Source-linked AI summary

Quantum random number generation

Xiongfeng Ma, Xiao Yuan, Zhu Cao, Bing Qi, Zhen Zhang

arXiv:1510.08957v2quant-ph

TL;DR

True randomness cannot be established by statistical tests alone, motivating quantum processes as sources of randomness. The paper surveys QRNG approaches and reports implementation-independent certification, arbitrary amplification under ε < 0.058, and a demonstrated rate above 1 Gbps.

  • Problem

    Statistical tests cannot rule out predetermined outputs, so true randomness requires processes with inherent randomness.

  • Method

    The paper examines QRNG architectures using quantum-state entropy sources and device-independent witnessing to certify implementation-independent output randomness.

  • Results

    A demonstrated source-independent QRNG achieves a randomness generation rate over 1 Gbps, while randomness with ε < 0.058 can be amplified into arbitrarily free random bits.

  • Takeaways & Limitations

    Device-independent QRNGs can certify randomness independent of device implementations, although Bell-test-based generation speed is usually very low.

  • Takeaways & Limitations

    Theoretical security depends on model assumptions, and adversarially manipulated devices may produce outputs that are not genuinely random.

Abstract

from arXiv · show

Quantum physics can be exploited to generate true random numbers, which play important roles in many applications, especially in cryptography. Genuine randomness from the measurement of a quantum system reveals the inherent nature of quantumness --- coherence, an important feature that differentiates quantum mechanics from classical physics. The generation of genuine randomness is generally considered impossible with only classical means. Based on the degree of trustworthiness on devices, quantum random number generators (QRNGs) can be grouped into three categories. The first category, practical QRNG, is built on fully trusted and calibrated devices and typically can generate randomness at a high speed by properly modeling the devices. The second category is self-testing QRNG, where verifiable randomness can be generated without trusting the actual implementation. The third category, semi-self-testing QRNG, is an intermediate category which provides a tradeoff between the trustworthiness on the device and the random number generation speed.

1 Introduction

Quantum measurements provide inherent randomness for true random-number generation, whereas classical output testing cannot rule out predetermined sequences. QRNGs therefore span practical, self-testing, and semi-self-testing designs that trade device trust, security, speed, and cost.

  • Motivation: True randomness requires inherent randomness because a malicious generator can produce a predetermined sequence that passes statistical tests.Classical RNG outputs may appear random while retaining long-range correlations that undermine security or scientific and physics applications.
  • Quantum randomness: Quantum measurements can be intrinsically random under Born’s rule, enabling quantum systems to generate true random numbers.Measurement of a superposed quantum state produces outcomes that cannot be predicted better than blind guessing.
  • QRNG categories: Practical QRNGs use trusted, modeled devices to achieve high generation speed and relatively low cost, but their security depends on fulfilled model assumptions.Quantum effects are mixed with classical noise, which can be subtracted after properly modeling the quantum process.
  • QRNG categories: Self-testing QRNGs certify randomness device-independently through Bell-inequality violations, but demonstrating nonlocality makes their generation speed usually very low.Observed nonlocality provides a lower bound on genuine randomness even when classical noise is uncharacterized.
  • QRNG categories: Semi-self-testing QRNGs generate randomness without fully characterizing devices and trade practical QRNG performance and cost against self-testing security.One example uses a trusted readout system with an arbitrary untrusted randomness resource.

2 Trusted-device QRNG I: single-photon detector

Trusted-device QRNGs typically use photonic systems with an entropy source and detection system to generate quantum randomness. Because classical noise mixes with the quantum output, randomness extraction is applied to obtain genuine randomness.

  • Most practical QRNGs use photonic systems because high-quality optical components are available and chip-size integration is possible.
  • A typical QRNG combines an entropy source that generates defined quantum states with a corresponding detection system.
  • Quantum randomness in the output is generally mixed with classical noise, so the quantum component should be quantified and dominant.
  • Randomness extraction recovers genuine randomness from the mixture of quantum and classical noise.The extraction procedure is detailed in Methods.
  • Measuring a qubit in the state |+⟩= (|0⟩+ |1⟩)/ naturally generates random bits.

Qubit state · Temporal mode

Practical QRNGs encode randomness in measured qubit states or higher-dimensional photon modes. Temporal-mode QRNGs extract multiple bits from each detection by resolving randomly distributed photon arrival times, reducing detector-deadtime limitations.

