Pith. sign in

REVIEW 2 major objections 5 minor 82 references

Self-testing quantum randomness expansion on an integrated photonic chip

T0 review · 2 major / 5 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read A silicon photonic chip with fully integrated encoder and decoder self-tests its quantum randomness, certifying 15.33 Mbits of fresh output per run despite an untrusted homodyne detector.

desk verdict First integrated-chip MDI-QRNG with homodyne self-testing; chip work is real, but security claim needs clearer accounting of PRG inputs and extrapolated bit count. read the letter →

arxiv 2411.13712 v1 pith:YTMCARGW submitted 2024-11-20 quant-ph

classification quant-ph MSC 81P4581P68 PACS 03.67.-a
keywords self-testingquantumrandomnumbergeneratormeasurement-device-independentsiliconphotonicchiphomodynedetectioncontinuous-variableinformationrandomnessexpansionentropyaccumulationtheoremQPSKcoherentstates
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper aims to show that self-testing quantum randomness expansion can be put on a fully integrated silicon photonic chip operating at room temperature. The chip produces random numbers whose security is certified in real time by the measured score distribution, with the homodyne detector treated as untrusted while the state source remains trusted. In a proof-of-principle run with $3\times10^{10}$ rounds at 10 MHz repetition rate it generated 15.33 Mbits of certified fresh randomness per run, an expansion rate of $5.11\times10^{-4}$. The significance is practical: if the protocol and chip design are sound, certified randomness with detector self-testing can be mass-produced on standard foundry processes, replacing trusted-detector models in small-footprint devices.

What carries the argument

The carrying object is a prepare-and-measure game $G$: Alice prepares one of four coherent states $|\sqrt{\mu}e^{ix\pi/2}\rangle$ with $x\in\{0,1,2,3\}$, Bob measures with an untrusted homodyne detector in one of two settings (local-oscillator phase 0 or $\pi/2$), and the continuous outcome is binned into $2m$ bins and assigned a score $c$ by Eq. (1). Security flows from the min-tradeoff function $f_\nu$: a semidefinite-programming-derived upper bound on the single-round guessing probability compatible with the observed score distribution, which the entropy accumulation theorem converts into a lower bound on the total smooth min-entropy of the raw string against the adversary's quantum side information. On the hardware side, the phase-loss independence machinery does the load-bearing work: an IQ modulator driven at $\pm0.1$ V avoids phase-dependent loss in encoding, and a push-push Mach-Zehnder modulator at an optimum ratio $r\approx0.6$ makes the basis-selection phase shift loss-free, preserving the 69.1% total homodyne efficiency that keeps the rate positive.

What would settle it

Run the protocol with the trusted input source replaced by a publicly known seed and with a detector engineered to reproduce the accepted score frequencies; if the extractor output can be predicted from that seed, the certified-randomness claim is false.

Watch

Extended reading notes

Core claim

The central discovery claim is that a measurement-device-independent QRNG protocol using four QPSK coherent states and an untrusted homodyne receiver can certify randomness expansion on a chip: the protocol accepts only when empirical score frequencies fall within a tolerance of the ideal distribution, and the entropy accumulation theorem then lower-bounds the smooth min-entropy of the raw string against quantum side information. The experiment integrates the encoder and decoder on silicon: an IQ modulator encodes the four states, a push-push Mach-Zehnder modulator selects the measurement basis without phase-dependent loss, and an on-chip balanced homodyne detector with total efficiency 69.1% measures the $X$ or $P$ quadrature, binned into 6 or 2 outcomes. Running $n=3\times10^{10}$ rounds with state amplitude $\sqrt{\mu}=0.0672$ and test probability $\gamma=0.12$, the measured score distribution passed, yielding 15.33 Mbits of certifiable randomness at expansion rate $5.11\times10^{-4}$ at 10 MHz repetition. The authors claim this is the first self-testing QRNG chip with a fully integrated encoder and decoder operating at room temperature.

Load-bearing premise

The proof's soundness rests on the assumption that every protocol input is drawn from a private, trusted, i.i.d. random source uncorrelated with the adversary, whereas the demonstration generates inputs from a pseudorandom 100-bit seed.

Editorial extensions

If this is right

  • A fully integrated, room-temperature self-testing QRNG is manufacturable on standard silicon photonics foundry platforms, with only the laser remaining off-chip.
  • Operators can certify detector integrity during operation from the score distribution alone, without a trusted characterisation of the homodyne detector.
  • The protocol remains positive-rate down to homodyne efficiencies near 67 percent, matching the loss and noise budget of integrated photonics.
  • With upgraded components (92.4 percent photodiode quantum efficiency at 1550 nm), the simulated expansion rate improves by roughly two orders of magnitude.
  • The bandwidth of the integrated modulators and detectors supports clock rates far above the 10 MHz used here, so the per-run output can scale substantially.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Editorial inference: in the proof-of-principle run, the trusted-input assumption is not met, because the 100-bit pseudorandom seed is not a private physical source; a deployable version needs a hardware random source for inputs before the certified numbers can be claimed.
  • Editorial inference: the self-testing guarantee covers only the measurement device and channel; the state-preparation unit and the classical post-processing remain trusted, so the result is semi-device-independent rather than fully device-independent.
  • Editorial inference: since the protocol recycles input randomness by hashing and assumes inputs never leak, an input-side side channel would silently destroy the expansion; the input source isolation is as essential as the score test.
  • Editorial inference: the same score-certified homodyne approach could be adapted to other continuous-variable tasks needing an untrusted receiver, such as measurement-device-independent quantum key distribution with trusted transmitters, but this paper does not analyse that extension.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 5 minor

