Random number generator
Patent Information
- Application Number
- GB2025002043
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2026-10-07
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
The present disclosure relates to a random number generator and a method for generating random numbers. In particular, but not exclusively, the method relates to a random number generator and method that generate random numbers which are certified as they are created. Random numbers are used in a wide variety of applications, such as encryption, online gaming, scientific modelling (for example, Monte Carlo simulations), high frequency automated share trading, probabilistic computing and the like. In many of these applications, it is important for the numbers to be truly random, so they cannot be predicted by third parties. Classical (pseudo) random number generators are implemented in software-based algorithms or classical based noisy physical processes, which can be predicted and / or influenced. Quantum mechanics, on the other hand, is a fundamentally random process, and thus random number generators based on quantum mechanical effects are an area of significant activity. Certification or validation of a quantum random number generator confirms that the distribution of numbers is truly random and allows the numbers to be provided for further uses with confidence. WO 2018 / 087516 discloses one method for generating random numbers and certifying that the process by which the numbers are generated is quantum in origin, so the numbers are truly random. The method includes: mixing a bright quantum state in a first mode with a vacuum input, in a two mode transformation for mixing the first mode and an orthogonal second mode; after mixing, detecting the intensity in the first mode, and the second mode; generating random numbers based on the difference between the detected intensity of the first mode and the second mode; and simultaneously to generating random numbers, certifying the numbers as random, based on the sum of the detected intensity of the first mode and the second mode. WO 2018 / 087516 discloses generating a binary string from the statistical distribution of the difference between the number of particles in the different mode. The binary string is provided to a random number extractor which uses a seed to generate random numbers. According to a first aspect, there is provided a random number generator having: a source arranged to propagate bosons along or substantially along an axis; a diffraction screen placed along the axis, the screen having one or more apertures arranged to diffract bosons from the source; two or more detectors each arranged to detect the number or intensity of bosons falling thereon, the detectors provided in a detection plane spaced from the screen such that spatial distribution of bosons diffracted by the screen forms a diffraction pattern at the detection plane; and circuitry arranged to generate random numbers based on the difference in or ratio of the number or intensity of bosons detected by different detectors; and certify the numbers as random based on the total number or intensity of bosons detected by the different detectors. The one or more apertures in the diffraction screen may comprise a single pinhole to diffract bosons incident on the screen. The random number generator may include: a comparator to compare an output signal based on the difference in or ratio of the number or intensity of bosons detected by different detectors against a reference at different times to generate a digital time series of random numbers, each comparison providing a bit in the series. The detectors may be arranged such that for a plurality of measurements taken over a time averaged period, substantially the same number or intensity of bosons falls on each detector. The random numbers may be generated based on the difference in or ratio of the number or intensity of bosons detected by different detectors at a given time. The ratio between the number or intensity of bosons detected a first detector and a second detector over the time averaged period may be between 50:50 and 80:20. Each detector may be arranged to detect number or intensity of bosons incident on a portion of the detection plane, the detectors being the same size as each other. Each detector may comprise a multi-pixel detector arranged to combine the output from the pixels into a single output of the detector. The detectors may be arranged symmetrically around a centreline or centre point of the detection plane. The centreline or centre point may be defined along a straight line from the source, through a centre point of the apertures in the diffraction screen. The random number generator may include only two detectors. The two detectors may abut each other in the detection plane such that the detector cover a contiguous detection area on the detection plane. The source may be arranged to operate at an intensity such that the intensity or number of bosons falling on the detectors is below the intensity required for the detectors to reach saturation and above a minimum detection threshold for the detectors. The random number generator may comprise hardware circuitry arranged to: generate an output signal based on the difference in or ratio of the number or intensity of bosons detected by different detectors, the output signal for generating random numbers; and generate a validation signal based on the total of the number or intensity of bosons detected the detectors, the validation signal for certifying the numbers as random. The numbers may be certified as random at the same time as the numbers are generated. The random number generator may include: a comparator arranged to compare an output signal based on the total number or intensity of bosons detected by the detectors to a second reference to certify the numbers. The random number generator may be arranged to measure a dark current of the detectors from the outputs of the detectors, wherein the dark current is incorporated in certifying the random numbers. According to a second aspect of the invention, there is provided a method of generating random numbers, the method including: diffracting bosons onto a detection plane; detecting bosons falling on the detection plane at a least two different positions; generating random numbers based on the difference in or ratio of the number or intensity of bosons detected at the different positions; and certifying the numbers as random based on the total number or intensity of bosons detected at the different positions. The bosons may be diffracted through a pinhole. Generating random numbers based on the difference in or ratio of the number or intensity of bosons detected at the different positions may comprise: at different times, comparing the difference in or ratio of the number or intensity of bosons detected at different positions against a reference; and generating a digital time series of random numbers, each comparison providing a bit in the series. Averaged over a time period, substantially equal numbers or intensity of bosons may fall on the different positions. The bosons falling on the detection plane at each position may be detected over a region, each region having the same size. The two or more positions may be arranged symmetrically around a centreline or centre point of the detection plane, the centreline or centre point defined along a straight line from a source of the bosons, through a centre of apertures in a diffraction screen used to diffract the bosons. The bosons may be detected in only two different positions. The numbers may be certified as random at the same time as the numbers are generated. Certifying the numbers as random based on the total number or intensity of bosons detected at the different positions may comprise: comparing an output signal based on the total number or intensity of bosons detected at the different positions against a reference; certifying the numbers as random based on the comparison. The random number generator is simple to implement in an integrated circuit or in any small unit. It is also simple to scale up to a device including many such generators. By leveraging diffraction, the random numbers are generated based on a quantum