An adaptive quantum random number generation method based on real-time entropy estimation
Patent Information
- Application Number
- CN202610053282.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-15
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-01-15
AI Technical Summary
本发明提供了一种基于实时熵估计的自适应量子随机数生成方法,能够根据物理熵源的实时质量动态调整后处理参数,实现随机性安全与生成效率的平衡。
Smart Images

Figure CN121887389B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of quantum random number generation technology, and relates to an adaptive quantum random number generation method based on real-time entropy estimation. Background Technology
[0002] As quantum communication technology moves from point-to-point experiments to networked deployment, high performance, integration, and low cost of equipment have become inevitable trends in the development of quantum communication technology, and are also key issues that must be addressed for the large-scale development of the quantum communication industry.
[0003] Against this backdrop, quantum random number generators based on optoelectronic integration technology have developed rapidly. These integrated chips utilize microscopic quantum effects in semiconductor devices as a source of physical entropy, offering advantages such as small size, easy integration, low power consumption, and compatibility with Complementary Metal-Oxide-Semiconductor (CMOS) processes. They are one of the key technologies driving the localization and integration of quantum communication equipment. However, although CMOS technology has solved the size and cost issues of quantum random number generators, challenges remain in practical applications. The physical entropy source based on the quantum tunneling effect is essentially a non-stationary random process; its tunneling probability is extremely sensitive to minute fluctuations in ambient temperature and bias voltage. Simultaneously, defects in semiconductor materials introduce significant afterpulse effects, causing the entropy rate of the original random sequence to dynamically drift over time, resulting in unstable output entropy quality.
[0004] Existing quantum random number chips typically use fixed post-processing parameters to extract random numbers, which cannot adapt to dynamically changing physical entropy sources. When environmental fluctuations cause a decrease in entropy rate, a fixed compression ratio cannot completely cancel out correlation and classical noise, resulting in reduced security of the output random numbers. Conversely, when the entropy source quality is high, a fixed compression ratio wastes randomness resources, limits the effective output bit rate, and affects overall generation efficiency. Therefore, how to effectively address the dynamic fluctuations of physical entropy sources and achieve an adaptive balance between randomness security and generation efficiency while maintaining integration and low cost has become a technical problem that the quantum information industry still needs to solve. Summary of the Invention
[0005] In view of this, the purpose of this invention is to provide an adaptive quantum random number generation method based on real-time entropy estimation. This method utilizes state transition probabilities combined with confidence interval correction to calculate the real-time minimum entropy of the original random sequence; then, based on the residual hash lemma, it dynamically determines the input bit width under a fixed output bit width; finally, it completes data compression and randomness purification by reconstructing the Toeplitz matrix. This method can increase the compression ratio when the entropy source quality decreases, ensuring the randomness security of the output bits; and decrease the compression ratio when the entropy source quality improves, thereby increasing the effective random bit rate and achieving a dynamic balance between security and generation efficiency.
[0006] To achieve the above objectives, the present invention provides the following technical solution: An adaptive quantum random number generation method based on real-time entropy estimation specifically includes the following steps: S1: A silicon-based single-photon avalanche diode (SPAD) manufactured using standard CMOS technology serves as the core unit of the physical entropy source. Under conditions of no light and low temperature, a reverse bias voltage higher than its avalanche breakdown voltage is applied to the SPAD through a bias circuit, causing it to operate in Geiger mode, forming a high electric field in the depletion region, thereby generating a quantum tunneling effect; S2: Initial charge carriers are generated by utilizing the interband tunneling effect and defect-assisted tunneling effect of the tunneling current, including interband tunneling electrons and defect-assisted tunneling electrons. S3: Electrons or holes generated by the aforementioned tunneling enter the high-field multiplication region, triggering avalanche breakdown. According to the McIntyre model, the triggering probability is... ; S4: Utilizing a series quenching and reset resistor, the automatic cycle of "metastable-avalanche-quenching-reset" is achieved through the voltage drop generated by the avalanche current, thereby continuously generating dark counting pulses. The dark counting rate of a single SPAD unit... for: (1) in, This indicates the effective photosensitive area of the SPAD device; Indicates the width of the depletion layer; and These are the inter-band