Key generation device and method

A self-contained hardware device leveraging quantum phenomena generates certified random numbers and post-quantum cryptographic keys, addressing vulnerabilities in classical algorithms by ensuring high entropy levels, providing secure and efficient key generation.

JP7808205B2Active Publication Date: 2026-01-28QUANTINUUM LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024553861
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-03-11
Filing Date
2023-03-09
Publication Date
2026-01-28
Estimated Expiration
2043-03-09

AI Technical Summary

Technical Problem

Existing pseudorandom number generation algorithms on classical computing devices are deterministic and potentially predictable by adversaries with sufficient computational resources, making generated data keys vulnerable, while classical stochastic processes fail to produce unbreakable encryption keys.

Method used

A self-contained hardware device using quantum phenomena to generate certified random numbers through a prepare-and-measure method, incorporating a quantum device, a classical computing device, and a control and processing system to ensure high entropy levels, generating post-quantum cryptographic keys.

Benefits of technology

The device produces highly secure, compact, and efficient data keys resistant to prediction, even with virtually unlimited computational resources, suitable for high-security environments with minimal power consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007808205000005
    Figure 0007808205000005
  • Figure 0007808205000006
    Figure 0007808205000006
  • Figure 0007808205000007
    Figure 0007808205000007
Patent Text Reader

Abstract

An apparatus for generating certified random numbers usable as data keys, e.g., post-quantum cryptographic keys, is provided, the apparatus being a self-contained hardware unit configured to operate at room temperature. The apparatus includes a quantum random number generator including a certified light source for generating a quantum random bit sequence using a preparation and measurement technique. The apparatus further includes an extractor for verifying the entropy of the quantum random bit sequence using a proof of entropy and, after verification, generating certified random numbers using the quantum random bit sequence. The apparatus further includes a control and processing unit configured to control and monitor operation of the apparatus and to process the certified random numbers to generate data keys.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Incorporation by reference to priority applications This application claims the benefit of priority to U.S. Provisional Application No. 63 / 319,172, entitled "KEY GENERATION APPARATUS AND METHOD," filed March 11, 2022, the entire disclosure of which is incorporated herein by reference.

[0002] The present disclosure relates to methods and apparatus for generating quantum random numbers for generating data keys, more optionally for generating cryptographic keys, and even more optionally for generating post-quantum cryptographic keys. [Background technology]

[0003] Pseudorandom number generation algorithms are executable on classical computing devices (e.g., classical binary computing devices), and such algorithms can generate sequences of random numbers from a seed number, and a data key can be generated from the sequence of random numbers. However, such algorithms are in principle deterministic, and therefore the sequence of random numbers is potentially predictable to a third party given sufficiently powerful computational resources, and therefore the data key generated from the sequence of random numbers is correspondingly predictable. To address such vulnerabilities, it has been proposed to use classical stochastic processes to generate sequences of random numbers, and a data key can be generated from the sequence of random numbers. However, quantum phenomena can generate sequences of random numbers with sufficient entropy that the data key generated therefrom cannot be predicted, assuming virtually unlimited computational resources are available to a third-party hacker, and similar considerations apply to keys used in various cryptographic systems. Therefore, it is desirable to have a data key generation system that generates such keys using quantum phenomena. Summary of the Invention [Means for solving the problem]

[0004] The present disclosure seeks to provide a hardware device for generating certified random numbers using a prepare-and-measure method, where the certified random numbers are generated based on quantum events associated with energy-type constraints satisfied by a light source. The certified random numbers may be used to generate post-quantum cryptographic keys.

[0005] According to one aspect, an apparatus for generating certified random numbers based at least in part on quantum events includes a quantum device configured to generate quantum events, a classical computing device in communication with the quantum device, the classical computing device including a control and processing system, the control and processing system including a memory configured to store specific computer-executable instructions, and a hardware processor in communication with the memory and configured to execute the specific computer-executable instructions to at least generate a quantum random bit string using the quantum device, determine an entropy level of the quantum random bit string using a plurality of entropy witnesses, and generate a certified random number using the quantum random bit string in response to determining that the entropy level of the quantum random bit string is higher than an entropy level associated with an entropy witness in the plurality of entropy witnesses.

[0006] According to another aspect, a method for generating certified random numbers based at least in part on quantum events includes using, by a hardware processor of a control and processing system, a quantum device configured to generate a quantum random bit string; determining an entropy level of the random bit string using a plurality of entropy proofs; and generating a certified random number using the quantum random bit string in response to determining that the entropy level of the quantum random bit string is higher than an entropy level associated with an entropy proof of the plurality of entropy proofs.

[0007] According to another aspect, a method of calibrating and qualifying a light source for use in a quantum device for generating quantum random bit sequences, the light source including a photon source and an optical link, the optical link transmitting at least a portion of the light generated by the photon source to a photodetector, the method including measuring, using the photodetector, a portion of the light received by the photodetector while controlling the photon source with a first trigger signal to determine a quantum state of the portion of the light received by the photodetector with respect to an energy-type constraint, the method further including, in response to determining that the portion of the light received by the photodetector does not satisfy the energy-type constraint, adjusting the optical link to attenuate the portion of the light received by the photodetector while controlling the photon source with a second trigger signal, using the photodetector to measure the attenuated portion of the light received by the photodetector while controlling the photon source with a second trigger signal to determine a quantum state of the attenuated portion of the light received by the photodetector with respect to the energy-type constraint, and qualifying the light source for use in the quantum device in response to determining that the portion of the light received by the photodetector or the attenuated portion satisfies the energy-type constraint.

[0008] According to another aspect, an apparatus for generating certified quantum random numbers in an operational mode and generating seed random numbers in a kickoff mode includes a quantum device configured to generate quantum events, a classical computing device in communication with the quantum device, and a control and processing system configured to: generate a first quantum random bit sequence and a second quantum random bit sequence using the quantum device, generate a seed random number using the first quantum random bit sequence and the second quantum random bit sequence using the quantum device, generate a third quantum random bit sequence using the quantum device, and generate the certified random number using the third quantum random bit sequence and the seed random number.

[0009] According to another aspect, a method for generating certified quantum random numbers in an operational mode and generating seed random numbers in a kick-off mode includes generating, by a control and processing system, a first quantum random bit sequence and a second quantum random bit sequence using a quantum device; generating a seed random number using the first quantum random bit sequence and the second quantum random bit sequence; generating a third quantum random bit sequence using a quantum device; and generating a certified random number using the third quantum random bit sequence and the seed random number.

[0010] According to another aspect, a non-transitory computer-readable storage medium comprising specific computer-readable instructions executable on data processing hardware, the specific computer-readable instructions, when executed on the data processing hardware, performing any of the methods described in the above aspects.

[0011] According to another aspect, there is provided an apparatus for generating certified random numbers (data keys), the apparatus being a self-contained hardware unit configured to operate substantially at room temperature, the apparatus including a quantum random number generator including a quantum device for generating a quantum random bit stream, and a randomness extractor (e.g., a seeded extractor) for generating random numbers using the quantum random bit stream.

[0012] Particular embodiments may provide advantages in that the device can be implemented as a self-contained, compact item of hardware and, when in use, is capable of delivering large amounts of data keys of extremely high entropy.

[0013] Optionally, the data key comprises a cryptographic key. More optionally, the data key comprises a post-quantum cryptographic key.

[0014] Optionally, in the apparatus, the quantum random number generator is implemented using a laser that generates photons, an optical mechanism for coupling at least a portion of the photons from the laser to a detector mechanism, and a processing mechanism for processing signals from the detector mechanism, the optical mechanism configured with the detector mechanism to create conditions for single-photon quantum events in a spatial or temporal regime, the detector mechanism configured to detect the events, and the processing mechanism configured to apply a statistical test to verify that the events are truly quantum events. More optionally, in the apparatus, the statistical test includes determining an entropy level or a minimum entropy level of the quantum random bit stream using one or more entropy proofs, although other types of statistical tests can be used instead or additionally.

[0015] Optionally, in the device, the laser is implemented as a mode-locked self-pulsing laser.

[0016] Optionally, in the device, the laser is a solid state laser, a fiber laser, or a semiconductor laser.

[0017] Optionally, in the apparatus, the laser is configured to operate in a pulsed mode.

[0018] Optionally, in the apparatus, the laser is configured to operate in a self-triggering mode.

[0019] Optionally, in the device, the laser may be externally triggered to generate the pulse train.

[0020] Optionally, in the apparatus, the extractor is implemented as a Dodis extractor.

[0021] Optionally, the device includes a monitoring mechanism within the data interface and control unit configured to monitor operating conditions of the device to determine whether evidence of entropy can be used to ensure that the entropy level of a quantum random bit string (QRBS) generated using the quantum device of the device exceeds a required degree of entropy for the QRBS to be used (e.g., to generate a data key).

[0022] Optionally, the apparatus is configured to switch from an operational phase when generating random numbers to a "quick-off" phase in which the quantum device is used to generate seeds for use in an extractor that is seeded during another operational phase.

[0023] Optionally, in the device, the data processing required for the device to function when in use is implemented using at least one FPGA.

[0024] Optionally, the device is 3 It is implemented using hardware that can be housed in a volume less than

[0025] Optionally, the device is configured to consume less than 10 watts when in operation.

[0026] According to another aspect, there is provided a method for (i.e., a method of using) an apparatus for generating a data key, wherein the apparatus (10) is a self-contained hardware unit configured to operate at substantially room temperature, and the method comprises: (a) configuring an apparatus to include a quantum random number generator including a quantum device for generating a quantum random bit stream; (b) using an extractor (e.g., a seeded extractor) to generate a random number using the quantum random bit sequence received from the quantum device; (c) using a control and processing system to control and monitor operation of the apparatus and process the output of the extractor to generate the random number.

[0027] Optionally, the device generates a data key using a random number. The data key may be a cryptographic key. More optionally, the data key is a post-quantum cryptographic key.

[0028] Optionally, the method comprises: (i) implementing a quantum random number generator that uses a laser to generate photons; (ii) coupling photons from the laser to a detector mechanism using an optical mechanism; (iii) processing signals from the detector mechanism using a processing mechanism, the optical mechanism being configured with the detector mechanism to create conditions for measuring single photon detection quantum events in a spatial or temporal fashion; (iv) detecting the event using a detector mechanism; (v) generating a quantum random bit sequence using the events; (vi) using a processing mechanism to apply a statistical test based on the evidence of entropy to verify that the entropy of the quantum random bit string is greater than a minimum entropy associated with the evidence of entropy.

[0029] According to another aspect, there is provided a software product recorded on a machine-readable data storage medium, the software product being executable on data processing hardware to perform the method of the second aspect.

[0030] Additional aspects, advantages, features, and objects of the present disclosure will become apparent from the drawings and detailed description of illustrative embodiments taken in conjunction with the appended claims below.

[0031] It will be understood that features of the present disclosure are capable of being combined in various combinations without departing from the scope of the present disclosure as defined by the appended claims.

[0032] Embodiments of the present disclosure will now be described, by way of example only, with reference to the figures of the present disclosure. [Brief explanation of the drawings]

[0033] [Figure 1] 1 is a diagram of an embodiment of a random number generator according to the present disclosure. [Figure 2A] FIG. 2 is a schematic diagram of an optical setup that can be used to implement the quantum random number generator of the device of FIG. 1. [Figure 2B] FIG. 2 is a schematic diagram of an optical setup that can be used to implement the quantum random number generator of the device of FIG. 1. [Figure 3] FIG. 2 is a schematic diagram of an active damping mechanism for the quantum device of the apparatus of FIG. 1. [Figure 4] FIG. 1 is a block diagram illustrating a system that may be used to generate certified random numbers associated with quantum events using the prepare-and-measure or OOK method. [Figure 5A]FIG. 5 is a block diagram of an apparatus for generating certified quantum random numbers using the method described above with respect to FIG. 4. [Figure 5B] 5B is a flow diagram illustrating an exemplary process that may be used by the device shown in FIG. 5A during normal mode operation to generate certified random numbers. [Figure 6] FIG. 1 is a block diagram illustrating an exemplary optoelectronic system for generating certified random numbers. [Figure 7] 5B is a flow diagram illustrating an exemplary process that may be used by the device shown in FIG. 5A in a quick-off phase or mode to generate a seed random number. DETAILED DESCRIPTION OF THE INVENTION

[0034] In the accompanying figures, underlined numbers are used to represent the item on which the underlined number is located or to which it is adjacent. When a number is not underlined and has an associated arrow, the non-underlined number is used to identify the general item to which the arrow is pointing.

[0035] The present disclosure relates to methods and apparatus for generating data keys, more optionally for generating cryptographic keys, and even more optionally for generating post-quantum cryptographic keys. Furthermore, the present disclosure relates to methods for (i.e., methods of using) the aforementioned apparatus for generating the aforementioned keys. Furthermore, the present disclosure relates to software products, for example stored on a data carrier, which software products are executable on computing hardware for performing the aforementioned methods.

[0036] Pseudorandom number generation algorithms are executable on classical binary computing devices, and such algorithms can generate sequences of random numbers from a seed number. The sequences of random numbers can be used to generate data keys. However, such algorithms are deterministic, and therefore the sequences of random numbers are potentially predictable to a third party with sufficiently powerful computational resources, and therefore the data keys generated from the sequences of random numbers are also predictable. To address such vulnerabilities, the use of classical stochastic processes such as electronic noise, Zener diode noise, and thermal noise has been proposed as a method for generating sequences of random numbers with higher entropy, and higher-entropy data keys can be generated from sequences of random numbers with higher entropy. However, assuming an adversary has sufficiently powerful computational resources, such classical stochastic processes cannot be used to generate unbreakable encryption keys extracted from sequences with higher entropy (e.g., using a Dodis extractor). In contrast, quantum phenomena may be used to generate sequences of random numbers with sufficiently large entropy that the data keys generated therefrom resist prediction, even assuming an adversary with virtually unlimited computational resources; similar considerations apply mutatis mutandis to RSA cryptographic keys. A technical problem encountered is that a user would like to have a data key generation device that is spatially local to them, for example, located in their own high-security enclave or entirely local to their system, for a cryptographic key generation device.

