Source-linked AI summary
A self-testing quantum random number generator
Tommaso Lunghi, Jonatan Bohr Brask, Charles Ci Wen Lim, Quentin Lavigne, Joseph Bowles, Anthony Martin, Hugo Zbinden, Nicolas Brunner
TL;DR
The paper addresses how to estimate entropy from quantum-device outputs without relying on detailed device characterization. It develops a prepare-and-measure self-testing protocol based on a dimension witness and shows that randomness can remain certifiable under implementation imperfections and non-qubit events when their fraction is bounded.
Problem
Estimating the entropy of data generated by a quantum device remains a central challenge, especially when real-world sources may not always satisfy the qubit assumption.
Method
The protocol uses a dimension witness and min-entropy analysis to bound guessing probabilities and determine extractable randomness from observed statistics.
Results
The proof establishes a witness-based guessing-probability bound that remains valid with detector afterpulsing, and the analysis can bound extractable randomness when the fraction of non-qubit events is constrained.
Takeaways & Limitations
The protocol supports self-testing quantum randomness generation without requiring a detailed model of device functioning, within its stated assumptions and scope.
Abstract
from arXiv · showhide
The generation of random numbers is a task of paramount importance in modern science. A central problem for both classical and quantum randomness generation is to estimate the entropy of the data generated by a given device. Here we present a protocol for self-testing quantum random number generation, in which the user can monitor the entropy in real-time. Based on a few general assumptions, our protocol guarantees continuous generation of high quality randomness, without the need for a detailed characterization of the devices. Using a fully optical setup, we implement our protocol and illustrate its self-testing capacity. Our work thus provides a practical approach to quantum randomness generation in a scenario of trusted but error-prone devices.
SUPPLEMENTARY MATERIAL
The supplementary material supplies the protocol’s randomness proof and supporting analyses, including robustness, multi-photon treatment, finite-size effects, and output-data tests.
- The supplementary material provides a proof of randomness for the protocol and states its required assumptions.It also addresses detector afterpulsing, multi-photon events, finite-size effects, and statistical tests of the output.
Appendix A: Proof of randomness
The proof lower-bounds randomness in the observed output using a dimension witness while allowing independent internal randomness in the preparation and measurement devices.
- The proof uses a dimension witness to lower-bound the randomness of the observed output.The devices may contain internal randomness represented by λ and µ, and the goal is to bound the output guessing probability when these variables are known.
1. Setting and assumptions
The analysis assumes independent inputs, round-local output dependence, devices that do not record outputs, stable internal-variable distributions, and independent devices. Under these assumptions, entropy per output bit is bounded by the observed witness.
- Inputs are assumed independent of one another and of the devices.The output in each round is conditionally dependent only on that round’s inputs and current device states.
- The devices are assumed not to record previous outputs, preventing output dependence on earlier rounds.This is expressed as conditional independence of the current output from previous outputs and prior variables given the current inputs and device states.
- The internal random variables are assumed identically distributed throughout the experiment and independent between devices.With these assumptions, the observed witness bounds the guessing probability in the large-sample limit.
- The output-string entropy per bit is bounded under the stated assumptions.In implementation, the required stability means external parameters should vary slowly over the roughly one-minute witness-estimation interval; they need not remain unchanged between runs.
- The proof’s stability assumptions may be relaxed for some effects, because detector afterpulsing can violate an assumption while randomness remains certifiable.
2. Proof
The proof relates Bob’s measurement incompatibility witness to the maximum guessing probability, then converts the resulting bound into extractable min-entropy. The bound is tight at maximal witness value W = 1.
- 2. Proof: The proof defines the guessing probability over inputs and local randomness for the protocol’s four preparations and two measurements.Inputs are taken uniformly, so each preparation-measurement pair occurs with probability 1/8.
- 2. Proof: The best average guess is obtained from a state midway between Bob’s two measurement directions on the Bloch sphere.For measurement angle θµ, the outcome probabilities are cos^2(θµ/4) and sin^2(θµ/4).
- 2. Proof: The witness value bounds the measurement angle and therefore bounds the guessing probability.The derivation uses the relation between Wλ,µ and θµ, with maximally anti-commuting measurements giving Wλ,µ = 1.
- 2. Proof: The proof uses concavity and monotonic decrease of the bounding function f, together with convexity properties of the witness.These steps combine local-randomness-dependent bounds into a bound based on the observed witness W.
- 2. Proof: The resulting guessing-probability bound is tight when maximal witness violation is achieved, W = 1.The maximum number of extractable random bits is calculated separately from this bound.
Appendix B: Certifying randomness in the presence of afterpulsing
The protocol remains valid under afterpulsing: afterpulse events reduce the witness value in the same way as perfectly predictable non-quantum events, so randomness can still be certified.
