QUANTUM RANDOM NUMBER GENERATION SYSTEM FOR SELF-TESTING OF TRULY RANDOM BIT CHAINS AND METHOD FOR GENERATING A QUANTUM RANDOM NUMBER CHAIN
Patent Information
- Application Number
- DE602023022610
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-09-23
- Publication Date
- 2026-09-16
- Estimated Expiration
- 2043-09-23
Description
[0001] The invention refers to self-testing quantum devices allowing generation of truly random bit strings and method for generation of string of quantum random numbers using the system.
[0002] This system - device and the protocol of creation of random numbers can be used in e.g for application in communication, cryptography, computer Monte Carlo simulations, password generation, banking encryption, lotteries and casinos, video-computer games, randomized controlled trials testing hypotheses, or samples of products. Pseudo random numbers used for task listed above pose the danger of hacking the procedures.
[0003] Random number generation is a crucial aspect of various fields of study, including cryptography, statistical analysis, and simulations. Random numbers are used to generate cryptographic keys, to simulate stochastic events, and to ensure the fairness of games and lotteries, among other applications. However, generating truly random numbers is a challenging task. Most computer-based random number generators rely on algorithms that are deterministic and thus in practice predictable, and thus produce only pseudo-random numbers.
[0004] A frequent approach to generating random numbers is through the use of pseudo-random number generators (PRNGs). PRNGs generate sequences of numbers that appear random but are generated using deterministic algorithms. These algorithms use a seed value to generate a sequence of numbers that has a statistical randomness property, making it difficult to predict future numbers in the sequence. However, if an attacker knows the seed value, they can reproduce the sequence of numbers, which compromises the security of applications that rely on those sequence of random numbers, [Barker E., Kelsey J., Recommendation for Random Number Generation Using Deterministic Random Bit Generators, NIST SP800-90A, January 2012].
[0005] Recently, quantum random number generators (QRNGs) have emerged as a promising solution to the limitations of PRNGs. QRNGs use the inherent fundamental randomness of quantum mechanical systems to generate truly random numbers. In QRNGs, quantum measurements of physical quantities like photon polarization are used to generate random numbers that cannot be predicted or reproduced by an attacker. These devices offer high levels of security, making them ideal for applications for which security is critical. However, many marketed devices rely on attenuated essentially classical light (coherent states), and thus their quantumness is questionable.
[0006] A promising development in the field of random number generation is the concept of device-independent quantum random number generators (DIQRNGs). These devices would not require any assumptions about the underlying physics or trust in the device manufacturer.
[0007] Instead, they rely on the non-classical correlations of the measurement outcomes of the device and the basic assumptions of the non-signaling theorem. The main resource used for DIQRNGs is quantum entanglement which enables Bell-inequality violation which certifies the non-classical (non-deterministic) origin of the results.
[0008] A features of QRNGs is the possibility of self-testing of the device. A self-testing device can monitor the output statistics conditioned on the input to perform verification of the quality of the obtained randomness, and further based on this knowledge improve on this quality. This is most commonly quantified using the concept of min-entropy which is related to the probability of guessing the outcome by third parties. This feature is important for the device as the environment fluctuations and imperfections of the device can result in temporal or permanent bias in the obtained bits and self-testing allows for effective compensation of such effects.
[0009] Multiple quantum random number generators based on optical devices were proposed. Usually the involve highly attenuated beams of light of average intensity much below one photon per detection time gate. The main phenomenon used is random distribution of detection events between exit beams of a beam splitter oran interferometer. Most commonly weak coherent states obtained by attenuation of a pulsed laser beam are used as input light states to such devices, because this is an easy operational procedure, see examples: T. Ferreira da Silva, G. B. Xavier, G. C. Amaral, G. P. Temporão, and J. P. von der Weid, "Quantum random number generation enhanced by weak-coherent states interference," Opt. Express 24, 19574-19580 (2016). Christopher C. Gerry, Richard J. Birrittella, Paul M. Alsing, Amr Hossameldin, Miller Eaton, and Olivier Pfister, "Proposal for a quantum random number generator using coherent light and a non-classical observable," J. Opt. Soc. Am. B 39, 1068-1074 (2022). Davide Rusca, Thomas van Himbeeck , Anthony Martin, Jonatan Bohr Brask , Weixu Shi, Stefano Pironio , Nicolas Brunner, Hugo Zbinden . "Practical self-testing quantum random number generator based on an energy bound". arXiv: 1904.04819, (2019). WO / 2018 / 065593.
[0010] Such devices however cannot be indisputably classified as quantum random number generators as coherent states are the most classical states of light for which a direct violation of classicality is impossible. They do not have even the anti-bunching property which is the most elementary feature of a non-classical light.
[0011] There are solutions which are based on single photon states sources: ● CN206209694U, ● EP3674885B1, ● WO2006133650A1.
[0012] These however also do not make direct tests of quantumness of the state, and thus of randomness of the bits. Quantum randomness is rather assumed based on the construction of the device.
[0013] There is also a proposal of QRNG device based on a single photon which claims to verify the non-classicality of the state: Shafi, K. M., Chawla, P., Hegde, A. S., Gayatri, R. S., Padhye, A., & Chandrashekar, C. M., Multi-bit quantum random number generator from path-entangled single photons. arXiv:2202.10933, (2022).
[0014] However the claim that quantum nature random numbers produced by the setup is based on a violation of a Bell inequality can be easily shown to be wrong.
[0015] There are schemes which verify the non-classical origin of the randomness through Bell inequality: Pironio, S., Acín, A., Massar, S. et al. Random numbers certified by Bell's theorem. Nature 464, 1021-1024 (2010). Liu, Y., Zhao, Q., Li, MH. et al. Device-independent quantum random-number generation. Nature 562, 548-551 (2018).
[0016] However, these schemes use states of two entangled particles in distinction with ours in which we use the entanglement of single-photon excitations in two output modes of a beamsplitter. They are based on standard Bell experiments. Our scheme is based on non-classicality of a single photon (often named as "nonlocality" of a single photon), in a specific configuration of weak homodyne measurement, the correct link of which with Bell's theorem has been established only recently. Thus, these concept demonstrations and our invention are based on entirely different core ideas, and thus form alternative technological paths. E.g. our device operates in an event ready mode (heralding) by default, the two above need re-arrangement to entanglement - swapping configuration to operate in event-ready mode. This would require detection in heralding station of pairs of photons in coincidence, and therefore would lead to a much sharper reduction of generated random bits in the case of non-perfectly efficient detection.
