A Real-Time Online Security Assessment and Post-Processing Method for Quantum Entropy Sources Based on FPGA
By constructing a real-time quantum conditional minimum entropy evaluation module and a Toeplitz hash post-processing module inside the FPGA, real-time online security evaluation and post-processing of quantum random number generation are realized. This solves the problem of lacking real-time entropy source quality verification in the existing technology and ensures the real-time security and stability of quantum random number generation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TAIYUAN UNIVERSITY OF TECHNOLOGY
- Filing Date
- 2026-03-10
- Publication Date
- 2026-06-02
AI Technical Summary
Existing quantum random number generators lack the ability to verify the quality of entropy sources in real time and dynamically adjust them when facing rapidly changing attack environments, making them unable to effectively cope with external attacks such as quantum channel leakage and pulse injection.
A real-time online security assessment and post-processing method for quantum entropy sources based on FPGA is adopted. By constructing a real-time quantum conditional minimum entropy assessment module and a Toeplitz hash post-processing module with dynamically configurable matrix size inside the FPGA, the minimum entropy calculation and random number generation are parallelized. The size of the Toeplitz matrix is dynamically adjusted according to the real-time minimum entropy value to adaptively match the entropy source quality.
It achieves real-time online security assurance for quantum random number generation, avoiding the risk of entropy evaluation results being forged due to PC attacks, and ensuring the high-speed real-time generation and stability of quantum random numbers.
Smart Images

Figure CN122137535A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of quantum secure communication and quantum random number generator technology, specifically providing a method for real-time online security assessment and post-processing of a quantum entropy source based on FPGA. Background Technology
[0002] Random number generators are crucial in information security systems, directly determining the system's resistance to attacks and the effectiveness of data protection. Quantum random number generators, due to the unpredictability based on quantum mechanics, can generate truly random sequences rigorously proven by information theory, and have become one of the most reliable random source schemes. However, with the advancement of quantum computing and quantum communication technologies, the information security field has gradually recognized that improving the speed and statistical verification of quantum random number generators is not the only concern. How to quantify and ensure the quality of generated random numbers, especially the effectiveness of the entropy source, has become a new research focus.
[0003] The quality of the entropy source in a quantum random number generator determines the security of random bits, especially when facing external attacks such as quantum channel leakage and pulse injection. The stability of the entropy source is crucial. Most current quantum random number schemes use static entropy evaluation methods, which fail to continuously track the dynamic behavior of the system and lack real-time verification of the security of the entropy source.
[0004] In the quantum key distribution process, especially in the privacy amplification stage, traditional methods rely on offline post-processing to estimate the minimum entropy, but this method often cannot cope with rapidly changing attack environments.
[0005] To address these issues, recent research has explored real-time evaluation techniques for quantum conditional minimum entropy to ensure that the quantum random number generation process is unaffected by potential attacks. However, existing real-time evaluation techniques for quantum conditional minimum entropy are either offline and cannot provide real-time feedback, or their processing speed is limited and cannot meet the demands of high-speed quantum random number generation. Therefore, achieving real-time entropy evaluation in parallel with quantum random number generation has become crucial for improving the security of quantum random numbers. Summary of the Invention
[0006] To address the shortcomings of existing technologies, this invention provides a method and system for real-time online security assessment and post-processing of quantum entropy sources based on FPGA. It enables parallel processing of minimum entropy calculation and random number generation, and dynamically adjusts the size of the Toeplitz matrix according to the real-time minimum entropy value, so that the extraction ratio is adaptively matched with the quality of the entropy source.
[0007] Firstly, to achieve the above objectives, this invention provides a real-time online security assessment and post-processing method for quantum entropy sources based on FPGA, comprising the following steps: A real-time quantum conditional minimum entropy evaluation module is built inside the FPGA to perform real-time minimum entropy calculation on the original quantum random signal acquired by the analog-to-digital converter and output the real-time minimum entropy value. A Toeplitz hash post-processing module with dynamically configurable matrix size is built inside the FPGA. The post-processing module runs in parallel with the minimum entropy evaluation module to extract random numbers from the original quantum random signal in real time. Based on the real-time minimum entropy value, the matrix size parameter of the post-processing module is calculated and updated in real time, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.
