Pith. sign in

REVIEW 5 minor 1 cited by

Device-Independent Randomness Amplification

T0 review · 0 major / 5 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This paper reports the first experimental demonstration of device-independent randomness amplification, converting 5,368,709,120 bits with up to 0.75% bias into 20,431,465 bits certified to be uniformly random to within 10^-12 error.

desk verdict A genuine experimental first in DI randomness amplification; the headline guarantee is honestly conditional on an uncertified SV-source assumption that the paper states clearly. read the letter →

arxiv 2412.17931 v1 pith:WO5BXOXC submitted 2024-12-23 quant-ph

classification quant-ph
keywords device-independentrandomnessamplificationSantha-Vaziranisourcemeasurement-dependentlocalityinequalityloophole-freeBelltestquantumrandomnumbergeneratortwo-sourceextractorsuperconductingqubitsmin-entropy
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper reports the first experimental demonstration of randomness amplification: turning weakly random bits into almost perfect randomness in a device-independent way. Specifically, the authors used a loophole-free Bell test with two superconducting qubits 30 meters apart, driving the measurement choices with two commercial quantum random number generators treated as biased public sources. From 5,368,709,120 input bits with bias up to 0.75%, they produced 20,431,465 output bits certified to be uniformly random to within $10^{-12}$, assuming only that the input sources are Santha-Vazirani sources and that the adversary holds classical side information about them. The result closes a long-standing gap: prior device-independent protocols assumed perfect input randomness, while this one starts from imperfect sources. If correct, the method supplies a practical, certified randomness source for quantum cryptography and other tasks that need full-entropy randomness.

What carries the argument

The central object is the measurement-dependent locality (MDL) inequality S_μ, a version of the CHSH/Eberhard Bell inequality that accounts for biased input distributions: for inputs from a μ-SV source, a violation S_μ > 0 certifies min-entropy in the outputs. The proof chain uses the entropy accumulation theorem to bound smooth min-entropy of the outputs AB given inputs XY and adversary side information E in terms of S_μ, and then a two-source extractor (constructed from non-cyclic shift matrices) that converts AB plus an additional public seed Z into a near-uniform private string K. The experiment closes the locality, fair-sampling, and memory loopholes via 30 m separation, all-trials inclusion, and a non-i.i.d. security proof.

What would settle it

Measure the predictability of each QRNG bit conditioned on all earlier bits and on classical environmental variables (temperature, supply voltage, laser current). If the best predictor succeeds with probability above 0.5075 for any bit, the Santha-Vazirani assumption with μ = 0.75% is violated, and the ε = $10^{-12}$ guarantee for K no longer follows. Alternatively, an independent timing audit that reconstructs t_protocol from the published segment durations and finds it exceeds 109.83 ns would open the locality loophole and invalidate the device-independent certification.

Watch

Extended reading notes

Core claim

The paper claims that a two-node superconducting circuit apparatus can amplify the randomness of a public, imperfect source: running a loophole-free Bell test with measurement choices drawn from two possibly correlated Santha-Vazirani sources with bias μ = 0.75% yields a string K of length 20,431,465 bits that is ε-random with ε = $10^{-12}$, guaranteed by the violation of the measurement-dependent locality inequality S_μ. The guarantee is device-independent for the quantum device—the device is treated as an untrusted black box—and holds provided the input sources satisfy the SV condition and the adversary has only classical side information about them. The output passes the NIST and Diehard statistical test suites.

Load-bearing premise

The result assumes, without direct experimental proof, that the two commercial QRNGs really are Santha-Vazirani sources with bias at most 0.75% against an adversary who holds only classical side information.

Editorial extensions

If this is right

  • The output K, 20.4 Mbit with ε = 10^-12, is large enough to serve as a public certified randomness beacon or as input randomness for later device-independent protocols.
  • The demonstrated rate and statistics enter the regime required for device-independent quantum key distribution without assuming perfect randomness.
  • The protocol aborts when the MDL violation is not observed, so the same hardware can be reused in a fallback mode whenever the sources degrade.
  • The result shifts randomness amplification from a theoretical existence proof to an experimentally achievable task, establishing a benchmark for future implementations.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural extension, not explored in the paper, would be to allow the adversary quantum side information about the QRNGs; the current security proof only covers classical side information, so a malicious manufacturer who entangles the seed photons would break the stated guarantee.
  • The margin between the protocol duration (106.7 ns) and the Bell-distance budget (109.8 ns) is only 2.8% of the budget; tighter timing or longer distances would increase the robustness of the locality loophole closure.
  • The same setup, with better channel loss and faster repetition, could tolerate sources with bias above 0.75%, reducing the gap toward the theoretical 4% limit shown in the paper's parameter plot.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

