Source-linked AI summary

Certified randomness in quantum physics

Antonio Acín, Lluis Masanes

arXiv:1708.00265v1quant-ph

TL;DR

The paper reviews how to certify quantum randomness when standard generators depend on difficult-to-verify device assumptions and cannot establish privacy. It surveys device-independent protocols based on general assumptions and Bell-inequality violations, their implementations, alternative methods, and fundamental implications. These approaches certify randomness without modeling device interiors, but experimental certification remains constrained by loopholes and demanding arrangements.

  • Problem

    Standard randomness certification relies on device assumptions, while statistical tests cannot establish uniformity and privacy against adversaries such as memory-stick providers.

  • Method

    The review synthesizes device-independent protocols that use Bell-test correlations and other certification approaches based on general physical assumptions rather than detailed device models.

  • Results

    Bell-inequality violations certify randomness without assumptions about devices’ inner workings, while semi-device-independent methods reduce experimental requirements by imposing a dimension bound.

  • Takeaways & Limitations

    Certified randomness connects practical quantum random-number generation with fundamental questions about nonlocality, randomness amplification, and the existence of random events.

  • Takeaways & Limitations

    Device-independent implementations face detection, locality, collapse-locality, and free-will loopholes, with some requiring physically motivated assumptions or demanding experimental arrangements.

Abstract

from arXiv · show

The concept of randomness plays an important role in many disciplines. On one hand, the question of whether random processes exist is fundamental for our understanding of nature. On the other hand, randomness is a resource for cryptography, algorithms and simulations. Standard methods for generating randomness rely on assumptions on the devices that are difficult to meet in practice. However, quantum technologies allow for new methods for generating certified randomness. These methods are known as device-independent because do not rely on any modeling of the devices. Here we review the efforts and challenges to design device-independent randomness generators.

1 Introduction

The paper frames certified randomness as a fundamental and practical challenge because statistical tests and device assumptions cannot establish unpredictability and privacy against arbitrary observers. It introduces device-independent quantum random-number generators as a solution based on general physical assumptions rather than detailed device models.

  • 1 Introduction: Good randomness requires outputs that are unpredictable to the user and to any observer.The ideal output is uniformly distributed and uncorrelated with the environment.
  • 1 Introduction: Randomness generation cannot avoid assumptions, because a super-deterministic model could explain every event as predetermined.The appropriateness of assumptions depends strongly on the application.
  • 1 Introduction: Statistical tests cannot certify randomness with finite computational power and do not certify privacy against an adversary.A memory-stick attack can produce statistically convincing outputs that the adversary predicts perfectly.
  • 1 Introduction: Conventional QRNGs rely on assumptions about device behavior, purity, imperfections, and memory effects that may undermine output quality or privacy.A beam-splitter QRNG is an idealized model whose experimental implementation may contain uncontrolled imperfections and correlations.
  • 1 Introduction: Device-independent QRNGs certify randomness using general setup assumptions, such as quantum physics, without modeling the devices’ internal workings.The review covers Bell-inequality-based certification, protocol development, experiments, and approaches with milder experimental requirements.

2 Device-independent randomness generation

Device-independent quantum random-number generators certify randomness from Bell-violating correlations without modeling the devices’ internal workings. The certification relies on observed statistics, while requiring physical conditions such as independent inputs and no communication between devices.

  • Bell-based certification: Bell-violating correlations between separated entangled devices provide the basis for device-independent randomness certification.The user collects inputs and outputs, estimates P(a, b|x, y), and evaluates a Bell inequality.
  • Bell-based certification: Observed Bell violation witnesses non-classical correlations and certifies properties of the unknown quantum state, including entanglement and purity.Purity limits correlations with the environment, while entanglement makes local measurement outcomes random.
  • CHSH example: Maximal CHSH violation is possible only with projective measurements on a maximally entangled two-qubit state.Because this state is pure, measurements on half of it produce perfect random bits certified by the Bell violation.
  • CHSH example: For noisy, non-maximal CHSH violations, the observed violation can still quantify the amount of generated randomness.The paper illustrates this relationship in Figure 3.
  • Operational requirements: Bell-based randomness can be certified under the weaker assumption of no-signalling rather than the validity of quantum theory.Quantum technology is nevertheless used to generate the Bell-violating correlations discussed here.
  • Operational requirements: Device-independent certification requires independent inputs and no communication between the separated devices during each round.These conditions are physical assumptions about the setup rather than models of the devices’ internal workings.

3 Protocols

DIQRNG protocols collect multi-device input-output data, estimate non-locality, and extract a final random string when the observed non-locality is sufficient. Their design balances expansion, seed quality, robustness, device count, composability, and physical assumptions.