[0008] Preferably, the real-time evaluation module for quantum conditional minimum entropy adopts a two-stage parallel pipeline structure to perform quantum conditional minimum entropy calculation, including: The variance calculation submodule is used to perform voltage dequantization, accumulation, and square accumulation on the collected raw random numbers to calculate the variance of the raw random sequence. The minimum entropy calculation submodule is used to perform square root operation on the variance to obtain the standard deviation, and then perform normalization processing in combination with the sampling range and sampling accuracy of the analog-to-digital converter. Finally, through error function and logarithmic operation, the minimum entropy value is output.
[0009] Preferably, the variance calculation submodule is implemented in the following way: In each clock cycle, the collected N-bit raw data is dequantized into a voltage value v; Accumulate v into register A, then add v 2 Accumulate to register B; After a preset number of periods, the variance is calculated as follows: (A 2 -B), and store the result in the variance register.
[0010] Preferably, the minimum entropy calculation submodule is implemented in the following way: The variance value is read from the variance register, and the standard deviation is obtained by bitwise iterative square root operation. The standard deviation is used in conjunction with the sampling accuracy and sampling range of the analog-to-digital converter to perform intermediate calculations to obtain the error function input value; The x-to-1 multiplexer allocates the corresponding selection circuit path according to the magnitude of the error function input value, and the error function output value is obtained by calculating the piecewise error function based on linear interpolation. The logarithmic operation IP core is invoked to perform logarithmic operations on the output value of the acquisition error function to obtain the minimum entropy evaluation result.
[0011] Preferably, calculating and updating the matrix size parameter of the post-processing module in real time based on the real-time minimum entropy value includes: Based on the residual hash lemma, matrix size calculation logic is constructed in FPGA; Set hash security parameters based on the security requirements extracted according to the overall randomness of the system; After receiving the minimum entropy evaluation result, the required Toeplitz matrix size is calculated in real time using the hash security parameter and the minimum entropy evaluation result as inputs to the residual hash lemma. The calculated matrix size is fed back to the Toeplitz hash post-processing module, triggering the module to adjust its internal matrix size configuration.
[0012] Preferably, the adjustment of its internal matrix size configuration is achieved in the following way: Multiple matrix sizes are preset inside the FPGA, and each matrix size corresponds to a different number of XOR cycles for the submatrix multiplication results. After receiving the matrix size, the corresponding matrix size is decoded and parsed. After a complete large matrix multiplication is completed, the XOR period number of the corresponding submatrix multiplication results is selected according to the matrix size to realize dynamic matrix size adjustment after real-time entropy evaluation.
[0013] Preferably, during the operation of the minimum entropy calculation submodule, all data involved are processed as fixed-point numbers in mQn format, where m is the number of digits in the integer part and n is the number of digits in the decimal part; the position of the decimal point and the number of digits change dynamically during the operation and are adapted through shift operations.
[0014] Preferably, it also includes a confidence assessment step for safety parameters: Collect multiple sets of minimum entropy values calculated by FPGA and compare them with the standard minimum entropy value to obtain the minimum entropy calculation error; The error is processed using a t-distribution, a confidence level is set, and the confidence interval is calculated. The confidence level is incorporated as part of the system security parameters and included in the calculation of the matrix size in the residual hash lemma; The confidence interval is two to three orders of magnitude smaller than the minimum entropy change accuracy required for discrete changes in matrix size, ensuring that the minimum entropy calculation error within the board does not affect the matrix size calculation.
[0015] Preferably, the range of the minimum entropy calculation result is limited by the selection path range of the x-to-1 multiplexer, and the input values that exceed the selection path range are not processed; The range of selected paths is obtained by mapping the remaining hash lemma through the adjustable range of the Toeplitz matrix size.
