Self-testing quantum random number generation
The self-testing quantum random number generation method using a routed Bell test with selective client measurements addresses the limitations of existing DLQRNGs by reducing detector costs and complexity, ensuring randomness certification and cost savings through a server-client architecture.
Patent Information
- Application Number
- PCT/SG2025/050448
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-10
- Filing Date
- 2025-07-03
- Publication Date
- 2026-01-15
AI Technical Summary
Existing device-independent quantum random number generators (DLQRNGs) face limitations in operation speed and practicality due to the need for high-efficiency single-photon detectors, which are expensive and technologically less mature, and existing protocols for secret key distribution do not generate randomness effectively.
A method and system for self-testing quantum random number generation using a routed Bell test conducted in a round-by-round fashion, where entangled quantum states are measured locally by high-efficiency detectors at the server and selectively by less efficient detectors at the client, with entropy estimation and randomness extraction performed at the client based on measurement outcomes.
This approach reduces the cost and complexity of client devices by allowing the use of less expensive, technologically mature detectors, while ensuring randomness certification through device-independent protocols, offering cost savings and flexibility in operation modes.
Smart Images

Figure SG2025050448_15012026_PF_FP_ABST
Abstract
Description
[0001] SELF-TESTING QUANTUM RANDOM NUMBER GENERATION
[0002] FIELD OF INVENTION
[0003] The present invention relates broadly to a method of self-testing quantum random number generation, a system for self-testing quantum random number generation, a client for a system for self-testing quantum random number generation, and a server for a system for self-testing quantum random number generation.
[0004] BACKGROUND
[0005] Any mention and / or discussion of prior art throughout the specification should not be considered, in any way, as an admission that this prior art is well known or forms part of common general knowledge in the field.
[0006] Presently, several device-independent quantum random number generators (DLQRNGs) have been described.
[0007] The work in [1] is the pioneering work on DLQRNG and explains the principle of deviceindependence. The proposed DLQRNG protocol is based on the Clauser-Horne-Shimony-Holt (CHSH) Bell test between two parties (which may be referred to as the client and the server in an application scenario). The protocol is then implemented by measuring entangled atoms, which limits the operation speed and practicality of the method. Furthermore, the entire system will be bulky when implemented.
[0008] The works in [2] -[5] are quite similar. These works implement the protocol proposed in the work in [1] using fully photonic systems. This improves the operation speed; however, it is more challenging to build high efficiency detectors for photonic systems (e.g., superconducting single-photon detectors). As the works in [2] to [5] require all the devices to have high efficiency single-photon detectors, which are more expensive and technologically less mature, the practicality of these works is severely limited.
[0009] On the other hand, the works in [6]-[8] are based on routed Bell test (also known as local Bell test) for distribution of secret keys, as opposed to DLQRNG as in works
[0001] -[5J. Hence, the goals in works [6]-[8] are not to generate randomness, but to distribute secret keys.
[0010] Embodiments of the present invention seek to address at least one of the above problems.
[0011] SUMMARY
[0012] In accordance with a first aspect of the present invention, there is provided a method of selftesting quantum random number generation, comprising: conducting a routed Bell test in a round-by-round fashion, wherein each round comprises: generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at a client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes by the server to the client; performing entropy estimation at the client based on the input-output data, the third measurement settings and the third measurement outputs; and performing, at the client, randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
[0013] In accordance with a second aspect of the present invention, there is provided a system for selftesting quantum random number generation, comprising: a server comprising a source, a first detector coupled to the source, a second detector coupled to the source via a switch, and a first processor; and at least one client comprising a third detector and a second processor; wherein the system is configured for conducting a routed Bell test in a round-by-round fashion, wherein each round comprises: the source generating a signal representing a pair of entangled quantum states; the first detector performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either by the second detector based on associated second measurement settings and recording a second measurement outcome or by the third detector based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the switch is configured for selectively directing the second signal representing the second part of the pair of entangled quantum states to the second detector or to the third detector at the client based on the random selection input; wherein the first processor is configured for announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes to the client; and wherein the second processor is configured for performing entropy estimation based on the input-output data, the third measurement settings and the third measurement outputs, and for performing randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
[0014] In accordance with a third aspect of the present invention, there is provided a client for a system for self-testing quantum random number generation configured for conducting a routed Bell test in a round- by-round fashion, wherein each round comprises: generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at the client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the client comprises: the third detector; and a processor configured for receiving input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes announced by the server to the client; wherein the processor is configured for performing entropy estimation based on the inputoutput data, the third measurement settings and the third measurement outputs; and for performing randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
[0015] Tn accordance with a fourth aspect of the present invention, there is provided a server for a system for self-testing quantum random number generation configured for conducting a routed Bell test in a round-by-round fashion, wherein each round comprises: generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at the client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the server comprises: source for generating the signal representing a pair of entangled quantum states; the first detector coupled to the source; the second detector coupled to the source via a switch configured for selectively directing the second signal representing the second part of the pair of entangled quantum states to the second detector or to the third detector at the client based on the random selection input; and a processor configured for announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes to the client for performing entropy estimation and randomness extraction at the client.
[0016] BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Embodiments of the invention will be better understood and readily apparent to one of ordinary skill in the art from the following written description, by way of example only, and in conjunction with the drawings, in which:
[0018] Fig. 1 shows a schematic drawing illustrating a Network of clients and server, according to an example embodiment.
[0019] Fig. 2 shows a schematic drawing illustrating a routed Bell test set-up, according to an example embodiment.
