Method for quantum generation of random numbers, in particular lottery, game and device for quantum generation of random numbers

Through the interferometer-based quantum true random number generator and the real-time monitoring of minimum entropy by the control unit CU, the randomness and security issues of random number generators under non-ideal conditions in the existing technology are solved, and high-speed generation and self-detection are achieved, which is suitable for fields such as games and lotteries.

CN115885251BActive Publication Date: 2025-09-19POLITECHNIKA GDANSKA +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202080099391.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-04-24
Publication Date
2025-09-19
Estimated Expiration
2040-04-24

AI Technical Summary

Technical Problem

Existing random number generators are susceptible to interference under non-ideal conditions, resulting in reduced randomness and unpredictability. Existing self-checking methods are complex and costly, making it difficult to achieve high-speed generation and real-time self-testing.

Method used

It uses an interferometer-based quantum true random number generator, and uses the control unit CU to monitor and calculate the minimum entropy of the output in real time to ensure that the generated random numbers conform to quantum theory, have self-detection capabilities, and use commercial components to achieve high-speed generation.

Benefits of technology

While achieving high-speed generation of binary or non-binary random number strings, it also has real-time self-verification capabilities, can detect device defects and tampering, reduce costs and complexity, and ensure the unpredictability and security of random numbers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115885251B_ABST
    Figure CN115885251B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and apparatus for quantum random number generation. The present invention can be implemented when generating random numbers for lotteries and games. In particular, the apparatus comprises an interferometer, a control unit CU connected to a signal source S, the signal having interference characteristics, a component A for changing the characteristics of the signal, and a detector component A for measuring signal strength via an electrical wire, the detector component A being controlled by the control unit CU via the electrical wire using a parameter x. The detector D is configured to measure the signal strength and transmit the measurement result to the control unit CU via the electrical wire. The control unit CU performs a self-test based on the measurement result and returns its result H. min The control unit CU returns the random number and the self-test result H min .
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a novel method and apparatus for quantum random number generation. The invention can be implemented in generating random numbers for lotteries and games. The invention is used for the rapid generation of binary or non-binary random number strings. Background Art

[0002] Besides its philosophical importance, random processes are also used in a variety of technical disciplines. Random numbers are essential for scientific simulations and the gaming industry. The quality metric for generating random values ​​is known as minimum entropy and is related to the probability of guessing the generated sequence before publication. A good random number generator should be able to quickly generate high-entropy, ordered strings of bits.

[0003] Generally speaking, random number generators can be divided into two categories: pseudorandom number generators (PRNGs) and true random number generators (TRNGs). Pseudorandom number generators simulate randomness using complex mathematical algorithms, as described in Gentle JE's 2003 book, "Random Number Generation and Monte Carlo Methods." In these cases, the confidentiality and unpredictability of the random numbers cannot be guaranteed and are subject to factors discussed by CH Vincent in "The Generation of Truly Random Binary Numbers" (Acta Physica Sinica, Vol. 3, No. 6, pp. 594-598, 1970).

[0004] For example, if the seed parameters of a pseudorandom number algorithm are known to the outside world, the generated random numbers will lose confidentiality (Barker E, Kelsey J, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, NIST SP800-90A, January 2012). Issues introduced during the algorithm's implementation can also reduce the confidentiality of random numbers (L. Bello. "Openssl-predictable random number generator" . Debian Security Advisory, 1571-1, 2008), such as the periodicity and lack of consistency mentioned in the article.

[0005] On the other hand, true random number generators are based on one or more unpredictable physical processes. LavaRnd (www.lavarnd.org) is one such true random number generator. It uses a CCD chip to digitize a chaotic light source and a reverse-biased semiconductor device, the Araneus Alea II (www.araneus.fi / products / alea2 / en / ), to generate Gaussian white noise. Random numbers can also be generated using natural random phenomena, such as radioactive decay (www.fourmilab.ch / hotbits / ) or atmospheric noise (www.random.org). Another alternative approach is quantum random number generators (QRGNs), which are based on the inherent uncertainty in the measurement process of quantum systems (published in EP1821196).

