A quantum random number generator

GB2642214BActive Publication Date: 2026-07-24KK TOSHIBA
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
GB · GB
Patent Type
Patents
Current Assignee / Owner
KK TOSHIBA
Filing Date
2024-06-26
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing quantum random number generators (QRNGs) face issues with biased output distributions, high power consumption, and vulnerability to component failures, making them unsuitable for high-speed, low-power applications and requiring resource-intensive post-processing to achieve uniformity.

Method used

A QRNG design that combines multiple independent channels with 1-bit ADCs and a processing unit, such as an XOR gate or Von Neumann randomness extractor, to generate uniformly distributed random numbers on-device, enhancing statistical randomness and robustness against component failures.

Benefits of technology

The proposed QRNG achieves reduced bias and improved statistical randomness with lower power consumption, maintaining operation even with component failures, suitable for high-speed, low-power applications without the need for extensive post-processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000001_0000
    Figure 00000001_0000
  • Figure 00000001_0001
    Figure 00000001_0001
  • Figure 00000002_0000
    Figure 00000002_0000
Patent Text Reader

Abstract

A quantum random number generator (QRNG) includes a pair of QRNG channels (A and B). Each QRNG channel generates, per clock cycle, a random bit value. The QRNG further comprises a processing unit (5,
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field Embodiments described herein relate to quantum random number generators, in particular to optical quantum random number generators. Background Random numbers are used in a variety of applications including cryptography, numerical simulations, or lotteries. Sometimes these applications use pseudorandom binary sequence (PRBS) generators. PRBS generators have limited applications because they produce a repeating string of bits with a repetition length / time that is proportional to the power consumption of the PRBS generator. This makes PRBS generators unsuitable for certain application, e.g. applications that require high-rates, long (unrepeated) sequences, and low power consumption. Truly random numbers can be produced from Quantum Random Number Generators (QRNG). In a QRNG, the source of randomness is physical and relies on the unpredictability of a measurement, and, in particular, the unpredictability relies on a quantum mechanical property. QRNGs can be implemented using gained-switched diode lasers. In gain-switched diode lasers, the lasing process is seeded by spontaneous emission, which is a quantum mechanical process, such that the phase of the emitted pulse is random. By repeatedly switching the diode laser on and off, a stream of optical pulses, each having a random phase, can be generated. By measuring the random phase of each optical pulse in the stream of optical pulses, a sequence of random numbers can be obtained. However, these random numbers are non-uniformly distributed, and subsequent complex digital post-processing is necessary to obtain uniformly distributed random numbers. Thus, there is a continuing need to improve QRNGs. Brief Description of the Drawings Embodiments of the invention will now be described, by way of example only, with reference to the accompanying schematic drawings, in which: Figure 1 is a schematic illustration of a QRNG according to a comparative example; Figure 2 shows a simulated intensity distribution of an optical pulse; Figure 3 is a schematic illustration of a QRNG according to an embodiment; Figure 4 illustrates a debiasing effect of an exclusive OR gate; Figure 5 is schematic illustration of an example QRNG channel; Figure 6 is schematic illustration of an implementation of the QRNG of Figure 3; Figure 7 is schematic illustration of a further example QRNG channel; Figure 8 is schematic illustration of a further implementation of the QRNG of Figure 3; and Figures 9 and 10 are schematic illustrations of further example QRNGs according to embodiments. To avoid unnecessary repetition, like reference numerals will be used to denote like features in the figures. Detailed Description The present disclosure aims to provide new and useful Quantum Random Number Generators (QRNG). Before describing proposed embodiments relating to QRNGs, a design of an optical QRNG will now be described in detail with reference to Figure 1. This design employs a laser that emits optical pulses into an input port of a time delay interferometer (here an asymmetric Mach Zehnder interferometer (AMZI)). More specifically, Figure 1 shows a portion of a conventional optical QRNG that comprises a pulsed laser P1 driven at a fixed repetition rate by a controller P2 to output a stream of pulses. When the repetition rate is low enough, each pulse from the stream of pulses may have a random phase. The pulses are coupled into the time delay interferometer P3 via an input coupler P4. The time delay interferometer P3 comprises a short and a long arm. The long arm of the time delay interferometer P3 comprises a delay element P7, which delays the pulses by a time D with respect to the pulses travelling in the short arm. In this QRNG device, the delay element P7 is configured such that the delay D introduced is such that each delayed pulse temporally overlaps with a previous