Quantum eMotion Submits Entropy Module for NIST Review
Quantum eMotion has submitted its eCore-Q PCIe Quantum Entropy Module to the U.S. National Institute of Standards and Technology (NIST) for review under the Cryptographic Module Validation Program. The Montreal-based company announced that Lightship Security completed an independent assessment and submitted the package via the Entropy Source Validation Test System on August 27. This submission marks the beginning of the review process.
Details of the submission
The company is seeking an Entropy Validation Certificate, which aligns with NIST SP 800-90B. This standard outlines the requirements for the amount of genuine randomness an entropy source must produce. If NIST issues the certificate, it will confirm the quality of randomness for that specific implementation, version, and operating environment. This certificate is the sole outcome of this particular step.
Quantum eMotion appropriately stated in its release that the submission itself doesn’t constitute validation, and the outcome or timeline of the CMVP review isn’t guaranteed. This perspective is crucial, as NIST review queues can be extensive, and often take many months for a certificate to be issued after a filing.
The entropy itself is generated by the company’s proprietary quantum random number generator (QRNG), which derives randomness from quantum processes. A QRNG provides randomness but doesn’t, on its own, protect data from future quantum computers. Such protection relies on post-quantum cryptographic algorithms, specifically those standardized by NIST as FIPS 203, 204, and 205, which are distinct from entropy quality.
Why these distinctions are important
It’s essential to differentiate between three concepts often conflated in QRNG marketing:
- SP 800-90B validation: This specifically concerns the quality of randomness.
- FIPS 140-3 module validation: This certifies a cryptographic module as a whole, not just the algorithms within it.
- Resistance to quantum attacks: Addressed by post-quantum algorithms.
Currently, there are no cryptographically relevant quantum computers. Therefore, the primary threat driving this market is “harvest-now-decrypt-later,” where malicious actors store encrypted data today with the intention of decrypting it once quantum computing capabilities advance.
Quantum eMotion presents this filing as a foundational step for a broader range of cryptographic products aimed at regulated sectors. CEO Francis Bellido emphasized the move’s importance for customer trust and market access:
“This submission marks an important technical milestone for Quantum eMotion.”
The certificate could support future FIPS 140-3 module submissions that utilize this entropy source, provided they adhere to integration rules. The company’s shares trade on the NYSE American and TSXV under the ticker QNC.