Maximal global device-independent randomness from projective measurements in every dimension


Abstract

Device-independent random number generation (DIQRNG) is the most secure form of generating private randomness using quantum physical processes. Its strength lies in producing numbers that are impossible to predict by any eavesdropper restricted by the laws of quantum theory. Moreover, security is proven solely from observed measurement statistics, without the need to characterise or trust the devices used in random number generation. Implementing DIQRNG is, however, costly, as it requires high-quality entangled systems. It is therefore important to make the best use of available resources. In this work, we show that using projective measurements—which are most readily implementable experimentally—one can certify \(2\log(d)\) bits of device-independent randomness from a bipartite system of local dimension \(d\) for every \(d \ge 2\), thus reaching the theoretically maximum possible rate of DIQRNG. We provide explicit protocols reaching \(2\log(d)\) bits based on mutually unbiased bases. Furthermore, we compute numerical bounds on the rate for the case of imperfect implementations, showing that our protocols are robust to experimental noise.

Introduction.— Device-independent random number generation (DIQRNG) makes it possible to certify the randomness of the outcomes of certain quantum measurements even if the underlying quantum state and the measurements are completely uncharacterised. As long as the standard assumptions of Bell non-locality [1] are satisfied, numbers generated by a DIQRNG protocol cannot be predicted by any eavesdropper limited by the laws of quantum mechanics [2], [3]. Such secure random numbers find applications in cryptography [4], as the security of most cryptographic protocols depends on private random numbers [5].

DIQRNG protocols operate in a Bell scenario: two trusted parties share a pair of entangled quantum systems, each measure one of the systems and record their measurement choices (‘settings’) and outcomes [6], [7]. They collect the measurement statistics (often referred to as the correlation), and infer their conclusions—in particular the private randomness of their measurement outcomes—from the observed correlation.

DIQRNG is technologically challenging [8]. Among other difficulties, scaling up the number of degrees of freedom (the dimension) of the quantum system is complicated in practice. Since the dimension limits the amount of certifiable randomness per measurement (which is easily seen for projective measurements, see the next section), it is important to devise protocols that certify as much randomness as possible in a given dimension.

It has been shown [9] that the maximal possible, \(2 \log(d)\) bits, of device-independent randomness can be certified by a single party (i.e. locally) using generalised, non-projective measurements. That work leaves several questions open, one of them being the practical question of how much device-independent randomness can be certified by both parties (i.e. globally)? This work answers this question for the case of projective measurements, which are the most practical to implement experimentally. In particular, we show that the maximum theoretically possible amount of global randomness using projective measurements—also \(2 \log(d)\) bits—can be certified in every dimension \(d\). Up to our knowledge, so far this has only been known for the case of \(d=2\) [10], [11]. Furthermore, we numerically prove that our DIQRNG protocols are robust to noise. That is, close-to-perfect experiments certify close to \(2 \log(d)\) bits of global randomness.

Preliminaries.— In a Bell scenario, two parties—Alice and Bob—share a pair of entangled quantum systems and perform measurements on them. Alice chooses a measurement setting \(x\) from a finite alphabet and observes an outcome \(a\) also from a finite alphabet. Similarly, Bob chooses \(y\) and observes \(b\). According to quantum theory, the probability of outcomes \(a\) and \(b\) given settings \(x\) and \(y\) is given by \[p(a,b|x,y) = \mathop{\mathrm{tr}}[ (A^x_a \otimes B^y_b) \rho ],\] where \(\rho\) is a quantum state (positive semidefinite operator with unit trace) on a tensor product Hilbert space \(\mathcal{H}_A \otimes \mathcal{H}_B\), \((A^x_a)_a\) is a positive operator-valued measure (POVM) on \(\mathcal{H}_A\) for every \(x\) (that is, \(A^x_a\) are positive semidefinite operators adding up to the identity on \(\mathcal{H}_A\)) and \((B^y_b)_b\) is a POVM on \(\mathcal{H}_B\) for every \(y\). In this work, we assume Hilbert spaces to be finite-dimensional.