0 major / 5 minor

Summary. The paper reports an experimental realization of device-independent randomness amplification. Two commercial quantum random number generators serve as public Santha-Vazirani sources with bias μ = 0.75%; their bits set the measurement bases for a two-node superconducting circuit distributed over 30 m, which violates a measurement-dependent locality inequality. After n = 1.34×10^9 trials, with observed CHSH value S = 2.271 and MDL value S_μ,obs = 0.00296, the authors apply a two-source extractor seeded from one of the SV sources to produce a 20,431,465-bit output string K. The security claim, with ε = 10^-12, is based on a proof in the Supplementary Information that combines the entropy accumulation theorem with the MDL bound of Kessler and Arnon-Friedman and quantum-proof extractor results of Arnon-Friedman, Portmann, and Scholz. The experiment closes the locality, fair-sampling, and memory loopholes; the timing analysis leaves a 3.1 ns margin to the Bell bound.

Significance. If the security proof and experimental execution hold up, this is the first experimental demonstration of randomness amplification, a task that is impossible classically. The paper is notable for its transparency: it explicitly lists all assumptions in SI section V, provides a security proof in SI section VI as a chain of published theorems, and includes conservative timing verification with real-time monitoring. The result is a significant step toward device-independent cryptography without the assumption of perfect randomness, and the output length is already useful as input for device-independent QKD. The main limitation is that the SV-source property of the QRNGs is assumed, not certified; the authors state this assumption plainly, and it is inherent to the nature of the task.

minor comments (5)
  1. [Methods, 'Requirements for the randomness extractor'; SI section VI, Theorem 2] The main text attributes the extractor used in the experiment to Ref. [55], while the security proof in SI section VI is based on the construction from Ref. [63] (Theorem 2); please clarify whether these are the same construction and reconcile the citations, because the proof must cover the actually implemented function.
  2. [SI section V, Assumption 4; final summary paragraph] The ε = 10^-12 guarantee for K is conditional on the two QRNGs being μ-SV sources with μ ≤ 0.75% and on Eve holding only classical side information about them; although this is stated in the text, the abstract and conclusion could more prominently emphasize that this source property is assumed rather than experimentally certified, since the manufacturer's 'excess predictability below 10^-5' is not the same as the conditional SV bound required by the proof.
  3. [Main text, final summary paragraph] The statement that the protocol starts from 5,368,709,120 low-quality random bits could be clarified: with n = 1,342,177,280 trials, this number equals 4n, corresponding to two input bits per trial (xi, yi) plus an additional 2n-bit seed for the extractor; please spell out this accounting.
  4. [Methods, Eq. (4)] The notation PABXY(abcd) is used without an explicit definition; please define it as Pr[A=a, B=b, X=c, Y=d] so that the MDL inequality is unambiguous.
  5. [SI section VI, Eq. (18)] In the expression for the output size m, the additive term '-6εs' appears outside the factor n/6; please verify the expression and comment on the origin of this term, as it is not immediately transparent from the preceding Theorem 4.

Circularity Check

0 steps flagged · score 2.0 of 10

No circular derivation: the security guarantee is conditional on explicit SV-source assumptions, and all load-bearing theorems are imported external results.

full rationale

Verdict: no meaningful circularity. The amplified string K is not defined as the input; it is produced by an independent Bell-test measurement followed by a classical two-source extractor. The security statement is obtained by chaining Theorem 1 (smooth min-entropy from the MDL violation, quoted from Kessler and Arnon-Friedman [20]) with Theorems 2-4 (two-source extractor results from Dodis et al. [63] and Arnon-Friedman, Portmann, and Scholz [54]). The only place input randomness enters the bound is the SV-source min-entropy term, which is an explicit stated assumption (SI Section V, Assumption 4, plus Eqs. 9-10), not a construction. Measured quantities S_obs = 2.271 and S_mu,obs = 0.00296 are independent experimental data; Theorem 6 merely converts the observed violation into an allowed output length, so no fitted parameter is renamed as a prediction. The abstract's 'guaranteed' wording is stronger than the conditional theorem, but the limiting premise - that the two QRNGs are possibly correlated SV sources with bias at most 0.75% and that Eve has only classical side information about them - is stated transparently and is a falsifiable hardware assumption, not an equivalence imposed by definitions. Self-citations to [19] and [68] are background and a published entropy-accumulation theorem, respectively; neither is an unverified premise adopted because the present authors wrote it. The uncertified SV-source assumption is a limitation (flagged in SI Section V, Assumption 4), but it is not circularity. Overall: no step in the derivation reduces to its own input by construction.