reference pulse in the reference arm. The delayed and reference pulses interfere in a 2x2 coupler P5 (or beam splitter) of the time delay interferometer P3, and the interference pulse is sent to a single photodetector P6 which converts the random intensity of the interference pulse into a voltage pulse of random amplitude. This electrical signal has a random amplitude value because the phases of the reference and delayed pulses are random. Random numbers may be generated from the random intensities of the interfered pulses. To this end, the voltage pulse generated by the photodiode P6 is digitised by a high-bit analog-to-digital (ADC) converter P8 to generate a digital random number. In this example, the ADC P8 has a resolution of 8-bit. In an embodiment, a new and useful optical Quantum Random Number Generator (QRNG) is provided which at least partially overcomes problems of the device of Figure 1. For example, a problem of the device of Figure 1 is that the distribution of generated random numbers is biased, i.e. not uniform (i.e. the device has a tendency to output particular outcomes). This bias is caused by the inherently non-uniform intensity distribution of the interference pulse which follows an arcsine distribution as illustrated in Figure 2 (which shows (simulated) normalised intensity values detected by the photodiode P6 and digitised into an 8-bit value by the high-bit ADC P8). It can be seen that the probability distribution is not flat but that the values near the ends of the distribution (e.g. the values “0.0” and “1.0”) have higher probabilities than the values in the centre of the distribution. The output of the device of Figure 1 can be further biased by any mismatch between the dynamic range of the high-bit ADC P8 and the intensity distribution of the interference pulse (this bias may drift during the lifetime of the device, e.g. because of laser power drifts, aging of the photodiode, and so forth). Biased random numbers have limited applications (e.g. randomness tests often require uniformly distributed random numbers), and thus frequently it is necessary to apply downstream postprocessing to increase the uniformity of the random numbers. This can be achieved by applying suitable mathematical smoothing functions (such as a finite impulse response (FIR) filter or a Toeplitz matrix). However, applying such smoothing functions to flatten the highly non-uniform distribution of Figure 2 is undesirably resource-intensive (e.g. computationally and power intensive). Further, it is undesirable that such post-processing steps need to be performed off-device, i.e. by the receiver of the output of the device of Figure 1. To this end, the present disclosure proposes a device that combines (on-device and in a resource-friendly manner) the outputs of two or more independent QRNGs (referred to as independent “QRNG channels”) to output random numbers without (significant) bias (i.e. with improved statistical randomness of the output compared to the device of Figure 1 )and without relying on resource-intensive smoothing functions. Another problem of the device of Figure 1 is that the device stops working (i.e. stops outputting random numbers) when one of the components fails (e.g. when the laser or the photodetector are damaged). To this end, embodiments are proposed in which the outputs of the QRNG channels are combined such that, when one QRNG channel fails (due to a component failure), the device keeps outputting random numbers (generated from the outputs of the at least one other QRNG channels) - making the device robust against (single) component failure. Yet another problem of the device of Figure 1 is that, similar to the aforementioned PRBS generators, it is unsuitable for low-power, high-speed applications. This is because highspeed, high-bit ADCs have a high power consumption. To this end, the present disclosure proposes a device in which each QRNG channel uses, instead of a high-bit ADC, a comparator (i.e. a 1 -bit ADC) that has a much lower power consumption. In an embodiment, a quantum random number generator (QRNG) is provided. The QRNG comprises: i) a pair of QRNG channels, each QRNG channel configured to generate, per clock cycle, a random bit value; and ii) a processing unit configured to process the random bit values from the QRNG channels to generate, per clock cycle, a random output bit value having a lower bias than the random bit values from the QRNG channels. In an embodiment, the processing unit may comprise an exclusive OR gate (XOR gate) configured to receive, as input the random bit values from the QRNG channels, and to generate the random output bit value. Alternatively, the processing unit may be further configured to process the random bit values from the QRNG channels, using a Von Neumann randomness extraction algorithm, to generate the random output bit value. In an embodiment, each QRNG channel may comprise a light source configured to generate, per clock cycle, an intensity-randomised optical pulse, an optical detector optically coupled to the light source and configured to generate an analog signal indicative of the intensity of the intensity-randomised optical pulse, a reference voltage source configured to generate a reference voltage, and a comparator circuit configured to generate the random bit value for the respective clock cycle from the analog signal of the optical detector and the reference voltage. In an embodiment, the light