Skip to content

Quantum Randomness

Quantum random-number generation (QRNG) converts outcomes of a quantum experiment into classical symbols whose unpredictability is justified under a declared physical and adversarial model. A serious QRNG claim is therefore not merely that a file looks irregular or that quantum mechanics assigns several possible outcomes. It states which systems may be correlated with the raw data, how much conditional entropy the experiment certifies, which extractor is used, and how close the released string is to an ideal random resource.

The central engineering object is an entropy source, not a stream that has passed a test suite. The source includes the quantum process, preparation and measurement devices, analog electronics, digitizer, timing logic, operating environment, and any state retained between samples. Its raw record XnX^n is normally biased, correlated, and partly predictable. Certification lower-bounds its smooth min-entropy conditioned on side information; extraction compresses that entropy into a shorter string ZℓZ^\ell that is nearly uniform and private.

This page is the canonical home for that full contract: operational randomness, trusted and device-independent QRNGs, entropy estimation, extraction, health tests, rate accounting, implementation failure modes, randomness expansion, and randomness amplification. Random Variables and Entropy own the underlying probability theory. The Born Rule owns quantum measurement probabilities. Certification of Entanglement owns the broader witness–steering–Bell hierarchy, while Device-Independent QKD owns the use of Bell-certified entropy to establish a shared secret key.

A bit string may need several different properties. They should not be collapsed into the word random.

PropertyOperational questionWhat can fail
balancedAre zeros and ones nearly equally frequent?a deterministic alternating string is perfectly balanced
statistically typicalDoes the string avoid patterns targeted by a test suite?a pseudorandom or prerecorded string can pass
unpredictableCan an observer guess the next value better than the declared bound?hidden state, drift, or a copied sequence may reveal it
privateIs the value unknown to an adversary with specified side information?an outcome can be locally uncertain but already known to Eve
independentIs it uncorrelated with earlier outputs, seeds, settings, or another device?memory and oversampling can preserve correlations
freshWas it generated after the relevant request or commitment?replayed old randomness may look ideal
authenticDid the intended generator produce the delivered string without alteration?a network attacker can replace excellent random bits

A public lottery beacon needs timely unpredictability, public verifiability, and integrity after release; it does not need secrecy after publication. A key generator needs private outputs. A Monte Carlo calculation may care primarily about distributional accuracy and independence, whereas a cryptographic nonce also needs resistance to prediction, state compromise, rollback, and replay. The application contract must come before the source label.

Why output tests cannot prove unpredictability

Section titled “Why output tests cannot prove unpredictability”

Consider a deterministic table containing a billion independently sampled fair bits. A device can replay the table and pass frequency, runs, and correlation tests. Someone holding a copy predicts every output. Conversely, a genuinely random finite string can contain a long run or receive a small pp-value by chance. Statistical tests can expose selected anomalies; they cannot infer the hidden causal history of one sequence.

This is why NIST distinguishes statistical output testing from entropy-source validation and explicitly rejects test suites as a substitute for assessing a cryptographic generator. A defensible claim combines a source model, evidence that the device remains within that model, an entropy estimate, and appropriate postprocessing.

Let Z∈{0,1}ℓZ\in\{0,1\}^\ell be the released string, EE all adversarial quantum side information, and CC all classical information that is permitted to be public: calibration data, extractor seed, test choices revealed after use, and other transcript fields. Ideal private randomness has the classical–quantum state

τZ⊗ρEC,τZ=2−ℓ∑z∣z⟩ ⁣⟨z∣.\tau_Z\otimes\rho_{EC}, \qquad \tau_Z=2^{-\ell}\sum_z |z\rangle\!\langle z|.

A composable real-world statement is

12∥ρZEC−τZ⊗ρEC∥1≤εrnd.\frac12 \left\| \rho_{ZEC}-\tau_Z\otimes\rho_{EC} \right\|_1 \leq \varepsilon_{\mathrm{rnd}}.

Trace Distance explains the operational metric. Roughly, replacing the real output by ideal uniform private bits changes the behavior of any larger protocol by at most the declared error. Separate failure allocations may cover entropy estimation, parameter estimation, extraction, authentication, and implementation checks; composable analyses add them into one budget.

An aborting generator should state the contract on the nonabort output and also report completeness, the probability that an honest, correctly operating device aborts. Soundness without completeness can describe a box that remains secure only because it almost never releases bits. Availability is distinct again: an adversary may be able to jam a physical source and force an abort without learning any accepted output.

Born Probabilities Are Not Yet a Security Proof

Section titled “Born Probabilities Are Not Yet a Security Proof”

For a trusted qubit prepared in

∣+⟩=∣0⟩+∣1⟩2,|+\rangle = \frac{|0\rangle+|1\rangle}{\sqrt 2},

a computational-basis measurement gives

Pr⁡(0)=Pr⁡(1)=12.\Pr(0)=\Pr(1)=\frac12.

Under the additional assumptions that the state really is ∣+⟩|+\rangle, the measurement implements the intended projectors, and no outside system is correlated with the qubit, one outcome is an ideal random bit. The Born rule is the physical origin of its unpredictability within that model.

The same local probabilities do not prove privacy. Suppose Eve prepares

ρQE=12∣0⟩ ⁣⟨0∣Q⊗∣0⟩ ⁣⟨0∣E+12∣1⟩ ⁣⟨1∣Q⊗∣1⟩ ⁣⟨1∣E.\rho_{QE} = \frac12 |0\rangle\!\langle0|_Q\otimes|0\rangle\!\langle0|_E + \frac12 |1\rangle\!\langle1|_Q\otimes|1\rangle\!\langle1|_E.