The aim of DIQRNG is to certify randomness based only on the observed probabilities (the correlation). In particular, the amount of randomness certifiable from the outcomes of the measurements \(x\) and \(y\) can be quantified using the classical-quantum state [12] \[\label{eq:ccq95state} \begin{align} \sigma^{x,y}_{\mathrm{A}\mathrm{B}E} = & \left. \sum_{a,b} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\right. \\ & \left. \otimes \mathop{\mathrm{tr}}_{AB}[ ( A^x_a \otimes B^y_b \otimes \mathbb{I}_E ) |\psi \rangle \langle \psi|], \right. \end{align}\tag{1}\] where \(\{ | a \rangle_\mathrm{A}\}_a\) is an orthonormal basis of a Hilbert space with the same dimension as the number of possible outcomes of Alice, and \(\{ | b \rangle_\mathrm{B}\}_b\) is similarly defined (note that these Hilbert spaces are denoted using an upright \(\mathrm{A}\) and \(\mathrm{B}\), whereas the Hilbert spaces of the quantum state are italic \(A\) and \(B\)). Furthermore, \(| \psi \rangle\) is a purification of the state used to obtain \(p(a,b|x,y)\); in other words, we have \(p(a,b|x,y) = \langle \psi |(A^x_a \otimes B^y_b \otimes \mathbb{I}_E) | \psi \rangle\).

Crucially, in DIQRNG we don’t have information about the underlying state (\(\rho\) or \(| \psi \rangle\)) and measurements (\(A^x_a\) and \(B^y_b\)). All claims are made based only on the observed correlation. The device-independent randomness is thus characterised by the conditional von-Neumann entropy \(H(\mathrm{A},\mathrm{B}|E)\) of the state in Eq. 1 , minimised over all states \(| \psi \rangle\) and all POVMs \(A^x_a\) and \(B^y_b\) compatible with the observed correlation [12]. The intuition behind this formula is that it quantifies the uncertainty in the measurement outcomes of Alice and Bob, given quantum side information of a potential eavesdropper Eve, who holds a purification of the state shared between Alice and Bob. This uncertainty then has to be minimised over all possible realisations of the observed correlation in order to obtain the most conservative randomness estimate. When the correlation arises from a locally \(d\)-dimensional state (i.e. \(\dim \mathcal{H}_A = \dim \mathcal{H}_B = d\)) and projective measurements, then \(H(\mathrm{A},\mathrm{B}|E)\) cannot be larger than \(2 \log(d)\), since projective measurements have at most \(d\) outcomes.

To bound device-independent randomness, we often use a Bell inequality [1], which is a linear functional of correlations, \(\hat{W}(p) = \sum_{a,b,x,y} c_{abxy} p(a,b|x,y)\) for some \(c_{abxy} \in \mathbb{R}\). The value of a Bell inequality for a given state \(\rho\) and collection of POVMs \(\mathcal{A}= ((A^x_a)_a)_x\) and \(\mathcal{B}= ((B^y_b)_b)_y\) can be expressed in terms of the Bell operator, \(W(\mathcal{A}, \mathcal{B}) = \sum_{a,b,x,y} c_{abxy} A^x_a \otimes B^y_b\), through \(\hat{W}(p) = \mathop{\mathrm{tr}}[W(\mathcal{A}, \mathcal{B}) \rho]\). In certain cases, observing the maximal possible value of a Bell inequality certifies useful information about the state and measurements used in the experiment. An often used technique to obtain such certification is a sum-of-squares (SOS) decomposition. An SOS decomposition [13], [14] is an operator inequality satisfied by the Bell operator which has the form \[\label{eq:SOS} \beta \mathbb{I}- W(\mathcal{A}, \mathcal{B}) \ge \sum_j P_j^\dagger(\mathcal{A},\mathcal{B}) P_j(\mathcal{A},\mathcal{B})\tag{2}\] for some \(\beta \in \mathbb{R}\) and operator-valued functions \(P_j\), where the operator inequality holds under the assumption that \(\mathcal{A}\) and \(\mathcal{B}\) are collections of POVMs. Note that the right-hand side of Eq. 2 is positive semidefinite by design, and therefore constructing an SOS decomposition proves that \(\hat{W}(p) = \mathop{\mathrm{tr}}[W(\mathcal{A},\mathcal{B}) \rho] \le \beta\) for any state \(\rho\) and measurements \(\mathcal{A}\) and \(\mathcal{B}\).