[0017] Another type of QRNG uses homodyne detection to obtain continuous variable based random numbers: P. R. Smith, D. G. Marangon, M. Lucamarini, Z. L. Yuan, and A. J. Shields, Simple source device-independent continuous-variable quantum random number generator, Phys. Rev. A 99, 062326 (2019). Weinan Huang, Yichen Zhang, Ziyong Zheng, Yang Li, Bingjie Xu, and Song Yu, Practical security analysis of a continuous-variable quantum random-number generator with a noisy local oscillator, Phys. Rev. A 102, 012422 (2020).
[0018] These, however, do not use weak homodyne measurement schemes which are based on measurements of discrete degrees of freedom like photon numbers. Moreover, they do not use Bell inequality violation for non-classicality verification. However, this is the Bell inequality violation which definitely certifies non-classicality of a process. And therefore, the protocols do not guarantee the true quantum randomness.
[0019] There are QRNG devices which perform additional self-testing to enhance the randomness of obtained bits: US 2015 / 227343 EP 1447740 WO2021215941
[0020] Those, however, do not use to this end a Bell inequality violation, and non-classicality of a single photon.
[0021] In several works various schemes for testing non-classicality of single photon in superposition of two exit modes of a beamsplitter have been discussed: 1. S. M. Tan, D. F. Walls, and M. J. Collett, Nonlocality of a single photon, Phys. Rev. Lett., 66:252-255, (1991). 2. L. Hardy, Nonlocality of a single photon revisited, Phys. Rev. Lett., 73:2279-2283, (1994). 3. G. Donati, T. Bartley, X-M. Jin, M-D. Vidrighin, A. Datta, Barbieri M., and I. A. Walmsley, Observing optical coherence across Fock layers with weak-field homodyne detectors, Nat. Commun., 5:5584, (2014). 4. T. Das, M. Karczewski, A. Mandarino, M. Markiewicz, B. Woloncewicz, and M. Zukowski, Can single photon excitation of two spatially separated modes lead to a violation of Bell inequality via weak-field homodyne measurements? New Journal of Physics, 23(7):073042, (2021). 5. T. Das, M. Karczewski, A. Mandarino, M. Markiewicz, B. Woloncewicz, and M. Zukowski, Wave-particle complementarity: detecting violation of local realism with photon-number resolving weak-field homodyne measurements, New Journal of Physics, 24(3):033017, (2022). 6. T. Das, M. Karczewski, A. Mandarino, M. Markiewicz, B. Woloncewicz, and M. Zukowski, Comment on 'Single particle nonlocality with completely independent reference states'. New Journal of Physics, 24(3):038001, (2022). 7. T. Das, M. Karczewski, A. Mandarino, M. Markiewicz, B. Woloncewicz, and M. Zukowski, Remarks about Bell-nonclassicality of a single photon, Physics Letters A, 435:128031, (2022). 8. T. Das, M. Karczewski, A. Mandarino, M. Markiewicz, and M. Zukowski, Optimal Interferometry for Bell Nonclassicality Induced by a Vacuum-One-Photon Qubit, Phys. Rev. Applied 18, 034074, (2022).
[0022] All publications listed above are theoretical scientific works describing the interferometric effects which are useful in devising of our RNG. The works 1-8 do not study or suggest any practical applications of these interferometric effects. Documents WO2020 / 257124A1 and Miguel Herrero-Collantes et al, Quantum random number generators, DOI: 10.1103 / RevModPhys.89.015004, 2016, constitute also relevant prior art.
[0023] The present invention is defined by the appended independent claims. Preferred embodiments are set out in the dependent claims.
[0024] According to the invention, the random bits are obtained via detection events in detectors observing two exit beams of a balanced two input -two output port beamsplitter which is fed with a heralded single photon via one defined input port. The most important characteristics of the invention is the interferometric configuration which allows to test the quantumness of the optical state (i.e. that the source indeed produces heralded single photons). Additionally, the interferometric configuration is switched off during the random bit generation runs. Thus possible imperfections related with tuning of the interferometer do not affect the generation. The system also known as a device can be realized using a suitable combination of commercial grade quantum optical and electronic equipment.
[0025] The system-invention-device uses hybrid weak homodyne photon counting detection scheme to verify the non-classicality of a single photon and therefore of the true fundamental randomness of the results. What is more, based on the obtained violation of a Bell inequality, the device performs a self-test to verify the quality of the randomness to allow for extracting fully random bit strings from the obtained results. The performed Bell test does not have to be a loophole-free Bell one, as the existence of Bell non-classicality of quantum systems was established in many previous experiments, and violation of Bell inequality in QRNGs takes the role of verification of the correct operation of the quantum device. The invention-device also produces two independent sequences of quantum-pseudo-random numbers between quantum random number generation runs (generation runs are only those in the case of which the heralding detector fires) which are used by the device in Bell test to determine the local settings. Such a combination of features is not present in any current state-of-the-art device.
[0026] The subject matter of the invention is described in the claims.
[0027] The invention is described in details in examples and drawings: Fig. 1 The general scheme of the device; Fig. 2 Scheme of a particular hardware realization of the device showing a sub-division of control unit and the interferometric configuration Fig. 3a Scheme of the particular hardware realization of the device with outlined interference stations A and B with corresponding detectors from system of detectors Fig. 3b Schematic representation of a specific configuration of the control unit Figure 3. a) Scheme of the example realization of the invention. b) The example of the control unit. General example 1: Introduction
[0028] The invention-device is based on a specific interferometric configuration monitored and operationally manipulated by a control unit. The control unit collects information on the response of the detectors monitoring the exit beams of the interferometer, and out of that forms a random-bit string and in randomly chosen moments it is responsible for performing a self-testing of the quality of quantum quantumness of the input state of the device, and therefore of the quality of obtained randomness. This is performed by conducting a specific Bell inequality test and in the next step calculating a lower bound on min-entropy which quantifies the fraction of fully random bits in the generated bit string.General description of the elements of the invention-device:
[0029] The invention is a system based on the elements described below with its configuration and connections presented in Figure 1.
