REVIEW 2 major objections 4 minor 44 references
Security Evaluation of Laser-Phase-Noise Quantum Random Number Generators with Intrinsic Correlations
T0 review · 2 major / 4 minor · reviewed 2026-08-02 · deepseek-v4-flash
Pith's one-line read Single-laser phase-noise QRNGs carry intrinsic temporal correlations that can be captured by a closed-form conditional min-entropy; ignoring them overstates extractable randomness by about 46% in typical compact setups.
desk verdict The correlation coefficient formula is a genuine, well-validated result, but the conditional min-entropy is built on a false Markovian assumption and the reported numbers don't reproduce, so the central security claim does not hold. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying mechanism is the overlap of the two phase-evolution intervals [t - T_d, t] and [t + kT_s - T_d, t + kT_s] under a Wiener (random-walk) model of laser phase. That overlap produces a hyperbolic-sine covariance, leading to the closed-form correlation coefficient of Eq. (6). The same bivariate Gaussian conditional distribution, with variance scaled by 1 - rho^2, is then used to convert the correlation coefficient into bits per sample through Eq. (16), including a signal-to-noise penalty that removes classical electrical noise from the entropy budget.
What would settle it
Compute the conditional min-entropy of the recorded 5.25 ns-delay raw data by conditioning on the full correlated window (lags k=1 through about 10) using the covariance matrix in Eq. (B1), and compare with the bivariate value of 4.51 bits/sample at 20 dB SNR; if the full conditioning gives a lower value, the simplified formula overestimates extractable randomness.
Extended reading notes
Core claim
The paper's central claim is that the raw output of a single-laser phase-noise QRNG is a multivariate Gaussian sequence whose correlation structure is fully determined by the overlap of phase-evolution intervals, and that this structure can be written in closed form. For a Wiener-process phase with coherence time tau_c, delay T_d, and sampling period T_s, the k-lag autocorrelation is rho_X(k) = sinh(2(T_d - kT_s)/tau_c) / sinh(2T_d/tau_c). From this the paper derives an analytical conditional min-entropy that conditions on the nearest correlated sample and on full knowledge of electrical noise, giving 5.80 bits/sample for the experimental parameters without noise (versus 7.02 bits/sample und
Load-bearing premise
The load-bearing premise is that after conditioning on the nearest neighbor, no other correlated sample adds exploitable information — the paper calls this Markovian — but its own Wiener model yields substantial correlations at lags 2, 3, and beyond, so this premise is what carries the analytical entropy formula.
Editorial extensions
If this is right
- Compact QRNGs with short delays can be deployed with a defensible security bound, because the correlation penalty is quantifiable rather than neglected.
- Existing phase-noise QRNG entropy rates that assume i.i.d. samples may overstate secure bits by roughly a fifth without electrical noise and by roughly 46% when electrical noise is present.
- The correlation formula gives device designers a direct trade-off: increasing T_d or tau_c relative to T_s lowers rho and raises conditional min-entropy, at the cost of delay-line length and generation speed.
- Eq. (16) can be used as an online security monitor by measuring the total variance, the electrical-noise variance, and the first-lag correlation coefficient of the digitized signal.
- The framework extends to other laser-phase-noise architectures, since it relies only on the Wiener phase model and the overlap of phase increments.
Reading between the lines
- Our inference: because Eq. (6) gives strong correlation at lags beyond k=1 (rho_X(2) is about 0.81 in the experimental setup), the bivariate Eq. (16) is best read as an upper bound on conditional min-entropy; conditioning on the full correlated window would likely reduce the extractable bits further, making the 46% gap a lower bound on the cost of ignoring correlations.
- Our inference: the same overlap calculation can be inverted as a self-test — checking whether measured rho_Y(k) follows Eq. (6) at all lags would reveal deviations from the Wiener model, such as 1/f phase noise or detector memory, that should invalidate the entropy estimate.