Moreover, if \(\hat{W}(p) = \beta\) can be attained with some state \(\rho\) and POVMs \(\mathcal{A}\) and \(\mathcal{B}\), then these must satisfy \(\mathop{\mathrm{tr}}[ P_j^\dagger(\mathcal{A},\mathcal{B}) P_j(\mathcal{A},\mathcal{B}) \rho] = 0\) which also implies \(P_j(\mathcal{A},\mathcal{B}) \rho = 0\) for all \(j\). These equations constrain the state and measurements that give rise to the maximal value of the Bell inequality. In some cases, these constraints are sufficient to compute the conditional entropy of all classical-quantum states of the form in Eq. 1 that are compatible with the observed correlations.

Results.— To certify \(2 \log(d)\) bits of global randomness in every dimension \(d\) using locally \(d\)-dimensional states and projective measurements, we use a variant of a family of Bell inequalities originally introduced in Ref. [15] . The Bell inequalities are parametrised by an integer \(d \ge 2\). In the ideal realisation, \(d\) is also the local dimension of the state, but importantly, \(d\) is simply a parameter of the Bell inequality. In the Bell scenario, Alice has two settings, \(x \in \{1,2\}\) with \(d\) outcomes each labelled by \(a \in \{1, 2, \ldots, d\} =: [d]\). Bob has \(d^2+1\) settings. The first \(d^2\) are labelled by \(jk\) where \(j,k \in [d]\), and each of these have three outcomes, labelled by \(b \in \{1,2,3\}\). Bob’s last measurement setting is labelled by \(\mathbf{r}\) (for “randomness”) and this has \(d\) outcomes. Alice and Bob aim to generate randomness from their settings ‘2’ and ‘\(\mathbf{r}\)’, respectively.

The Bell inequality used to certify randomness is \[\label{eq:Bell} \begin{align} \hat{W}_d(p) = & \left. \sum_{j,k=1}^{d} \Big[ p(j,1|1,jk) - p(j,2|1,jk) \right. \\ & \left. + p(k,2|2,jk) - p(k,1|2,jk) \Big] \right. \\ & \left. - \frac{1}{2} \sqrt{ \frac{d-1}{d} } \sum_{j,k=1}^{d} \big[ p_B(1|jk) + p_B(2|jk) \big] \right. \\ & \left. + \sum_{j=1}^{d} p(j,j|1,\mathbf{r}), \right. \end{align}\tag{3}\] where \(p_B\) is Bob’s marginal distribution. The first two sums correspond exactly to the Bell inequalities from Ref. [15]. The new element is the addition of the setting \(\mathbf{r}\) to Bob’s side, which features in the last term of \(\hat{W}_d\).

From Ref. [15], we know that the maximal quantum value achievable for the first two sums is \(\sqrt{d(d-1)}\) and this can be reached by a locally \(d\)-dimensional state and projective measurements. This implies that the maximal quantum value of \(\hat{W}_d\) is \(\sqrt{d(d-1)} + 1\). In order to reach this maximal value, the first two sums must be maximised, which certifies the following properties [15][17]: for every purification \(| \psi \rangle_{ABE}\) of the bipartite state \(\rho\) on \(\mathcal{H}_A \otimes \mathcal{H}_B\) used to reach the maximal violation, there exist Hilbert spaces \(\mathcal{H}_{A'}\) and \(\mathcal{H}_{B'}\), local isometries \(V_A : \mathcal{H}_A \to \mathbb{C}^d \otimes \mathcal{H}_{A'}\) and \(V_B : \mathcal{H}_B \to \mathbb{C}^d \otimes \mathcal{H}_{B'}\) such that \[\begin{align} \label{eq:selftest1} (V_A \otimes V_B \otimes \mathbb{I}_E)(A^1_j \otimes \mathbb{I}_B \otimes \mathbb{I}_E)|\psi \rangle_{ABE} \\ \nonumber = (|j \rangle \langle j| \otimes \mathbb{I}_{\mathbb{C}^d}) |\phi^+_d \rangle \otimes |\text{aux} \rangle_{A'B'E}, \end{align}\tag{4}\] where \(\{ | j \rangle \}_{j=1}^d\) is the computational basis on \(\mathbb{C}^d\) and \(| \phi^+_d \rangle = \frac{1}{\sqrt{d}} \sum_{j=1}^d | j \rangle \otimes | j \rangle \in \mathbb{C}^d \otimes \mathbb{C}^d\) is the maximally entangled state. Eq. 4 also implies (summing over \(j\)) that \[\label{eq:selftest2} (V_A \otimes V_B \otimes \mathbb{I}_E)|\psi \rangle_{ABE} = |\phi^+_d \rangle \otimes |\text{aux} \rangle_{A'B'E}.\tag{5}\] Furthermore, Alice’s measurements satisfy the algebraic relations (when acting on the state) \[\begin{align} \label{eq:selftest3} (A^1_j A^2_k A^1_j \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle_{ABE} = \frac{1}{d} (A^1_j \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle_{ABE} \end{align}\tag{6}\] for all \(j,k \in [d]\). Summing the above over \(k\), we also see that \(A^1_j\) act on the state as projections, that is, \[\begin{align} \label{eq:selftest4} ( ( A^1_j )^2 \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle_{ABE} = (A^1_j \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle_{ABE}. \end{align}\tag{7}\] In particular, any pair of \(d\)-dimensional mutually unbiased bases [18] satisfies these relations.