mechanical phenomenon that is simple to put into practice, and to certify in parallel to generating numbers. It will be appreciated that features discussed in relation to a particular aspect or embodiment may also be applied to other aspects or embodiments. Embodiments of the invention will now be described, by way of example only, with reference to the accompanying figures, in which: Figure 1 illustrates a source used to generate an entropy signal and validation signal used to generate certified random numbers; Figure 2 shows the detection plane of the source of Figure 1, facing front on; Figure 3 shows a method of generating random numbers using the source of Figure 1; Figure 4 shows a flow chart of a first embodiment of generating random numbers from the entropy signal and validation signal generated in the source of Figure 1; Figure 5 illustrates a circuit for implementing a second embodiment of generating random numbers from the entropy signal and validation signal generated in the source of Figure 1; Figure 6 illustrates a distribution of the entropy signal generated in the source of Figure 1; Figure 7A illustrates a circuit of a first embodiment for generating the entropy and validation signals from the output of the detectors in the source of Figure 1; Figure 7B illustrates a circuit of a second embodiment for generating the entropy and validation signals from the output of the detectors in the source of Figure 1; and Figure 8 illustrates the minimum entropy for different pinhole sizes in the source shown in Figure 1. Figure 1 schematically illustrates a source 1 used to generate an entropy signal 3 that is used to generate random numbers and a validation signal 5 that is used to certify the process by which the random numbers are generated, to provide a level of confidence the numbers are random. The source 1 includes a light source 7. In the example being described, the light source 7 is a laser having a wavelength of 635nm, however it will be appreciated that any suitable light source may be used. The light emitted from the light source 7 is directed along an optical axis 9 indicated by a dashed line. A diffraction screen 11 is provided along the optical axis 9, spaced from the light source by a distance xo (xo >0). In this example, the diffraction screen 11 has a single circular pinhole 13 arranged along the optical axis 9. The centre of the pinhole 13 is arranged on the axis. The diffraction screen 11 is shielded to ensure only diffracted light from the pinhole 13 passes from one side of the screen to the other, and there is no external light contribution between the diffraction screen 11 and detection plane 19. Any light incident in this region may cause systematic noise which may be predictable. Two detectors 15, 17 are arranged in a detection plane 19 spaced from the diffraction screen 11 along the optical axis 9 by a distance z. As will be discussed in more detail below, the distances xo and z, and the radius of pinhole 13 are selected so that light emitted from the light source 7 satisfies the plane wave approximation at the diffraction screen, and light falling on the detection plane satisfies the Fraunhofer diffraction condition. Figure 2 shows the detection plane 19 viewed along the optical axis 9. In the example shown, the detectors 15, 17 are multipixel charge-coupling device (CCD) detectors arranged to detect the light falling on a detection area 21 defined in the plane 19. In such detectors 15, 17, photons falling on a pixel 15’, 17’, generate a current. Each detector collects the current generated by a set of pixels covering an area of the detection plane 19. The detection plane 19 (and detection area 21) has a centre point 23 defined along the optical axis 9 and a centreline 25 extending in the plane 19, through the optical axis 9. In the example shown, the centreline 25 is vertical but this need not be the case. A first of the detectors 15 measures light falling on a rectangular portion of the detection area 21 on one side of the centreline 25. A second of the detectors 17 measures light falling on a rectangular portion of the detection area 21 on the opposite side of the centreline 25. The detectors 15,17 are the same size as each other and abut each other along the centreline 25 so the two detectors 15, 17 measure a single contiguous rectangular area. The person skilled in the art will understand that when a single photon encounters an aperture, such as the pinhole 13, the probability distribution of detecting a single photon on the detection plane 19 follows the same diffraction pattern predicted by wave theory. Therefore, at any given instant, there will be a difference between the current detected on the two detectors, assuming the photon falls on one of the detectors 15, 17. Since the detectors 15,17 are arranged symmetrically around the centreline 25 and are of the same size, then over a sufficient period of time, the time averaged current generated by the two detectors will be approximately equal due to the symmetry of the diffraction pattern generated by a pinhole 13. At a given time, the number of photons falling on the first detector 15 is Ca and the number of photons falling on the second detector 17 is Cb. The output 27, 29 of the detectors 15,17 may be the photon count or a voltage or current (Va,b / Ia.b) which are proportional to the photon current. Initially, in the below, the count will be referred to, but it will be appreciated that the voltage and current can be used in place of the photon count, without changing the underlying principle. The voltage or current may be calibrated to allow the count to be extracted (within calibrated error bounds), or the values of the voltage and current may simply be used. The random number source 1 includes a signal processing module 31 which takes the outputs 27, 29 and generates the entropy signal 3 corresponding to the difference in the number of particles falling on each detector at a given time (Ca - Cb) and the validation signal 5 corresponding to the total number of particles falling on the two detectors (Ca + Cb). Thus, the output from the random number source 1 will be an analogue entropy signal 3 having a time series of outputs corresponding to Ca - Cb and an analogue validation signal having a time series of outputs corresponding to Ca + Cb). Over a sufficient number of measurements of Ca - Cb, a symmetric distribution centred on Ca - Cb = 0 will be obtained. The distribution may be approximated by any suitable distribution. For example, the distribution may be approximated by a Gaussian distribution, a Binomial distribution or a Poisson distribution. The entropy of the system is given by: Hmin = -log2P(CA, CB) = -log2 EQN 1 CA‘CB‘ Where Ra and Rb are the proportions of the detection area covered by each detector 15, 17. Therefore, in the above example where the detectors are the same size, Ra = Rb = 0.5. As discussed above, when a single photon encounters a pinhole 13, the probability distribution of detecting the photon at various points across the detection plane 19 is the same as the diffraction pattern from wave theory. In the example discussed above, the detectors 15,17 are arranged such that each photon will fall on one or the other of the detectors 15, 17. When the detectors 15, 17 are of equal size, cover the entire detection area 21 and symmetrically along the centreline 25 of the detection area 21, there is an equal chance that each individual photon will be detected on the first detector 15 or the second detector 17. Since the photons can be randomly detected at either detector 15, 17 Ca and Cb will vary randomly over time, and so Ca - Cb will also vary randomly. When the total number of photons incident on the screen does not vary over time, Ca and Cb are dependent on each other, but Ca - Cb still varies. When the total number of photons incident on the screen does vary over time, there is an additional factor in the randomness. The randomness in the variation of Ca and Cb is a result of the quantum mechanical nature of diffraction. Therefore, the difference between Ca and Cb is unpredictable. Thus, the diffraction provides a source of entropy for random number generation. As will be discussed in more detail below, Ca + Cb can be used to certify that