Assumptions & free parameters 1 free parameters · 7 assumptions · 0 invented entities

The ledger is clean: no new particles, forces, or dimensions are introduced. The experiment depends on one hand-chosen protocol parameter (μ = 0.75%) and a set of explicitly listed physical assumptions about the source, device shielding, and trusted classical hardware. The mathematical backbone (EAT, MDL bound, extractors) is imported from published work.

free parameters (1)
  • Tolerated source bias μ = 0.75%
    Chosen by the authors based on the observed Bell violation and the required dataset size (Fig. 2); the security statement holds only for SV sources with bias at most this value.
assumptions (7)
  • domain assumption Quantum mechanics is correct and complete; the adversary is quantum
    Listed as Assumption 1 in Supplementary Information section V; standard for device-independent protocols.
  • domain assumption The device λ is shielded from the adversary and outputs A,B are not leaked
    Assumption 2 in SI section V; necessary for privacy of K.
  • domain assumption Classical processing devices (ADC, FPGA, timing verification, computer) are trusted
    Assumption 3 in SI section V; these lie outside the untrusted device λ.
  • domain assumption The two QRNGs are (possibly correlated) SV sources with bias μ ≤ 0.75%, and Eve has only classical side information about them
    Assumption 4 in SI section V; the weakest load-bearing premise. It is not experimentally certified, only supported by the manufacturer's predictability spec below 1e-5.
  • domain assumption No causal influence from prior device outputs to current source bits (Eq. 9) and independence of extractor seed Z from AB (Eq. 10)
    Assumption 5 in SI section V; justified by physical separation, required for the two-source extractor Markov condition.
  • standard math Entropy accumulation theorem and the MDL inequality entropy bound from [20]
    The security proof applies Theorem 4 of [20] as Theorem 1; correctness of EAT is taken as established.
  • standard math Dodis two-source extractor and the quantum-proof conversion theorems from [54,63]
    Theorems 2-4 in SI section VI; external results.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Device-Independent Randomness Amplification." pith.science (2026). https://pith.science/paper/WO5BXOXC

@misc{pith2026241217931,
  author       = {Pith},
  title        = {Pith review of: Device-Independent Randomness Amplification},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/WO5BXOXC}},
  note         = {Machine review of arXiv:2412.17931}
}
read the original abstract

Successful realization of Bell tests has settled an 80-year-long debate, proving the existence of correlations which cannot be explained by a local realistic model. Recent experimental progress allowed to rule out any possible loopholes in these tests, and opened up the possibility of applications in cryptography envisaged more than three decades ago. A prominent example of such an application is device-independent quantum key distribution, which has recently been demonstrated. One remaining gap in all existing experiments, however, is that access to perfect randomness is assumed. To tackle this problem, the concept of randomness amplification has been introduced, allowing to generate such randomness from a weak source -- a task impossible in classical physics. In this work, we demonstrate the amplification of imperfect randomness coming from a physical source. It is achieved by building on two recent developments: The first is a theoretical protocol implementing the concept of randomness amplification within an experimentally realistic setup, which however requires a combination of the degree of Bell inequality violation (S-value) and the amount of data not attained previously. The second is experimental progress enabling the execution of a loophole-free Bell test with superconducting circuits, which offers a platform to reach the necessary combination. Our experiment marks an important step in achieving the theoretical physical limits of privacy and randomness generation.

Figures

Figures reproduced from arXiv: 2412.17931 by the authors.