The last term in \(\hat{W}_d\) in Eq. 3 is bounded by 1, and the Bell operator corresponding to this term is \(\sum_{j=1}^d A^1_j \otimes B^\mathbf{r}_j\). Notice that \[(A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2 = (A^1_j)^2 \otimes \mathbb{I}+ \mathbb{I}\otimes (B^\mathbf{r}_j)^2 - 2A^1_j \otimes B^\mathbf{r}_j,\] and therefore \[A^1_j \otimes B^\mathbf{r}_j = \frac{1}{2}\big[ (A^1_j)^2 \otimes \mathbb{I}+ \mathbb{I}\otimes (B^\mathbf{r}_j)^2 \big] - \frac{1}{2} (A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2.\] This leads to the operator inequality \[\label{eq:SOS95lastbit} \begin{align} & \left. \sum_{j=1}^d A^1_j \otimes B^\mathbf{r}_j = \frac{1}{2} \sum_{j=1}^{d} \big[ (A^1_j)^2 \otimes \mathbb{I}+ \mathbb{I}\otimes (B^\mathbf{r}_j)^2 \big] \right. \\ & \left. \quad - \sum_{j=1}^{d}\frac{1}{2} (A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2 \right. \\ & \left. \le \frac{1}{2} \sum_{j=1}^{d} \big[ A^1_j \otimes \mathbb{I}+ \mathbb{I}\otimes B^\mathbf{r}_j \big] - \sum_{j=1}^{d}\frac{1}{2} (A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2 \right. \\ & \left. = \mathbb{I}- \sum_{j=1}^{d}\frac{1}{2} (A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2 \right. \end{align}\tag{8}\] where the inequality comes from the fact that \((A^1_j)^2 \le A^1_j\) and \((B^\mathbf{r}_j)^2 \le B^\mathbf{r}_j\). Rearranging Eq. 8 is an SOS decomposition for the last term in the Bell inequality, \(\mathbb{I}- \sum_{j=1}^d A^1_j \otimes B^\mathbf{r}_j \ge \sum_{j=1}^{d}\frac{1}{2} (A^1_j \otimes \mathbb{I}- \mathbb{I}\otimes B^\mathbf{r}_j)^2\). To reach the maximal value, we therefore need that for all \(j \in [d]\) we have \((A^1_j \otimes \mathbb{I})\rho = (\mathbb{I}\otimes B^\mathbf{r}_j) \rho\). Since in finite dimensions all purifications are locally isometric on the purifying Hilbert space, this implies that for any purification \(| \psi \rangle_{ABE}\) of \(\rho\), we have \[\label{eq:selftest5} (A^1_j \otimes \mathbb{I}\otimes \mathbb{I}) |\psi \rangle_{ABE} = (\mathbb{I}\otimes B^\mathbf{r}_j \otimes \mathbb{I}) |\psi \rangle_{ABE} \quad \forall j \in [d].\tag{9}\] Note that this together with Eq. 7 implies that \(B^\mathbf{r}_j\) are projective on the state as well, i.e.  \[\label{eq:selftest6} (\mathbb{I}\otimes (B^\mathbf{r}_j)^2 \otimes \mathbb{I}) |\psi \rangle_{ABE} = (\mathbb{I}\otimes B^\mathbf{r}_j \otimes \mathbb{I}) |\psi \rangle_{ABE} \quad \forall j \in [d].\tag{10}\]

