Quantum Randomness
Quantum random-number generation (QRNG) converts outcomes of a quantum experiment into classical symbols whose unpredictability is justified under a declared physical and adversarial model. A serious QRNG claim is therefore not merely that a file looks irregular or that quantum mechanics assigns several possible outcomes. It states which systems may be correlated with the raw data, how much conditional entropy the experiment certifies, which extractor is used, and how close the released string is to an ideal random resource.
The central engineering object is an entropy source, not a stream that has passed a test suite. The source includes the quantum process, preparation and measurement devices, analog electronics, digitizer, timing logic, operating environment, and any state retained between samples. Its raw record is normally biased, correlated, and partly predictable. Certification lower-bounds its smooth min-entropy conditioned on side information; extraction compresses that entropy into a shorter string that is nearly uniform and private.
This page is the canonical home for that full contract: operational randomness, trusted and device-independent QRNGs, entropy estimation, extraction, health tests, rate accounting, implementation failure modes, randomness expansion, and randomness amplification. Random Variables and Entropy own the underlying probability theory. The Born Rule owns quantum measurement probabilities. Certification of Entanglement owns the broader witness–steering–Bell hierarchy, while Device-Independent QKD owns the use of Bell-certified entropy to establish a shared secret key.
What Random Must Mean
Section titled “What Random Must Mean”A bit string may need several different properties. They should not be collapsed into the word random.
| Property | Operational question | What can fail |
|---|---|---|
| balanced | Are zeros and ones nearly equally frequent? | a deterministic alternating string is perfectly balanced |
| statistically typical | Does the string avoid patterns targeted by a test suite? | a pseudorandom or prerecorded string can pass |
| unpredictable | Can an observer guess the next value better than the declared bound? | hidden state, drift, or a copied sequence may reveal it |
| private | Is the value unknown to an adversary with specified side information? | an outcome can be locally uncertain but already known to Eve |
| independent | Is it uncorrelated with earlier outputs, seeds, settings, or another device? | memory and oversampling can preserve correlations |
| fresh | Was it generated after the relevant request or commitment? | replayed old randomness may look ideal |
| authentic | Did the intended generator produce the delivered string without alteration? | a network attacker can replace excellent random bits |
A public lottery beacon needs timely unpredictability, public verifiability, and integrity after release; it does not need secrecy after publication. A key generator needs private outputs. A Monte Carlo calculation may care primarily about distributional accuracy and independence, whereas a cryptographic nonce also needs resistance to prediction, state compromise, rollback, and replay. The application contract must come before the source label.
Why output tests cannot prove unpredictability
Section titled “Why output tests cannot prove unpredictability”Consider a deterministic table containing a billion independently sampled fair bits. A device can replay the table and pass frequency, runs, and correlation tests. Someone holding a copy predicts every output. Conversely, a genuinely random finite string can contain a long run or receive a small -value by chance. Statistical tests can expose selected anomalies; they cannot infer the hidden causal history of one sequence.
This is why NIST distinguishes statistical output testing from entropy-source validation and explicitly rejects test suites as a substitute for assessing a cryptographic generator. A defensible claim combines a source model, evidence that the device remains within that model, an entropy estimate, and appropriate postprocessing.
The Ideal Output Contract
Section titled “The Ideal Output Contract”Let be the released string, all adversarial quantum side information, and all classical information that is permitted to be public: calibration data, extractor seed, test choices revealed after use, and other transcript fields. Ideal private randomness has the classical–quantum state
A composable real-world statement is
Trace Distance explains the operational metric. Roughly, replacing the real output by ideal uniform private bits changes the behavior of any larger protocol by at most the declared error. Separate failure allocations may cover entropy estimation, parameter estimation, extraction, authentication, and implementation checks; composable analyses add them into one budget.
An aborting generator should state the contract on the nonabort output and also report completeness, the probability that an honest, correctly operating device aborts. Soundness without completeness can describe a box that remains secure only because it almost never releases bits. Availability is distinct again: an adversary may be able to jam a physical source and force an abort without learning any accepted output.
Born Probabilities Are Not Yet a Security Proof
Section titled “Born Probabilities Are Not Yet a Security Proof”For a trusted qubit prepared in
a computational-basis measurement gives
Under the additional assumptions that the state really is , the measurement implements the intended projectors, and no outside system is correlated with the qubit, one outcome is an ideal random bit. The Born rule is the physical origin of its unpredictability within that model.