Figure 1
Figure 1. FIG. 1 [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. FIG. 2 [PITH_FULL_IMAGE:figures/full_fig_p003_2.png] view at source ↗
Figure 3
Figure 3. FIG. 3 [PITH_FULL_IMAGE:figures/full_fig_p004_3.png] view at source ↗
Figures from the paper (8 more)
Figure 4
Figure 4. Figure 4: FIG. 4 [PITH_FULL_IMAGE:figures/full_fig_p005_4.png]
Figure 5
Figure 5. Figure 5: FIG. 5: Division of the experimental setup into the untrusted (Device [PITH_FULL_IMAGE:figures/full_fig_p010_5.png]
Figure 6
Figure 6. Figure 6: FIG. 6: a) Clock and trigger distribution scheme for the synchronization of the room-temperature electronics at node A and [PITH_FULL_IMAGE:figures/full_fig_p010_6.png]
Figure 7
Figure 7. Figure 7: shows the inter-node timing and its stability. The key information one obtains from the figure is the deviations between the maximum and minimum for each curve (see fig￾ure caption for details) are bounded by at most 200ps and the curves are stable in time. In a simila…
Figure 8
Figure 8. Figure 8: FIG. 8 [PITH_FULL_IMAGE:figures/full_fig_p012_8.png]
Figure 9
Figure 9. Figure 9: FIG. 9: Timing overview of the randomness amplification experiment. See section [PITH_FULL_IMAGE:figures/full_fig_p014_9.png]
Figure 10
Figure 10. Figure 10: FIG. 10: Extracted 20,431,465 bits, arranged row by row from left to right, and from top to bottom. A white pixel represents a [PITH_FULL_IMAGE:figures/full_fig_p017_10.png]
Figure 11
Figure 11. Figure 11: FIG. 11: Sheep and one-time padded sheep. [PITH_FULL_IMAGE:figures/full_fig_p018_11.png]

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Deterministic Quantum Communication Between Fixed-Frequency Superconducting Qubits via Broadband Resonators

    quant-ph 2025-12 accept novelty 6.0 of 10

    Demonstrates deterministic quantum state transfer and remote entanglement between fixed-frequency superconducting qubits on separate chips using broadband resonators and frequency-tunable photon generation.

Reference graph

Works this paper leans on

78 extracted references · 59 canonical work pages · cited by 1 Pith paper

  1. [1]

    ,n}: (a) Sample xi,yi ∈ {0,1} from the two µ−SV sources (b) Feed the devices with the inputs xi, yi and record the respective outputs ai,bi ∈ {0,1}

    Measurement: For each trial i ∈ {1,2, . . . ,n}: (a) Sample xi,yi ∈ {0,1} from the two µ−SV sources (b) Feed the devices with the inputs xi, yi and record the respective outputs ai,bi ∈ {0,1}

  2. [2]

    If Sµ,obs < 0, the protocol aborts and no random bits can be produced

    Parameter estimation: Use the inputsX, Y and the outputs A, B to evaluate the observed value of the MDL inequality Sµ,obs. If Sµ,obs < 0, the protocol aborts and no random bits can be produced

  3. [3]

    (b) Apply the extractor to produce the final output K = Ext(AB,Z) of length m

    Randomness extraction: (a) Draw another bit string Z ∈ {0,1}d from one of the sources. (b) Apply the extractor to produce the final output K = Ext(AB,Z) of length m. col we have implemented inherits from the recent proposal in Ref. [20]. It requires a two-node system capable of violating a Bell-like measurement dependent locality (MDL) inequal- ity and tw...

  4. [4]

    In par- ticular, the adversary can be described using quantum mechanics

    Quantum mechanics is correct and complete. In par- ticular, the adversary can be described using quantum mechanics

  5. [5]

    In particular, the outputs An and Bn are not leaked to the adversary

    The device λ is shielded from the adversary, i.e., it does not leak any unwanted information. In particular, the outputs An and Bn are not leaked to the adversary

  6. [6]

    In particular, this includes the ADC, the timing verification and the computer used for classical post- processing

    The classical information processing devices are trusted. In particular, this includes the ADC, the timing verification and the computer used for classical post- processing

  7. [7]

    This includes the assumption that Eve only has clas- sical side-information about the sources (her side- information about the device λ itself is allowed to be quantum)

    The two sources are, possibly correlated, SV sources. This includes the assumption that Eve only has clas- sical side-information about the sources (her side- information about the device λ itself is allowed to be quantum)

  8. [8]

    This assumption is justified since the QRNG is separated from the outputs of the devices [20]

    The outputs XiYi of the two sources in round i are not influenced by the outputs Ai−1Bi−1 of the device from previous rounds. This assumption is justified since the QRNG is separated from the outputs of the devices [20]. More formally, we require that I(XiYi : Ai−1Bi−1|X i−1Y i−1E) =0. (9) 14 Oscilloscope A FPGA A Oscilloscope B FPGA B time, t time, t tim...