[0030] Special interferometer comprising parts described below connected by optical paths, and fed with a single photon input in a way also described below A compound pulsed source So of heralded single photon and two reference weak coherent states. A single photon, generated by pulsed (e.g .parametric down conversion - PDC) source So in signal mode, is beam-split on the two-input two-output port beamsplitter BS C . The coherent states play the role of reference states in the sense that the serve as local oscillators in the separated detection stations A and B, which allow to perform two weak homodyne measurements on two beams exited by the heralded single photon (in particle representation this represents a superposition of the photon to be in either this or that beam). Source So sends the information about successful generation of single photon to the detector station described further in the text. This in the case of PDC effect used to get heralded single photons, is obtained by a detection event in the idler mode of the down converter.
[0031] A detection of a single photon in the idler mode acts as trigger which heralds the presence of a single photon in the signal mode. If one uses a deterministic source of signal photons, their presence is heralded by the activation act of the source. Information about successful generation of single photon in the signal mode is encoded as a classical information (electronic signal) and passed to the control unit. Two interference stations A and B which via a suitable unbalanced beasplitter mix the beams of reference coherent states ("local oscillators") with the beams derived form BS C . carrying a superposition od single photon excitations. Importantly the local oscillator can be blocked before entering the unbalanced beamsplitters. with shutters S, two interference stations A and B which mix the beams of reference coherent states with the beams derived form BS C . carrying a superposition od single photon excitations , wherein hat is more, stations can modify interference properties of the input states, in particular they can block input ports into which reference coherent state is input, System of photo detectors monitoring all exit optical modes of the device. Each of these must be capable to detect single photons.
[0032] Control unit CU formed of a coincidence unit and a computer or a chip-system analyzing the data and controlling the shutters in the interferometer. Control unit is characterized by the following: The control unit CU is connected by classical communication channel to source So and can control initiation of its pulsed operation.. The control unit CU is connected by classical communication channels to interference stations A and B and can control their protocol settings in the Bell tests and RNG runs, that is the shutters (open / closed), as well can correct the possible detuning of relative phases (non-protocol action tuning the device to optimal interference). User can input to the CU number of required fully random bits N. The control unit CU comprises a coincidence circuit which gathers information from system of detectors through classical communication channel and analyzes and saves results into a memory. The control unit CU could comprise pseudo-random number generator which can be used in the setting choice at interference stations A and B, the setting choice is saved into the memory. Alternatively, the control unit CU could produce quantum-pseudo-random numbers based on the failed quantum random number generation runs, that is the ones in which heralded single photon was not successfully generated, for the use in the setting choice of interference stations A and B. Such numbers are produced with shutter open, and in this configuration stations A and B constitute two pseudo quantum random number generators, each based on detections in exit ports of a beamsplitter to which enters via a specific port a weak coherent state. The control unit CU produces out of RNG runs a raw random bit string b form collected data from interferometer during the RNG runs (defined by effectively heralded single photon and shutters closed). The control unit CU can perform Bell-test upon obtained data using CH (Clauser-Horne) inequality. The principal aim of such a test is to estimate the quantum ness of the state of the optical files in the signal mode of the source. The obtained result of the test can also be used by the CU to modify the alignment and phase matching of the device in order to calibrate the device to optimize its operation. The control unit CU with the above data computes the min entropy of the collected bits which determines the bitrate r. The control unit CU can output the raw random bit string b and calculated bitrate r to the user for randomness extraction procedure, or it can perform randomness extraction procedure by itself and output quantum fully random bit string b r .
[0033] In particular the elements of the device can be realized using the following parts with their configuration and connections presented in Figure 2.
[0034] LASER: One Laser, which produces a pulsed coherent beam of light. The beam is transmitted into the beamsplitter BS 1 . Work of LASER can be controlled by control unit CU CU.
[0035] F: Filter, which transmits light with a strictly defined frequency profile (at least 3 in the system).
[0036] BS 1 / 2 / A / B / C : Beamsplitters, namely an optical two-input-two-output port device of various transmittivity / reflectivity relation. Out of that BS C and BS 2 are preferably 50-50, and BS A and BS B are tunable, or if the system is very stable of reflectivity / transmittivity relation which is optimal for the test runs. BS C : creates and feeds into beamsplitters BS A and BS B the quantum superposition of the single heralded photon of being either in the beam heading to station A or in the beam heading to station B.
[0037] A: Attenuator, potentially with controllable transmissivity (in some circumstances not necessary if BS 1 can be put to have transmissivity close enough to 1 otherwise at least one in the device).
[0038] FD: One frequency doubling unit, which generates the second harmonics of the light from BS 1 passing through it. The light source is the pulsed LASER. The resulting pulsed beam of double frequency is fed into the PDC crystal.
[0039] PDC: Nonlinear medium which allows for the process of spontaneous parametric down conversion. This process results in two beams with light characterized by half of the frequency of the impinged beam. This process causes with a small probability per pulse of the source spontaneous emission of pairs of directionally and frequency correlated photons one into the signal beam (optical mode) and one to the idler beam. The idler photons end up in detector D t while signal photons enter BS C .
[0040] D A1 / B1 , D A2 / B2 , D t : Detectors, which effectively detect single photons of frequency profiles specified by the filters F. The output of the Detectors is connected to the control system for coincidence analysis. Notation: X y / z throughout the document is to generally mean X _x and X _y .
[0041] S: Shutter (two), which allows blocking of the optical path. Shutters are controlled by aCU.
[0042] P: Phase shifter, which shifts the phase of the beam in a controllable and stable way. (at least 1) CU: general control unit refers to control system involving coincidence / control / monitoring system, formed of a coincidence unit and a computer or a chip-system analyzing the data and reacting on them. It can be divided into three independent sub-control units CU A , CU B , CU D which control respectively the following sub-systems of the device (outlined schematically in the Figure 3a): (interference) Station A with corresponding detectors in detector system: Group of elements which comprises one of the filters F, one of the shutters S, one of the phase shifters P and D A1 , D A2 , BS A (interference) Station B with corresponding detectors in detector system: Group of elements which comprises one of the filters F, one of the shutters S, one of the phase shifters P and D B1 , D B2 , BS B Triger: D t
[0043] CU can be realized as a single unit without such subdivision taking the role of all sub-control units CU A , CU B , CU D .