[0006] All of the aforementioned random number generation methods guarantee randomness and unpredictability based on theoretically guaranteed generator security models, ensuring freedom from anomalies, failures, and malicious attacks during operation. However, in practice, random number generation can become increasingly irregular due to the inevitable use of non-ideal components under non-ideal conditions or inherent periodic disturbances in the system (e.g., temperature fluctuations, human activity, component wear, etc.). Therefore, random numbers must be verified to ensure that the random number generator operates as expected. Statistical tests exist for finding different types of correlations between random numbers (DieHarder, NIST STS 2.1.2). However, these tests cannot guarantee the absolute security of random number generators (Darren Hurley-Smith and Julio Hernandez-Castro. “Quam Bene Non-Quantum: Biasin a Family of Quantum Random Number Generators.” School of Computing, University of Kent, Canterbury CT2 7NF, Kent, UK).

[0007] However, it is possible to ensure absolute security by having the random number generator continuously analyze its results. In this direction, there have been some different attempts, namely the so-called "device-independent QRNGs" (DI-QRNGs), such as Davide Rusca, Thomas van Himbeeck, Anthony Martin, Jonatan

[0008] Bohr Brask, Weixu Shi, Stefano Pironio, Nicolas Brunner, Hugo Zbinden et al. proposed "Practical self-testing quantum random number generator based on anenergy bound" (arXiv:1904.04819, 2019). However, the DI-QRNGs currently proposed are not practical because they are based on complex quantum communication protocols (disclosed in Anatoly Kulikov, Markus Jerger, Anton Andreas Wallraff, and Arkady Fedorov. "Realization of a Quantum RandomGenerator Certified with the Kochen-Specker Theorem." Phys. Rev. Lett. 119, 240501, 2017), namely Bell tests, and require quantum entanglement. In these cases, users can verify the generation of true random numbers. Specifically, the minimum entropy generated by the random number generator can be directly estimated from the observed data. In this case, the random number generator can self-verify the randomness and unpredictability of the random numbers in real time, eliminating the need for statistical testing of the generated bit strings. However, in practice, DI-QRNGs require a large amount of complex and expensive hardware equipment, and even then, random number generation can only run at an extremely low rate (Davide G. Marangon, Giuseppe Vallone, and Paolo Villoresi. "Source-Device-Independent Ultrafast Quantum Random Number Generation." Phys. Rev. Lett. 118, 060503, 2017), which severely limits its application.

[0009] EP 1447740 discloses a microprocessor with a random number generator (RNG), which can perform a self-test during a system reset and can selectively turn the RNG on or off based on the self-test results. The random number generator RNG includes a self-test unit that performs a self-test to determine whether the RNG is operating normally in response to power-on or a hot reset. If the self-test fails, the microprocessor will disable the RNG. Disabling the RNG may include: returning extended information indicating that the RNG does not exist in response to a CPUID instruction. Disabling the RNG may include: generating a general protection fault in response to executing an MSR instruction associated with the RNG, specifically an RDMSR or WRMSR instruction. Disabling the RNG may include: generating an invalid opcode fault in response to executing an instruction that attempts to obtain a random number from the RNG. The device is a device that can perform a self-test at startup. However, the self-test only includes basic characteristics of the device and does not include entropy detection. In addition, the device is not based on quantum mechanics but on classical physics, so the self-test procedure is not very accurate.

[0010] EP 3040853 describes a random number generator (1, 1000) comprising: a device for measuring two continuous observable quantities in an electromagnetic field in a quantum state; and a conversion device for obtaining a first sequence and a second sequence of bit streams by measuring each observable quantity. In particular, a processing unit is used to calculate the conditional minimum entropy of a random variable associated with the first sequence. A post-processing unit is used to extract a third random bit sequence, the length of which depends on the conditional minimum entropy of the first sequence. The output of the post-processing unit is a set of random bits that can be inserted into a digital signal (such as a digital signal with an encryption key). The invention also relates to a method for generating random numbers. The device is a quantum device but cannot perform self-testing. The device can estimate the entropy of its output result, but this entropy is only based on the probability distribution of the output result, not on the input and the conditional probability of the input.

[0011] US 2015 / 227343 describes a random number generation system and method. The system may include a random number generator (RNG), such as a self-correcting / adaptive quantum random number generator (QRNG), which can roughly achieve randomness based on the output of the RNG. Through regulation, the RNG can generate random numbers that can be considered random without undergoing random number testing. For example, the RNG may include a component that monitors one or more random number generator characteristics during operation, and can perform regulation or self-correction based on the monitored characteristic data, ultimately providing random numbers based on one or more performance criteria. The device does not estimate entropy based on its input and output, but rather uses it to evaluate its operating efficiency (according to some standard) and adjust the input based on the calculated results to achieve the highest operating efficiency. Our device cannot select its input independently.