[0037] Compact quantum random number generators are known. For example, the scientific paper "Compact quantum random number generator based on superluminescent light-emitting diodes," Shihai Wei et al., Rev Sci Instrum 2017 Dec; 88(12):123115 doi: 10.1063 / 1.5005506, describes a method for implementing a compact quantum random number generator (QRNG). The QRNG functions by measuring the amplified spontaneous emission (ASE) noise of a superluminescent light-emitting diode. After detecting and amplifying the ASE noise, the QRNG performs both data acquisition and randomness extraction in real time. The final random bit sequence generated by the extraction is delivered to a host computer at a real-time generation rate of 1.2 Gbps. The data acquisition and randomness extraction are integrated into a field-programmable gate array (FPGA). Furthermore, to achieve compactness, all components of the QRNG are integrated onto three independent printed circuit boards in a compact design, and the QRNG is housed in a small enclosure measuring 140mm x 120mm x 25mm. The final random bit sequence can pass all NISTSTS and DIEHARD tests.

[0038] According to a first aspect, there is provided an apparatus for generating data keys (e.g., encryption keys, post-quantum encryption keys), the apparatus being a self-contained hardware unit configured to operate at room temperature, the apparatus comprising: a quantum random number generator including a quantum device for generating a quantum random bit stream; an extractor for generating certified random numbers using a quantum random bit sequence received from the quantum device; and a data control and processing unit configured to control and monitor operation of the apparatus.

[0039] Referring to FIG. 1 , an embodiment of a data key generation device is shown, generally designated 10. The data key generated by device 10 during operation is optionally a cryptographic key, e.g., a post-quantum cryptographic key. Device 10 further includes an optical system (quantum device) 22 that provides random quantum events, an extractor 30, a pseudorandom number generator 40, and a control system 60 that functions in use to perform statistical tests based on entropy evidence, e.g., evidence of entropy associated with generator 20, as well as a data processor and interface 50. In some cases, control and processing system 60 can be a self-contained electronic system. Advantageously, it is difficult for a malicious third party to monitor signals within such an electronic system and thereby intercept data flows and data processing operations occurring therein, thus making it difficult for a malicious third party to capture any information that could compromise the security of the system or the randomness of certified random numbers generated by the system. In various implementations, control and processing system 60 may include a field programmable gate array (FPGA), a development board (e.g., a board including a central processing unit (CPU) and / or an FPGA), a microcontroller, a microprocessor, an application specific integrated circuit (ASIC), or other system. In some cases, pseudorandom number generator 40 and data processor and interface 50. In some cases, control and processing system 60 may include an analog-to-digital converter or a digital-to-analog converter.

[0040] Optionally, portions of the data interface and control unit 50 are implemented using a microprocessor and / or microcontroller configured to execute one or more software products for performing the functions of the device 10, as described above.

[0041] In some cases, in the device 10, at least a portion of the quantum random number generator 20 is carefully electromagnetically shielded from electronic switching devices, such as control systems, to reduce any signaling that occurs between the device and the electronic switching devices. Such shielding is beneficially achieved using a ferromagnetic conductive sheet, e.g., a mu alloy sheet, although other conductive shielding materials may alternatively be used. In some cases, as shown in FIG. 3 , at least a portion of the quantum random number generator 20 may be attached to an actuator mechanism 220 and may also be provided with a solid-state vibration sensor 200, with a vibration signal from the vibration sensor 200 provided via a negative feedback loop amplifier 210 to drive the actuator mechanism 220 to counteract vibrations experienced in critical portions of the quantum random number generator 20. Such an implementation allows the device 10 to be installed in a high-vibration environment, e.g., an equipment rack where cooling fans cause significant environmental vibration and acoustic noise. Optionally, the actuator mechanism 220 includes at least one of a piezoelectric actuator 230A and an electromagnetic actuator 230B. Optionally, such active damping is activated on demand when device 10 is needed to distribute data keys, but is otherwise deactivated to reduce power waste within device 10.

[0042] The quantum devices of generator 20 are configured to use at least the quantum phenomenon of quantum superposition to generate data streams having a minimum level of entropy, and these high entropy data streams are statistically processed within control and processing system 60 and subjected to entropy level tests using entropy evidence, e.g., when the data streams pass the entropy evidence test, they are thereby determined to have an entropy level greater than the minimum entropy associated with the corresponding entropy evidence.

[0043] The device 10 may be physically compact, e.g., 1000 cm 3 Less than, more arbitrarily, 500 cm 3 Less than, more arbitrarily, 300cm 3 It is understood that the device 10 is intended to be contained within a volume less than 100 .mu.m and to be able to function near (substantially) room temperature, i.e., in the room temperature range of about +0°C to +40°C, although the device 10 can be configured to function outside this range if desired. By using photonics components, it is feasible to implement quantum devices such that they do not require cooling or refrigeration, thereby allowing a compact mechanism to be realized. When in use, the quantum devices of generator 20 detect the presence or absence of individual photons by either temporal or spatial discrimination, or both. Preferably, the quantum devices are temperature stabilized, e.g., heated to function at a steady-state temperature of +45°C when in operation.

[0044] 2A is a block diagram illustrating an exemplary experimental setup that may be used to characterize an output light beam (photon stream) generated by a light source 25 (e.g., a laser), optionally attenuated before being split by a beam splitter 100. A given photon passing through splitter 100 may either follow a first optical path A 110A and be received at a first detector A 120A, or follow a second optical path B 110B and be received at a second detector B 120B, but not both at a given instant. In some cases, for example, when light source 25 is a single-photon source, if signals are generated at both detectors 120A, 120B at a given instant of propagation of a given photon, the corresponding signals SIG.A and SIG.B are likely to be stochastic classical noise. In some cases, if a signal is generated in only one of detectors 120A, 120B at a given moment, the corresponding signal SIG.A or SIG.B can be associated with a quantum event. Detectors 120A, 120B may have high sensitivity and low noise. In some cases, detectors 120A, 120B may include single-photon detectors.

[0045] In some embodiments, light source 25 comprises a solid-state laser or an erbium-doped fiber laser. Optionally, light source 25 is operated as a pulsed light source or comprises a pulsed laser. Optionally, light source 25 is operated as a self-pulsating laser. In some cases, such pulsed operation may reduce power dissipation and lower cooling requirements for light source 25.

[0046] In some embodiments, the light source 25 is temperature controlled when in operation; for example, the laser 25 beneficially has an associated built-in temperature sensor and associated temperature feedback control loop to maintain heat dissipation within the laser 25 so as to operate at a substantially constant operating temperature. In some embodiments, the light source 25 is electromagnetically shielded against stray electrostatic radiation or electromagnetic ambient radiation. In some cases, the output light beam generated by the light source 25 is attenuated as described above before being allowed to propagate along the first optical path A 110A and be received at the first detector A 120A or along the second optical path B 110B and be received at the second detector B 120B; such attenuation is required to enable a relatively low photon flux and satisfy energy-type constraints on the quantum states of the photons received by the first and second photodetectors 120A, 120B.

[0047] 2B shows an exemplary optical system 22 used in apparatus 10. In some cases, temporal discrimination may be used to detect individual photons within the optical beam of photons propagating during operation from laser 25 to detector A 120A. Again, detector 120A needs to have high sensitivity and low noise to be able to detect individual photons. Using temporal discrimination of individual photons potentially results in apparatus 10 being simpler in design and more compact than when the mechanism of FIG. 2A is used.

[0048] 2B, light source 25 is optionally a solid-state laser or an erbium-doped fiber laser, as described above. Optionally, laser 25 is a mode-locked laser 25. Optionally, laser 25 is operated as a pulsed laser. Optionally, laser 25 is operated as a self-pulsating laser. Optionally, laser 25 is temperature-controlled when in operation. Optionally, laser 25 is electromagnetically shielded from all stray electrostatic or electromagnetic ambient radiation, thereby operating in a nearly, and more optionally, substantially non-signaling manner (i.e., completely shielded from all forms of crosstalk from other components of device 10). The output beam from laser 25 is attenuated before being allowed to propagate to detector A 120A. Such attenuation is required to provide a photon flux having quantum states that satisfy the energy-type constraint.

[0049] In some embodiments, output parameters of laser 25 of optical system 22 may be monitored for changes over time that may affect the performance of apparatus 10. If the change is greater than a threshold amount, apparatus 10 is configured to send a warning message to a user of apparatus 10. Optionally, a feedback loop is included in apparatus 10 to control laser 25 so that the pulse power or the number of photons in the optical pulse remains substantially constant, and in some cases, changes may be monitored to determine aging in apparatus 10, for example, by comparison with a mathematical model of apparatus 10. If the changes indicate that apparatus 10 is potentially becoming unreliable, a warning is sent to a user of apparatus 10 via a user interface. In some implementations, the optical output from laser 25, i.e., the spectral composition of the beam, is monitored, for example, using an optical Bragg grating with an associated array light sensor to identify individual spectral components of the optical output.

[0050] Because detecting individual photons is technically extremely difficult given the small signals involved, the output from a quantum device contains components of classical stochastic noise (e.g., thermal noise in the photon detector and associated amplifiers) as well as quantum noise. A test for a quantum phenomenon can be verification that the output from the quantum device represents a quantum event and is suitable for use in generating random numbers (e.g., data keys) in apparatus 10, for example, post-quantum cryptographic keys.

[0051] During operation, quantum random number generator 20 provides extractor 30 with a string of 0s and 1s as logic states, referred to as a “QRNG.” During operation of apparatus 10, the QRNG is statistically verified as having a sufficient level of entropy by statistical test 24. In some cases, statistical test 24 may include testing the QRNG using an entropy evidence designed to determine whether the QRNG's entropy level exceeds a threshold entropy level associated with the entropy evidence. Preferably, extractor 30 is configured to function as a Dodis extractor, although other implementations of extractors are feasible for use in apparatus 10. Pseudorandom number generator 40 generates pseudorandom numbers used to trigger optical device 22 to generate quantum events usable to generate QRBSs, which are provided to extractor 30 to generate post-quantum cryptographic keys for output from apparatus 10. In some examples, apparatus 10 may generate over 50 million post-quantum cryptographic data keys per second. As is known from Claude Shannon's theory, for optimal data security, a cryptographic key may only be used once (i.e., a "nonce") and should ideally have a bit length comparable to the length of the data being encrypted. Thus, when device 10 is used in highly secure cybersecurity systems required to provide high data throughput, many post-quantum cryptographic keys may be used per second, e.g., millions of such keys per second, and device 10, when in operation, may be capable of distributing such a large amount of data keys.

[0052] The random number generators described herein (e.g., device 10) can be semi-device-independent (SDI) random number generators that generate certified random numbers based at least in part on quantum events. These random number generators may be designed to provide an optimal tradeoff between ease of practical implementation in a self-contained, compact hardware mechanism and providing extremely high data security. Furthermore, these random number generators are advantageous in that they can be operated with modest energy consumption, i.e., consuming power on the order of a few watts during operation, optionally less than 1 watt. In some embodiments, these random number generators implement QRNG protocols, including those described in the publication entitled "Semi-device-independent framework based on natural physical assumptions" by T. V. Himbeeck, E. Woodhead, N. J. Cerf, R. Garcia-Patron, and S. Pironio, Quantum 1 (2017), https: / / doi.org / 10.22331 / q-2017-11-18-33, herein referred to as "Himbeeck / Pironio," and the publication entitled "Correlation and randomness generation based on energy constraints" by T. V. Himbeeck and S. Pironio, arXiv:1905.09117v1 [quant-ph], the entire contents of which are incorporated herein by reference. In an embodiment, the quantum random number generator may utilize the "On-Off-Keying" (OOK) method as described in Himbeeck / Pironio.

[0053] When attempting to build a device that implements a quasi-device-independent QRNG protocol such as that described by Himbeeck / Pironio, two objective problems are encountered: Problem 1: Himbeeck / Pironio does not teach how to build a quantum random number generator, but only provides theoretical justification and mathematical proofs. Therefore, inventive effort is required to put Himbeeck / Pironio's theoretical ideas into practice. The embodiments of the present disclosure are distinguishable from the teachings of Himbeeck / Pironio because Himbeeck / Pironio does not teach how to design a suitable randomness certificate for use in the control and processing system 60 of device 10 to ensure that at least a minimum threshold of entropy in the generated QRNG data is achieved, and furthermore, Himbeeck / Pironio does not teach how to build a practical, low-power device that can be used in challenging environments likely to encounter, for example, environmental temperature changes and mechanical vibrations. Issue 2: Implementing device 10 and experimentally verifying assumptions used when designing device 10 to ensure that the data key has sufficient entropy, e.g., manufacturing device 10 includes experimental verification that the light generated by the light source of optical system 22 satisfies the energy-type assumptions (e.g., the energy-type assumptions described in Himbeeck / Pironio).