Measuring QQ produces a perfectly balanced bit, but Eve can measure EE and guess it with certainty. Randomness is always relative to side information and to a trust model. Calling an effect quantum identifies a candidate entropy mechanism; it does not by itself quantify private output.

For a classical random variable XX, the min-entropy is

Hmin⁡(X)=−log⁡2 ⁣(max⁡xpX(x)).H_{\min}(X) = -\log_2\!\left(\max_x p_X(x)\right).

It measures worst-case single-shot predictability. A bit with p(0)=0.55p(0)=0.55 has

Hmin⁡(X)=−log⁡2(0.55)≈0.862H_{\min}(X)=-\log_2(0.55)\approx0.862

bits of min-entropy, not one full bit. Shannon entropy answers a different average coding question and can overstate what is safely extractable in a one-shot adversarial task.

For a classical register XX correlated with a quantum system EE, conditional min-entropy has the operational identity

Hmin⁡(X∣E)ρ=−log⁡2pguess(X∣E),H_{\min}(X\mid E)_\rho = -\log_2 p_{\mathrm{guess}}(X\mid E),

where pguessp_{\mathrm{guess}} is Eve’s best probability of identifying XX using the optimal measurement on EE. Conditioning should include every variable the security model grants to Eve, including classical environmental records and the public transcript.

Finite protocols use the smooth conditional min-entropy Hmin⁡εs(X∣E)H_{\min}^{\varepsilon_s}(X\mid E). Smoothing permits optimization over states within a small operational neighborhood of the observed state and is the right quantity for finite-block extraction. It is not permission to discard unfavorable data after looking at them; the smoothing parameter is part of the predeclared failure budget.

For a sequence, one may not silently multiply a one-sample estimate by the number of samples:

Hmin⁡(Xn∣E)≠nHmin⁡(X1∣E)H_{\min}(X^n\mid E) \ne n H_{\min}(X_1\mid E)

in general. Equality or a comparable lower bound needs independence, a Markov condition, a stationary-process analysis, entropy accumulation, or another explicit argument controlling temporal correlations and memory.

A quantum randomness pipeline from a physical process through digitization and entropy certification to a seeded extractor and release-or-abort output, with health tests and a ladder of device-trust models.

A QRNG releases bits only after two logically different checks. The physical model, calibration record, and observed data justify a lower bound kk on Hmin⁡ε(Xn∣E,C)H_{\min}^{\varepsilon}(X^n\mid E,C); a quantum-proof strong extractor then converts that bound into a uniformity-and-privacy guarantee. Startup and online health tests detect specified failures and can trigger abort, but do not create entropy. Moving right along the trust ladder removes internal device models at the cost of stronger causal tests, lower typical rates, or both.

The figure separates four interfaces that product descriptions often merge:

  1. Generation: a physical process and measurement create an analog or discrete record.
  2. Digitization: clocks, thresholds, ADC bins, and firmware define the raw symbols XnX^n.
  3. Certification: a theorem plus measured evidence lower-bounds entropy against specified side information.
  4. Extraction and delivery: a vetted algorithm compresses the record, and the system either authenticates and releases the result or aborts.

Every arrow can fail independently. A sound optical model does not characterize an undocumented ADC; a correct entropy estimate does not repair a faulty extractor; and private bits inside a module can be replaced over an unauthenticated network interface.

QRNG labels describe what the proof does not need to characterize. They do not rank devices by one universal security number.

ModelQuantum components treated as trustedEvidence that certifies entropyRepresentative limitation
trusted-device or device-dependentsource and measurement model, including bounded imperfectionscalibrated physical model plus monitored parametersunmodeled classical noise or manipulation can invalidate the estimate
source-independentmeasurement apparatus is characterized; incoming state may be arbitrary or adversarialcomplementary measurements, energy or photon-number monitoring, and finite statisticsdetector and basis-choice assumptions remain trusted
measurement-device-independentprepared probe ensemble is characterized; measurement device is untrustedprepare-and-measure input-output statisticssource dimension, overlap, and independence assumptions remain
semi-device-independentonly restricted properties such as dimension, energy, or overlap are assumedviolation of a dimension or prepare-and-measure witnessthe bounded property must itself be enforced
one-sided device-independentone measurement side is characterized and the other is notsteering correlationstrusted-side calibration and causal assumptions remain
fully device-independentsource and quantum measurement internals are uncharacterizedloophole-aware Bell statisticshigh efficiency, isolation, input independence, and substantial finite data are required

These assumptions form a partial order, not always a straight ladder. An energy bound and a dimension bound constrain different attacks; source-independent and measurement-device-independent designs move opposite subsystems outside the trusted boundary. The right comparison is a trust ledger listing every characterized interface, not the shortest label on a datasheet.

Trusted-device generators can operate at high rates because they infer entropy from a detailed model rather than from a Bell violation. Their assurance is only as good as that model and the monitoring that keeps the implementation inside it.

An ideal single photon entering one port of a balanced beam splitter transforms, up to convention-dependent phases, as

∣1⟩a∣0⟩b⟼∣1⟩c∣0⟩d+i∣0⟩c∣1⟩d2.|1\rangle_a|0\rangle_b \longmapsto \frac{ |1\rangle_c|0\rangle_d +i|0\rangle_c|1\rangle_d }{\sqrt2}.

