REVIEW 4 major objections 6 minor 45 references
40Gbps Tri-type Quantum Random Number Generator
T0 review · 4 major / 6 minor · reviewed 2026-08-07 · deepseek-v4-flash
Pith's one-line read A single optical detector can output uniform, Gaussian, and Rayleigh quantum random numbers on demand at secure rates above 40 Gbps.
desk verdict A capable dual-quadrature QRNG with on-demand output types, but the secure-rate claims outrun the shot-noise calibration and the Gaussian extractor's proof status. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrier of the argument is dual-quadrature homodyne detection of the vacuum field: a balanced receiver measures one quadrature I while a second receiver measures the conjugate quadrature Q with a $\pi/2$ phase-shifted local oscillator, and the two Gaussian-distributed voltages constitute the raw entropy. The distribution switch is the polar-coordinate identity $\theta = \arctan(Q/I)$, $r = \sqrt{I^2+Q^2}$: $\theta$ is uniform and $r$ is Rayleigh whenever I and Q are independent Gaussians. Security is carried by a min-entropy bound against quantum side information computed from the measured signal variance and the conditional quantum variance, together with Toeplitz hashing for uniform extraction and a recursive sum-of-squares-preserving transform for Gaussian extraction. The same electronics therefore select among three output types without any optical reconfiguration.
What would settle it
Record the homodyne voltage variance while sweeping local-oscillator power in fine steps near 4.13 mW per diode; if the variance-versus-power curve shows curvature or an intercept comparable to the shot-noise slope, or if a classical monitor of laser intensity and phase can predict post-extraction bits at a rate above the claimed min-entropy bound, the shot-noise-limited security assumption is refuted.
Extended reading notes
Core claim
Starting from the vacuum state, the two conjugate quadratures I and Q measured by balanced homodyne detection are independent Gaussian random variables. The same pair of measurements, converted to polar form, yields a phase angle $\theta = \arctan(Q/I)$ that is uniformly distributed and a radius $r = \sqrt{I^2+Q^2}$ that is Rayleigh distributed, all from the same optical setup. The authors build a 1550 nm dual-quadrature homodyne system with two 1.6 GHz detectors, sample at 2 GHz, and postprocess on an FPGA: Toeplitz hashing extracts uniform bits at 42.66 Gbps total with a quantum-side-information min-entropy bound; a modified recursive matrix method extracts Gaussian bits at 14.01 Gbps; and Savitzky-Golay-filtered radial samples approximate Rayleigh statistics but do not yet pass goodness-of-fit tests after extraction. The central claim is that distribution type becomes a software choice, not a hardware property, and that this choice costs nothing in generation rate.
Load-bearing premise
The security bounds assume the two homodyne detectors are shot-noise-limited at 4.13 mW per diode, so the measured variance is dominated by quantum vacuum fluctuations rather than classical electronic or laser noise.
Editorial extensions
If this is right
- A service can offer uniform, Gaussian, and Rayleigh random numbers from one continuously running device, so the user's choice of distribution no longer requires provisioning separate quantum hardware.
- Switching distribution type in FPGA logic means throughput stays at the full detector-limited rate even when the requested distribution changes between requests.
- The uniform output at 42.66 Gbps secure and Gaussian output at 14.01 Gbps secure are high enough for real-time cryptographic key generation and Monte Carlo simulation workloads.
- Replacing the anti-aliasing filter with a high-speed low-noise version is projected to raise the uniform rate to about 68 Gbps and the Gaussian rate to about 22 Gbps on the same hardware.
- A rigorous Rayleigh extractor remains the missing piece; until it exists, Rayleigh output is statistical raw material rather than a secure random stream.
Reading between the lines
- Because every homodyne setup that already records both I and Q obtains $\theta$ and $r$ for free, the tri-type result transfers to any dual-quadrature QRNG design; the only missing ingredient for Rayleigh output is a conditional min-entropy bound for the radial distribution.
- If a Rayleigh extractor is developed, the same device could potentially add a third secure stream on top of the I and Q channels, so total secure throughput might exceed the reported 42.66 Gbps rather than merely swapping distributions.
- The FPGA switching architecture suggests a multiplexed network service where different clients receive different distributions simultaneously, which the paper's cloud deployment hints at but does not characterize.