[0016] Secondly, to achieve the above objectives, this invention provides a real-time online security assessment and post-processing system for quantum entropy sources based on FPGA, used to implement a method for real-time online security assessment and post-processing of quantum entropy sources based on FPGA, comprising: Analog-to-digital converters are used to acquire raw quantum random signals and convert them into raw digital random sequences. An FPGA chip is connected to the analog-to-digital converter, and the FPGA chip is internally configured with: The quantum conditional minimum entropy real-time evaluation module is used to calculate the minimum entropy of the original digital random sequence in real time and output the real-time minimum entropy value. A Toeplitz hash post-processing module with dynamically configurable matrix size runs in parallel with the minimum entropy evaluation module to extract random numbers in real time from the original random sequence of numbers. The feedback control module is connected to both the minimum entropy evaluation module and the post-processing module. It is used to calculate and update the matrix size parameter of the post-processing module in real time based on the real-time minimum entropy value, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.
[0017] The beneficial effects of this invention are as follows: 1. A mechanism for synchronous computation and feedback of minimum entropy within the board is provided, which, combined with a Toeplitz hash extractor that can be scaled in real time, forms a real-time online security guarantee scheme for quantum entropy sources: 2. The calculation of quantum conditional minimum entropy is transferred from the host computer to the FPGA, thereby avoiding the risk of entropy evaluation results being forged due to attacks on the PC. 3. Onboard minimum entropy calculation and Toeplitz matrix operation are performed in parallel within the FPGA. The minimum entropy calculation result is fed back in real time and triggers the instantaneous adjustment of the Toeplitz matrix size. While achieving high-speed real-time generation of random numbers, the generated quantum random numbers are ensured to have real-time online security. 4. The adjustable range of matrix size in the Toeplitz operation module determines the computational range that the minimum entropy calculation module deployed in the FPGA needs to cover; 5. Multiple matrix sizes are preset in the FPGA. By changing the number of accumulations between the Toeplitz submatrix and the original subsequence operation results, i.e., adjusting the number of XOR operation cycles, the size of the Toeplitz hash extraction matrix can be dynamically adjusted. Attached Figure Description
[0018] The disclosure of this invention will become more readily understood with reference to the accompanying drawings. It will be readily understood by those skilled in the art that these drawings are for illustrative purposes only and are not intended to limit the scope of protection of this invention. Furthermore, similar numbers in the drawings are used to denote similar components, wherein: Figure 1 This is a schematic diagram of an FPGA quantum conditional minimum entropy real-time evaluation and random number generation system according to an embodiment of the present invention; Figure 2 This is a flowchart of real-time entropy evaluation and matrix size feedback according to an embodiment of the present invention; Figure 3 This is a timing diagram of real-time entropy evaluation and matrix size feedback within an FPGA according to an embodiment of the present invention; Figure 4 This is a schematic diagram of a real-time online security assessment and post-processing method for a quantum entropy source based on FPGA, according to an embodiment of the present invention.
[0019] In the diagram, there is an analog-to-digital converter (ADC) 1; a programmable logic array (PLA) 2; and a host computer 3. Detailed Implementation
[0020] Some embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0021] like Figure 1-4 As shown, this invention provides a real-time online security assessment and post-processing method for quantum entropy sources based on FPGA, including: Step S1: Construct a real-time quantum conditional minimum entropy evaluation module inside the FPGA to perform real-time minimum entropy calculation on the original quantum random signal acquired by analog-to-digital converter 1 and output the real-time minimum entropy value.
[0022] Step S2: Construct a Toeplitz hash post-processing module with dynamically configurable matrix size inside the FPGA. The post-processing module runs in parallel with the minimum entropy evaluation module to extract random numbers from the original quantum random signal in real time. Step S3: Based on the real-time minimum entropy value, calculate and update the matrix size parameter of the post-processing module in real time, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.