  • Qubit state: Polarization-based QRNGs represent |0⟩ and |1⟩ as horizontal and vertical polarization, with |+⟩ denoting +45° polarization.
  • Qubit state: Path-based QRNGs represent |0⟩ and |1⟩ by photon propagation through paths R and T, respectively.
  • Qubit state: Qubit QRNGs generate at most one random bit per detected photon, so detector dead time and efficiency constrain the generation rate.
  • Qubit state: Typical silicon-SPD dead times of tens of ns limit qubit QRNG generation rates to tens of Mbps, below GHz-clock-rate QKD demands.
  • Temporal mode: Temporal QRNGs measure photon arrival times using a time-resolving SPD after controlling continuous-wave laser intensity to yield roughly one event within period T.
  • Temporal mode: Random detection times within T are digitized at resolution δt, producing about log2(T/δt) bits of raw randomness per detection.
  • Temporal mode: With 100 ps resolution and 100 ns dead time, temporal QRNGs reach around log2(1000)×10 Mbps versus 10 Mbps for the qubit scheme.
  • Temporal mode: More than one bit can be extracted per single-photon detection, alleviating dead-time effects when T is comparable to detector dead time.

Spatial mode … Vacuum noise

Trusted-device QRNGs generate randomness from spatial measurements, photon-number measurements, and macroscopic photodetector signals. Vacuum-noise schemes produce Gaussian randomness efficiently, but require shot-noise-limited detection and face bandwidth and technical-noise limitations.

  • Spatial mode: Spatial QRNGs measure photon position with space-resolving detectors, but their output depends on illumination and detector-array uniformity.They require multiple detectors, and pixel cross talk can introduce correlations between random bits.
  • Multiple photon number states: Photon-number-resolving detection of coherent laser pulses generates random numbers following a Poisson distribution.The approach has been experimentally demonstrated, including photon-number measurements using various detectors.
  • Multiple photon number states: Photon-number QRNG performance is sensitive to both the source photon-number distribution and detector efficiency.For coherent states, beam-splitter-modeled loss can be compensated with a relatively strong laser pulse.
  • 3 Trusted-device QRNG II: macroscopic photodetector: Macroscopic photodetectors provide another implementation route for trusted-device QRNGs, analogous to homodyne-based optical protocols.The discussion reviews two QRNG examples using macroscopic photodetectors.
  • Vacuum noise: A typical vacuum-noise QRNG sends a strong laser pulse through a symmetric beam splitter and measures the differential output with a balanced receiver.With a single-mode coherent local oscillator and shot-noise-limited detector, the output follows a Gaussian distribution.
  • Vacuum noise: 3.25 bits of random numbers are generated from each vacuum-quadrature measurement.The continuous-variable nature of the vacuum field allows more than one random bit per measurement.
  • Vacuum noise: Technical detector noise may be observed or controlled by an adversary, so secure extraction requires shot-noise-limited operation dominated by vacuum noise.Broadband shot-noise-limited homodyne detection above a few hundred MHz is technically challenging and may limit operating speed.

Amplified spontaneous emission

ASE-based QRNGs exploit quantum-mechanical phase or intensity noise, with phase-noise schemes offering robustness to detector noise and very high demonstrated sampling rates. However, reported generation speeds are not strictly real-time because randomness extraction remains a limiting step.

  • ASE-based QRNGs generate randomness by measuring the phase or intensity noise of amplified spontaneous emission, which is quantum mechanical by nature.
  • Phase-noise QRNGs measure a field quadrature of phase-randomized weak coherent states to generate random numbers.
  • When the average photon number n is large, phase-noise uncertainty can exceed vacuum noise, making the scheme more robust against detector noise.The uncertainty is of the order of n⟨(∆θ)2⟩ when the average phase is around π/2.
  • Phase stabilization enabled a ≥6 Gbps QRNG and a 68 Gbps QRNG demonstration, while pulsed lasers achieved an 80 Gbps raw rate.Pulsed-laser phase differences between adjacent pulses are automatically randomized.
  • These generation speeds are not strictly real-time because randomness extraction is speed-limited, motivating faster extraction schemes and hardware.The limitation is described as technical but practically important for matching fast random-bit generation.

4 Self-testing QRNG

Self-testing QRNGs certify output randomness independently of device implementations, addressing the security risks caused by device noise and model mismatch. Bell-inequality violations, under no-signalling, provide the central certification mechanism, though experimental loopholes and low rates remain challenges.