[0012] In WO 2018 / 065593, a device that supports randomness self-checking is mentioned, but it requires a source that can generate one or two possible states in a clear overlapping situation.

[0013] Furthermore, a technical solution is needed and there remains a need for a random number generation technology that is capable of self-testing the unpredictability of the generated stream. Summary of the Invention

[0014] The object of the present invention is to provide a generator and method for generating a digital string with unpredictability at high speed, characterized by having high entropy that can be self-tested in real time.

[0015] The present invention is based on the physical process of generating and detecting quantum states that ultimately result in inherent randomness. Of particular importance is the self-detection capability of the present invention, enabling real-time randomness verification of the generated random numbers. This approach consistently ensures the functional correctness of the device, and the security of the resulting random numbers is not conditional on the performance of subsequent statistical tests. This solution is easy to implement, enables efficient extraction of the final random number string, is robust to device defects, and supports high-speed generation of binary or non-binary random number strings.

[0016] The present invention proposes a practical implementation method and technical equipment for a quantum true random number generator, and supports real-time self-verification. The operation of the device is based on the active operation method of the interferometer. The technology is particularly easy to implement and only requires standard components that are easy to purchase commercially to be integrated and assembled into a device. The present invention proposes a simplified system with lower cost and complexity than existing systems. The device supports high-speed random generation (on the order of Mbit / s). Another advantage is that unlike most existing solutions, the minimum entropy of the random bits generated in the present invention can be calculated and monitored in real time.

[0017] Compared to current state-of-the-art technologies, the present invention fundamentally differs in its ability to constantly monitor the entropy of randomness, a method that requires neither a specific quantum state source nor specialized measurement equipment. This method ensures robustness against potential defects in all components of the random number generator, thus offering broad application prospects in the gaming industry. Any pre-existing issues or tampering with components will be detected during startup, and any failures or wear will be detected during device operation. If the output is not random, the measured entropy will be zero, making it detectable by the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The present invention will be described in detail with reference to the following examples and accompanying drawings:

[0019] Figure 1 It is a standard multi-path interferometer;

[0020] Figure 2a to improve interferometer equipment based on the addition of signal-modifying components and detectors;

[0021] Figure 2b An apparatus for improving an interferometer based on the addition of a signal modification component;

[0022] Figure 2c For devices based on unmodified interferometers;

[0023] Figure 3 This is a specific embodiment of the present invention - application in games;

[0024] Figure 4 for Figure 2a 、 2b , Schematic diagram of the control unit CU in 2c. DETAILED DESCRIPTION

[0025] General Examples

[0026] a) System-Generator

[0027] The device consists of two components: (a) an interferometer; (b) a control unit (CU). The interferometer is a common instrument and will be described below. The interferometer components of this device can be modified by adding other components. The control unit (CU) manages the operation of the interferometer and self-tests the quality of the randomness generated by the interferometer. This self-test is achieved by calculating the lower bound of the minimum entropy of the output digital string.

[0028] An interferometer is a device used to measure the interference properties of waves in the form of signals. Figure 1 is a schematic diagram describing an interferometer.

[0029] The interferometer has a signal from a source (S) and consists of n paths. The signal can be controlled by the components Parameters in To modify. The interferometer appears in the interference region (I), and the signal is in the detection region The number of detectors m is usually equal to the number of paths, but it is not necessary.

[0030] The initial wave signal is emitted by source S and propagates through two or more paths. The initial wave signal can be in any form with interference properties, such as particles, current, light or sound waves. On each path, in each path, the input parameters can be The configuration modifies the signal independently to change its The properties in the component represented by . Figure 1 Signal interference occurs in the interference area I described in the above. After leaving the interference area I, the signal is detected in the detection area. The number of measurement frequency bands m can be equal to the number of paths n, but it is not necessary. Joint probability distribution of measurement results of the measurement detection area , which is used to establish the signal interference characteristics.