[0023] In this embodiment, an on-board minimum entropy synchronous calculation and feedback mechanism is provided. Combined with a Toeplitz hash extractor that can be adjusted in real time, a real-time online security guarantee scheme for quantum entropy sources is formed: the calculation of quantum conditional minimum entropy is transferred from the host computer 3 to the FPGA, thereby avoiding the risk of entropy evaluation results being forged due to attacks on the PC; the on-board minimum entropy calculation and Toeplitz matrix operation are executed in parallel within the FPGA, and the minimum entropy calculation result is fed back in real time and triggers the instantaneous adjustment of the Toeplitz matrix size. While realizing high-speed real-time generation of random numbers, the generated quantum random numbers are ensured to have real-time online security.
[0024] In QRNG and QKD applications, side-channel information such as electromagnetic interference and temperature changes, or deliberate source signal injection attacks, can cause fluctuations in the entropy source, leading to changes in the quantum conditional minimum entropy of the original random sequence. Traditional real-time hardware post-processing schemes for quantum entropy sources typically perform a minimum entropy calculation on the PC before implementation to determine the true random extraction ratio. This invention feeds back the calculation results to the Toeplitz post-processing module in matrix form, enabling real-time evaluation of the entropy source. This not only avoids the risk of entropy evaluation results being falsified due to attacks on the PC, but also effectively suppresses the interference of environmental fluctuations on the stability of the entropy source.
[0025] In one embodiment, the real-time evaluation module for quantum conditional minimum entropy employs a two-stage parallel pipeline structure to perform quantum conditional minimum entropy calculation, including: The variance calculation submodule is used to perform voltage dequantization, accumulation, and square accumulation on the collected raw random numbers to calculate the variance of the raw random sequence. The minimum entropy calculation submodule is used to perform square root operation on the variance to obtain the standard deviation, and then perform normalization processing in combination with the sampling range and sampling accuracy of the analog-to-digital converter 1. Finally, through error function and logarithmic operation, the minimum entropy value is output.
[0026] In this embodiment, the variance calculation result of the variance calculation submodule is used as the input data of the minimum entropy calculation submodule, and the two modules can run simultaneously. The minimum entropy calculation submodule is currently processing the minimum entropy calculation result corresponding to the previous group of a-bit original random bits.
[0027] Specifically, the variance calculation submodule is implemented in the following way: A comprehensive analysis of the impact of different initial random bit quantities on the minimum entropy evaluation time and results was conducted to determine the required initial random bit quantity 'a' for the calculation; a / N initial random numbers were collected, and the results were calculated according to the formula 0. 2 n-1 Digital range to b quantizes the voltage range standard, converting N-bit raw random numbers into the corresponding analog voltage value v; Design two registers, A and B. Each clock cycle, add the quantized voltage value v to the data in register A, and then overwrite the original value in register A. Each clock cycle, the quantized voltage value v is squared, added to the data in register B, and then the original value in register B is overwritten; after a / N clock cycles, the variance of the original random sequence is obtained by squared register A and subtracting register B from the value of register B.
[0028] The minimum entropy calculation submodule is implemented as follows: the variance value is read from the variance register, and the standard deviation is obtained by bitwise iterative square root operation; the standard deviation is combined with the sampling precision and sampling range of the analog-to-digital converter 1 to obtain the error function input value; the error function input value is allocated to the corresponding selection circuit path according to the magnitude of the error function input value through an x-to-1 multiplexer, and the error function output value is obtained by calculating the piecewise error function based on linear interpolation; the logarithmic operation IP core is called to collect the error function output value and perform logarithmic operation to obtain the minimum entropy evaluation result.
[0029] In this embodiment, a standard deviation calculation module for bit-by-bit iterative operation is constructed in the programmable logic array 2. Initially, all bits are set to 0, and starting from the most significant bit, they are sequentially set to 1 and squared. If the squared result is greater than the variance, the bit is set to 0; otherwise, it is set to 1. This process is repeated until all bits are determined, and the standard deviation is obtained and stored in a register. The standard deviation is then used in intermediate operations with parameters such as ADC sampling accuracy and sampling range to obtain the error function input value erf_in. The error function module uses an x-to-1 multiplexer to allocate the error to the corresponding selection circuit path according to the size of erf_in. The error function is then calculated using a piecewise error function based on linear interpolation to obtain the error function output erf_out. The logarithmic operation IP core is called to collect erf_out through the AXI4-stream bus and perform logarithmic operations to finally obtain the minimum entropy evaluation result Hmin.