the process by which the numbers are generated is quantum in origin, and so the numbers generated are random. In at least some embodiments, certification can be carried out without having to know the number of photon input to the pinhole 13. Figure 3 shows a flow chart of a method 100 of generating random numbers using the source 1 discussed above. In a first step 102, light from a source 7 is diffracted onto a detection plane 19, having at least two detectors 15, 17. In a second step 104, the light falling on the two detectors 15, 17 is measured. At step 106, random numbers are generated and at step 108 the numbers are certified. Steps 106 and 108 will now be discussed in more detail. Random numbers can be generated and certified using the measurements of Ca and Cb. Random numbers can be generated in a number of ways. In one embodiment, random numbers are generated and certified by a random number extractor, using Ca + Cb and CA - Cb. Random number extractors are known in the art. Random number extractors use algorithms that use a random string of length k and a random seed as inputs, and outputs a string of random numbers. The string is derived from the output of Ca - Cb The random number seed can be taken from earlier results of the random number source 1 (in a bootstrapping mode), or any other suitable secure source, free from influence or prediction of other parties. The random number seed need not be certified, for example it may be generated by an algorithm. It will be appreciated that the output of the extractor may still be certified in certain circumstances, even with an uncertified seed. In at least some embodiments, the random number extractor relies on a one-way function (a function in which the input can be computed to provide the outputs, but the outputs cannot be inverted to find the inputs). One example of a group of one-way functions that can be used is hashing functions. Hashing functions can be used to ensure that the entropy is extracted to a level that is compatible with a certification value obtained from the quantum process. The entropy in the system can be determined, using an entropic uncertainty relationship, based on the total number of particles detected (Ca + Cb). In general, high Ca + Cb means high entropy. The entropy fixes the hashing fraction required for the randomness extractor to provide a secure (certified) random output. The hashing of Ca - Cb produces a secure (certified) string of random numbers. A first embodiment of a process 200 of deriving random numbers is shown in more detail in Figure 4. The random number source 1 provides an output of a time series of measurements of Ca and Cb. In the current embodiment, the light source 7 is pulsed, and each bit / measurement in the output corresponds to a single pulse. At a first step 202, n = Ca + Cb and m = Ca - Cb is determined for each measurement, giving a time series of pairs of n and m as the entropy signal 3 and validation signal 5. It will be appreciated that both n and m may vary for each measurement. At a second step 204, the pairs of (n, m) values are sorted into separate bins. Each bin corresponds to a different value of n or range of values of n. Overall, k bins may be used. Log2(k) is referred to as the bit depth. The bit depth is used as a fixed parameter to determine the minimum entropy in the system. Where there is noise on the system, a number of bins can be grouped together or omitted, when digitising. This reduces the bit depth of the system, since there are fewer bins. The length (j) of the binary string generated from the distribution of m depends on the bit depth of the detection system used (i.e. the minimum entropy), after the systematic noise is taken into account. As the number of measurements build up, , there is a set of statistics for the variation of m within each bin. A binary string is generated at a third step 206. In one example, the detection of a new pulse, or the measurement of a new sample may trigger the generation of the binary string. The binary string may be generated from distribution of m for the bin that the (n, m) pair is placed into. In a next step 208, the total number of particles detected (n) is used to determine the number N of random numbers that can be generated using a randomness extractor. The maximum value of N for which the numbers generated can still be certified as truly random is approximately given by N~ log2(A / 7rn / 2). However, it will be appreciated that various factors may require a reduction of N. This includes, for example, inaccuracies and errors introduced by the hardware, the window length, the bandwidth of the detectors and various other factors. Extracting more random numbers than the limit N would result in the numbers including predictable elements from the extractor. In a further step 210, the binary string, and the total number of random numbers that can be generated is provided to the random number extractor, along with a random seed of the correct length. The random number generator then generates the random numbers in the manner discussed above. It will be appreciated that in some examples, the (n, m) pair may be provided to the randomness extract (hashing function) so that the single measurement may be processed to generate the random numbers. In other examples, various other schemes may be applied to generate a random number. For example, a random binary output may be generated by comparing the value of m to a threshold splitting the output distribution into two, or random numbers may be generated in other suitable ways. Over a series of measurement, the value of Ca and Cb are random. However, over time, both Ca and Cb will tend to an average of n / 2. If n is above a minimum threshold, selected to ensure sufficient randomness in the system, and to ensure Ca and Cb are of sufficiently high intensity to be detected, then the numbers are certified as random. Otherwise, the numbers are not certified. In step 212, an output is provided, giving the certification status of the numbers. Alternatively, the method 200 may stop outputting numbers if the numbers are not certified, for example, if n drops below the threshold. The method maintains certification of the numbers by varying the number of random numbers that are output as a function of log(n), as discussed above. Certification (and generation) only stops in the particular circumstance discussed above. It will be appreciated that, assuming the pinhole 13 is circular and the detectors 15, 17 are the same size and symmetrically arranged around the centreline 25 of the detection area 21, the certification is independent of the source 7 and the type of detectors 15, 17, and is instead an underlying check that the process generating the randomness is truly quantum. The random number extractor can extract up to k random numbers from a string of length k, where the string is at least partially random. Therefore, provided the length of the string is above a threshold, the pinhole 13 is circular, and the detectors 15, 17 are symmetrically arranged around the centreline 25 of the detection area 21, the numbers generated can be trusted (and hence certified) as being truly random, and based on a quantum mechanical effect. As discussed above, the number of random numbers that can be extracted is dependent on the total number of particles. Therefore, variation in the system can be accommodated by varying the number of random numbers generated. The method of Figure 4 may be implemented in any suitable circuitry - in software or hardware. This may be part of a controller (not shown) or other entity. Figure 5 illustrates a circuit 33 for implementing an alternative embodiment of generating random numbers based on the entropy signal 3 and validation signal 5 generated by the source 1 shown in Figure 1. This circuit 33 is implemented in hardware and may be formed as part of the signal processing module 31 or in a separate module. The circuit 33 in Figure 5 outputs a series of random binary bits, which randomly fluctuate between 0 and 1. In the circuit 33 of Figure 5, the entropy signal 3 is provided in the form of a voltage. This is provided to a comparator 35 such as a Schmitt trigger, ADC or other component which compares two signals. Schmitt triggers are an