The same local probabilities do not prove privacy. Suppose Eve prepares
Measuring produces a perfectly balanced bit, but Eve can measure and guess it with certainty. Randomness is always relative to side information and to a trust model. Calling an effect quantum identifies a candidate entropy mechanism; it does not by itself quantify private output.
Min-Entropy and Guessing Probability
Section titled “Min-Entropy and Guessing Probability”For a classical random variable , the min-entropy is
It measures worst-case single-shot predictability. A bit with has
bits of min-entropy, not one full bit. Shannon entropy answers a different average coding question and can overstate what is safely extractable in a one-shot adversarial task.
For a classical register correlated with a quantum system , conditional min-entropy has the operational identity
where is Eve’s best probability of identifying using the optimal measurement on . Conditioning should include every variable the security model grants to Eve, including classical environmental records and the public transcript.
Finite protocols use the smooth conditional min-entropy . Smoothing permits optimization over states within a small operational neighborhood of the observed state and is the right quantity for finite-block extraction. It is not permission to discard unfavorable data after looking at them; the smoothing parameter is part of the predeclared failure budget.
For a sequence, one may not silently multiply a one-sample estimate by the number of samples:
in general. Equality or a comparable lower bound needs independence, a Markov condition, a stationary-process analysis, entropy accumulation, or another explicit argument controlling temporal correlations and memory.
Certification and Extraction Pipeline
Section titled “Certification and Extraction Pipeline”A QRNG releases bits only after two logically different checks. The physical model, calibration record, and observed data justify a lower bound on ; a quantum-proof strong extractor then converts that bound into a uniformity-and-privacy guarantee. Startup and online health tests detect specified failures and can trigger abort, but do not create entropy. Moving right along the trust ladder removes internal device models at the cost of stronger causal tests, lower typical rates, or both.
The figure separates four interfaces that product descriptions often merge:
- Generation: a physical process and measurement create an analog or discrete record.
- Digitization: clocks, thresholds, ADC bins, and firmware define the raw symbols .
- Certification: a theorem plus measured evidence lower-bounds entropy against specified side information.
- Extraction and delivery: a vetted algorithm compresses the record, and the system either authenticates and releases the result or aborts.
Every arrow can fail independently. A sound optical model does not characterize an undocumented ADC; a correct entropy estimate does not repair a faulty extractor; and private bits inside a module can be replaced over an unauthenticated network interface.
Trust Models
Section titled “Trust Models”QRNG labels describe what the proof does not need to characterize. They do not rank devices by one universal security number.
| Model | Quantum components treated as trusted | Evidence that certifies entropy | Representative limitation |
|---|---|---|---|
| trusted-device or device-dependent | source and measurement model, including bounded imperfections | calibrated physical model plus monitored parameters | unmodeled classical noise or manipulation can invalidate the estimate |
| source-independent | measurement apparatus is characterized; incoming state may be arbitrary or adversarial | complementary measurements, energy or photon-number monitoring, and finite statistics | detector and basis-choice assumptions remain trusted |
| measurement-device-independent | prepared probe ensemble is characterized; measurement device is untrusted | prepare-and-measure input-output statistics | source dimension, overlap, and independence assumptions remain |
| semi-device-independent | only restricted properties such as dimension, energy, or overlap are assumed | violation of a dimension or prepare-and-measure witness | the bounded property must itself be enforced |
| one-sided device-independent | one measurement side is characterized and the other is not | steering correlations | trusted-side calibration and causal assumptions remain |
| fully device-independent | source and quantum measurement internals are uncharacterized | loophole-aware Bell statistics | high efficiency, isolation, input independence, and substantial finite data are required |
These assumptions form a partial order, not always a straight ladder. An energy bound and a dimension bound constrain different attacks; source-independent and measurement-device-independent designs move opposite subsystems outside the trusted boundary. The right comparison is a trust ledger listing every characterized interface, not the shortest label on a datasheet.
Trusted Quantum Sources
Section titled “Trusted Quantum Sources”Trusted-device generators can operate at high rates because they infer entropy from a detailed model rather than from a Bell violation. Their assurance is only as good as that model and the monitoring that keeps the implementation inside it.