Summary. The paper develops a semi-device-independent, measurement-device-independent QRNG protocol using QPSK coherent states and an untrusted homodyne detector, with the score distribution monitored via fine-grained binning. Security is analyzed with the entropy accumulation theorem and a min-tradeoff function, and the protocol is implemented on a silicon photonic chip with integrated IQ modulator, phase modulator, tunable beam splitter, and balanced homodyne detector. The authors claim a net randomness expansion rate of 5.11e-4 at 10 MHz, corresponding to 15.33 Mbits of certifiable randomness per run for n=3e10 rounds, and report a total homodyne efficiency of 69.1%.

Significance. If fully supported, this would be an important advance: it combines a room-temperature, fully integrated silicon photonic platform with a self-testing protocol that does not require a characterized detector, and it shows tolerance to detection efficiencies down to about 67%. The chip-engineering achievements are substantial and well documented: the phase-loss-compensated modulators, the >65 dB common-mode rejection, and the careful efficiency accounting are credible and useful contributions. However, the headline claim of certified randomness expansion is not currently established because the experimental input generation violates a central assumption of the security proof, and the security analysis is not self-contained because the min-tradeoff function is borrowed from Ref. [18] without its SDP construction or dual certificates. The protocol and chip are nevertheless a valuable proof-of-principle that could be made rigorous with additional work.

major comments (2)
  1. [Sec. VI and Methods VIII A, Assumption 4 and Eq. (20)] The soundness proof assumes that the protocol inputs T, X, Y are drawn from a private, trusted, i.i.d. random source independent of the adversary, and Eq. (20) credits these inputs with n[h2(gamma)+2gamma] bits of entropy. For the stated parameters (n=3e10, gamma=0.12), this is about 2.3e10 bits per run. Section VI states that the experiment uses a 100-bit pseudorandom input. A pseudorandom expansion of a 100-bit seed cannot supply this entropy, and the PRG output is deterministic given the seed, so it is not i.i.d. and not independent of the adversary in the sense required by Assumption 4. Consequently, the QAEP and EAT steps in Eqs. (16)-(23) do not apply to the demonstrated data, and the claimed 15.33 Mbits of certifiable randomness is not established. To support the claim, the experiment must use a trusted physical randomness source for all protocol inputs (with its entropy explicitly accounted), or the manuscript must clearly restrict the demonstration to a proof-of-principle device characterization and remove or qualify the certified-expansion claim.
  2. [Methods VIII A, Eqs. (23)-(26)] The security bound depends on the min-tradeoff function through the constants alpha_nu and lambda_nu, obtained, according to the text, by taking the dual of the SDP in Eq. (21) and following the derivation of Theorem 1 in Ref. [18]. The manuscript does not provide the SDP construction, the affine bounds, the numerical values of alpha_nu and lambda_nu for the six-bin configuration, or the dual certificates used to enforce Eq. (22). Since these constants enter h, V, and K in Eqs. (24)-(26), the reported rates cannot be independently verified from this paper. Please include the full SDP formulation and the numerical constants, or supply supplementary code that generates them.
minor comments (5)
  1. [Sec. VI] Please specify the pseudorandom generator algorithm and the source of its 100-bit seed, and state explicitly whether the seed is assumed secret and trusted. As written, the description is insufficient to assess any security argument.
  2. [Table I and Eq. (15)] The listed parameters are inconsistent: with epsilon_ext = 1e-6 and epsilon_s = 4.99e-7, Eq. (15) gives epsilon_sou = 2epsilon_s + epsilon_ext = 1.998e-6, not the listed 1e-6. Please reconcile the soundness parameter or the smoothing parameter.
  3. [Throughout] There are several typographical errors, including 'particulary' in the Introduction, 'Mazh-Zehnder' in Section I, 'Homodyme' in the Discussion, 'Lecory' in Section VIII B, and 'randomeness' in the Author Contributions section.
  4. [Fig. 1(b)] The score-assignment table in Fig. 1(b) is difficult to read at the printed size; larger fonts and clearer separation between the X and P score blocks would improve readability.
  5. [Introduction] The claim of being the 'first self-testing QRNG chip with a fully integrated encoder and decoder' should be carefully qualified relative to previous chip-based self-testing demonstrations, such as Refs. [24] and [35], to make the precise novelty clear.

Circularity Check

1 steps flagged · score 4.0 of 10

The chip experiment is independently meaningful, but the certified-bit-count security bound is imported from the authors' own Ref. [18]; the 100-bit PRG input also violates the proof's trusted-i.i.d.-seed assumption.

