Quantum random number generation system and method
By using a single-photon source and a zero-difference detector, combined with CHSH inequality verification, the problem of unclear randomness sources in existing QRNG systems is solved, achieving efficient and economical quantum random number generation with a significant improvement in generation rate.
Patent Information
- Application Number
- CN202080057428.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-05
- Filing Date
- 2020-07-03
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2040-07-03
AI Technical Summary
Existing quantum random number generator (QRNG) systems struggle to effectively distinguish whether randomness is caused by quantum processes or classical noise, and they are costly and lack accurate characterization and verification methods for system components.
Using a single-photon or equivalent single-photon source, a beam splitter, and a zero-difference detector, the randomness is verified by changing the phase of the local oscillator and utilizing the CHSH inequality. Quantum random numbers are generated using standard optical components to test whether the randomness of the system originates from a quantum process.
It achieves efficient and economical generation of provable quantum random numbers, reduces reliance on expensive equipment, can self-check for degradation of system components, and has a generation rate of up to 1.4 Gbit/s, far exceeding existing commercial products.
Smart Images

Figure CN114303128B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates generally to quantum random number generation (QRNG) systems and methods. BACKGROUND
[0002] Random number generation is an important activity in many applications, such as cryptography (encryption, authentication, digital signatures), finance (trading algorithms, electronic money), numerical simulation of physical processes, optimization problems using Monte Carlo techniques, and fundamental research. The randomness and unpredictability of random numbers are key to information security, especially in cryptographic applications.
[0003] Random number generators (RNGs) can be divided into two broad categories: pseudo-random number generators (PRNGs), which generate random numbers according to deterministic algorithms using a seed value, and true random number generators (TRNGs), in which random numbers are generated according to unpredictable physical effects such as turbulence in a flowing stream, or jitter in a circuit or circuit component.
[0004] A problem with most TRNGs based on physical phenomena is that they generate random numbers according to classical physics. Thus, although system noise or chaotic phenomena can introduce some degree of unpredictability, the source of the random numbers is ultimately deterministic.
[0005] Accordingly, there have been recent attempts to design quantum random number generators (QRNGs) based on quantum physical processes. Because quantum phenomena are inherently random, QRNGs offer a way to achieve true random number generation. However, the performance of a QRNG depends on the quantum properties exploited, the proper functioning of the system components, and the ability to distinguish randomness from a truly quantum process or a predictable classical signal.
[0006] For example, in one known QRNG product developed by ID Quantique, a single photon is injected into a semi-transparent mirror. Depending on whether the photon path is detected (reflection or transmission), the system announces bit 0 or bit 1 as a random output.
[0007] The operating principle of the ID Quantique system assumes that the single-photon generation has been fully characterized, that the mirror is an ideal semi-transparent mirror, and that the photon detection is perfect. However, if there are some equipment imperfections (which are practically unavoidable), or if the core components degrade over time, then the system can not actually implement the ideal quantum process. In other words, it is difficult to determine whether the randomness is caused by noise or quantum effects.
[0008] One solution to this problem is to fully characterise the properties of each component and modify the random number generation scheme accordingly. However, this brings another difficulty, which is that there is still a need to verify that the fully characterised system actually produces quantum random numbers in practice. There is currently no clear guidance on how or how often the accurate characterisation of core quantum components should be performed.
[0009] It is desirable to overcome or alleviate at least one of the above problems, or at least provide a useful alternative. SUMMARY
[0010] The summary discloses a quantum random number generation (QRNG) system comprising:
[0011] a single photon or equivalent single photon light source;
[0012] a beam splitter arranged to direct an output from the light source to a first homodyne detector having a first local oscillator and a second homodyne detector having a second local oscillator; and
[0013] a signal control and processing unit configured to:
[0014] vary a phase of the first local oscillator and the second local oscillator;
[0015] receive a plurality of measurements of the output from the first homodyne detector and the second homodyne detector, the plurality of measurements being dependent on an intensity of the light source and the phase of the first local oscillator and the second local oscillator;
[0016] determine from the plurality of measurements whether a CHSH inequality is satisfied; and
[0017] output one or more random numbers in dependence on whether the CHSH inequality is satisfied.
[0018] Also disclosed is a quantum random number generation (QRNG) method comprising:
[0019] directing, by a beam splitter, an output from a single photon or equivalent single photon light source to a first homodyne detector coupled to a first local oscillator and a second homodyne detector coupled to a second local oscillator;
[0020] varying a phase of the first local oscillator and the second local oscillator;
[0021] receiving, at a signal control and processing unit, a plurality of measurements of the output from the first homodyne detector and the second homodyne detector, the plurality of measurements being dependent on an intensity of the light source and the phase of the first local oscillator and the second local oscillator;
[0022] determining from the plurality of measurements whether the CHSH inequality is satisfied; and
[0023] outputting one or more random numbers depending on whether the CHSH inequality is satisfied.