[0044] CU D : Control unit monitoring the detector D t , which sends information about detection event at the detector to control units CU A , CU B for analysis by coincidence circuit.
[0045] CU B : Control unit, which steers the shutter S and the phase shifter P, and records the outcomes from detectors D B1 and D B2 . The outputs of detectors are shared with CU A for coincidence analysis. It randomly closes and opens the shutter based on pseudorandom numbers or quantum pseudo random numbers. It can also process information from other control units. It can export data to control unit CU A .
[0046] CU A : Control unit, which steers the shutter S and the phase shifter P, and records the outcomes from detectors D A1 , D A2 . It randomly closes and opens the shutter based on pseudorandom numbers (like above). It can also control LASER, and attenuator A. It can also process information from other control units and perform bitrate calculations upon this information. Processing of information includes coincidence analysis through coincidence circuit. It can export data. User can input information to this control unit about the parameters of the randomness generation like number of required fully random bits N.
[0047] Classical communication channel: Any information channel which could transmit classical information between control units CU A / B / D and which allows for steering and controlling devices S, P, D A1 / a2 , D b1 / B2 . D t and BS. This can be implemented by electrical connection cables (wiring).
[0048] Optical path: Physical medium through which the beam propagates. It can be realized by optical fibers or by propagating beams in the air and changing their directions with suitably placed mirrors.
[0049] In the above operational blue-print of the invention the following elements (outlined in the Figure 2): LASER, BS 1 , BS 2 , BS C , FD, PDC, A, and one of the filters F contribute as a source So of heralded single photon and reference coherent state. Detection of the photon in trigger D t signalizes the success of the generation of heralded single photon by the source So. Source in general could be realized in different manner, but has to be characterized by production of heralded single photon of a strictly defined frequency profile further beam-splitted into two optical paths and simultaneous production of two beams of photons in reference coherent states which are able to interfere with generated single photon.Description of physical processes of generation of random key using the invention - device.
[0050] The quantum random number generation process starts with a generation of a pulse of coherent beam by the LASER. Afterward, the beam impinges onto beamsplitter (BS 1 ) of regulated transmissivity with two output ports.
[0051] The beam of the reflection output port of BS 2 passes via an attenuator A which allows further weakening of the intensity. Next the beam impinges into the input port of the second beamsplitter (BS 2 ), which should be symmetric, unbiased. Output ports distribute beam of coherent light to two measurement stations A and B controlled by CU A and CU B respectively. In both stations the intensity of the beam is defined by the reflectivity of the beamsplitter BS 1 and the attenuator A and can be blocked by the shutter (S ). It should be very low. The beam can be phase shifted by phase shifter (P ), for calibration purposes only. The phase shift is kept fixed, which is important in the Bell test runs. The beams are also locally filtered by filters (F ). Next the beams enter one of two entry ports of the local beamsplitters (BS A / B ). They play the role of local oscillators in (weak) homodyne measurements.
[0052] The transmission exit port of BS 1 is connected with the frequency doubling unit, which creates generates second harmonic of the incident Output light enters a nonlinear medium in which the spontaneous parametric down conversion of type II can occur, namely a pair of entangled photons is created in idler and signal modes out of the second harmonics light. The pulse after passing the non-linear medium plays further no role and is blocked. The idler mode passes through the filter F, behind the filter the detector D t is placed. If detector D t registers a photon this heralds that in signal mode there is a photon which has the frequency profile determined by filter (F ). Such filtering at a distance is one of the properties of parametric down conversion. This is necessary for later interference effects in homodyne measurements. The detection event of D t is registered in control unit CU D and information on that sent to the coincidence circuit via a classical communication channel. Transfer of the information about detection in detector D t is responsible for the "event-ready" aspect of the following measurement as it ensures that photon is present in signal mode and marks the time gate for random bit generation. Measurement stations controlled by control units CU A and CU B choose their local settings based on possibly biased pseudorandom or quantum-pseudo-random numbers (which will be defined further on) by either closing ("off" setting) or opening ("on" setting) shutter (S ) in the local oscillator beams and save the chosen setting into their memory together with the time stamp. The choice of settings is repeated with some average frequency and it is independent from the detections in detector D t ,
[0053] Signal beam (carrying the heralded single photon to induce the required entanglement in the state of exit modes of BS C ) is directed onto the balanced beamsplitter (BS C ), the output ports of which are connected with the input ports of beamsplitters in local measurement stations controlled by CU A and CU B into which the local oscillator fields are not fed in. The signal beam interferes with local oscillators in both local measurement stations at beamsplitters BS A / B . The exit beams of the beamsplitters are monitored by detectors D A1 , D A2 and D B1 , D B2 by detectors which can effectively detect if there was at least a single photon in the monitored beam. Control units CU A and CU B save the results for each run in the memory. This finalizes the run. The control units accept as useful runs for bit generation of the raw key, or test of Bell inequality only the events which are in coincidence with time gate of the order of 1 / Δf with detection at D t , where Δf is the frequency band of the filter F.
[0054] Results which do not coincide with detection at D t and when the shutters are open can be utilized for generations of biased quantum-pseudo-random numbers (i.e. not certified) based on photon counts originating from the local weak coherent state and can be utilized for the local setting choice as an alternative for pseudo-random numbers.