- Afterpulsing reduces the witness value correspondingly, yet randomness can still be certified.The self-testing protocol captures the effect despite afterpulsing violating the i.i.d. assumption.
- The dataset can be decomposed into non-afterpulse events and additional afterpulsing events, with η denoting the fraction without afterpulsing.Uniform inputs make the number of afterpulses equal across input combinations.
- Afterpulse outcomes are uncorrelated with the current inputs because each outcome is inherited from the preceding event.This permits the afterpulsing contribution to be represented separately when computing observed frequencies.
- The witness is computed from conditional-frequency differences, so input-independent afterpulse contributions cancel from those differences.The observed witness therefore scales with the witness obtained from events without afterpulsing.
- Even perfectly predictable afterpulse outputs preserve the guessing-probability bound because afterpulsing reduces W exactly like added predictable events.Thus the protocol’s randomness guarantee applies despite the predictability of afterpulse events.
Appendix C: Accounting for multi-photon events
Multi-photon emissions challenge the protocol’s qubit assumption, but the witness violation associated with valid qubit events can still be bounded using observed data and a bound on non-qubit events.
- Real-world single-photon sources may emit more than one photon, violating the qubit assumption.This issue applies to spontaneous parametric down-conversion and weak coherent sources.
- The analysis seeks a lower bound on the witness violation from qubit-compatible events using the observed distribution and the fraction of non-qubit events.
- The fraction of non-qubit events can be estimated without a detailed source model, for example from photon-statistics information.
1. Bounding the violation for given qubit fraction
The analysis bounds the quantum violation achievable for a given fraction of qubit events, identifying when observed violations certify randomness and when the bound becomes trivial.
- The experiment is modeled as a mixture of qubit events satisfying the qubit assumption and unrestricted non-qubit events.The qubit fraction is α, with distributions pqa and p̄qa for the two event classes.
- The observed witness W is expressed in terms of α, the qubit contribution Wqa, the non-qubit contribution W̄qa, and cross terms.
- For fixed |Wqa|, maximizing the attainable W yields a bound whose inversion lower-bounds the qubit violation when the observed violation is below unity.
- For α > 1/2, the maximum bound can exceed 1, so a minimum qubit-event fraction is required for practical randomness certification.
- For each α, violations below a minimum observed threshold make the randomness bound trivial and prevent certification.
2. Estimating the qubit fraction
The qubit-event fraction is estimated from source behavior and post-selection, using conservative finite-sample bounds that hold with a specified confidence.
- Source and detector inefficiencies, transmission losses, and inconclusive events must be incorporated when estimating the fraction α of qubit events.
- The implementation discards inconclusive events under a fair-sampling assumption and treats events with at most one emitted photon as satisfying the qubit assumption.
- Before post-selection, the asymptotic qubit-event fraction is α = q, where q is the probability of emitting at most one photon.
- With probability at least 1 −ν, the finite-sample count satisfies Nα > qN −t.
- The margin t is determined from N and ν using a Chernoff-Hoeffding tail bound, with separate conservative treatment after post-selection.
Appendix D: Security Analysis
The security analysis connects observed statistics to extractable private randomness through conditional min-entropy and universal hashing, while accounting for finite-sample deviations and source imperfections.
- The leftover hash lemma converts a raw binary string Z into an output S that is close to uniform conditioned on inputs and classical side-information.
- The number of extractable bits is controlled by the conditional min-entropy Hmin(Z|XYL), equivalently by the guessing probability of Z given side-information.
- The output quality is tied directly to the number of extractable bits, which is bounded by fixing a security level and lower-bounding the min-entropy.
- The extraction rate ℓ/m converges to the min-entropy rate as m →∞ and the finite-size deviation Δ tends to zero.
- Chernoff-Hoeffding bounds relate observed frequencies to expected probabilities, enabling an estimate of the expected witness with controlled failure probability.
- The effective violation is defined by fixing the non-qubit contribution to zero and is used to quantify randomness in Z.
- The implementation chooses ε = 10^-3 for the output string's closeness to uniformity conditioned on XYL.
Appendix E: Output data analysis
The output analysis evaluates extracted bits with NIST statistical tests and a visual binary image, finding successful performed tests and no visible regular pattern.
- NIST tests assess the extracted output, with p-values between 0.01 and 0.99 required for success.
- Although the sample was too small for all tests, every performed NIST test was successful.
- A 500×500 black-and-white image displays 250000 extracted bits, where repeated structure would indicate correlations.
- The displayed bit image contains no apparent pattern.
Appendix F: Example of raw data
The appendix introduces an extract of the experiment’s raw data and directs the reader to Table I.
- The appendix presents an extract of the experiment’s raw data.
- The raw-data extract is provided in Table I.
- The passage serves as an introduction to the appendix’s raw-data presentation.