A click in output cc or dd supplies a binary outcome. Real analysis must cover unequal splitting, detector-efficiency mismatch, dark counts, afterpulsing, dead time, double clicks, missed events, source multiphoton probability, and the rule for assigning or rejecting every event. Calibrating away bias is different from proving that accepted clicks were unknown to an adversary.

Spontaneous emission, radioactive decay, and photon arrival times provide continuous waiting-time or count distributions. Digitizing an arrival time into bins can yield several raw bits per event, but detector jitter, clock structure, dead time, pileup, and afterpulsing correlate neighboring bins. Conditioning on “exactly one click in this window” also changes the distribution and must be part of the model rather than an undocumented postselection.

A balanced homodyne receiver can measure a field quadrature of the vacuum. A simple digitized model is

Yi=Qi+Ci,Xi=QADC(gYi+o),Y_i=Q_i+C_i, \qquad X_i=\mathcal Q_{\mathrm{ADC}}(gY_i+o),

where QiQ_i is the modeled quantum contribution, CiC_i collects classical and electronic contributions, gg is gain, oo is offset, and QADC\mathcal Q_{\mathrm{ADC}} includes finite range and binning. If conservative analysis grants Eve knowledge or control of CiC_i, entropy must be bounded conditioned on that variable, not estimated from the total variance as though all measured noise were private quantum noise.

Vacuum and laser-phase designs can exploit wide optical and electronic bandwidths. They also make saturation, local-oscillator manipulation, common-mode leakage, ADC nonlinearities, and bandwidth correlations central security parameters. More variance is not automatically more entropy.

Spontaneous emission gives a reset or gain-switched laser pulse a quantum phase component. Interfering neighboring pulses converts phase difference into intensity, schematically

Ii=I0[1+Vcos⁡(ϕi−ϕi−1+θ)].I_i = I_0\left[1+V\cos(\phi_i-\phi_{i-1}+\theta)\right].

Fast generators can be built from this mechanism, but the proof must quantify residual phase coherence, pulse-energy variation, interferometer drift, classical phase noise, visibility, digitizer response, and inter-pulse memory. The nonlinear cosine map also makes the raw distribution nonuniform even when the phase is uniform.

Physical observableAttractive featureEntropy-critical failure modes
photon path or polarizationtransparent binary modeldetector mismatch, source impurity, no-click handling
photon arrival timeseveral bins per eventdead time, jitter, clock leakage, afterpulsing
vacuum quadraturehigh bandwidth and many ADC binsclassical side information, saturation, gain drift, correlations
laser phase diffusionvery high optical ratesincomplete phase reset, interferometer drift, pulse memory
photon number or spontaneous emissiondirect quantum-counting interpretationefficiency, pileup, background, source-state assumptions

No row is intrinsically “more quantum” in a way that settles security. The model, observables, side information, and fault monitors determine the claim.

Suppose an ADC has bins BxB_x. Conditional on a classical nuisance value cc, the most likely raw symbol has probability

pmax⁡(c)=max⁡x∫BxpY∣C(y∣c) dy.p_{\max}(c) = \max_x \int_{B_x} p_{Y\mid C}(y\mid c)\,dy.

A conservative classical-side-information estimate may use

pguess(X∣C)=∑cp(c) pmax⁡(c),Hmin⁡(X∣C)=−log⁡2pguess(X∣C).p_{\mathrm{guess}}(X\mid C) = \sum_c p(c)\,p_{\max}(c), \qquad H_{\min}(X\mid C) = -\log_2 p_{\mathrm{guess}}(X\mid C).

Continuous or quantum side information requires the corresponding integral or operator formulation, but the lesson is unchanged: the largest conditional bin probability, including overflow bins, controls one-shot entropy. An mm-bit ADC does not certify mm random bits per sample.

An implementation audit should characterize at least:

  • differential and integral nonlinearity, missing codes, clipping, and saturation probability;
  • gain, offset, temperature, supply voltage, and local-oscillator drift;
  • aliasing, analog filtering, clock feedthrough, and electromagnetic injection;
  • sample-to-sample autocorrelation and longer memory from detectors or feedback;
  • firmware transformations, packet loss, buffering, duplicated blocks, and restart behavior;
  • whether calibration and test data are included in the conditioning register CC.

Oversampling is a common rate error. Sampling at fsf_s far above the effective noise bandwidth BB produces correlated values, not fs/Bf_s/B independent copies of the same entropy. A secure bound must be made on blocks or through a validated spectral or dynamical model. Downsampling can reduce correlation but does not by itself prove independence.

Three layers of evidence serve different purposes.

  1. Design-time validation establishes a stochastic or quantum model, estimates worst-case parameters, evaluates side channels, and chooses a conservative entropy rate.
  2. Startup tests check that the source, sensors, and conditioning path begin in an allowed operating region.
  3. Continuous health tests detect selected catastrophic or gradual failures quickly enough to stop release.

NIST SP 800-90B specifies entropy-source design and validation requirements and includes repetition-count and adaptive-proportion health tests. Such tests can detect a stuck or badly biased source, but their thresholds are not an online estimate of every adversarial entropy loss. Passing says only that the tested failure signature was not observed. A sophisticated deterministic sequence can pass, and an honest random source occasionally triggers a false alarm.