[0024] Also disclosed is a photonic chip comprising a system as disclosed in the summary and / or implementing a method as disclosed in the summary. BRIEF DESCRIPTION OF DRAWINGS
[0025] Embodiments of the application will now be described, by way of non-limiting example only, with reference to the accompanying drawings in which:
[0026] Figure 1 (a) and 1(b) show high level schematic diagrams of a quantum random number generator (QRNG) according to certain embodiments;
[0027] Figure 2 is a block diagram of an example architecture of a signal control and processing module of a QRNG;
[0028] Figure 3 is a schematic diagram of another possible implementation of a QRNG according to certain embodiments;
[0029] Figure 4 is a schematic diagram of an example implementation of a QRNG as a photonic chip;
[0030] Figure 5 is a plot of random bit numbers produced by a QRNG as a function of detector threshold according to certain embodiments;
[0031] Figure 6 is a plot of CHSH violations as a function of detector threshold for a QRNG according to certain embodiments; and
[0032] Figure 7 is another plot of random bit numbers produced by a QRNG as a function of detector threshold according to certain embodiments. DETAILED DESCRIPTION
[0033] Embodiments of the application provide a method and system for generating provable quantum random numbers based on quantum nonlocal correlations and homodyne detection.
[0034] Embodiments of the application enable guaranteeing that the output randomness comes from true quantum correlations without using any expensive equipment, such as single photon detectors.
[0035] Embodiments provide a method and system for self-testing QRNG whose randomness depends only on the violation of Bell's inequality, indicating the true random nature of quantum entanglement, and not on the proper functioning of the device. Thus, it can be determined that the randomness comes from a quantum process, and not from classical noise caused by component degradation.
[0036] In previous Bell's inequality violation based QRNG, strict experimental requirements are needed, such as high-quality entanglement generation and single-photon detection. In contrast, embodiments of the QRNG method disclosed herein can be performed using only off-the-shelf components, resulting in a significant cost reduction compared to previously known methods.
[0037] In general, the method and system according to the present embodiments inject single photons sequentially onto a 50:50 beam splitter, and then generate a series of entangled quantum states according to two different output paths a and b:
[0038]
[0039] The correlations of the quantum entangled states, which can be quantified by the CHSH inequality violation, are used to ensure that the randomness is quantum and not classical.
[0040] Reference is first made to Figure 1 (a), an embodiment of a quantum random number generation (QRNG) system 10 includes a single-photon or equivalent single-photon light source 12 configured to output light at a single-photon level. The output of the source 12 is directed to a 50:50 beam splitter 14 to generate a series of single-photon entangled states, each of which is detected by either a first measurement device 16 or a second measurement device 18.
[0041] The system 10 can be broadly considered to implement three functions: quantum state generation, quantum state measurement, and signal modulation and acquisition.
[0042] Quantum state generation can be implemented by the single-photon source 12 (which can include, for example, a laser diode, an intensity modulator, and an attenuator) and the 50:50 beam splitter 14. In an ideal case, entanglement can be generated using a single-photon source. However, an equivalent single-photon source can be provided by other means, such as by using a coherent state and a decoy state technique to retrieve the single-photon contribution. To perform this technique, the intensity of the coherent state is varied, and appropriate post-processing is performed, as will be described in further detail below. A laser diode can be used to generate the coherent state, an intensity modulator can be used for the intensity variation, and an attenuator can be used for the single-photon level power attenuation.
[0043] The quantum state measurement portion is depicted as being in Figure 1The first measuring device 16 and the second measuring device 18 in (a) may include two sets of zero-difference detectors and associated local oscillators, the phase of which may be controlled by a phase modulator. Each zero-difference detector may include a pair of photodetectors and an electrical amplifier. By changing the phases of the two local oscillators, measurement statistics with different settings can be obtained to estimate the degree of Bell violation, as well as the minimum randomness obtainable from the system.
[0044] The first measuring device 16 may include a first balanced zero-difference detector coupled to a first local oscillator; similarly, the second measuring device 18 may include a second balanced zero-difference detector coupled to a second local oscillator. The use of balanced zero-difference detectors is advantageous because it means that no cooling is required, making the system according to the embodiment suitable for integration into a photonic chip operating at room temperature.