tunneling and defect-assisted tunneling current densities, respectively. It is the fundamental charge; This represents the probability of an avalanche being triggered. S5: Will Several independent SPAD units are integrated on the same module to form an array, and the output signals of all units are connected to a high-speed logic OR gate for convergence to obtain a high-speed physical entropy source pulse stream. The additivity of the Poisson process is used to increase the total dark count rate. for: (2) in, Indicates the number of SPADs in the array. For the first Dark count rate of each SPAD unit; S6: Use a time-to-digital converter to acquire the pulse stream and sample the clock frequency. The time interval between adjacent pulses is quantized, the least significant bit of the quantized value is taken, and the original random bit stream is generated. ; S7: Real-time generated bitstream Write to the cache to ensure the sequence is stored in perfect chronological order, and set the window length. and in the window Within the system, the frequency of four state transitions of adjacent bits is counted in real time to construct a state transition probability matrix. And calculate the maximum conditional probability. ; S8: To prevent the limited sampling length The resulting statistical fluctuations can lead to misjudgments. To correct this, a statistical confidence interval is introduced based on the maximum conditional probability, and the real-time minimum entropy is calculated. as follows: (3) in, express The minimum entropy contained in each bit of the original data at any given time. To determine the data length of the statistics window, For statistical confidence coefficients; S9: Based on the residual hash lemma, to adapt to the fixed characteristics of the hardware circuit, with a fixed output bit width... Under the premise of combining the real-time minimum entropy output by the statistical window With system security parameters Calculate the dynamic input bit width that meets security requirements. And by shifting the truly random seed sequence, the Toeplitz matrix is reconstructed to obtain a matrix of dimension . Dynamic Toeplitz matrix The original data column vector input to the current window. With matrix Performing matrix operations under modulo 2 constraints, the final output length is... quantum random number sequence .
[0007] S6 includes the following steps: S61: Receives pulse stream using a time-to-digital converter module, and sets the sampling reference clock frequency to [value missing]. The continuous time interval between adjacent arrival times is measured. And the continuous time interval is discretized into the number of clock cycles: (4) in, This indicates the floor function; S62: Maps the discrete clock cycle data into binary bits, and selects... The least significant bit is used as the output bit. : (5) S7 includes the following steps: S71: Writes the real-time generated bitstream to a buffer to ensure the sequence is stored in perfect chronological order, and sets the window length. Then at any time the th The data blocks are: (6) S72: For each data block, the frequency of the four state transitions of adjacent bits is counted in real time. That is, the previous one is The current position is The number of times, among which ; S73: Based on the frequency data obtained from the above statistics, calculate the conditional probability for each state and construct the following... State transition probability matrix : (7) S74: Calculate the maximum conditional probability from the state transition probability matrix. : (8) S9 includes the following steps: S91: Based on the residual hash lemma, to adapt to the fixed characteristics of the hardware circuit, with a fixed output bit width... Under the premise of combining the real-time minimum entropy output by the statistical window With system security parameters Dynamic input bit width that meets security requirements Must meet: (9) Take the minimum value as: (10) in, To fix the output bit width, it is set to the width of the internal data bus of the circuit. For dynamic input bit width, it varies with entropy value. change, For system safety parameters, The rounding up symbol; S92: Constructed using the diagonal identity property of the Toeplitz matrix by shifting the seed sequence. Construct a matrix with dimension... Dynamic Toeplitz matrix ,Right now: (11) in, This is the current truly random seed sequence; S93: Using the Toeplitz matrix to analyze the original data column vector of the current input. Performing matrix operations with modulo 2 constraints yields an output of length [length missing]. quantum random number sequence for: (12) The beneficial effects of this invention are as follows: This invention provides an adaptive quantum random number generation method based on real-time entropy estimation, which can dynamically adjust post-processing parameters according to the real-time quality of the physical entropy source, thereby achieving a balance between randomness security and generation efficiency.
[0008] When environmental fluctuations cause a decrease in the quality of the entropy source and a reduction in the entropy rate of the original random bit stream, this method can automatically increase the compression ratio, effectively remove correlation and classical noise, ensure that the randomness of the output quantum random numbers meets the security requirements, and avoid the security risks caused by a fixed compression ratio.