Generic batteries such as NIST SP 800-22 can be useful during development for finding coding errors or unexpected patterns. They are not a security certificate. The strongest practice is to make each health monitor traceable to a physical failure mode and to specify the response: immediate suppression of output, zeroization or quarantine of affected blocks, fault logging, and a controlled restart procedure.

A seeded extractor is a deterministic function

Z=Ext⁡(X,S)Z=\operatorname{Ext}(X,S)

whose guarantee holds when XX has enough conditional min-entropy and the seed SS satisfies the extractor’s independence requirement. A strong extractor produces output that remains close to uniform even when SS is published. The seed therefore need not be secret, but it must not have been chosen as a function of the raw block or adversarial side information in a way excluded by the theorem.

Two-universal hashing, often implemented with a Toeplitz matrix, gives a standard quantum-proof construction. A representative leftover-hash bound is

12∥ρZSEC−τZ⊗ρSEC∥1≤εs+122−12[Hmin⁡εs(X∣E,C)−ℓ].\frac12 \left\| \rho_{ZSEC} - \tau_Z\otimes\rho_{SEC} \right\|_1 \leq \varepsilon_s + \frac12 2^{-\frac12\left[ H_{\min}^{\varepsilon_s}(X\mid E,C)-\ell \right]}.

Thus an extractor-error allocation εext\varepsilon_{\mathrm{ext}} permits the schematic length choice

ℓ≤Hmin⁡εs(X∣E,C)−2log⁡2 ⁣12εext.\ell \leq H_{\min}^{\varepsilon_s}(X\mid E,C) -2\log_2\!\frac{1}{2\varepsilon_{\mathrm{ext}}}.

Exact conventions and finite corrections depend on the theorem used. The key point is invariant: extraction concentrates certified entropy; it does not create it. Hashing a deterministic string yields a deterministic string.

Simple debiasing deserves the same caution. Von Neumann’s pair rule, 01↦001\mapsto0, 10↦110\mapsto1, and 00,11↦∅00,11\mapsto\varnothing, removes unknown bias for independent identically distributed coin flips. It does not generally handle memory, adversarial side information, detector asymmetry, or a drifting source. It is not a substitute for a quantum-proof extractor with a stated entropy premise.

For a strong extractor, publishing SS with ZZ is allowed. Reusing a seed can also be valid in a proof that preserves the required independence across blocks, but a device with memory or an adaptive adversary can violate a casual reuse argument. The implementation must protect seed integrity and domain-separate extractor invocations. In Bell protocols, random setting choices have a different timing requirement: they must be sufficiently unpredictable to the devices when the measurements occur, even if disclosed later.

For nn raw symbols, a typical proof has the form

Hmin⁡εs(Xn∣E,C)≥nhcert−Δfin,H_{\min}^{\varepsilon_s}(X^n\mid E,C) \geq n h_{\mathrm{cert}}-\Delta_{\mathrm{fin}},

where hcerth_{\mathrm{cert}} is a model-dependent entropy rate and Δfin\Delta_{\mathrm{fin}} includes finite estimation, smoothing, nonstationarity, and other proof-specific penalties. The releasable length is then bounded by

ℓ≤nhcert−Δfin−Δext.\ell \leq n h_{\mathrm{cert}} -\Delta_{\mathrm{fin}} -\Delta_{\mathrm{ext}}.

If one block takes wall time TT, the delivered rate is Rout=ell/TR_{\mathrm{out}}=ell/T after accounting for discarded startup samples, test rounds, transfer limits, extractor throughput, aborts, and downtime. Quoting the ADC sample rate or the raw interface bitrate as the random-bit rate omits the quantity of interest.

As an illustrative ledger, suppose 10810^8 raw samples have a defensible block rate hcert=0.73h_{\mathrm{cert}}=0.73 bits per sample after conditioning on all modeled side information, and the finite penalty is 1.5×1061.5\times10^6 bits. With εext=2−64\varepsilon_{\mathrm{ext}}=2^{-64}, the displayed leftover-hash convention requires about 126126 more bits of compression:

Hmin⁡εs(Xn∣E,C)≥73,000,000−1,500,000,ℓ≤71,499,874.\begin{aligned} H_{\min}^{\varepsilon_s}(X^n\mid E,C) &\geq 73{,}000{,}000-1{,}500{,}000,\\ \ell &\leq 71{,}499{,}874. \end{aligned}

This arithmetic is not a security analysis by itself. The hard step is justifying 0.730.73 against the actual correlations and side information. The ledger merely prevents a certified premise from being lost between experiment, firmware, extraction, and marketing.

A fully device-independent QRNG treats the source and quantum measurement devices as black boxes with classical inputs and outputs. In a bipartite CHSH protocol, the boxes receive x,y∈{0,1}x,y\in\{0,1\} and return a,b∈{0,1}a,b\in\{0,1\}. The correlators

Exy=∑a,b(−1)a+bp(a,b∣x,y)E_{xy} = \sum_{a,b} (-1)^{a+b}p(a,b\mid x,y)

form the CHSH value

S=E00+E01+E10−E11.S=E_{00}+E_{01}+E_{10}-E_{11}.

Local hidden-variable behavior obeys ∣S∣≤2|S|\leq2, while quantum mechanics permits ∣S∣≤22|S|\leq2\sqrt2. A Bell violation rules out a strategy in which all relevant outputs were fixed and known in advance, provided the causal, input-independence, loss, and laboratory assumptions of the Bell experiment hold.