- Our inference: because the derivation depends only on the covariance of a Gaussian process, the method could be adapted to other entropy sources with known Gaussian temporal covariance, not just laser phase noise.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper addresses intrinsic temporal correlations in single-laser phase-noise QRNGs. The authors model the laser phase as a Wiener process and derive a closed-form k-lag autocorrelation coefficient (Eq. 6) for the detected signal V=sin(Δφ). They verify this expression by numerical simulation and experiment across three regimes (Td>>τc, Td≈τc, Td<<τc). They then propose an analytical conditional min-entropy (Eqs. 9 and 16) for the quantized samples by reducing the conditioning from the full 2β-neighbor set to the nearest neighbor, claiming a Markovian property. Including electronic noise as adversarial side information, they report that the i.i.d. assumption overestimates extractable randomness by approximately 46% in a typical setup (Td=5.25 ns, Ts=0.5 ns, τc=53.05 ns).
Significance. The correlation model is simple, explicit, and well supported: Eq. (6) is validated by independent numerical and experimental data without fitted parameters, which is a genuine contribution for assessing correlation strength in such QRNGs. However, the main advertised result—analytical conditional min-entropy—is not reliably established. The reduction to a bivariate Gaussian is based on a false Markovian premise; hence Eqs. (9) and (16) do not provide a conservative security bound. If corrected, the paper could serve as a useful correlation model, but the entropy claim and the 46% security-gap figure require substantial revision.
major comments (2)
- [Accounting for correlation (after Eq. 8)] The reduction from the 2β-dimensional neighbor set to the nearest neighbor rests on the assertion 'Leveraging the Markovian property of the source.' Under the paper's own Wiener model, the sampled phase increments Δφ(mTs)=φ(mTs)-φ(mTs-Td) form a moving-average process of order roughly Td/Ts (β−1=9 for the experimental parameters), not a first-order Markov chain; the sine nonlinearity cannot create first-order Markovianity. For a multivariate Gaussian, conditioning on additional neighbors strictly reduces the conditional variance, so the bivariate conditional min-entropy of Eqs. (9) and (16) is an upper bound on the true value, not a conservative estimate. This matters quantitatively: with Td=5.25 ns, Ts=0.5 ns, τc=53.05 ns, Eq. (6) gives ρ_X(2)≈0.81, so the second neighbor is nearly as informative as the first. The paper provides no bound on the error from truncating the conditioning set
- [Experimental demonstration / Eq. (16)] Because Eq. (16) is not a valid lower bound on extractable randomness, the quantitative claims built on it—H_min(Y^dis_m|Y^dis_{m-k},E)=4.51 bits/sample and the 46% overestimation relative to H_iid-E=6.60 bits/sample—are not supported. Additionally, H_iid-E is imported from the companion work [32] without derivation; even if Eq. (16) were correct, this comparison value should either be derived in the appendix or referenced with sufficient detail to be independently verifiable.
minor comments (4)
- [Eq. (6) / Appendix A (Eq. A5)] For kTs > Td, the expression gives negative values, whereas the physical covariance is zero (as stated in the text before Eq. (4)). The formula should be written with max(0,·) or a case distinction.
- [Appendix B, Eq. (B1)] The vector definition '𝑿joint=[𝑋𝑚−𝛽, 𝑋𝑚−𝛽+2, …, 𝑋𝑚, …, 𝑋𝑚+𝛽−2, 𝑋𝑚+𝛽]' appears to contain typographical errors in the indices; presumably it should list all indices consecutively.
- [Notation] The conditioning set notation is inconsistent: Eq. (8) writes H_min(X_m^dis|X_t^dis) while Eq. (9) uses H_min(X_m^dis|X_{m-k}^dis). The conditioning set should be explicit throughout.
- [Experimental results] The phrase 'thereby introducing potential security' in the experimental section should be 'introducing a security vulnerability.'