  1. self citation load bearing [Methods VIII A, text before Eq. (23)]
    "Following the derivation of Theorem 1 presented in Ref. [18], EAT implies that the conditional smooth min-entropy H ϵ1 min(B|TXY, E)ρ|Ω is given by"

    The headline certified-randomness amount is set by h in Eq. (24) through Eq. (37), and that h is not derived in this paper. It is imported from 'the derivation of Theorem 1 presented in Ref. [18]', the same authors' earlier uncharacterised-homodyne QRNG work. The SDP constants αν and λν that determine h are cited to [18,67,68] without providing dual certificates, and the Markov-chain condition required for EAT is asserted by the same prior-experiment citation. Thus the load-bearing step of the security proof reduces to a self-citation chain: if Theorem 1 of Ref. [18] were invalid or inapplicable to the 6-bin scoring rule, this manuscript alone would not establish Eq. (23) or the 15.33 Mbit certified output.

full rationale

No circular reduction by construction is present in the experimental derivation chain. The score acceptance rule Eq. (3), the chain rule Eq. (16), the QAEP bound Eq. (17), the leftover-hash bound Eq. (13), and the EAT structure are standard external tools, and the final 5.11e-4 rate is a certified lower bound conditional on the observed score distribution, not a refit of the output. The main circularity-adjacent concern is the load-bearing self-citation to Ref. [18] for the min-tradeoff function and the SDP constants, which warrants the moderate score. Separately, Section VI states that the input generation step 'uses a pseudorandom input with a length of 100', whereas Assumption 4 and Eq. (20) require a private, trusted, i.i.d. seed providing n[h2(γ)+2γ] bits; this is a serious soundness gap for the data as taken, but it is an assumptions-versus-implementation mismatch rather than a circular derivation, so it does not by itself raise the circularity score. The central experimental result—an integrated silicon-photonic homodyne QRNG chip with 69.1% efficiency—remains independently meaningful.

Assumptions & free parameters 5 free parameters · 8 assumptions · 0 invented entities

The central claim rests on a standard MDI-QRNG security model: trusted source, untrusted detector, secure isolation, private random inputs, and no adversarial update during the run. The main non-standard ingredient is the SDP-based min-tradeoff function, which is taken from the authors' prior work rather than derived in this paper. The only hand-tuned numbers are the optimization parameters (amplitude, test probability, bin count, tolerances) and the MZM working ratio.

free parameters (5)
  • State amplitude sqrt(mu) = 0.0672
    Optimized to maximize rnet at homodyne efficiency 69.1 percent; experimentally set with tolerance +/-0.0022 (Sec. VI, Table I).
  • Test probability gamma = 0.12
    Optimized in simulation; the authors used a slightly lower value than the optimum to widen the tolerated score range delta (Sec. VI, Fig. 4c).
  • Tolerated score deviations delta_c = 1.55e-5 to 3.60e-5 per score
    Chosen per score to keep completeness error below 1e-3; values listed in Table II.
  • Number of discretization bins = 6 (X quadrature), 2 (P quadrature)
    Protocol choice trading rate against complexity; simulations show higher bins improve loss tolerance (Sec. VI, Fig. 4a).
  • Push-push MZM working ratio r = 0.6
    Design parameter chosen so the pi/2 phase range has no phase-dependent loss and minimum insertion loss (Sec. IV).
assumptions (8)
  • domain assumption Quantum theory is correct.
    Explicitly stated in Methods Sec. VIII A, assumption 1.
  • domain assumption The device has a trusted, characterised source and an uncharacterised measurement device.
    Assumption 2 in Methods Sec. VIII A; the whole MDI security model depends on this.
  • domain assumption The device is in a secure location and isolated, with only pre-shared correlation with the adversary.
    Assumption 3 in Methods Sec. VIII A and Sec. II.
  • domain assumption Protocol inputs are generated by a private, trusted, i.i.d. random source uncorrelated with the adversary and the devices.
    Assumption 4 in Methods Sec. VIII A; used for QAEP and input entropy accounting. The experiment uses a pseudorandom seed instead.
  • domain assumption The adversary does not update her quantum side information during the protocol.
    Stated in Sec. II; needed for the EAT Markov condition.
  • domain assumption The EAT Markov chain condition holds for the inputs and outputs.
    Justified by 'the same argument as our previous experiment [18]' (Methods Sec. VIII A).
  • domain assumption Honest behaviour is a homodyne measurement with known efficiency, used for the completeness test.
    Methods Sec. VIII A, completeness proof; needs the device's honest score distribution to set tolerances.
  • ad hoc to paper The min-tradeoff function from Ref. [18] extends to this multi-bin QPSK protocol and can be constructed by SDP.
    The soundness proof invokes Theorem 1 of Ref. [18] without providing the SDP dual solution for the specific scoring rule (Methods Sec. VIII A, Eqs. 21-23).

how reviews work

0 comments
Cite this review

Pith. "Pith review of Self-testing quantum randomness expansion on an integrated photonic chip." pith.science (2026). https://pith.science/paper/YTMCARGW