For a representative single-round quantum CHSH analysis, the adversary’s guessing probability for one party’s output can be bounded by

pguess(A∣E,x)≤12(1+2−S24),p_{\mathrm{guess}}(A\mid E,x) \leq \frac12 \left( 1+\sqrt{2-\frac{S^2}{4}} \right),

and hence

Hmin⁡(A∣E,x)≥1−log⁡2 ⁣(1+2−S24).H_{\min}(A\mid E,x) \geq 1- \log_2\!\left( 1+\sqrt{2-\frac{S^2}{4}} \right).

At S=2S=2 this certifies no local randomness; at the Tsirelson value it certifies one bit in the ideal single-round setting. Finite sequential protocols do not apply this formula independently to observed rounds. They predeclare a score, test a random subset or use a probability-estimation method, derive a high-confidence lower score S∗S_*, and use entropy accumulation or another general-attack theorem:

Hmin⁡εs(Agenn∣E,C)≥nf(S∗)−ΔEA.H_{\min}^{\varepsilon_s}(A_{\mathrm{gen}}^n\mid E,C) \geq n f(S_*)-\Delta_{\mathrm{EA}}.

The extractor then produces the composable output. The exact tradeoff function ff, test probability, stopping rule, and finite term are protocol-specific.

Device independence does not mean assumption-free. A defensible protocol fixes:

  • the start and end of every eligible trial before outcomes are known;
  • a complete output alphabet, including no-click and timeout behavior;
  • spacelike separation or an enforced no-communication boundary between boxes during a trial;
  • sufficient independence of current inputs from the devices and Eve;
  • authenticated input, output, and timing records;
  • physical isolation against radio, optical, acoustic, power, and network leakage;
  • treatment of within-run memory and reuse across later sessions;
  • a finite-statistics theorem valid for the permitted sequential attack.

Discarding no-click rounds can open the detection loophole. Allowing settings to reach the source before the causal deadline can open an input-predictability or communication loophole. Resetting software without retiring a malicious device does not erase its physical memory. These requirements closely parallel DIQKD, but randomness generation has no second raw key to reconcile: its output task is local private entropy rather than a shared secret string.

Randomness expansion starts from a short, sufficiently uniform seed, uses some of it to select Bell-test settings, and aims to produce a longer certified string. If dd fresh seed bits are consumed and ℓ\ell private bits are released, net expansion requires

ℓ−d>0.\ell-d>0.

Spot-checking protocols choose a small fraction of test rounds and use a fixed generation setting otherwise, reducing seed cost. A gross output larger than the raw setting record is not enough: the ledger must count all fresh randomness consumed under the security theorem and retain the declared soundness error.

Randomness amplification addresses a different problem. A Santha–Vazirani source produces bits RiR_i satisfying, for some 0<α≤1/20<\alpha\leq1/2,

α≤Pr⁡(Ri=0∣R<i,E)≤1−α.\alpha \leq \Pr(R_i=0\mid R_{<i},E) \leq 1-\alpha.

When α\alpha is small, each input may be highly biased and correlated with the past and side information, though not completely fixed. Deterministic classical processing cannot generally turn such a source into nearly uniform bits. Bell-based protocols can amplify weak randomness under protocol-specific quantum or no-signaling, causal-independence, device, and acceptance assumptions. That is a physical cryptographic task, not ordinary extractor postprocessing.

The distinction matters experimentally. Expansion assumes a high-quality seed and asks for more bits; amplification weakens the initial-randomness assumption and asks for better bits. In 2026, Kulikov and collaborators reported the first experimental implementation of randomness amplification, using a loophole-free Bell test with separated superconducting circuits. This establishes an experimental milestone under the paper’s model and parameters; it does not make arbitrarily weak sources universally repairable in ordinary deployments.

Experimental Milestones and Claim Boundaries

Section titled “Experimental Milestones and Claim Boundaries”

Rates from different trust models are not directly comparable. A gigabit-rate trusted or source-independent generator and a kilobit-rate Bell-certified generator solve different assurance problems.

  • Vacuum, phase-noise, and integrated-photonic QRNGs have demonstrated multi-gigabit rates under explicit device models. A 2018 source-device- independent heterodyne experiment reported 17.42 Gbit s−117.42\ \mathrm{Gbit\,s^{-1}}; that result removed source characterization, not measurement trust.
  • Pironio and collaborators’ 2010 trapped-ion proof of concept certified 42 new random bits at 99% confidence. Its approximately one-meter layout did not close the locality loophole, so it was not the later fully loophole-free operational standard.
  • In 2018, Liu and collaborators used a roughly 200 m photonic Bell experiment with more than 78% creation-to-detection efficiency and extracted 6.2469×1076.2469\times10^7 certified bits from 96 hours of data, with total failure probability below 10−510^{-5} under their analysis.
  • Also in 2018, Bierhorst and collaborators produced 1,024 bits within distance 10−1210^{-12} of uniform using a loophole-free photonic Bell test and a security analysis based on the impossibility of superluminal signaling.
  • A 2020 low-latency experiment produced requested blocks of 512 device-independent bits in less than five minutes on average, with error 2−642^{-64} under its quantum-proof protocol.
  • A 2021 photonic experiment secure against quantum side information reported a net gain of 2.57×1082.57\times10^8 certified bits over 19.2 hours, averaging 13,527 bit s−113{,}527\ \mathrm{bit\,s^{-1}}, with soundness error 3.09×10−123.09\times10^{-12}.
  • One-sided-device-independent and semi-device-independent experiments occupy intermediate regimes. A 2025 steering-based experiment distributed the relevant optical correlations through 2 km of fiber and reported 7.06 Mbit s−17.06\ \mathrm{Mbit\,s^{-1}} under its trusted-side model.