[0020] Fig. 3 shows a schematic drawing illustrating a source of entangled quantum states for CHSH Bell test, according to an example embodiment.
[0021] Fig. 4 shows a schematic drawing illustrating a measurement device, according to an example embodiment. Fig. 5 shows a graph illustrating randomness generation rate vs the client’s detection efficiency, according to an example embodiment.
[0022] Fig. 6 shows a flowchart illustrating a method of self-testing quantum random number generation, according to an example embodiment.
[0023] Fig. 7 shows a schematic drawing illustrating a system for self-testing quantum random number generation, according to an example embodiment, a server according to an example embodiment, and a client according to an example embodiment.
[0024] DETAILED DESCRIPTION
[0025] Embodiments of the present invention provide a method and architecture for randomness generation based on quantum theory. The architecture according to an example embodiment comprises of a network of clients and a server. Notably, neither the clients’ nor the server’s devices are required to be characterized according to an example embodiment. Furthermore, to implement the method according to an example embodiment, the clients only require devices that are technologically mature. A sizeable portion of the cost is borne by the server, which can serve many clients. As such, the implementation of the invention according to example embodiments advantageously enjoys significant economies-of-scale.
[0026] Unlike the works in [l]-[5], embodiments of the present invention advantageously do not require the client(s) to perform any Bell test. Instead, the routed Bell test setup is used in an example embodiment, where the only Bell test in the protocol is performed locally by the server. As performing a Bell test imposes a very stringent requirement on the devices that perform the Bell test, embodiments of the present invention can significantly relax the requirement on the client’s device. Ultimately, this will significantly lower the cost of the client’s module. Furthermore, as a single server can serve multiple clients according to an example embodiment, the cost of the server is shared among all the clients. Therefore, embodiments of the present invention provide significant cost savings to the end-users, as compared to existing proposals.
[0027] On the other hand, the works in [6] -[8] are based on routed Bell test for distribution of secret keys, as opposed to DLQRNG. The present inventors have recognized that applying the routed Bell test as proposed in [6]-[8] for randomness generation will not work, as the server will be able to guess the client’s random string since these protocols produce correlated random strings. Instead, in accordance with an aspect of the present invention, a method of self-testing quantum random number generation as defined in claim 1 is provided.
[0028] According to an example embodiment described herein, a method and network architecture for device-independent quantum random number generation is provided. Device-independent quantum random number generation is a protocol to generate random numbers from quantum devices that are uncharacterized - the randomness of the output can be certified even when one treats the devices as black boxes. That is, the randomness can be certified by only looking at the input-output statistics that arc obtained in the protocol execution.
[0029] With reference to Fig. 1, in an example embodiment a network 100 of clients e.g. 102 and a server 104 is considered. As an illustration and as shown in Fig. 1, a star network topology is considered, where the server is in the central node, and it is connected to each client #1 to #5 in the network 100. In this embodiment, it is easy to onboard a new client into the network 100 as the new client simply needs to establish a single connection to the server 104. However, it is noted that the present invention can also be applied to other network topologies.
[0030] More specifically, if the goal is to minimize the number of linkages, then the star network according to the example embodiment shown in Fig, 1, where the server 104 occupies the central node and is connected to each client e.g. 102, is optimal. However, this may not be the most robust architecture. For example, having the clients to be connected to each other can improve the robustness of the network in another embodiment. In case the linkage between the server and one client #1 is broken, if the client #1 is connected to client #2, client #2 can help to connect client #1 to the server using entanglement-swapping
[0012] , and hence improve robustness.
[0031] With reference to Fig. 2, to generate the random numbers, a three-device setup is considered, where two of the devices 200, 202 are inside the server 104 while the third device 204 is with the client e.g. 102. It is noted that other numbers of devices can be used in different embodiments. For example, one can also consider the case where the clients also perform a local Bell test, as an additional, optional feature. In this case, there will be four devices. Another example is one where the server performs a multi -partite Bell test. Such embodiments will be more costly to implement. The three-device case is considered a preferred example embodiment.
[0032] Additionally, the server 104 also contains a source 206 of quantum states and an optical switch 208. Herein, the first device 200 is referred to as Alice, the second device 202 is referred to as Bob, and the third device 204 is referred to as Charlie. Both Alice and Bob contain high- efficiency single-photon detectors 210, 212, respectively. On the other hand, Charlie contains another detector 214 (which may have lower specifications, e.g., a less efficient single-photon detector or a homodyne detector). The three devices 200, 202, 204 arc performing the so-called routed Bell test, as will be described below in more detail.
[0033] In an example embodiment, the routed Bell test is conducted in a round- by-round fashion for many rounds. In each round, the source 206 of quantum states will emit a pair of entangled states. One part of the entangled state is then sent to Alice. Meanwhile, the optical switch 208 will receive a random input s G {0,1}. When s — 0, the optical switch will route the other part of the entangled state to Bob. Alice and Bob will then perform a Bell test locally inside the server 104. On the other hand, when s = 1, the other part of the entangled state is sent to Charlie. In this case, Charlie, e.g. the client e.g. 102, will either perform a test round (to estimate the amount of information being leaked to the environment) or a generation round (to generate the raw random outputs). In each round, Alice, Bob, and Charlie each receive the inputs x, y and z respectively. They will then measure their respective part of the entangled state. Then, they record the outputs a, b and c, respectively. Throughout the entire protocol, it is assumed that each device’s input (including the optical switch’s input) is not communicated to anyone else. In practice, this assumption can be enforced by either isolating the devices or by timing the input and output of each device such that they are spacelike separated.