source of each QRNG channel may be configured to generate, per clock cycle, the intensity-randomised optical pulse from at least one phase-randomised pulse. In an embodiment, the light source of each QRNG channel may comprise a laser configured to emit a stream of phase-randomised pulses, and a time delay interferometer to pairwise interfere the pulses emitted by the laser to generate the intensity-randomised optical pulse. In an embodiment, the light source of each QRNG may comprise a first laser configured to emit a stream of phase-randomised pulses, a second laser configured to emit coherent light in a continuous operation mode, and an interference unit to interfere a phase-randomised pulse from the first laser with coherent light from the second laser to generate the intensity-randomised optical pulse. In an embodiment, the light source of each QRNG may comprises a first and a second laser (each laser configured to emit a stream of phase-randomised pulses), and an interference unit to interfere a phase-randomised pulse from the first laser with a phase-randomised pulse from the second laser to generate the intensity-randomised optical pulse. In an embodiment, the laser may be configured to emit a stream of phase-randomised pulses is a gain-switched semiconductor laser. In an embodiment, the QRNG may further comprise at least one further QRNG channel. As an example, the pair of QRNG channels may be a first pair of QRNG channels, and the QRNG further comprises (at least) a second pair of QRNG channels. In an embodiment, the processing unit may be configured to process the random bit values from the QRNG channels of the first pair of QRNG channels and the random bit values from the QRNG channels of the second pair of QRNG channels to generate, per clock cycle, a random output bit value having a lower bias than the random bit values from the QRNG channels. In an embodiment, the processing unit may comprise a first, second and third exclusive OR gate (XOR gate). The first XOR gate may be configured to receive, as input, the random bit values from the QRNG channels of the first pair of the QRNG channels, and to generate a first intermediate random bit value. The second XOR gate may be configured to receive, as input, the random bit values from the QRNG channels of the second pair of the QRNG channels, and to generate a second intermediate random bit value. The third XOR gate may be configured to receive, as input, the first and second intermediate random bit values to generate the random output bit value. In an embodiment, the processing unit may be configured to process the random bit values from each QRNG channel to generate, per clock cycle, a random output bit value for each pair of QRNG channels, the random output bits having a lower bias than the random bit values from the respective QRNG channels. In an embodiment, the QRNG may be implemented as an integrated device. In an embodiment, the processing unit may be implemented by a field programmable gate array, FPGA. Figure 3 shows an example optical quantum random number generator (QRNG) 1 according to an embodiment. In general, the QRNG 1 is “clocked” device, i.e. the QRNG 1 operates at a fixed clock rate (e.g. at a clock rate of at least 1 GHz). More specifically, the QRNG 1 is configured to generate (and output) a single random bit value at each clock cycle (i.e. in each clock cycle, the QRNG 1 outputs a binary (or digital) electrical signal indicative of the bit value for the clock cycle). This means that, during operation, the QRNG 1 outputs a sequence of single random bits which are temporally spaced apart by one clock cycle. The QRNG 1 is typically provided as an integrated device (and described as such in the following), i.e. the components of the device 1 are integrated on a common semiconductor substrate (or on multiple semiconductor substrates that are appropriately assembled / connected). However, in other embodiments, the QRNG 1 may also be implemented using discrete components (e.g. optical fibre pigtailed or free-space components). The QRNG 1 comprises two identical QRNG channels (denoted QRNG channels “A” and “B” in Figure 3). Each QRNG channel is a 1-bit QRNG by itself, i.e. each QRNG channel is configured to generate a single random bit value at each clock cycle. The QRNG channels A and B are independent from each other. This means that a random bit value generated by channel A is uncorrelated to a random bit value generated by channel B (and vice versa). In some implementations, the distribution of the bit values generated by channel A (and / or channel B) may be biased (i.e. the probability for generating a “0” value may be different from the probability for generating a “1” value). In general, the QRNG channels A and B may be implemented using any suitable QRNG technique. In the embodiment of Figure 3, the QRNG channels A and B are configured to generate random bits from intensity measurements of intensity-randomised optical pulses. More specifically, each QRNG channel comprises a respective light source 2 configured to generate an intensity-randomised optical pulse at each clock cycle (i.e. an optical pulse having randomised intensity values; the pulse having randomised intensity values may have a non-uniform distribution of intensity values, e.g. an arcsine distribution). Each QRNG channel further comprises a respective optical detector 3 (e.g. a (fast) photodiode optically coupled (e.g. via an integrated