example of comparators that exhibit hysteresis in the switch between states. A comparator which shows hysteresis has two thresholds at or around the reference value. When the input is below the first (lower) threshold, the output is logic low. When the input is above the second (higher) threshold, the output is logic high. When the input is between the thresholds, the output retains its previous value. For example, if the input starts low, and gradually increases the output will start in the low state and stay in this state as it crosses the first, lower, threshold. The output only switches state when the input crosses the second, higher, threshold. As the input then decreases, it retains the higher state as it crosses the second, higher, threshold, and only switches state when it crosses the first, lower, threshold. The use of a comparator, such as a Schmitt trigger, which exhibits hysteresis, ensures noise and random fluctuations do not cause unwanted fluctuations in the output state. Other similar comparators, with our without hysteresis, may be used. The comparator compares the voltage of the entropy signal 3 to a reference value 37. If the voltage is below the reference 37, a first binary value is provided (for example “low” or 0) and if the voltage is above the reference value 37, a second binary value is provided (for example “high” or 1). The reference value 37 is selected such that there is a 50:50 chance of either binary value. Assuming the detectors 15,17 are of equal size and symmetrically oriented along the centreline 25 of the detection area 21 the distribution of the entropy signal 3 will be a symmetric distribution, centred around a peak. The reference value 37 is aligned with the peak to ensure an equal chance of each of the binary values being outputted for each measurement. It will be appreciated that a voltage bias may be applied to the entropy signal 3 and / or the reference value 37 to achieve this. Figure 6 illustrates an example of the distribution of the entropy signal, the reference value 37 and the random bit that is output. In cases where the detectors 15, 17 are not of equal size and / or are not symmetrically oriented along the centreline 25 of the detection area 21, the relative probability of the two outputs occurring may be kept at 50:50 by ensuring that the reference value 37 is positioned such that the integral under the curve is the same on either side of the reference 37. The value of the distribution of Ca-Cb which has equal integrals either side of it is referred to as the centroid of the distribution. In the symmetric distribution, the centroid aligns with the peak. In an asymmetric distribution, the centroid may be offset from the peak. The reference value 37 may be provided by any suitable source, under control of a controller 41. For example, an output from a digital to analogue converter (DAC) 39 or other voltage source may be used may be used to provide the reference value 37 to the comparator 35. In a similar manner to the first embodiment, which makes use of a random number extractor, the numbers in the second embodiment are certified as random if Ca + Cb is above a threshold. Furthermore, in order to be considered random, the detectors 15, 17 must detect over sufficiently similar areas and be sufficiently symmetrically arranged around the centreline 25. The requirement for sufficiently equal and symmetric coverage of the detectors 15, 17 is addressed by the setup of the source 1, and is discussed below. In order to determine that Ca + Cb is above a threshold, a second comparator 43, such as a Schmitt Trigger, is used. The validation signal 5 is compared to a second reference 45. Provided the validation signal 5 is above the second reference 45, the numbers are certified as random. If the validation signal 5 falls below the second reference 45, the numbers are no longer certified. In a similar manner to the random number extractor embodiment, identification that the numbers are not certified may either result in numbers no longer being generated, or may simply provide an output indicating the numbers are not certified to the required level. The reference 45 for the second comparator 43 may be provided by the same DAC 39 or other voltage source as the reference 37 for the first comparator 35, or a separate voltage source. As discussed above, the reference values 37, 45 are set through a controller 41. The controller 41 may also provide an interface to output the generated random numbers 47 and certification status 49. In the embodiment shown with reference to Figures 4 and 5, each bit in the output has a binary value (0 to 1), based on whether the signal corresponding to Ca - Cb is above or below a reference value 37. It will be appreciated that further reference values may be applied such that the output string includes a larger range of values. Further reference values may be applied by arranging additional comparators in a chain. Alternatively, a digital comparator, which can apply multiple references can be used. For example, a plurality of the reference values may define a plurality of bands within the range of possible measurements of the entropy signal, each band corresponding to a different value in the output string. Provided that the integral of the distribution of the entropy signal is the same for each band, each value in the output string will have an equal chance of being generated. Alternatively, the binary output string 47 from the comparator 35 may be provided to a randomness extractor along with the certification signal. It will be appreciated that the second comparator 43 may also be used to certify that Ca + Cb is above a threshold in the embodiment using the random number extractor. It will be appreciated that in all the embodiments discussed above, the same system is used for both generation of random numbers, and certification. Therefore, the processes of generation and certification can be carried out in parallel, at the same time. The measurements for generating random numbers and certification do not need to rely on an auxiliary trusted source. As such the random number source 1 is secure against fluctuations in the inputs to the measurement system, or indeed malicious control over those inputs. Within the setup of the random number source 1 shown in Figure 1, the minimum spacing between the light source 7 and the diffraction screen 11 is such that the light emanating from the source 7 is treated as a plane wave at the pinhole 13. The distance measured from the centre of the pinhole 13 to the light source 7 is taken to be xo, the distance from the edge of the pinhole 13 to the light source 7 is taken to be xo + x and the pinhole 13 is taken to have radius rp. There is an angle 0 between a line extending from the light source 7 to the centre of the pinhole 13 (xo) and a line from the light source 7 to the edge of the pinhole 13 (xo + x) The limit for the plane wave approximation is x « xo. From the small angle approximation, it is also known that: tanO = rp / xo ~ 0 EQN 2a sinO = x / rp ~ 0 EQN 2b x = xoO2 EQN 2c Therefore, 02 « 1. Generally, for a pinhole 13 of radius rp, the spacing xo of the diffraction screen 11 from the light source 7 should be at least xo = rp / 0. The spacing xo can be any distance above this value. However, it will be appreciated that minimising xo will ensure as much of the light as possible from the light source 7 falls on the pinhole 13 (and detectors 15, 17) ensuring larger numbers of random numbers can be generated (due to increased Ca + Cb). Furthermore, minimising xo will also ensure the source 1 is as small as possible. The spacing z from the diffraction screen 11 and detection plane 19 is selected to satisfy the Fraunhofer diffraction condition: z » EQN 3a A Where X is the wavelength of light emitted by the light source 7. Generally, in order to achieve the Fraunhofer condition: z = EQN 3b A Where C is a multiplication factor. It will be appreciated that the diffraction pattern from a single pinhole 13 is a central bright spot surrounded by a series of light and dark rings. The radius of the zeroth order ring (the central bright spot) is given by: ^ = 1.22— EQN4 2rp The central bright spot contains 84% of the total energy falling on the pinhole 