The German built device cleared a three month ISO standard check for side channel attacks (physical exploits that read hardware behavior such as timing, power draw, or electromagnetic emissions to leak key material) on the physical hardware that
Quantum Optics Jena says its ELVIS system is the first commercial quantum encryption device to clear an independent, ISO-standard audit of its physical hardware, passing a three-month check for the side-channel attacks that have kept real-world quantum cryptography from going mainstream.
Quantum key distribution, or QKD, generates shared encryption keys using quantum physics. The security is theoretically unbreakable, but the realistic attack surface is the physical hardware: lasers, single-photon detectors, modulators, and optical splitters that can be subtly manipulated to leak key material without triggering an alert. Until now, no standardized, independent way existed to test for those implementation flaws in commercial gear.
TÜV Informationstechnik (TÜVIT) ran the audit under ISO/IEC 23837, completing six targeted security assessments in three months. The assessor found no major vulnerabilities or exploitable side-channel weaknesses, per the company's announcement and parallel industry coverage.
The methodology was developed under QuNET+BlueCert, a German federal research initiative involving Fraunhofer institutes, and now sits behind the ISO/IEC 23837 test standard. That gives the QKD sector a reusable framework rather than ad hoc vendor claims.
Caveats hold: six test scenarios is a starting set, and one vendor under one assessor is not a sector-wide verdict. Theoretical security still has to be earned in deployed hardware, and ELVIS is the first device to clear that bar.