Circularity Check
No significant circularity: correlation and conditional-entropy formulas are derived from an explicit Wiener-process model; the only self-citation is a comparison baseline that is not load-bearing.
full rationale
The core derivation chain is self-contained. The correlation coefficient rho_X(k) in Eq. (6) follows from the explicit Wiener-process model and the joint-Gaussian characteristic function, and its agreement with numerical simulation and experiment (Figs. 2 and 3) is independent evidence, not an input fitted to the entropy result. The conditional min-entropy expressions, Eqs. (9) and (16), are obtained by substituting the bivariate Gaussian conditional variance sigma_X^2(1-rho_X^2) and the quantization step; they are not fitted to the reported entropy values (5.80 and 4.51 bits/sample), which are evaluations of the formulas. No parameter is renamed as a prediction, and no uniqueness theorem from the authors' prior work is invoked to force the choice. The only self-citation entering a quantitative comparison is [32], used for the i.i.d.-with-electrical-noise baseline: 'H_min^{iid-E} = 6.60 bits/sample with i.i.d. assumption[32]'. That baseline appears in the 'approximately 46%' overestimation statement, but it is not used to derive the paper's conditional entropy expressions, and those expressions do not reduce to it. It is therefore a minor, non-load-bearing self-citation. The reduction of the full 2beta-dimensional conditioning set to a single nearest neighbor via 'Leveraging the Markovian property of the source' is a potentially serious modeling/security-analysis concern: under the paper's own Wiener model the sampled phase increments form a moving-average process, so Eq. (16) may not bound the genuine conditional min-entropy. That is a validity weakness, not circularity: the bivariate formulas are explicitly stated simplifications rather than identities smuggled in as predictions. Overall, the advertised correlation model and entropy formula have independent content and are not circular in the sense of reproducing their inputs by construction.
Assumptions & free parameters
free parameters (2)
- SNR =
20 dB (assumed)
- ADC range convention =
R_X=A; R_Y=±6σ_Y
assumptions (4)
- domain assumption Laser phase noise φ(t) is a Wiener process with Lorentzian linewidth Δν=1/(πτ_c)
- ad hoc to paper Sampled phase-difference sequence can be treated as Markov in the nearest neighbor
- domain assumption Electrical noise is Gaussian, independent of quantum signal, and fully known to the adversary
- domain assumption Discrete maximum conditional probability ≈ peak continuous conditional PDF × bin width
Cite this review
Pith. "Pith review of Security Evaluation of Laser-Phase-Noise Quantum Random Number Generators with Intrinsic Correlations." pith.science (2026). https://pith.science/paper/4FHIAATO
@misc{pith2026260713521,
author = {Pith},
title = {Pith review of: Security Evaluation of Laser-Phase-Noise Quantum Random Number Generators with Intrinsic Correlations},
year = {2026},
howpublished = {\url{https://pith.science/paper/4FHIAATO}},
note = {Machine review of arXiv:2607.13521}
}
read the original abstract
Quantum random number generators are essential for achieving information-theoretical security in modern cryptographic systems. Among various implementations, laser phase noise schemes are widely favored for their simple architecture and high integration potential. However, the intrinsic correlations in the raw data are often neglected, which violates the independent and identically distributed assumption and potentially compromises system security. In this work, we establish an analytical model of correlation and formulate an analytical expression for the conditional min-entropy in the presence of intrinsic correlations to accurately quantify the genuinely extractable randomness. The validity of our theoretical model is confirmed by numerical simulations and experimental results, exhibiting excellent agreement. Under typical setups it is shown that neglecting intrinsic correlations leads to an overestimation of extractable randomness by approximately 46%. This work provides a valuable theoretical framework for designing compact, high-performance quantum random number generators with rigorous security analysis.
