Qrng

last updated 2026-08-31 · +1 sources in last 30d

Physics / mechanism

A quantum random number generator (QRNG) extracts unpredictable bits from the intrinsic indeterminism of a quantum measurement rather than from a deterministic algorithm or a classical noise source. Two device families dominate the sources here. The discrete-variable route uses single photons in an interferometric network, where the which-path outcome is fundamentally random; the continuous-variable route performs homodyne measurement on the vacuum state and digitises the resulting quadrature fluctuations.

The output metric that matters is not raw bit rate but certified conditional min-entropy: the number of bits per round that remain unpredictable to an adversary who may partially control the device. Semi-device-independent QRNGs certify this from an observed violation of a non-classical inequality, so the security claim rests on measured statistics plus a small set of assumptions rather than on a full physical model of the hardware. An on-chip implementation integrating two silicon photonic chips, combining a heralded single-photon source with a reconfigurable interferometric mesh to prepare, transform and measure qutrit states, tested a KCBS contextuality inequality and reported a violation exceeding the classical bound by more than 10σ, from which a conditional min-entropy of H_min = 0.077 ± 0.002 per round was certified via a semidefinite-programming-based analysis. Contextuality-based certification requires no entanglement, which relaxes the hardware burden relative to loophole-free Bell-test approaches.

Raw quantum-derived bits are not uniform, so a randomness extractor is applied. Universal hash functions act as strong seeded extractors, with security bounded by the Quantum Leftover Hash Lemma. This creates the “randomness loop”: a seeded extractor needs an initial random seed in order to produce randomness. One proposed resolution bootstraps from the raw data of two independent seedless QRNG entropy sources, and the same extractor machinery is proposed as an alternative to XOR-based combining of post-quantum cryptography and QKD keys.

Throughput after certification and extraction is severely reduced relative to raw acquisition. In a satellite-based CV-QRNG demonstration using the continuous-variable payload of the SPOQC mission, a raw key of roughly 1 Mb per satellite pass yielded approximately 19.5 kb of certified random numbers from a 12-bit ADC, with output validated against the NIST test suite and a formal upper bound placed on the min-entropy.

Competitive landscape

ApproachEntropy sourceCertificationReported figure
Semi-DI contextuality, integrated photonicsHeralded single photons in a reconfigurable meshKCBS inequality violation, SDP-derived bound>10σ violation; H_min = 0.077 ± 0.002 per round
CV homodyne (vacuum fluctuations)Vacuum-state quadrature noise, laser + homodyne detectorMin-entropy upper bound plus NIST suite~19.5 kb certified from ~1 Mb raw per satellite pass, 12-bit ADC

The trade-off is between assumption strength and rate. The contextuality device buys a device-independence-flavoured security claim without entanglement, at the cost of a low certified entropy yield per round. The CV homodyne route reuses hardware already present for other functions, since the SPOQC payload laser also serves the QRNG and the homodyne detector could double as the receiver in an uplink scenario, favouring it where space, mass and power are constrained. Both then depend on the same downstream extractor and seeding question. Single-photon detector supply is a relevant upstream dependency for the discrete-variable route; market scanning identifies STMicroelectronics as the leading SPAD player on CMOS-integrated SPAD and vertically integrated manufacturing, with Sony Semiconductor Solutions and Hamamatsu Photonics in second tier.

Evidence base

Frontier (open questions)

Synthesised 2026-08-31 from 5 KB sources by the resynth pipeline; citations are KB source slugs.

Recent mentions

Frontier questions