[0031] Basic idea

[0032] The invention described in this article is based on the interferometer mentioned above and the control unit CU connected thereto. The main idea of ​​the invention is that when the device is working properly, the input parameters from the control unit CU are For some combinations of the outputs, the output of the detection unit should be deterministic, while for others it should be completely random. When we expect a deterministic output, examining and estimating the magnitude of the deviation allows us to quantify the quality of the device and its random output. Only when the device's behavior is modeled according to quantum theory (rather than classical theory) can the device's output be self-determiningly random.

[0033] Equipment composition

[0034] The device contains Figures 2a-2c The interferometer and control unit CU described in.

[0035] Interferometer can be used with Figure 1 Remain unchanged as described in , or improve by adding dependencies on some or all of the paths. The additional components represented get their own input from the control unit CU ,like Figure 2a As shown, it can also be Figure 2b Add detection units as described in The control unit CU is a microprocessor in the form of an FPGA or an ASIC, which may contain known auxiliary electronics if necessary.

[0036] Signal source, essential interferometer , optional components ,detector , the attached detection frequency band (if any), are controlled by the control unit CU. Indicates that it comes from the detector or (if any) and sent to the control unit CU, Represents all input parameters Or additional input parameters The control unit CU itself has four main components: a timer T, a hardware driver HD, a memory M and a computing processor CP, all communicating via circuits.

[0037] according to Figure 2a , the device signal comes from the source (S) and propagates through n paths. The signal is transmitted in the control unit CU component According to the parameters Processing. Among them, there are additional components on some paths , which contains its own parameters Based on the See the parameter value in the path , the signal can continue to propagate along the original path or be redirected to an additional detector The signal remaining in the original path interferes in the interference area (I) and is then sent to the detection area. The control unit CU is in the form of FPGA or ASIC, which controls other components besides itself. It has a timer and divides the operation of the device into several steps. In each step, the control unit CU triggers the signal source (S) to send a signal to generate input and information, which is transmitted through the circuit in the component and At each step, all detectors and The input signal is measured and the measurement result is sent to the control unit CU through the circuit. In each step, the control unit CU sends the measurement result and the estimated minimum entropy To the user.

[0038] like Figure 2b As shown, the signal in the device comes from the signal source (S) and propagates through n paths. The signal can be transmitted in the control unit CU component According to the parameters To process. There are additional components in some paths , which has its own parameters The signal will be processed by two components. Interference occurs in the interference area, and then the signal is processed in the detection area. The control unit CU is in the form of FPGA or ASIC, which controls other components except itself. It has a timer and divides the operation of the device into several steps. In each step, the control unit CU triggers the signal source (S) to send a signal to generate input information. and , they pass through the circuit in the component and At each step, all detectors and Measure the input signal and pass the measurement result through the circuit Send to the control unit CU. In each step, the control unit CU sends the measurement results and the estimated minimum entropy To the user.

[0039] like Figure 2c As described in the previous section, the signal in the device comes from the signal source (S) and propagates through n paths. The signal can be transmitted in the control unit CU component According to the parameters To process. Interference occurs in the interference area, and then the signal is in the detection area The control unit CU is in the form of FPGA or ASIC, which controls other components except itself. It has a timer and divides the operation of the device into several steps. In each step, the control unit CU triggers the signal source (S) to send a signal to generate an input , delivered to the components through the circuit At each step, all detectors Measure the input signal and pass the measurement result through the circuit Send to the control unit CU. In each step, the control unit CU sends the measurement results and the estimated minimum entropy To the user.

[0040] method

[0041] Random Generation

[0042] The internal structure of the control unit CU is Figure 4 The control unit CU takes effect in each step. Each step starts when the timer T sends a signal to the hardware driver HD to inform it that a new step has started. The hardware driver HD then gets the random variable from the memory M. .Hard Drive HD Transfer To component and , and command signal source S to send a signal. (and( ), if any), after measurement, the detector will The result is sent to the hardware drive HD, which in turn transfers it to the memory M. The computing unit CP then retrieves the result from the memory M. and Set, and calculate the self-test results from it, that is, Minimum entropy This is a standard measure of random number quality in information theory. The computing processor is used to calculate The method will be described in the next section. The step ends when the computing unit CP sends and To the user. Indicates the random number generated in this step, Indicates the self-test results.

[0043] The computing unit CP also uses a random extractor (a well-known mathematical function) to extract Extract the data sent to memory M The value will be used to set up the component in the next step and .

