Source-linked AI summary

Device independent quantum random number generation

Yang Liu, Qi Zhao, Ming-Han Li, Jian-Yu Guan, Yanbao Zhang, Bing Bai, Weijun Zhang, Wen-Zhao Liu, Cheng Wu, Xiao Yuan, Hao Li, W. J. Munro, Zhen Wang, Lixing You, Jun Zhang, Xiongfeng Ma, Jingyun Fan, Qiang Zhang, Jian-Wei Pan

arXiv:1807.09611v2quant-ph

TL;DR

Device-independent quantum random-number generation seeks genuine unpredictable randomness without device assumptions, but experiments face demanding security and loophole-closure challenges. This paper builds a loophole-free Bell-test platform and uses large-scale Toeplitz hashing, generating 6.2469×10^7 quantum-certified random bits at 181.20 bits/s with uniformity within 10−5.

  • Problem

    DIQRNG seeks genuine unpredictable randomness without device assumptions, while experimental studies face formidable technical challenges and vulnerability to adversaries.

  • Method

    The experiment combines loophole-free Bell-inequality violation with continuous data recording and Toeplitz-matrix hashing for security against general quantum adversaries.

  • Results

    6.2469×10^7 quantum-certified random bits are generated at 181.20 bits/s, with uniformity within 10−5.

  • Takeaways & Limitations

    The demonstrated platform provides a fully functional DIQRNG with output passing the NIST statistical test suite.

Abstract

from arXiv · show

Randomness is critical for many information processing applications, including numerical modeling and cryptography. Device-independent quantum random number generation (DIQRNG) based on the loophole free violation of Bell inequality produces unpredictable genuine randomness without any device assumption and is therefore an ultimate goal in the field of quantum information science. However, due to formidable technical challenges, there were very few reported experimental studies of DIQRNG, which were vulnerable to the adversaries. Here we present a fully functional DIQRNG against the most general quantum adversaries. We construct a robust experimental platform that realizes Bell inequality violation with entangled photons with detection and locality loopholes closed simultaneously. This platform enables a continuous recording of a large volume of data sufficient for security analysis against the general quantum side information and without assuming independent and identical distribution. Lastly, by developing a large Toeplitz matrix (137.90 Gb $\times$ 62.469 Mb) hashing technique, we demonstrate that this DIQRNG generates $6.2469\times 10^7$ quantum-certified random bits in 96 hours (or 181 bits/s) with uniformity within $10^{-5}$. We anticipate this DIQRNG may have profound impact on the research of quantum randomness and information-secured applications.

SUPPLEMENTAL MATERIAL

The protocol generates device-independent randomness from loophole-free Bell-inequality violation and extracts a string designed to be close to uniform, including against quantum side information.

  • Device-independent randomness generation is based on a loophole-free Bell-inequality violation.
  • Security is formulated relative to the input randomness and an adversary’s system, while completeness requires that an honest device rarely aborts.
  • The protocol records outputs and inputs across repeated trials, using test trials to assess adversarial behavior and generation trials for randomness.
  • The protocol aborts when the Bell-test condition is not satisfied; otherwise, randomness is estimated and extracted from the output string.
  • Toeplitz-matrix hashing extracts a string close to uniform with a specified failure probability and soundness error.

B. Estimation of randomness production

The section extends randomness estimation from simplified collective or i.i.d. analyses toward coherent attacks using entropy accumulation, while highlighting finite-data costs and unresolved directions.

  • The entropy accumulation theorem reduces the complex multi-trial protocol to an i.i.d.-like analysis for coherent attacks.
  • Randomness is bounded through conditional min-entropy given the Bell-violation value and the adversary’s side information.
  • Finite data require sufficiently large trial counts, creating experimental difficulties and making improved generation rates important.
  • A numerical approach reduces a high-dimensional state to a two-qubit Bell-diagonal state to estimate randomness in the collective-attack case.
  • The rigorous proof of this reduction is deferred to future work, and full-statistics methods and quantum-side-information extensions remain open directions in the cited discussion.

C. Biased random input

For nonuniform inputs, the protocol modifies Bell-test spot-checking by introducing additional random variables that separate test and generation behavior across trials.