Beam-splitter path choice
Section titled “Beam-splitter path choice”An ideal single photon entering one port of a balanced beam splitter transforms, up to convention-dependent phases, as
A click in output or supplies a binary outcome. Real analysis must cover unequal splitting, detector-efficiency mismatch, dark counts, afterpulsing, dead time, double clicks, missed events, source multiphoton probability, and the rule for assigning or rejecting every event. Calibrating away bias is different from proving that accepted clicks were unknown to an adversary.
Arrival time and photon counting
Section titled “Arrival time and photon counting”Spontaneous emission, radioactive decay, and photon arrival times provide continuous waiting-time or count distributions. Digitizing an arrival time into bins can yield several raw bits per event, but detector jitter, clock structure, dead time, pileup, and afterpulsing correlate neighboring bins. Conditioning on “exactly one click in this window” also changes the distribution and must be part of the model rather than an undocumented postselection.
Vacuum quadrature measurements
Section titled “Vacuum quadrature measurements”A balanced homodyne receiver can measure a field quadrature of the vacuum. A simple digitized model is
where is the modeled quantum contribution, collects classical and electronic contributions, is gain, is offset, and includes finite range and binning. If conservative analysis grants Eve knowledge or control of , entropy must be bounded conditioned on that variable, not estimated from the total variance as though all measured noise were private quantum noise.
Vacuum and laser-phase designs can exploit wide optical and electronic bandwidths. They also make saturation, local-oscillator manipulation, common-mode leakage, ADC nonlinearities, and bandwidth correlations central security parameters. More variance is not automatically more entropy.
Laser phase diffusion
Section titled “Laser phase diffusion”Spontaneous emission gives a reset or gain-switched laser pulse a quantum phase component. Interfering neighboring pulses converts phase difference into intensity, schematically
Fast generators can be built from this mechanism, but the proof must quantify residual phase coherence, pulse-energy variation, interferometer drift, classical phase noise, visibility, digitizer response, and inter-pulse memory. The nonlinear cosine map also makes the raw distribution nonuniform even when the phase is uniform.
Architecture comparison
Section titled “Architecture comparison”| Physical observable | Attractive feature | Entropy-critical failure modes |
|---|---|---|
| photon path or polarization | transparent binary model | detector mismatch, source impurity, no-click handling |
| photon arrival time | several bins per event | dead time, jitter, clock leakage, afterpulsing |
| vacuum quadrature | high bandwidth and many ADC bins | classical side information, saturation, gain drift, correlations |
| laser phase diffusion | very high optical rates | incomplete phase reset, interferometer drift, pulse memory |
| photon number or spontaneous emission | direct quantum-counting interpretation | efficiency, pileup, background, source-state assumptions |
No row is intrinsically “more quantum” in a way that settles security. The model, observables, side information, and fault monitors determine the claim.
Digitization Is Part of the Source
Section titled “Digitization Is Part of the Source”Suppose an ADC has bins . Conditional on a classical nuisance value , the most likely raw symbol has probability
A conservative classical-side-information estimate may use
Continuous or quantum side information requires the corresponding integral or operator formulation, but the lesson is unchanged: the largest conditional bin probability, including overflow bins, controls one-shot entropy. An -bit ADC does not certify random bits per sample.
An implementation audit should characterize at least:
- differential and integral nonlinearity, missing codes, clipping, and saturation probability;
- gain, offset, temperature, supply voltage, and local-oscillator drift;
- aliasing, analog filtering, clock feedthrough, and electromagnetic injection;
- sample-to-sample autocorrelation and longer memory from detectors or feedback;
- firmware transformations, packet loss, buffering, duplicated blocks, and restart behavior;
- whether calibration and test data are included in the conditioning register .
Oversampling is a common rate error. Sampling at far above the effective noise bandwidth produces correlated values, not independent copies of the same entropy. A secure bound must be made on blocks or through a validated spectral or dynamical model. Downsampling can reduce correlation but does not by itself prove independence.
Health Tests and Entropy Certification
Section titled “Health Tests and Entropy Certification”Three layers of evidence serve different purposes.
- Design-time validation establishes a stochastic or quantum model, estimates worst-case parameters, evaluates side channels, and chooses a conservative entropy rate.
- Startup tests check that the source, sensors, and conditioning path begin in an allowed operating region.
- Continuous health tests detect selected catastrophic or gradual failures quickly enough to stop release.