- A natural test of the 'switching costs nothing' claim is to benchmark bit rate and statistical-test results under rapid alternating distribution requests; the paper demonstrates the mechanism but does not report a switching-stress test.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper reports a dual-quadrature homodyne vacuum-noise QRNG that generates uniform, Gaussian, and Rayleigh distributed random numbers on demand from the same hardware. It claims a secure uniform bit rate of 42.66 Gbps using a Toeplitz extractor, a Gaussian bit rate of 14.01 Gbps using a modified Wallace method, and raw Rayleigh bits after denoising. The min-entropy estimation follows Gehring et al. and Bruynsteen et al., and the experimental verification relies on variance-vs-LO-power linearity and PSD measurements.
Significance. If fully substantiated, the dual-quadrature approach is a useful step toward multi-distribution QRNGs, and the 42 Gbps uniform rate is competitive with state-of-the-art. However, the security claims for the Gaussian stream are explicitly unproven, the Rayleigh output is not extracted randomness, and the shot-noise certification is not sufficient to support the claimed min-entropy values. The paper also omits key parameters of the entropy calculation, making the rates not independently verifiable.
major comments (4)
- [Section III, Fig. 3a] The linear dependence of the measured variance on LO power (R=0.99) is not sufficient to certify shot-noise-limited operation, because LO-correlated technical noise (e.g., relative intensity noise and imperfect common-mode rejection) also scales linearly with LO power. The authors should provide a quantitative shot-noise-to-excess-noise ratio at the 4.13 mW operating point, for example by comparing the measured PSD to the calculated shot-noise level from the photocurrent, or by an independent calibration measurement. Without this, the min-entropy values Hmin=0.70/0.71 and the resulting rates are not supported.
- [Section IV and V.A] The min-entropy derivation is not reproducible because the paper does not report sigma_M^2, sigma_Q,c^2, the effective photon number n, the ADC parameters R and N, or the nonlinearity term DNL_max that enter Eqs. (2)-(4). It also does not state the security parameter epsilon used in Eq. (1) or explain how the block sizes in the Toeplitz extractor (1536 input bits to 1024 output bits) relate to the claimed 2 GHz effective sampling rate and the 42.66 Gbps secure rate. Please provide the full set of measured parameters and a sample calculation, or include a supplementary document.
- [Section V.B and Abstract] The Gaussian extractor is explicitly stated to 'lack theoretical proof of randomness preservation' and to be 'not entirely reliable' and 'may introduce subtle correlations.' Therefore the abstract's claim of 'over 14 Gbps secure bit rate for Gaussian random number' is not supported. Please rephrase to 'statistically Gaussian' or provide a security proof for the modified Wallace method; otherwise remove 'secure' from the abstract.
- [Section V.C, Title, and Abstract] The Rayleigh output consists of raw bits that, after applying a Savitzky-Golay filter, still fail the chi-squared goodness-of-fit test (p=0). Since no randomness extraction is performed for the Rayleigh distribution, the paper does not actually demonstrate a third secure random number type. The title '40Gbps Tri-type' and the abstract's characterization of generating 'three distribution types of random numbers at over 60 Gbits/s raw bits' should be qualified to clarify that only uniform and (statistically) Gaussian outputs are extracted, while Rayleigh is a raw-data-only demonstration.
minor comments (6)
- [Section V.C] The term 'Raleigh' is a misspelling of 'Rayleigh' throughout this section.
- [Section V.B] The symbol K is introduced as the group size in the Wallace method but later k is used; please use consistent notation.
- [Section V.A] The sentence 'To generate the n−m+ 1-bit seed required' appears to be a typo; the Toeplitz seed length is n+m−1.
- [Section IV] Eqs. (2) and (4) use 'erf' while the subsequent definition uses 'erfc'; please check the consistency of the expressions and clarify the relationship.
- [Fig. 3c] The caption says 'quantum vacuum noise of both quadratures' but the text refers to 'conditional quantum variance sigma_Q^2'; please label the plotted quantity explicitly on the axis and define it precisely in the caption.
- [General] The paper would benefit from a table listing all parameters used in the entropy calculation, including the ADC range, resolution, DNL_max, sigma_M^2, sigma_Q,c^2, and the resulting effective n for each channel.