[0054] FIG. 4A is a block diagram illustrating a system 400 that may be used to generate certified random numbers associated with quantum events using a preparation-and-measurement (OOK) method. In some embodiments, the system 400 may include a quantum device (e.g., a photonic quantum device) 402 in communication with and controlled by a classical computing device 404. The quantum device 402 generates a quantum random bit string (QRBS) including quantum random bits associated with a quantum event (e.g., the detection of a photon). The quantum device 402 may generate the quantum random bits using a two-step process including preparing a quantum state using a preparation process 406 triggered by the classical computing device 404 and a measurement process 408 including measuring the quantum state. The classical computing system may trigger the preparation process 406 by generating a trigger signal and sending a first portion 411a of the trigger signal to the quantum device 402. In some cases, the trigger signal may include a pseudorandom number (PRN) generated by a seeded pseudorandom number generator (PRNG) 410. In some cases, the preparation process 406 may be constrained by an energy-type constraint, resulting in a constrained quantum state 407. In some cases, such a constrained quantum state 407 may generate quantum random events when measured. A plurality of measured random quantum events may be transmitted to the classical computing device 404 as a quantum random bit string (QRBS) 409. The classical computing device 404 may then use an evidence verification process 412 to verify that the entropy level of the QRBS 409 is greater than a minimum entropy associated with the entropy evidence. In some examples, the verification process 412 may include evaluating the QRBS 409 using the second portion 411b of the triggered signal received from the seeded PRNG 410 and at least the entropy evidence. In some cases, the verification process 412 may evaluate the QRBS 409 using the second portion 411b of the triggered signal and sorted groups of entropy evidence sorted based on corresponding entropy levels.In some such examples, the verification process 412 includes sequentially evaluating (QRBS) 409 using individual entropy evidences in the sorted group, starting with the entropy evidence with the highest entropy level, until (QRBS) 409 satisfies the entropy condition associated with the entropy evidence. In some cases, the different entropy evidences in the sorted group may be associated with different physical states of the quantum device 402. For example, the different entropy evidences in the sorted group may be associated with different temperatures of the quantum device 402, with the first witness function having the highest entropy level being associated with the lowest temperature. Such an evidence verification process may result in a lower rate of QRBS rejection, as a QRBS with a lower level of entropy due to the physical state of the quantum device 402 can still be verified by an entropy evidence with a lower entropy level (lower in the sorted group).

[0055] Once one or more QRBSs are verified using the evidence verification process 412, the verified QRBSs 413 may be sent to a seeded randomness extractor 416. The seeded randomness extractor uses a seed random number (e.g., a cryptographic seed) 414 and the verified QRBSs 413 to generate one or more certified random numbers 418. In some cases, the cryptographic seed 414 may be hard-coded into the classical computing device 404.

[0056] In embodiments, quantum device 402 may include a light source that provides photons having a constrained quantum state and a photodetector that detects the photons and generates a detection signal. In these cases, the constrained quantum state may have a constrained number of photons or a constrained overlap with the vacuum state. For example, the overlap between the constrained quantum state of the photons and the vacuum state may be greater than a threshold. The detection signals may be transmitted to classical computing device 404 as QRBS 409.

[0057] Advantageously, the measurement process 408 may have greater than a minimum entropy and may not be constrained by specific physical constraints for generating QRBS associated with quantum events.

[0058] 5A is a block diagram of an apparatus 500 for generating qualified quantum random numbers using the methods described above with respect to system 400. In some cases, apparatus 502 may include a photonic quantum device 502 that serves as quantum device 402. Photonic quantum device 502 includes a photonic system including a light source 506 configured to generate light (photons) and a photodetector 508 configured to detect photons received from light source 506 and generate a detection signal indicative of the received and detected photons.

[0059] The wavelength (e.g., center wavelength) of the light generated by light source 506 can be 400-700 nm, 700-1700 nm, 1700-2500 nm, or any value within a range formed by any of these values, or a smaller or larger value.

[0060] The light source 506 may include a photon source (507a) such as a laser, e.g., a solid-state laser, a fiber laser, a semiconductor laser, or other light source (e.g., a light-emitting diode). In some cases, the laser may emit a pulse with a pulse width (t P ) ). In some cases, the laser may be a pulsed laser configured to generate pulses of light having t Pcan be from 1 ns to 10 ns, from 10 ns to 20 ns, from 20 ns to 30 ns, from 30 ns to 50 ns, or any range formed by these values, or can be larger or smaller. In some cases, photodetector 508 is a single-photon detector (e.g., a single-photon avalanche diode or SPAD). In some implementations, the photonic system may include optical link 507b configured to receive light from photon source 507a, attenuate the received light, and transmit the attenuated light to photodetector 508. In some cases, the attenuated light may satisfy an energy-type constraint. In some examples, the light generated by photon source 507a may not satisfy the energy-type constraint, while the attenuated light does. The energy-type constraint may include a finite expected value of an observable (or measurable) physical parameter of the light (photon stream), such as energy, photon number, or quantum state overlap with the vacuum state. For example, the overlap between the quantum state of the attenuated light transmitted from optical link 507b to photodetector 508 and the vacuum state may be greater than a threshold. In some cases, the energy-type constraint may include a max-peak assumption that imposes an upper limit on the average energy observable by a user of apparatus 500 and an adversary with access to classical information related to photonic quantum device 502. In some examples, the characterization process may include using a “trusted detector” to measure properties of the resulting light or attenuated light (e.g., photon statistics). The trusted detector may be a photodetector that is thoroughly characterized and placed in a protected environment. Further details about the max-peak assumption are described below.

[0061] The detected signal generated by the photodetector 508 may be transmitted to measurement circuitry 519 configured to process and store the detected signal to generate a quantum random bit sequence (QRBS).

[0062] In some implementations, the photonic quantum device 502 may generate multiple detection signals using multiple preparation and measurement cycles (which may operate according to the OOK process). Each preparation and measurement cycle may include, for example, triggering the light source 506 to generate light (e.g., a light pulse) using a trigger signal, measuring (detecting) the resulting light, and storing the resulting detection signal. The trigger signal may cause the light source 506 to send a light pulse to the photodetector 508.

[0063] The trigger signal may be generated by a preparation circuit 518 that receives a pseudorandom number (PRN) generated by the pseudorandom number generator 510. The trigger signal may therefore comprise a random series of ON / OFF signals (corresponding to logic 1s and logic 0s) configured to cause the photon source 507a to generate a series of pulses randomly distributed in the time domain. The photon source 507a may be configured to generate light pulses upon receiving an ON signal and not generate light upon receiving an OFF signal. The preparation and measurement cycle may include receiving, by the light source 506, a signal that may be a random ON or OFF signal, and measuring a corresponding detection signal that may indicate the detection of one or more photons or the non-detection of a photon.

[0064] The apparatus 500 may use an evidence verification circuit or process 512 to determine and confirm the entropy level of the QRBS generated by the measurement circuit 519 using a signal (e.g., part of the trigger signal) generated by the preparation circuit 518 and at least one entropy evidence associated with a particular level of entropy. In some cases, the evidence verification process 512 may include a comparison between the QRBS and the entropy evidence to determine whether the entropy level of the QRBS is equal to or greater than the particular level of entropy. If the entropy level of the QRBS is determined to be equal to or greater than the particular level of entropy (associated with the entropy evidence), the QRBS is verified, and the evidence verification process 512 provides the verified QRBS (V-QRBS) to an extractor circuit or randomness extraction process 516. In some cases, the extractor 516 may include a seeded extractor that uses the seed random number 514 and the V-QRBS to generate the certified random number 530. The seed random number 514 may be, for example, a cryptographic random number hard-coded into the device 500 as part of the extractor circuit or extraction process 516 .

[0065] The apparatus 500 may include an electronic device 504 in communication with the photonic system of the photonic quantum device 502. In some implementations, the circuits or processes described above with respect to the apparatus 500 may be implemented in the electronic device 504 as processes executed by one or more electronic processors of the electronic device 504 using machine-readable instructions stored in a memory of the electronic device 504. In some cases, one or more of the circuits or processes described above with respect to the apparatus 500 may comprise individual circuits of the electronic device 504. The electronic device 504 may include a control and processing system 520 that controls the operation of the circuits and execution of processes within the electronic device 504, as well as the operation of the optical system of the photonic quantum device 502. The photonic quantum device 502 may include a photonic system (e.g., a light source 506 and a photodetector 508) and preparation 518 and measurement 519 circuits / processes implemented in the electronic device 504. In various implementations, the electronic device 504 may include a field programmable gate array (FPGA), a development board (e.g., a board including a central processing unit (CPU) and / or an FPGA), a microcontroller, a microprocessor, an application specific integrated circuit (ASIC), or other types of electronic devices. In some cases, the electronic device 504 may be connected to an external computing system (e.g., a classical computing system) and use the processor of the external computing system for at least some of the processing tasks performed to generate the certified quantum random numbers 530.

[0066] In some embodiments, the device 500 may be used in two or more modes, with each mode corresponding to a configuration of the device 500 to perform a computational task. For example, in a normal mode (also called an operational mode), the device 500 may be configured to generate certified random numbers 530, and in a kick-off mode, the device 500 may be configured to generate seed random numbers. In some cases, the device 500 may be operated in the kick-off mode during the manufacturing process to generate seed random numbers for use during the operational mode. In some cases, the device 500 may be operated in the kick-off mode after a period of operation in the normal mode.

[0067] 5B is a flow diagram illustrating an exemplary process 500 that may be used by a control and processing system 520 (also referred to as a controlled system 520) of the apparatus 500 during a normal mode (operational mode) to generate one or more certified random numbers. The control system 520 executes the process 500 using various circuits, processors, non-transitory memory elements of the electronic device 504, and information / instructions stored therein.

[0068] In block 502, a control system 520 triggers a light source 506 using a pseudorandom number generator 510 and a preparation process (or circuit) 518 to generate a photon stream and provide the photon stream to a photodetector 508. In some cases, providing the photon stream may include reducing the number of photons in the photon stream (e.g., using an optical attenuator 507). In some cases, the quantum state of the photon stream delivered to the detector may satisfy a maximum peak assumption (e.g., the quantum state may have a minimal overlap with the vacuum state).

[0069] In block 504 , a control system 520 detects and measures the photon stream generated in block 502 using a photodetector 508 and a measurement process (or circuit) 519 .

[0070] In block 506, the control system 520 stores the results of the measurement process of block 504 (e.g., the detected signal) in non-transitory memory of the electronic device 504. The measurement results may include random bits associated with the quantum events.

[0071] At decision block 508, the control system 520 determines the total number of stored measurements (random bits). If the total number of stored measurements is greater than or equal to the threshold, the process proceeds to block 510. If the total number of stored measurements is less than the threshold, the process returns to block 502. In some cases, the threshold is a predefined value stored in the memory of the electronic device 504.

[0072] In block 510, the control system 520 generates a QRBS using the stored random bits.

[0073] At decision block 512, the control system 520 determines the entropy of the QRBS using one or more entropy evidences. If the determined entropy of the QRBS is higher than the entropy level associated with the entropy evidence, the process proceeds to block 514. If the determined entropy of the QRBS is less than the entropy level associated with the one or more entropy evidences, the process returns to block 502.

[0074] 6 is a block diagram illustrating an exemplary optoelectronic system 600 for generating certified random numbers. Optoelectronic system 600 can be an implementation of apparatus 500 shown in FIG. 5A. Optoelectronic system 600 may include an electronic substrate 602 (e.g., serving as electronic device 504), an optical system 603 (serving as an optical system for photonic quantum device 502), and a power supply 604 configured to provide power to electronic substrate 602 and optical system 603.

[0075] The optical system may include a photon source 507a (e.g., a laser), an optical link 507b, and a photodetector 508. The electronics board 602 is connected to the laser 506 and the photodetector 508 via a wired or wireless link, for example, to send control signals and receive data signals. In some implementations, the photon source 507a is optically connected to the photodetector 508 via an optical link 507b including an optical connector assembly 608 and an optical fiber 610. The optical link 507b may serve as the optical attenuator 507 of the device 500. In some cases, the optical link 507b may include an absorptive optical attenuator. In some cases, the optical connector assembly 608 may include an absorptive optical layer configured to attenuate the light generated by the photon source 507a. In some cases, the total optical attenuation of the light transmitted through the optical link 507b may be configured to reduce the power of the light generated by the photon source 507b to satisfy an energy-type constraint.

[0076] In some cases, during a manufacturing or recalibration process, detector 508 may be replaced with a reliable photodetector to adjust parameters of photon source 507a and the total optical attenuation of link 507b so that one or more characteristics of the light detected by the reliable detector satisfy an energy-type constraint. In some cases, satisfying the energy-type constraint may include a maximum peak assumption. In some examples, the one or more characteristics of the light may include an average photon number or an overlap of the quantum state of the light with the vacuum state.

[0077] In some embodiments, system 600 may include an environmental sensor 612 configured to measure an environmental parameter (e.g., temperature). In these embodiments, the control system of electronic board 602 may use sensor signals received from environmental sensor 612 to determine that environmental conditions during the quantum random number generation process have changed beyond a threshold level. In response to such a determination, the control system of electronic board 602 may abort the quantum random number generation and / or evidence verification process. Alternatively or additionally, in response to such a determination, the control system of electronic board 602 may alert a user of device 600 that device 600 is malfunctioning and that the certified quantum random numbers are likely unreliable.

[0078] In some embodiments, a control system of the electronic board 602 may adjust or select values ​​for parameters of the electronic board 602 based at least in part on the sensor signals.

