust in the form of a TPM, eFuse or equivalent for secure boot and anti-rollback firmware, an authenticated integration path such as PCIe or AXI DMA with access control lists, and isolated entropy pools for multi-tenant hosts. Table 1 turns that into four trust levels. TL-0 is a bare component with raw data access and no provenance. TL-1 has self-tests but no runtime proof of quantum origin. TL-2 is the platform that meets the EZT profile, with attestation and hardened interfaces. TL-3, labeled military and critical infrastructure grade, adds dual entropy sources with certification and secure boot with a quantum-entropy-sealed identity.
The side-channel catalog: detector blinding, electromagnetic injection, magnetic fields, radiation, power and timing analysis, and a vendor case with a 20 percent repeat rate
Clause 5.1.4 is the part a security officer will read twice. Photodetectors can be blinded by a bright flash or laser pulse, forcing them into a deterministic state without physical contact. Out-of-band electromagnetic injection from an RF probe can force patterns, and the report notes that the effect can be subtle enough to pass standard statistical tests. Faraday rotator mirrors in unbalanced interferometers respond to external magnetic fields. Radiation can trigger false detections in photon-counting designs, and vacuum-fluctuation designs are less exposed than single-photon or radioactive-decay designs. Power analysis, supply-voltage tampering that pushes a laser out of regulation, timing analysis of detection intervals and weak post-processing round out the list. A short clause on AI-driven attacks is careful on the physics: machine learning cannot predict the quantum process, and it can learn the classical noise a vendor left out of the physical model.
Annex C gives the most concrete evidence in the document. A quantum entropy source built for stochastic simulation failed several Diehard tests, and a filter that followed 128-bit phrases across 27 million samples found repeats after fewer than a thousand rows, recurring every 40 to 240 rows, at a mean of one repeat per 5.5 phrases. The authors attribute the pattern to an internal glitch, possibly an 8-bit register overflow. A partitioned sliding Bloom filter in hardware, with an 8,000-bit array and a 400-element window, brought the output to 17 of 19 Diehard passes with two weak results. The report says plainly that more work would be needed for commercial or military grade, and that a filter that removes repeats too aggressively can destroy the distribution a cryptographic use requires. Annex A adds a procurement warning: some products marketed as quantum rely on amplified classical chaos or thermal noise, and buyers should request proof of quantum entropy validation.
Quantum pillar: post-quantum cryptography (roots of trust in hardware). Use posture: defensive. Technology readiness: assessed at TRL 1 of 9, pending verification against the governing readiness rubric. This is an informative technical report of guidelines and classification tables rather than a tested device, so there is no measured device result to place on the ladder, and the sub-branch follows the report's own placement of the quantum entropy source beneath a hardware root of trust that seals secure boot and seeds post-quantum keys.
Who gains from an entropy zero trust profile: HSM and TPM integrators, PQC key hierarchies, and the drone one-time-pad example in clause 5.3
Under the capability map this lane uses, the value described here lies entirely in protecting one's own keys, which is why the panel reads defensive. The report describes how an adversary would attack your generator and what to build against it, and it offers nothing for use against anyone else's. Annex A.5 states the layered target: a quantum source with validation evidence, post-quantum algorithms that do not rely on QKD, runtime attestation of entropy generation and consumption, and modular deployment. A comparison table places a software-seeded PQC-only stack at partial quantum-threat resilience and low supply-chain tamper resilience, and a PQC plus attested QRNG stack at strong and medium-to-high. The report's own integration examples are QRNG-backed secure boot with sealed firmware hashes, TPM-fused entropy for per-device identity keys, and certificate authorities with QRNG-seeded key pairs.
That is the same place in the stack the Monitor examined when SEALSQ put ML-DSA and ML-KEM into its QVault TPM: the security of a post-quantum signing key depends on the unpredictability of its key-generation randomness, and the ETSI profile says what those bits must prove about themselves. The hardware root of trust in Layer 3 is the hinge. Without it a generator can attest to nothing, and the provenance log the report asks for in clause 5.1.7, with a timestamp, firmware identifier and pipeline identifier on every output block, has no anchor.