NIST SP 800-90B specifies entropy-source design and validation requirements and includes repetition-count and adaptive-proportion health tests. Such tests can detect a stuck or badly biased source, but their thresholds are not an online estimate of every adversarial entropy loss. Passing says only that the tested failure signature was not observed. A sophisticated deterministic sequence can pass, and an honest random source occasionally triggers a false alarm.
Generic batteries such as NIST SP 800-22 can be useful during development for finding coding errors or unexpected patterns. They are not a security certificate. The strongest practice is to make each health monitor traceable to a physical failure mode and to specify the response: immediate suppression of output, zeroization or quarantine of affected blocks, fault logging, and a controlled restart procedure.
Randomness Extraction
Section titled “Randomness Extraction”A seeded extractor is a deterministic function
whose guarantee holds when has enough conditional min-entropy and the seed satisfies the extractor’s independence requirement. A strong extractor produces output that remains close to uniform even when is published. The seed therefore need not be secret, but it must not have been chosen as a function of the raw block or adversarial side information in a way excluded by the theorem.
Two-universal hashing, often implemented with a Toeplitz matrix, gives a standard quantum-proof construction. A representative leftover-hash bound is
Thus an extractor-error allocation permits the schematic length choice
Exact conventions and finite corrections depend on the theorem used. The key point is invariant: extraction concentrates certified entropy; it does not create it. Hashing a deterministic string yields a deterministic string.
Simple debiasing deserves the same caution. Von Neumann’s pair rule, , , and , removes unknown bias for independent identically distributed coin flips. It does not generally handle memory, adversarial side information, detector asymmetry, or a drifting source. It is not a substitute for a quantum-proof extractor with a stated entropy premise.
Seed handling
Section titled “Seed handling”For a strong extractor, publishing with is allowed. Reusing a seed can also be valid in a proof that preserves the required independence across blocks, but a device with memory or an adaptive adversary can violate a casual reuse argument. The implementation must protect seed integrity and domain-separate extractor invocations. In Bell protocols, random setting choices have a different timing requirement: they must be sufficiently unpredictable to the devices when the measurements occur, even if disclosed later.
Finite-Block and Rate Ledger
Section titled “Finite-Block and Rate Ledger”For raw symbols, a typical proof has the form
where is a model-dependent entropy rate and includes finite estimation, smoothing, nonstationarity, and other proof-specific penalties. The releasable length is then bounded by
If one block takes wall time , the delivered rate is after accounting for discarded startup samples, test rounds, transfer limits, extractor throughput, aborts, and downtime. Quoting the ADC sample rate or the raw interface bitrate as the random-bit rate omits the quantity of interest.
As an illustrative ledger, suppose raw samples have a defensible block rate bits per sample after conditioning on all modeled side information, and the finite penalty is bits. With , the displayed leftover-hash convention requires about more bits of compression:
This arithmetic is not a security analysis by itself. The hard step is justifying against the actual correlations and side information. The ledger merely prevents a certified premise from being lost between experiment, firmware, extraction, and marketing.
Device-Independent Randomness
Section titled “Device-Independent Randomness”A fully device-independent QRNG treats the source and quantum measurement devices as black boxes with classical inputs and outputs. In a bipartite CHSH protocol, the boxes receive and return . The correlators
form the CHSH value
Local hidden-variable behavior obeys , while quantum mechanics permits . A Bell violation rules out a strategy in which all relevant outputs were fixed and known in advance, provided the causal, input-independence, loss, and laboratory assumptions of the Bell experiment hold.
For a representative single-round quantum CHSH analysis, the adversary’s guessing probability for one party’s output can be bounded by
and hence
At this certifies no local randomness; at the Tsirelson value it certifies one bit in the ideal single-round setting. Finite sequential protocols do not apply this formula independently to observed rounds. They predeclare a score, test a random subset or use a probability-estimation method, derive a high-confidence lower score , and use entropy accumulation or another general-attack theorem:
The extractor then produces the composable output. The exact tradeoff function , test probability, stopping rule, and finite term are protocol-specific.
Trial contract and loopholes
Section titled “Trial contract and loopholes”Device independence does not mean assumption-free. A defensible protocol fixes:
- the start and end of every eligible trial before outcomes are known;
- a complete output alphabet, including no-click and timeout behavior;
- spacelike separation or an enforced no-communication boundary between boxes during a trial;
- sufficient independence of current inputs from the devices and Eve;
- authenticated input, output, and timing records;
- physical isolation against radio, optical, acoustic, power, and network leakage;
- treatment of within-run memory and reuse across later sessions;
- a finite-statistics theorem valid for the permitted sequential attack.