[0079] In some implementations, the output of the photon source 507a may include a sequence of periodically generated optical pulses having pulse widths between 1 ns and 100 ns, for example, when electronically triggered. In some cases, the repetition rate of the optical pulses can be between 1 and 100 MHz. The optical link between the photon source 507a and the photodetector 508 may include one or more absorbing neutral density (ND) filters in combination with intentionally decoupled optical fibers to achieve a desired average number of photons received by the photodetector 508 for a given optical output power generated by the light source 506. In some cases, the photodetector 508 may include a single-photon avalanche diode (SPAD). The SPAD may generate a single TTL pulse when a photon (or multiple photons) triggers an avalanche in the SPAD. The detection efficiency of the SPAD may be 60 to 90% for wavelengths between 600 nm and 700 nm. The dead time of the photodetector 508 may be 20 ns to 60 ns. The dark count of the photodetector 506 can be less than 200 Cps, less than 300 Cps, or less than 600 Cps.

[0080] In some implementations, extractor 30 or 516 may be beneficially implemented as an optionally seeded Dodis extractor. Parameters of extractor 30 or 516 may be adjusted by control and processing system 60 or electronic device 504. In some implementations, extractor 30 or 516 may be configured as a Markov model two-source extractor (e.g., when the device operates in kick-off mode). In some cases, extractor 30 or 516 may include a randomness extraction algorithm running on a processor of control and processing system 60 or electronic device 504.

[0081] The device 10, system 400, or device 500 may include one or more of the following innovations.

[0082] Innovation 1: Use of multiple proofs of randomness within the data key generator Ensuring that the device 10, 500, or system 400 is trustworthy in operation and provides certified random numbers or verifiable data keys, e.g., but not limited to, post-quantum cryptographic keys, is an essential attribute that the device 10, 500, or system 400 must provide to satisfy its practical end use in, e.g., banking systems, secure data communication systems, infrastructure safety-critical control systems, secure data storage systems, etc. Such verified operation of the device 10, 500, or system 400 may be provided by having proof of entropy hard-coded into the device 10, 500, or system 400, e.g., in the control processing system 60, classical computing device 404, or electronic device 504. Furthermore, including such proof of entropy may be useful to guarantee performance as the device 10, 500, or system 400 ages (e.g., as the corresponding quantum device ages).

[0083] The quantum device (e.g., optical system) of apparatus 10, 500, or system 400 can generate a sequence of output bits whose entropy can be strictly lower bounded based on the validity of quantum theory. In some implementations, this entropy lower bound is obtained by solving an optimization problem whose inputs are estimated probabilities of individual outputs (e.g., detection signals) for a given choice of preparation. Due to the complexity of the optimization algorithm, solving such an optimization problem using control processing system 60, classical computing device 404, or electronic device 504 may be difficult. To address this limitation, in some implementations, evidence of entropy may be used during the manufacturing process of apparatus 10, 500, or system 400 to determine whether an n-output-bit QRBS contains a certain minimum amount of entropy. Such entropy evidence may be expressed as a conditional probability P that indicates the probability of obtaining measurement a in response to preparation x given the measured behavior of the quantum device (e.g., optical system) or the operating conditions of the quantum device (e.g., typical or expected behavior of the quantum device).typ (a|x). Such conditional probabilities may be estimated by running the quantum device many times under expected environmental conditions. The resulting entropy evidence may be hard-coded into the control processing system 60, classical computing device 404, or electronic device 504 and used to determine whether the n output-bit QRBS is greater than a minimum entropy established to proceed to the extraction step.

[0084] The use of a single entropy proof is an effective alternative to solving the optimization on-board, assuming the behavior of the quantum device (optical system) does not deviate significantly from the "expected" conditions for which the single entropy proof was prepared and optimized. In some cases, variations in environmental conditions may result in a high probability that the QRBS will be rejected by statistical tests 24 or proof validation processes 412, 512. In some cases, when the environmental conditions of the quantum device differ from the environmental conditions associated with the entropy proof, the entropy level of the QRBS generated by the quantum device may be less than the entropy level associated with the entropy proof.

[0085] In a real implementation, a quantum device may operate over the expected lifetime of the device in a range of different environmental conditions (e.g., a range of temperatures between 10 and 40°C). Environmental conditions such as temperature can have a strong effect on the behavior of components (e.g., optical components) of the quantum device, which can be expressed as a conditional probability P typThis may result in a dependence of (a|x). Similarly, aging of optical components may affect the expected behavior of a quantum device. To account for variability in quantum device behavior (e.g., due to variable environmental conditions), inventive aspects of the systems disclosed herein include preparing or designing different entropy proofs appropriate for different environmental conditions to which the quantum may be exposed and / or different behavior of the quantum device that may be expected over the lifetime or operation of the corresponding apparatus or system. By way of example, when a quantum device of apparatus 10, 500, or system 400 is expected to function over a temperature range between 10°C and 40°C, three entropy proofs may be designed for operation from 10°C to 20°C, 20°C to 30°C, or 30°C to 40°C. Depending on the level of sensitivity of the quantum device's behavior to temperature, additional entropy proofs may be designed for use at smaller temperature intervals (e.g., every 5°C instead of 10°C).

[0086] Advantageously, using multiple entropy proofs can reduce the probability of aborting a cycle without adding assumptions to the random number generation protocol. In some embodiments, the individual entropy proofs provide bounds on the entropy that are valid across different environmental conditions, although the results may not be optimal. In some cases, different entropy proofs of the multiple proofs may be associated with different entropy levels. The individual entropy proofs may be used to determine that the entropy of a bit string (e.g., a qubit string) is greater than the entropy level associated with the individual proof function.

[0087] In some cases, the verification process 412 may evaluate the QRBS 409 using the second portion 411b of the triggered signal and multiple entropy evidences. In some such examples, the verification process 412 includes evaluating the (QRBS) 409 using each entropy evidence until the (QRBS) 409 satisfies the entropy condition associated with the entropy evidence. In some such examples, at least two entropy evidences may be associated with substantially equal entropy levels. In some such examples, at least two entropy evidences may be associated with different environmental conditions.

[0088] In some implementations, the multiple entropy evidences may be sorted based on corresponding entropy levels to form a sorted set of entropy evidence groups. Thus, in an operational mode of the apparatus 10, 500, or system 400, the statistical test 24 or evidence verification process 412, 512 may evaluate a QRBS received from a quantum device using a first entropy evidence of the sorted group, and if the QRBS does not meet the entropy level of the first entropy evidence, using a second entropy evidence of the sorted group, and continuing the evaluation process using subsequent entropy evidences in the ordered groups until the QRBS meets the entropy level of the entropy evidence. In some examples, the entropy evidence associated with the highest level of entropy may be placed first in the sorted group, followed by the remainder of the entropy evidence in descending order.

[0089] Therefore, the rate of generation of certified quantum random numbers may be determined by the initial proof that the entropy level is met by the QRBS, which means that the overall rate of generation of certified random numbers may be improved.

[0090] In some cases, the aging of the quantum devices of apparatus 10 may be monitored by monitoring the validation rate of received QRNs by statistical tests 24; for example, the validation rate may decrease as a function of the total operating time of apparatus 10. In some such cases, such a decrease may indicate that classical stochastic phenomena become more prominent and dominant as apparatus 10 functions, thereby potentially decreasing the rate at which post-quantum cryptographic keys can be generated from apparatus 10. Alternatively or additionally, other parameters may be used to monitor apparatus 10, such as: (i) the laser output power used in the quantum device; (ii) photodetector noise when no photons are received within the quantum device (e.g., when laser 25 or photon source 507a is turned off); and (iii) Changes in the spectral distribution of noise occurring in quantum devices, for example, changes in the spectral distribution of noise in laser output.

[0091] Thus, in an embodiment, multiple parameters may be monitored in device 10, each parameter affecting a different aspect of the certified random number or data key generation by device 10; for example, in some embodiments, some or all of the following parameters are monitored to verify the correct operation of device 10: (i) aging of components used in device 10; (ii) the energy output of the laser 25 (or photon source 507a) decreasing as a function of time; (iii) The dark count of the detector, which increases with time and is detected, for example, when the laser 25 (or photon source 507a) is turned off.

[0092] Optionally, the data interface and control unit 50 keeps a record of at least (i) to (iii) measurements over time, and when monitoring the operation of the device 10, performs statistical analysis of trends or compares to acceptable thresholds and generates a warning signal from the device 10 if the device 10 is potentially generating data keys with insufficient entropy.

[0093] In some embodiments, the control and processing system 60 or 520 may select an entropy evidence or a subset of entropy evidence from the sorted group of entropy evidence based at least in part on monitoring signals related to one or more of the monitored parameters listed above. In some cases, the monitoring signals may include sensor signals generated by sensors (e.g., environmental sensors).

[0094] Innovation 2: Seed generation for random sampling In some cases, the quantum random number generator may use a random "seed," i.e., data corresponding to a small amount of initial near-perfect randomness, to generate a random number (RN) for random number extraction, for example, when random number extraction is performed in extractor 30 of device 10 (or extractor 516 of device 500).

[0095] This seed is used by extractor 30 (or extractor 516) during the randomness extraction step to randomize the process by randomly selecting a hash function to be applied to the output of the RNG. The hash function may be selected based on the value of the seed. While the seed can be generated using an external high-quality RNG and then hard-coded into the device, in some applications it is desirable to generate the seed internally within the device, mitigating the need for an external seed.

[0096] Aspects of the invention discussed herein include implementing a "quick-off mode" or "quick-off phase" in which the device generates a seed. In some cases, the device 10 or 500 may be operated in a quick-off mode during the manufacturing process to generate a seed random number that is hard-coded into the device 10 or 500. In some cases, operation of the device 10 or 500 may include a quick-off phase prior to the normal randomness generation phase in which a seeded random number generator uses the seed generated in the kick-off phase.

[0097] In some implementations, the seed is generated on apparatus 10 or 500 using a quantum device (optical system) of QRNG 20 or photonic quantum device 502, i.e., from the first few uses of the quantum device. To generate the seed, the quantum device is used multiple times initially, i.e., during a "quick-off" phase, i.e., a latency period after which the quantum device settles to generate quantum random data with large entropy.

[0098] During use of device 10 (or 500), the device is configured to perform a hard reset. After completing a "quick-off" phase, device 10 can generate data keys upon request from one or more users of device 10.

[0099] Optionally, the aforementioned “quick-off” phase is repeated to provide extractor 30 (or extractor 516) with a new, fresh seed; such a method of operation, as opposed to having to input a pseudo-random seed from an external source to device 10 (or 500), makes device 10 (or 500) more robust in its operation against unauthorized third-party modification. Optionally, extractor 30 (or extractor 516) is used to perform a seeded extractor function when generating the aforementioned data key using the seed generated during the aforementioned “quick-off” phase. However, it will be understood that other types of extractors may be used in device 10 (or 500) instead of or in addition to a Dodis extractor; for example, a Diffie-Hellman extractor protocol is optionally used in extractor 30 (or 516) as an alternative to using a Dodis extractor protocol. In some cases, the same type of extractor protocol may be used both when generating seed data during the “quick-off” phase and when generating certified random numbers, but with different parameters. In some cases, the device control and processing system may change the parameters of the extractor algorithm to change the extractor 516 (or extractor 30) from a seed extractor during the normal (operating) phase to a two-source extractor during the quick-off phase.

[0100] 7 is a flow diagram illustrating an exemplary process 700 that may be used by the control system 520 of the random number generator device 500 during a quick-off phase or mode to generate one or more seed random numbers for use during an operational phase of the device 500 to generate, for example, certified random numbers 530. The control system 520 performs the process 700 using various circuits, processors, non-transitory memory elements, and information / instructions stored therein.

[0101] In block 702, the control system 520 generates a first bit string using the quantum device 502. In some examples, the first bit string may include n bits output from the measurement device 519. The first bit string may have a minimum entropy k1.

[0102] In block 704, control system 520 resets quantum device 502 to remove memory effects. In some cases, resetting quantum device 502 may include turning off quantum device 502 for a waiting period, e.g., quantum device 502 may be powered off and then powered on again after the waiting period. The waiting period may be long enough to erase data from a previous operation period (e.g., data or information left over by generating the first bit string in block 702) and prevent such data from leaking into a subsequent operation.

[0103] In block 706, the control system generates a second bit string using the quantum device 502 (e.g., after possibly being reset). In some examples, the second bit string may include m bits output from the measurement device 519. The second bit string may have a minimum entropy k2. In some examples, m can be equal to n. In some examples, n and m are predetermined values ​​stored in a memory of the electronic device 504.

[0104] In some embodiments, the control system 520 may skip block 704 and generate the second bit sequence after generating the first bit sequence without allowing the quantum device 502 to rest.

[0105] At decision block 708, the control system 520 uses the evidence verification process 512 (e.g., an evidence verification algorithm implemented in the electronic device 504) to determine whether the minimum entropy (k1+k2) of the sum of the first bit string and the second bit string is greater than or equal to a threshold (k th) to determine whether k1+k2 is greater than k th If k is greater than 1, the control system sends the first and second bit strings to the extractor 516 and the process 700 proceeds to block 710. th is essentially equal to n+k, k>0. k1+k2 is k th If so, the process 700 returns to block 702 .

[0106] In some embodiments, the evidence verification process 512 uses one or more entropy proofs hard-coded into the electronic device 504. Similar to the operational phase, the entropy proofs used during the quick-off phase (or quick-off mode) may be selected from multiple entropy proofs hard-coded into the electronic device 504 based on a set of operational and / or environmental conditions of the quantum device 502. In some cases, at least some of the entropy proofs used during the quick-off phase (or quick-off mode) may be the same as the entropy proofs used during the operational phase. In some cases, one or more entropy proofs may be dedicated to quick-off phase operation. For example, the entropy proofs hard-coded into the device may include entropy proofs used exclusively during the quick-off phase and entropy proofs used exclusively during the normal phase. Advantageously, using dedicated entropy proofs during the quick-off phase may improve the efficiency and / or reliability of the resulting random seed numbers.