Figures
Reference graph
Works this paper leans on
-
[32]
J. Liu, J. Yang, Y. Gao, G. Zhang, Y. Pan, H. Wang, Y. Ding, Y. Li, W. Huang, B. Xu, and W. Chen, Performance Optimization Method for Laser-Phase-Noise Based Quantum Random Number Generation, arXiv:2604.14511 (2026)
arXiv 2026
-
[1]
S. L. Lohr, Sampling: Design and Analysis (Chapman and Hall/CRC, 2021)
2021
-
[2]
Metropolis and S
N. Metropolis and S. Ulam, J. Am. Stat. Assoc. 44, 335 (1949)
1949
-
[3]
Herrero-Collantes and J
M. Herrero-Collantes and J. C. Garcia-Escartin, Rev. Mod. Phys. 89, 015004 (2017)
2017
-
[4]
Gisin, G
N. Gisin, G. Ribordy, W. Tittel, and H. Zbinden, Rev. Mod. Phys. 74, 145 (2002)
2002
-
[5]
Schneier, Applied Cryptography (Wiley, 1996)
B. Schneier, Applied Cryptography (Wiley, 1996)
1996
-
[6]
D. E. Knuth, The Art of Computer Programming: Seminumerical Algorithms, Volume 2 (Addison -Wesley Professional, 2014)
2014
-
[7]
P. A. M. Dirac, The Principles of Quantum Mechanics (Oxford University Press, 1981)
1981
Show all 44 references
-
[8]
Bruynsteen, T
C. Bruynsteen, T. Gehring, C. Lupo, J. Bauwelinck, and X. Yin, PRX Quantum 4, 010330 (2023)
2023
-
[9]
Gehring, C
T. Gehring, C. Lupo, A. Kordts, D. Solar Nikolic, N. Jain, T. Rydberg, T. B. Pedersen, S. Pirandola, and U. L. Andersen, Nat. Commun. 12, 605 (2021)
2021
-
[10]
Gabriel, C
C. Gabriel, C. Wittmann, D. Sych, R. Dong, W. Mauerer, U. L. Andersen, C. Marquardt, and G. Leuchs, Nat. Photonics 4, 711 (2010)
2010
-
[11]
J. Li, Z. Huang, C. Yu, J. Wu, T. Zhao, X. Zhu, and S. Sun, Opt. Express 32, 5056 (2024)
2024
-
[12]
J. Yang, F. Fan, J. Liu, Q. Su, Y. Li, W. Huang, and B. Xu, Quantum Sci. Technol. 6, 015002 (2021)
2021
-
[13]
J.-Y. Haw, S. M. Assad, A. M. Lance, N. H. Y. Ng, V. Sharma, P. K. Lam, and T. Symul, Phys. Rev. Appl. 3, 054004 (2015). 13
2015
-
[14]
Álvarez, S
J.-R. Álvarez, S. Sarmiento, J. A. Lá zaro, J. M. Gené , and J. P. Torres, Opt. Express 28, 5538 (2020)
2020
-
[15]
Raffaelli, G
F. Raffaelli, G. Ferranti, D. H. Mahler, P. Sibson, J. E. Kennard, A. Santamato, G. Sinclair, D. Bonneau, M. G. Thompson, and J. C. F. Matthews, Quantum Sci. Technol. 3, 025003 (2018)
2018
-
[16]
X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, npj Quantum Inf. 2, 1 (2016)
2016
-
[17]
Lovic, D
V. Lovic, D. G. Marangon, M. Lucamarini, Z. Yuan, and A. J. Shields, Phys. Rev. Appl. 16, 054012 (2021)
2021
-
[18]
Qi, Y.-M
B. Qi, Y.-M. Chi, H.-K. Lo, and L. Qian, Opt. Lett. 35, 312 (2010)
2010
-
[19]
H. Zhou, X. Yuan, and X. Ma, Phys. Rev. A 91, 062316 (2015)
2015
-
[20]
Y.-Q. Nie, L. Huang, Y. Liu, F. Payne, J. Zhang, and J.-W. Pan, Rev. Sci. Instrum. 86, 063105 (2015)
2015
-
[21]
F. Xu, B. Qi, X. Ma, H. Xu, H. Zheng, and H.-K. Lo, Opt. Express 20, 12366 (2012)
2012
-
[22]
