Standards & Validation

ETSI TR 104 171: QRNG Implementation Guidance Explained

What ETSI TR 104 171 V1.1.1 is, what it covers for QRNG implementers and users, and why it should be described as implementation guidance rather than certification.

QRNG.io · iQrypto4 min read
  • ETSI QRNG implementation guidance

Why this publication matters

QRNG discussions often borrow general RNG assurance concepts from NIST, BSI and cryptographic engineering practice. TR 104 171 is notable because it is focused specifically on quantum random number generators.

That makes it useful as a bridge between quantum-source claims and practical implementation concerns.

Intended audience

ETSI states that the report targets both implementers and users of QRNG devices.

That dual perspective is valuable. A developer needs guidance on architecture and assurance; an integrator needs to know what evidence to ask for and what properties matter in deployment.

Topics in scope

ETSI's work-item scope explicitly names:

  • entropy sources;
  • testing;
  • performance;
  • practical implementation aspects;
  • design trade-offs;
  • assurance of QRNG security.

QRNG.io should use the report to strengthen explanations of these concepts rather than quote it as a badge.

QRNG-specific implementation thinking

A QRNG has at least two interacting domains:

  1. the quantum physical process that is claimed to provide unpredictability;
  2. the classical system used to measure, process, monitor and deliver digital output.

The implementation challenge is to preserve a defensible connection between those domains.

This is why good QRNG engineering considers the source model, measurement chain, raw data, health monitoring, conditioning, interfaces and operating conditions as one assurance story.

Relationship to NIST SP 800-90B

ETSI TR 104 171 is QRNG-specific implementation guidance. NIST SP 800-90B is a broader entropy-source recommendation used in random-bit generation.

They should not be treated as interchangeable documents.

A useful engineering workflow is to use:

  • ETSI for QRNG-specific implementation perspective;
  • SP 800-90B for entropy-source assurance concepts;
  • SP 800-90C for complete RBG constructions;
  • other applicable assurance/certification frameworks for the target market.

Performance versus assurance

High bit rate is easy to market, but an RNG evaluation should separate:

  • raw sampling rate;
  • conservatively estimated entropy rate;
  • conditioned output rate;
  • interface throughput;
  • latency;
  • behavior under stress or degradation.

A high output number without the source and processing context says little about assurance.

What ETSI publication does not imply

The existence of the Technical Report does not mean:

  • a particular QRNG is ETSI-certified;
  • conformance to the report has been independently validated;
  • the product has NIST or BSI validation;
  • the use of quantum physics automatically establishes secure randomness.

Claims need their own evidence.

How QRNG.io should cite it

Use the work-program page as the stable source for publication status, title, scope, version and the fact that it is not a harmonised standard.

Link to the official PDF for readers who want the complete document.

Do not copy long passages. Summarize concepts and point readers to the primary source.

Why this helps QRNG.io authority

This page is valuable because it connects QRNG.io to a current QRNG-specific standards body publication rather than relying only on vendor explanations.

It also creates a natural bridge to the existing pages on QRNG trustworthiness, quantum-entropy approaches, statistical-testing limitations and the local entropy assessment kit.

Sources and further reading

  1. ETSI TR 104 171 work item
  2. ETSI TR 104 171 PDF
  3. NIST SP 800-90B
  4. NIST SP 800-90C

Primary sources

Part of the QRNG.io quantum randomness knowledge hub.

Keep learning

More on quantum randomness

QRNG.io is an educational hub. Browse the full library, or look up any term you met in this article in the glossary.