[0030] In one embodiment, calculating and updating the matrix size parameter of the post-processing module in real time based on the real-time minimum entropy value includes: constructing matrix size calculation logic in the FPGA based on the residual hash lemma; setting hash security parameters according to the security requirements extracted based on the overall randomness of the system; after receiving the minimum entropy evaluation result, using the hash security parameters and the minimum entropy evaluation result as inputs to the residual hash lemma, calculating the required Toeplitz matrix size in real time; and feeding back the calculated matrix size to the Toeplitz hash post-processing module, triggering the module to adjust its internal matrix size configuration.
[0031] In this embodiment, while random number acquisition and post-processing are performed inside the FPGA, minimum entropy calculation and matrix size update are performed online. N bits of raw random data are acquired each clock cycle, and the minimum entropy is calculated cumulatively. After several Toeplitz post-processing iterations (depending on the amount of raw random data used for calculation), the minimum entropy calculation is complete. A logic array for matrix size update and related components is constructed on-board using a hash strong extractor formula. Appropriate system security parameters are selected, and the new matrix size is calculated based on the minimum entropy evaluation result and updated in the Toeplitz post-processing module (by changing the XOR period number of the Toeplitz submatrix result), thereby achieving real-time matrix size update.
[0032] In one embodiment, the adjustment of the internal matrix size configuration is achieved by pre-setting multiple matrix sizes within the FPGA. Each matrix size corresponds to a different number of XOR cycles for the submatrix multiplication results. For example, if the maximum matrix size is j×k and the submatrix size is j×q, then there are k / q submatrixes, each corresponding to a different total number of XOR cycles for the submatrix multiplication results, denoted as y. Upon receiving the matrix size, it is decoded and parsed to obtain the corresponding matrix size. After a complete large matrix multiplication is performed, the corresponding number of XOR cycles for the submatrix multiplication results is selected based on the matrix size, achieving dynamic matrix size adjustment after real-time entropy evaluation.
[0033] In one embodiment, during the operation of the minimum entropy calculation submodule, all data involved are processed as fixed-point numbers in mQn format, where m is the number of digits in the integer part and n is the number of digits in the decimal part; the position of the decimal point and the number of digits change dynamically during the operation and are adapted through shift operations.
[0034] Specifically, for the variance result in mQn format, all M bits are first set to 0, and then the high bits are sequentially set to 1 and multiplied. If the result is too large, the corresponding bit is set to 0; if the result is less than or equal to the corresponding bit, the square root calculation is completed after M clock cycles.
[0035] Throughout the FPGA-based logic operations, all data is processed in a fixed-point format of mQn (m bits for the integer part and n bits for the fractional part). Since the Verilog hardware description language does not directly support decimals, the mQn format is used to represent decimal analog voltage values as binary "fractional" numbers. The position and number of decimal points may dynamically change throughout the computation process; therefore, it is necessary to anticipate potential changes and adapt them through shift operations in the programming, while also considering the longest computation time to prevent register overflow. This process continues until the matrix size calculation is complete, after which the matrix size adjustment and other steps revert to normal computation methods.
[0036] In one embodiment, a security parameter confidence assessment step is also included: collecting multiple sets of minimum entropy values calculated by the FPGA, comparing them with the standard minimum entropy value to obtain the minimum entropy calculation error; performing t-distribution processing on the error, setting a confidence level, and calculating a confidence interval; incorporating the confidence level as part of the system security parameters and integrating it into the residual hash lemma to participate in the matrix size calculation; the confidence interval is two to three orders of magnitude smaller than the minimum entropy change accuracy required for discrete changes in matrix size, ensuring that the minimum entropy calculation error within the board does not affect the matrix size calculation.