[0034] It is noted that the method according to an example embodiment uses some random inputs for each round. These random inputs can be supplied using either a trusted public source of randomness or using a pre-installed random seed in each device. For each round, the inputs correspond to the measurement settings of each device and the outputs correspond to the measurement outcomes of each device. At the end of the final round, the server 104 announces the inputs to the optical switch and to Alice and Bob. The server 104 also announces the outputs of Alice and Bob. From the server’s 104 announcement, the client e.g. 102 will be able to estimate the joint conditional probability distribution between Alice and Bob (for s = 0) and between Alice and Charlie (for s = 1).
[0035] From the joint input-output data, Charlie can estimate the entropy of his outputs conditioned on all the inputs (s, x, y, z), the server’s outputs (a, b), and any potential side-information E that can be possessed by an external party. From there, Charlie can apply an appropriate randomness extraction procedure (e.g., Tocplitz extractor [9] or Trcvisan extractor
[0011] ) to obtain a bit-string that is private and uniform. In the case where the client e.g. 102 uses preinstalled random seed to choose Charlie’s inputs, the randomness extraction can be applied jointly on the raw string and the input seed. This will allow the client to recycle the random seed, which improves the efficiency of the protocol.
[0036] The reason why randomness can be certified from black-box devices by simply looking at the statistics according to an example embodiment is as follows. When Alice and Bob share a so- called non-local correlation when s = 0, there are some constraints on the measurement that Alice can make as well as the state that she can share with Bob. “Non-local correlation” refers to correlations that cannot be explained by mixing local deterministic strategies using preshared random numbers, as will be appreciated by a person skilled in the art. As non-local correlations cannot be explained using a mixture of deterministic processes, one can conclude that the outputs have to be random. In the extreme case (when the correlation is extremal, i.e., when it cannot be constructed from a mixture of other correlations, whether local or non-local, one can 'uniquely’ identify Alice’s measurements (more precisely, up to a local isometry, in other words, reversible local operations that arc allowed by quantum theory, as will be appreciated by a person skilled in the art). Due to the assumption that the devices 200, 202, 204, and 208 are not communicating their inputs to other parties, Alice’s device must behave in the same way as when the switch 208 receives s = 1. In this case, if Alice and Charlie share a long range quantum correlation (as defined in Ref.
[0010] ) when s = 1, Charlie’s measurement outcomes must be random. Significantly, in an example embodiment, the Alice-Charlie correlation does not have to be non-local (unlike typical device-independent QRNGs). This significantly lowers the requirements on Charlie’s measurement device, therefore reducing the cost of the client’s c.g. 102 module.
[0037] Due to the server-client architecture according to an example embodiment, the Bell test is performed completely inside the server 104, which can be assumed as a secure location. Therefore, one can reasonably assume that there is no external agent that is actively tampering with the server’s 104 devices c.g. 200, 202 during the protocol execution. This offers flexibility in the operation of example embodiment: the users can decide whether they require full deviceindependence (in which case, the server’s 104 devices can be completely untrusted). The fully dcvicc-indcpcndcnt mode of operation offers the highest level of security, at the cost of a lower randomness generation rate. On the other hand, if the users prioritize the randomness generation rate over security, the users can choose the semi-device-independent mode of operation, using the fair sampling assumption. The fair sampling assumption means that whenever the server’s 104 devices 200, 202 do not produce any output, the data for that round can be safely discarded. This is in contrast to the fully dcvicc-indcpcndcnt mode of operation, where the users arc required to assign an output (cither deterministically or randomly) to the rounds in which the devices fail to produce an output. The mode of operation with the fair sampling assumption has higher randomness generation rate at the cost of introducing an assumption on the server’s 104 devices 200, 202. In practice, this docs not significantly reduce the security of the protocol as practical measurement devices obey the fair sampling property, except when an external agent is tampering with them actively.
[0038] Protocol according to an example embodiment
[0039] Next, a detailed protocol description for the random number generation according to an example embodiment is provided. Let N be the total number of rounds. For each round i £ {1, 2, N] repeat Step 1 to 4.
[0040] 1 . Entanglement distribution'. The source 206 of quantum states emits a pair of entangled quantum states. One part of the entangled quantum states is sent to Alice, while the other is sent to the optical switch 208.
[0041] 2. Routing'. The switch 208 receives input s, E {0, 1}. It s, = 0, the switch 208 directs the quantum state to Bob. If Sj = 1, the switch directs the quantum state to Charlie.
[0042] 3. Measurement'. Alice receives input x(. Bob receives input yt, and Charlie receives input Zj. If Zj = 0, the round is assigned to test round, which is used by Charlie to estimate the amount of information E being leaked to the environment. If z(- = 1, the round is assigned to generation round, which is used by Charlie to generate the raw random outputs Cj. In both test and generation rounds, they set their measurement settings according to the respective inputs and then perform the quantum measurement. Alice records her measurement outcome <2;, Bob records his measurement outcome and Chailie records his measurement outcome Q. 4. Announcement: Using an authenticated classical channel, the server announces his data (s;, xityu- aL, bt~) to the client e.g. 102.
[0043] 5. Entropy estimation: Based on the input-output data accumulated over all the rounds, the client e.g. 102 decides whether the conditional smooth min-entropy above a certain threshold h. If yes, then the client e.g. 102 proceeds to the next step. Otherwise, the client e.g. 102 aborts the protocol. Here, E denotes the quantum side-information that any external party may have about the client’s e.g. 102 random string, C. The capital letters denote the string of the corresponding small-capped random variables.