The maximal violation of the Bell inequality in Eq. 3 therefore leads to the certification results in Eqs. 47 , and 910 . These turn out to be sufficient to bound the device-independent randomness. In particular, for any collection of POVMs \(\mathcal{A}\), \(\mathcal{B}\) and any state with purification \(| \psi \rangle_{ABE}\) that are compatible with the maximal violation, the classical-quantum state 1 corresponding to the measurements ‘2’ for Alice and ‘\(\mathbf{r}\)’ for Bob has the form

\[\begin{align} \sigma^{2, \mathbf{r}}_{\mathrm{A}\mathrm{B}E} & \left. = \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{AB} [ (A^2_a \otimes B^\mathbf{r}_b \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE} ] \right. \\ & \left. = \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{AB} [ (A^2_a \otimes B^\mathbf{r}_b \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE} (\mathbb{I}_A \otimes B^\mathbf{r}_b \otimes \mathbb{I}_E)] \right. \\ & \left. = \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{AB} [ (A^2_a A^1_b \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE} (A^1_b \otimes \mathbb{I}_B \otimes \mathbb{I}_E)] \right. \\ & \left. = \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{AB} [ (\frac{1}{d} A^1_b \otimes \mathbb{I}_B \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE}] \right. \end{align}\]

Here, the second equation is a consequence of the cyclicty of the partial trace and the projectivity of \(B^\mathbf{r}_b\) when acting on \(| \psi \rangle_{ABE}\). The third equation is Eq. 9 applied twice, and the fourth one is Eq. 6 together with the cyclicity of the partial trace. We now plug in the isometries \(V_A^\dagger V_A \otimes V_B^\dagger V_B = \mathbb{I}_A \otimes \mathbb{I}_B\) from Eq. 4 to obtain

\[\begin{align} \sigma^{2, \mathbf{r}}_{\mathrm{A}\mathrm{B}E} & \left. = \frac{1}{d} \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{AB} [ (V_A^\dagger V_A A^1_b \otimes V_B^\dagger V_B \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE}] \right. \\ & \left. = \frac{1}{d} \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{\mathbb{C}^d \otimes \mathbb{C}^d \otimes A' B'} [ ( V_A A^1_b \otimes V_B \otimes \mathbb{I}_E) |\psi \rangle \langle \psi|_{ABE} (V_A^\dagger \otimes V_B^\dagger \otimes \mathbb{I}_E)] \right. \\ & \left. = \frac{1}{d} \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{\mathbb{C}^d \otimes \mathbb{C}^d \otimes A' B'} [ (|b \rangle \langle b| \otimes \mathbb{I}_{\mathbb{C}^d} ) |\phi^+_d \rangle \langle \phi^+_d| \otimes |\text{aux} \rangle \langle \text{aux}|_{A'B'E} ] \right. \\ & \left. = \frac{1}{d^2} \sum_{a,b=1}^{d} |a \rangle \langle a|_\mathrm{A}\otimes |b \rangle \langle b|_\mathrm{B}\otimes \mathop{\mathrm{tr}}_{A'B'} ( |\text{aux} \rangle \langle \text{aux}|_{A'B'E} ) = \frac{\mathbb{I}_{\mathbb{C}^{d^2}}}{d^2} \otimes \eta_E. \right. \end{align}\]

Here, the second equality is the cyclicity of the partial trace, the third one is Eqs. 4 and 5 , the fourth one is taking the partial trace on \(\mathbb{C}^d \otimes \mathbb{C}^d\), and in the last we introduce \(\eta_E := \mathop{\mathrm{tr}}_{A'B'} ( | \text{aux} \rangle \langle \text{aux} |_{A'B'E} )\). It is straightforward to see that for any such classical-quantum state \(\sigma^{2, \mathbf{r}}_{\mathrm{A}\mathrm{B}E}\), we have \(H(\mathrm{A},\mathrm{B}|E) = \log(d^2) = 2 \log(d)\). In other words, if Alice and Bob observe the maximal violation of the Bell inequality \(\hat{W}_d\), then they can certify the theoretical maximum in dimension \(d\), \(2\log(d)\) bits of randomness from projective measurements. Importantly, this maximum can be achieved by systems of local dimension \(d\), as shown in Ref. [15], supplemented by \(B^\mathbf{r}_j = (A^1_j)^T\), where \((.)^T\) is transposition in the computational basis.