[0009] When the entropy source quality is high and the entropy rate of the original random bit stream is increased, this method can automatically reduce the compression ratio, reduce the waste of randomness resources, thereby significantly improving the output rate of effective random bits and improving the overall generation efficiency of the quantum random number generator.
[0010] This method achieves adaptive processing of non-stationary physical entropy sources without increasing hardware complexity, sacrificing integration and low cost advantages, through real-time entropy estimation and dynamic Toeplitz matrix reconstruction. It solves the problem of balancing security and efficiency in practical applications of traditional fixed-parameter post-processing methods.
[0011] This invention is applicable to integrated quantum random number generators based on CMOS technology, which can stably provide high-quality, high-speed quantum random numbers under various environmental conditions, providing reliable random source support for quantum communication, quantum key distribution and other quantum information applications.
[0012] Other advantages, objectives, and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination, or may be learned from practice of the invention. The objectives and other advantages of the invention can be realized and obtained through the following description. Attached Figure Description
[0013] To make the objectives, technical solutions, and advantages of the present invention clearer, the preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings, wherein: Figure 1 This is a basic structural diagram of the quantum random number chip of the present invention; Figure 2 This is the working principle of the time-to-digital conversion of the present invention; Figure 3 This is a schematic diagram illustrating the principle of randomness extraction in this invention. Detailed Implementation
[0014] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Unless otherwise specified, the following embodiments and features can be combined with each other.
[0015] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual pictures. They should not be construed as limiting the invention. To better illustrate the embodiments of the invention, some parts in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.
[0016] In the accompanying drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components. In the description of the present invention, it should be understood that if terms such as "upper," "lower," "left," "right," "front," and "rear" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting the present invention. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.
[0017] refer to Figures 1 to 3 This invention provides an adaptive quantum random number generation method based on real-time entropy estimation. This method uses a silicon-based single-photon avalanche diode as a physical entropy source and dynamically adjusts the post-processing parameters through real-time entropy estimation to achieve adaptive generation of quantum random numbers.
[0018] S1: A silicon-based single-photon avalanche diode (SPAD) manufactured using standard CMOS technology serves as the core unit of the physical entropy source. Under conditions of no light and low temperature, a reverse bias voltage higher than its avalanche breakdown voltage is applied to the SPAD through a bias circuit, causing it to operate in Geiger mode, forming a high electric field in the depletion region, and generating a quantum tunneling effect; S2: Initial charge carriers are generated using the interband tunneling effect and defect-assisted tunneling effect of the tunneling current, namely interband tunneling electrons and defect-assisted tunneling electrons. The interband tunneling current density is: (13) in, This represents the effective mass of charge carriers in silicon material. Indicates the bandgap width of silicon materials. Represents the elementary charge. To reduce Planck's constant, This represents the electric field strength as a function of the bias voltage. Defect-assisted tunneling current for: (14) in, , These represent the effective mass of light holes and the effective mass of conduction band electrons, respectively. This represents the defect density per unit volume. This represents the density of effective states in the valence band. Represents the effective density of states in the conduction band. and These are the barrier heights from the top of the valence band to the defect level and from the defect level to the bottom of the conduction band, respectively. S3: Electrons or holes generated by the aforementioned tunneling enter the high-field multiplication region, triggering avalanche breakdown. According to the McIntyre model, the triggering probability is... for: (15) in, and These represent the collisional ionization rates of electrons and holes, respectively. Let be the initial avalanche probability of the carriers just entering the doubling region, and its value satisfies the integral equation: (16) in, The thickness of the multiplication layer; S4: Utilizing a series quenching and reset resistor, the automatic cycle of "metastable-avalanche-quenching-reset" is achieved through the voltage drop generated by the avalanche current, thereby continuously generating dark counting pulses. The dark counting rate of a single SPAD unit... for: (17) in, This indicates the effective photosensitive area of the SPAD device; Indicates the width of the depletion layer; and These are the inter-band tunneling and defect-assisted tunneling current densities, respectively. It is the fundamental charge; This represents the probability of an avalanche being triggered. S5: Will Several independent SPAD units are integrated on the same module to form an array, and the output signals of all units are connected to a high-speed logic OR gate for convergence to obtain a high-speed physical entropy source pulse stream. The additivity of the Poisson process is used to increase the total dark count rate. for: (18) in, Indicates the number of SPADs in the array. For the first Dark count rate of each SPAD unit; S6: Use a time-to-digital converter to acquire the pulse stream and sample the clock frequency. The time interval between adjacent pulses is quantized, the