waveguide) to the light source 2 to receive the intensity-randomised optical pulses from the respective light source 2. Each optical detector 3 is configured to generate an electrical analog signal (e.g. a voltage pulse) indicative of the intensity of the received intensity-randomised optical pulse. Each QRNG channel further comprises a respective comparator 4 (i.e. a 1-bit ADC) coupled to the respective optical detector 3. Each comparator 4 is configured to convert the received electrical analog signal into a digital signal (i.e. into a binary signal). To this end, the comparator 4 may be configured to compare a magnitude of the received analog signal to a reference analog signal (e.g. a reference voltage signal) and to generate the digital output signal based on the comparison (e.g. if the magnitude of the received analog signal exceeds the reference analog signal, the comparator 4 may generate a digital signal corresponding to a logic “1” value; if the magnitude of the received analog signal does not exceed the reference analog signal, the comparator 4 may generate a digital signal corresponding to a logic “0” value). The QRNG 1 may comprise circuitry to generate the references voltages for the comparators 4 of the QRNG channels A, B. In some implementations, the QRNG 1 may be configured to provide the same reference analog signal to the comparators 4 of both QRNG channels A, B. In other implementations, the QRNG 1 may be configured to provide the different reference analog signals to the comparators 4 of the QRNG channels A, B (i.e. to take into account channel-specific manufacturing variations, channel-specific aging effects, and so forth). The QRNG 1 further comprises a real-time processing unit 5 configured to generate, as output of the QRNG 1, a single random binary number from the outputs of the QRNG channels A, B. The term “real-time” is used here to indicate that the processing unit 5 processes the outputs of the QRNG channels A, B when they become available (i.e. the processing unit 5 does not process a stored list of previously generated random values but rather processes the outputs of the QRNG channels A, B on the fly). In particular, the processing unit 5 may be configured to, for each clock cycle, i) receive one “fresh” random bit from each QRNG channel A, B (i.e. the processing unit 5 may receive the respective random bits that the QRNG channels A, B have generated in the directly preceding clock cycle) and ii) output a single random bit based on the two received random bits. It is to be understood that the output of the processing unit 5 may (deterministically) depend on the corresponding input values to the processing unit 5 (i.e. the corresponding outputs of the QRNG channels A, B), but may not depend on previously received input values or generated output values (e.g. the processing unit 5 may not store and rely on any history data, e.g. previously received input values or generated output values). In broad terms, the distribution of the random output values generated by the processing unit 5 has a reduced bias compared to the outputs of the QRNG channels A, B, i.e. the output generated by the processing unit 5 has an improved statistical randomness compared to the outputs of the individual QRNG channels A, B. This makes the QRNG 1 resilient to bias of individual QRNG channels, and thus lowers the manufacturing and operating tolerances for the individual QRNG channels (e.g. operating parameters (such as the reference analog signal provided to the comparator) may not need to be dynamically corrected during the lifetime of the device). Many possibilities of combining the 1 -bit outputs of the QRNG channels A, B to generate a random bit with lower bias exist. In one possibility, the processing unit 5 comprises an exclusive OR logic gate (“XOR gate” hereafter). The XOR gate may be configured to receive the outputs of the QRNG channels A, B and generate an output based on the following truth table: QRNG channel A QRNG channel B XOR gate output: X= A ® B 0 0 0 0 1 1 1 0 1 1 1 0 From the above truth table, it can be seen that the output of the XOR gate is random if one or both input values are random. Further, the output of the XOR gate may have a reduced bias compared to the bias of the inputs as illustrated in Figure 4. Figure 4 shows in panel 40 an example distribution of the output values generated by QRNG channel A, in panel 41 an example distribution of the output values generated by QRNG channel B, and in panel 42 a resulting output distribution of the XOR gate. It can be seen that, in this example, both QRNG channels are biased towards outputting a “0” value (i.e. the probability for “0” is higher than the probability for “1” in panels 40 and 41). It can be further seen that the output of the XOR gate does not exhibit any significant bias. In some implementations, using the XOR gate is further advantageous because the XOR gate can be implemented with power-efficient circuitry, i.e. the XOR gate provides a stage of processing the random bits generated by the QRNG channels A, B with little additional power consumption. In some implementations, using the XOR gate may make the QRNG robust against component failure. For example, a failure of the light source 2 in QRNG channel B may mean that the channel generates only “0” value bits instead of random bit values (because no optical pulses are generated and thus the intensity measured at the respective photodetector