Circularity Check
No significant circularity: the min-entropy and rate claims are computed from measured parameters using independent external prior-work formulas, and the admitted caveats are security limitations rather than constructional circularity.
full rationale
The paper's derivation chain for the headline uniform rate starts from measured electrical quantities: ADC range (128 mV peak-to-peak), ADC resolution (16 bits), measured voltage variances, and power spectral densities of signal and excess noise. These feed the min-entropy bound of Gehring et al. [21] and the effective-iid model of Bruynsteen et al. [22], both of which are independent external works with stated assumptions that do not include the target rate. The 42.66 Gbps uniform figure is the implemented Toeplitz-block throughput (1536 input bits to 1024 output bits at a 2 GHz effective sample rate on two channels), not a re-labeling of a fitted parameter; the measured H_min values (0.70/0.71) are used only to set extractor parameters. The Gaussian and Rayleigh distributions arise from the standard polar-coordinate transformation of two quadratures, and the paper explicitly does not claim a secure Rayleigh extractor. The two substantive concerns - shot-noise-limited operation not independently certified and the Gaussian extractor lacking a proof of randomness preservation - are acknowledged in the text (e.g., Section V.B: 'this method lacks theoretical proof of randomness preservation and is thus not entirely reliable') and are physical/security correctness risks, not circular reductions. There is no load-bearing self-citation chain and no parameter fitted to the claimed output. Therefore no circular step can be exhibited, and the honest finding is score 0.
Assumptions & free parameters
free parameters (2)
- K (group size in Wallace method) =
4
- m (number of MSBs retained in Gaussian extractor) =
From Hmin: m = 0.70 or 0.71 effective, likely m=10?
assumptions (3)
- domain assumption The noise model of the measurement is independent and identically distributed Gaussian, with side information from a thermal state.
- domain assumption The homodyne detector operates in shot-noise-limited regime, so all classical noise is either rejected or known to the eavesdropper.
- standard math The Toeplitz extractor with seed from Dodis extractor is a strong extractor with seed reuse as per [39].
Cite this review
Pith. "Pith review of 40Gbps Tri-type Quantum Random Number Generator." pith.science (2026). https://pith.science/paper/O7ASOBY2
@misc{pith2026250605627,
author = {Pith},
title = {Pith review of: 40Gbps Tri-type Quantum Random Number Generator},
year = {2026},
howpublished = {\url{https://pith.science/paper/O7ASOBY2}},
note = {Machine review of arXiv:2506.05627}
}
read the original abstract
Traditional quantum random number generators can produce only one type of random number, while the optimal distribution of random numbers for different applications is usually distinct. The typical solution to this challenge is either using different quantum phenomena for different types of random number, or converting one distribution of random numbers to another type. However, the former solution requires multiple hardware systems, while the latter one sacrifices a lot of secure bits. Here, we develop a quantum random number generator that can on-demand produce three distribution types of random numbers at over 60 Gbits/s (Gbps) raw bits by measuring the quantum vacuum noise. After randomness extraction, over 42 Gbps secure bit rate is demonstrated for uniform random numbers, and over 14 Gbps secure bit rate for Gaussian random number. Due to the lack of Rayleigh randomness extraction, only denoised Rayleigh raw bits are generated. Switching between different types of random numbers is achieved in electronics, which does not affect the generation rate. The random numbers pass NIST and Dieharder tests, and are available for various applications, which can be continuously accessed via Cisco Quantum Random Number web service.
Figures
Reference graph
Works this paper leans on
-
[1]
N. Ferguson and B. Schneier,Practical cryptography, Vol. 141 (Wiley New York, 2003)
work page 2003
-
[2]
