Digital trust also needs infrastructure

More and more critical processes depend on digital systems: payments, electronic signatures, communications, infrastructure, cloud services or connected devices. To protect them we use cryptography, but behind many of these operations there is a fundamental element that is much less talked about: randomness. Cryptographic keys, certificates, tokens or many authentication mechanisms need unpredictable numbers to be secure. That unpredictability is what, in this context, we call entropy.

For years, much of the industry has focused on one question: how to best generate randomness. But there is a second, equally important question: how do we know that randomness is still good once the system is deployed and working? A source may have been properly designed, validated and integrated and yet operate for years under changing conditions. Temperature, aging of components, hardware errors, incorrect configurations or interference can affect its behavior.

This is one of the problems Quside is working on, and also a way of understanding a broader challenge: digital trust should not depend solely on guarantees established at the time of design or validation, but on an infrastructure capable of offering evidence of its real functioning. The company develops quantum random number generation technology, but its proposal goes beyond supplying a component: it seeks to convert trusted physical capabilities into services that can be integrated, observed and verified within the systems they protect.

Quside workers in the laboratory. Image courtesy of Quside / Photo: Raquel Puras

From a security component to a trusted infrastructure

Cryptography is usually presented as a software layer, but its guarantees also depend on physical elements. Entropy generation is one of them. Knowing that a generator is on and producing data is not necessarily the same as knowing that it is producing good randomness.

This is where entropy monitoring comes into play. Its objective is to provide continuous visibility on the behavior of the randomness source, allowing us to check whether it continues to operate within the expected parameters and detect deviations that could affect security. The idea is similar to what already happens in other layers of the technological infrastructure: we monitor networks, servers, energy consumption, latency or temperature because we do not assume that everything will continue to function correctly indefinitely. Entropy should be treated with the same level of observability.

Furthermore, not all bits that appear random necessarily contain the same amount of unpredictability. Therefore, monitoring is not only about checking that a device continues to generate data, but about estimating the real quality of that randomness. In simple terms, it is about continually answering an essential question: how much real unpredictability is the source producing at the moment? This information allows us to detect degradations, anomalies or changes in behavior that could go unnoticed if only the final output of the generator were observed.

Digital trust should not depend only on guarantees established at the time of design, but on an infrastructure capable of offering evidence of its actual functioning

LOVE: trust that can be observed and verified

This need to move from trusting entropy to being able to observe and verify it is the starting point of LOVE, Locally Verified Entropy, the approach developed by Quside around three principles: local generation, observability and entropy verification. The proposal is simple to understand: entropy must be generated close to the system that uses it, it must be observable while it is operating, and it must provide evidence that it maintains the expected quality.

Verifying locally also adds a layer of control that is especially relevant in distributed infrastructures. Data centers, telecommunications networks, financial systems, critical infrastructures or cloud platforms generate and consume large amounts of cryptographic material. The more complex and distributed the environment, the more important it is to be able to verify what is happening at the point where the randomness is generated, without depending solely on a validation carried out at another time or in another place.

Quantum technology offers a particularly interesting advantage because it allows the generation of randomness from intrinsically unpredictable physical processes. But even in this case, the quantum origin does not eliminate the need for monitoring. The question is not only where the randomness comes from, but whether we can demonstrate that the device continues to behave as we expect once integrated into a real infrastructure.

Evolution is not just about generating more randomness; Trust must be turned into a capability that can be integrated, observed and verified.

Trust as an infrastructure capacity

This issue is gaining weight as organizations review their security architectures, adopt new cryptographic technologies, and prepare for scenarios such as the transition to post-quantum cryptography. In all of them, the quality of entropy will continue to be a fundamental piece. But the challenge doesn’t end there: organizations need trusted capabilities to be able to be deployed, managed and verified consistently across increasingly complex systems.

Quside’s vision is to move towards a trusted infrastructure that connects hardware to the needs of modern cryptography. An infrastructure in which entropy generation, observability and other cryptographic capabilities are not isolated elements, but rather part of a physical foundation on which more secure and verifiable digital services can be built.

Evolution, therefore, is not just about generating more randomness, but about turning trust into a capability that can be integrated, observed and verified. Because digital security depends not only on cryptography being strong, but also on whether we can trust the foundations on which it works.

Trust should not be an assumption. It should be a property of the infrastructure.

quside.com