least significant bit of the quantized value is taken, and the original random bit stream is generated. ; S7: Real-time generated bitstream Write to the cache to ensure the sequence is stored in perfect chronological order, and set the window length. and in the window Within the system, the frequency of four state transitions of adjacent bits is counted in real time to construct a state transition probability matrix. And calculate the maximum conditional probability. ; S8: To prevent the limited sampling length The resulting statistical fluctuations can lead to misjudgments. To correct this, a statistical confidence interval is introduced based on the maximum conditional probability, and the real-time minimum entropy is calculated. as follows: (19) in, express The minimum entropy contained in each bit of the original data at any given time. To determine the data length of the statistics window, For statistical confidence coefficients; S9: Based on the residual hash lemma, to adapt to the fixed characteristics of the hardware circuit, with a fixed output bit width... Under the premise of combining the real-time minimum entropy output by the statistical window With system security parameters Calculate the dynamic input bit width that meets security requirements. And by shifting the truly random seed sequence, the Toeplitz matrix is reconstructed to obtain a matrix of dimension . Dynamic Toeplitz matrix The original data column vector input to the current window. With matrix Performing matrix operations under modulo 2 constraints, the final output length is... quantum random number sequence .
[0019] S6 includes the following steps: S61: Receives pulse stream using a time-to-digital converter module, and sets the sampling reference clock frequency to [value missing]. The continuous time interval between adjacent arrival times is measured. And the continuous time interval is discretized into the number of clock cycles: (20) in, This indicates the floor function; S62: Maps the discrete clock cycle data into binary bits, and selects... The least significant bit is used as the output bit. : (twenty one) S7 includes the following steps: S71: Writes the real-time generated bitstream to a buffer to ensure the sequence is stored in perfect chronological order, and sets the window length. Then at any time the th The data blocks are: (twenty two) S72: For each data block, the frequency of the four state transitions of adjacent bits is counted in real time. That is, the previous one is The current position is The number of times, among which ; S73: Based on the frequency data obtained from the above statistics, calculate the conditional probability for each state and construct the following... State transition probability matrix : (twenty three) S74: Calculate the maximum conditional probability from the state transition probability matrix. : (twenty four) S9 includes the following steps: S91: Based on the residual hash lemma, to adapt to the fixed characteristics of the hardware circuit, with a fixed output bit width... Under the premise of combining the real-time minimum entropy output by the statistical window With system security parameters Dynamic input bit width that meets security requirements Must meet: (25) Take the minimum value as: (26) in, To fix the output bit width, it is set to the width of the internal data bus of the circuit. For dynamic input bit width, it varies with entropy value. change, For system safety parameters, The rounding up symbol; S92: Constructed using the diagonal identity property of the Toeplitz matrix by shifting the seed sequence. Construct a matrix with dimension... Dynamic Toeplitz matrix ,Right now: (27) in, This is the current truly random seed sequence; S93: Using the Toeplitz matrix to analyze the original data column vector of the current input. Performing matrix operations with modulo 2 constraints yields an output of length [length missing]. quantum random number sequence for: (28) Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. An adaptive quantum random number generation method based on real-time entropy estimation, characterized in that: Includes the following steps: S1: The silicon-based single-photon avalanche diode SPAD, manufactured using standard CMOS technology, serves as the core unit of the physical entropy source. Under no-light conditions, a reverse bias voltage higher than its avalanche breakdown voltage is applied to the SPAD through a bias circuit, causing the SPAD to operate in Geiger mode and generate a quantum tunneling effect. S2: Initial carriers are generated by utilizing the interband tunneling effect of the tunneling current and the defect-assisted tunneling effect; S3: The initial charge carriers enter the high-field multiplication region, triggering avalanche breakdown; S4: Automatic cycling is achieved by using series quenching and reset resistors, thereby continuously generating dark counting pulses; S5: Integrate multiple independent SPAD units into an array, and connect the output signals of all SPAD units to a high-speed logic "OR" gate for convergence to obtain a physical entropy source pulse stream; S6: The pulse stream is acquired using a time-to-digital converter module, the time interval between adjacent pulses is quantized at the sampling clock frequency, the least significant bit of the quantized value is taken, and an original random bit stream is generated. S7: Write the original random bit stream into a buffer, set the window length, count the frequency of the four states of adjacent bits in real time within the window, construct the state transition probability matrix and calculate the maximum conditional probability. S8: Based on the maximum conditional probability, introduce statistical confidence interval correction and calculate the real-time minimum entropy; S9: Based on the residual hash lemma, under the premise of fixed output bit width, combined with the real-time minimum entropy and system security parameters, the dynamic input bit width is calculated, and the Toeplitz matrix is reconstructed by shifting the true random seed sequence. The original data column vector of the current window and the Toeplitz matrix are subjected to matrix operations under modulo 2 constraints to obtain a quantum random number sequence with a fixed output bit width.