[0045] Depend on Figure 1 (a) The signal control and processing module 20, representing the signal modulation and acquisition section, is responsible for modulating control signals for components such as the intensity modulator and attenuator of the quantum state generation section and the phase modulator of the quantum state measurement section, real-time calibration of the system, and data processing to generate the final random number.
[0046] The signal control and processing unit 20 performs numerous functions, including controlling the phases of the first and second local oscillators of the homodyne detectors 16 and 18, controlling the intensity of the source 12, acquiring signals from the photodetectors of the homodyne detectors 16 and 18, and performing various processing operations on the acquired signals to facilitate the generation of random numbers. Processing may include, for example, analyzing the measurement sequence (conditional on the phase of the local oscillators and the intensity of the source 12) to determine whether the CHSH inequality is satisfied, thereby determining whether the randomness observed in the sequence is due to a quantum or classical source. Randomness extraction can then be performed in response to the detection of a violation of the CHSH inequality.
[0047] This invention is based on the realization that single-photon entanglement can be used to create random numbers through zero-difference measurements in vacuum and single-photon subspaces. Crucially, this allows for self-checking of the quality of the quantum process and determination of the amount of private randomness that can be extracted from the measurement data. If any system component fails, this will be reflected in a reduction in the degree of Bell violation, thereby decreasing the extraction of randomness.
[0048] Advantageously, embodiments of the invention utilize ultrafast zero-difference detection and a laser source, thereby providing the ability to generate random numbers up to and exceeding 1 GHz. In simulations based on off-the-shelf component management by the inventors, it has been found that this method can easily generate quantum-certified random numbers up to 1.4 Gbit / s.
[0049] One possible implementation of the QRNG system is...Figure 1 (b) is shown in schematic form, where solid lines represent optical paths, arrowed solid lines represent output signals, and arrowed dashed lines represent control signals.
[0050] The QRNG system 100 implements quantum state generation using a laser diode 102 that illuminates a first beam splitter 104. The first beam splitter is arranged to direct a first optical beam to an intensity modulator 120, the output of which is directed to an attenuator 140 arranged to attenuate the power of the first optical beam to a single photon level. The output of the attenuator 140 is directed to a second beam splitter 106 to generate an entangled state.
[0051] The QRNG system 100 implements quantum state measurement using a first balanced homodyne detector 150 and a second balanced homodyne detector 152. A third beam splitter 108 is arranged to receive a second optical beam from the first beam splitter 104 and further split the second optical beam along first and second optical paths to respective phase modulators 130 and 132. The first phase modulator 130 feeds into the first balanced homodyne detector 150, which is provided with a first local oscillator signal. Likewise, the second phase modulator 132 feeds into the second balanced homodyne detector 152, which is provided with a second local oscillator signal. The first balanced homodyne detector 150 comprises a beam splitter 110 arranged to direct incoming photons from the quantum state generation section and the phase modulator 130 into photodetectors 150a and 150b. The second balanced homodyne detector 152 comprises a beam splitter 112 arranged to direct incoming photons from the quantum state generation section and the phase modulator 132 into photodetectors 152a and 152b.
[0052] The QRNG system 100 further comprises a signal control and processing (SCP) module 20. The SCP module 20 transmits control signals to the laser diode 102, the intensity modulator 120, the attenuator 140 and the phase modulators 130, 132 to vary the intensity of the coherent state from the laser diode 102 and the phase of the local oscillator signals for the homodyne detectors 150, 152. The SCP module 20 also receives photocurrent measurements from the homodyne detectors 150, 152, which form the basis of the random number generation. Photocurrents from the photodetectors 150a, 150b propagate along signal lines 151a, 151b to the SCP module 20, and photocurrents from 152a, 152b propagate along signal lines 153a, 153b.
[0053] An example architecture of the SCP module 20 is shown in Figure 2. The SCP module 20 comprises a processor 200, a memory 202, and a signal conditioning module 204. The processor 200 is configured to receive photocurrent measurements from the photodetectors 150a, 150b, 152a, 152b along the signal lines 151a, 151b, 153a, 153b. The processor 200 is further configured to process the photocurrent measurements to generate a random number. The processor 200 is further configured to transmit control signals to the laser diode 102, the intensity modulator 120, the attenuator 140 and the phase modulators 130, 132 to vary the intensity of the coherent state from the laser diode 102 and the phase of the local oscillator signals for the homodyne detectors 150, 152. Figure 2Some or all of the SCP module 20 can be a standalone component, such as a system on a chip (SOC), but it will be appreciated that different sub-modules of the SCP module 20 can form part of separate physical components.