[0107] At block 710, the control system 520 configures the extractor 516 as a two-source extractor. For example, the control system 520 may modify one or more parameters of the extractor algorithm or run a dedicated two-source extractor algorithm using the computational resources of the electronic device 504. The two-source extractor is configured to generate (extract) a random number using two input random numbers. The two-source extractor 516 then generates a third bit string using the first bit string and the second bit string received from the evidence verification 512. In some examples, the third bit string may be a near-perfect random bit string with a minimum entropy that exceeds the minimum entropy of the first bit string and the second bit string. The control system 520 stores the third bit string in non-transitory memory (e.g., memory associated with the evidence verification), and the process proceeds to block 712.

[0108] At decision block 712, the control system determines whether the number of near-perfect random bit sequences generated by quantum device 502 and stored in electronic device 504 exceeds a threshold number (N th ) or more. th ), process 700 proceeds to block 714. If the number of near-perfect random bit sequences is N th If so, the process returns to block 702. In some examples, N th may be determined based on a selected security parameter of the near-perfect output bits. th may be limited by the computational power of the electronic device 504. In some cases, N th may be determined based on the time interval over which the number of random seeds generated by process 700 may be used in device 500. For example, a seed of size 4096 may be reliable for 50 days of operation, but if the device must operate for 10 years without receiving a new number of seeds, 73 seed random numbers of size 4096 may be required. In various implementations, N th1000 to 5000, 5000 to 10 3 Up to 10 3 From 5 x 10 3 Up to 5 x 10 3 From 10 4 Up to 10 4 From 10 5 Up to 10 5 From 10 6 It can be up to or even greater than this.

[0109] In some implementations, the steps described above with respect to blocks 702 through 712 may be repeated M times before the process proceeds to block 714. In some examples, M may be less than or equal to N th It is possible for the .DELTA..times ...

[0110] In block 714[6], the control system 520 generates a seed random number 514 using at least a portion of the near-perfect random bit string and stores the seed random number 514 in non-transitory memory of the electronic device 504 for use during an operational phase or mode.

[0111] Advantageously, resetting the system at block 504 may enable the use of a Markov model extractor 30. In some examples, extractor 516 (e.g., when configured as a two-source extractor) can be a "Dodis extractor." Examples of such extractors are discussed in "Practical randomness amplification and privatization with implementations on quantum computers," 2009, arXiv:2009.06551v2.

[0112] In some cases, if the third sequence is a near-perfect random bit sequence, n can be as large as 10. 4 Greater than or equal to 10 5 Greater than or equal to 10 6n can be larger than n. In some cases, n may be limited by the extractor 516. In some such cases, the extractor 516 may be executed by a processor of a computing system separate from the electronic device 504 of the apparatus 500, for example, to enable extraction of the third random bit sequence from the large first and second bit sequences. Such a computing system may have greater computing power compared to the electronic device 504 (e.g., an FPGA) of the apparatus 500. In some cases, the computing system may include a notebook, personal computer, notepad, or other computing system. In some cases, the computing system may be connected to the apparatus 500 via a wired or wireless data link.

[0113] In some implementations, to generate a large seed random number, for example, a seed number large enough to enable the use of a Dodis extractor during the operational phase, the quick-off phase described above may be used during the manufacturing phase (or recalibration phase) of the device 500 to generate such a large seed random number, which is then hard-coded into the electronic device 504 of the device 500 for use throughout the life of the device 500.

[0114] In some implementations, the device 500 may be configured in quick-off mode to generate one or more seed random numbers. 4 bits or greater than 10 5 bits or greater than 10 6The device 500 may be connected to a computing system for generating seed random numbers larger than 128 bits. These seed random numbers may be stored or hard-coded in one or more random generators similar to the device 500 so that they can be used to generate certified random numbers 530 in normal mode without the need for any quick-off phase. Such device operation may be referred to as randomness amplification or multi-source extraction. Thus, random numbers generated using the device 500 in quick-off mode may replace the cryptographic seed 414 of the system 400 or device 500, eliminating the need for a cryptographic seed generated by a classical computing system or the need to interrupt device operation and switch to a quick-off phase.

[0115] Innovation 3: Light source manufacturing, calibration, and certification During manufacture of the apparatus 10, 500, or optoelectronic system 600, the laser 25 (or photon source 507a) may be characterized using a number of methods to ensure that the laser 25 (or photon source 507a) is functioning in a manner that enables the QRNG 20 or photonic quantum device 502 to generate quantum random bit strings, where the randomness is associated with quantum events, using the preparation and measurement methods described above.

[0116] In some implementations, during the manufacturing process and / or recalibration of apparatus 10, 500, or optoelectronic system 600, the light source may be factory calibrated and certified for use in a quantum device used to generate quantum random bit sequences (e.g., for use as light source 506 of photonic quantum device 502 or light source of optical system 22 of QRNG 20). As described above, the light source may include a photon source and an optical link, where the optical link transmits at least a portion of the light generated by the photon source to a photodetector of the quantum device. For calibration and certification, the light source may be optically connected to a trusted photodetector. In some cases, the trusted photodetector (also referred to as a trusted detector) may be a detector dedicated to calibrating and certifying the light source of the quantum device used to generate quantum random bit sequences. It will be understood that the trusted detector is meticulously calibrated. In some embodiments, the trusted photodetector may be mechanically, thermally, electromagnetically, electrically, or magnetically isolated from the surrounding environment. Alternatively or additionally, the trusted photodetector may be protected from tampering by an adversary. Thus, the detection signal (e.g., photocurrent) generated by the reliable photodetector may not be affected by any parameters other than the light received by the light source or, in some cases, changes or effects related to the internal circuitry of the photodetector. In some cases, the reliable photodetector may be battery-powered to electrically isolate the reliable photodetector. In some cases, the use of such a reliable detector may be limited to the manufacturing process of the device 10, 500, or optoelectronic system 600, and the reliable photodetector may not form an integral part of the device 10, 500, or optoelectronic system 600.

[0117] In some embodiments, the trusted detector may be optically connected or coupled to laser 25 (or photon source 507a) of optical system 22 (or photonic quantum device 502) of QRNG 20 without the use of any lens disposed between laser 25 (or photon source 507a) and the trusted detector. In some cases, the trusted detector may be optically connected to laser 25 (or photon source 507a) of optical system 22 (or photonic quantum device 502) of QRNG 20 via optical path 110A (or optical link 507b) that is also used to optically connect laser 25 (or photon source 507a) to detector 120A (or photodetector 508) after a calibration and qualification process. In various implementations, an optical link (e.g., optical path 110A or optical link 507b) used to transmit light generated by a photon source (e.g., laser 25 or photon source 507a) to a trusted detector may include optical connectors (e.g., fiber optic connectors), optical attenuators, and / or optical fibers (e.g., single-mode fiber optic waveguides). Such optical links may be configured to attenuate the light generated by the photon source (light beam) such that the power of the light received by the trusted photodetector (optical power) is 1 to 3 dB, 3 to 6 dB, 6 to 10 dB, 10 to 15 dB, 15 to 20 dB, 20 to 25 dB, 25 to 30 dB, or any range formed by these values, or a greater or lesser value. In various implementations, the optical link (e.g., optical path 110A or optical link 507b) used to transmit light generated by the photon source (e.g., laser 25 or photon source 507a) to the reliable detector may include an optical connector (e.g., an optical fiber connector), an optical attenuator (e.g., a tunable attenuator), and / or an optical fiber (e.g., a single-mode optical fiber waveguide). The attenuation of the optical link may be tunable or adjustable by a user.In some examples, optical attenuation through the optical link may be associated with insufficient coupling of the laser 25 (or photon source 507a) to the optical fiber used when calibrating the light source during the manufacturing process and also used during operation of the apparatus 10, 500, or optoelectronic system 600. This type of optical attenuation may reduce the complexity of the light source and its susceptibility to misalignment and environmental disturbances. In some cases, the optical link between the photon source and the trusted detector (and between the photon source and the photodetector after calibration) may include an optical attenuator and an optically absorptive filter. In some such cases, the optical attenuation of the optical link may be adjusted by selecting a different fixed attenuator or by changing the attenuation of a tunable optical attenuator. After adjusting the attenuation of the optical link, the optical link may be carefully disconnected from the trusted photodetector and connected to the quantum device's photodetector, while avoiding any changes in the optical link that may cause changes in the attenuation of the optical link, so that, for a given setting of the photon source, the optical power received by the quantum device's detector is substantially equal to the optical power received by the trusted photodetector at the factory.

[0118] As mentioned above, the level of attenuation of light from laser 25 (or light source 506) to a reliable detector may be designed or adjusted so that the quantum state of the light received by the photodetector satisfies energy-type constraints, such as having a minimum overlap with the vacuum state.

[0119] In some implementations, the light source calibration and qualification process may include adjusting the power of light output by the light source (the optical power received by the trusted photodetector) using the trusted photodetector so that the light received by the trusted photodetector satisfies the energy-type constraint. In some cases, measuring the detection signal generated by the trusted photodetector during a measurement period may be used to evaluate the quantum state of the light received by the trusted photodetector to determine whether the quantum state satisfies the energy-type constraint. Advantageously, switching the trusted detector with a photodetector (e.g., photodetector 508) used in apparatus 10, 500, or optoelectronic system 600 without changing components between the photon source and the photodetector can ensure that the light received by the photodetector in a quantum device (e.g., photonic quantum device 502, or QRNG 20) satisfies the energy-type constraint.

[0120] Preferably, in the device 10, 500, or optoelectronic system 600, the laser 25 (or photon source 507a) is temperature controlled by using a temperature sensing feedback loop as described above, for example, the laser 25 (or light source 506) is attached to a Peltier thermoelectric element and includes a temperature sensor coupled to a feedback loop that maintains the laser 25 (or light source 506) at a constant temperature when in operation; alternatively, the laser 25 (or photon source 507a) is operated at a constant temperature slightly higher than the ambient temperature of the device 10, 500, or optoelectronic system 600. Optionally, the laser 25 (or photon source 507a) is operated in a triggered pulse mode in the device 10, 500, or optoelectronic system 600, rather than in a continuous operation mode; such a method of operation may enable the device 10, 500, or optoelectronic system 600 to generate a QRBS based on a preparation and measurement protocol, for example, in situations where the device 10, 500, or optoelectronic system 600 is battery powered (such as in a portable device), while reducing power consumption within the device 10, 500, or optoelectronic system 600.

[0121] In some cases, the current provided to the photon source 507a (e.g., a laser) to generate light may be substantially equal to a critical current of the photon source 507a. In some cases, the current provided to the source 507a may be adjusted so that a characteristic of the light output by the photon source 507a meets a threshold condition. In some examples, the characteristic may include a noise level (e.g., relative intensity noise) or a coherence level, and the threshold condition may include a threshold noise level or a threshold coherence level.

[0122] In some implementations, the calibration and qualification process may include using a photodetector to measure a portion of the light received by the reliable photodetector while controlling the photon source with a trigger signal. In some examples, the trigger signal may include a series (e.g., a random series) of on / off signals that cause the light source to generate multiple light pulses during a measurement period. In some cases, the photon source may be a pulsed light source configured to generate a light pulse upon receiving an on signal. In some cases, the trigger signal used during the measurement period may be a pseudorandom bit string, and individual light pulses generated by the photon source may be triggered by bits of the pseudorandom bit string. The reliable photodetector receives the multiple light pulses and generates multiple detection signals, each signal indicating the detection of at least one photon. Using the trigger signal (indicating the expected temporal distribution of the light pulses) and the multiple detection signals (indicating photon detection events), the probability (e.g., average probability) of occurrence of a photon detection event with and without a light pulse may be determined. For example, the pseudorandom bit string used to generate the light pulses may be used to determine the average probability of photon detection for the resulting light pulses.

[0123] This probability may then be used to determine the overlap of the quantum state of the light pulse generated by the light source with the vacuum state (an example of testing an energy-type constraint). Advantageously, this approach does not require photon counting, as the number of photons detected in each photon detection event is not required for the probability calculation.

[0124] Other energy-type constraints on the light source can also be tested using a reliable detector that receives light from the photon source via an optical link. For example, in some cases, the reliable detector may be used to measure the average photon number of multiple light pulses generated by the light source (triggered by a trigger signal) during a measurement period. In some cases, an upper limit on the measured average photon number may be used to determine that the quantum state of light received by the photodetector (output by the light source) satisfies the energy-type constraint (in this case, the photon number).

[0125] In some cases, in response to determining that a portion of the light received by the trusted photodetector during a first measurement period does not satisfy a selected energy-type constraint, a user or an automated system may adjust the optical link to attenuate the portion of the light received by the trusted photodetector. Then, during a second measurement period, the measurement process described above (e.g., with respect to overlap with the vacuum state) may be repeated to determine whether the quantum state of the portion of the light received by the photodetector after increasing the attenuation satisfies the energy-type constraint. This process may be repeated until the light output by the light source satisfies the energy-type constraint, and accordingly, the light source may be certified for use in a quantum device (assuming no changes were made to the optical link during installation in the quantum device).

[0126] As described above, adjusting the optical link may include adjusting the level of optical attenuation of a tunable optical attenuator included in the optical link, or adjusting the level of optical attenuation or reducing optical coupling at an optical junction (e.g., connection or coupling to an optical fiber waveguide). In some cases, the qualified light source optical link may attenuate light generated by the photon source by 1 to 3 dB, 3 to 6 dB, 6 to 10 dB, 10 to 15 dB, 15 to 20 dB, 20 to 25 dB, 25 to 30 dB, or any range formed by these values, or by a greater or lesser value.

