Quantum commercialisation: The importance of standards in fostering growth
The UK’s National Quantum Strategy, published in March 2023, commits £2.5 billion to developing quantum technologies in the UK over the next 10 years – part of the government’s commitment to transforming the UK into a quantum-enabled economy by 2033. The strategy sets out the key activities necessary to drive the commercialisation of quantum technologies. One of which is to engage in standards development in collaboration with leading international bodies. Another example is the commissioning of a report by the Regulatory Horizons Council (RHC) earlier this year, which advocates for a pro-innovation approach to regulating quantum technology.
Standards and certifications play an important role in the journey towards commercialisation byin guiding emerging technologies from conception to widespread adoption. They help set consistency, build trust, accelerate product development, and reduce obstacles to commercialisation. But for them to fulfil this role effectively, everyone in the industry needs to understand them clearly. In this article, we will explain one example of international standards that apply to a quantum-enabled technology: the certification of Quantum Random Number Generators (QRNGs).
Why is the certification of QRNGs important?
The security of a system relies on preventing attackers from obtaining keys, therefore it is crucial not only to keep keys secret but also to avoid choosing them in a predictable way. Instances like the failure of Linux.Encoder.1, the first Linux ransomware, underscore the dangers of neglecting this. Its downfall resulted from a non-random key selection, derived from easily retrievable information such as the system timestamp, and allowed the key to be compromised without requiring decryption. This is why it is essential to use high-quality entropy for key generation. By doing so, we strengthen entire cryptographic systems against potential weaknesses and safeguard them from malicious attacks.
Since the generation of high-quality randomness is central to cryptography, having a process for verifying the quality of an entropy source means organisations can be assured they are using the highest quality and most reliable source of entropy available. Reliable assessment of the quality of randomness can only be done with considerable expertise and detailed examination of the process that generates it.
What international standards apply to QRNGs?
The Federal Information Processing Standard (FIPS) 140, issued by the National Institute of Standards and Technology (NIST) in the US, is regarded as the de facto standard for the testing of products that carry out encryption and decryption. In 2022, the National Physical Laboratory (NPL) in the UK signed a memorandum of understanding (MOU) with NIST, as a commitment to work together more closely in the quantum field – including in the development of standards.
The certification scope of FIPS 140 was amended in its latest version, FIPS 140-3, which supersedes FIPS 140-2 and changed the process for the certification of QRNGs. In FIPS 140-2, testing and validation were carried out on the entire cryptographic module, including an entropy source. FIPS 140-3 acknowledges that entropy generation differs from other functions used in cryptography by splitting this element out into a separate approval called Entropy Source Validation (ESV).
FIPS 140-3 is now divided into three distinct elements:
-
The Cryptographic Module Verification Program (CMVP)
-
The Cryptographic Algorithm Validation Program (CAVP)
-
Entropy Source Validation (ESV)
What are the advantages of the ESV certification for QRNGs?
-
It eliminates the need to repeat entropy testing: An entropy source now only needs to be approved once and is issued its own certificate meaning it can be used with multiple products.
-
It enables a more thorough assessment of entropy sources: Separate approval ensures that entropy sources meet stringent criteria for randomness, without being constrained by the requirements of an entire cryptographic module's certification.
-
It streamlines the certification process: The ESV certificate facilitates customers’ certifications through the NIST’s Cryptographic Module Validation Program (CMVP).
Quantum Dice maintains an active commitment to meeting international standard requirements and has started the process of ESV certification for its DISCTM QRNGs. Get in touch to find out more.
To learn more about FIPS 140-3 and ESV, visit the NIST website.
View all campaign week content
techUK – Unleashing UK Tech and Innovation
The UK is home to emerging technologies that have the power to revolutionise entire industries. From quantum to semiconductors; from gaming to the New Space Economy, they all have the unique opportunity to help prepare for what comes next.
techUK members lead the development of these technologies. Together we are working with Government and other stakeholders to address tech innovation priorities and build an innovation ecosystem that will benefit people, society, economy and the planet - and unleash the UK as a global leader in tech and innovation.
For more information, or to get in touch, please visit our Innovation Hub and click ‘contact us’.
Tech and Innovation Summit, 6 Nov (rescheduled date)
Emerging technologies will be debated and explored at our annual Tech and Innovation Summit, taking place on 6 November. This campaign week will directly feed into the themes discussed at the Summit.
techUK’s flagship Tech and Innovation Summit returns to traverse the extraordinary and ground-breaking discoveries made possible by the application of emerging and transformative technologies.
Upcoming events:
Latest news and insights:
Get our tech and innovation insights straight to your inbox
Sign-up to get the latest updates and opportunities from our Technology and Innovation and AI programmes.
Learn more about our Unleashing Innovation campaign:
Sprint Campaigns
This campaign explored how the UK can lead on the development, application and commercialisation of space technologies and ultimately realise the benefits of the New Space Economy.
These technologies include AI, quantum, lasers, robotics & automation, advanced propulsion and materials, and semiconductors.
Activity has taken the form of roundtables, panel discussions, networking sessions, Summits, thought leadership pieces, policy recommendations, and a report.
Get in touch below to find out more about techUK's ongoing work in this area.
Event round-ups
Report
Insights
Get in touch
This campaign has explored how the UK can lead on the development, application and commercialisation of the technologies set to underpin the Gaming & Esports sector of the future.
These include AI, augmented / virtual / mixed / extended reality, haptics, cloud & edge computing, semiconductors, and advanced connectivity (5/6G).
Activity has taken the form of roundtables, panel discussions, networking sessions, Summits, and thought leadership pieces. A report featuring member case studies and policy recommendations is currently being produced (to be launched in September 2024).
Get in touch below to find out more about contributing to or collaborating on this campaign.
Event round-ups
Insights
Get in touch
Running from July to December 2024, this campaign will explore how the UK can lead on the development, application and commercialisation of web3 and immersive technologies.
These include blockchain, smart contracts, digital assets, augmented / virtual / mixed / extended reality, spatial computing, haptics and holograms.
Activity will take the form of roundtables, workshops, panel discussions, networking sessions, tech demos, Summits, thought leadership pieces, policy recommendations, and reports.
Get in touch below to find out more about contributing to or collaborating on this campaign.
Upcoming events
Get in touch
Campaign Weeks
Our annual Campaign Weeks enable techUK members to explore how the UK can lead on the development and application of emerging and transformative technologies.
Members do this by contributing blogs or vlogs, speaking at events, and highlighting examples of best practice within the UK's tech sector.
Summits
Tech and Innovation Summit 2023