13. Therefore, the detection area 21 may be arranged to include at least the central bright spot, and may extend out to further rings to ensure sufficient signal is detected Generally, to achieve the desired diffraction pattern and intensity, the source 1 is arranged so that 02 = 0.005 (measured in radians) and C = 100. However, it will be appreciated that these values may be varied. In the above examples, the entropy signal 3 and validation signal 5 are described based on CA and Cb i.e. the number of photons falling on each detector 15, 17. It will be appreciated that the detectors 15, 17 may be calibrated to allow an electric response signal to be converted into Ca and Cb. In at least some embodiments, the detectors 15, 17 may be calibrated to determine the minimum number of photons that could have resulted in the measured response, rather than the exact amount, as discussed below. It will be appreciated that in some embodiments, a trusted light source or light sources can be used to calibrate the detectors 15, 17. Typically a detector 15, 17 has a fixed relationship between the number of photons detected and the output signal that is known (for example linear). By measuring the output signal for different known inputs of photons, the detector 15, 17 is calibrated. A single light source having variable power, where the output number of photons is determined by the power, or different light sources having different outputs, could be used. In order to ensure that the numbers extracted are truly random, the detectors 15, 17 should be conservatively calibrated, so that they either exactly estimate Ca and Cb based on the measured response, or underestimate them. If Ca + Cb is over estimated, then the certification may give a false positive. Furthermore, when a random number extractor is used, the extractor will extract more random numbers than possible, and the random numbers will include a systematic element from the extractor, which could be predicted. In some examples, the calibration can also be used to calibrate the dark current in the random number generator 1, so that this can be discounted when generating the random numbers. The dark current causes a base level of measurement on the detector, in the absence of a light input, and is accounted for by measuring the base level detected in the absence of any input. Measurement of the dark current is used to determine a level of confidence that the distribution of the entropy signal follows a predictable shape . This can be used in determining the certification status and / or the number of random numbers that can be extracted. For example, if the confidence of the shape of the distribution drops below a threshold, the numbers may not be certified, or the number of random numbers that can be generated may be varied depending on the confidence. In general, dark current is proportional to "V(Ca + Cb). Therefore, if a variable power light source (as discussed above) is used, then the noise can be measured as a function of CA + Cb, and the noise can be calibrated. There may be systematic noise on the system, in addition to the dark current. The systematic noise is fixed, and does not depend on Ca + Cb. The systematic noise sets a minimum threshold number of particles at which a signal is detected. Calibration of the noise also helps to determine the minimum threshold of input particles that can be used. The minimum threshold should be selected to ensure that the output power is above the systematic noise threshold. This means that the dark current is larger than the systematic noise. The dark current is quantum in origin, and so above the systematic noise threshold, the signal is dominated by quantum effects. In one example the minimum threshold is n = 500. This is above the threshold required for use of photodiodes as the detectors 15, 17. It will be appreciated that n may vary from pulse to pulse, but it should be above this threshold. Calibration can be done prior to assembly of the random number source 1, or after. In some embodiments, separate light sources may be used for the calibration. The light sources required for the calibration are more complex than the light source 7 for use in random number generation, since the input number of photons must be known. However, the complex light source is only required for calibration, and not for generating numbers. This means that the need for complex light sources is reduced, since the same light source could be used to calibrate many random number sources 1. Alternatively, in some embodiments, the random number source 1 may include a calibration light source. In some examples, the detector and dark current calibration may be carried out from time to time, as a check of the random number source 1. It will be appreciated that the entropy signal 3 and validation signal 5 may be the current or voltage response from the detectors (i.e. an intensity) or another suitable parameter. It will be appreciated that these factors are all proportional to the counts Ca and Cb and thus can be used as the entropy and validation source in the same way as Ca and Cb. As discussed above, the random number source includes a post processing module 31 which takes the outputs 27, 29 from the detectors 15,17 and generates the entropy signal 3 and validation signal 5. The signal processing module 31 may be implemented in many different ways in software or hardware. For example, this may be implemented as addition and subtraction modules in a micro-controller, or in other ways. In hardware implementations, differential amplifiers or other electrical components may be used to generate the entropy signal 3 and validation signal 5. Figures 7A and 7B illustrate circuit diagrams of two hardware implementations of the postprocessing module 31. The hardware implementations are in the form of circuits 51, 53 for generating outputs corresponding to Ca + Cb and Ca - Cb. The first circuit 51 (Figure 7A) is a voltage measurement topology. The second circuit 53 (Figure 7B) is a current measurement architecture. In both circuits 51, 53, the detectors 15, 17 are illustrated as simple photodiodes, having cathodes 15a, 17a and anodes 15b, 17b. It will be appreciated that this is for illustrative purposes only, and any suitable detectors 15,17 may be incorporated based on the same circuits 51, 53. In both circuits 51, 53 , the detectors 15, 17 are connected in series with a bias (Vbias) applied. The positive bias (+Vbias) is connected at the cathode 15a of the photodiode representing the first detector 15, and the negative bias (-Vbias) is connected at the anode 17b of the photodiode representing the second detector 17. The photons incident on the detectors 15, 17 causes a current Ii in the first detector 15 and a current I2 in the second detector 17. In both circuits 51, 53, the current is measured between the detectors 15, 17. This provides a measure of Ii - I2 (i.e. the entropy signal 3). To generate the entropy signal 3, the difference current (Ii - I2) is passed through a capacitor 55 and then amplified by a transimpedance amplifier 57 to produce a signal 3 corresponding to Vi - V2. In the voltage measurement topology 51, resistors 59, 61 are provided in series with the detectors 15, 17, between the detectors 15,17 and the voltage bias terminals. The voltage drop across the resistors 59, 61 is measured by corresponding differential amplifiers 63, 65. The voltage drop over the resistor 59 between the first detector 15 and the voltage bias terminal is Vi = IiR, and so the output of the differential amplifier is proportional to -Ii. Similarly, the voltage drop over the resistor 61 between the second detector 17 and the voltage bias terminal is V2 = -I2R and so the output of the differential amplifier is proportional to +I2. The outputs from the differential amplifiers 63, 65 measuring the voltage drops across the resistors 59, 61 are provided to a third differential amplifier 67. The output of the third differential amplifier corresponds to V2 - (-Vi) = Vi + V2, which is the validation signal 5. In the current measurement architecture 53, current mirror circuits 69, 71 are provided in series with the detectors 15, 17, between the detectors 15, 17 and the voltage bias terminals. The current mirror circuits generate