  • Protocol structure: A general DIQRNG protocol uses n ≥2 devices, independently selected inputs, entangled states, local measurements, and stored input-output data over Nr rounds.The collected data are used for subsequent non-locality estimation and randomness extraction.
  • Protocol structure: The protocol estimates non-locality from empirical input-output frequencies and determines the final string length Nk; insufficient non-locality causes abortion with Nk = 0.Greater observed non-locality yields a longer final random string.
  • Protocol structure: Classical post-processing combines raw data with part of the seed, often using a randomness extractor to produce the final Nk-bit string.This stage follows data collection and non-locality estimation.
  • Design parameters: Protocol efficiency is the trade-off between generated randomness and consumed resources, including seed bits Ns and device uses Nr.Other design parameters include seed quality, robustness, device count, composability, and physical assumptions.
  • Design parameters: Robust protocols tolerate noise and imperfections, producing Nk > 0 for violations above a threshold that need not equal the local bound.Composability requires that learning some final bits reveals essentially no additional information.
  • Design parameters: Security may assume quantum mechanics or only no-signalling, although quantum technology remains necessary to generate Bell-violating correlations.Protocols can also address imperfect or publicly available seeds.
  • Expansion and amplification: Randomness expansion protocols can generate an unbounded amount of randomness from a finite seed.Randomness amplification protocols instead study arbitrarily good output from imperfect sources, including Santha-Vazirani and min-entropy sources.
  • Expansion and amplification: Expansion and amplification are aspects of generating device-independent private randomness with minimal assumptions and resources.Bell-certified randomness also supports device-independent quantum key distribution, whose goal is secret-key establishment between distant users.

4 Implementations

DIQRNG implementations require Bell-inequality violations under demanding experimental conditions, with separate-particle and entangled-photon setups offering different routes and challenges.

  • Bell-test requirements: Bell-violation implementations distribute entangled states among devices performing local measurements, with observed statistics constrained by experimental conditions C1 and C2.
  • Experimental loopholes: Approximately ≳70% detection efficiency is required to close the detection loophole and prevent deterministic EPR descriptions from blocking randomness certification.
  • Experimental loopholes: Locality, collapse-locality, and free-will loopholes challenge the validity of the protocol’s statistical model and can only be made plausible through physical assumptions.
  • Experimental loopholes: Closing locality and timing loopholes requires precise control of measurement separation and of when inputs and outputs are generated.
  • Experimental platforms: Two principal platforms are distant entangled particles and entangled photons, with demonstrations reporting 42 random bits after approximately one month and 0.4 bits/s, respectively.

5 Other methods for randomness generation

Alternative certified-randomness proposals retain device-independent principles while adding limited assumptions, including dimensional constraints or trusted devices.

  • Semi-device-independent methods: Semi-device-independent protocols constrain the Hilbert-space dimension to at most d and certify randomness through dimension-witness violations.
  • Semi-device-independent methods: Dimensional protocols avoid entanglement and can require lower detection efficiencies, although the efficiencies remain demanding.
  • Semi-device-independent methods: Assuming uncorrelated preparation and measurement devices without memory effects can certify randomness for any detection efficiency.
  • Asymmetric methods: Asymmetric steering scenarios fully trust some devices, and steering detection provides quantum certification sufficient to guarantee randomness.
  • Asymmetric methods: Steering-based approaches still face detection-efficiency challenges, while general security proofs require a very low noise level.

6 Fundamental questions on randomness

Randomness and non-locality illuminate both quantum-technology applications and foundational questions, while showing that certification depends subtly on entanglement and measurement design.

  • Randomness amplification: Under only no-signalling, Bell-inequality violations certify random outputs but require some initial randomness, so full amplification only partially breaks the circularity.
  • Foundational significance: Bell-inequality violation rules out completing quantum predictions with a deterministic theory that preserves no-signalling.
  • Certification mechanisms: States with arbitrarily small entanglement and non-locality can allow maximal randomness certification.
  • Certification mechanisms: Non-projective measurements and measurement sequences can provide further advantages for randomness certification.

7 Outlook

DIQRNG has established a new paradigm but still requires theoretical and experimental advances toward more robust, secure, and feasible protocols.

  • Theoretical outlook: Existing DIQRNG security proofs validate the approach, while further theory is needed to relax the requirements for randomness generation.
  • Theoretical outlook: The proposed ultimate goal is composable security with infinite randomness expansion, arbitrarily weak public randomness, two devices, and only no-signalling assumptions.
  • Experimental outlook: Future implementations are expected to improve generation rates and explore integrated photonic circuits and solid-state platforms.
  • Experimental outlook: Open implementation questions include required detection efficiencies, noise robustness, and handling detection inefficiencies and cross-talk.
  • Overall outlook: Theory and implementation are increasingly combined to design more robust and feasible randomness-generation schemes.
Loading 1708.00265v1…