Show all 78 references
  1. [9]

    J. S. Bell, Physics (N. Y .)1, 195 (1964)

  2. [10]

    J. F. Clauser, M. A. Horne, A. Shimony, and R. A. Holt, Phys. Rev. Lett. 23, 880 (1969)

  3. [11]

    S. J. Freedman and J. F. Clauser, Phys. Rev. Lett. 28, 938 (1972)

  4. [12]

    Aspect, P

    A. Aspect, P. Grangier, and G. Roger, Phys. Rev. Lett. 49, 91 (1982)

  5. [13]

    Rowe, Kielpinski, Meyer, Sackett, Itano, Monroe, and Wineland, Nature 409 (2001)

  6. [14]

    Salart, A

    D. Salart, A. Baas, C. Branciard, N. Gisin, and H. Zbinden, Nature 454, 861 (2008)

  7. [15]

    Einstein, B

    A. Einstein, B. Podolsky, and N. Rosen, Phys. Rev. 47, 777 (1935)

  8. [16]

    J. S. Bell and A. Aspect, Speakable and Unspeakable in Quan- tum Mechanics: Collected Papers on Quantum Philosophy, 2nd ed. (Cambridge University Press, 2004)

  9. [17]

    Hensen, H

    B. Hensen, H. Bernien, A. E. Dreau, A. Reiserer, N. Kalb, M. S. Blok, J. Ruitenberg, R. F. L. Vermeulen, R. N. Schouten, C. Abellan, W. Amaya, V . Pruneri, M. W. Mitchell, M. Markham, D. J. Twitchen, D. Elkouss, S. Wehner, T. H. Taminiau, and R. Hanson, Nature 526, 682 (2015)

  10. [18]

    Giustina, M

    M. Giustina, M. A. M. Versteegh, S. Wengerowsky, J. Hand- steiner, A. Hochrainer, K. Phelan, F. Steinlechner, J. Kofler, J.- A. Larsson, C. Abell´an, W. Amaya, V . Pruneri, M. W. Mitchell, J. Beyer, T. Gerrits, A. E. Lita, L. K. Shalm, S. W. Nam, T. Scheidl, R. Ursin, B. Wittm...

  11. [19]

    L. K. Shalm, E. Meyer-Scott, B. G. Christensen, P. Bierhorst, M. A. Wayne, M. J. Stevens, T. Gerrits, S. Glancy, D. R. Hamel, M. S. Allman, K. J. Coakley, S. D. Dyer, C. Hodge, A. E. Lita, V . B. Verma, C. Lambrocco, E. Tortorici, A. L. Migdall, Y . Zhang, D. R. Kumor, W. H. F...

  12. [20]

    A. K. Ekert, Phys. Rev. Lett. 67, 661 (1991)

  13. [21]

    D. P. Nadlinger, P. Drmota, B. C. Nichol, G. Araneda, D. Main, R. Srinivas, D. M. Lucas, C. J. Ballance, K. Ivanov, E. Y .-Z. Tan, P. Sekatski, R. L. Urbanke, R. Renner, N. Sangouard, and J.-D. Bancal, Nature 607, 682 (2022)

  14. [22]

    Zhang, T

    W. Zhang, T. van Leent, K. Redeker, R. Garthoff, R. Schwon- nek, F. Fertig, S. Eppelt, W. Rosenfeld, V . Scarani, C. C.-W. Lim, and H. Weinfurter, Nature 607, 687 (2022)

  15. [23]

    Liu, Y .-Z

    W.-Z. Liu, Y .-Z. Zhang, Y .-Z. Zhen, M.-H. Li, Y . Liu, J. Fan, F. Xu, Q. Zhang, and J.-W. Pan, Phys. Rev. Lett. 129, 050502 (2022)

  16. [24]