is zero for each clock cycle following the failure of the light source). In this case, the output of the XOR gate (and thus the output of the QRNG) is still random due to the random bits provided by the QRNG channel A. In another possibility, the processing unit 5 is configured to implement a Von Neumann randomness extractor algorithm (e.g. instead of using the above described XOR gate). An example Von Neumann randomness extractor algorithm may i) if the input bits match, generate no output, and ii) if the input bits differ, generate the bit value of the channel A as output bit, i.e. following truth table: QRNG channel A QRNG channel B XOR gate output: X= A ® B 0 0 No output 0 1 0 1 0 1 1 1 No output This means that, in some implementations when the processing unit 5 is configured to implement a Von Neumann randomness extractor algorithm, the QRNG 1 may not generate an output for every clock cycle. In these cases, the QRNG 1 may be configured to provide, as a further output, a signal indicating whether an output signal has been generated. In some implementations, using a Von Neumann randomness extractor algorithm instead of an XOR gate may result (at the expense of output bit rate) in an even lower bias at the output; in particular, when the initial biases of the QRNG channels are similar (e.g. substantially equal). The processing unit 5 may be implemented in any suitable manner, i.e. a variety of circuitry may be used, including dedicated logic integrated circuits (e.g. a dedicated XOR-gate integrated circuit), programmable logic devices (PLDs) (e.g. field programmable gate arrays (FPGAs)), application specific integrated circuits (ASICs), and so forth. In some implementations in which the processing unit 5 is implemented using a FPGA, the FPGA may (advantageously) provide further processing (e.g. resulting in a compact device). For example, the FPGA may provide the clock signals to the QRNG channels (e.g. to the light sources and comparators of the QRNG channels. The FPGA may further process the generated output random bits to distribute the output bits to high-speed peripherals (such as Ethernet or USB3) where the bit stream may be sent to application(s) via commonly used protocols (e.g. through streaming or packetization). With reference to Figure 5, an example implementation of the QRNG channels A, B of Figure 3 will now be described. In broad terms, the QRNG channel 50 of Figure 5 generates random bits based on a phase diffusion technique. More specifically, the QRNG channel 50 extracts a random bit from an intensity measurement of an intensity-randomised pulse generated by interference of two phase-randomised optical pulses. The QRNG channel 50 of Figure 5 comprises (as light source 2) a gain-switched semiconductor laser diode 51 (e.g. a distributed feedback (DFB) diode laser) optically coupled to an input port of an input coupler of a time-delay interferometer 52. The laser 51 is configured to emit a stream of phase-randomised pulses (i.e. one pulse per clock cycle). The phase difference between two consecutive pulses is only truly random if there is no phase coherence between consecutive pulses generated by the laser 51. For a semiconductor gain-switched laser (such as laser 51), the laser emission is started by spontaneous emission. This is a random process, which means that the phase of the generated long light pulse will be random. In order that the random process of spontaneous emission is responsible for starting the laser emission for all pulses, the laser cavity needs to be completely empty before each light pulse is generated, i.e. the applied current needs to be below the threshold current for a sufficiently long time in between long pulses. In order to switch the laser 51 above and below its lasing threshold, a controller unit of the QRNG (not shown) may supply a time varying current to an AC input of a bias-T 53 connected to the laser 51 (i.e. the time varying current acts as clock signal for the laser 51). In the example of Figure 5, a signal generator 54 is configured to provide the time varying current. In one embodiment, the time varying current has a square type wave form, for example with a frequency (i.e. clock rate) of 1 GHz. A DC bias current may be supplied to a DC input of the bias T 53. The laser 51 is optically coupled to an input port of an input coupler of the time delay interferometer 52 (i.e. an asymmetric Mach-Zehnder interferometer in this example). The input coupler may be a 1x2 coupler (as depicted in Figure 5) or a 2x2 coupler. The time delay interferometer 52 comprises a short and a long arm. The long arm of the time delay interferometer 52 comprises a delay element, which delays the pulses by a time T (that matches the temporal spacing between two consecutive pulses) with respect to the pulses travelling in the short arm. Thus, the delay element is configured such that the introduced delay is such that each delayed pulse temporally overlaps with a subsequent pulse in the short arm. The delayed and the subsequent pulses interfere at an output-coupler of the time delay interferometer 55, and an interfered pulse is sent to a photodiode 55 (corresponding to the detector 3 of Figure 3). In other words, the time delay interferometer 52 is configured to enable pairwise interference of subsequently emitted pulses (to generate the intensity-randomised optical pulse). More specifically, the delay element may be configured such that the