@misc{pith2026241113712,
  author       = {Pith},
  title        = {Pith review of: Self-testing quantum randomness expansion on an integrated photonic chip},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YTMCARGW}},
  note         = {Machine review of arXiv:2411.13712}
}
abstract

The power of quantum random number generation is more than just the ability to create truly random numbers$\unicode{x2013}$it can also enable self-testing, which allows the user to verify the implementation integrity of certain critical quantum components with minimal assumptions. In this work, we develop and implement a self-testing quantum random number generator (QRNG) chipset capable of generating 15.33 Mbits of certifiable randomness in each run (an expansion rate of $5.11\times 10^{-4}$ at a repetition rate of 10 Mhz). The chip design is based on a highly loss-and-noise tolerant measurement-device-independent protocol, where random coherent states encoded using quadrature phase shift keying are used to self-test the quantum homodyne detection unit: well-known to be challenging to characterise in practice. Importantly, this proposal opens up the possibility to implement miniaturised self-testing QRNG devices at production scale using standard silicon photonics foundry platforms.

Figures

Figures reproduced from arXiv: 2411.13712 by the authors.

Figure 1
Figure 1. FIG. 1. Overview of the self-testing quantum randomness expansion chip. (a) Schematic of the encoding and decoding scheme. [PITH_FULL_IMAGE:figures/full_fig_p004_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2. Modulator phase-loss dependency analysis. (a) [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3. Homodyne detector performance. (a,b) Current [PITH_FULL_IMAGE:figures/full_fig_p006_3.png] view at source ↗
Figures from the paper (1 more)
Figure 4
Figure 4. Figure 4: FIG. 4. Quantum randomness expansion rate simulation. (a) [PITH_FULL_IMAGE:figures/full_fig_p007_4.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

82 extracted references · 63 canonical work pages

  1. [18]

    C. Wang, I. W. Primaatmaja, H. J. Ng, J. Y. Haw, R. Ho, J. Zhang, G. Zhang, and C. Lim, Provably-secure quan- tum randomness expansion with uncharacterised homo- dyne detection, Nature Communications 14, 316 (2023)

  2. [1]

    For each round i ∈ [n], the round is randomly chosen between test round (Ti = 1) and generation round ( Ti = 0) with test probability γ and key probability 1 − γ

    Input generation. For each round i ∈ [n], the round is randomly chosen between test round (Ti = 1) and generation round ( Ti = 0) with test probability γ and key probability 1 − γ. In each test round, the encoder, named Alice, selects her input as Xi ∈ X = {0, 1, 2, 3}, with an equal probability of 0.25 for each input. The receiver, named Bob, selects his...

  3. [2]

    Quantum state preparation. Alice prepares trusted quantum states |ψXi ⟩ ∈ {|√µeixπ/2⟩ : x ∈ X }in the form of quadrature phase-shift keying (QPSK) with fixed intensity µ based on her input Xi, as shown in Fig. 1a

  4. [3]

    Bob measures the states prepared by Alice using an untrusted homo- dyne detector with his setting Yi ∈ {0, 1}, which corresponds to the local oscillator phase of 0 and π/2

    Quantum state measurement. Bob measures the states prepared by Alice using an untrusted homo- dyne detector with his setting Yi ∈ {0, 1}, which corresponds to the local oscillator phase of 0 and π/2. The continuous output is discretized into 2 m bins B = {±1, ±2, ...,±m} by dividing a finite in- terval (−L, L) into equal (2m−2) intervals, and the discreti...

  5. [4]

    For all generation rounds (Ti = 0), we set Ci =⊥

    Parameter estimation. For all generation rounds (Ti = 0), we set Ci =⊥. On the other hand, for the test rounds ( Ti = 1), the scores Ci = c are 3 determined based on the following scoring rule, c =    +bX , (X = 0, B= +b or X = 1, B= −b) −bX , (X = 0, B= −b or X = 1, B= +b) +bP , (X = 2, B= +b or X = 3, B= −b) −bP , (X = 2, B= −b or X = 3, B= +b)...

  6. [5]

    Our raw random string is formed by concatenating R = ( B, T, X, Y)

    Randomness extraction. Our raw random string is formed by concatenating R = ( B, T, X, Y). A quantum-proof strong extractor Ext with some uniformly random seed S is applied to the raw random string and outputs a ℓ-bit string Z = Ext(R, S). The protocol finally outputs the con- catenated string K = (Z, S). Note that our randomness certification does not as...

  7. [6]

    Liu and D

    Y.-K. Liu and D. Moody, Post-quantum cryptography and the quantum future of cybersecurity, Physical Re- view Applied 21, 040501 (2024)

  8. [7]

    Soundness Let Ω be the event in which the protocol is not aborted (i.e., it successfully produces a random out- put) and let Pr[Ω] denotes the probability that this event occurs. For a given εsou ∈ (0, 1), a randomness generation protocol is said to be εsou-sound if the output K and the adversary’s quantum side information E satisfies Pr[Ω] · 1 2 ρKE|Ω − ...