  • The analysis considers input bits whose values occur with probabilities (p, 1−p), with p < 1/2.
  • Because the earlier analysis assumes uniformly distributed test inputs, the Bell test is modified into a spot-checking protocol.
  • Additional random variables T A and T B determine whether trials contribute to testing or generation under the biased-input distribution.
  • The modified procedure repeats the two-step process for n trials and records a payoff on test trials while setting J_i = 0 otherwise.

4. We abort the protocol when P

The section describes input assumptions and the QRNG hardware used to convert laser phase fluctuations and quantum noise into processed random numbers.

  • The modification can handle known nonuniform input distributions, but the analysis assumes i.i.d. input randomness not controlled by Eve’s system.
  • The protocol focuses on perfect input randomness and leaves imperfect-source analysis for future work; input imperfections can alter the Bell-test classical bound.
  • The system uses a 1550 nm laser, an unbalanced interferometer, photodetection, ADC digitization, and FPGA processing to generate random numbers from quantum fluctuations.
  • The QRNG module contains separate stabilization and acquisition/post-processing electronics, including PID feedback and real-time Toeplitz hashing.
  • The ADC samples at 1 GSa/s and converts each sample to 8 bits before FPGA processing and synchronized output.

B. Min-entropy analysis and real-time post-processing

The section quantifies raw-data randomness with min-entropy and implements Toeplitz hashing in FPGA for real-time extraction and delayed output.

  • Min-entropy evaluation: Min-entropy quantifies the randomness of the raw data, and the raw distribution is evaluated using a Gaussian model.The quantum signal is treated as Gaussian, allowing its distribution to be accessed from phase-fluctuation variance.
  • Min-entropy evaluation: Above 6.4 bits per sample, or 0.8 bits per bit, is obtained for the min-entropy.
  • Real-time post-processing: Toeplitz hashing is implemented in FPGA by selecting one bit from each 8-bit ADC output and calculating running parities.
  • Real-time post-processing: 16-bit seeds construct the complete Toeplitz matrix and are refreshed after every synchronizing clock cycle.
  • Real-time post-processing: 16 raw bits are multiplied into a temporary column vector and extracted to a single random bit, with post-processing taking less than 68 ns.
  • Real-time post-processing: The extracted bits are delayed by 270 ns for Alice and 230 ns for Bob before being sent to the Pockels-cell drivers.

C. Preparation of optical modes for pump and collection

The experiment prepares pump and collection modes with specified optical focusing and coupling parameters, then characterizes transmission and heralding efficiencies.

  • Mode preparation: A 1-cm PPKTP crystal is pumped with a 180 µm waist and collected with an 85 µm waist to couple downconversion photons into single-mode fiber.
  • Pump mode: The pump originates from a 780HP single-mode fiber and is focused into the PPKTP crystal 70 cm away using an f=8 mm aspherical lens.
  • Collection mode: An aspherical lens with f=11 mm and a spherical lens with f=175 mm set the beam diameter to 85 µm at the crystal center.
  • Efficiency characterization: Heralding efficiency is defined from coincidence counts C and single counts NA and NB as ηA = C/NB and ηB = C/NA.
  • Efficiency characterization: The source optical-element efficiency is ηso = 95.9%, while fiber, measurement-station, and detector transmissions are separately characterized.
  • Efficiency characterization: The single-photon heralding efficiencies are ηA = (78.8 ± 1.9)% for Alice and ηB = (78.5 ± 1.5)% for Bob.

E. Quantum state characterization

The experiment characterizes a non-maximally entangled state and verifies the timing and geometry needed for space-like separation in the Bell-test setup.

  • Quantum state characterization: The experiment prepares a non-maximally entangled two-photon state and selects polarization-analysis bases for Alice and Bob.
  • Quantum state characterization: 99.5% and 98.5% visibility are measured in the horizontal/vertical and diagonal/anti-diagonal bases, respectively, at µ = 0.0035.
  • Quantum state characterization: 99.02% state fidelity is measured by tomography, with imperfections attributed to multi-photon components, optical elements, and mode matching.
  • Locality and space-like separation: Alice’s and Bob’s quantum-random-number-generation events lie outside the future light cone in the space-time diagram.
  • Timing and distance calibration: Fiber reflections measure source-to-detector distances, while trigger-to-detection intervals determine the Pockels-cell modulation delays.
  • Locality and space-like separation: The stations are 93 m and 90 m from the source, with effective optical lengths of 132 m and 119 m for Alice and Bob.