introduced delay is equal to N*T, where N is a positive integer number (N >1) and T is the repetition time (i.e. T = 1 / co, where co is the clock rate). In some implementations, N=1. In other implementations, N>1, e.g. N = 2, N = 3, N =4, and so forth (using N >1 may be particularly advantageous in cases where directly subsequent pulses exhibit (undesired but sometimes hard to avoid) correlations). The output coupler may be a 1x2 coupler (as depicted in Figure 5) or a 2x2 coupler (in implementations where the output coupler is 2x2 coupler, the other output port of the 2x2 output-coupler may be coupled to a photodetector for monitoring the intensity distribution of the complementary interference pulse). In some implementations, the time delay interferometer 52 may be configured to that the intensities of the delayed pulse and the pulse in the short arm are substantially equal at the output coupler (to ensure complete interference). To this end, one or both of the arms of the time delay interferometer may comprise one or more optical attenuators and / or optical amplifiers (e.g. to compensate for additional losses in the long arm). In addition or alternatively, the input coupler (and / or the output coupler) may be configured to have an unbalanced coupling ratio (to ensure complete interference at the output coupler). The photodiode 55 is coupled to a clock gated comparator 56. The comparator 56 is configured to receive i) an electrical analog pulse generated by the photodiode 55 in response to detecting the interference pulse, ii) a reference (or “threshold”) voltage signal, and, at a gate input of the comparator 56, a clock signal. The reference voltage signal may be generated by a corresponding voltage source of the QRNG (not shown). The clock signal for the gated comparator 56 may be provided by the signal generator 54. As indicated in Figure 5, the clock signal for the comparator 56 may be appropriately delayed to synchronise the comparator 56 with the arrival of the electrical analog pulses from the photodiode 55, e.g. so that the comparator 56 is (only) enabled when the electrical analog pulses generated by the photodiode 55 have propagated to the comparator 56. The comparator 56 is configured to, when enabled by the clock signal, sample a voltage amplitude of the pulse from the photodiode, compare the sample voltage to the reference voltage signal and generate a digital signal based on the comparison (e.g. if the voltage of the received photodiode pulse exceeds the reference voltage, the comparator 56 may generate a digital signal corresponding to an “1” value; if the voltage of the photodiode pulse does not exceed the reference voltage, the comparator 56 may generate a digital signal corresponding to an “0” value). It is to be understood that the reference voltage may be selected to be in the centre of the intensity distribution of the interference pulse. In some implementations, the QRNG channel 50 may be robust against small fluctuations / drifts in the intensity distribution of the interference pulse. This is because the threshold for biasing the comparator to achieve an even distribution of “0” and “1” outputs is relatively insensitive at the centre of the arcsine-shaped intensity distribution (Figure 2). The simplicity and elegance of using a comparator biased with a reference voltage generated from a voltage source may be further understood by considering a comparative arrangement in which the intensity of the complementary interference pulse is measured by a second photodiode (i.e. the pulse entering at a second output port of the time delay interferometer) and the corresponding voltage pulse is fed into the comparator instead of the reference voltage. This comparative example is not only undesirably more complex (e.g. because of the second photodiode) but also more prone to bias in the output bits because of signal variations caused by aging effects associated with the second photodiode (voltages sources are often less prone to aging-induced drifts compared to photodiodes). Figures 6 illustrates an implementation of the QRNG of Figure 3 where both QRNG channels A, B are implemented using the design of the QRNG channel 50 of Figure 5. The QRNG 60 of Figure 6 comprises (as processing unit 5) an XOR logic gate 61. Although the example QRNG channel of Figures 5 has been described as comprising, as time delay interferometer, an asymmetric Mach-Zehnder interferometer, it is to be understood that other implementations of the QRNG channel may comprise a different type of interferometer (instead of the asymmetric Mach-Zehnder interferometer) suitable to convert phase-randomised pulses into intensity-randomised pulses (e.g. a Michelson interferometer; in this case the input and output coupler may be the same component) - or no interferometer at all as described below. With reference to Figure 7, a further example implementation of the QRNG channels A, B of Figure 3 will now be described. The QRNG channel 70 of Figure 7 is identical to the QRNG channel 50 of Figure 5, except that the QRNG channel 70 comprises, instead of the time delay interferometer, a second laser 71 (e.g. a DFB diode laser). The second laser 71 may be configured to emit coherent light at substantially the same optical frequency as the first laser 51. To this end, the QRNG may comprise control circuitry (not shown) to control and stabilise the optical frequencies of the lasers 51,71. The first laser 51 and