Robustness.— Observing the maximal violation exactly is practically infeasible. To gauge the practicality of our protocol, we numerically compute lower bounds on the device-independent randomness in realistic cases when the violation is not exactly maximal. To obtain these bounds, we first lower bound the von Neumann entropy \(H(\mathrm{A},\mathrm{B}|E)\) with the min-entropy, and then compute bounds on the min-entropy [19] using established semidefinite programming techniques [20][22] with the Navascué-Pironio-Acı́n (NPA) method [23][25].

Figure 1 shows the resulting min-entropy as a function of the noise level for the three considered Bell certificates. Two of these are from the family discussed in this work, given by Eq. 3 for \(d=3\) and \(d=4\), respectively. The so-called modCHSH inequality is included for comparison. It corresponds to the Bell inequality (and corresponding DIQRNG protocol) introduced in [26], where Alice has three measurement settings and Bob has two, each with binary outcomes. The maximal violation of this Bell inequality can be achieved with local dimension \(d=2\). We included this Bell inequality as it is known for its high robustness among binary outcome inequalities.

On the horizontal axis we plot the noise level, defined as a normalised measure of the violation of a Bell expression. For each Bell certificate, the normalisation is performed using its maximal quantum value (\(\beta_Q\)) and its white-noise value (\(\beta_{\mathrm{WN}}\), obtained by assigning equal probability to all outcomes). For the Bell inequalities proposed in this work, \(\beta_Q=\sqrt{d(d-1)} + 1\), while for the modCHSH \(\beta_Q=1 + 2\sqrt{2}\). For the Bell inequalities introduced here, the white-noise values are \(\beta_{\mathrm{WN}}(d=3) \approx -2.1162\), and \(\beta_{\mathrm{WN}}(d=4) \approx -4.3688\). Using these quantities, the noise level \(\eta\) is defined as \[\label{eq:noise95level} \eta \equiv \frac{\beta_{\mathrm{obs}} - \beta_{\mathrm{WN}}}{\beta_Q - \beta_{\mathrm{WN}}},\tag{11}\] where \(\beta_{\mathrm{obs}}\) denotes the observed value of the Bell expression. The observed Bell value \(\beta_{\mathrm{obs}}\) is imposed as a constraint in the NPA optimisation at level \(1+AB\). For each value of the noise level, we upper-bound the corresponding guessing probability \(P_{\mathrm{guess}}\) of the outcomes used to generate randomness. The certified randomness is quantified by the min-entropy, \(H_{\min} = -\log_2 P_{\mathrm{guess}}\).

In the case of maximal violation, all three cases (\(d=2,3,4\)) yield the maximum possible global randomness of \(2 \log (d)\) bits, consistent with the theoretical limit. In the near-threshold regime (\(\eta \approx 0.993\)), we observe a gain in certified randomness for dimensions \(d>2\) compared to the modCHSH case. In particular, for \(d=3\) and \(d=4\), the curves surpass 2 bits of certified randomness at \(\eta \approx 0.997\) and \(\eta \approx 0.998\), respectively, thus surpassing the maximal amount of certifiable global randomness for \(d=2\). Remarkably, experimental noise levels given by Eq. 11 of the order of \(0.9975\) have been reported for qubit systems [27], suggesting that the advantages of using higher-dimensional systems (\(d>2\)) for device-independent randomness certification are within reach of current technology.

Figure 1: Certified randomness (min-entropy) as a function of the noise level \eta defined in 11 . The curves correspond to d=3 (blue, solid), d=4 (orange, dashed), and the modCHSH inequality (green, dotted). For d=3 and d=4, certified randomness exceeds 2 bits around \eta \approx 0.997 and \eta \approx 0.998, respectively, demonstrating an advantage over binary-outcome (d=2) scenarios. The plot was obtained using the Navascués–Pironio–Acín (NPA) hierarchy at the level 1+AB.