J. E. Gentle,Random number generation and Monte Carlo methods, Vol. 381 (Springer, 2003)
work page 2003
-
[3]
P. Shadbolt, J. C. Mathews, A. Laing, and J. L. O’brien, Testing foundations of quantum mechanics with photons, Nature Physics10, 278 (2014)
work page 2014
- [4]
-
[5]
Vershynin,High-dimensional probability: An introduction with applications in data science, Vol
R. Vershynin,High-dimensional probability: An introduction with applications in data science, Vol. 47 (Cambridge university press, 2018)
work page 2018
-
[6]
V. Vovk, A. Gammerman, and G. Shafer,Algorithmic learning in a random world, Vol. 29 (Springer, 2005)
work page 2005
-
[7]
X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, Quantum random number generation, npj Quantum Information2, 1 (2016)
2016
-
[8]
M. Herrero-Collantes and J. C. Garcia-Escartin, Quantum random number generators, Re- views of Modern Physics89, 015004 (2017)
work page 2017
Show all 45 references
-
[9]
Mannalatha, S
V. Mannalatha, S. Mishra, and A. Pathak, A comprehensive review of quantum random num- ber generators: Concepts, classification and the origin of randomness, Quantum Information Processing22, 439 (2023)
2023
-
[10]
Applegate, O
M. Applegate, O. Thomas, J. Dynes, Z. Yuan, D. Ritchie, and A. Shields, Efficient and robust quantum random number generation by photon number detection, Applied Physics Letters 107(2015)
2015
-
[11]
Eaton, A
M. Eaton, A. Hossameldin, R. J. Birrittella, P. M. Alsing, C. C. Gerry, H. Dong, C. Cuevas, and O. Pfister, Resolution of 100 photons and quantum generation of unbiased random num- bers, Nature Photonics17, 106 (2023)
2023
-
[12]
Q. Yan, B. Zhao, Q. Liao, and N. Zhou, Multi-bit quantum random number generation by measuring positions of arrival photons, Review of Scientific Instruments85(2014)
2014
-
[13]
C. Meng, M. Cai, Y. Yang, H. Wu, Z. Li, Y. Ruan, Y. Zhang, H. Zhang, K. Xia, and F. Nori, Generation of true quantum random numbers with on-demand probability distributions via single-photon quantum walks, Optics Express32, 20207 (2024). 16
2024
-
[14]
M. Wahl, M. Leifgen, M. Berlin, T. R¨ ohlicke, H.-J. Rahn, and O. Benson, An ultrafast quan- tum random number generator with provably bounded output bias based on photon arrival time measurements, Applied Physics Letters98(2011)
2011
-
[15]
Nie, H.-F
Y.-Q. Nie, H.-F. Zhang, Z. Zhang, J. Wang, X. Ma, J. Zhang, and J.-W. Pan, Practical and fast quantum random number generation based on photon arrival time relative to external reference, Applied Physics Letters104(2014)
2014
-
[16]
Gabriel, C
C. Gabriel, C. Wittmann, D. Sych, R. Dong, W. Mauerer, U. L. Andersen, C. Marquardt, and G. Leuchs, A generator for unique quantum random numbers based on vacuum states, Nature Photonics4, 711 (2010)
2010
-
[17]
Avesani, D
M. Avesani, D. G. Marangon, G. Vallone, and P. Villoresi, Source-device-independent heterodyne-based quantum random number generator at 17 gbps, Nature communications 9, 5365 (2018)
2018
-
[18]
Zheng, Y
Z. Zheng, Y. Zhang, W. Huang, S. Yu, and H. Guo, 6 gbps real-time optical quantum random number generator based on vacuum fluctuation, Review of Scientific Instruments90(2019)
2019
-
[19]
Drahi, N
D. Drahi, N. Walk, M. J. Hoban, A. K. Fedorov, R. Shakhovoy, A. Feimov, Y. Kurochkin, W. S. Kolthammer, J. Nunn, J. Barrett,et al., Certified quantum random numbers from untrusted light, Physical Review X10, 041048 (2020)
2020
-
[20]
Huang, Z
M. Huang, Z. Chen, Y. Zhang, and H. Guo, A gaussian-distributed quantum random number generator using vacuum shot noise, Entropy22, 618 (2020)
2020
-
[21]
Gehring, C
T. Gehring, C. Lupo, A. Kordts, D. Solar Nikolic, N. Jain, T. Rydberg, T. B. Pedersen, S. Pirandola, and U. L. Andersen, Homodyne-based quantum random number generator at 2.9 gbps secure against quantum side-information, Nature Communications12, 605 (2021)
2021
-
[22]
In this section, we have described a method to lower bound the min-entropy
for details. In this section, we have described a method to lower bound the min-entropy. Substituting this bound into Eq. 1, we can determine the length of the random sequence extractable from the measurement result. In next section, we will describe how to implement randomnes...