[0055] Optical paths of the signal photon and local oscillator beams are tuned to be equal.Method Description of a specific Random Number Generation Protocol to be implemented with the device:
[0056] The protocol of random number generation in the algorithmic form: 1. The device uses via a self calibration protocol, or set upon construction of the device, optimal local oscillators' amplitudes for both measurement stations A and B and with respect to it sets local beamsplitters' transmissivities, so that a violation of the Clauser-Horne (CH) inequality is possible for the setup. 2. User chooses the number of required random bits N. 3. Protocol for a single run: A photon pair is generated in the PDC process. When the detector D t placed in the idler mode dtetctorclicks, the coincident counts at stations A and B can be used to generate a random bit, or for a Bell test of quantumness of the device. The choice between the settings "on" and "off" is locally pseudo-random or alternatively quantum-pseudo-random at each of the detection stations, and stored in the memory of CU A / B in the sequence S A / B together with the time stamp of the protocol run generated upon setting choice. The ratio between "on" and "off" settings is arbitrarily chosen before the start of the protocol. A higher frequency of "off" settings guarantees a higher random bit generation per unit of time, as only the counts during "off-off" settings generates the raw string. 4. After measurements at stations A and B coinciding with the detection in D t the following assignment of results is stored in the control unit CU A / B memory as next element of the sequence of bits R A / B is used: i. For "on" setting: if a click is registered only in the local detector D A1 the local control unit assigns the result "0" and otherwise it assigns "1". The same for station B, for a click at only D B1 ii. For "off" setting control units assign "0" if any click is registered one of the two local detectors and otherwise "1". 5. Steps 3 and 4 are repeated for a chosen number of runs. 6. Control units CU A and CU B communicate to each other the sequence of chosen settings S A / B , obtain results R A / B . Based on the data CH expression which enters the Bell inequality is evaluated. 7. Bitrate r for "off-off" configuration run is calculated in terms of the so-called min-entropy using estimated value of the CH inequality violation or assessment of the optimal strategy for guessing the bit by the third parties. 8. Raw bit string b is prepared from bit string R A using all runs with "off-off". In general, the number of possible to extract fully random bits using known methods of randomness extraction from raw bit string b characterized by bitrate r is given by some protocol specific function N ext (b, r) of bit string length b and bitrate r (e.g. N ext (b, r) = b * r which corresponds to lossless extraction algorithms). If N ext (b, r) is at least as large as the number of required bits N, raw data are either output with all relevant statistics for further post-processing, or post-processed by one of the control units (If extraction protocol was not specified in front of bit generation then N ext (b, r) = b * r is used.). In another case the device stores the data and repeats points 5, 6, and 7 until achieving the required number of fully random bits N.
[0057] Important notice: The random raw bit string b as it is generated only in the "off-off" setting is not affected by the detections of "on-off", "off-on", and "on-no" modes of the shutters (local oscillators) which are used only for the Bell test of non-classicality. "Off-off" is the default setting and only sometimes it changes to "on" on this or that side or both . Only this change of setting is governed by pseudo random number generators. Essentially string b results from certified quantumness of the single photon impinged on BS C . The certification is via the Bell test..Verification of quality of randomness I:
[0058] In steps 6 and 7 of the protocol of random bits generation, the verification of the quality of the obtained randomness is performed. The preferred method for this device is estimation of the quality of the input state and imperfections of the measurement device based on Bell (CH) inequality violation.
[0059] First the probabilities P(ab|x, y) of obtaining result a in station A upon chosen measurement setting x=off, on and result b in station B upon chosen measurement setting y=off, on are estimated by the control unit CU A as frequencies i.e. ratios of the number of pairs (a, b) in sequence (R A , R B ) corresponding to pairs (x, y) in sequence (S A , S B ) to the length of the sequence R A . Similarly, probabilities P A (a|x) ( P B (b|y)) of obtaining the result a (b) in station A (B) upon chosen measurement setting x(y) are estimated. Based on those the CH expression is estimated:
[0060] Obtaining as a result CH > 0 demonstrates a violation of the CH Bell-type inequality, which guarantees that there is no underlying local hidden variable model could be the cause the results of the experiment. This excludes any classical model of the correlations which is in agreement with Relativity, and thus any classical description of the process. This includes also local algorithmic models, and thus generation of the counts at the detectors by a pseudo random process.
[0061] Thus, the results are fundamentally random as they have a quantum nature. What is more, local results for "off-off" scenarios in the almost ideal case, if one excludes the cases of two identical results on side A and side B, which are due to imperfections, allow generation of random bits 0 and 1 with the same probability. The maximal value of CH expression obtainable for this device can be calculated using quantum mechanics giving value CH max ≈ 0.1086. This is not a minute violation as it seems, as the Tsirelson bound for CH inequality is ≈ 0.204. Any imperfections of the device, and any fluctuations in its parameters induced internally or by environment will result in decreasing the value of obtained experimentally value CH exp < CH max . This is because such imperfections result in effectively adding a noise to the assumed single-photon state. Assuming the worst case scenario, in which all the noise results in deterministic assignment of the results and lowers the expectation value of the CH expression in the least possible way i.e. having expectation value 0, one can estimate the effective probability p eff of the measurement upon undisturbed state by bounding this probability from the above as follows: p eff ≤ CH exp / CH max .
[0062] From this one can estimate maximal probability of guessing the outcome P guess as: p guess ≈ 1 − CH exp / CH max + CH exp / 2 CH max
[0063] This allows for estimating the minimal percentage of extractable random bits (bitrate r ) in the raw generated bit string b which is approximately equal to well-known min-entropy H min : r ≈ H min = − log 2 p guess .
[0064] After calculation of r in Step 8, calculating control unit CU A checks if length of the bitstring b (denoted by b) times r fulfills relation b * r ≤ N and based upon that, either calls for the continuation of generation of bits, or outputs the raw bitstring b and bitrate r to the user or postprocesses the bitstring b using one of the well-known randomness extraction algorithms which generates using r and b the string of fully random bits b r and then outputs b r to the user. This procedure effectively compensates for imperfections of the device.Verification of quality of randomness II:
[0065] An alternative method can be used to verify the quality of the extraction of fully random bit string b r from b. In such scenario probabilities P(x, y) are estimated in the same way as in the previous section. This is followed by performing all possible decompositions of the distribution P(x, y) in terms of extremal points of no-signaling polytope by control unit CU A using pseudo-inverse as described in: [Marek Winczewski, Tamoghna Das, John H. Selby, Karol Horodecki, Pawe Horodecki, ukasz Pankowski, Marco Piani, Ravishankar Ramanathan , Complete extension: the non-signaling analog of quantum purification, arXiv:1810.02222 (2018)], storing the information about maximal probabilistic contribution of deterministic local boxes p det . Value p det corresponds to the optimal guessing strategy of the bit by the third parties. This allows for device-independent method of accessing the maximal probability of guessing bit p guess as this method is based solely on obtained probabilities and not on the specific construction of the setup. Bound on p guess can be calculated as: p guess ≤ p det + 1 − p det / 2 .
[0066] Then control unit CU A assigns the bitrate r as min-entropy based on calculated bound, as it bounds from below the real value of the bitrate: r = − log 2 p det + 1 − p det / 2 .