[0044] Self-Assessment, Part 1: Estimating Probability Distributions .

[0045] This method is used to establish and update and of , works as follows:

[0046] The control unit CU will go back one step Results and Stored in memory M. It is a parameter that can be selected by the user. In any step, and pairs, and remove the longest-lived pair from memory. The current memory stores List of , and the next step (cycle) Value. Given any step returned The value is the previous Step The average minimum entropy of .

[0047] As The first conditional probability distribution of a function Estimated by the control unit CU. Any specific step Any given The probability of the value can be given by the following equivalent formula:

[0048]

[0049] in, is the Kronecker function, which is 1 when a=b and 0 otherwise.

[0050] Self-Test, Part 2: Estimating Minimum Entropy .

[0051] is called the observable probability distribution and is assumed to be derived from the underlying probability There are two types of parameters that we cannot access directly:

[0052] γ represents the characteristics of the interferometer setup, such as the loss of different paths or the characteristics of the interference area. Although they will change over time, the change is slow enough for us to assume that γ is constant at the latest is constant within the block of steps.

[0053] on the other hand, Indicates the parameters that can be changed at each step during the operation of the equipment. Rapid parameter changes only occur when the control signal source S and the detector Behavior (and ( )(if any)) on the electronic circuit. Therefore, we mark , where D is the number of detectors, Figure 2a In is equal to m, in Figure 2b is equal to m+k, are signal source related parameters, For detectors Related parameters.

[0054] The control unit CU stores a limited amount of and Yes, they pre-determine γ and Use γ and The exact parameterization of the device and its parameter ranges depend on the choice of safety paradigm. For example, to model the device, we can assume that the parameters of the device do not change rapidly and is constant, or it is assumed that the signal source always generates a single photon. The device can store multiple sets of (parameters) and the user can switch between different paradigms, sacrificing the security paradigm level to obtain a higher random generation rate. To ensure and is a finite set of parameters γ and Coarse-graining may be required. Then for each γ and calculate Then we get the probability The minimum entropy of , where Γ and Indicates that γ and The value set of , namely:

[0055]

[0056] If we use and To represent the probability distribution. Then the minimum entropy of potential opponents for a specific γ is lower bounded by:

[0057]

[0058] The observed probability distribution for a particular γ is:

[0059]

[0060] At this time, the control unit CU can perform linear programming to The minimum value of (*) is obtained under , where ∈ is an implicit constant that matches the coarse-graining. The significance of this constraint is to obtain the minimum entropy compatible with the observed probability distribution through linear programming. After solving the linear program for all values ​​of γ, It can be expressed as the minimum entropy minimum of all γ, that is: .

[0061] Example 2

[0062] DESCRIPTION OF THE PREFERRED EMBODIMENTS OF THE INVENTION

[0063] The preferred embodiment of the present invention ( Figure 3 (as shown), a four-arm Mach-Zehnder interferometer built based on modern fiber optic technology.

[0064] Because the result of the lottery requires a random number, the random number can be obtained by sending a signal to the control unit CU of the device.

[0065] The control unit CU is a field-programmable gate array (FPGA). It contains all the necessary elements for the control unit CU: memory M, timer T, hardware driver HD, and calculation unit CP. The FPGA controls and synchronizes the signal source S, signal modifiers A and B, and detector D.

[0066] After the light is emitted from the laser, an optical attenuator is then used to reduce the initial signal intensity. The optical attenuator sets the average number of photons per pulse to μ = 0.2. In this case, the signal source can be considered to be a good approximation to a single-photon uncertainty source. We use the standard right-hand representation of quantum information and describe the light state after the generation of a single photon by |χ0> = |0>. After passing through the optical attenuator, the signal is separated into four channels by a 4×4 multi-port beam splitter unit (MBS0). This unit contains a commercial demultiplexer (DEMUX) with 1 optical fiber as input and 4 optical fibers as output. It implements a 4-dimensional Hadamard gate operation:

[0067]

[0068] The quantum state of light after leaving the source is:

[0069]

[0070] Where |k> represents the mode of the photon in the kth channel.