Discarding no-click rounds can open the detection loophole. Allowing settings to reach the source before the causal deadline can open an input-predictability or communication loophole. Resetting software without retiring a malicious device does not erase its physical memory. These requirements closely parallel DIQKD, but randomness generation has no second raw key to reconcile: its output task is local private entropy rather than a shared secret string.
Expansion and Amplification
Section titled “Expansion and Amplification”Randomness expansion starts from a short, sufficiently uniform seed, uses some of it to select Bell-test settings, and aims to produce a longer certified string. If fresh seed bits are consumed and private bits are released, net expansion requires
Spot-checking protocols choose a small fraction of test rounds and use a fixed generation setting otherwise, reducing seed cost. A gross output larger than the raw setting record is not enough: the ledger must count all fresh randomness consumed under the security theorem and retain the declared soundness error.
Randomness amplification addresses a different problem. A Santha–Vazirani source produces bits satisfying, for some ,
When is small, each input may be highly biased and correlated with the past and side information, though not completely fixed. Deterministic classical processing cannot generally turn such a source into nearly uniform bits. Bell-based protocols can amplify weak randomness under protocol-specific quantum or no-signaling, causal-independence, device, and acceptance assumptions. That is a physical cryptographic task, not ordinary extractor postprocessing.
The distinction matters experimentally. Expansion assumes a high-quality seed and asks for more bits; amplification weakens the initial-randomness assumption and asks for better bits. In 2026, Kulikov and collaborators reported the first experimental implementation of randomness amplification, using a loophole-free Bell test with separated superconducting circuits. This establishes an experimental milestone under the paper’s model and parameters; it does not make arbitrarily weak sources universally repairable in ordinary deployments.
Experimental Milestones and Claim Boundaries
Section titled “Experimental Milestones and Claim Boundaries”Rates from different trust models are not directly comparable. A gigabit-rate trusted or source-independent generator and a kilobit-rate Bell-certified generator solve different assurance problems.
- Vacuum, phase-noise, and integrated-photonic QRNGs have demonstrated multi-gigabit rates under explicit device models. A 2018 source-device- independent heterodyne experiment reported ; that result removed source characterization, not measurement trust.
- Pironio and collaborators’ 2010 trapped-ion proof of concept certified 42 new random bits at 99% confidence. Its approximately one-meter layout did not close the locality loophole, so it was not the later fully loophole-free operational standard.
- In 2018, Liu and collaborators used a roughly 200 m photonic Bell experiment with more than 78% creation-to-detection efficiency and extracted certified bits from 96 hours of data, with total failure probability below under their analysis.
- Also in 2018, Bierhorst and collaborators produced 1,024 bits within distance of uniform using a loophole-free photonic Bell test and a security analysis based on the impossibility of superluminal signaling.
- A 2020 low-latency experiment produced requested blocks of 512 device-independent bits in less than five minutes on average, with error under its quantum-proof protocol.
- A 2021 photonic experiment secure against quantum side information reported a net gain of certified bits over 19.2 hours, averaging , with soundness error .
- One-sided-device-independent and semi-device-independent experiments occupy intermediate regimes. A 2025 steering-based experiment distributed the relevant optical correlations through 2 km of fiber and reported under its trusted-side model.
These are research demonstrations with different adversaries, loophole closures, extraction conventions, block sizes, and error parameters. Quoting only the largest bitrate erases the scientific content of the comparison.
From an Entropy Source to a Deployed Generator
Section titled “From an Entropy Source to a Deployed Generator”A deployed cryptographic random-bit generator often combines several layers:
A deterministic random bit generator (DRBG) can expand a seed efficiently, buffer demand, separate consumers, and support reseeding and state-management policies. It does not add information-theoretic entropy. Conversely, a raw QRNG without careful state handling, authentication, and an application interface may be a poor system component despite a sound quantum mechanism.