Show all 82 references
  1. [8]

    A randomness genera- tion protocol is said to be εcom-complete if Pr[Ω]honest ≥ 1 − εcom

    Completeness Let εcom ∈ (0, 1) be given. A randomness genera- tion protocol is said to be εcom-complete if Pr[Ω]honest ≥ 1 − εcom. (6) Here, the subscript “honest” indicates that the probability of the protocol not being aborted is evaluated assuming that the device behaves ho...

  2. [9]

    Quantum theory is correct

  3. [10]

    The device consist of a trusted and characterised source of quantum states (which we personify as Alice), an uncharacterised measurement device (which we personify as Bob) and a trusted clas- sical processing unit which supplies random in- puts, stores measurement outcomes and...

  4. [11]

    We allow the device to share some correlation (which can be classical or quantum) with the adversary prior to the protocol execution

    The device is located in a secure location and is sufficiently isolated from the environment during the execution of the protocol. We allow the device to share some correlation (which can be classical or quantum) with the adversary prior to the protocol execution

  5. [12]

    The proof for the protocol’s completeness is consid- erably more straightforward

    The device is equipped with some trusted random seed that is uncorrelated to the adversary’s side information, nor to the devices (i.e., the source and the measurement device) themselves. The proof for the protocol’s completeness is consid- erably more straightforward. When th...

  6. [13]

    Rukhin, J

    A. Rukhin, J. Soto, J. Nechvatal, M. Smid, E. Barker, S. Leigh, M. Levenson, M. Vangel, D. Banks, N. Hecker, J. Dray, S. Vo, and L. Bassham, A statistical test suite for random and pseudorandom number generators for cryptographic applications, Tech. Rep. Special Publica- tion ...

  7. [14]

    Stipˇ cevi´ c and C ¸

    M. Stipˇ cevi´ c and C ¸ . K. Ko¸ c, True random number gen- erators, in Open Problems in Mathematics and Compu- tational Science, edited by C ¸ . K. Ko¸ c (Springer Interna- tional Publishing, Cham, 2014) pp. 275–315

  8. [15]

    Y. Yao, X. Chen, W. Kang, Y. Zhang, and W. Zhao, Thermal brownian motion of skyrmion for true random number generation, IEEE Transactions on Electron De- vices 67, 2553 (2020)

  9. [16]

    Herrero-Collantes and J

    M. Herrero-Collantes and J. C. Garcia-Escartin, Quan- tum random number generators, Reviews of Modern Physics 89, 015004 (2017)

  10. [17]

    X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, Quantum random number generation, npj Quantum Information 2, 1 (2016)

  11. [19]

    Mayers and A

    D. Mayers and A. Yao, Self testing quantum apparatus, Quantum Info. Comput. 4, 273–286 (2004)

  12. [20]

    Ac ´ ın and L

    A. Ac ´ ın and L. Masanes, Certified randomness in quan- tum physics, Nature 540, 213 (2016)

  13. [21]

    Pironio, A

    S. Pironio, A. Ac ´ ın, S. Massar, A. B. de La Giroday, D. N. Matsukevich, P. Maunz, S. Olmschenk, D. Hayes, L. Luo, T. A. Manning, et al., Random numbers certified by bell’s theorem, Nature 464, 1021 (2010)

  14. [22]

    Liu, M.-H

    W.-Z. Liu, M.-H. Li, S. Ragy, S.-R. Zhao, B. Bai, Y. Liu, P. J. Brown, J. Zhang, R. Colbeck, J. Fan, et al., Device- independent randomness expansion against quantum side information, Nature Physics 17, 448 (2021)

  15. [23]

    L. K. Shalm, Y. Zhang, J. C. Bienfang, C. Schlager, M. J. Stevens, M. D. Mazurek, C. Abell´ an, W. Amaya, M. W. Mitchell, M. A. Alhejji, et al., Device-independent randomness expansion with entangled photons, Nature Physics 17, 452 (2021)

  16. [24]

    D.-L. Deng, C. Zu, X.-Y. Chang, P.-Y. Hou, H.-X. Yang, Y.-X. Wang, and L.-M. Duan, Exploring quantum contextuality to generate true random numbers, arXiv preprint arXiv:1301.5364 (2013)

  17. [25]

    V. C. Vivoli, P. Sekatski, J.-D. Bancal, C. C. W. Lim, A. Martin, R. T. Thew, H. Zbinden, N. Gisin, and N. Sangouard, Comparing different approaches for gen- erating random numbers device-independently using a photon pair source, New Journal of Physics 17, 023023 (2015)

  18. [26]

    D. G. Marangon, G. Vallone, and P. Villoresi, Source- device-independent ultrafast quantum random number generation, Physical review letters 118, 060503 (2017)

  19. [27]

    Z. Cao, H. Zhou, X. Yuan, and X. Ma, Source- independent quantum random number generation, Phys- ical Review X 6, 011020 (2016)

  20. [28]

    Avesani, D

    M. Avesani, D. G. Marangon, G. Vallone, and P. Villoresi, Source-device-independent heterodyne- based quantum random number generator at 17 gbps, Nature communications 9, 5365 (2018)