the second laser 71 are optically coupled to a coupler (an “interference unit”), depicted as a 2x1 coupler in the example of Figure 7. An output of the coupler is optically coupled to the photodiode 55. The signal generated by the photodiode 55 is processed by the comparator 56 as described above with reference to Figure 5. The second laser 71 may be configured to emit a stream of phase-randomised pulses (i.e. one pulse per clock cycle) or may be configured to emit coherent light in (quasi-)continuous-wave mode. Thus, for each clock cycle, a phase-randomised pulse from the first laser 51 interferes, at the coupler, with coherent light emitted from the second laser 71 (i.e. either with a phase-randomised pulse or with continuously emitted coherent light from the second laser 71) to generate an intensity-randomised optical pulse which is guided to the photodiode 55. In some implementations, the QRNG channel 70 may enable more compact designs compared to the QRNG channel 50 of Figure 5 since no time delay interferometer is needed (at the cost of providing an additional laser). Figures 8 illustrates an implementation of the QRNG of Figure 3 where both QRNG channels A, B are implemented using the design of the QRNG channel 70 of Figure 7. The QRNG 80 of Figure 8 comprises (as processing unit 5) an XOR logic gate 81. The proposed QRNG may comprise more than two QRNG channels, e.g. to improve the security (unpredictability of the sequence) or to increase the random bit generation rate. As one example, in some implementations, the QRNG may comprise three QRNG channels A, B, C. In this case, the QRNG may comprise a processing unit that comprises a first XOR gate to combine the outputs of QRNG channels A and B (as described above) and a second XOR gate to combine the output of the first XOR gate and the output of the QRNG channel C. Further example variations will now be described with reference to Figures 9 and 10. Figure 9 shows an example QRNG 90 which comprises a plurality of pairs of QRNG channels. More specifically, the QRNG 90 comprises a first pair of QRNG channels (denoted QRNG channels A and B in Figure 9) and a second pair of QRNG channels (denoted QRNG channels C and D in Figure 9). It is to be understood that the QRNG 90 may comprise further pairs of QRNG channels. The individual QRNG channels may be implemented as described above with reference to Figures 3 to 8. The QRNG 90 comprises a processing unit 91 configured to receive, in each clock cycle, a random bit from each of the QRNG channels and process the received bits to generate, as output of the QRNG 90, a (single) random output bit. To this end, the processing unit 91 may comprise a plurality of XOR logic gates arranged in a “serial” (or “cascaded”) combination as illustrated in Figure 9. In general, the processing unit 91 may comprise multiple processing stages. For example, the processing unit 91 may comprise a first stage in which the outputs of the QRNG channels belonging to the same pair are combined (e.g. XOR gate 92 combines the output bits of QRNG channels A and B; XOR gate 93 combines the output bits of QRNG channels C and D). The processing unit 91 may comprise one or more further processing stages in which the outputs of the previous stage are further combined via XOR gates until the single random output bit is obtained (e.g. XOR gate 94 combines the outputs of the XOR gates 92 and 93). In some implementations, the use of additional QRNG channels (compared to QRNG 1 of Figure 3) may not only improve the unpredictability of the generated output sequence but also further improve the robustness of the device against component failure. Figure 10 shows an example QRNG 100 which, similar to QRNG 90 of Figure 9, comprises a plurality of pairs of QRNG channels. In this example, the additional pairs of QRNG channels are used to increase the random bit generation rate, in particular the number of random bits generated per clock cycle (i.e. the QRNG 100 generates more than 1 random bit per clock cycle). The QRNG 100 comprises a processing unit 101 configured to receive, for each clock cycle, a random bit from each of the QRNG channels and process the received bits to generate, as output of the QRNG 100, a sequence of random bits consisting of 1 random output bit per pair of QRNG channels. Like the processing unit 91 of Figure 9, the processing unit 101 may comprise a first stage in which the outputs of the QRNG channels belonging to the same pair are combined (e.g. XOR gate 92 combines the output bits of QRNG channels A and B; XOR gate 93 combines the output bits of QRNG channels C and D). Unlike the processing unit 91 of Figure 9, the processing unit 101 may further comprise a serializer circuit 102 configured to convert the outputs of the XOR gates of the first processing state into a binary output sequence. Whilst certain embodiments have been described, these embodiments have been presented by way of example only, and are not intended to limit the scope of the inventions. Indeed, the novel devices, and methods described herein may be embodied in a variety of other forms; furthermore, various omissions, substitutions and changes in the form of the devices, methods and products described herein may be made without departing from the spirit of the inventions. The accompanying claims and their equivalents are intended to cover such forms or modifications as would fall within the scope and spirit of the inventions.