[0044] 6. Randomness extraction: The client applies an appropriate randomness extraction protocol on the random string, C.
[0045] In relation to step 5, in practice, the entropy estimation is typically done by checking if the observed input-output frequency distribution q is within some accepted range. The range of accepted distributions may be denoted as Sn. By way of example, not limitation, it is shown below that if the observed input-output frequency distribution q is within the accepted range, i.e., q E Sn. then the conditional smooth min-entropy is higher than some threshold, except with a small probability.
[0046] In this example, once the accepted distributions are fixed, the smooth min-entropy can be lower bounded using the generalized entropy accumulation theorem (GEAT) which gives a certified lower bound on the conditional smooth min-entropy for the entire protocol according to an example embodiment in terms of a single round lower bound on the conditional von Neumann entropy (reference is made, e.g., to Corrolary 4.6 of
[0015] ). Then, the single round conditional von Neumann entropy can be bound using the Navascues-Pironio-Acin (NPA) hierarchy of semidefinite programming.
[0047] The GEAT essentially reduces the analysis of the conditional smooth min-entropy for n rounds of the protocol to the construction of a min-tradeoff function, which is related to the singleround conditional von Neumann entropy. To obtain the lower bound on the single -round conditional von Neumann entropy, we lower bound it using the conditional min-entropy, which is related to the guessing probability
[0048] The first inequality (1) is due to us discarding the non-negative terms corresponding to = 0 or Zj = X;. For .S'(- — 1 terms, the conditioning on Hi is trivial since Bt— 0. Similarly, the conditioning on Yj_ can be removed due to the non- signaling condition. The second inequality (2) is due to the conditional min-entropy being a lower bound on the conditional von Neumann entropy and the last equality (3) is due to the definition of the conditional min-entropy with Pgdenoting the guessing probability.
[0049] The guessing probability can then be bounded using the Navascucs-Pironio-Acm (NPA) hierarchy
[0019] . Specifically, one shall solve the following optimisation problem
[0050] Here, and { / :'e|axz}e Q Y 7corresponds to the projectors for Alice,
[0051] Bob, Charlie, and the adversary, respectively. It is noted that Bob’s projectors may not commute with those of Charlie and the adversary since the behavior of the switch is not trusted.
[0052] The method according to an example embodiment can be applied to any Bell test scenario, not only those with two-inputs and two-outputs. This is why the possible inputs and the possible outputs for each device 200, 202, 204 are not specified in the above example protocol. Moreover, the protocol according to an example embodiment can be implemented with any entangled quantum state and quantum measurements, as long as they produce non-local correlations between Alice and Bob as well as give long range quantum correlation between Alice and Charlie., i.e. the threshold h > 0 can be set in the protocol parameter such that in the entropy estimation step of the protocol according to an example embodiment, the protocol will be accepted (i.e., not aborted) with high probability.
[0053] In the above protocol according to an example embodiment, the client includes both the measurement results from the test rounds and the generation rounds into the raw input of the randomness extraction, i.e. random string, C. It is also possible to consider the case where the client excludes the data from the test rounds, thus only using the measurement results from the generation round as the raw input to the randomness extraction. In such an embodiment, the estimated entropy (compare entropy estimation step above) will be conditional on the event that only the measurement results from the generation rounds arc used as the raw input of the randomness extraction.
[0054] When both the locality and the detection loopholes are closed, the above protocol according to an example embodiment will be fully device-independent. In such an example embodiment, the server’s detectors need to have very high efficiencies and the source must be close to ideal. However, one can adopt a scmi-dcvicc-indcpcndcnt (scmi-DI) approach according to another example embodiment, with some reasonable assumptions to reduce the requirements on the server’s devices.
[0055] For example, it is noted that the source 206, the optical switch 208, Alice 200, and Bob 202 are all located inside the server 104. One can reasonably assume that the server 104 is a secure location which makes it difficult for a potential adversary to physically access. Moreover, the server 104 docs not expect to receive any quantum signals from the client 102. Therefore, one can also use an optical power limiter L 13 J and an optical isolator to prevent attacks such as the detector blinding attack
[0014] from being launched via the quantum channel. One can then justifiably assume fair sampling, which means that one can safely discard the rounds where Alice 200 or Bob 202 do not produce a conclusive outcome.
[0056] Therefore, advantageously the same set of devices (compare Fig. 2) can perform both the fully device-independent QRNG protocol or the semi-Dl protocol. This grants users the flexibility to operate the devices depending on their security needs. When the user is skeptical about the servers’ devices, the fully device-independent mode according to an example embodiment of operation offers the highest level of security as all the devices can be fully untrusted - as long as the server operates them honestly (c.g., it announces its inputs and outputs honestly during the protocol). This gold standard of security comes at the cost of lower randomness generation rate. On the other hand, if the user sufficiently trusts the server’s devices, applying the fair sampling assumption on the server’s measurement devices allows for higher randomness generation rate, according to another example embodiment.
[0057] Implementation according to an example embodiment
[0058] The configuration of the example implementation according to an example embodiment is the same as shown in Fig. 2. For the following example, the case where Alice and Bob perform the CHSH Bell test is considered.