[0054] The SCP module 20 can include a signal input component 202 to receive the photocurrent signals from the homodyne detectors 150 and 152, and it can also receive signals from other parts of the QRNG, such as for diagnostic purposes. The SCP module 20 also includes a control signal output module 204, enabling the SCP 20 to transmit control signals to components such as the laser diode 102, the intensity modulators 120 and the attenuators 140, to turn them on or off or to tune them to achieve the required output intensity. The control signal output 204 also transmits signals to the phase modulators 130 and 132 to control their operation, such as switching between two predetermined phase values of the local oscillators of the homodyne detectors.
[0055] The photocurrent signals received at the signal input 202 can be pre-processed by a pre-processing module 203 using methods known in the art, and the pre-processed signals can be transmitted to other components of the SCP 20 for further processing.
[0056] The SCP 20 also includes a process control module 210, which coordinates the overall operation of the SCP 20, and hence the overall operation of the QRNG 100.
[0057] For example, the process control module 210 can be configured to perform a calibration process by means of a calibration module 212. The calibration module 212 can be configured to turn on the laser diode 102, to calibrate the intensity of the coherent state using the intensity modulators 120 and the attenuators 140, and to calibrate the phase reference of the local oscillators with the phase modulators 130 and 132 by monitoring the homodyne detector 150, 152 output signals received at the signal input 102.
[0058] The process control module 210 can also be configured to perform a random number generation process by modulating the intensity and phase of the coherent state produced by the laser diode 102, determining a plurality of photocurrent measurements for different intensities and phases, and then passing the plurality of photocurrent measurements to one or more data processing modules to extract random numbers based on the photocurrent measurements.
[0059] For example, in each round of measurement, the process control module 210 can determine a specific intensity and local oscillator M} of the coherent state μ∈{μ1,μ2,…μ the phase selection, where i e {a, b} denotes one of the two balanced homodyne detectors 150 and 152, and j e {0, 1} denotes the two different phase settings of the local oscillator. The intensity and phase selection are then propagated via the intensity modulation component 206 and the phase modulation component 208 to the intensity modulator 120, the attenuator 140, and the phase modulators 130, 132 by the control signal output 204.
[0060] The process control module 210 can then receive a plurality of photocurrent measurements performed by the balanced homodyne detectors 150, 152. The raw photocurrent measurements can be provided to the post-processing module 214, which determines a measurement result from each balanced homodyne detector 150 or 152
[0061] Each measurement result represents a photocurrent difference between the photodetectors of the homodyne detector (e.g., the difference between the photocurrents measured by the photodetectors 150a and 150b of the homodyne detector 150). The measurement result depends on the intensity of the quantum state μ and the phase setting j e {0, 1} of the local oscillator. That is, each measurement is associated with a particular quantum state intensity and local oscillator phase setting.
[0062] The post-processing module 214 can compare the measurement results to a set of predefined post-selection thresholds {-t, t}. As will be appreciated by those skilled in the art, the thresholds can be chosen to optimize the random number generation rate. If the final measurement result of a particular balanced homodyne detector is designated as 1, and if the final measurement result of a particular balanced homodyne detector is
[0063] Next, by adjusting the different settings of the phase selection and the associated measurement results the post-processing module 214 can obtain the normalized correlation probabilities (for each coherent state μ). Furthermore, by deploying the decoy state technique, the post-processing module 214 can obtain the single-photon contribution
[0064] The decoy state technique can be used to obtain the statistics of single-photon events by the following.
[0065] In a system according to the presently disclosed embodiments, phase random weak coherent states (WCS) with three or more different intensities are used to reconstruct the single-photon statistics with high precision.
[0066] By randomizing the phase of the coherent state, the density matrix of the coherent state can be rewritten as a mixture of density matrices of a series of photon number states (Fock states) that follow a Poisson distribution. The success probability of three WCS {μ1, μ2, μ3} (i.e., the probability of a coherent state generation measurement that satisfies the CHSH inequality) can then be expressed as:
[0067]
[0068]
[0069]
[0070] In the above, represents the probability that the system obtains a successful event (i.e., an event that satisfies the CHSH inequality) when using the phase-randomized coherent state μ1, represents the probability of zero photons occurring in a WCS with intensity μ1, and Y 0 represents the probability that the system obtains a successful event when using the zero-photon Fock state |0>, and the same for the other quantities above. Because the coherent states are weak coherent states, the probability of more than 2 photons is very small and can be neglected to a good approximation, so the above summation can be truncated at the 2-photon order.
[0071] Thus, by solving the above three linear equations, one can obtain P 1 , the single-photon contribution.
[0072] In some embodiments, more than three coherent states can be used in the decoy state technique. This would result in a higher precision of the estimate of P 1 It will be appreciated that the above summation can then be extended to higher orders, e.g., if four weak coherent states are used, one can include the 3-photon contribution, resulting in four equations in four unknowns.