currents matching Ii and I2 at new outputs The outputs from the current mirrors 69, 71 are provided to corresponding transimpedance amplifiers 73, 75. Resistors 77, 79 are connected in parallel across the amplifiers 73, 75. The current from the current mirror 69, 71 flows through the respective feedback resistor 77 and 79 and gets converted to voltage. The first current mirror 69 produces an output corresponding to Ii. This is fed to the first amplifier 73, which produces an output of -Vi = IiR (where R is the resistance of the resistor 77 connected across the amplifier 73. The second current mirror 71 produces an output correspond to I2. This is fed to the second amplifier 75, which produces an output of V2 = I2R (where R is the resistance of the resistor 79 connected across the amplifier 75. The outputs from the amplifiers 73, 75 measuring the voltage drops over the resistors 77, 79 are provided to the third differential amplifier 67. In a similar manner to the voltage measurement architecture 51, the output of the third differential amplifier 67 corresponds to V2 - (-Vi) = Vi + V2, which is the validation signal 5. Any suitable type of detector can be used in the random number source 1. For example, the detectors 15, 17 could be implemented with linear photodiodes, microwave intensity detectors with antenna / amplifier systems, atom intensity detectors with absorption or fluorescence measurements, superconducting intensity detectors with Josephson junctions or SQUID amplifiers, mechanical intensity detectors with Raman or Brillouin scattering measurements,. The detectors may be considered means for detecting the intensity, photon count or other factor representing the proportion of light falling on the different areas. In other examples, the detectors 15,17 may be one of the following: nanowire detectors, superconducting transition edge sensors, superconducting kinetic inductance detectors, avalanche photodiodes, photomultiplier tubes, CCD detectors, or CMOS detectors. In the above example, the detectors are described as multipixel detectors arranged to detect the amount of light falling on an area. It will be appreciated that each pixel may include a detecting element of one of the types discussed above, and the detector may then combine the output from multiple detecting elements. Alternatively, each detector 15,17 may include a single element extending over the entire area to be covered by the detector 15, 17. In the above examples, it is assumed that the detectors 15,17 are of the same size and arranged symmetrically around the centreline 25 of the detection area 21. As such, over time, the ratio of light falling on the two detectors will be 50:50. It will be appreciated that the detectors 15,17 may be moved and / or changed in size or shape whilst still achieving the 50:50 ratio. The detectors need not necessarily be the same shape and size to achieve this ratio. In the examples discussed above, the detectors 15, 17 each cover a single continuous area, and the two detectors 15,17 together cover the whole detection area 21. It will be appreciated that this may not be the case. Each detector 15, 17 may be made of one or more separate areas. Furthermore, the detectors 15, 17 need not cover the whole detection area 21 and need not be contiguous with each other. The detectors 15, 17 may have one or more separate areas, arranged over the detection area 21 in any way to achieve the 50:50 ratio of light detected over a time averaged period between the two detectors 15, 17. Where a multipixel detector is used, separate detectors may be used for each detector 15, 17 (or region of a detector). Alternatively, a single detector may be used, and the response from light falling on different regions may be extracted from the output (e.g. by separately addressable pixels or groups of pixels. In this case, the different regions of the single detector may still be considered two detectors. In the above, the relative ratio of light falling on each detector over a time average period is taken to be 50:50. It will be appreciated that this may be varied. In practice, certified random numbers can still be generated if the relative ratio of light falling on each detector over a time average period is below 100:0. It will be appreciated that as this ratio varies away from 50:50, the minimum entropy will reduce and the number of random numbers that can be generated will reduce. The number of random numbers that can be generated is generally stable when the ratio is in the range of approximately 20:80 to 80:20. However, outside of this range, the number of random numbers that can be generated reduces quickly. In some cases, it may be that if the number of random numbers that can be generated is below a minimum amount, the numbers are considered uncertified. Variance from the 50:50 ratio can be due to, for example, misalignment of the detectors 15, 17 and / or diffraction screen 11 and / or light source with respect to the centreline 25, faults or errors in pixels of the detectors 15, 17, the detectors 15, 17 being different size, the pinhole 13 varying from perfectly circle. It will also be appreciated that the detectors 15, 17 and / or diffraction screen 11 and / or light source may be misaligned with respect to the centreline, whilst still achieving a nominal ratio of 50:50. EQN 1 above gives the minimum entropy as a function of the total number of photons detected (Ca + Cb). Figure 8 shows data points for the minimum entropy measured for different pinhole sizes and the fitted minimum entropy 81 based on EQN 1, assuming 50:50 ratio between the two detectors 15, 17. The data in Figure 8 is for a specific configuration of the random number source 1, and includes factors corresponding to, for example, the specific electronic components chosen. EQN 1 includes Ra and Rb, which are the proportions of the detection area 21 covered by each detector 15, 17. Figure 8 also shows the calculated minimum entropy 83 for the same configuration, assuming Ra = 0.6 and Rb = 0.4, showing the tolerance of the system for some misalignment. In the above example, two detectors 15, 17 are used, resulting in two responses measured (Ca, Cb). As discussed above, Ca and Cb may be derived from multiple detectors / detecting elements grouped together to give the two desired outputs. In other examples, the random numbers may be generated on more than two signals. In other words, the random number source 1 may include outputs incorporating Ca, Cb, Cc. Where more than two detectors 15, 17 are provided, they may be of the same size and arranged symmetrically around the centreline 25 or centre point 23 of the detection 19 plane with a degree of rotational symmetry equal to the number of detectors 15, 17. In this way, equal amounts of light will fall on each detector 15,17 over a time averaged period (with tolerances discussed above). Alternatively, the detectors 15, 17 may be arranged in any pattern with suitable sizes such that the equal amounts of light will fall on each detector 15, 17 over a time averaged period (with tolerances discussed above). As with the two detector example, the detectors 15, 17 may be a single area or multiple separate areas, and the detectors may cover all or part of the detection area 21. In embodiments with more than two detectors, various methods may be used to generate the entropy signal and validation signal. For example, the entropy signal may be the difference between the signal detected by any two detectors, and the validation signal may be the sum of the signal detected by the same two detectors. In this way, multiple pairs of entropy signal and validation signal may be generated, each used to generate random numbers as discussed above. Alternatively, where the difference (Cx - Cy) is determined by two or more (nonoverlapping) pairs of detectors, multiple values of the entropy signal may be inputted into the randomness extractor (e.g. hashing function). In this case, the validation signal should be based on the total of the signals detected from all detectors used in the different entropy signals. Where there are more than two detectors 15, 17, the ratio between the intensity falling on the detectors over a time averaged period is preferably 1:1:1... However, it will be