Conclusions and outlook.— We have shown that for every dimension \(d\), the theoretical maximum, \(2\log(d)\) bits of global device-independent randomness can be certified from a system of local dimension \(d\) using projective measurements. We introduced explicit protocols reaching this bound, and numerically prove the protocols’ robustness to experimental imperfections.

To make full use of these protocols, analytic techniques for robust certification (such as robust self-testing) would be desirable. It further remains open how much randomness can be certified from a system of local dimension \(d\) if only one party is restricted to projective measurements. To tackle this question, one would need to devise methods for finding a non-projective measurement that maximises device-independent randomness for a fixed projective measurement for the other party.

Acknowledgements.— NPA optimisation was implemented using the Python library ncpol2sdpa [28] and the MOSEK solver [29]. We acknowledge the use of a computational server financed by the Foundation for Polish Science (IRAP project, ICTQT, contract no. 2018/MAB/5/AS-1, co-financed by EU within Smart Growth Operational Programme). The Center for QuantumEnabled Computing project is carried out within the International Research Agendas programme of the Foundation for Polish Science co-financed by the European Union under the European Funds for Smart Economy 2021-2027 (FENG).

Note added.— Notice that similar results were independently developed in Ref. [30] where novel constructions of Bell inequalities for global randomness certification were provided.