[0073] In some previous implementations of the decoy state technique, one or more vacuum states are used as decoy states. In at least some of the presently disclosed embodiments, all of the states are weak coherent states.
[0074] The single-photon correlation probabilities can be provided to the CHSH violation detector 216. Based on the normalized correlation probabilities, the CHSH violation detector 216 can evaluate the Bell violation observed in the system using an inequality known as the CHSH inequality:
[0075]
[0076] where, As known to those skilled in the art, any strategy based on local deterministic events results in S < 2, while for entangled quantum systems, the results of two measurement settings can result in S > 2, meaning that not all observed outputs can be predetermined and at least some results come from intrinsic quantum correlations. Thus, if the CHSH violation detector 216 determines that S > 2, the measurements of the current round can be used to generate quantum random numbers through randomness extraction or privacy amplification.
[0077] In the case of S > 2, the CHSH violation detector 216 passes The amount of randomness (R) of the system 100 (the average number of random numbers that can be extracted per experimental trial) can be linked to the CHSH statistic through the Von Neumann entropy:
[0078]
[0079] The randomness extractor 218 can take into account real-world system imperfections, such as statistical fluctuations in measurement results, possible correlations between a series of measurements, and deploy more stringent formulas to estimate the final amount of random numbers in a given total number of trials.
[0080] Thereafter, the random extractor can be constructed accordingly to extract the final random numbers. For example, a hash function such as a universal hash function can be used for randomness extraction (see R. Renner and R. Koenig, “Simple Cryptographic Protocols for Universally Composable Privacy Amplification Against Quantum Adversaries, Theory of Cryptography, pp. 407-425 (Springer, 2005), the contents of which are incorporated by reference herein). In one example, a Toeplitz hash extractor can be used. In another example, a Trevisan extractor can be used (see X. Ma et al., Phys. Rev. A 87, 062327, the contents of which are incorporated by reference herein). As will be appreciated by those skilled in the art, many other randomness extraction or privacy amplification suitable for the generated quantum random numbers can be used.
[0081] For example, a seed value for the randomness extractor can be obtained by using random numbers generated from previous rounds of measurements and random number extraction. Since there is no need to change the universal hash function in each round, some of the previously generated random numbers should not be overly consumed.
[0082] Reference is now made to Figure 3Figure 3 shows another example of a QRNG 300. The QRNG 300 implements quantum state generation using a laser diode 302 that illuminates a polarizing beam splitter 310. A polarization controller 304 can be inserted in the beam path between the laser diode 302 and the first beam splitter 310 to control the intensity distribution between the signal and local oscillator of two balanced homodyne detectors 350, 352. The polarizing beam splitter is arranged to direct a first beam towards an intensity modulator 320, the output of which is directed via a polarization modulator 330 towards an attenuator 340 arranged to attenuate the power of the first beam to a single photon level. The polarization modulator 330 can be used to randomize the phase of the signal to implement a decoy state mechanism. In some embodiments, the polarization modulator 330 can not be needed for this purpose; for example, a gain-switched laser diode 302 can be used to produce pulses of the coherent state, thereby providing an intrinsically random phase for the decoy state mechanism to be deployed. The output of the attenuator 340 is directed towards a beam splitter 314 to generate an entangled state.
[0083] The QRNG system 300 implements quantum state measurement using a first balanced homodyne detector 350 and a second balanced homodyne detector 352. A third beam splitter 312 is arranged to receive a second beam from the first (polarizing) beam splitter 310 and further splits the second beam along first and second optical paths to respective phase modulators 332 and 334. The first phase modulator 332 feeds into the first balanced homodyne detector 350, which is provided with a first local oscillator signal. Likewise, the second phase modulator 332 feeds into the second balanced homodyne detector 352, which is provided with a second local oscillator signal. The first and second balanced homodyne detectors 350, 352 can be configured in a similar manner to the first and second homodyne detectors 150, 152 of (b). Figure 1
[0084] The components of the QRNG system 300 are each coupled to a signal control and processing (SCP) module, such as the SCP module 20, although these connections are not shown in Figure 4 .