[0059] In the CHSH Bell test, Alice and Bob estimate the so-called winning probability m, defined as
[0060] <n = Pr[Aj©Bj = X[ • Y} |Sj = 0, A[ ¥= 0, B, T50] where © denotes addition modulo 2. On the other hand, to test for long-range quantum correlations, Alice and Charlie will monitor the error rate Qo between Alice’s and Charlie’s first measurement setting as well as the error rate Qi between Alice’s and Charlie’s second measurement setting. The error rates are defined as
[0061] The client also monitors the transmittivity TZ— Pr[C;01^ = 1,Z;= z]for all z.The case where the source 206 emits quantum states that are entangled in polarization is considered. For example, such a source 206 can be realized using spontaneous parametric down-conversion (SPDC) process where a bright laser beam (called pump laser) impinges on a non-linear crystal (e.g., BBO). In this case, an entangled photon pair is generated by using a pair of two-mode squeezed vacuum states (TMSV) as shown in Fig. 3. The output entangled state can be tuned by tuning the intensity of each TMSV state. As a concrete example, the setting of the SPDC source can be tuned such that the intensities of the two TMSV states are equal. The singlephoton pair component of the state corresponds to the maximally entangled polarization qubits.
[0062] Here, the state \H) denotes the horizontally polarized qubit, and the state |F) denotes the vertically polarized qubit.
[0063] It is noted that the SPDC source also has some vacuum and multi-photon components. For simplicity, in this example embodiment it is assumed that the intensity of the source is set to be low enough that one can neglect the multiphoton components.
[0064] The measurement devices 200, 202, 204 can be realized using polarization modulators 400, a polarizing beam-splitter 402 and two threshold single-photon detectors 404, 406, as shown in Fig. 4. The incoming quantum signal 408 is first directed to the polarization modulator 400. The polarization modulator 400 takes the respective device’ s (i.e. 200, 202, or 204) setting and rotates the polarization of the incoming quantum signal 408 according to the setting. After that, the modulated signal 410 impinges the polarization beam-splitter (PBS) 402 which splits the modulated signal 410 depending on its polarization. If the modulated signal is horizontally polarized, it will be transmitted by the PBS 402 towards the detector Do404. If the modulated signal 410 is vertically polarized, it will be reflected towards the detector Dr406. In a semi-DI example embodiment, the respective device (i.e. 200, 202, or 204) then outputs the bit “0” when the detector Do404 clicks or when both detectors 404, 406 click. The respective device (i.e. 200, 202, or 204) outputs the bit “1” when the detector Dt406 clicks. The respective device (i.e. 200, 202, or 204) outputs “no detection” when neither detector 404, 406 clicks. The fair sampling assumption imposes that in any given round, the probability of Alice (or Bob) obtaining the output "no detection" is independent of their inputs. It is further supposed that the client only generates random numbers in rounds where Alice produces a conclusive outcome (i.e., Alice does not produce the outcome "no detection”).
[0065] It is noted that one can readily construct a fully device-independent example embodiment of the protocol by mapping the inconclusive outcome "no detection” deterministically to the bit value ‘O’. Thus, in a fully device-independent example embodiment of the protocol, each party’s output will also be binary, i.e.,c / Z = B = C = {0,1}, where <A, B, C are the output alphabet of Alice, Bob, and Charlie, respectively. As the semi-DI example embodiment of the protocol offers a higher randomness generation rate without significantly reducing the level of security since the servers’ devices are inside a secure location, the scmi-DI example embodiment will be focused on below.
[0066] For one semi-DI example embodiment, when Alice chooses x = 0, Alice will set the polarization angle to be at 0°. In this example embodiment, Alice projects her quantum state to the {| / / ), |V)} basis. Meanwhile, when Alice chooses x = 1, Alice will set the polarization angle to be at 45°. In this case, Alice projects her quantum state to the {|+45°), |— 45°)} basis. In this example embodiment, when Bob chooses the setting y = 0, Bob will set the polarization angle to be at 22.5°. Thus, Bob effectively projects his quantum state to the {|+22.5°), |— 67.5°)} basis. Lastly, when Bob chooses the setting y = 1, Bob effectively projects his quantum state to the {| — 22.5°), |+67.5°)}. Throughout, the following notation has been used:
[0067] On the client’s e.g. 102 side, in this example embodiment, when Charlie chooses the setting z = 0, Charlie’s polarization angle is set at 0°. When z = 1, Charlie’s polarization angle is set at 45°. Therefore, Charlie’s device 204 in this example embodiment is identical to Alice’s device 200, except that the single-photon detectors used by Charlie can be significantly less efficient, as will be described with reference to Fig. 5 below.
[0068] In this non limiting example embodiment, the choice of polarization angle settings for Alice and Bob is chosen such that it maximizes the winning probability, a), of the CHSH Bell test when the detectors are perfect. Furthermore, the choice of polarization angle settings for Charlie is chosen such that (1) there are zero errors when Alice and Charlie choose the same settings (i.e., Qoand are both zero), and (2) the measurement outcomes of Alice and Charlie in the generation rounds will be uncorrelated. The choice of having two measurement settings for each party also gives the minimal number of settings.
[0069] However, it is noted that it is possible to modify the protocol in different example embodiments. For example, for the local Bell tests (i.e., for Alice's and Bob's polarization angles), we can use the optimal settings studied in
[0017] . Correspondingly, Charlie's polarization angles will be set to be the same as Alice's polarization angles. Again, this will ensure that Qoand QLare zero. This choice has the advantage of enabling the fully device-independent version of the protocol using imperfect detectors, but at the cost of lower entropy since Charlie's measurement outcomes will be weakly correlated to Alice's measurement outcomes.