References↩︎

[1]
N.  Brunner, D. Cavalcanti, S. Pironio, author V. Scarani, and S. Wehner, title Bell nonlocality, https://doi.org/10.1103/RevModPhys.86.419 journal Reviews of Modern Physics 86, 419 (2014).
[2]
D.  Mayers and A. Yao, Quantum cryptography with imperfect apparatus, in Proceedings 39th Annual Symposium on Foundations of Computer Science (Cat. No. 98CB36280)(IEEE, 1998) pp. 503–509.
[3]
R.  Colbeck, Quantum And Relativistic Protocols For Secure Multi-Party Computation, https://arxiv.org/abs/0911.3814Phd thesis, University of Cambridge(2007).
[4]
Ç. K. Koç, About cryptographic engineering, in Cryptographic engineering(Springer, year2009) pp. 1–4.
[5]
S.  Pironio, A. Acı́n, S. Massar, author A. B. de La Giroday, author D. N. Matsukevich, author P. Maunz, S. Olmschenk, D. Hayes, L. Luo, T. A. Manning, et al., title Random numbers certified by bell’s theorem, https://doi.org/10.1038/nature09008 journal Nature 464, 1021 (2010).
[6]
J. S. Bell, On the Einstein Podolsky Rosen paradox, https://doi.org/10.1103/PhysicsPhysiqueFizika.1.195 Physics 1, pages 195 (1964).
[7]
J. F. Clauser, M. A. Horne, A. Shimony, and author R. A. Holt, Proposed experiment to test local hidden-variable theories, https://doi.org/10.1103/PhysRevLett.23.880NoStop.
[8]
Y.  Liu, Q. Zhao, author M.-H. Li, J.-Y. Guan, Y. Zhang, B. Bai, W.  Zhang, W.-Z. Liu, C. Wu, X. Yuan, H. Li, W. J. Munro, Z.  Wang, L. You, author J. Zhang, X. Ma, J. Fan, Q.  Zhang, and J.-W. Pan, Device-independent quantum random-number generation, https://doi.org/10.1038/s41586-018-0559-3 journal Nature 562, 548 (2018).
[9]
M.  Farkas, J.  Volčič, S. A. L. Storgaard, R. Chen, and L. Mančinska, Maximal device-independent randomness in every dimension, https://doi.org/10.1038/s41567-025-03141-yNature Physics 22, 319 ( 2026).
[10]
A.  Acı́n, S. Massar, and S. Pironio, Randomness versus nonlocality and entanglement, https://doi.org/10.1103/PhysRevLett.108.100402Physical Review Letters 108, 100402 ( year 2012).
[11]
E.  Woodhead, J. Kaniewski, B. Bourdoncle, author A. Salavrakos, J. Bowles, A. Acı́n, and R. Augusiak, Maximal randomness from partially entangled states, https://doi.org/10.1103/PhysRevResearch.2.042028 Physical Review Research 2, 042028 (2020)NoStop.
[12]
M.  Tomamichel, R.  Colbeck, and R.  Renner, A fully quantum asymptotic equipartition property, https://doi.org/10.1109/TIT.2009.2032797IEEE Trans. Inf. Theory 55, 5840 ( 2009).
[13]
C.  Bamps and S.  Pironio, Sum-of-squares decompositions for a family of clauser-horne-shimony-holt-like inequalities and their application to self-testing, https://doi.org/10.1103/PhysRevA.91.052111 journal Physical Review A 91, pages 052111 (2015).
[14]
I.  Šupić, R. Augusiak, A. Salavrakos, and A. Acín, titleSelf-testing protocols based on the chained bell inequalities, https://doi.org/10.1088/1367-2630/18/3/035013New Journal of Physics 18, 035013 ( 2016).
[15]
A.  Tavakoli, M. Farkas, D. Rosset, author J.-D. Bancal, and author J. Kaniewski, Mutually unbiased bases and symmetric informationally complete measurements in Bell experiments, https://doi.org/10.1126/sciadv.abc3847 journal Science Advances 7, pages eabc3847 (2021).
[16]
G.  Pereira Alves and J.  Kaniewski, Optimality of any pair of incompatible rank-one projective measurements for some nontrivial Bell inequality, https://doi.org/10.1103/PhysRevA.106.032219.
[17]
M.  Farkas, Unbounded device-independent quantum key rates from arbitrarily small nonlocality, https://doi.org/10.1103/PhysRevLett.132.210803NoStop.
[18]
T.  Durt, B.-G. Englert, I. Bengtsson, and K. Życzkowski, On mutually unbiased bases, https://doi.org/10.1142/S0219749910006502 journal International Journal of Quantum Information volume 08, 535 (2010)NoStop.
[19]
R.  König, R. Renner, and C. Schaffner, The operational meaning of min- and max-entropy, https://doi.org/10.1109/TIT.2009.2025545.
[20]
P.  Skrzypczyk and D.  Cavalcanti, https://doi.org/10.1088/978-0-7503-3343-6, 2053-2563 (IOP Publishing, year2023).
[21]
P.  Mironowicz, Semi-definite programming and quantum information, https://doi.org/10.1088/1751-8121/ad2b85 journal Journal of Physics A: Mathematical and Theoretical 57, 163002 ( 2024).
[22]
A.  Tavakoli, A.  Pozas-Kerstjens, P.  Brown, and M.  Araújo, Semidefinite programming relaxations for quantum correlations, https://doi.org/10.1103/RevModPhys.96.045006 Reviews of Modern Physics 96, 045006 (2024)NoStop.
[23]
M.  Navascués, S.  Pironio, and A.  Acı́n, Bounding the set of quantum correlations, https://doi.org/10.1103/PhysRevLett.98.010401 Physical Review Letters 98, 010401 (2007)NoStop.
[24]
M.  Navascués, S.  Pironio, and A.  Acín, A convergent hierarchy of semidefinite programs characterizing the set of quantum correlations, https://doi.org/10.1088/1367-2630/10/7/073013NoStop.
[25]
M.  Navascués, Y.  Guryanova, M. J. Hoban, and A.  Acı́n, Almost quantum correlations, https://doi.org/10.1038/ncomms7288NoStop.
[26]
P.  Mironowicz and M.  Pawłowski, Robustness of quantum-randomness expansion protocols in the presence of noise, https://doi.org/10.1103/PhysRevA.88.032319 journal Physical Review A 88, pages 032319 (2013).
[27]
A.  Jean-Marie Seguinard, A.  Piveteau, P.  Mironowicz, and M.  Bourennane, Experimental certification of more than one bit of quantum randomness in the two inputs and two outputs scenario, https://doi.org/10.1088/1367-2630/ad05a6New Journal of Physics 25, 113022 ( 2023).
[28]
P.  Wittek, Algorithm 950: Ncpol2sdpa—sparse semidefinite programming relaxations for polynomial optimization problems of noncommuting variables, https://doi.org/10.1145/2699464 ACM Transactions on Mathematical Software 41, 1–12 (2015)NoStop.
[29]
M.  ApS, https://docs.mosek.com/10.2/pythonapi/index.html(2024).
[30]
I.  Perito, R. D’Avino, M. Jung, P. Mironowicz, A. Acín, and R. Augusiak, title Bell inequalities tailored to optimal global randomness certification, arXiv preprint arXiv:2606.xxxxx (2026)NoStop.