As of this review, NIST SP 800-90B is the final recommendation for entropy-source design and validation, and SP 800-90C, finalized in September 2025, specifies RBG constructions combining SP 800-90B entropy sources with SP 800-90A DRBGs. NIST IR 8446, finalized in January 2026, compares the NIST series with Germany’s BSI AIS 20/31 framework. ISO/IEC 20543:2019, confirmed current in 2025, supplies an implementation-agnostic evaluation methodology for cryptographic random-bit generators. ETSI TR 104 171 V1.1.1, published in March 2026, gives QRNG-specific implementation guidance.
None of these documents declares that a source is secure merely because its noise is quantum. Conformance or certification is a formal claim about a specific implementation, documentation set, evaluation scope, and version of a scheme. A paper citation, passing test report, or QRNG component label does not automatically confer that status on a larger product.
Public beacons and remote randomness
Section titled “Public beacons and remote randomness”A randomness beacon publishes values intended to be unpredictable before a deadline and auditable afterward. Privacy after release is irrelevant, but freshness, timestamping, source commitments, availability, and authenticated history are essential. Hash chains or signed transcripts can make replacement or deletion evident; they do not prove that the preimage contained entropy. Remote private-randomness delivery additionally needs a confidential and authenticated channel, endpoint trust, replay protection, and a clear statement of who may have known the bits before delivery.
Audit Checklist
Section titled “Audit Checklist”Before relying on a QRNG claim, ask for a ledger with concrete answers.
- Application: Must the output be private, merely public and unpredictable, statistically representative, or all three? What freshness and availability are required?
- Adversary: Which classical and quantum side information is conditioned on? Can the source, detector, environment, firmware, or network be malicious?
- Trust boundary: Which source, measurement, dimension, energy, isolation, and input-independence assumptions remain?
- Raw interface: What is one trial or sample? How are no-clicks, overflow, packet loss, startup data, and repeated blocks handled?
- Entropy theorem: What exact quantity is lower-bounded, with what confidence, under what temporal-correlation model?
- Monitoring: Which measured parameters keep the device inside the model, and what happens when a threshold is crossed?
- Extraction: Is the extractor quantum-proof for the stated side information? How are length, seed, domain separation, and failure error chosen?
- Rate: Is the reported number raw sampling rate, certified entropy rate, extracted rate, net expansion, or delivered application throughput?
- Lifecycle: How are manufacturing variation, recalibration, firmware updates, rollback, cross-session memory, fault logs, and retirement handled?
- Evidence: Are raw data, analysis code, calibration records, standards claims, and versioned security parameters available for independent review?
Common Mistakes
Section titled “Common Mistakes”- “It passed NIST tests, so it is unpredictable.” Output tests can reject some bad sequences; they cannot identify a hidden deterministic generator.
- “A quantum measurement always gives a private bit.” Eve may know the preparation, hold a purification, or influence an unmonitored device.
- “An 8-bit ADC yields eight random bits per sample.” The largest conditional bin probability and temporal correlations determine entropy.
- “Classical noise only improves randomness.” Classical noise may be known to or controlled by the adversary and can reduce private entropy.
- “Hashing fixes any source.” An extractor needs a proved entropy premise and correct seed conditions.
- “Device-independent means no trusted components.” The causal envelope, laboratories, input choices, classical recorder, and extractor remain within the trust contract.
- “Bell violation automatically implies net expansion.” Finite penalties and setting randomness can exceed the certified output.
- “Amplification is ordinary debiasing.” It changes the quality of a weak physical randomness resource using nonclassical correlations; deterministic postprocessing alone cannot solve the general task.
- “The largest bitrate is the best generator.” Rates are meaningful only beside trust assumptions, side information, error parameters, latency, and delivered interface behavior.
Connections
Section titled “Connections”- Born Rule develops the measurement probabilities from which trusted QRNG models begin.
- Entropy owns Shannon entropy, conditional entropy, mutual information, and differential-entropy cautions; the present page uses min-entropy for the one-shot operational task.
- CHSH Inequality owns the Bell expression, local bound, Tsirelson bound, and standard quantum realization used in device-independent certification.
- Certification of Entanglement compares trusted witnesses, steering, Bell tests, and self-testing.
- Device-Independent QKD adds two-party key agreement, error correction, and public leakage accounting to the Bell-to-entropy machinery.
- Quantum Key Distribution owns privacy amplification in the complete composable key-distillation pipeline.
Exercises
Section titled “Exercises”1. Balanced but completely predictable
Section titled “1. Balanced but completely predictable”A device emits forever. Compute the empirical frequency of each bit and the min-entropy of the next bit for an observer who knows the rule.