  • 4 Self-testing QRNG: Self-testing QRNGs certify output randomness independently of device implementations, unlike schemes whose security relies on device models.Device deviations from theoretical models can compromise randomness, whereas self-testing removes this dependence.
  • Self-testing randomness expansion: Under the no-signalling condition, Bell-inequality violations certify randomness because predetermined outputs from local hidden variables cannot produce such violations.A Bell inequality is defined as a linear combination of probabilities p(a, b|x, y) for outputs generated from random inputs.
  • Self-testing randomness expansion: Robust CHSH-based protocols improved noise tolerance enough to make experimental fully self-testing randomness expansion feasible.These protocols require faithful Bell-test realisations that exclude locality and efficiency loopholes.
  • Self-testing randomness expansion: The first experimental expansion against classical adversaries closed the efficiency loophole in an ion-trap system but not the locality loophole.Photonic systems are preferable for closing the locality loophole when quantum memories are unavailable.
  • Self-testing randomness expansion: Hmin = 7.2 × 10−5 in each run and 0.4 bits/s were obtained in an optical implementation with minimal CHSH violation.The settings can be designed to maximize CHSH violation, while imperfections may make optimizing over other Bell inequalities advantageous.
  • Self-testing randomness expansion: 2 bits of randomness can be certified with little involvement of nonlocality and entanglement, despite maximal CHSH violation generating 1.23 bits.Randomness generation does not require maximum nonlocal correlation or a maximally entangled state.

Randomness amplification

Randomness amplification generates arbitrarily free randomness from partially free randomness, a task impossible classically. Bell-based protocols can amplify weak sources under no-signaling, while fully self-testing tasks remain impossible without additional assumptions.

  • Definition and challenge: Randomness amplification generates arbitrarily free randomness from partially free randomness and is impossible using classical processes.An adversary may exploit input knowledge to fake Bell-inequality violations.
  • Protocols: For Santha-Vazirani weak sources with ǫ < 0.058, a two-party chained Bell inequality amplifies randomness into arbitrarily free random bits self-testing under no-signaling.This was the first randomness amplification protocol, proposed by Colbeck and Renner.
  • Protocols: A five-party Mermin inequality generates perfectly random bits from arbitrarily imperfect random bits under no-signaling.This result addressed whether free random bits can be obtained from arbitrary weak randomness.
  • Foundations: Randomness amplification is connected to the freewill assumption because Bell violations must arise from quantum effects rather than predetermined classical processes.The assumption requires inputs to be random enough to induce such violations.
  • Limitations: Fully self-testing tasks are impossible because faithful Bell-inequality violations require intrinsic randomness, while witnessing nonlocality requires additional true randomness.Security independent of the untrusted part can be achieved only by placing reasonable assumptions on the trusted part.

5 Semi-self-testing QRNGs

Semi-self-testing QRNGs provide an intermediate compromise between model-dependent trusted QRNGs and impractically slow self-testing schemes. They aim to combine reasonably fast generation with secure randomness while trusting only parts of the devices.

  • 5 Semi-self-testing QRNGs: Traditional model-based QRNGs pose security risks during fast random number generation.Their security depends on specific device models.
  • 5 Semi-self-testing QRNGs: Self-testing QRNGs provide information-theoretically secure randomness without characterising devices, but their processes are impractically slow.This motivates an intermediate approach between trusted and self-testing schemes.
  • 5 Semi-self-testing QRNGs: Semi-self-testing QRNGs seek a tradeoff that enables reasonably fast and secure random number generation.They occupy an intermediate position between trusted and self-testing QRNGs.
  • 5 Semi-self-testing QRNGs: Semi-self-testing QRNGs trust only parts of the devices, unlike trusted-device QRNGs that model both source and measurement devices.A QRNG includes a quantum-state source and a measurement device that outputs random bits; in semi-self-testing scenarios, one component may be characterised while the other is not.

Source-independent QRNG

Source-independent QRNGs treat the source as untrusted while trusting the measurement devices, monitoring the source through measurement choices and validation. They can generate randomness without a well-characterized source, but require careful device characterization and currently achieve rates above 1 Gbps.