-
[23]
Bruynsteen, T
C. Bruynsteen, T. Gehring, C. Lupo, J. Bauwelinck, and X. Yin, 100-gbit/s integrated quan- tum random number generator based on vacuum fluctuations, PRX quantum4, 010330 (2023)
2023
-
[24]
Y.-Q. Nie, L. Huang, Y. Liu, F. Payne, J. Zhang, and J.-W. Pan, The generation of 68 gbps quantum random number by measuring laser phase fluctuations, Review of Scientific Instruments86(2015)
2015
-
[25]
J. Yang, F. Fan, J. Liu, Q. Su, Y. Li, W. Huang, and B. Xu, Randomness quantification for quantum random number generation based on detection of amplified spontaneous emission noise, Quantum Science and Technology6, 015002 (2020). 17
2020
-
[26]
Qi, Y.-M
B. Qi, Y.-M. Chi, H.-K. Lo, and L. Qian, High-speed quantum random number generation by measuring phase noise of a single-mode laser, Optics letters35, 312 (2010)
2010
-
[27]
F. Xu, B. Qi, X. Ma, H. Xu, H. Zheng, and H.-K. Lo, Ultrafast quantum random number generation based on quantum phase fluctuations, Optics express20, 12366 (2012)
2012
-
[28]
P. J. Bustard, D. Moffatt, R. Lausten, G. Wu, I. A. Walmsley, and B. J. Sussman, Quantum random bit generation using stimulated raman scattering, Optics express19, 25173 (2011)
2011
-
[29]
Y.-Y. Hu, X. Lin, S. Wang, J.-Q. Geng, Z.-Q. Yin, W. Chen, D.-Y. He, W. Huang, B.-J. Xu, G.-C. Guo,et al., Quantum random number generation based on spontaneous raman scattering in standard single-mode fiber, Optics Letters45, 6038 (2020)
2020
-
[30]
Y. Liu, Q. Zhao, M.-H. Li, J.-Y. Guan, Y. Zhang, B. Bai, W. Zhang, W.-Z. Liu, C. Wu, X. Yuan,et al., Device-independent quantum random-number generation, Nature562, 548 (2018)
2018
-
[31]
J. S. Sidhu, T. Brougham, D. McArthur, R. G. Pousa, and D. K. Oi, Finite key performance of satellite quantum key distribution under practical constraints, Communications Physics6, 210 (2023)
2023
-
[32]
Gryszka, From biased coin to any discrete distribution, Periodica Mathematica Hungarica 83, 71 (2021)
K. Gryszka, From biased coin to any discrete distribution, Periodica Mathematica Hungarica 83, 71 (2021)
2021
-
[33]
¨Okten and A
G. ¨Okten and A. G¨ onc¨ u, Generating low-discrepancy sequences from the normal distribution: Box–muller or inverse transform?, Mathematical and Computer Modelling53, 1268–1281 (2011)
2011
-
[34]
Zhang, Y.-Q
X. Zhang, Y.-Q. Nie, H. Liang, and J. Zhang, Fpga implementation of toeplitz hashing ex- tractor for real time post-processing of raw random numbers, in2016 IEEE-NPSS Real Time Conference (RT)(IEEE, 2016) pp. 1–5
2016
-
[35]
AMD,Zynq UltraScale+ RFSoC RF Data Converter v2.6 Gen 1/2/3/DFE LogiCORE IP Product Guide(2023), pG269, p. 17
2023
-
[36]
Xilinx, RFSoC-PYNQ PYNQ support for RFSoC (2024), accessed: 2024-03-14
2024
-
[37]
Strath-SDR, rfsoc qpsk QPSK transceiver example for RFSoC (2024), accessed: 2024-03-14
2024
-
[38]
Tomamichel, C
M. Tomamichel, C. Schaffner, A. Smith, and R. Renner, Leftover hashing against quantum side information, IEEE Transactions on Information Theory57, 5524–5535 (2011)
2011
-
[39]
Dodis, A
Y. Dodis, A. Elbaz, R. Oliveira, and R. Raz, Improved randomness extraction from two in- dependent sources, inApproximation, Randomization, and Combinatorial Optimization. Al- 18 gorithms and Techniques (RANDOM APPROX 2004), Lecture Notes in Computer Science, Vol. 3122, edited...
2004
-
[40]
X. Ma, F. Xu, H. Xu, X. Tan, B. Qi, and H.-K. Lo, Postprocessing for quantum random- number generators: Entropy evaluation and randomness extraction, Physical Review A87, 062327 (2013)
2013
-
[41]
M. N. Wegman and J. L. Carter, New hash functions and their use in authentication and set equality, Journal of Computer and System Sciences18, 143 (1979)
1979
-
[42]
Foreman, S
C. Foreman, S. Wright, A. Edgington, M. Berta, and F. J. Curchod, Practical randomness amplification and privatisation with implementations on quantum computers, Quantum7, 969 (2023)
2023
-
[43]
X. Guo, F. Lin, J. Lin, Z. Song, Q. Wang, Y. Guo,et al., Parallel and real-time post-processing for quantum random number generators, arXiv preprint arXiv:2403.19479 (2024)
2024 arXiv
-
[44]
C. S. Wallace, Fast pseudorandom generators for normal and exponential variates, ACM Trans- actions on Mathematical Software (TOMS)22, 119 (1996)
1996
-
[45]
Cisco quantum random number generator,https://outshift.cisco.com/ quantum-random-number-generator(2025). 19
2025
Reviewed August 7, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.