These are research demonstrations with different adversaries, loophole closures, extraction conventions, block sizes, and error parameters. Quoting only the largest bitrate erases the scientific content of the comparison.

From an Entropy Source to a Deployed Generator

Section titled “From an Entropy Source to a Deployed Generator”

A deployed cryptographic random-bit generator often combines several layers:

physical entropy source⟶conditioning⟶DRBG state⟶application interface.\text{physical entropy source} \longrightarrow \text{conditioning} \longrightarrow \text{DRBG state} \longrightarrow \text{application interface}.

A deterministic random bit generator (DRBG) can expand a seed efficiently, buffer demand, separate consumers, and support reseeding and state-management policies. It does not add information-theoretic entropy. Conversely, a raw QRNG without careful state handling, authentication, and an application interface may be a poor system component despite a sound quantum mechanism.

As of this review, NIST SP 800-90B is the final recommendation for entropy-source design and validation, and SP 800-90C, finalized in September 2025, specifies RBG constructions combining SP 800-90B entropy sources with SP 800-90A DRBGs. NIST IR 8446, finalized in January 2026, compares the NIST series with Germany’s BSI AIS 20/31 framework. ISO/IEC 20543:2019, confirmed current in 2025, supplies an implementation-agnostic evaluation methodology for cryptographic random-bit generators. ETSI TR 104 171 V1.1.1, published in March 2026, gives QRNG-specific implementation guidance.

None of these documents declares that a source is secure merely because its noise is quantum. Conformance or certification is a formal claim about a specific implementation, documentation set, evaluation scope, and version of a scheme. A paper citation, passing test report, or QRNG component label does not automatically confer that status on a larger product.

A randomness beacon publishes values intended to be unpredictable before a deadline and auditable afterward. Privacy after release is irrelevant, but freshness, timestamping, source commitments, availability, and authenticated history are essential. Hash chains or signed transcripts can make replacement or deletion evident; they do not prove that the preimage contained entropy. Remote private-randomness delivery additionally needs a confidential and authenticated channel, endpoint trust, replay protection, and a clear statement of who may have known the bits before delivery.

Before relying on a QRNG claim, ask for a ledger with concrete answers.

  1. Application: Must the output be private, merely public and unpredictable, statistically representative, or all three? What freshness and availability are required?
  2. Adversary: Which classical and quantum side information is conditioned on? Can the source, detector, environment, firmware, or network be malicious?
  3. Trust boundary: Which source, measurement, dimension, energy, isolation, and input-independence assumptions remain?
  4. Raw interface: What is one trial or sample? How are no-clicks, overflow, packet loss, startup data, and repeated blocks handled?
  5. Entropy theorem: What exact quantity is lower-bounded, with what confidence, under what temporal-correlation model?
  6. Monitoring: Which measured parameters keep the device inside the model, and what happens when a threshold is crossed?
  7. Extraction: Is the extractor quantum-proof for the stated side information? How are length, seed, domain separation, and failure error chosen?
  8. Rate: Is the reported number raw sampling rate, certified entropy rate, extracted rate, net expansion, or delivered application throughput?
  9. Lifecycle: How are manufacturing variation, recalibration, firmware updates, rollback, cross-session memory, fault logs, and retirement handled?
  10. Evidence: Are raw data, analysis code, calibration records, standards claims, and versioned security parameters available for independent review?
  • “It passed NIST tests, so it is unpredictable.” Output tests can reject some bad sequences; they cannot identify a hidden deterministic generator.
  • “A quantum measurement always gives a private bit.” Eve may know the preparation, hold a purification, or influence an unmonitored device.
  • “An 8-bit ADC yields eight random bits per sample.” The largest conditional bin probability and temporal correlations determine entropy.
  • “Classical noise only improves randomness.” Classical noise may be known to or controlled by the adversary and can reduce private entropy.
  • “Hashing fixes any source.” An extractor needs a proved entropy premise and correct seed conditions.
  • “Device-independent means no trusted components.” The causal envelope, laboratories, input choices, classical recorder, and extractor remain within the trust contract.
  • “Bell violation automatically implies net expansion.” Finite penalties and setting randomness can exceed the certified output.
  • “Amplification is ordinary debiasing.” It changes the quality of a weak physical randomness resource using nonclassical correlations; deterministic postprocessing alone cannot solve the general task.
  • “The largest bitrate is the best generator.” Rates are meaningful only beside trust assumptions, side information, error parameters, latency, and delivered interface behavior.
  • Born Rule develops the measurement probabilities from which trusted QRNG models begin.
  • Entropy owns Shannon entropy, conditional entropy, mutual information, and differential-entropy cautions; the present page uses min-entropy for the one-shot operational task.
  • CHSH Inequality owns the Bell expression, local bound, Tsirelson bound, and standard quantum realization used in device-independent certification.
  • Certification of Entanglement compares trusted witnesses, steering, Bell tests, and self-testing.
  • Device-Independent QKD adds two-party key agreement, error correction, and public leakage accounting to the Bell-to-entropy machinery.
  • Quantum Key Distribution owns privacy amplification in the complete composable key-distillation pipeline.

A device emits 010101…010101\ldots forever. Compute the empirical frequency of each bit and the min-entropy of the next bit for an observer who knows the rule.