Solution
Over every even-length block, the empirical frequencies are . The next bit is nevertheless fixed by the position, so the informed observer guesses with probability one. Therefore
Frequency balance is not unpredictability.
2. Local uncertainty versus privacy
Section titled “2. Local uncertainty versus privacy”Compare measurement of with measurement of the correlated state
Find and in each case, assuming the first qubit has no side information.
Solution
Both measurements have a uniform local distribution, so bit. For the isolated preparation, Eve has no correlated system and , giving . For the correlated state, measuring in the computational basis reveals exactly, so and .
3. Extraction budget for a biased source
Section titled “3. Extraction budget for a biased source”Assume, as an explicit model, that independent bits have and no side information. Ignore parameter-estimation penalties and take . Using the displayed leftover-hash length rule with zero smoothing, estimate the maximum output length.
Solution
One sample has min-entropy . Independence gives
The extractor penalty is
Thus bits under these deliberately simplified premises. In a real source, estimating the bias and proving independence would add finite penalties.
4. Oversampling
Section titled “4. Oversampling”A homodyne receiver is digitized at but has effective noise bandwidth . Explain why assigning one independent entropy contribution to every ADC sample is unjustified, and name two valid routes to a block entropy bound.
Solution
The analog filter and detector response spread one fluctuation over several samples, creating temporal correlation. A one-sample distribution does not determine . One may use a validated stationary spectral or dynamical model that bounds the conditional entropy rate, or analyze empirical blocks with a theorem that permits the observed memory. Conservative downsampling can support either model, but merely selecting every tenth sample does not prove independence.
5. Public extractor seed
Section titled “5. Public extractor seed”Why may the seed of a strong seeded extractor be published, while a Bell-test measurement setting still has to be unpredictable to the boxes at measurement time?
Solution
Strong-extractor security explicitly compares the joint state of output, seed, and side information with , so disclosure after choosing an independent seed is covered by the theorem. Bell certification instead uses the absence of a prearranged correlation between current settings and device behavior. If a box knows the setting before responding, a local deterministic strategy can imitate the selected correlations. The two random variables enter different causal positions in the proofs.
6. CHSH randomness bound
Section titled “6. CHSH randomness bound”Use the displayed single-round bound to estimate the certified min-entropy of one party’s output at . Check the local and Tsirelson limits.
Solution
At ,
so
At , the bound gives and zero entropy. At , it gives and one bit. A finite experiment must replace the observed score by a confidence-adjusted score and include the sequential finite-size penalty.
7. Expansion or amplification?
Section titled “7. Expansion or amplification?”Classify each task: (a) 1,000 ideal seed bits lead to 10,000 certified bits; (b) highly biased Santha–Vazirani inputs lead to nearly uniform outputs; (c) a Toeplitz hash compresses a trusted raw block with known min-entropy.
Solution
(a) is randomness expansion if all fresh seed use is counted and the net output is positive. (b) is randomness amplification because the quality assumption on the initial source is weakened. (c) is randomness extraction: it converts already certified entropy into nearly uniform bits and does not generate or amplify the physical entropy premise.
8. Design an abort policy
Section titled “8. Design an abort policy”A vacuum QRNG monitors ADC saturation, optical local-oscillator power, and a repetition-count test. For each alarm, state what should happen to the current block and what evidence is needed before restart.
Solution
Any threshold crossing that violates the entropy model should suppress release and quarantine the full block whose certification may depend on the affected samples. Saturation requires confirming ADC range, gain, and signal statistics; an optical-power alarm requires restoring and recalibrating the local oscillator and detector operating point; a repetition alarm requires diagnosing source, clock, data-path, and buffering faults rather than simply clearing the flag. Restart should follow a documented startup test and create an authenticated fault record. The exact affected interval and thresholds must be fixed by the model, not chosen after inspecting whether the output looked acceptable.
References
Section titled “References”- X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, “Quantum random number generation,” npj Quantum Information 2, 16021 (2016), doi:10.1038/npjqi.2016.21.
- M. Herrero-Collantes and J. C. Garcia-Escartin, “Quantum random number generators,” Reviews of Modern Physics 89, 015004 (2017), doi:10.1103/RevModPhys.89.015004.
- C. Gabriel et al., “A generator for unique quantum random numbers based on vacuum states,” Nature Photonics 4, 711–715 (2010), doi:10.1038/nphoton.2010.197.