J. Yang, J. Liu, Q. Su, Z. Li, F. Fan, B. Xu, and H. Guo, Opt. Express 24, 27475 (2016)
2016
-
[23]
J. Liu, J. Yang, Z. Li, Q. Su, W. Huang, B. Xu, and H. Guo, IEEE Photonics Technol. Lett. 29, 283 (2017)
2017
-
[24]
Abellan, W
C. Abellan, W. Amaya, D. Domenech, P. Muñ oz, J. Capmany, S. Longhi, M. W. Mitchell, and V. Pruneri, Optica 3, 989 (2016)
2016
-
[25]
T. K. Paraiso, T. Roger, D. G. Marangon, I. De Marco, M. Sanzaro, R. I. Woodward, J. F. Dynes, Z. Yuan, and A. J. Shields, Nat. Photonics 15, 850 (2021)
2021
-
[26]
Chrysostomidis, I
T. Chrysostomidis, I. Roumpos, D. A. Outerelo, M. Troncoso -Costas, V. Moskalenko, J. C. Garcia -Escartin, F. J. Diaz - Otero, and K. Vyrsokinos, EPJ Quantum Technol. 10, 5 (2023)
2023
-
[27]
D. G. Marangon, P. R. Smith, N. Walk, T. K. Para ı̈so, J. F. Dynes, V. Lovic, M. Sanzaro, T. Roger, I. De Marco, M. Lucamarini, et al., Nat. Electron. 7, 396 (2024)
2024
-
[28]
J. Yang, M. Wu, Y. Zhang, Y. Li, W. Huang, H. Wang, Y. Pan, Q. Su, Y. Bian, and H. Jiang (et al.), Commun. Phys. 8, 42 (2025)
2025
-
[29]
H. Guo, W. Tang, Y. Liu, and W. Wei, Phys. Rev. E 81, 051137 (2010)
2010
-
[30]
Sö nmez Turan, E
M. Sö nmez Turan, E. Barker, J. Kelsey, K. McKay, M. Baish, and M. Boyle, Recommendation for the Entropy Sources Used for Random Bit Generation, Tech. Rep. (National Institute of Standards and Technology, 2016)
2016
-
[31]
W. Lei, Z. Xie, Y. Li, J. Fang, and W. Shen, Quantum Inf. Process. 19, 405 (2020)
2020
-
[33]
Henry, J
C. Henry, J. Lightwave Technol. 4, 298 (1986)
1986
-
[34]
Lax, Phys
M. Lax, Phys. Rev. 160, 290 (1967)
1967
-
[35]
Yariv and P
A. Yariv and P. Yeh, Photonics: Optical Electronics in Modern Communications (Oxford University Press, 2007)
2007
-
[36]
Stipčević and B
M. Stipčević and B. M. Rogina, Rev. Sci. Instrum. 78, 043104 (2007)
2007
-
[37]
Impagliazzo, R
R. Impagliazzo, R. Jaiswal, V. Kabanets, and A. Wigderson, in Proceedings of the Fortieth Annual ACM Symposium on Theory of Computing, 579 (2008)
2008
-
[38]
M. G. A. Paris, Phys. Rev. A 53, 2658 (1996)
1996
-
[39]
M. B. Priestley, Spectral Analysis and Time Series (Academic Press, 1981)
1981
-
[40]
M. H. Kalos and P. A. Whitlock, Monte Carlo Methods (John Wiley & Sons, 2008)
2008
-
[41]
Binder and D
K. Binder and D. W. Heermann, Monte Carlo Simulation in Statistical Physics, Vol. 8 (Springer, 1992)
1992
-
[42]
S. M. Ross, Introduction to Probability Models (Academic Press, 2014)
2014
-
[43]
T. M. Cover, Elements of Information Theory (John Wiley & Sons, 1999)
1999
-
[44]
Papoulis, Probability, Random Variables, and Stochastic Processes, 3rd ed
A. Papoulis, Probability, Random Variables, and Stochastic Processes, 3rd ed. (McGraw-Hill, New York, 1991)
1991
Reviewed August 2, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.