Solution

Over every even-length block, the empirical frequencies are p^(0)=p^(1)=1/2\hat p(0)=\hat p(1)=1/2. The next bit is nevertheless fixed by the position, so the informed observer guesses with probability one. Therefore

Hmin⁡(Xi+1∣i)=−log⁡21=0.H_{\min}(X_{i+1}\mid i)= -\log_2 1=0.

Frequency balance is not unpredictability.

Compare measurement of ∣+⟩Q|+\rangle_Q with measurement of the correlated state

ρQE=12∑x=01∣x⟩ ⁣⟨x∣Q⊗∣x⟩ ⁣⟨x∣E.\rho_{QE} = \frac12\sum_{x=0}^1 |x\rangle\!\langle x|_Q\otimes|x\rangle\!\langle x|_E.

Find Hmin⁡(X)H_{\min}(X) and Hmin⁡(X∣E)H_{\min}(X\mid E) in each case, assuming the first qubit has no side information.

Solution

Both measurements have a uniform local distribution, so Hmin⁡(X)=1H_{\min}(X)=1 bit. For the isolated ∣+⟩|+\rangle preparation, Eve has no correlated system and pguess(X∣E)=1/2p_{\mathrm{guess}}(X\mid E)=1/2, giving Hmin⁡(X∣E)=1H_{\min}(X\mid E)=1. For the correlated state, measuring EE in the computational basis reveals XX exactly, so pguess(X∣E)=1p_{\mathrm{guess}}(X\mid E)=1 and Hmin⁡(X∣E)=0H_{\min}(X\mid E)=0.

Assume, as an explicit model, that n=106n=10^6 independent bits have p(0)=0.55p(0)=0.55 and no side information. Ignore parameter-estimation penalties and take εext=2−40\varepsilon_{\mathrm{ext}}=2^{-40}. Using the displayed leftover-hash length rule with zero smoothing, estimate the maximum output length.

Solution

One sample has min-entropy −log⁡2(0.55)≈0.862496-\log_2(0.55)\approx0.862496. Independence gives

Hmin⁡(Xn)≈862,496 bits.H_{\min}(X^n) \approx 862{,}496\ \text{bits}.

The extractor penalty is

2log⁡212εext=2log⁡2(239)=78.2\log_2\frac{1}{2\varepsilon_{\mathrm{ext}}} =2\log_2(2^{39})=78.

Thus ℓ≤862,418\ell\leq862{,}418 bits under these deliberately simplified premises. In a real source, estimating the bias and proving independence would add finite penalties.

A homodyne receiver is digitized at 1 GS/s1\ \mathrm{GS/s} but has effective noise bandwidth 100 MHz100\ \mathrm{MHz}. Explain why assigning one independent entropy contribution to every ADC sample is unjustified, and name two valid routes to a block entropy bound.

Solution

The analog filter and detector response spread one fluctuation over several samples, creating temporal correlation. A one-sample distribution does not determine Hmin⁡(Xn∣E)H_{\min}(X^n\mid E). One may use a validated stationary spectral or dynamical model that bounds the conditional entropy rate, or analyze empirical blocks with a theorem that permits the observed memory. Conservative downsampling can support either model, but merely selecting every tenth sample does not prove independence.

Why may the seed of a strong seeded extractor be published, while a Bell-test measurement setting still has to be unpredictable to the boxes at measurement time?

Solution

Strong-extractor security explicitly compares the joint state of output, seed, and side information with τZ⊗ρSEC\tau_Z\otimes\rho_{SEC}, so disclosure after choosing an independent seed is covered by the theorem. Bell certification instead uses the absence of a prearranged correlation between current settings and device behavior. If a box knows the setting before responding, a local deterministic strategy can imitate the selected correlations. The two random variables enter different causal positions in the proofs.

Use the displayed single-round bound to estimate the certified min-entropy of one party’s output at S=2.5S=2.5. Check the local and Tsirelson limits.

Solution

At S=2.5S=2.5,

pguess≤12(1+2−2.524)≈0.83072,\begin{aligned} p_{\mathrm{guess}} &\leq \frac12\left(1+\sqrt{2-\frac{2.5^2}{4}}\right)\\ &\approx0.83072, \end{aligned}

so

Hmin⁡(A∣E,x)≳−log⁡2(0.83072)≈0.267 bits.H_{\min}(A\mid E,x) \gtrsim -\log_2(0.83072) \approx0.267\ \text{bits}.

At S=2S=2, the bound gives pguess=1p_{\mathrm{guess}}=1 and zero entropy. At S=22S=2\sqrt2, it gives pguess=1/2p_{\mathrm{guess}}=1/2 and one bit. A finite experiment must replace the observed score by a confidence-adjusted score and include the sequential finite-size penalty.

Classify each task: (a) 1,000 ideal seed bits lead to 10,000 certified bits; (b) highly biased Santha–Vazirani inputs lead to nearly uniform outputs; (c) a Toeplitz hash compresses a trusted raw block with known min-entropy.

Solution

(a) is randomness expansion if all fresh seed use is counted and the net output is positive. (b) is randomness amplification because the quality assumption on the initial source is weakened. (c) is randomness extraction: it converts already certified entropy into nearly uniform bits and does not generate or amplify the physical entropy premise.

A vacuum QRNG monitors ADC saturation, optical local-oscillator power, and a repetition-count test. For each alarm, state what should happen to the current block and what evidence is needed before restart.