G. Optimize mean photon number for optimum CHSH game value

The section models multi-pair photon contributions and experimentally studies mean-photon-number dependence to optimize the CHSH-game Bell value.

  • Mean-photon-number optimization: Bell violation initially increases with mean photon number as non-vacuum events become more frequent, then decreases when multi-photon effects become significant.
  • Mean-photon-number optimization: The study combines experimental tests with numerical simulation to optimize mean photon number, while selecting a conservative sub-optimum intensity experimentally.
  • Model and simulation: The simulation considers vacuum, one-, two-, and three-pair photon cases, including threshold detection, dark counts, and misalignment error.
  • Model and simulation: Three-pair probabilities are computed from nine possible single-pair outcomes using coefficients selected from a 9 × 9 × 9 matrix.
  • Model and simulation: Dark-count probability is set to pB = 2 × 10^-5 and misalignment error to pM = 5 × 10^-4 in the simulation.

H. System robustness

The CHSH violation was monitored over time while optical alignment gradually degraded. Occasional mirror adjustments maintained sufficient significance for continuous data collection.

  • Every 60 seconds, accumulated data were used to estimate the CHSH violation.
  • Optical alignment degraded slowly during the experiment and was occasionally restored by manually tweaking the mirrors.
  • The CHSH violation remained at a sufficient significance level, allowing continuous data collection.
  • Figure 10 plots the CHSH violation value versus time.

I. Randomness extraction

The experiment extracts quantum-certified random bits from a large raw-data record using Toeplitz hashing. The resulting stream passes NIST tests and achieves a rate of 181.20 bits/s with uniformity within 10^-5.

  • 1.3790×10^11 raw bits were collected from n = 6.895 × 10^10 experimental trials completed in 95.77 hours.
  • 6.2469 × 10^7 final random bits were extracted using a Toeplitz matrix of dimensions (6.2469×10^7)×(1.3790×10^11).
  • The extraction used blocked FFT acceleration, dividing the original data into 500 blocks on a computer with 16 Gbytes of memory.
  • The complete Toeplitz-hashing calculation took 11 hours, including data loading and computation.
  • The measured CHSH game value was ωexp = 2.757 × 10^-4, with εs = εEA = 1 × 10^-5 and δest specified for the security analysis.
  • 181.20 bits/s were generated with uniformity within 10^-5 after 137.90 Gb × 62.469 Mb Toeplitz matrix hashing.
  • The generated random bits passed the NIST statistical test suite using 62.469 Mbits divided into 60 sequences of 1.041 Mbit.

B. Test of no signaling

The no-signaling analysis tests whether the observed data are compatible with no-signaling distributions without assuming independent and identically distributed trials. The reported tests found no evidence of anomalous signaling.

  • The analysis measures the KL-divergence distance from the observed frequency distribution to the closest no-signaling distribution.
  • The optimal no-signaling distribution is unique because KL divergence is strictly convex over the convex no-signaling polytope.
  • Prediction-based ratios use frequency distributions estimated from prior trial results to construct test statistics without an i.i.d. assumption.
  • The experiment processed 95.77 hours of data block by block, using 24,000,000 trials per block and prior-block frequencies for later prediction-based ratios.
  • Under uniform settings, the no-signaling p-value upper bound was pn = 1, indicating no evidence of anomalous signaling.
  • The PBR p-value upper bound may not be tight when experimental evidence against no-signaling is weak.

C. Test of local realism

The experiment tests local realism using an optimal local-realistic distribution and prediction-based ratios without assuming i.i.d. trials. It reports extremely strong evidence against local realism while finding no evidence against no-signaling.

  • The local-realism test uses the same prediction-based-ratio procedure and does not require the i.i.d. assumption.
  • After 95.77 hours and n = 6.895 × 10^10 trials, the p-value for rejecting local realism was upper bounded by 10^-204792.
  • The resulting data provide extremely strong evidence against local realism under the stated assumption.
  • The analysis assumes uniform setting distributions at each trial, while allowing the setting-distribution assumption to be relaxed using a cited strategy if necessary.
  • The same analysis reports no evidence against no-signaling and extremely strong evidence against local realism.
Loading 1807.09611v2…