    Bierhorst, E

    P. Bierhorst, E. Knill, S. Glancy, Y . Zhang, A. Mink, S. Jor- dan, A. Rommal, Y .-K. Liu, B. Christensen, S. W. Nam, M. J. Stevens, and L. K. Shalm, Nature 556, 223 (2018)

  17. [25]

    Y . Liu, Q. Zhao, M.-H. Li, J.-Y . Guan, Y . Zhang, B. Bai, W. Zhang, W.-Z. Liu, C. Wu, X. Yuan, H. Li, W. J. Munro, Z. Wang, L. You, J. Zhang, X. Ma, J. Fan, Q. Zhang, and J.-W. Pan, Nature 562, 548 (2018)

  18. [26]

    Storz, A

    S. Storz, A. Kulikov, J. D. Sch ¨ar, V . Barizien, X. Valcarce, F. Berterotti`ere, N. Sangouard, J.-D. Bancal, and A. Wallraff, (2024), arXiv:2408.01299 [quant-ph]

  19. [27]

    Colbeck and R

    R. Colbeck and R. Renner, Nat. Phys. 8, 450 (2012)

  20. [28]

    Kessler and R

    M. Kessler and R. Arnon-Friedman, IEEE Journal on Selected Areas in Information Theory 1, 568 (2020)

  21. [29]

    Storz, J

    S. Storz, J. Sch¨ar, A. Kulikov, P. Magnard, P. Kurpiers, J. L¨utolf, T. Walter, A. Copetudo, K. Reuer, A. Akin, J.-C. Besse, M. Gabureac, G. J. Norris, A. Rosario, F. Martin, J. Martinez, W. Amaya, M. W. Mitchell, C. Abellan, J.-D. Bancal, N. San- gouard, B. Royer, A. Blais, ...

  22. [30]

    Ekert and R

    A. Ekert and R. Renner, Nature 507, 443 (2014)

  23. [31]

    Frauchiger, R

    D. Frauchiger, R. Renner, and M. Troyer, arXiv:1311.4547 (2013), arXiv:1311.4547 [quant-ph]

  24. [32]

    RAND Coorporation, A Million Random Digits with 100,000 Normal Deviates (American Book Publishers, 2001)

  25. [33]

    R. L. Rivest, A. Shamir, and L. Adleman, Communications of the ACM 21, 120 (1978)

  26. [34]

    Heninger, Z

    N. Heninger, Z. Durumeric, E. Wustrow, and J. A. Halderman, in Proceedings of the 21st USENIX Security Symposium(2012)

  27. [35]

    A. K. Lenstra, J. P. Hughes, M. Augier, J. W. Bos, T. Kleinjung, and C. Wachter, IACR Cryptol. ePrint Arch. (2012)

  28. [36]

    Herrero-Collantes and J

    M. Herrero-Collantes and J. C. Garcia-Escartin, Rev. Mod. Phys. 89, 015004 (2017)

  29. [37]

    Dhara, G

    C. Dhara, G. de la Torre, and A. Ac ´ın, Phys. Rev. Lett. 112, 100402 (2014)

  30. [38]

    Hurley-Smith and J

    D. Hurley-Smith and J. Hernandez-Castro, ACM Transactions on Privacy and Security 23, 1 (2020)

  31. [39]

    Mayers and A

    D. Mayers and A. Yao, Quantum Information and Computation 4, 273 (2003)

  32. [40]

    Colbeck, Quantum And Relativistic Protocols For Secure Multi-Party Computation , Ph.D

    R. Colbeck, Quantum And Relativistic Protocols For Secure Multi-Party Computation , Ph.D. thesis, University of Cam- bridge (2009), arXiv:0911.3814 [quant-ph]

  33. [41]

    Pironio, A

    S. Pironio, A. Ac ´ın, S. Massar, A. B. de la Giroday, D. N. Mat- sukevich, P. Maunz, S. Olmschenk, D. Hayes, L. Luo, T. A. Manning, and C. Monroe, Nature 464, 1021 (2010)

  34. [42]

    B. G. Christensen, K. T. McCusker, J. B. Altepeter, B. Calkins, T. Gerrits, A. E. Lita, A. Miller, L. K. Shalm, Y . Zhang, S. W. Nam, N. Brunner, C. C. W. Lim, N. Gisin, and P. G. Kwiat, Phys. Rev. Lett. 111, 130406 (2013)

  35. [43]