  • Source-independent QRNG: The scheme treats the source as untrusted while relying on trusted measurement devices to monitor the source in real time.Measurement settings are randomly switched so an adversarial source cannot predict the measurement ahead.
  • Source-independent QRNG: A central challenge is that the source-independent protocol cannot assume either the emitted state |+⟩ or the dimension of ρx.This contrasts with protocols that rely on a known state and dimension.
  • Source-independent QRNG: Randomness is quantified by occasional X-basis projections and extracted after estimating classical noise from phase-error information.A squashing model can make the measured state equivalent to a qubit, but it strongly restricts the measurement devices.
  • Source-independent QRNG: Source-independent QRNGs generate randomness without a well-characterized source, but require known detector-efficiency bounds and carefully controlled input intensity.These controls prevent attacks exploiting detector-efficiency mismatch and detector vulnerabilities.
  • Source-independent QRNG: Over 1 Gbps, a continuous-variable source-independent QRNG has been experimentally demonstrated, with state-of-the-art devices potentially reaching tens of Gbps.The projected speed is similar to trusted-device QRNGs, bringing semi-self-testing QRNGs toward the practical regime.

Other semi-self-testing QRNGs … Min-entropy source

The paper describes semi-self-testing QRNGs that certify randomness under mild dimensional assumptions using varied inputs, measurements, and dimension witnesses. It then outlines practical and theoretical prospects for QRNGs and introduces min-entropy as a measure of randomness for binary sequences.

  • Other semi-self-testing QRNGs: Semi-self-testing QRNGs can achieve self-testing except under mild assumptions about the source and measurement devices.The devices may occupy independent two-dimensional quantum subspaces.
  • Other semi-self-testing QRNGs: These QRNGs use different input states and measurement settings, with randomness estimated through a dimension witness.A positive dimension-witness value could certify randomness in this scenario.
  • 6 Outlook: QRNG development spans highly efficient trusted-device systems and theoretically interesting self-testing protocols.This progression is motivated by demands for “perfect” random numbers in quantum communication and fundamental physics experiments.
  • 6 Outlook: The practical goal is fast, low-cost random-number generation while maintaining a high level of randomness.Waveguide fabrication may enable chip-size, high-performance QRNGs in the near future.
  • 6 Outlook: Accurate physical models and quantification of quantum and classical noise are needed to guarantee QRNG output randomness.Semi-self-testing protocols can make QRNGs more robust against classical noise and device imperfections.
  • 6 Outlook: Making self-testing QRNGs practical remains an open technological challenge, although single-photon detection may soon support practical readout.The entanglement source remains a significant practical limitation.
  • 6 Outlook: Self-testing QRNGs provide robust randomness and deepen understanding of fundamental physics, while their use in testing quantum physics remains debatable.The paper also raises whether randomness generation can go beyond QRNGs and use more general resources.
  • Min-entropy source: Given an underlying probability distribution, the randomness of a binary sequence X on {0, 1}^n can be quantified by its min-entropy.A random-number generator typically consists of an entropy source and a second component.

Randomness extractor

Randomness extractors convert imperfect QRNG entropy-source outputs into nearly perfect random numbers, with min-entropy quantifying the source and determining extractor input. Trevisan’s and Toeplitz-hashing extractors provide practical constructions, but extractor speed remains a major limitation relative to QRNG generation.

  • Extractor role: A QRNG combines a fundamentally unpredictable physical entropy source with an algorithmic randomness extractor that produces nearly perfect random numbers from imperfect output.The source and extractor are connected by quantifying randomness with min-entropy.
  • Extractor role: Min-entropy is first estimated for the entropy source and then supplied to the randomness extractor as an input parameter.
  • Extractor role: Photon-number detection produces non-uniform raw bits from Poisson-distributed coherent-state photon numbers, requiring postprocessing to obtain perfectly random numbers.Although at most log2(N) raw random bits can be generated per detection event, the non-uniform distribution prevents obtaining that many random bits directly.
  • Extractor role: Coherent-detection QRNG outputs contain detector noise, system imperfections, and adjacent-sample correlations, which appropriate extraction can eliminate once quantified.
  • Extractor implementations: Trevisan’s and Toeplitz-hashing extractors are commonly used, with Trevisan’s secure against quantum adversaries and Toeplitz hashing reaching O(n log n) runtime via fast Fourier transformation.Both are strong extractors, and Trevisan’s seed length is a polylogarithmic function of the input.
  • Extractor implementations: 68 Gbps QRNG generation exceeds the speed of implemented extractors, making extractor speed the main limitation of practical QRNGs.
Loading 1510.08957v2…