[0070] Additionally, in different example embodiments it is also possible to increase the number of measurement settings for Charlie. As shown in
[0018] , one can use the same settings for Alice and Bob for the local Bell test and N measurement settings for Chailie, corresponding to N polarization angles which are distributed uniformly between (0 to 90 degrees). For this choice, to monitor the long-range quantum correlation, it is possible to consider the quantity = t,S = 1) where t denotes Charlie's polarization angle. This choice enables the protocol to be performed over longer distances (or with lower detection efficiency on the client's side).
[0071] Returning to the semi-DI example embodiment described above, to simplify further, in this example embodiment the asymptotic case is considered, where the number of rounds are large, i.e., n -> oo. In this case, one can take the limit s 0. The randomness generation rate can be approximated by the single-round conditional von Neumann entropy where
[0072] Pt = (Si,Xi, Yi,Ai,Bi)' .
[0073] It is noted that in the practical case with finite number of rounds according to different example embodiments, there will be a correction term that scales with O(l / Vn)
[0015] . This correction term vanishes in the asymptotic limit according to this example embodiment.
[0074] In this example embodiment, the threshold h can for example be calculated using the computational technique introduced in [7] and [8]. For this semi-DI example embodiment with the fair-sampling assumption for the local Bell test at the server 104, the resulting randomness generation rate for each client’s e.g. 102 detection efficiency is shown in Fig. 5. Specifically, the randomness generation rate per heralded event (i.e., the events in which Alice does not produce the “no detection” outcome) is shown in Fig. 5. It can be seen that the randomness generation rate is positive as long as the detection efficiency of the client’ s device is larger than 50%. This is significantly lower than the detection efficiency required to perform the usual DIQRNG which is based solely on the CHSH game. For example, the minimum detection efficiency required is around 70% in [1] to [5].
[0075] It is noted that the number of measurement bases on the client’s side can be increased to improve the loss tolerance of the protocol in other example embodiments
[0016] . Advantageously, increasing the number of measurement bases of the client is relatively easy and the cost is relatively low, making such embodiments of the present invention still cost- effective. In particular, this means that self-testing quantum random number generation with more measurement bases for the clients can be implemented with single-photon detectors based on avalanche photodiodes according to example embodiments, instead of superconducting nanow'ire single -photon detectors that are significantly more expensive and need to operate at cryogenic temperatures.
[0076] Fig. 6 shows a flowchart 600 illustrating a method of self-testing quantum random number generation, according to an example embodiment. At step 602, a routed Bell test is conducted in a round-by-round fashion, wherein each round comprises generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at a client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input. At step 604, input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes is announced by the server to the client. At step 606, entropy estimation is performed at the client based on the input-output data, the third measurement settings and the third measurement outputs. At step 608, randomness extraction is performed, at the client, on the third measurement outputs if the estimated entropy is above a threshold.
[0077] In each round in which the second signal representing the second part of the pair of entangled quantum states is sent to the third detector at the client, the client may cither performs a test round for estimating an amount of information leaked to an external party or a generation round for randomness generation. The entropy estimation at the client may be further based on the estimated amount of information leaked to the external party. The third measurement results from the test rounds may also be used for the randomness generation.
[0078] The randomness extraction may be jointly applied to the third measurement outcomes and a pre-installed random seed at the client used to determine the measurement settings.
[0079] The threshold may be greater than zero.
[0080] Fig. 7 shows a schematic drawing illustrating a system 700 for self-testing quantum random number generation, according to an example embodiment, a server 702 according to an example embodiment, and a client 712 according to an example embodiment. The system 700 comprises the server 702 according to an example embodiment, which comprises a source 704, a first detector 706 coupled to the source 704, a second detector 708 coupled to the source 704 via a switch 718, and a first processor 710; and at least one client 712 according to an example embodiment, which comprises a third detector 714 and a second processor 716. The system 700 according to an example embodiment is configured for conducting a routed Bell test in a round- by-round fashion, wherein each round comprises the source generating a signal representing a pair of entangled quantum states; the first detector performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states cither by the second detector based on associated second measurement settings and recording a second measurement outcome or by the third detector based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input. The switch 718 is configured for selectively directing the second signal representing the second part of the pair of entangled quantum states to the second detector 708 or to the third detector 714 at the client based on the random selection input. The first processor 710 is configured for announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes to the client 712. The second processor 716 is configured for performing entropy estimation based on the input-output data, the third measurement settings and the third measurement outputs, and for performing randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
[0081] The second processor 716 may be configured for performing, in each round, either a test round for estimating an amount of information leaked to an external party or a generation round for recording the third measurement result. The second processor 716 may be configured for further basing the entropy estimation on the estimated amount of information leaked to the external party. The second processor 716 may be configured for also using third measurement results from the test rounds for the randomness generation. The second processor 716 may be configured to apply the randomness extraction jointly applied to the third measurement outcomes and a pre-installed random seed of the client used to determine the measurement settings.
[0082] The threshold may be greater than zero.
[0083] In an example embodiment, the announcement by the server 702 to the client 712 is performed using an authenticated classical channel 720.
[0084] In an example embodiment, the second part of the pair of entangled quantum states is transmitted to the third detector 714 using an untrusted quantum channel 722.
[0085] Embodiments of the present invention can have one or more of the following characteristics and associated benefits / advantages:
[0086] Commercial Applications
[0087] Embodiments of the present invention can be used to generate random numbers securely using uncharacterized devices. This is especially suitable for cryptographic applications, secure password generator, etc. The random number generator according to an example embodiment can also be used in other applications such as competitive gaming, gambling, lotteries, and other applications where it is important to certify that the output randomness is fair.