Solution

Any threshold crossing that violates the entropy model should suppress release and quarantine the full block whose certification may depend on the affected samples. Saturation requires confirming ADC range, gain, and signal statistics; an optical-power alarm requires restoring and recalibrating the local oscillator and detector operating point; a repetition alarm requires diagnosing source, clock, data-path, and buffering faults rather than simply clearing the flag. Restart should follow a documented startup test and create an authenticated fault record. The exact affected interval and thresholds must be fixed by the model, not chosen after inspecting whether the output looked acceptable.

  1. X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, “Quantum random number generation,” npj Quantum Information 2, 16021 (2016), doi:10.1038/npjqi.2016.21.
  2. M. Herrero-Collantes and J. C. Garcia-Escartin, “Quantum random number generators,” Reviews of Modern Physics 89, 015004 (2017), doi:10.1103/RevModPhys.89.015004.
  3. C. Gabriel et al., “A generator for unique quantum random numbers based on vacuum states,” Nature Photonics 4, 711–715 (2010), doi:10.1038/nphoton.2010.197.
  4. M. Avesani, D. G. Marangon, G. Vallone, and P. Villoresi, “Source-device-independent heterodyne-based quantum random number generator at 17 Gbps,” Nature Communications 9, 5365 (2018), doi:10.1038/s41467-018-07585-0.
  5. X. Lin et al., “Security analysis and improvement of source independent quantum random number generators with imperfect devices,” npj Quantum Information 6, 100 (2020), doi:10.1038/s41534-020-00331-9.
  6. A. Acín and L. Masanes, “Certified randomness in quantum physics,” Nature 540, 213–219 (2016), doi:10.1038/nature20119.
  7. S. Pironio et al., “Random numbers certified by Bell’s theorem,” Nature 464, 1021–1024 (2010), doi:10.1038/nature09008.
  8. M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, “Leftover hashing against quantum side information,” IEEE Transactions on Information Theory 57, 5524–5535 (2011), doi:10.1109/TIT.2011.2158473.
  9. A. De, C. Portmann, T. Vidick, and R. Renner, “Trevisan’s extractor in the presence of quantum side information,” SIAM Journal on Computing 41, 915–940 (2012), doi:10.1137/100813683.
  10. C. A. Miller and Y. Shi, “Universal security for randomness expansion from the spot-checking protocol,” SIAM Journal on Computing 46, 1304–1335 (2017), doi:10.1137/15M1044333.
  11. F. Dupuis, O. Fawzi, and R. Renner, “Entropy accumulation,” Communications in Mathematical Physics 379, 867–913 (2020), doi:10.1007/s00220-020-03839-5.
  12. R. Arnon-Friedman, R. Renner, and T. Vidick, “Simple and tight device-independent security proofs,” SIAM Journal on Computing 48, 181–225 (2019), doi:10.1137/18M1174726.
  13. Y. Liu et al., “Device-independent quantum random-number generation,” Nature 562, 548–551 (2018), doi:10.1038/s41586-018-0559-3.
  14. P. Bierhorst et al., “Experimentally generated randomness certified by the impossibility of superluminal signals,” Nature 556, 223–226 (2018), doi:10.1038/s41586-018-0019-0.
  15. Y. Zhang et al., “Experimental low-latency device-independent quantum randomness,” Physical Review Letters 124, 010505 (2020), doi:10.1103/PhysRevLett.124.010505.
  16. W.-Z. Liu et al., “Device-independent randomness expansion against quantum side information,” Nature Physics 17, 448–451 (2021), doi:10.1038/s41567-020-01147-2.
  17. Y. Zhang et al., “One-sided device-independent random number generation through fiber channels,” Light: Science & Applications 14, 25 (2025), doi:10.1038/s41377-024-01641-9.
  18. R. Colbeck and R. Renner, “Free randomness can be amplified,” Nature Physics 8, 450–453 (2012), doi:10.1038/nphys2300.
  19. R. Gallego et al., “Full randomness from arbitrarily deterministic events,” Nature Communications 4, 2654 (2013), doi:10.1038/ncomms3654.
  20. A. Kulikov et al., “Experimental randomness amplification,” Nature 653, 1033–1038 (2026), doi:10.1038/s41586-026-10521-8.
  21. M. Farkas et al., “Maximal device-independent randomness in every dimension,” Nature Physics 22, 319–324 (2026), doi:10.1038/s41567-025-03141-y.
  22. NIST, Recommendation for the Entropy Sources Used for Random Bit Generation, SP 800-90B (2018; errata noted 2025), doi:10.6028/NIST.SP.800-90B.
  23. NIST, Recommendation for Random Bit Generator (RBG) Constructions, SP 800-90C (2025), doi:10.6028/NIST.SP.800-90C.
  24. E. Barker et al., Bridging the Gap Between Standards on Random Number Generation: Comparison of SP 800-90 Series and AIS 20/31, NIST IR 8446 (2026), doi:10.6028/NIST.IR.8446.
  25. ISO/IEC, ISO/IEC 20543:2019: Test and Analysis Methods for Random Bit Generators within ISO/IEC 19790 and ISO/IEC 15408 (2019; confirmed 2025), standard record.
  26. ETSI, Implementation Guidelines for Quantum Random Number Generators, TR 104 171 V1.1.1 (2026), official work item.
  27. NIST, A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications, SP 800-22 Rev. 1a (2010; revision decision 2022), doi:10.6028/NIST.SP.800-22r1a.