  21. [29]

    Zhang, R

    J.-N. Zhang, R. Yang, X. Li, C.-W. Sun, Y.-C. Liu, Y. Wei, J.-C. Duan, Z. Xie, Y.-X. Gong, and S.-N. Zhu, Realization of a source-device-independent quantum ran- dom number generator secured by nonlocal dispersion cancellation, Advanced Photonics 5, 036003 (2023)

  22. [30]

    Stanco, D

    A. Stanco, D. G. Marangon, G. Vallone, S. Burri, E. Charbon, and P. Villoresi, Efficient random number generation techniques for cmos single-photon avalanche diode array exploiting fast time tagging units, Physical Review Research 2, 023287 (2020)

  23. [31]

    Nie, J.-Y

    Y.-Q. Nie, J.-Y. Guan, H. Zhou, Q. Zhang, X. Ma, J. Zhang, and J.-W. Pan, Experimental measurement- device-independent quantum random-number genera- tion, Physical Review A 94, 060301 (2016)

  24. [32]

    Z. Cao, H. Zhou, and X. Ma, Loss-tolerant measurement- device-independent quantum random number genera- tion, New Journal of Physics 17, 125011 (2015)

  25. [33]

    J. B. Brask, A. Martin, W. Esposito, R. Houlmann, J. Bowles, H. Zbinden, and N. Brunner, Megahertz- rate semi-device-independent quantum random number generators based on unambiguous state discrimination, Physical Review Applied 7, 054018 (2017)

  26. [34]

    Lunghi, J

    T. Lunghi, J. B. Brask, C. C. W. Lim, Q. Lavigne, J. Bowles, A. Martin, H. Zbinden, and N. Brunner, Self- testing quantum random number generator, Physical re- view letters 114, 150501 (2015)

  27. [35]

    Zhang, H.-P

    Y. Zhang, H.-P. Lo, A. Mink, T. Ikuta, T. Honjo, H. Takesue, and W. J. Munro, A simple low-latency real- time certifiable quantum random number generator, Na- ture communications 12, 1056 (2021)

  28. [36]

    Rusca, T

    D. Rusca, T. Van Himbeeck, A. Martin, J. B. Brask, W. Shi, S. Pironio, N. Brunner, and H. Zbinden, Self- testing quantum random-number generator based on an energy bound, Physical Review A 100, 062338 (2019)

  29. [37]

    Avesani, H

    M. Avesani, H. Tebyanian, P. Villoresi, and G. Val- lone, Semi-device-independent heterodyne-based quan- tum random-number generator, Physical Review Applied 15, 034034 (2021)

  30. [38]

    Bruynsteen, T

    C. Bruynsteen, T. Gehring, C. Lupo, J. Bauwelinck, and X. Yin, 100-gbit/s integrated quantum random number generator based on vacuum fluctuations, PRX Quantum 4, 010330 (2023)

  31. [39]

    B. Bai, J. Huang, G.-R. Qiao, Y.-Q. Nie, W. Tang, T. Chu, J. Zhang, and J.-W. Pan, 18.8 gbps real-time quantum random number generator with a photonic in- tegrated chip, Applied Physics Letters 118 (2021)

  32. [40]

    Zheng, Y

    Z. Zheng, Y. Zhang, W. Huang, S. Yu, and H. Guo, 6 gbps real-time optical quantum random number gener- ator based on vacuum fluctuation, Review of Scientific Instruments 90 (2019)

  33. [41]

    Jennewein, U

    T. Jennewein, U. Achleitner, G. Weihs, H. Weinfurter, and A. Zeilinger, A fast and compact quantum random number generator, Review of Scientific Instruments 71, 1675 (2000)

  34. [42]

    J. Wang, F. Sciarrino, A. Laing, and M. G. Thompson, Integrated photonic quantum technologies, Nature Pho- tonics 14, 273 (2020)

  35. [43]

    Zhang, C

    G. Zhang, C. Wang, K. T. Goh, S. Q. Ng, R. Ho, H. Semenenko, S. A. Srinivasan, H. Wang, Y. Chen, J. Y. Haw, et al., Single-photon path entanglement based on 14 integrated silicon photonics, in CLEO: Fundamental Sci- ence (Optica Publishing Group, 2023) pp. FM4E–7

  36. [44]

    Bertapelle, M

    T. Bertapelle, M. Avesani, A. Santamato, A. Monta- naro, M. Chiesa, D. Rotta, M. Artiglia, V. Sorianello, F. Testa, G. De Angelis, et al., High-speed source-device- independent quantum random number generator on a chip, arXiv preprint arXiv:2305.12472 (2023)

  37. [45]

    Kincaid, L

    P. Kincaid, L. De Marinis, A. Montanaro, A. Santamato, N. Andriolli, and G. Contestabile, Source device indepen- dent quantum random number generator with integrated inp photonics, in 2023 International Conference on Pho- tonics in Switching and Computing (PSC)(IEEE, 2023) pp. 1–3

  38. [46]