[0088] Aspects of the systems and methods described herein, such as the control and operation of the devices 200, 202, 204, may be implemented on computing device(s), including cloud-based computing device(s) and / or Intemet-of-Things computing device(s), for example as functionality programmed into any of a variety of circuitry, including programmable logic devices (PLDs), such as field programmable gate arrays (FPGAs), programmable array logic (PAL) devices, electrically programmable logic and memory devices and standard cell-based devices, as well as application specific integrated circuits (ASICs). Some other possibilities for implementing aspects of the system include: microcontrollers with memory (such as electronically erasable programmable read only memory (EEPROM)), embedded microprocessors, firmware, software, etc. Furthermore, aspects of the system may be embodied in microprocessors having software-based circuit emulation, discrete logic (sequential and combinatorial), custom devices, fuzzy (neural) logic, quantum devices, and hybrids of any of the above device types. Of course the underlying device technologies may be provided in a variety of component types, e.g., metal-oxide semiconductor field-effect transistor (MOSFET) technologies like complementary metal-oxide semiconductor (CMOS), bipolar technologies like emitter-coupled logic (ECL), polymer technologies (e.g., Silicon-conjugated polymer and metal-conjugated polymcr-mctal structures), mixed analog and digital, etc.
[0089] The various functions or processes disclosed herein may be described as data and / or instructions embodied in various computer-readable media, in terms of their behavioral, register transfer, logic component, transistor, layout geometries, and / or other characteristics. Computer-readable media in which such formatted data and / or instructions may be embodied include, but arc not limited to, non-volatile storage media in various forms (e.g., optical, magnetic or semiconductor storage media) and carrier waves that may be used to transfer such formatted data and / or instructions through wireless, optical, or wired signaling media or any combination thereof. When received into any of a variety of circuitry (e.g. a computer), such data and / or instruction may be processed by a processing entity (e.g., one or more processors).
[0090] It will be appreciated by a person skilled in the art that numerous variations and / or modifications may be made to the present invention as shown in the specific embodiments without departing from the spirit or scope of the invention as broadly described. The present embodiments are, therefore, to be considered in all respects to be illustrative and not restrictive. Also, the invention includes any combination of features described for different embodiments, including in the summary section, even if the feature or combination of features is not explicitly specified in the claims or the detailed description of the present embodiments.
[0091] In general, in the following claims, the terms used should not be construed to limit the systems and methods to the specific embodiments disclosed in the specification and the claims, but should be construed to include all processing systems that operate under the claims. Accordingly, the systems and methods arc not limited by the disclosure, but instead the scope of the systems and methods is to be determined entirely by the claims.
[0092] Unless the context clearly requires otherwise, throughout the description and the claims, the words "comprise," "comprising," and the like are to be construed in an inclusive sense as opposed to an exclusive or exhaustive sense; that is to say, in a sense of "including, but not limited to." Words using the singular or plural number also include the plural or singular number respectively. Additionally, the words "herein," "hereunder," "above," "below," and words of similar import refer to this application as a whole and not to any particular portions of this application. When the word "or" is used in reference to a list of two or more items, that word covers all of the following interpretations of the word: any of the items in the list, all of the items in the list and any combination of the items in the list.
[0093] References
[0094] L 1 J Random numbers certified by Bell’s theorem [Nature 464, 1021 (2010)]
[0095] [2] Randomness extraction from Bell violation with continuous spontaneous parametric down-conversion [Phys. Rev. Lett. 121, 150402 (2018)] [3] High-speed device-independent quantum random number generation without a detection ioophoic [Phys. Rev. Lett. 120, 010503 (2018)]
[0096] [4] Device-independent randomness expansion with entangled photons [Nature Physics 17, 452 (2021)]
[0097] [5] Device-independent randomness expansion against quantum side information [Nature Physics 17, 448 (2021)]
[0098] [6] Device-independent quantum key distribution with local Bell test [Phys. Rev. X 3, 031006 (2013)]
[0099] [7] Entropy bounds for device-independent quantum key distribution with local Bell test [arXiv: 2404.00792 (2024)]
[0100] [8] Device-independent quantum key distribution based on routed Bell test [arXiv: 2404.01202 (2024)]
[0101] [9] H. Krawczyk, LSFR-based hashing and authentication, Advances in Cryptology - CRYPTO’94 839, 129 (1994)
[0102]
[0010] E.P. Lobo, .1. Pauwels, S. Pironio, Certifying long-range quantum correlations through routed Bell tests, Quantum 8, 1332 (2024)
[0103]
[0011] W. Mauerer, C. Portmann, V.B. Scholz, A modular framework for randomness extraction based on Trevisan’s construction, arXiv: 1212.0520 (2012)
[0104]
[0012] J.-W. Pan, D. Bouwmeester, H. Weinfurter, A. Zeilinger, Experimental Entanglement Swapping: Entangling Photons That Never Interacted, Phys. Rev. Lett. 80, 3891 (1998)
[0105]
[0013] G. Zhang, T. W. Primaatmaja, J. Y. Haw, X. Gong, C. Wang, and C. C. W. Lim, Securing practical quantum communication systems with optical power limiters, PRX Quantum 2, 030304 (2021 ).
[0106]
[0014] L. Lydersen, C. Wiechers, C. Wittmann, D. Elser, J. Skaar, and V. Makarov, Hacking commercial quantum cryptography systems by tailored bright illumination, Nature photonics 4, 686 (2010).
[0107]
[0015] T. Metger, O. Faw / i, D. Sutter, and R. Renner, Generalised entropy accumulation, Communications in Mathematical Physics 405, 261 (2024).