[0085] Advantageously, the QRNG system 100, 300 is able to generate quantum random numbers at a faster speed than previously known systems, using standard optical components instead of expensive and highly customized components such as single-photon detectors. The speed of the QRNG system 100, 300 can be further improved by deploying a high-speed balanced homodyne detector for quantum entanglement detection (e.g. Finisar CPRV1222A optical sensor), instead of using a conventional shot noise limited (SNL) BHD. The high-speed BHD can have a nominal 3 dB bandwidth of 25 GHz, which is more than 20 times faster than the most advanced SNL BHD. To address the problem of high electrical noise, three reasonable assumptions can be made about the electrical noise: 1) the electrical noise from the two detectors (e.g. 150, 152) should be independent of each other, 2) the electrical noise is independent of the measured quantum signal, and 3) it has a Gaussian distribution. Therefore, if these assumptions hold, the effect of the electrical noise is equivalent to an optical loss on the signal. Thus, the combined output of the laser sources and the equivalent optical loss can be seen as the source of the quantum states. Since the electrical noise of the detectors is locally independent, they will not contribute to the non-local correlations of the single-photon entangled states. Therefore, the effect of the electrical noise can be easily eliminated, overcoming the strict trade-off between noise and bandwidth in the circuit design using SNL BHD.
[0086] In fact, other practical issues, such as noise of the data acquisition device (e.g. ADC), low efficiency of the photodiodes, polarization mismatch between the signal and the local oscillator, etc., can also be addressed by this loss-equivalent scheme, leading to the quantum maximum violation of the CHSH inequality.
[0087] In a laboratory-scale system, the output of the BHD (e.g. 150, 152) can be acquired by a high-speed oscilloscope (Tek DPO72004C) with a bandwidth of 20 GHz and a sampling rate of 50 GS / s. The acquired data can then be stored for offline digital signal processing (DSP). Therefore, according to the Wiener-Khinchin theorem, the down-converted data with a sampling rate of 40 GS / s has minimal correlation between trials. As will be appreciated and as mentioned above, some embodiments can implement the QRNG in integrated circuit form (e.g. in a photonic chip), in which case the data acquisition and DSP functions can be integrated in components within the chip itself.
[0088] In some embodiments, the final random output bits can be obtained by high-speed randomness extraction on FPGA hardware. To account for the effect of finite data size, the entropy accumulation theorem (EAT) can be used to obtain the random number generation rate in security proofs.
[0089] One possible implementation of a QRNG as a photonic chip will be described with reference to Figure 4 The photonic chip 400 is similar toFigure 3 The QRNG system 300 shown in FIG. 3.
[0090] It will be appreciated that the photonic chip 400 includes a number of components and features typical of such devices, such as a substrate and at least one light guide (photonic circuit) layer, and that the light guide structures can include optical fibers, optical waveguides, etc. These components and features will not be described in detail herein.
[0091] The photonic chip 400 implements quantum state generation using a laser diode 402 that illuminates a beamsplitter 410. Unlike the arrangement of FIG. 3, with beamsplitters 310 and 312, a single three-output beamsplitter can be used to direct light from the laser diode 402 to three different paths 431, 432, and 433. Paths 431 and 433 are used to generate local oscillator signals for balanced homodyne detectors 450 and 452, respectively, by phase modulation implemented by respective phase modulators 412 (along path 431) and 414 (along path 433). Figure 3
[0092] Light propagates along path 432 to a first interferometer 420 that functions as an intensity modulator. The intensity modulator 420 includes a first beamsplitter 422 that splits the light beam into a first light beam and a second light beam, which are then recombined at a second beamsplitter 426, the first light beam passing en route through a phase modulator 424. The phase modulator 424 is controlled by the signal control and processing module 20.
[0093] The output of the intensity modulator 420 is directed to a second interferometer 440 that functions as an attenuator. The attenuator 440 includes a first beamsplitter 442 that directs light to a first path and a second path that are recombined at a second beamsplitter 446. Light propagating along the first path passes through a phase modulator 444, which is again controlled by the signal control and processing module 20, so that the attenuator 440 can be configured to attenuate the power of the light beam exiting the attenuator 440 to a single photon level. The phase modulator 444 can be used to randomize the phase of the signal to implement a decoy state mechanism, or the laser diode 402 can be a gain-switched laser diode for generating coherent state pulses, thereby providing an intrinsically random phase for the decoy state mechanism to be deployed.
[0094] Once the signal has been attenuated to the single photon level, the output of the attenuator 440 is the entangled state generated by the beam splitter 446. The output entangled state is then measured using a first balanced homodyne detector 450 and a second balanced homodyne detector 452. The first balanced homodyne detector 450 includes a beam splitter 460 arranged to direct input photons from the attenuator 440 and the phase modulator 412 into photodetectors 450a and 450b. The second balanced homodyne detector 452 includes a beam splitter 462 arranged to direct input photons from the attenuator 440 and the phase modulator 414 into photodetectors 452a and 452b.