[0037] In this embodiment, a / N minimum entropy calculation results are collected, and the minimum entropy calculation results under 64-bit calculation precision of the MATLAB software platform are used as the standard value. The minimum entropy calculation error is obtained by subtraction, and t-distribution processing is performed. A confidence level of the same order of magnitude as the system safety parameters is set, and the reliability of the confidence interval is calculated to evaluate the error interval. This determines the safety parameters of the QRNG post-processing system generated by the minimum entropy calculation module. At the same time, seed imperfection and the use of the same matrix for random extraction will bring their own safety parameters to the QRNG post-processing system. The safety parameters generated by each module in the system are merged together by using a probability upper bound method, thereby evaluating the overall safety of the system.
[0038] In one embodiment, the range of the minimum entropy calculation result is limited by the selection path range of the x-to-1 multiplexer, and input values exceeding the selection path range are not processed; the selection path range is obtained by mapping the adjustable range of the Toeplitz matrix size through the residual hash lemma.
[0039] In this embodiment, the XOR period number (corresponding to matrix size q) designed by the FPGA internal matrix size change module has an upper limit, and the range of the minimum entropy result obtained through the residual hash lemma mapping is also correspondingly limited. In the error function construction module, the wider the calculation range, the larger the required multiplexer size and the more circuit paths. To save FPGA internal logic resources, the range of the minimum entropy calculation result is limited by the error function module, and results exceeding the range are not processed.
[0040] Example 2 like Figure 1As shown, this invention discloses a real-time online security assessment and post-processing system for quantum entropy sources based on FPGA, comprising: an analog-to-digital converter 1 for acquiring raw quantum random signals and converting them into raw digital random sequences; an FPGA chip connected to the analog-to-digital converter 1, wherein the FPGA chip is internally configured with: a real-time quantum conditional minimum entropy assessment module for calculating the minimum entropy of the raw digital random sequence in real time and outputting a real-time minimum entropy value; a Toeplitz hash post-processing module with dynamically configurable matrix size, running in parallel with the minimum entropy assessment module, for extracting random numbers from the raw digital random sequence in real time; and a feedback control module connected to both the minimum entropy assessment module and the post-processing module, for calculating and updating the matrix size parameters of the post-processing module in real time based on the real-time minimum entropy value, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.
[0041] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the original technical features, and the technical solutions resulting from these changes or substitutions will all fall within the scope of protection of the present invention.
Claims
1. A method for real-time online security assessment and post-processing of quantum entropy sources based on FPGA, characterized in that, Includes the following steps: A real-time quantum conditional minimum entropy evaluation module is built inside the FPGA to perform real-time minimum entropy calculation on the original quantum random signal acquired by the analog-to-digital converter and output the real-time minimum entropy value. A Toeplitz hash post-processing module with dynamically configurable matrix size is built inside the FPGA. The post-processing module runs in parallel with the minimum entropy evaluation module to extract random numbers from the original quantum random signal in real time. Based on the real-time minimum entropy value, the matrix size parameter of the post-processing module is calculated and updated in real time, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.
2. The method according to claim 1, characterized in that, The real-time evaluation module for quantum conditional minimum entropy adopts a two-stage parallel pipeline structure to calculate the quantum conditional minimum entropy, including: The variance calculation submodule is used to perform voltage dequantization, accumulation, and square accumulation on the collected raw random numbers to calculate the variance of the raw random sequence. The minimum entropy calculation submodule is used to perform square root operation on the variance to obtain the standard deviation, and then perform normalization processing in combination with the sampling range and sampling accuracy of the analog-to-digital converter. Finally, through error function and logarithmic operation, the minimum entropy value is output.
3. The method according to claim 2, characterized in that, The variance calculation submodule is implemented in the following way: In each clock cycle, the collected N-bit raw data is dequantized into a voltage value v; Accumulate v into register A, then add v 2 Accumulate to register B; After a preset number of periods, the variance is calculated as follows: (A 2 -B), and store the result in the variance register.