[0108]
[0016] P. Sekatski, J. Pauwels, E. P. Lobo, S. Pironio, and N. Brunner, Certification of quantum correlations and diqkd at arbitrary distances through routed Bell tests, arXiv preprint arXiv:2502.12241 (2025).
[0109]
[0017] Tsujimoto et al, Optimal conditions for the Bell test using spontaneous parametric downconversion sources, Phys. Rev. A 98, 063842 (2018)
[0018] Sckatski, Pavel, Jef Pauwcls, Edwin Peter Lobo, Stefano Pironio, and Nicolas Brunner, Certification of quantum correlations and DIQKD at arbitrary distances through routed Bell tests, arXiv:2502.12241 (2025).
[0110]
[0019] M. Navascu'es, S. Pironio, and A. Ac 'in, Bounding the set of quantum correlations, Phys. Rev. Lett. 98, 010401 (2007).
Claims
CLAIMS1. A method of self-testing quantum random number generation, comprising: conducting a routed Bell test in a round -by-round fashion, wherein each round comprises: generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at a client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes by the server to the client; performing entropy estimation at the client based on the input-output data, the third measurement settings and the third measurement outputs; and performing, at the client, randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
2. The method of claim 1 , wherein in each round in which the second signal representing the second part of the pair of entangled quantum states is sent to the third detector at the client, the client either performs a test round for estimating an amount of information leaked to an external party or a generation round for randomness generation.
3. The method of claim 2, wherein the entropy estimation at the client is further based on the estimated amount of information leaked to the external party.4.The method of claims 2 or 3, wherein the third measurement results from the test rounds are also used for the randomness generation.
5. The method of one of the preceding claims, wherein the randomness extraction is jointly applied to the third measurement outcomes and a pre-installed random seed at the client used to determine the measurement settings.
6. The method of any one of the preceding claims, wherein the threshold is greater than zero.
7. A system for self-testing quantum random number generation, comprising:a server comprising a source, a first detector coupled to the source, a second detector coupled to the source via a switch, and a first processor; and at least one client comprising a third detector and a second processor; wherein the system is configured for conducting a routed Bell test in a round-by-round fashion, wherein each round comprises: the source generating a signal representing a pair of entangled quantum states; the first detector performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either by the second detector based on associated second measurement settings and recording a second measurement outcome or by the third detector based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the switch is configured for selectively directing the second signal representing the second part of the pair of entangled quantum states to the second detector or to the third detector at the client based on the random selection input; wherein the first processor is configured for announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes to the client; and wherein the second processor is configured for performing entropy estimation based on the input-output data, the third measurement settings and the third measurement outputs, and for performing randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
8. The system of claim 7, wherein the second processor is configured for performing, in each round, either a test round for estimating an amount of information leaked to an external party or a generation round for recording the third measurement result.
9. The system of claim 8, wherein the second processor is configured for further basing the entropy estimation on the estimated amount of information leaked to the external party.
10. The system of claims 8 or 9, wherein the second processor is configured for also using third measurement results from the test rounds for the randomness generation.1 1. The system of one of claims 7 to 10, wherein the second processor is configured to apply the randomness extraction jointly to the third measurement outcomes and a pre-installed random seed of the client used to determine the measurement settings.
12. The system of any one of claims 7 to 1 1 , wherein the threshold is greater than zero.
13. A client for a system for self-testing quantum random number generation configured for conducting a routed Bell test in a round-by-round fashion, wherein each round comprises: generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at the client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the client comprises: the third detector; and a processor configured for receiving input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes announced by the server to the client; wherein the processor is configured for performing entropy estimation based on the inputoutput data, the third measurement settings and the third measurement outputs; and for performing randomness extraction on the third measurement outputs if the estimated entropy is above a threshold.
14. The client of claim 13, wherein the processor is configured for performing, in each round, either a test round for estimating an amount of information leaked to an external party or a generation round for recording the third measurement result.
15. The client of claim 14, wherein the processor is configured such that the entropy estimation is further based on the estimated amount of information leaked to the external party.
16. The client of claims 14 or 15, wherein the processor is configured for also using the third measurement results from the test rounds for the randomness generation.
17. The client of one of claims 13 to 16, wherein the processor is configured such that the randomness extraction is jointly applied to the third measurement outcomes and a pre-installed random seed of the client used to determine the measurement settings.
18. The client of any one of claims 13 to 17, wherein the threshold is greater than zero.
19. A server for a system for self-testing quantum random number generation configured for conducting a routed Bell test in a round-by-round fashion, wherein each round comprises:generating, at a server, a signal representing a pair of entangled quantum states; performing a quantum measurement of a first signal representing a first part of the pair of entangled quantum states in a first detector at the server based on associated first measurement settings and recording a first measurement outcome; and selectively performing a quantum measurement of a second signal representing a second part of the pair of entangled quantum states either in a second detector at the server based on associated second measurement settings and recording a second measurement outcome or in a third detector at the client based on associated third measurement settings and recording a third measurement outcome, wherein the selection is based on a random selection input; wherein the server comprises: a source for generating the signal representing a pair of entangled quantum states; the first detector coupled to the source; the second detector coupled to the source via a switch configured for selectively directing the second signal representing the second part of the pair of entangled quantum states to the second detector or to the third detector at the client based on the random selection input; and a processor configured for announcing input-output data comprising the random input, the first and second measurement settings, and the first and second measurement outcomes to the client for performing entropy estimation and randomness extraction at the client.
Citation Information
Patent Citations
Cryptographic systems and non-deterministic random number generators based on quantum systems
US20230291555A1