[0067] Upon this calculation control unit CU A starts the step 8 of the algorithm. This method gives lower estimates of r than the method described in the previous section as it optimizes also upon post-quantum realizations of the system resulting in more secure randomness.. However, the method needs longer time for generation of specific number of random bits N as this method results in lower values of r. But this is safer.Example 2
[0068] The abbreviations were explained before.
[0069] The scheme of an example of realization is presented in Figure 3. Control unit is implemented as a one control unit CU presented on Figure 3b based on a computer (PC ) with connected necessary devices described in the following. In particular the control unit possess the following features: input, output coincidence circuit with clock (CC ), memory (M ), computing capabilities coming from the processor of the PC (CPU ), pseudo number generator (PRNG ) and hardware drivers for the control over the other steerable devices in the device described below (LASER, shutters S ) and for receiving the input from them (detectors D A1 / B1 , D A2 / B2 , D t ). All active elements (LASER, shutters S, detectors D A1 / B1 , D A2 / B2 , D t , CU ) are powered by power supply PSU.
[0070] All beamsplitters are chosen as beamsplitters with set transmissivity, in particular: BS A , BS B with transmissivity 0.025, BS 2 , BS C with transmissivity 0.5 and BS 1 with transmissivity 0.99. The shutters S in front of the beamsplitters BS A , BS B are mechanical shutters which block the beam completely when closed and transmit the beam completely when open. Shutters are connected to CU. Single pulsed quasi-monochromatic LASER is chosen to work with central frequency f (frequency is tuned to match the frequency for which detectors work with the highest efficiency), pulse time length t, and power p. Attenuator A is chosen to attenuate the beam in such a way that the average photon number in the beam is 20. Phase shifter P in station A and B performs phase shift 0. The Frequency doubler is chosen to work in the range of frequencies containing f and with efficiency higher than 15%. For the PDC process the BBO nonlinear crystal is chosen which generates from the beam coming from frequency doubler two beams of light frequency f (idler and signal beams). The transmitted beams of light frequency f and its second harmonic are blocked. All three filters F have the same characteristics and filter the frequencies around f within the frequency band. All five detectors D A1 / B1 , D A2 / B2 , D t are chosen to be superconducting nanowire single-photon detectors which are able to detect single photon in range around f with high efficiency 98% and the dead time lower than time between the laser pulses. The optical paths are realized using the optical fibers, and classical communication channels using electric connection wires. The optical path of the photon in the signal beam to the detectors is chosen to be equal to the optical path of the idler photon to the detector D t within a tolerance of an order of magnitude shorter than the optical length of the pulses leaving the filters ΔL = c / Δf. The total optical path from LASER to the detectors of all beams in the system is set to be equal within the same tolerance.
[0071] The output of the LASER is connected to the input port of beamsplitter BS 1 . The first output port (reflected beam) of BS 1 is connected to Attenuator A and then to BSz. The first output port of BS 2 is connected to shutter S of the measurement station A and then to phase shifter P followed by filter F which is connected to the input port of BS A . The second output port of BS 2 is connected to shutter S of the measurement station B and then to phase shifter P followed by filter F which is connected to the input port of BS B . The second output port (transmitted beam) of BS 1 is connected to frequency doubler FD and then to BBO crystal from which the idler beam is propagated towards detector D t and the signal beam towards beamsplitter BS C . The detector D t is connected to CU in particular to the coincidence circuit CC. The first output port of BS C is connected to the second input port of BS A , and the second output port of BS C is connected to the second input port of BS B . The output ports of BS A are connected to the detectors D A1 , D A2 as in Figure 3a. The output ports of BS B are connected to the detectors D B1 , D B2 as in Figure 3a. The detectors D A1 / B1 , D A2 / B2 are connected to CC.
[0072] The device that is shown on Figure 3a, and 3b starts with the input from the user of the number of required random bits N. CU initiates LASER. Single pulsed near monochromatic LASER is chosen to work with central frequency f (frequency is tuned to match the frequency for which detectors work with the highest efficiency), pulse time length t, and power p. Control unit CU chooses pseudo-random settings of the shutters with ratio 9:1 of "off" to "on" settings. This is done for each shutter separately. The change of the settings is simultaneous in both measurement stations and occurs with constant frequency f s . The particular settings are stored in the memory as a sequence (S A , S B ) with time stamps. The CC registers outputs from detectors D A1 / B1 , D A2 / B2 , D t saving the outcomes coinciding with detection in D t up to time gate 1 / Δf to memory in sequence (R A , R B ) with a timestamp that marks the corresponding setting choice. The sequence (R A , R B ) is prepared using on the following key: i. For "on" setting: if in station A (B) a click is registered only in the local detector D A1 (D B1 )then CU adds "0" to sequence R A (R B )otherwise it adds "1". ii. For "off" setting the control unit adds "0" to sequence R A (R B ) if any click is registered in station A (B) and otherwise "1".
[0073] The control unit CU keeps LASER on (producing new pulses) repeating the procedure until number of detections in the detector D t reaches 10*N or at least 1000. The string of bits b is prepared by CU from R A by selecting results only corresponding to the ("off" ,"off") settings combination. As an additional safety measure CU can treat events with results 1 at station A and 1 at station B for the ("off" ,"off") settings as unsuccessful bit generation runs (as this combination can appear only from imperfections) and not include them in b, however, those events are still used in further evaluation of bitrate r. Afterwards CU evaluates bitrate r corresponding to obtained raw bit string b with first or second randomness verification algorithm and stores it in the memory (bitrate calculations on particular examples of bit generations is presented below). Further CU checks the number of obtained random bits b * r where b is the number of results corresponding to setting configuration ("off" ,"off") and decides whether to continue the generation procedure (switching on the LASER for next 10 * (N - b * r) detections of idler photons) or to extract random bit string b r followed by saving it into the memory. After a random bit string b r is generated CU outputs it to the user.