Claims

:

1. A quantum random number generator, QRNG, comprising:a pair of QRNG channels, each QRNG channel configured to generate, per clock cycle, a random bit value and comprising:5 a light source configured to generate, per clock cycle, an intensity-randomisedoptical pulse;an optical detector optically coupled to the light source and configured to generate an analog signal indicative of the intensity of the intensity-randomised optical pulse;a reference voltage source configured to generate a reference voltage; and10 a comparator circuit configured to generate the random bit value for therespective clock cycle from the analog signal of the optical detector and the reference voltage;a processing unit configured to process the random bit values from the QRNG channels to generate, per clock cycle, a random output bit value having a lower bias than the random bit values from the QRNG channels.

152. The QRNG of claim 1, wherein the processing unit comprises an exclusive OR gate, XOR, configured to receive, as input the random bit values from the QRNG channels, and to generate the random output bit value.20 3. The QRNG of claim 1, wherein the processing unit is further configured to process therandom bit values from the QRNG channels, using a Von Neumann randomness extraction algorithm, to generate the random output bit value.25 4. The QRNG of any preceding claim, wherein the light source of each QRNG channel isconfigured to generate, per clock cycle, the intensity-randomised optical pulse from at least one phase-randomised pulse.

5. The QRNG of claim 4, wherein the light source of each QRNG channel comprises:30 a laser configured to emit a stream of phase-randomised pulses; anda time delay interferometer to pairwise interfere the pulses emitted by the laser to generate the intensity-randomised optical pulse.

6. The QRNG of claim 4, wherein the light source of each QRNG comprises:35 a first laser configured to emit a stream of phase-randomised pulses;a second laser configured to emit coherent light in a continuous operation mode;24and an interference unit to interfere a phase-randomised pulse from the first laser with coherent light from the second laser to generate the intensity-randomised optical pulse.

7. The QRNG of claim 4, wherein the light source of each QRNG comprises:5 a first and a second laser, each laser configured to emit a stream of phase-randomised pulses; and an interference unit to interfere a phase-randomised pulse from the first laser with a phase-randomised pulse from the second laser to generate the intensity-randomised optical pulse.10 8. The QRNG of any one of claims 5 to 7, wherein the laser configured to emit a streamof phase-randomised pulses is a gain-switched semiconductor laser.

9. The QRNG of any preceding claim, wherein the QRNG further comprises at least one further QRNG channel.1510. The QRNG of any preceding claim, wherein the pair of QRNG channels is a first pair of QRNG channels, and the QRNG further comprises a second pair of QRNG channels.

11. The QRNG of claim 10, wherein the processing unit is configured to process the 20 random bit values from the QRNG channels of the first pair of QRNG channels and the random bit values from the QRNG channels of the second pair of QRNG channels to generate, per clock cycle, a random output bit value having a lower bias than the random bit values from the QRNG channels.25 12. The QRNG of claim 11, wherein the processing unit comprises a first, second and thirdexclusive OR gate, XOR gate, and wherein:the first XOR gate is configured to receive, as input, the random bit values from the QRNG channels of the first pair of the QRNG channels, and to generate a first intermediate random bit value;30 the second XOR gate is configured to receive, as input, the random bit values from theQRNG channels of the second pair of the QRNG channels, and to generate a second intermediate random bit value, andthe third XOR gate is configured to receive, as input, the first and second intermediate random bit values to generate the random output bit value.3513. The QRNG of claim 10, wherein the processing unit is configured to process the random bit values from each QRNG channel to generate, per clock cycle, a random output bitvalue for each pair of QRNG channels, the random output bits having a lower bias than the random bit values from the respective QRNG channels.

14. The QRNG of any preceding claim, wherein the QRNG is implemented as an 5 integrated device.

15. The QRNG of any preceding claim, wherein the processing unit is implemented by a field programmable gate array, FPGA.10LD