    L. K. Shalm, Y . Zhang, J. C. Bienfang, C. Schlager, M. J. Stevens, M. D. Mazurek, C. Abell ´an, W. Amaya, M. W. Mitchell, M. A. Alhejji, H. Fu, J. Ornstein, R. P. Mirin, S. W. Nam, and E. Knill, Nature Physics 17, 452 (2021)

  36. [44]

    Liu, M.-H

    W.-Z. Liu, M.-H. Li, S. Ragy, S.-R. Zhao, B. Bai, Y . Liu, P. J. Brown, J. Zhang, R. Colbeck, J. Fan, Q. Zhang, and J.-W. Pan, Nature Physics (2021), 10.1038/s41567-020-01147-2

  37. [45]

    Gallego, L

    R. Gallego, L. Masanes, G. de la Torre, C. Dhara, L. Aolita, and A. Acin, Nat Commun (2013), arXiv:1210.6514 [quant-ph]

  38. [46]

    F. G. S. L. Brandao, R. Ramanathan, A. Grudka, K. Horodecki, M. Horodecki, P. Horodecki, T. Szarek, and H. Wojewodka, Nat Commun 7, 11345 (2016)

  39. [47]

    Blais, A

    A. Blais, A. L. Grimsmo, S. M. Girvin, and A. Wallraff, Rev. Mod. Phys. 93, 025005 (2021)

  40. [48]

    Schaer, S

    J. Schaer, S. Storz, P. Magnard, J. Luetolf, A. Kulikov, P. Kurpiers, R. Schlatter, N. Kohli, M. Frey, R. Keller, F. Marxer, A. Fauquex, M. Hinderling, S. Wili, T. Walter, N. Meinhardt, A. Schwarzer, and A. Wallraff, in preparation (2023)

  41. [49]

    Kurpiers, T

    P. Kurpiers, T. Walter, P. Magnard, Y . Salathe, and A. Wallraff, EPJ Quantum Technology 4, 8 (2017)

  42. [50]

    Magnard, S

    P. Magnard, S. Storz, P. Kurpiers, J. Sch¨ar, F. Marxer, J. L¨utolf, T. Walter, J.-C. Besse, M. Gabureac, K. Reuer, A. Akin, B. Royer, A. Blais, and A. Wallraff, Phys. Rev. Lett. 125, 260502 (2020)

  43. [51]

    Abell ´an, W

    C. Abell ´an, W. Amaya, D. Mitrani, V . Pruneri, and M. W. Mitchell, Phys. Rev. Lett. 115, 250403 (2015)

  44. [52]

    Magnard, P

    P. Magnard, P. Kurpiers, B. Royer, T. Walter, J.-C. Besse, S. Gasparinetti, M. Pechal, J. Heinsoo, S. Storz, A. Blais, and 20 A. Wallraff, Phys. Rev. Lett.121, 060502 (2018)

  45. [53]

    J. I. Cirac, P. Zoller, H. J. Kimble, and H. Mabuchi, Phys. Rev. Lett. 78, 3221 (1997)

  46. [54]

    Kurpiers, P

    P. Kurpiers, P. Magnard, T. Walter, B. Royer, M. Pechal, J. Heinsoo, Y . Salath´e, A. Akin, S. Storz, J.-C. Besse, S. Gas- parinetti, A. Blais, and A. Wallraff, Nature 558, 264 (2018)

  47. [55]

    Walter, P

    T. Walter, P. Kurpiers, S. Gasparinetti, P. Magnard, A. Potoˇcnik, Y . Salath´e, M. Pechal, M. Mondal, M. Oppliger, C. Eichler, and A. Wallraff, Phys. Rev. Appl.7, 054020 (2017)

  48. [56]

    Garg and N

    A. Garg and N. D. Mermin, Phys. Rev. D 35, 3831 (1987)

  49. [57]

    P. H. Eberhard, Phys. Rev. A 47, R747 (1993)

  50. [58]

    Larsson, J

    J.-A. Larsson, J. Phys. A: Math. Theor. 47, 424003 (2014)

  51. [59]

    Ac ´ın, N

    A. Ac ´ın, N. Brunner, N. Gisin, S. Massar, S. Pironio, and V . Scarani, Phys. Rev. Lett.98, 230501 (2007)

  52. [60]