[0074] Consider the successful bit generation runs and self-testing runs assuming that energy profile of beam generated by LASER exactly matches characteristics of filters F and taking approximation that detectors have 100% efficiency. Let us denote the relevant optical modes (see Figure 3) as follows: a S signal mode, a t trigger (idler) mode, a A , a B output mode of BS C directed towards stations A and B respectively, b A , b B outputs modes of BS 2 fed into stations A and B respectively, a 1 , a 2 , b 1 , b 2 . Output modes of local beamspliters fed into detectors D A1 , D A2 , D B1 , D B2 respectively. Note that beamsplitters perform the following transformation of creation operators of some input modes a in1 , a in2 to output modes a out1 , a out2 (transmitted, reflected mode): a ^ out 1 † a ^ out 2 † = T − i R − i R T a ^ in 1 † a ^ in 2 † ,
[0075] Where R, T stands for reflectivity and transmissivity of the beamsplitter.
[0076] The beam of the coherent light is produced by the LASER. This beam after passing through BS 1 , A, BS 2 , FD, PDC the state of the relevant optical modes is given approximately by: 1 − p αe iπ / 2 b A αe iπ b B 0 a s 0 a t + p αe iπ / 2 b A αe iπ b B 1 a s 1 a t ,
[0077] Where p stands for probability of generating photon pair in PDC, |n〉 a stands for state with n photons in mode a and |α〉 b stands for coherent state with amplitude α where in this example α = 10 . The conditional state upon detecting photon in trigger mode by detector D t is given by αe iπ / 2 b A αe iπ b B 1 a s , what corresponds to the situation of successful bit generation / self-testing run. If state |0〉 at is measured in trigger mode run was unsuccessful and CU does not save such result into the sequence of results (R A ,R B ). In the successful case the beam after passing through BS C is given by: αe iπ / 2 b A αe iπ b B 1 a A 0 a B + i αe iπ / 2 b A αe iπ b B 0 a A 1 a B 1 2 .
[0078] Depending on the setting choice of given stations the state can be modified. If shutter in station A is closed i.e. "off" setting we have |αe iϕ< 〉 bA modified to |0〉 bA and analogously for station B. For every setting change the information of chosen setting is saved into memory in sequence (S A , S B ) with time stamp which specifies when the given setting was used. Upon considered state the beamsplitting operation is performed of described above form. On this beamspllited state detectors perform photo detection. If run is bit generating ("off-off" setting) and state is efectively given by: 0 b A 0 b B 1 a A 0 a B − i 0 b A 0 b B 0 a A 1 a B 1 2 . if detectors in station A effectively detect state |0〉 bA |1〉 aA (any of the detectors D A1 , D A2 detected photon) what happens with probability ½ then CU saves into sequence R A result 0 and in such case there is no click in the detectors D B1 , D B2 as single photon was detected in station A and thus CU will save result 1 from station B into R B . Simultaneously the time stamp corresponding to the obtained results is saved by CU for later identification of the used setting. If no photons were detected in station A and photon was detected in station B result 0 is saved into R A and result 1 to R B .
[0079] Analogously results are saved into (R A ,R B ) for other setting choices using the described above result assignment for "off" and "on" settings. Then after reaching the length of the sequence R A to be 10*N (e.g. N=1000), the CU performs self-test by computing bitrate estimating number of fully random bits generated. Example of this procedure is described below.The first randomness verification algorithm (bitrate calculation):
[0080] The following expression is evaluated: which results for the example in the value CH=0.09 which is lower than the maximal one. Obtaining lower values could result from imperfections of the system and outside influences of environment, The specific values of the P(a, b|x, y) are estimated as: n xA n yB N r , where n {xA} is a number of outcomes "a" in sequence R A corresponding to setting "x" in S A , n {yB} is a number of outcomes "b" in sequence R B corresponding to setting "y" in S B and N r is the length of R A Values P A (0|x) and P B (0|y) are evaluated as: P A a x = n xA N r , P B b y = n yB N r .
[0081] Then the bitrate is calculated r = − log 2 1 − CH 0.1086 + CH 0.2172 = − log 2 0.5856 = 0.7719 .
[0082] The string of bits b is prepared from R A by selecting results only corresponding to the ("off" ,"off") settings combination. Let us assume that we obtained b = 9000, where b is the length of b, then b*r=6 947,1>N. Therefore, the CU performs a well known randomness extraction algorithm using b and r generating fully random bit string b r which is then outputted to the user by CU.The second randomness verification algorithm (bitrate calculation):
[0083] The following table is evaluated using formulas from the previous algorithm P(00 | off,off)P(10 | off,off)P(00 | on,off)P(10 | on,off)P(01 | off,off)P(11 | off,off)P(01 | on,off)P(11 | on,off)P(00 | off,on)P(10 | off,on)P(00 | on,on)P(10 | on,on)P(01 | off,on)P(11 | off,on)P(01 | on,on)P(11 | on,on)
[0084] Let the result be: 01 / 20.39220.10771 / 200.10230.39760.39220.10230.30630.18820.10770.39760.18820.3170
[0085] Decomposing this box into local and non-local boxes using methods from [Marek Winczewski, Tamoghna Das, John H. Selby, Karol Horodecki, Pawe Horodecki, ukasz Pankowski, Marco Piani, Ravishankar Ramanathan , Complete extension: the non-signaling analog of quantum purification, arXiv:1810.02222 (2018)] yields the maximal probability of local boxes p det = 0.7968. Based on this most conservative estimate for the bitrate is estimated with: r = − log 2 p det + 1 − p det 2 = 0.1545 .
[0086] Now device calculates the number of fully random bits b*r=9000*0.1545 = 1391.1 > N. Therefore, the CU performs a well known randomness extraction algorithm using b and r generating fully random bit string b r which is then output to the user by CU.
[0087] The work is part of 'International Centre for Theory of Quantum Technologies' project (contract no. 2018 / MAB / 5), which is carried out within the International Research Agendas Programme (IRAP) of the Foundation for Polish Science (FNP) co-financed by the European Union from the funds of the Smart Growth Operational Programme, axis IV: Increasing the research potential (Measure 4.3).