2. The adaptive quantum random number generation method based on real-time entropy estimation according to claim 1, characterized in that: S6 includes: S61: Receive the pulse stream using the time-to-digital converter module, and set the sampling reference clock frequency to... ,in To sample the reference clock frequency, the consecutive time intervals between adjacent pulses Discrete into clock cycles: in The consecutive time interval between adjacent pulses. The number of clock cycles after discretization. This indicates the floor function; S62: The number of discrete clock cycles Mapped to binary bits, the least significant bit is selected as the output bit, where the output bit is denoted as . .
3. The adaptive quantum random number generation method based on real-time entropy estimation according to claim 1, characterized in that: The S7 includes: S71: Writes the real-time generated bitstream to a buffer to ensure the sequence is stored in perfect chronological order, setting the window length to [value missing]. ,in Let be the data length of the statistical window, and be the data length of the at any given time. One data block is ,in t For data block sequence number, b Bits in a bitstream; S72: For each data block, count the frequency of four state transitions between adjacent bits in real time, i.e., the number of times the previous bit is 0 and the current bit is 0. The number of times the previous digit is 0 and the current digit is 1 The number of times the previous digit is 1 and the current digit is 0 The number of times the previous digit is 1 and the current digit is 1. ,in , These represent the corresponding state transition frequencies; S73: Calculate the conditional probability of each state based on the frequency, and construct the state transition probability matrix: in , , , ; S74: Calculate the maximum conditional probability from the state transition probability matrix: in This represents the maximum conditional probability.
4. The adaptive quantum random number generation method based on real-time entropy estimation according to claim 3, characterized in that: The formula for calculating the real-time minimum entropy in S8 is as follows: in, for t The real-time minimum entropy contained in each bit of raw data at any given time. t For a moment, For the maximum conditional probability, To calculate the confidence coefficient, This represents the data length of the statistics window.
5. The adaptive quantum random number generation method based on real-time entropy estimation according to claim 1 or 4, characterized in that: S9 includes: S91: According to the residual hash lemma, with a fixed output bit width Under the premise of combining the real-time minimum entropy output by the statistical window With system security parameters Dynamic input bit width Must meet: Take the smallest integer value: in, To fix the output bit width, For dynamic input bit width, For system security parameters, For real-time minimum entropy, The rounding up symbol; S92: Construct a dimension of [dimensionality] by shifting a truly random seed sequence. Dynamic Toeplitz matrix: in, For length is The current truly random seed sequence; S93: The original data column vector input to the current window. With the Toeplitz matrix Performing matrix operations under modulo 2 constraints yields an output of length . quantum random number sequence in, For length is The original data column vector, For length is A sequence of quantum random numbers.
6. The adaptive quantum random number generation method based on real-time entropy estimation according to claim 1, characterized in that: The total dark count rate in S5 is: in The total dark count rate, K This represents the number of SPAD cells in the array. For the first i Dark count rate per SPAD unit.
Citation Information
Patent Citations
Rayleigh entropy estimation method of superlattice physical entropy source
CN114968176A
Municipal road state sensing method and system based on sensor fusion
CN120027864A