[0127] In some cases, during manufacturing of the apparatus 10, 500, or optoelectronic system 600, various properties of the light generated by the laser 25 (or photon source 507a) may be characterized. In some cases, the characterization may include measuring the photon statistics of the light generated by these sources. In some cases, the characterization may include measuring the degree of coherence of the light generated by these sources. In some cases, the characterization may include measuring the degree of coherence of the light generated by these sources.

[0128] In some implementations, the light source calibration and qualification process includes isolating the light source from all external perturbations (e.g., mechanical, electrical, magnetic, thermal, and electromagnetic) and characterizing the stability of the photon source (e.g., laser) by measuring the light detected by a reliable photodetector over a time interval. The stability of the photon source may include, for example, the stability of the wavelength, power, coherence properties, or polarization of the light generated by the photon source.

[0129] For example, the power fluctuation statistics or photon statistics of the laser may be measured during a stability test period, which may be, for example, 1 to 5 seconds, and the results of the stability measurement are used to assess the validity of the maximum peak assumption.

[0130] Following this, the light generated by the light source may be characterized to test energy-type constraints (e.g., the overlap of the light's quantum state with the vacuum state) over a range of environmental conditions (e.g., temperature) expected during operation of the light source in the quantum device of the random number generator. A portion of the worst-case results (e.g., insufficient overlap with the vacuum state) may then be used to design the random number generation protocol. For example, the entropy proof may be designed taking into account the worst-case results to reduce the probability of rejecting the random qubit string in the entropy verification step. Furthermore, other aspects, such as the size of the random qubit string or the parameters of the seed extractor, may be selected based on the worst-case results obtained for the light source. As a result, in addition to adjusting the light source output according to the energy-type constraints, the light source calibration and qualification process allows the random number generation protocol and corresponding processes (e.g., randomness verification and extraction) to be tailored to the characteristics of the specific light source. This differs from existing QRNGs, in which the preparation of specific quantum states is required by the random number generation protocol independently of the light source, which can potentially result in a low rate of quantum random number generation.

[0131] In some implementations, photon statistics may be characterized using a method described in "Reconstruction of photon-number distribution using low-performance photon counters" by G. Zambra and M. G.A. Paris, published December 27, 2006, in Physical Review A, Vol. 74, 063830, herein referred to as "Zambra," the entire contents of which are incorporated herein by reference. In the Zambra method, when a laser beam is directed at a photodetector, the output of the photodetector includes a current pulse whose charge has the statistical distribution of the actual photon number convolved with a Bernoulli distribution. In the Zambra method, the inverse of the Bernoulli convolution may be performed by maximum likelihood, aided by measurements made on the quantum efficiency of different detectors. The method can be used to show that a detector that can distinguish between zero detected photons, one detected photon, and two or more detected photons is generally sufficient to provide reliable reconstruction of the photon number distribution for single-peak distributions. Furthermore, Zambra's method can identify that for quasi-classical states of light, even an on / off detector is sufficient to provide good reconstruction. Finally, Zambra's method can show that reliable reconstruction of multi-peak distributions requires either higher quantum efficiency or higher resolution.

[0132] In embodiments of the present disclosure, a simple "click / noclick" detector is beneficially used. Optionally, in embodiments of the present disclosure, it is feasible to distinguish between 0 and >1 photons.

[0133] In some cases, in apparatus 10, laser 25 is implemented as a self-pulsating laser, which allows laser 25 to limit its own pulse power, thereby giving laser 25 greater operational stability.

[0134] In various implementations described above, the photon sources used in the optics (photonic systems) of the devices 10, 500, the systems 400, and the optoelectronic systems 600 may include incoherent light sources or light sources having optical coherence lower than that of a laser beam. For example, the photon source 507a may include a light emitting diode (LED) or other light source that generates photons primarily by spontaneous emission.

[0135] Energy-like constraints on light sources Device-independent (DI) protocols provide cryptographically secure protocols for quantum random number generation. Besides a minimal set of assumptions about the physical implementation (e.g., that the device is shielded), these protocols may not require characterization of the quantum device (e.g., the quantum device used for quantum random number generation) because the security and privacy of the resulting quantum random numbers may not be affected by parameters other than those related to the statistics of the quantum device's output (e.g., the statistics of photons in a photon stream output by a quantum optical device). On the downside, device independence requires the use of entanglement-based protocols, which are experimentally demanding and provide very low, if any, rates of certified entropy.

[0136] The random number generation system described above operates based on a semi-device-independent (SDI) approach to quantum random number generation. By imposing appropriately selected additional physical assumptions on the system's devices (e.g., quantum devices), most of the security benefits of the DI approach may be maintained without the use of quantum entanglement or certain other features that limit the practical use of corresponding protocols due to challenges associated with the physical implementation of those features. An exemplary SDI approach used in apparatus 10, 500, system 400, and optoelectronic system 600 is a preparation-and-measurement approach in which a quantum state is prepared and then measured to generate quantum events or random qubits. In the preparation-and-measurement approach, the preparation (e.g., preparation of a photon stream) includes limited energy-type constraints (e.g., energy, photon number, overlap with vacuum) on the quantum state prepared by the quantum device source (e.g., laser). In contrast to constraints considered in some other approaches, such as the assumption that the state belongs to a finite-dimensional Hilbert space, the energy-type constraints can be experimentally monitored, providing a high level of confidence in the validity of the assumptions. Advantageously, this approach leaves the component most susceptible to adversary attack, the measurement device (eg, photodetector), uncharacterized.

[0137] In particular, the above-described apparatus 10, 500, system 400, and optoelectronic system 600 may implement an on-off modulation (OOK) protocol using a quantum device consisting of a light source (e.g., a laser) with two preparation modes (vacuum or coherent state) and a single-photon detector (SPD) that either detects photons or not. This is one of the simplest quantum devices capable of certifying randomness (e.g., quantum randomness) in a quasi-device-independent manner. The preparation selection is performed independently of the quantum device using the output of a biased pseudorandom number generator (PRNG), making this a randomness-enhanced protocol.

[0138] In some implementations, a preparation device, the "source" (e.g., a light source), and a measurement device, the "detector" (e.g., a photodetector), are connected via a quantum channel (optical link), but do not share any entanglement. The source and the detector are only allowed to communicate through the quantum channel. In some cases, the source takes an input x∈{0, 1} independently selected from the source and the detector, and generates one of two possible quantum states ρ χ These systems are sent to a detector where a measurement M with two possible outcomes a∈{-1, 1} is performed.

[0139] The probability of obtaining outcome a by choosing preparation x over many uses of the device may be expressed as p(a|x). In correlation space (which is equivalent to probability space since a is binary), the expected (statistical) value of the outcome for each preparation x may have the following form: E x = p(1|x) - p(-1|x) (1)

[0140] Equation 1 quantifies the bias of the outcome towards one of the two outputs. In a completely device-agnostic scenario, where we do not make any assumptions about the internal functionality of the device, a decisive strategy from the adversary's perspective would yield a correlation E x This means that if the source can send a selection of preparatory x to the detector, then any E can be obtained by a deterministic response function. x can be obtained, which can be easily understood by the fact that it depends on classical randomness shared by the detector and the adversary. Although seemingly random, the output from the detector is then perfectly predictable by the adversary.

[0141] Correlation E allowed for deterministic strategies xTo find the separation between the set of θ and the set of quantum strategies, one can add the assumption that the source prepares a state that has finite expectation value with respect to a given observable O. The observable O satisfies the following two conditions: i. O has a non-degenerate ground state ii. O has a finite gap between the ground state and the next eigenstate

[0142] Without loss of generality, it may be assumed that the eigenvalue associated with the ground state has value 0 and the gap is 1. Examples of such observables are energy, photon number, or overlap with the vacuum, which may be experimentally controlled and characterized. In some cases, the observable O may be called an energy observable. Appropriate bounds on the expectation value of O with respect to the prepared state may prevent the source from sending a choice of input x to the detector.

[0143] In some cases, users of quantum devices may ω x = Tr(ρ x O) (2) can be accessed.

[0144] An adversary with access to classical side information, denoted by a random variable Λ distributed on p(λ), can calculate the average energy

number

number

[0145] The maximum peak assumption also imposes an upper bound on the average energy observed by the adversary.

number

[0146] The maximum average assumption represents a lighter physical assumption about the source, i.e., a user can check its validity by measuring the energy of preparation x over a sufficient number of rounds with a reliable detector. The maximum peak assumption requires precise knowledge of the internal functioning of the source in order to impose absolute limits on the energy of states prepared by the source. It is possible to test and verify the validity of the maximum peak assumption for a given source (e.g., a light source such as a laser) by characterizing the source using a reliable detector.

[0147] Advantageously, the maximum peak assumption allows for randomness to be certified in cases where it may not be possible to do so under the maximum average assumption. An example is the on-off keying (OOK) scheme used in the random number generation system described above.

[0148] One of the challenges in implementing OOK schemes can be ensuring that the maximum peak assumption holds. This condition states that for a given power input, source (laser) temperature, and other source parameters, the average energy of any state prepared by the source is

number

[0149] Illustrative Embodiments Various additional exemplary embodiments of the present disclosure may be illustrated by the following examples.

[0150] Group 1 Example 1. 1. An apparatus for generating certified random numbers, the apparatus being a self-contained hardware unit configured to operate substantially at room temperature, the apparatus comprising: a quantum random number generator including a quantum device for generating a quantum random bit sequence; an extractor for generating certified random numbers using the quantum random bit sequence; and a control and processing unit configured to control and monitor operation of the apparatus.

[0151] Example 2. 10. The apparatus of Example 1 configured to generate data keys including post-quantum cryptographic keys.

[0152] Example 3. 3. The apparatus of Examples 1 or 2, wherein the quantum random number generator is implemented using a laser that generates photons, an optical mechanism configured to couple a portion of the photons from the laser to a detector mechanism, and a processing mechanism for processing signals from the detector mechanism, wherein the optical mechanism is configured with the detector mechanism to create conditions for single-photon quantum events in a spatial or temporal form, the detector mechanism is configured to detect the events, and the processing mechanism is configured to apply statistical tests to verify the level of entropy of the detected events.

[0153] Example 4. The apparatus of Example 3, wherein the statistical testing includes assessing the level of entropy of an event using evidence of entropy hard-coded into the apparatus.

[0154] Example 5. The apparatus of example 3 or 4, wherein the laser is implemented as a pulsed laser.

[0155] Example 6. The apparatus of any one of Examples 1 to 5, wherein the extractor is implemented as a Dodis extractor.

[0156] Example 8. The apparatus of any one of the preceding examples, wherein the apparatus is configured to switch from an operational phase when it outputs a data key to a "quick-off" phase in which the quantum device is used to generate seeds for use in a seeded random number generator.

[0157] Example 9. The device of any one of the preceding examples, wherein data processing required for the device to function when in use is implemented using at least one FPGA.

[0158] Example 10. 1000cm 3

[0023] The apparatus of any one of the preceding examples is implemented using hardware that can be contained in a volume of less than

[0159] Example 11. The device of any one of the preceding examples, wherein the device is configured to consume less than 10 watts when in operation.

[0160] Example 12. 1. A method of using an apparatus for generating certified random numbers, the apparatus being a self-contained hardware unit configured to operate at room temperature, the method comprising: (a) configuring an apparatus to include a quantum random number generator including a quantum device for generating a quantum random bit sequence; (b) using an extractor to generate certified random numbers using the quantum random bit sequence; (c) using the control and processing unit to control and monitor operation of the device.

[0161] Example 13. 13. The method of Example 12, comprising configuring a device to generate a random number as a post-quantum cryptographic key.

[0162] Example 14. A method using the device of Example 12 or 13, comprising: Example 15. Implementing a quantum random number generator using a laser to generate photons; Example 16. using an optical mechanism to couple a portion of the photons from the laser (25) to a detector mechanism; Example 17. processing signals from the detector mechanism using a processing mechanism, the optical mechanism being configured with the detector mechanism to create conditions for single photon quantum events in a spatial or temporal fashion; Example 18. detecting events using a detector mechanism and using the events to generate a quantum random bit sequence; and Example 19. using a processing mechanism to apply a statistical test to verify that the quantum random bit string satisfies a minimum entropy condition associated with a proof of entropy stored in the processing mechanism.

[0163] Example 20. A machine-readable data storage medium containing specific instructions executable in data processing hardware, the instructions, when executed by the data processing hardware, performing the method of any one of Examples 13 to 15.

[0164] Group 2 Example 1. 1. An apparatus for generating certified random numbers based at least in part on quantum events, comprising: a quantum device configured to generate quantum events; 1. A classical computing device in communication with a quantum device, the classical computing device comprising: a control and processing system, the control and processing system being in communication with the memory configured to store specific computer-executable instructions, and the control and processing system being configured to execute the specific computer-executable instructions to perform at least: Generate a quantum random bit string using a quantum device; determining an entropy level of the quantum random bit string using multiple entropy proofs; and a classical computing device, comprising a hardware processor configured to generate certified random numbers using the quantum random bit string in response to determining that the entropy level of the quantum random bit string is higher than an entropy level associated with an entropy evidence among the plurality of entropy evidences.

[0165] Example 2. The apparatus of Example 1, wherein the control and processing system uses a pseudorandom number generator implemented in a classical computing device to trigger a series of preparation steps in a quantum device and a corresponding series of measurement steps to generate a quantum random bit string.

[0166] Example 3. 3. The apparatus of Example 2, wherein the control and processing system determines an entropy level of the quantum random bit string based at least in part on a pseudorandom number generated by the pseudorandom number generator.

[0167] Example 4. The apparatus of any one of Examples 1 to 3, wherein the plurality of entropy evidences comprises a sorted set of entropy evidences sorted in descending order of entropy with respect to corresponding entropy levels.