    Santha and U

    M. Santha and U. V . Vazirani, Journal of Computer and System Sciences 33, 75 (1986)

  53. [61]

    Shaltiel, in Automata, Languages and Programming, edited by L

    R. Shaltiel, in Automata, Languages and Programming, edited by L. Aceto, M. Henzinger, and J. Sgall (Springer Berlin Hei- delberg, Berlin, Heidelberg, 2011) pp. 21–41

  54. [62]

    Arnon-Friedman, C

    R. Arnon-Friedman, C. Portmann, and V . B. Scholz, (2016), 10.4230/LIPICS.TQC.2016.2

  55. [63]

    Vazirani, in Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing , STOC ’87 (Association for Computing Machinery, New York, NY , USA, 1987) p

    U. Vazirani, in Proceedings of the Nineteenth Annual ACM Symposium on Theory of Computing , STOC ’87 (Association for Computing Machinery, New York, NY , USA, 1987) p. 160–168

  56. [64]

    Foreman, S

    C. Foreman, S. Wright, A. Edgington, M. Berta, and F. J. Cur- chod, Quantum 7, 969 (2023)

  57. [65]

    Rukhin, J

    A. Rukhin, J. Soto, J. Nechvatal, M. Smid, E. Barker, S. Leigh, M. Levenson, M. Vangel, D. Banks, N. Heckert, J. Dray, and S. V o, (2010)

  58. [66]

    Marsaglia and W

    G. Marsaglia and W. W. Tsang, Journal of Statistical Software 7 (2002), 10.18637/jss.v007.i03

  59. [67]

    Kelsey, L

    J. Kelsey, L. T. Brand˜ao, R. Peralta, and H. Booth, A reference for randomness beacons: Format and protocol version 2, Tech. Rep. (National Institute of Standards and Technology, 2019)

  60. [68]

    Dodis, S

    Y . Dodis, S. J. Ong, M. Prabhakaran, and A. Sahai, in 45th Annual IEEE Symposium on Foundations of Computer Science (2004) pp. 196–205

  61. [69]

    A. C. Yao, in 23rd Annual Symposium on Foundations of Com- puter Science (sfcs 1982) (1982) pp. 160–164

  62. [70]

    Goldreich, S

    O. Goldreich, S. Micali, and A. Wigderson (Association for Computing Machinery, New York, NY , USA, 1987) p. 218–229

  63. [71]

    Dodis, A

    Y . Dodis, A. Elbaz, R. Oliveira, and R. Raz, in Approximation, Randomization, and Combinatorial Optimization. Algorithms and Techniques, edited by K. Jansen, S. Khanna, J. D. P. Rolim, and D. Ron (Springer Berlin Heidelberg, Berlin, Heidelberg,

  64. [72]

    Brunner, D

    N. Brunner, D. Cavalcanti, S. Pironio, V . Scarani, and S. Wehner, Rev. Mod. Phys.86, 419 (2014)

  65. [73]

    P ¨utz, D

    G. P ¨utz, D. Rosset, T. J. Barnea, Y .-C. Liang, and N. Gisin, Phys. Rev. Lett. 113, 190402 (2014)

  66. [74]

    Renner, Security of Quantum Key Distribution , Ph.D

    R. Renner, Security of Quantum Key Distribution , Ph.D. the- sis, ETH Zurich (2005), available at http://arxiv.org/abs/quant- ph/0512258

  67. [75]

    Tomamichel and M

    M. Tomamichel and M. Hayashi, IEEE Transactions on Infor- mation Theory 59, 7693–7710 (2013)

  68. [76]

    Dupuis, O

    F. Dupuis, O. Fawzi, and R. Renner, Communications in Math- ematical Physics 379, 867 (2020)

  69. [77]

    Storz, Non-local Physics with Superconducting Circuits , Ph.D

    S. Storz, Non-local Physics with Superconducting Circuits , Ph.D. thesis, ETH Zurich (2023)

  70. [78]

    M.-H. Li, C. Wu, Y . Zhang, W.-Z. Liu, B. Bai, Y . Liu, W. Zhang, Q. Zhao, H. Li, Z. Wang, L. You, W. J. Munro, J. Yin, J. Zhang, C.-Z. Peng, X. Ma, Q. Zhang, J. Fan, and J.-W. Pan, Phys. Rev. Lett. 121, 080404 (2018)

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.