    Y. Du, X. Hua, Z. Zhao, X. Sun, Z. Zhang, X. Xiao, and K. Wei, Source-independent quantum random num- ber generators with integrated silicon photonics, arXiv preprint arXiv:2312.17011 (2023)

  39. [47]

    Leone, D

    N. Leone, D. Rusca, S. Azzini, G. Fontana, F. Acerbi, A. Gola, A. Tontini, N. Massari, H. Zbinden, and L. Pavesi, An optical chip for self-testing quantum ran- dom number generation, APL Photonics 5 (2020)

  40. [48]

    Haylock, D

    B. Haylock, D. Peace, F. Lenzini, C. Weedbrook, and M. Lobino, Multiplexed quantum random number gener- ation, Quantum 3, 141 (2019)

  41. [49]

    Abellan, W

    C. Abellan, W. Amaya, D. Domenech, P. Mu˜ noz, J. Cap- many, S. Longhi, M. W. Mitchell, and V. Pruneri, Quan- tum entropy source on an inp photonic integrated circuit for random number generation, Optica 3, 989 (2016)

  42. [50]

    Argillander, A

    J. Argillander, A. Alarc´ on, C. Bao, C. Kuang, G. Lima, F. Gao, and G. B. Xavier, Quantum random number gen- eration based on a perovskite light emitting diode, Com- munications Physics 6, 157 (2023)

  43. [51]

    Prokhodtsov, V

    A. Prokhodtsov, V. Kovalyuk, P. An, A. Go- likov, R. Shakhovoy, V. Sharoglazova, A. Udaltsov, Y. Kurochkin, and G. Goltsman, Silicon nitride mach- zehnder interferometer for on-chip quantum random number generation, in Journal of Physics: Conference Series, Vol. 1695 (IOP Publ...

  44. [52]

    Raffaelli, P

    F. Raffaelli, P. Sibson, J. E. Kennard, D. H. Mahler, M. G. Thompson, and J. C. Matthews, Generation of random numbers by measuring phase fluctuations from a laser diode with a silicon-on-insulator chip, Optics Ex- press 26, 19730 (2018)

  45. [53]

    A. H. Atabaki, S. Moazeni, F. Pavanello, H. Gevorgyan, J. Notaros, L. Alloatti, M. T. Wade, C. Sun, S. A. Kruger, H. Meng, et al., Integrating photonics with sil- icon nanoelectronics for the next generation of systems on a chip, Nature 556, 349 (2018)

  46. [54]

    I. W. Primaatmaja, K. T. Goh, E. Y.-Z. Tan, J. T.-F. Khoo, S. Ghorai, and C. C.-W. Lim, Security of device- independent quantum key distribution protocols: a re- view, Quantum 7, 932 (2023)

  47. [55]

    W. Luo, L. Cao, Y. Shi, L. Wan, H. Zhang, S. Li, G. Chen, Y. Li, S. Li, Y. Wang, et al., Recent progress in quantum photonic chips for quantum communication and internet, Light: Science & Applications 12, 175 (2023)

  48. [56]

    Zhang, L

    M. Zhang, L. Feng, M. Li, Y. Chen, L. Zhang, D. He, G. Guo, G. Guo, X. Ren, and D. Dai, Supercompact photonic quantum logic gate on a silicon chip, Physical Review Letters 126, 130501 (2021)

  49. [57]

    Vigliar, S

    C. Vigliar, S. Paesani, Y. Ding, J. C. Adcock, J. Wang, S. Morley-Short, D. Bacco, L. K. Oxenløwe, M. G. Thompson, J. G. Rarity, et al., Error-protected qubits in a silicon photonic chip, Nature Physics 17, 1137 (2021)

  50. [58]

    Qiang, Y

    X. Qiang, Y. Wang, S. Xue, R. Ge, L. Chen, Y. Liu, A. Huang, X. Fu, P. Xu, T. Yi, et al., Implementing graph-theoretic quantum algorithms on a silicon photonic quantum walk processor, Science Advances 7, eabb8375 (2021)

  51. [59]

    K. Wei, W. Li, H. Tan, Y. Li, H. Min, W.-J. Zhang, H. Li, L. You, Z. Wang, X. Jiang, et al., High-speed measurement-device-independent quantum key distribu- tion with integrated silicon photonics, Physical Review X 10, 031030 (2020)

  52. [60]

    Sibson, J

    P. Sibson, J. E. Kennard, S. Stanisic, C. Erven, J. L. O’Brien, and M. G. Thompson, Integrated silicon pho- tonics for high-speed quantum key distribution, Optica 4, 172 (2017)

  53. [61]

    Zhang, J

    G. Zhang, J. Y. Haw, H. Cai, F. Xu, S. Assad, J. F. Fitzsimons, X. Zhou, Y. Zhang, S. Yu, J. Wu, et al., An integrated silicon photonic chip platform for continuous- variable quantum key distribution, Nature Photonics 13, 839 (2019)

  54. [62]

    Bunandar, A

    D. Bunandar, A. Lentine, C. Lee, H. Cai, C. M. Long, N. Boynton, N. Martinez, C. DeRose, C. Chen, M. Grein, et al., Metropolitan quantum key distribution with sili- con photonics, Physical Review X 8, 021009 (2018)