[0168] Example 5. 5. The apparatus of Example 4, wherein the control and processing system determines the entropy level of the quantum random bit string by sequentially testing the quantum random bit string against the entropy evidences of the sorted set, starting with a first entropy evidence associated with the highest entropy level in the sorted set.

[0169] Example 6. 6. The apparatus of any one of Examples 1 to 5, wherein the plurality of entropy evidences includes at least two entropy evidences having substantially the same entropy level.

[0170] Example 7. 7. The apparatus of any one of Examples 1 to 6, wherein the control and processing system tests the quantum random bit string against a plurality of entropy proofs and determines that the entropy level of the quantum random bit string is higher than an entropy level associated with an entropy proof of the plurality of entropy proofs.

[0171] Example 8. The device of any one of Examples 1 to 7, wherein individual entropy proofs of the multiple entropy proofs are associated with different states of the quantum device.

[0172] Example 9. 9. The apparatus of any one of Examples 1 to 8, wherein the quantum device comprises a photonic system including a light source configured to generate light and a photodetector configured to receive the light generated by the light source and generate a quantum event.

[0173] Example 10. 10. The apparatus of example 9, wherein the light source includes an optical link configured such that light received by the photodetector satisfies an energy type constraint.

[0174] Example 11. The apparatus of Example 10, wherein the light source is qualified using a calibration and qualification process that includes adjusting the optical link so that the light received by the photodetector meets an energy type constraint.

[0175] Example 12. 12. The apparatus of Example 11, wherein the energy type constraint comprises a lower limit on the overlap between the quantum state of the light generated by the light source and the vacuum state.

[0176] Example 13. 13. The apparatus of any one of Examples 1 to 12, further including a sensor configured to generate a sensor signal indicative of a state of the quantum device, and wherein the control and processing system generates the certified random number based at least in part on the sensor signal.

[0177] Example 14. The apparatus of Example 13, wherein the control and processing system rejects the quantum random bit string in response to determining that the sensor signal indicates that the state of the quantum device deviates from the predefined state by a threshold amount.

[0178] Example 15. 15. The apparatus of any one of Examples 13 or 14, wherein the control and processing system generates a warning message via a user interface of the apparatus in response to determining that the sensor signal indicates that the state of the quantum device deviates from a predefined state by a threshold amount.

[0179] Example 16. 16. The apparatus of any one of Examples 13 to 15, wherein the state of the quantum device includes an environmental condition of the quantum device.

[0180] Example 17. 17. The apparatus of any one of Examples 13 to 16, wherein the state of the quantum device comprises a temperature of the quantum device.

[0181] Example 18. 18. The apparatus of any one of Examples 1 to 17, wherein the classical computing device comprises a single electronic board containing at least a field programmable gate array.

[0182] Example 19. The apparatus of any one of Examples 1 to 17, wherein the control and processing system uses a random number extractor implemented on a classical computing device to extract certified random numbers using quantum random bit strings.

[0183] Example 20. The apparatus of example 19, wherein the random number extractor is a Dodis extractor.

[0184] Example 21. 21. The apparatus of any one of examples 19 or 20, wherein the random number extractor is a seeded extractor.

[0185] Example 22. 22. The apparatus of example 21, wherein the seed random number used by the random number extractor is a cryptographic random number hard-coded into the classical computing system.

[0186] Example 23. 20. The apparatus of Example 19, wherein, during a period after generation of the certified random quantum numbers, the control and processing system operates the apparatus in a kick-off mode to generate seed random numbers used by the random number extractor.

[0187] Example 24. 24. The apparatus of example 23, wherein in a kick-off mode, the control and processing system uses the quantum device to generate two quantum random bit sequences and operates the random number extractor as a two-source random number extractor to generate a seed random number using the two quantum random bit sequences.

[0188] Example 25. 25. The apparatus of any one of Examples 1 to 24, which is a self-contained hardware unit configured to operate at substantially room temperature.

[0189] Example 26. 1. A method of generating certified random numbers based at least in part on quantum events, comprising: using a quantum device configured to generate a sequence of quantum random bits; determining an entropy level of the random bit string using a plurality of entropy proofs; generating certified random numbers using the quantum random bit string in response to determining that the entropy level of the quantum random bit string is higher than an entropy level associated with an entropy evidence from the plurality of entropy evidences.

[0190] Example 27. 27. The method of Example 26, wherein determining an entropy level of the quantum random bit string comprises testing the quantum random bit string against an entropy evidence of the plurality of entropy evidences and determining that the entropy level of the quantum random bit string is higher than an entropy level associated with the entropy evidence of the plurality of entropy evidences.

[0191] Example 28. 28. The method of any one of Examples 26 or 27, wherein the plurality of entropy evidences comprises a sorted set of entropy evidences sorted in descending order of entropy with respect to corresponding entropy levels.

[0192] Example 29. 29. The method of Example 28, wherein determining the entropy level of the quantum random bit string comprises sequentially testing the quantum random bit string against the entropy proofs of the sorted set, starting with a first entropy proof associated with the highest entropy level in the sorted set.

[0193] Example 30. 30. The method of any one of Examples 26 to 29, wherein individual entropy proofs of the plurality of entropy proofs are associated with different states of the quantum device.

[0194] Example 31. 30. The method of any one of Examples 26 to 29, wherein the quantum device comprises a photonic system including a light source configured to generate light and a photodetector configured to receive the light generated by the light source and generate a quantum event.

[0195] Example 32. 32. The method of example 31, wherein the light source includes an optical link configured such that light received by the photodetector satisfies an energy type constraint.

[0196] Example 33. The method of Example 32, wherein the light source is qualified using a calibration and qualification process that includes adjusting the optical link so that the light received by the photodetector meets an energy type constraint.

[0197] Example 34. 34. The method of any one of Examples 32 or 33, wherein the energy type constraint includes a lower limit on the overlap between the quantum state of the light generated by the light source and the vacuum state.

[0198] Example 35. 1. A method of calibrating and qualifying a light source for use in a quantum device for generating a quantum random bit sequence, the light source including a photon source and an optical link, the optical link transmitting at least a portion of the light generated by the photon source to a photodetector, the method comprising: measuring, using the photodetector, a portion of the light received by the photodetector while controlling the photon source with the first trigger signal to determine a quantum state of the portion of the light received by the photodetector with respect to an energy type constraint; adjusting the optical link to attenuate the portion of the light received by the photodetector in response to determining that the portion of the light received by the photodetector does not satisfy the energy type constraint; measuring, using the photodetector, the attenuated portion of the light received by the photodetector while controlling the photon source with the second trigger signal to determine a quantum state of the attenuated portion of the light received by the photodetector with respect to an energy type constraint; and qualifying the light source for use in the quantum device in response to determining that the portion of the light received by the light detector or the attenuated portion satisfies the energy type constraint.

[0199] Example 36. 36. The method of example 35, wherein the optical link includes an optical attenuator, and wherein adjusting the optical link includes adjusting a level of optical attenuation of the optical attenuator.

[0200] Example 37. 36. The method of any one of Examples 34 or 35, wherein the optical link includes a fiber optic waveguide, and wherein adjusting the optical link includes adjusting a level of optical attenuation in an optical connection to the fiber optic waveguide.

[0201] Example 38. 38. The method of any one of Examples 35 to 37, wherein the attenuated portion of the light received by the photodetector is attenuated by at least 10 dB relative to the light generated by the light source.

[0202] Example 39. 39. The method of any one of Examples 35 to 38, wherein the light generated by the photon source comprises at least one pulse of light.

[0203] Example 40. 40. The method of any one of Examples 35 to 39, wherein measuring the portion or attenuated portion of the light received by the photodetector includes determining an overlap between the measured quantum state of the portion or attenuated portion of the light and a vacuum state.

[0204] Example 41. 41. The method of any one of Examples 35 to 40, wherein determining that the portion of light or the attenuated portion received by the photodetector satisfies the energy-type constraint comprises determining that a determined overlap between a measured quantum state of the portion of light or the attenuated portion and a vacuum state is greater than a minimum overlap.

[0205] Example 42. 42. The method of any one of Examples 35 to 41, wherein the portion of light or the attenuated portion of light received by the photodetector comprises a plurality of light pulses.

[0206] Example 43. 43. The method of Example 42, wherein the first trigger signal and the second trigger signal include pseudorandom bit sequences, and each light pulse is associated with a bit of the pseudorandom bit sequence.

[0207] Example 44. 44. The method of Example 43, wherein the step of measuring the portion or attenuated portion of the light received by the photodetector includes determining an average probability of detecting a photon based at least in part on the corresponding pseudorandom bit sequence.

[0208] Example 45. 45. The method of any one of Examples 35 to 44, wherein the optical detector is a trusted optical detector protected from tampering by an adversary.

[0209] Example 46. 47. The method of any one of Examples 35 to 46, further comprising the steps of: decoupling the light source from the photodetector; and connecting the light source to the photodetector of the quantum device of the quantum random bit generator (QRBG).

[0210] Example 47. The method of any one of Examples 35 to 46, wherein the photodetector is mechanically, thermally, or electromagnetically, electrically, or magnetically isolated from the surrounding environment.

[0211] Example 48. 1. An apparatus for generating certified quantum random numbers in an operational mode and for generating seed random numbers in a kick-off mode, the apparatus comprising: a quantum device configured to generate quantum events; 1. A classical computing device in communication with a quantum device, comprising: using a quantum device to generate a first quantum random bit sequence and a second quantum random bit sequence; generating a seed random number using the first quantum random bit sequence and the second quantum random bit sequence; generating a third quantum random bit sequence using a quantum device; a classical computing device including a control and processing system configured to generate certified random numbers using the third quantum random bit sequence and the seed random number; 1. An apparatus comprising:

[0212] Example 49. 49. The apparatus of Example 48, wherein the control and processing system is further configured to verify the entropy levels of the first bit string and the second bit string based on the entropy evidence before generating the seed random number.

[0213] Example 50. 49. The apparatus of any one of examples 48 or 49, wherein the control and processing system selects an entropy evidence from a plurality of entropy evidences.

[0214] Example 51. 51. The apparatus of any one of Examples 48 to 50, wherein the control and processing system is further configured to reset the quantum device after generating the first sequence of quantum random bits and before generating the second sequence of random bits.

[0215] Example 52. 52. The apparatus of any one of Examples 48 to 51, wherein the control and processing system configures the random number extractor implemented in the classical computing system as a two-source extractor and provides the first quantum random bit sequence and the second quantum random bit sequence to the two-source extractor to generate the seed random number.

[0216] Example 53. 53. The apparatus of example 52, wherein after generating the seed random number, the control and processing system configures the random number extractor as a seeded extractor for generating certified random numbers.

[0217] Example 54. 54. The apparatus of any one of Examples 48 to 53, wherein the quantum device includes a light source configured to generate a photon stream and a photodetector configured to receive at least a portion of the photon stream via the optical link.

[0218] Example 55. The apparatus of example 54, wherein the light source and the optical link are configured such that the expectation values ​​of the energy observables related to the quantum states of the photon stream are bounded.

[0219] Example 56. 56. The apparatus of example 55, wherein the energy observable comprises an energy, a photon number, or an overlap with a vacuum state.

[0220] Example 57. 57. The apparatus of any one of examples 54 to 56, wherein the light source and the optical link are configured such that the overlap between the quantum state of the photon stream and the vacuum state is greater than a threshold.

[0221] Example 58. 1. A method for generating certified quantum random numbers in an operational mode and seed random numbers in a kick-off mode, the method comprising: generating a first quantum random bit sequence and a second quantum random bit sequence using a quantum device; generating a seed random number using a first quantum random bit sequence and a second quantum random bit sequence; generating a third quantum random bit sequence using a quantum device; and generating a certified random number using the third quantum random bit sequence and the seed random number.

[0222] Example 59. 59. The method of Example 58, further comprising verifying the entropy levels of the first bit string and the second bit string based on the entropy evidence before generating the seed random number.

[0223] Example 60. 60. The method of example 59, wherein verifying the entropy levels of the first bit string and the second bit string further comprises selecting an entropy evidence from a plurality of entropy evidences.

[0224] Example 61. 61. The method of any one of Examples 58 to 60, further comprising resetting the quantum device after generating the first sequence of quantum random bits and before generating the second sequence of random bits.

[0225] Example 62. 62. The method of any one of Examples 58-61, wherein the step of generating a seed random number includes configuring the random number extractor as a two-source extractor; and providing the first quantum random bit sequence and the second quantum random bit sequence to the two-source extractor to generate the seed random number.

[0226] Example 63. 63. The method of Example 62, wherein the step of generating the certified random number includes, after generating a seed random number, configuring the random number extractor as a seeded extractor, and generating the certified random number using the seeded extractor.

[0227] Example 64. 64. The method of any one of Examples 62 or 63, wherein the random number extractor comprises a Dodis extractor.

[0228] term Modifications to the embodiments of the present disclosure described above are possible without departing from the scope of the disclosure, which is defined by the appended claims. Words such as "including," "comprising," "incorporating," "consisting of," "have," and "is," used to describe and claim the present disclosure, are intended to be construed in a non-exclusive manner, i.e., allowing for the presence of items, components, or elements not expressly recited. References to the singular should also be construed to relate to the plural; for example, "at least one of" may refer to "one of" in one instance and to "a plurality of" in another instance, and "two of" and similarly "one or more" should be construed in the same manner. Numerals contained within parentheses in the appended claims are intended to aid in understanding the claims and should in no way be construed as limiting the subject matter claimed by those claims.