4. The method according to claim 3, characterized in that, The minimum entropy calculation submodule is implemented in the following way: The variance value is read from the variance register, and the standard deviation is obtained by bitwise iterative square root operation. The standard deviation is used in conjunction with the sampling accuracy and sampling range of the analog-to-digital converter to perform intermediate calculations to obtain the error function input value; The x-to-1 multiplexer allocates the corresponding selection circuit path according to the magnitude of the error function input value, and the error function output value is obtained by calculating the piecewise error function based on linear interpolation. The logarithmic operation IP core is invoked to perform logarithmic operations on the output value of the acquisition error function to obtain the minimum entropy evaluation result.
5. The method according to claim 1, characterized in that, Based on the real-time minimum entropy value, the matrix size parameter of the post-processing module is calculated and updated in real time, including: Based on the residual hash lemma, matrix size calculation logic is constructed in FPGA; Set hash security parameters based on the security requirements extracted according to the overall randomness of the system; After receiving the minimum entropy evaluation result, the required Toeplitz matrix size is calculated in real time using the hash security parameter and the minimum entropy evaluation result as inputs to the residual hash lemma. The calculated matrix size is fed back to the Toeplitz hash post-processing module, triggering the module to adjust its internal matrix size configuration.
6. The method according to claim 5, characterized in that, The adjustment of its internal matrix size configuration is achieved in the following way: Multiple matrix sizes are preset inside the FPGA, and each matrix size corresponds to a different number of XOR cycles for the submatrix multiplication results. After receiving the matrix size, the corresponding matrix size is decoded and parsed. After a complete large matrix multiplication is completed, the XOR period number of the corresponding submatrix multiplication results is selected according to the matrix size to realize dynamic matrix size adjustment after real-time entropy evaluation.
7. The method according to claim 4, characterized in that, During the operation of the minimum entropy calculation submodule, all data involved are processed as fixed-point numbers in mQn format, where m is the number of digits in the integer part and n is the number of digits in the decimal part; the position of the decimal point and the number of digits change dynamically during the operation and are adapted through shift operations.
8. The method according to claim 1, characterized in that, It also includes a confidence assessment step for security parameters: Collect multiple sets of minimum entropy values calculated by FPGA and compare them with the standard minimum entropy value to obtain the minimum entropy calculation error; The error is processed using a t-distribution, a confidence level is set, and the confidence interval is calculated. The confidence level is incorporated as part of the system security parameters and included in the calculation of the matrix size in the residual hash lemma; The confidence interval is two to three orders of magnitude smaller than the minimum entropy change accuracy required for discrete changes in matrix size, ensuring that the minimum entropy calculation error within the board does not affect the matrix size calculation.
9. The method according to claim 4, characterized in that, The range of the minimum entropy calculation result is limited by the selection path range of the x-to-1 multiplexer; input values that exceed the selection path range are not processed. The range of selected paths is obtained by mapping the remaining hash lemma through the adjustable range of the Toeplitz matrix size.
10. A real-time online security assessment and post-processing system for quantum entropy sources based on FPGA, used to implement the method of claim 1, characterized in that, include: Analog-to-digital converters are used to acquire raw quantum random signals and convert them into raw digital random sequences. An FPGA chip is connected to the analog-to-digital converter, and the FPGA chip is internally configured with: The quantum conditional minimum entropy real-time evaluation module is used to calculate the minimum entropy of the original digital random sequence in real time and output the real-time minimum entropy value. A Toeplitz hash post-processing module with dynamically configurable matrix size runs in parallel with the minimum entropy evaluation module to extract random numbers in real time from the original random sequence of numbers. The feedback control module is connected to both the minimum entropy evaluation module and the post-processing module. It is used to calculate and update the matrix size parameter of the post-processing module in real time based on the real-time minimum entropy value, so that the extraction ratio of the post-processing module is adaptively matched with the current entropy source quality.