The classification clauses show who the authors expect to buy. Clause 5.3 opens with a surveillance drone whose uplink is protected by a one-time pad generated on board and transferred to the ground station over a wired interface before flight, and it sets the envelope such a generator would have to meet: on the order of 10 grams, 100 milliwatts and 10 kilobits per second. Throughput classes run from Class I at or below 100 kilobits per second for embedded sensors to Class V above 1 gigabit per second for real-time QKD; power classes run from 100 milliwatts to 10 watts, with anything above that described as not typical or recommended. Weight bands are defined for airborne, space and mobile platforms. These are the size, weight and power terms a program office already uses, and their appearance in a randomness standard is the clearest signal in the document that defense integration is in view.
What stands between a technical report and a program office relying on it: no normative clauses, no test method for TL-3, certification regimes that measure the wrong entropy, and a technical specification still to be written
The first gap is the document's own status. A Technical Report at ETSI is informative. Clause 2.1 states that normative references are not applicable, the modal verb throughout is "should", and clause 5.3.6 says the command set and modes it sketches would be defined in a future Technical Specification. Nobody can claim conformance to TR 104 171 today, and a vendor who prints an EZT claim on a datasheet is citing a profile with no accredited test behind it.
The second gap is certification. The report lists FIPS 140-3, NIST SP 800-90B, BSI AIS 20/31, ISO/IEC 19790 and national schemes such as ANSSI and CCN as the routes to market, and its own Annex D explains why those routes do not settle the question the report raises. The NIST entropy source recommendation validates unconditional min-entropy from a million sequential samples, a thousand restarts and two health tests. It does not quantify unpredictability against side information, which is precisely the quantity clause 4 shows can be zero while every test passes. The German BSI functionality classes, revised to version 3.0 in September 2024, evaluate physical true random number generators by stochastic model and are the closest existing fit, and they were written for classical noise sources. For TL-3, Table 1 does not specify a certification scheme or evaluation procedure for confirming the required "dual entropy sources with appropriate certification."
The third gap is evidence. The Annex C case study names no vendor and no product, the Bloom filter result stops at two weak Diehard tests, and the side-channel catalog cites laboratory literature rather than tests on fielded products. A reader who wants to know whether a specific generator is exposed to blinding or electromagnetic injection will not find a test procedure here. The conclusions are candid about this and call for security certification models beyond statistical testing, mandatory logging and attestation protocols, and integration guidelines for hybrid PQC and QRNG systems as the next priorities.
For a buyer the practical reading is narrower than the headline and more useful. The trust-level table gives a procurement office a common vocabulary: ask a vendor which level it claims, ask for the physical model and the online conditional min-entropy estimate, and ask what happens to the output stream when the monitor trips. The side-channel catalog is a checklist for an acceptance test a laboratory can run now, standard or no standard. The same discipline is what the Monitor's general blog asked of operational technology owners when NIST's draft SP 800-82 revision 4 reached post-quantum cryptography: inventory the component, name its assurance, and decide what evidence would change the decision. A proposed next public step that would move this profile from guidance to requirement is a Technical Specification with a test method for each trust level. Until such methods appear, a claimed quantum entropy source remains a claim, and the report is a usable list of the questions that turn it into evidence.
Sources
Primary source: ETSI Technical Committee Cyber Security, "ETSI TR 104 171 V1.1.1 (2026-03), Cyber Security (CYBER); Implementation Guidelines for Quantum Random Number Generators," published March 2026, announced by ETSI press release September 24, 2026. Other material: ETSI press release of September 24, 2026 quoting Mark Pecen; NIST SP 800-90B; BSI page on the AIS 20/31 functionality classes; Quantum Computing Report, September 26, 2026.