appreciated that as with the two detector example 15, 17, some variance from this can be contemplated. The pinhole 13 may have any suitable size that generates sufficient response at the detectors 15, 17, so that the detectors 15, 17 trigger a response above the minimum threshold, without the detectors 15, 17 reaching saturation. For example, the pinhole 13 may be between 100 microns and 400 microns in diameter. As shown from EQN 1, the minimum entropy scales quadratically with the pinhole size. As the pinhole 13 reaches an upper limit, all photons from the light source pass through the pinhole. Therefore, further increasing the pinhole does not impact the detection. As discussed above, the radius of the pinhole 13 should be below a minimum value, such that diffraction occurs (light falling on the diffraction plane satisfies the Fraunhofer diffraction condition). In some cases, the pinhole size at which all photons pass through the pinhole 13 may be larger than the minimum radius. In other cases, the threshold may be below the minimum radius. In the examples given above, the distances xo and z (Figure 1), and the radius of pinhole 13 are selected so that light emitted from the light source 7 satisfies the plane wave approximation at the diffraction screen, and light falling on the detection plane satisfies the Fraunhofer diffraction condition. It will be appreciated that in some examples, it may not be necessary to satisfy the plane wave approximation. It may be that the pattern projected onto the detectors 15, 17 may be sufficiently spread out to create an entropy signal without satisfying this condition. Any suitable light source 7 may be used. In some examples, lasers are used, but this is by way of example only. Examples of light sources that could be used are light bulbs (halogen, fluorescent and the like), multi-mode lasers or light emitting diode (LED), or even sunlight or other light sources. Alternatively, the light source 7. may comprise a source that generates light in only a single mode, such as a single mode laser, LED or the like. Different light sources will provide different numbers of incident photons. Furthermore, the output of a light source may vary depending on many factors, such as age, environment, power supply and the like. However, the ability to generate the entropy signal is independent of the variation in total number of photons, since it simply uses total number to determine the minimum entropy. Single photon light sources may be used. In such cases, it will be appreciated that the diffraction formed on the screen is formed by the statistical distribution of photons over time, In some cases, the light may be provided by an external independent light source, such as ambient light. Therefore, the light source 7 in the system 1 may include a collector (not shown) for receiving light form the external source. The collector may simply be an opening in a housing, or some other receiver that directs photons to the diffraction screen 11. In all the above examples, light / photons are used. However, it will be appreciated that the random number generator can implemented using any particle that exhibits suitable diffraction patterns. For example, different bosonic systems may be used instead of photons. Examples of bosonic systems include optical or microwave excitations (photons), quantized mechanical excitations (phonons), bound electron-hole pairs (excitons) or strongly coupled light-matter excitations (plasmons and polaritons). In other examples, cold atoms or trapped ions, superconducting circuits or mechanical degrees of freedom could be used. It will be appreciated that when bosonic systems are used, the bosons are generally directed along a propagation axis. In the case of photonic / optical systems this system is referred to as the optical axis. In non-photonic systems this is more generally the axis / direction of propagation. In the examples discussed above, the source 7 is pulsed, with each pulse used to generate a value in the string forming the entropy signal 3 and a value in the string forming the validation signal 5. In at least some examples, the source 7. may be continuous instead of pulsed. In such cases, the output 27, 29 of the detectors 15, 17 may be continuous. However, in such cases, outputs 27, 29 of the detectors 15, 17 may be sampled to produce the effect of pulsed light. The pulses or samples should be sufficiently spaced so that there is no interference between consecutive pulses. This is limited by a number of factors including the response times, bandwidth, acquisition time, and rise time of the detectors 15, 17 and the coherence length of the light source. In one example, GHz photodiodes may be used, so the pulses may be spaced by approximately Ins. When the amount of light (or other bosonic signal) falling on the detectors 15, 17 is such that the detectors 15, 17 reach saturation, the response from the detectors is not fully random. Therefore, the source 7, pinhole size and detectors 15, 17 are arranged such that the response from the detectors 15, 17 is below saturation, and provides an unpredictable output. This may involve providing intensity filters or attenuators to reduce the intensity of light from the source. Alternatively, once a maximum value below or at saturation is reached, no entropy will be generated in a similar manner to when the numbers are not certified. In the examples discussed above, a pinhole diffraction pattern is used to generate random numbers. It is appreciated that this is by way of example only. Any suitable diffraction pattern may be used instead of the pinhole. For example, a slit, double slit or any other diffraction pattern may be used. The diffraction pattern is formed by one or more openings 13 in the diffraction screen 11. With a single opening, the optical axis 9 is aligned with the centre of the opening in the diffraction screen 11. When there are multiple openings, a combined centre of mass of the openings is aligned with the optical axis 9. It will be appreciated that for any diffraction pattern, detectors 15,17 may be sized and positioned such that they generate equal responses over a time averaged period, within accepted tolerances. For example, detectors of the same size may be oriented symmetrically around the optical axis 9. In the above examples, the two detectors generate outputs representative of Ca and Cb. Various software and hardware implementations have been provided to generate Ca + Cb and Ca - Cb. It will be appreciated that these are by way of example only. The person skilled in the art will appreciate that there are a variety of ways to generate these signals (or the corresponding signals in embodiments using more than two detectors 15, 17). In some examples, the entropy signal may be based on the ratio of the responses measured by the two detectors (e.g. Ca:Cb). Various other methods for exploiting the entropy will also be appreciated. Furthermore a number of different examples have been given for generating random numbers based on the entropy signal 3 and validation signal 5. These are also by way of example only, and the person skilled in the art will appreciate different ways of using the two signals to generate random numbers and certify the numbers as random. As discussed above, when the numbers are not certified, the numbers may be output along with an indication that they are not certified. Alternatively, the generation of random numbers may be stopped. In some embodiments, the random numbers may continue to be generated, and the certification determined. However, the numbers may not be provided / output to a user until they are certified again. It will be appreciated that at least part of the source 1 of the entropy and validation signals and optionally the circuitry may be provided on an integrated circuit, such as an integrated photonic circuit. For example, the light source 7, diffraction screen 11 and detectors 15, 17 may be provided on the integrated circuit. Alternatively, the light source 7 may be provided separately. Further elements such as the signal processing module 31, the controller 41, the random number extractor or comparators 35, 43 and DAC 39 may be provided on the same integrated circuit or a different integrated circuit.
