JP
Jordi Prieto Gallego
— On the schedule —
Building Cryptography on Locally Verified Entropy
Modern cryptography is only as trustworthy as the entropy it is built upon. Algorithms, protocols and cryptographic modules receive extensive scrutiny, yet the assumptions made about their underlying entropy sources are often inherited rather than examined; asserted once at integration time and rarely revisited. This session makes the case for a stricter target: locally verified entropy, meaning entropy whose origin, operating state and security claim remain verifiable at the point where it is generated, instead of being assumed further up the stack. Anything less leaves cryptographic mechanisms operating correctly on a foundation nobody has actually checked. Getting there means confronting why entropy has become a first-class assurance problem. Output that looks random is not the same as defensible entropy, and statistical testing alone cannot establish an entropy claim. What can is an unbroken assurance chain: the physical noise process, its implementation, the stochastic model that describes it, conservative min-entropy estimation, conditioning, operating conditions and continuous health monitoring. Local verification is what keeps that chain intact where it matters most; at the source. The talk follows this chain through the frameworks that govern it, examining how AIS 20/31, NIST SP 800-90B and CCN-MEGA each build confidence that genuine unpredictability is being generated, where they converge, and where their assurance boundaries diverge. Attendees will leave with a practical framework for reading entropy claims, understanding current certification requirements, and reasoning about locally verified entropy as the base layer of high-assurance cryptographic architectures.
— Compositor's note —
Jordi Prieto Gallego works as Security Architect at Quside, focusing on the architecture of cryptographic modules and entropy sources, leading certification processes, and integrating security and compliance requirements into product design. Before joining Quside, he worked as a cryptographic evaluator specializing in entropy sources and post-quantum cryptography. He led the laboratory’s RNG evaluation efforts and worked on multiple projects under standards and methodologies including the NIST SP 800-90 series and BSI AIS 20/31, while contributing to the development of the Spanish CCN-MEGA methodology. He also evaluated cryptographic modules under FIPS 140-3 and CCN-MEMeC.