[0071] This equipment is in accordance with Figure 2b Implementation shown. Component It is a phase demodulator (PM) connected to the MBS0 output optical fiber. is the phase FPGA controls the PM by giving different voltages to the driver. After passing the component After that, the state of light becomes:

[0072]

[0073] Components It is another set of phase modulators (PM) connected to each optical fiber. Phase The Field Programmable Gate Array (FPGA) controls the PM driver by giving it different voltages. After passing the component After processing, the state of the light becomes:

[0074]

[0075] Interference region I is another 4×4 multiport beam splitter unit (MBS1) constructed in the same way as (MBS0) and undergoes the same processing as MBS0. After processing, the state of the light becomes:

[0076]

[0077] The light then passes through detectors for measurement. Photons in mode |0> are measured by detector D1, photons in mode |1> are measured by detector D2, photons in mode |2> are measured by detector D3, and photons in mode |3> are measured by detector D4. The detectors are commercially available triggered InGaAs single-photon emission detectors.

[0078] The detector outputs the measurement results to the FPGA, which then estimates the minimum entropy of the results. The field programmable gate array FPGA uses a common random extraction method to For post-processing, the method input is and , the output is a random number string of arbitrary quality The next step is the field programmable gate array FPGA Return to the user, the user can The numbers in the lottery are the lottery results.

[0079] Acknowledgements

[0080] The inventors acknowledge support from the Foundation of Polish Science through grant First TEAM / 2016-1 / 5.

Claims

1. A self-testing quantum number generator device that can be used for lotteries and games, comprising: An interferometer, comprising: a signal source S, at least two channels for signal propagation, a component A capable of modifying signal properties, Interference area I, detector D; Characterized in that the device comprises a control unit CU, and at the same time, The control unit CU is connected to the signal source S, the signal has interference properties, the component A that modifies the signal properties, and the detector D that measures the signal strength through the circuit. The detector D is used to measure the signal strength and report the measurement results. The component A is transmitted to the control unit CU through the circuit, and the control unit CU uses the parameters Through circuit control, the signal source S sends a signal when it receives a request from the control unit CU in the circuit. The control unit CU Performs self-test and returns output results , the control unit CU returns a random number and self-test results ; in, is a vector representing the parameters of all components A, is a vector representing the measurement result of detector D, yes of The lower bound of the average minimum entropy of the string composed of values ​​is calculated by the formula , is a free parameter.

2. The generator device according to claim 1, characterized in that The generator comprises an interferometer of any design modified by adding additional components B.

3. The generator device according to claim 1, characterized in that The generator comprises an interferometer of any design modified by adding an additional component B and an additional detector D'.

4. The generator device according to claim 1, characterized in that The generator comprises a Mach-Zehnder interferometer modified by adding an additional component B.

5. The generator device according to claim 1, characterized in that The generator comprises a Mach-Zehnder interferometer modified by adding an additional component B and a detector D'.

6. The generator device according to claim 1, characterized in that The parameters is generated by the control unit CU from previously generated randomness, or the control unit CU receives it as input from an external source.

7. A random number generation method suitable for lotteries and games, characterized in that: The following steps are involved: a) The control unit CU requests the signal source S to generate a signal with interference characteristics; b) The control unit CU sends parameters to the component A ; c) transmitting the signal from the source S via the component A to the interference region I and the detector D; d) Measure the signal strength by the detector D and report the measurement result to Send to the control unit CU; e) Return the measurement results Randomness as output; f) Return the minimum entropy As a result of self-test; g) Repeat steps a to f.

8. The method according to claim 7, characterized in that The method for self-testing comprises the following steps: The control unit CU records the Steps and The value of is a free parameter; The control unit CU uses the following formula to evaluate the observed probability distribution: The control unit CU uses well-known linear or semidefinite programming; Use an algorithm to find the minimum entropy With the observation The minimum value for value compatibility; The control unit CU returns The value of is the Kronecker function, in 1 if yes, 0 otherwise.

9. The method according to claim 7, characterized in that The control unit CU uses a random number string generation method and a well-known randomness extraction method to post-process the random number string. and As input, and produces The control unit CU returns a random number string instead of As randomness.

Citation Information

Patent Citations

  • Microprocessor with selectively available random number generator based on self-test result

    EP1447740A1

  • Method and apparatus for seeding a cryptographic random number generator

    EP1821196A1

  • Method and apparatus for generating random a sequence of random bits

    EP3040853A1

  • Self-correcting random number generator

    US20150227343A1

  • Method and device for quantum random number generation

    WO2018065593A1