Claims
1. A random number generator having:a source arranged to propagate bosons along or substantially along an axis;a diffraction screen placed along the axis, the screen having one or more apertures arranged to diffract bosons from the source;two or more detectors each arranged to detect the number or intensity of bosons falling thereon, the detectors provided in a detection plane spaced from the screen such that spatial distribution of bosons diffracted by the screen forms a diffraction pattern at the detection plane; and circuitry arranged togenerate random numbers based on the difference in or ratio of the number or intensity of bosons detected by different detectors; andcertify the numbers as random based on the total number or intensity of bosons detected by the different detectors.
2. The random number generator of claim 1, wherein the one or more apertures in the diffraction screen comprises a single pinhole to diffract bosons incident on the screen.
3. The random number generator of claim 1 or claim 2, including:a comparator to compare an output signal based on the difference in or ratio of the number or intensity of bosons detected by different detectors against a reference at different times to generate a digital time series of random numbers, each comparison providing a bit in the series.
4. The random number generator of any preceding claim, wherein the detectors are arranged such that for a plurality of measurements taken over a time averaged period, substantially the same number or intensity of bosons falls on each detector, the random numbers being generated based on the difference in or ratio of the number or intensity of bosons detected by different detectors at a given time.
5. The random number generator of claim 4, wherein the ratio between the number or intensity of bosons detected a first detector and a second detector over the time averaged period is between 50:50 and 80:20.
6. The random number generator of any preceding claim, wherein each detector is arranged to detect number or intensity of bosons incident on a portion of the detection plane, the detectors being the same size as each other.
7. The random number generator of any preceding claim, wherein each detector comprises a multi-pixel detector arranged to combine the output from the pixels into a single output of the detector.
8. The random number generator of any preceding claim, wherein the detectors are arranged symmetrically around a centreline or centre point of the detection plane, the centreline or centre point defined along a straight line from the source, through a centre point of the apertures in the diffraction screen.
9. The random number generator of any preceding claim including only two detectors.
10. The random number generator of claim 9, wherein the two detectors abut each other in the detection plane such that the detector cover a contiguous detection area on the detection plane.
11. The random number generator of any preceding claim, wherein the source is arranged to operate at an intensity such that the intensity or number of bosons falling on the detectors is below the intensity required for the detectors to reach saturation and above a minimum detection threshold for the detectors.
13. The random number generator of any preceding claim, comprising hardware circuitry arranged to:generate an output signal based on the difference in or ratio of the number or intensity of bosons detected by different detectors, the output signal for generating random numbers; andgenerate a validation signal based on the total of the number or intensity of bosons detected the detectors, the validation signal for certifying the numbers as random.
14. The random number generator of any preceding claim, wherein the numbers are certified as random at the same time as the numbers are generated.
15. The random number generator of any preceding claim, including:a comparator arranged to compare an output signal based on the total number or intensity of bosons detected by the detectors to a second reference to certify the numbers.
16. The random number generator of any preceding claim, wherein the random number generator is arranged to measure a dark current wherein the dark current is incorporated in certifying the random numbers.
17. A method of generating random numbers, the method including:diffracting bosons onto a detection plane;detecting bosons falling on the detection plane at a least two different positions;generating random numbers based on the difference in or ratio of the number or intensity of bosons detected at the different positions; and certifying the numbers as random based on the total number or intensity of bosons detected at the different positions.
18. The method of claim 17, wherein the bosons are diffracted through a pinhole.
19. The method of claim 17 or claim 18, wherein generating random numbers based on the difference in or ratio of the number or intensity of bosons detected at the different positions comprises:at different times, comparing the difference in or ratio of the number or intensity of bosons detected at different positions against a reference;generating a digital time series of random numbers, each comparison providing a bit in the series.
20. The method of any of claims 17 to 19, wherein averaged over a time period, substantially equal numbers or intensity of bosons fall on the different positions.
21. The method of any of claims 17 to 20, wherein the bosons falling on the detection plane at each position is detected over a region, each region having the same size.
22. The method of any of claims 17 to 21, wherein the two or more positions are arranged symmetrically around a centreline or centre point of the detection plane, the centreline or centre point defined along a straight line from a source of the bosons, through a centre of apertures in a diffraction screen used to diffract the bosons.
23. The method of any of claims 17 to 22, wherein the bosons are detected in only two different positions.
24. The method of any of claims 17 to 23, wherein the numbers are certified as random at the same time as the numbers are generated.
25. The method of claim 24, wherein certifying the numbers as random based on the total number or intensity of bosons detected at the different positions comprises: comparing an output signal based on the total number or intensity of bosons detected at the different positions against a reference;certifying the numbers as random based on the comparison.
Citation Information
Patent Citations
ViewGB2576551AonEspacenetopensinnewtab
ViewWO2018/087516A1onEspacenetopensinnewtab