- M. Avesani, D. G. Marangon, G. Vallone, and P. Villoresi, “Source-device-independent heterodyne-based quantum random number generator at 17 Gbps,” Nature Communications 9, 5365 (2018), doi:10.1038/s41467-018-07585-0.
- X. Lin et al., “Security analysis and improvement of source independent quantum random number generators with imperfect devices,” npj Quantum Information 6, 100 (2020), doi:10.1038/s41534-020-00331-9.
- A. Acín and L. Masanes, “Certified randomness in quantum physics,” Nature 540, 213–219 (2016), doi:10.1038/nature20119.
- S. Pironio et al., “Random numbers certified by Bell’s theorem,” Nature 464, 1021–1024 (2010), doi:10.1038/nature09008.
- M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, “Leftover hashing against quantum side information,” IEEE Transactions on Information Theory 57, 5524–5535 (2011), doi:10.1109/TIT.2011.2158473.
- A. De, C. Portmann, T. Vidick, and R. Renner, “Trevisan’s extractor in the presence of quantum side information,” SIAM Journal on Computing 41, 915–940 (2012), doi:10.1137/100813683.
- C. A. Miller and Y. Shi, “Universal security for randomness expansion from the spot-checking protocol,” SIAM Journal on Computing 46, 1304–1335 (2017), doi:10.1137/15M1044333.
- F. Dupuis, O. Fawzi, and R. Renner, “Entropy accumulation,” Communications in Mathematical Physics 379, 867–913 (2020), doi:10.1007/s00220-020-03839-5.
- R. Arnon-Friedman, R. Renner, and T. Vidick, “Simple and tight device-independent security proofs,” SIAM Journal on Computing 48, 181–225 (2019), doi:10.1137/18M1174726.
- Y. Liu et al., “Device-independent quantum random-number generation,” Nature 562, 548–551 (2018), doi:10.1038/s41586-018-0559-3.
- P. Bierhorst et al., “Experimentally generated randomness certified by the impossibility of superluminal signals,” Nature 556, 223–226 (2018), doi:10.1038/s41586-018-0019-0.
- Y. Zhang et al., “Experimental low-latency device-independent quantum randomness,” Physical Review Letters 124, 010505 (2020), doi:10.1103/PhysRevLett.124.010505.
- W.-Z. Liu et al., “Device-independent randomness expansion against quantum side information,” Nature Physics 17, 448–451 (2021), doi:10.1038/s41567-020-01147-2.
- Y. Zhang et al., “One-sided device-independent random number generation through fiber channels,” Light: Science & Applications 14, 25 (2025), doi:10.1038/s41377-024-01641-9.
- R. Colbeck and R. Renner, “Free randomness can be amplified,” Nature Physics 8, 450–453 (2012), doi:10.1038/nphys2300.
- R. Gallego et al., “Full randomness from arbitrarily deterministic events,” Nature Communications 4, 2654 (2013), doi:10.1038/ncomms3654.
- A. Kulikov et al., “Experimental randomness amplification,” Nature 653, 1033–1038 (2026), doi:10.1038/s41586-026-10521-8.
- M. Farkas et al., “Maximal device-independent randomness in every dimension,” Nature Physics 22, 319–324 (2026), doi:10.1038/s41567-025-03141-y.
- NIST, Recommendation for the Entropy Sources Used for Random Bit Generation, SP 800-90B (2018; errata noted 2025), doi:10.6028/NIST.SP.800-90B.
- NIST, Recommendation for Random Bit Generator (RBG) Constructions, SP 800-90C (2025), doi:10.6028/NIST.SP.800-90C.
- E. Barker et al., Bridging the Gap Between Standards on Random Number Generation: Comparison of SP 800-90 Series and AIS 20/31, NIST IR 8446 (2026), doi:10.6028/NIST.IR.8446.
- ISO/IEC, ISO/IEC 20543:2019: Test and Analysis Methods for Random Bit Generators within ISO/IEC 19790 and ISO/IEC 15408 (2019; confirmed 2025), standard record.
- ETSI, Implementation Guidelines for Quantum Random Number Generators, TR 104 171 V1.1.1 (2026), official work item.
- NIST, A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications, SP 800-22 Rev. 1a (2010; revision decision 2022), doi:10.6028/NIST.SP.800-22r1a.