[0229] The phrases "in an embodiment," "according to an embodiment," and the like generally mean that the particular feature, structure, or characteristic that follows the phrase is included in at least one embodiment of the present disclosure, and may be included in more than one embodiment of the present disclosure. Importantly, such phrases do not necessarily refer to the same embodiment.

[0230] The term "computer" or "computing-based device" is used herein to refer to any device that has processing capability such that it executes instructions. Those skilled in the art will understand that such processing capability is incorporated in many different devices, and thus the terms "computer" and "computing-based device," respectively, include personal computers (PCs), servers, mobile phones (including smartphones), tablet computers, set-top boxes, media players, game consoles, personal digital assistants, wearable computers, and many other devices.

[0231] The methods described herein are, in some examples, performed by software in machine-readable form on a tangible, non-transitory storage medium, e.g., in the form of a computer program including computer program code adapted to perform one or more operations of the methods described herein when the program is run on a computer, and when the computer program may be embodied in a non-transitory computer-readable medium. The software is suitable for execution on a parallel or serial processor, such that the operations of the method may be performed in any suitable order, or simultaneously.

[0232] This recognizes that software is a valuable, separately tradable commodity. It is intended to encompass software that runs on or controls "dumb" or standard hardware to perform desired functions. It is also intended to encompass software that "describes" or defines the configuration of hardware, such as HDL (Hardware Description Language) software used to design silicon chips or configure universal programmable chips to perform desired functions.

[0233] Those skilled in the art will understand that storage devices utilized to store program instructions are optionally distributed across a network. For example, a remote computer may store an example process written as software. A local or terminal computer may access a remote computer and download some or all of the software to execute the program. Alternatively, a local computer may download software as needed, or execute some software instructions at the local terminal and some at the remote computer (or computer network). Those skilled in the art will also understand that, utilizing techniques known to those skilled in the art, all or some of the software instructions may be executed by dedicated circuitry, such as a digital signal processor (DSP), programmable logic array, or the like.

[0234] As will be apparent to those skilled in the art, all ranges or device values ​​given herein may be expanded or modified without losing the effect sought.

[0235] Although the subject matter has been described in language specific to structural features and / or method acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

[0236] It will be understood that the benefits and advantages described above may relate to one embodiment or may relate to several embodiments. Embodiments are not limited to embodiments that solve any or all of the stated problems or that have any or all of the stated benefits and advantages. No single feature or group of features is necessary or essential to every embodiment.

[0237] In particular, conditional language used herein, such as "can," "could," "might," "may," "for example," and the like, unless specifically stated otherwise or understood otherwise within the context in which it is used, is intended to generally convey that certain embodiments include certain features, elements, and / or steps, while other embodiments do not include certain features, elements, and / or steps. Thus, such conditional language is not generally intended to suggest that features, elements, and / or steps are in any way required for one or more embodiments, or that one or more embodiments necessarily include logic for determining, with or without author input or prompting, whether these features, elements, and / or steps are included in or should be performed in any particular embodiment. The terms "comprising," "including," "having," and the like are synonymous and used inclusively in an open-ended manner and do not exclude additional elements, features, actions, operations, blocks, etc. Also, the term "or" is used in its inclusive (rather than its exclusive) sense; thus, for example, when used connecting a list of elements, the term "or" means one, some, or all of the elements in the list. Furthermore, the articles "a," "an," and "the," as used in this application and the appended claims, should be construed to mean "one or more" or "at least one," unless expressly stated otherwise.

[0238] As used herein, a phrase referring to "at least one of" a list of items refers to any combination of those items, including single components. By way of example, "at least one of A, B, or C" is intended to encompass A, B, C, A and B, A and C, B and C, and A, B, and C. Conjunctive language such as "at least one of X, Y, and Z" is understood differently depending on the context, unless otherwise noted, and is used broadly to convey that an item, term, etc. may be at least one of X, Y, or Z. Thus, such conjunctive language is generally not intended to suggest that a particular embodiment requires that at least one of X, at least one of Y, and at least one of Z, respectively, be present.

[0239] The actions of the methods described herein may be performed in any suitable order, or simultaneously where appropriate. Furthermore, individual blocks may be deleted from any of the methods, combined with other blocks, or rearranged without departing from the scope of the subject matter described herein. Aspects of any of the above examples may be combined with aspects of any of the other examples described to form further examples without losing the desired effect.

[0240] It will be understood that the above description is given by way of example only, and that various modifications may be made by those skilled in the art. The above specification, examples, and data provide a complete description of the structure and use of the exemplary embodiments. Although various embodiments have been described above in some detail, or with reference to one or more specific embodiments, those skilled in the art may make numerous modifications to the disclosed embodiments without departing from the scope of the present specification. [Explanation of symbols]

[0241] 10 equipment 20 Quantum Random Number Generator 22 Optical Systems (Quantum Devices) 24 Statistical Tests 25 Light source, laser 30 extractor 40 Pseudorandom Number Generator 50 Data processor and interface, data interface and control unit 60 Control Systems, Control and Processing Systems 100 Beam Splitter 110A First optical path A 110B Second optical path B 120A First detector A 120B Second detector B 200 Solid-state vibration sensor 210 Negative Feedback Loop Amplifier 220 Actuator Mechanism 230A Piezoelectric Actuator 230B Electromagnetic Actuator 400 System 402 Quantum Devices 404 Classical Computing Devices 406 Preparation Process 407 Constrained quantum states 408 Measurement Process 409 Quantum Random Bit Sequences (QRBS) 410 Seeded Pseudo-Random Number Generator (PRNG) 411a First part of the trigger signal 411b Second part of the triggered signal 412 Evidence Verification Process 413 Verified QRBS 414 Seed Random Number 416 Seeded Randomness Extractor 418 Certified Random Numbers 500 Equipment, Process 502 Photonic Quantum Devices 504 Electronic Devices 506 Light source 507 Optical Attenuator 507a Photon Source 507b Optical Link 508 Photodetector 510 Pseudorandom Number Generator 512 Evidence Verification Circuit or Process 514 seed random number 516 Extractor circuit, randomness extraction process, extractor 518 Preparation circuit 519 Measuring Circuits, Measuring Processes 520 Control and Processing Systems, Controlled Systems 530 Certified Random Numbers 600 Optoelectronic System 602 Electronic Board 603 Optical System 604 Power supply 608 Optical Connector Assembly 610 Optical Fiber 612 Environmental Sensor 700 processes

Claims

1. 1. An apparatus for generating certified random numbers based at least in part on quantum events, comprising: a quantum device configured to generate the quantum events; a classical computing device in communication with the quantum device, the classical computing device including a control and processing system, the control and processing system communicating with the memory and executing the specific computer-executable instructions to perform at least: generating a quantum random bit string using the quantum device; determining the entropy of the quantum random bit string using a plurality of entropy evidence functions hard-coded into the classical computing device; generating the certified random number using the quantum random bit sequence in response to determining that the entropy of the quantum random bit sequence is higher than an entropy associated with an entropy evidence function of the plurality of entropy evidence functions; wherein each entropy evidence function of the plurality of entropy evidence functions is associated with a particular entropy and is configured to enable determination of a level of entropy of the quantum random bit string relative to the particular entropy value based on a statistical test; and 1. An apparatus comprising:

2. 10. The apparatus of claim 1, wherein the control and processing system uses a pseudorandom number generator implemented in the classical computing device to trigger a series of preparation steps in the quantum device and a corresponding series of measurement steps to generate the quantum random bit sequence.

3. 3. The apparatus of claim 2, wherein the control and processing system determines the entropy of the quantum random bit sequence based at least in part on a pseudorandom number generated by the pseudorandom number generator.

4. 4. The apparatus of claim 1, wherein the plurality of entropy evidence functions comprises a sorted set of entropy evidence functions sorted in descending order of entropy with respect to a corresponding entropy.

5. 5. The apparatus of claim 4, wherein the control and processing system determines the entropy of the quantum random bit string by sequentially testing the quantum random bit string against the entropy evidence functions of the sorted set, starting with a first entropy evidence function associated with the highest entropy in the sorted set.

6. The apparatus of claim 1 , wherein the plurality of entropy evidence functions comprises at least two entropy evidence functions having substantially the same entropy.

7. 2. The apparatus of claim 1, wherein the control and processing system tests the quantum random bit string against the plurality of entropy evidence functions and determines that the entropy of the quantum random bit string is higher than an entropy associated with at least one entropy evidence function of the plurality of entropy evidence functions.

8. The apparatus of claim 1 , wherein each entropy evidence function of the plurality of entropy evidence functions is associated with a different state of the quantum device.

9. 10. The apparatus of claim 1, wherein the quantum device comprises a photonic system including a light source configured to generate light and a photodetector configured to receive the light generated by the light source and generate the quantum event.

10. 10. The apparatus of claim 9, wherein the light source includes an optical link configured such that the light received by the photodetector satisfies an energy type constraint.

11. 11. The apparatus of claim 10, wherein the light source is qualified using a calibration and qualification process that includes adjusting the optical link so that the light received by the photodetector meets an energy type constraint.

12. The apparatus of claim 11 , wherein the energy type constraint comprises a lower limit of overlap between the quantum state of the light generated by the light source and a vacuum state.

13. 10. The apparatus of claim 1, further comprising a sensor configured to generate a sensor signal indicative of a state of the quantum device, wherein the control and processing system generates the certified random number based at least in part on the sensor signal.

14. 14. The apparatus of claim 13, wherein the control and processing system rejects the quantum random bit string in response to determining that the sensor signal indicates that the state of the quantum device deviates from a predefined state by a threshold amount.

15. 14. The apparatus of claim 13, wherein in response to determining that the sensor signal indicates that the state of the quantum device deviates from a predefined state by a threshold amount, the control and processing system generates a warning message via a user interface of the apparatus.

16. The apparatus of claim 13 , wherein the state of the quantum device comprises an environmental condition of the quantum device.

17. The apparatus of claim 13 , wherein the state of the quantum device comprises a temperature of the quantum device.

18. 10. The apparatus of claim 1, wherein the classical computing device comprises a single electronic board containing at least a field programmable gate array.

19. 10. The apparatus of claim 1, wherein the control and processing system uses a random number extractor implemented on the classical computing device to extract the certified random number using the quantum random bit string.

20. 20. The apparatus of claim 19, wherein the random number extractor is a Dodis extractor.

21. 20. The apparatus of claim 19, wherein the random number extractor is a seeded extractor.

22. 22. The apparatus of claim 21, wherein a seed random number used by the random number extractor is a cryptographic random number hard-coded into the classical computing device.

23. 20. The apparatus of claim 19, wherein, during a period after generation of a certified random quantum number, the control and processing system operates the apparatus in a kick-off mode to generate a seed random number used by the random number extractor.

24. 24. The apparatus of claim 23, wherein in the kick-off mode, the control and processing system uses the quantum device to generate two quantum random bit sequences and operates the random number extractor as a two-source random number extractor to generate the seed random number using the two quantum random bit sequences.

25. 10. The apparatus of claim 1, wherein the apparatus is a self-contained hardware unit configured to operate at substantially room temperature.

26. 1. A method of generating certified random numbers based at least in part on quantum events, comprising: using a quantum device configured to generate a sequence of quantum random bits; determining the entropy of the quantum random bit string using a plurality of entropy evidence functions hard-coded into a classical computing device, each entropy evidence function of the plurality of entropy evidence functions being associated with a particular entropy and configured to enable determination of the level of entropy of the quantum random bit string relative to the particular entropy value based on a statistical test; generating the certified random number using the quantum random bit sequence in response to determining that the entropy of the quantum random bit sequence is higher than an entropy associated with an entropy evidence function of the plurality of entropy evidence functions; A method comprising:

27. 27. The method of claim 26, wherein determining the entropy of the quantum random bit string comprises testing the quantum random bit string against an entropy evidence function of the plurality of entropy evidence functions and determining that the entropy of the quantum random bit string is higher than an entropy associated with any entropy evidence function of the plurality of entropy evidence functions.

28. 28. The method of claim 26 or 27, wherein the plurality of entropy evidence functions comprises a sorted set of entropy evidence functions sorted in descending order of entropy with respect to the corresponding entropy.

29. 29. The method of claim 28, wherein determining the entropy of the quantum random bit string comprises sequentially testing the quantum random bit string against the entropy evidence functions of the sorted set, starting with a first entropy evidence function associated with the highest entropy in the sorted set.

30. 27. The method of claim 26, wherein each entropy evidence function of the plurality of entropy evidence functions is associated with a different state of the quantum device.

31. 27. The method of claim 26, wherein the quantum device comprises a photonic system including a light source configured to generate light and a photodetector configured to receive the light generated by the light source and generate the quantum event.

32. 32. The method of claim 31, wherein the light source includes an optical link configured such that the light received by the photodetector satisfies an energy type constraint.

33. 33. The method of claim 32, wherein the light source is qualified using a calibration and qualification process that includes adjusting the optical link so that the light received by the photodetector meets the energy type constraint.

34. 33. The method of claim 32, wherein the energy type constraint comprises a lower limit on the overlap between the quantum state of the light generated by the light source and a vacuum state.

35. The apparatus described in claim 1, wherein the individual entropy evidence functions are generated by operating the quantum device multiple times to determine a conditional probability of obtaining a measurement in response to preparation with respect to the operating conditions of the quantum device.

36. The method described in claim 26, further comprising a step of generating evidence functions of the individual entropies by operating the quantum device multiple times to determine a conditional probability of obtaining a measurement in response to preparation with respect to the operating conditions of the quantum device.

Citation Information

Patent Citations

  • Method and device for quantum random number generation

    US20190243611A1

  • Generation of certified random numbers using an untrusted quantum computer

    WO2020226715A2