[0095] As described above, the first phase modulator 412 feeds into the first balanced homodyne detector 450 to provide a first local oscillator signal for the first balanced homodyne detector 450 along path 431. Likewise, the second phase modulator 414 feeds into the second balanced homodyne detector 452 to provide a second local oscillator signal for the second balanced homodyne detector 452 along path 433.
[0096] Experimental results
[0097] To simulate the actual performance of the QRNG system 100, a realistic model was developed to account for actual system imperfections, such as electrical noise of the homodyne detectors 150 and 152, statistical fluctuations in the measurements, etc., according to the teachings of J. Appel, D. Hoffman, E. Figueroa, and A. I. Lvovsky, Phys. Rev. A 75, 035802 (2007), which is incorporated by reference herein in its entirety.
[0098] The total number of trials simulated (each trial corresponding to one measurement result for each homodyne detector) was set to 10 10 As Figure 5 shown, the simulation shows that intrinsic random numbers can be obtained from the system 100 as a function of the post-selection threshold {-t, t}.
[0099] Figure 5 The total amount of random numbers as a function of the post-selection threshold t is shown. δ, ∈ s and ∈ e are error parameters of the calculation. Curve a is the ideal result without considering electrical noise or statistical fluctuations. Curve b corresponds to the result considering statistical fluctuations and security analysis but without noise. Curve c is the amount of random numbers that can be obtained in a real system, taking into account system noise, statistical fluctuations, etc.
[0100] From Figure 5In curve c, considering the imperfections of the actual system, it can be seen that if the operating frequency of the system 100 is set to 1 GHz, a raw random number generation rate of about 140 Mbits / sec can be obtained. This is much higher than the existing commercial QRNG product of ID Quantique, which provides a generation rate of 4 Mbits / sec for a single device.
[0101] A system according to the QRNG 300 was constructed and used to perform quantum random number generation. Using optimized parameters from a theoretical analysis of the system 300 (i.e., by modeling the system 300 and determining parameters that maximize the amount of extractable randomness), a CHSH violation of 2.38 was achieved, which can lead to high throughput random number generation of greater than 1 Gbps.
[0102] Figure 6 and Figure 7 Experimental results for the QRNG 300 are shown. Figure 6 The relationship of the CHSH violation to the threshold setting is shown. The dotted line 602 shows the theoretical CHSH violation with an ideal single photon source (as reflected by S, as described above). The solid line 604 shows the theoretical CHSH violation when using the three-intensity decoy state method. The circles represent the experimental results achieved by the system 300.
[0103] Figure 7 The relationship of the final random number generation rate to the threshold is shown. The solid line represents the theoretical (simulated) random number generation rate when using the three-intensity decoy state method, while the circles represent the experimental results.
[0104] From the foregoing, it can be seen that embodiments of the present application provide a simple and economical way of generating randomness from an intrinsic entangled quantum system that is not affected by the functioning of the constituent components such as beam splitters, detectors, etc. Instead, the modulation of the phase and intensity is used to generate a measurement from which randomness can be extracted. This is much easier to control than the condition of electrical or optical system components. Furthermore, embodiments can be implemented using standard components, facilitating implementation in a photonic chip. Moreover, according to simulation results, the random number estimates of the presently proposed system can be much higher than known QRNG products.
[0105] Many modifications will be apparent to those skilled in the art without departing from the scope of the present application.
[0106] Throughout this specification, unless the context requires otherwise, the word "comprise", and variations such as "comprises" and "comprising", will be understood to imply the inclusion of a stated integer or step or group of integers or steps but not the exclusion of any other integer or step or group of integers or steps.
[0107] The reference to or use of any prior publication (or information derived from it) or anything known to the prior art in this specification is not, and should not be taken as an acknowledgement or admission that the prior publication (or information derived from it) or known art forms part of the common general knowledge in the field of endeavour concerned by the present specification.