Claims
1. A quantum random number generation system for self-testing generation of truly random bit strings comprising the following parts: - pulsed heralded single photon and weak coherent states source (So) for generation of a single photon passed to beamsplitter (BSC), and two reference coherent states which enable weak homodyne measurement, - interferometer comprising parts connected by optical paths: ∘ two interference stations A and B which mix the beams of reference coherent states with the beams derived from the beamsplitter (BSC) carrying an entangled superposition of single photon excitations; - set of photo detectors for monitoring all exit optical modes of the device while each of detectors is configured to detect single photons; - control unit (CU) that is connected to source (So) which monitors and controls its work and is connected to interference stations A and B and can control their settings, where the control unit (CU) is configured for pseudorandom number generation, result of which is then used for the choice of settings of interference stations A and B, and the setting choice is saved into a memory, or the control unit (CU) is configured for producing quantum-pseudo-random numbers based on the failed quantum random number generation runs for the use in the setting choice at interference stations A and B, additionally the control unit (CU) is configured for generation of fully random bits (N) and raw random bit string (b) from collected data from the interferometer, and comprises o a coincidence circuit which gathers information from system of detectors through classical communication channels and analyzes and saves results, detection events and their coincidences, into a memory, - wherein the control unit (CU) is configured for performing Bell-test upon obtained data using a Clauser-Horne, CH, inequality, the obtained result of the test can also be used by the control unit (CU) to modify the settings of the device in order to calibrate the system, and the control unit (CU) is configured for performing self-test based on obtained results and thus, observed or not Bell non-classicality, by computing the minimum entropy which determines the bitrate (r),wherein each of the interference stations A and B comprise: • at least one shutter (S) for blocking of the optical path and that is controlled by a control unit (CU), • at least one phase shifter (P) for shifting the phase of the beam in a controllable and stable way, preferably controlled by the control unit (CU), • one tuneable or not-tuneable optical beamsplitter (BSA / B), preferably in a form of optical two-input-two-output port device controlled by the control unit (CU), • at least one filter (F), which transmits light with a strictly defined frequency profile corresponding to the filter in the source (So).
2. The system according to the claim 1, wherein the control unit (CU) is configured for outputting the raw random bit string (b) and calculated bitrate r to the user for randomness extraction procedure, or performing randomness extraction procedure by itself and output quantum fully random bit string (br).
3. The system according to any one of claims 1-2, wherein the source (So) comprises the following elements connected by optical paths: - one laser (LASER) controlled by the control unit (CU) for producing a pulsed coherent beam of light into beamsplitter (BS1) - one tuneable or not-tuneable optical beamsplitter (BS1), preferably in a form of optical two-input-two-output port device, - one tuneable or not-tunable optical beamsplitter (BS2), preferably in a form of symmetric optical two-input-two-output port device, - at least one attenuator (A), preferably with controllable transmissivity and controlled by the control unit (CU), - one tuneable or not-tuneable optical two-input-two-output port beamsplitter (BSC), preferably symmetric beamsplitter for distributing the photons among interference stations, - one frequency doubling unit (FD), which doubles the frequency of a part of incoming beam which originates from the (LASER) by a second harmonic generation, - at least one nonlinear medium (PDC) which allows for the process of spontaneous parametric down conversion which generates correlated single-photons in two beams redirected to detector (Dt) and to the beamsplitter (BSC), - at least one filter (F), which transmits light with a strictly defined frequency profile, and additionally the unit of detectors comprises: - five photo detectors (DA1, DA2, DB1, DB2, Dt) for detecting single photons of frequency profiles specified by filter (F) while the output of detectors is connected to the control unit (CU) for coincidence analysis, detection of the photon by (Dt) signalizes successful generation of heralded single photon state, while detectors (DA1, DA2 and DB1, DB2) detect photons in the outputs of the interference stations A and B respectively.
4. A method for generation of string of quantum random numbers to be used with system according to claim 1 comprising the following steps: a) for specific number of times requesting by the control unit (CU) the source (So) to sequentially generate of the heralded single photon states and coherent states, all of which are then transmitted to the interference stations A and B, b) in the meantime changing pseudo randomly the settings of interference stations A and B by the control unit (CU) by choosing between two settings "on", "off", where "off" setting stands for blocking input local reference coherent state pulse using shutter (s), for each station independently and saving the choice of the setting to the memory with time stamp, c) for each successfully heralded single photon generation the outcomes from the detectors are stored in the memory with time stamp which allows for identification of corresponding setting to the given run; as an outcome two bits are created, one bit for detection pattern in output ports of each stations A and B, the following assignment of results stored in the control unit (CU) memory is used: ∘ for "on" setting: if photons are registered only in the local detector (DA1 / B1) control unit (CU) assigns the result "0" and otherwise it assigns "1", ∘ for "off" setting control units assign "0" if any photon is registered and otherwise "1", d) preparing in the control unit (CU) raw bit string (b) from the results for runs in which settings for both interference stations were "off", from each successful such run only one bit of the string is produced, it is the result obtained at one, specified by the protocol, interference station, e.g. A, and at this stage, preferably, removing from raw bit string b elements corresponding to events with results 1 and results 0 in both local stations simultaneously as additional self-correction layer, e) performing self-test by calculation of bitrate (r) in terms of min entropy using either estimation of bit guessing probability based on the violation of CH inequality or decomposition of correlations in non-signalling polytope in the control unit (CU), f) comparing if the number Next(b, r) of possible to extract fully random bits from s raw bit string (b) estimated using bitrate (r) is higher than the number of fully random bits requested, while if yes the control unit (CU) outputs the raw random bit string (b) and calculated bitrate (r) or performs on them a randomness extraction protocol and outputs (br), otherwise steps a)-f) are repeated adding the new data to the data obtained in the previous repetitions.
5. The method according to claim 4, wherein the method for self-test comprises steps: - estimating in the control unit (CU) probabilities P(ab|x,y) of obtaining result a in station A upon chosen measurement setting x and result b in station B upon chosen measurement setting y as frequencies of their appearance in the obtained data, - estimating in the control unit (CU) bitrate (r) using one of the following steps: i. estimation through violation of CH inequality: • estimating in the control unit (CU) probabilities PA(a|x) (PB(b|y)) of obtaining the result a(b) in station A(B) upon chosen measurement setting x(y) and estimates the CH expression: CH = P 00 on on + P 00 on off + P 00 off on − P 00 off off − P A 0 on − P B 0 on , • the control unit (CU) preferably computes: r = − log 2 1 − CH 0.1086 + CH 0.2172 , ii. estimation through decomposition of correlations into non-signalling polytope: • estimating in the control unit (CU) the maximal probability pdet of contribution of local boxes in decomposition of correlations P(ab|x,y) into extremal points of non-signalling polytope, • computing in the control unit (CU) r = − log 2 p det + 1 − p det 2 .