  55. [63]

    C. Ma, W. D. Sacher, Z. Tang, J. C. Mikkelsen, Y. Yang, F. Xu, T. Thiessen, H.-K. Lo, and J. K. Poon, Silicon photonic transmitter for polarization-encoded quantum key distribution, Optica 3, 1274 (2016)

  56. [64]

    J. S. Bell, On the Einstein-Podolsky-Rosen paradox, Physics Physique Fizika 1, 195 (1964)

  57. [65]

    Brunner, D

    N. Brunner, D. Cavalcanti, S. Pironio, V. Scarani, and S. Wehner, Bell nonlocality, Rev. Mod. Phys. 86, 419 (2014)

  58. [66]

    Dupuis, O

    F. Dupuis, O. Fawzi, and R. Renner, Entropy accumula- tion, Communications in Mathematical Physics 379, 867 (2020)

  59. [67]

    Milovanˇ cev, F

    D. Milovanˇ cev, F. Honz, N. Voki´ c, M. Achleitner, F. Lau- denbach, C. Pacher, H. H¨ ubel, and B. Schrenk, Chip- level ghz capable balanced quantum homodyne receivers, Journal of Lightwave Technology 40, 7518 (2022)

  60. [68]

    S. Q. Ng, G. Zhang, C. Wang, and C. Lim, 240 gbps quantum random number generator with photonic inte- grated chip, in CLEO: Applications and Technology(Op- tica Publishing Group, 2023) pp. AM4N–6

  61. [69]

    Marinins, S

    A. Marinins, S. H¨ ansch, H. Sar, F. Chancerel, N. Gol- shani, H.-L. Wang, A. Tsiara, D. Coenen, P. Verheyen, G. Capuz, et al., Wafer-scale hybrid integration of inp dfb lasers on si photonics by flip-chip bonding with sub-300 nm alignment precision, IEEE Journal of Selected T...

  62. [70]

    N. Li, G. Chen, D. K. Ng, L. W. Lim, J. Xue, C. P. Ho, Y. H. Fu, and L. Y. Lee, Integrated lasers on silicon at communication wavelength: a progress review, Advanced Optical Materials 10, 2201008 (2022)

  63. [71]

    A. M. Zubkov and A. A. Serov, A complete proof of uni- versal inequalities for the distribution function of the bi- nomial law, Theory of Probability & Its Applications 57, 539 (2013)

  64. [72]

    Tomamichel, C

    M. Tomamichel, C. Schaffner, A. Smith, and R. Ren- ner, Leftover hashing against quantum side informa- tion, IEEE Transactions on Information Theory 57, 5524 (2011)

  65. [73]

    Vitanov, F

    A. Vitanov, F. Dupuis, M. Tomamichel, and R. Renner, Chain rules for smooth min-and max-entropies, IEEE Transactions on Information Theory 59, 2603 (2013). 15

  66. [74]

    Tomamichel, R

    M. Tomamichel, R. Colbeck, and R. Renner, A fully quantum asymptotic equipartition property, IEEE Transactions on Information Theory 55, 5840 (2009)

  67. [75]

    We use the version of QAEP given in Corollary 4.10 of Ref. [66]

  68. [76]

    Tomamichel and A

    M. Tomamichel and A. Leverrier, A largely self-contained and complete security proof for quantum key distribu- tion, Quantum 1, 14 (2017)

  69. [77]

    Dupuis and O

    F. Dupuis and O. Fawzi, Entropy accumulation with im- proved second-order term, IEEE Transactions on Infor- mation Theory 65, 7596 (2019)

  70. [79]

    P. J. Brown, S. Ragy, and R. Colbeck, A framework for quantum-secure device-independent randomness expan- sion, IEEE Transactions on Information Theory 66, 2964 (2019)

  71. [80]

    Y. Wang, I. W. Primaatmaja, E. Lavie, A. Varvitsio- tis, and C. C. W. Lim, Characterising the correlations of prepare-and-measure quantum networks, npj Quantum Inf. 5, 17 (2019)

  72. [81]

    Tomamichel, R

    M. Tomamichel, R. Colbeck, and R. Renner, Duality be- tween smooth min- and max-entropies, IEEE Transac- tions on Information Theory 56, 4674 (2010)

  73. [82]

    Hoshi et al., Interval algorithm for random number generation, IEEE Transactions on Information Theory 43, 599 (1997)

    M. Hoshi et al., Interval algorithm for random number generation, IEEE Transactions on Information Theory 43, 599 (1997)

  74. [100]

    Both the X and P quadrature for each state are mea- 0.7 0.8 0.9 1.0 10-4 10-3 10-2 10-1 rnet Homodyne Efficiency  Asymptotic 1x1012 1x1011 3x1010 Experiment 0.7 0.8 0.9 1.0 10-4 10-3 10-2 10-1 rnet Homodyne Efficiency  8 bins 6 bins 4 bins 2 bins 0.06 0.09 0.12 0.15 0.18 -2 ...

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.