Claims
1. A quantum random number generation system, comprising: Single-photon or equivalent single-photon light source; A first beam splitter is arranged to direct the output from the light source to a first homodyne detector having a first local oscillator and a second homodyne detector having a second local oscillator, wherein each single photon or equivalent single photon is randomly directed to the first homodyne detector via a first path and to the second homodyne detector via a second path to generate entangled quantum states in the first path and the second path. The second beam splitter is used to guide the signal from the first local oscillator and the single photon or equivalent single photon from the first path to the first pair of photodetectors of the first homodyne detector. A third beam splitter is used to guide the signal from the second local oscillator and the single photon or equivalent single photon from the second path to the second pair of photodetectors of the second homodyne detector. as well as A signal control and processing unit, wherein the signal control and processing unit is configured to: Change the phase of the first local oscillator and the second local oscillator; The first plurality of measurements are received from the first zero-difference detector, the first plurality of measurements depending on the intensity of the light source and the phase of the first local oscillator; The second plurality of measurements are received from the output of the second zero-difference detector, the second plurality of measurements depending on the intensity of the light source and the phase of the second local oscillator; Determine whether the CHSH inequality is violated from the first plurality of measurements and the second plurality of measurements to quantify the correlation between entangled quantum states in the first path and the second path; as well as If the CHSH inequality is violated, one or more random numbers are output based on the first plurality of measurements and the second plurality of measurements; Each of the first plurality of measurements represents the photocurrent difference between the respective photodetectors in the first pair of photodetectors, the photocurrent difference depending on the intensity of the light source and the phase of the first local oscillator; as well as Each of the second plurality of measurements represents the photocurrent difference between the respective photodetectors in the second pair of photodetectors, which depends on the intensity of the light source and the phase of the second local oscillator.
2. The quantum random number generation system according to claim 1, wherein, The light source is configured to generate multiple coherent states of different intensities, and the system includes an attenuator for attenuating the output to the single-photon level.
3. The quantum random number generation system according to claim 1 or 2, wherein, The signal control and processing unit is configured to determine a set of single-photon correlation probabilities from the first plurality of measurements and the second plurality of measurements; And determine whether the CHSH inequality is violated based on the set of single-photon correlation probabilities.
4. The quantum random number generation system according to claim 1 or 2, wherein, The signal control and processing unit is configured to apply a threshold to each measurement before determining whether the CHSH inequality is violated.
5. The quantum random number generation system according to claim 1 or 2, wherein, The signal control and processing unit is configured to apply a randomness extractor to the one or more random numbers.
6. The quantum random number generation system according to claim 5, wherein, The randomness extractor is a general hash function.
7. A method for generating quantum random numbers, comprising: The output from a single-photon or equivalent single-photon source is guided by a first beam splitter to a first homodyne detector coupled to a first local oscillator and a second homodyne detector coupled to a second local oscillator, wherein each single photon or equivalent single photon is randomly guided to the first homodyne detector via a first path and to the second homodyne detector via a second path to generate entangled quantum states in the first path and the second path. The signal from the first local oscillator and the single photon or equivalent single photon from the first path are guided to the first pair of photodetectors of the first homodyne detector by the second beam splitter. The signal from the second local oscillator and the single photon or equivalent single photon from the second path are guided to the second pair of photodetectors of the second homodyne detector by the third beam splitter. Change the phase of the first local oscillator and the second local oscillator; The first plurality of measurements are received from the first zero-difference detector, the first plurality of measurements depending on the intensity of the light source and the phase of the first local oscillator; The second plurality of measurements are received from the output of the second zero-difference detector, the second plurality of measurements depending on the intensity of the light source and the phase of the second local oscillator; Determine whether the CHSH inequality is violated from the first plurality of measurements and the second plurality of measurements to quantify the correlation between entangled quantum states in the first path and the second path; as well as If the CHSH inequality is violated, one or more random numbers are output based on the first plurality of measurements and the second plurality of measurements; Each of the first plurality of measurements represents the photocurrent difference between the respective photodetectors in the first pair of photodetectors, the photocurrent difference depending on the intensity of the light source and the phase of the first local oscillator; as well as Each of the second plurality of measurements represents the photocurrent difference between the respective photodetectors in the second pair of photodetectors, which depends on the intensity of the light source and the phase of the second local oscillator.
8. The quantum random number generation method according to claim 7, wherein, The light source is configured to generate multiple coherent states of different intensities; and the method includes attenuating the output to a single-photon level.
9. The quantum random number generation method according to claim 7 or 8, comprising determining a set of single-photon correlation probabilities from the first plurality of measurements and the second plurality of measurements; and determining whether the CHSH inequality is violated based on the set of single-photon correlation probabilities.
10. The quantum random number generation method according to claim 7 or 8, comprising applying a threshold to each measurement before determining whether the CHSH inequality is violated.
11. The quantum random number generation method according to claim 7 or 8, comprising applying a randomness extractor to the one or more random numbers.
12. The quantum random number generation method according to claim 11, wherein, The randomness extractor is a general hash function.
13. A photonic chip comprising a quantum random number generation system according to any one of claims 1 to 6, and / or configured to implement a quantum random number generation method according to any one of claims 7 to 12.
Citation Information
Patent Citations
True random number generation device and method based on photoquantology
CN108762724A
A device-independent quantum random number generator system and method
CN108984153A
Quantum Signal Detection Method and Quantum Signal Detection Apparatus
US20190028206A1
Quantum random number generator
US20190050203A1