Here's how to generate a truly random number with quantum physics
Very little in this life is truly random. A coin flip is influenced by the flipper's force, its surrounding airflow, and gravity. Similar variables dictate rolling a pair of dice or shuffling a deck of cards, while even classical computing's cryptographic algorithms are theoretically susceptible to outside influence or bias.
'True randomness is something that nothing in the universe can predict in advance,' explained Krister Shalm, a physicist at the National Institute of Standards and Technology (NIST).
So how does someone achieve true randomness? For that, you need to peer into the quantum realm. The task once required years of study and access to vast research facilities, but thanks to an ingenious new project from Shalm and his colleagues, now anyone can access a 'factory for random numbers.' And it's free to use.
Designed by NIST in collaboration with the University of Colorado Boulder, the Colorado University Randomness Beacon (CURBy) is a first-of-its-kind system that relies on headspinning quantum mechanics concepts to offer truly random number generation.
More specifically, CURBy's foundation rests on a task known as the Bell test. Named after the famed physicist John Stewart Bell, the test measures pairs of entangled photons with properties that remain correlated even after separating across huge distances. While the outcome is always random when measuring a single particle, a pair's properties are more correlated than classical physics dictates. This allows experts to verify the randomness at a quantum level.
Albert Einstein previously described this 'quantum nonlocality' as 'spooky action as a distance,' and he wasn't a fan of the idea. Unfortunately for him, NIST proved its existence back in 2015. Three years later, they developed methodologies to use Bell tests in order to construct the world's first true randomness generators.
These initial random results necessitated months of refinement and only ran for a few hours in total. Even then, the physicists and engineers only generated 512 bits of true randomness. Since then, researchers expanded and automated their experiment, thus offering random numbers whenever needed.'We really wanted to take that experiment out of the lab and turn it into a useful public service,' said Shalm.
Their finalized protocol served up randomness 7,454 times over its first 40 days of existence. Researchers then recorded 7,434 cases of randomness—a success rate of 99.7 percent.
But how do you actually generate true randomness? For that, you need a system that relies on a bespoke nonlinear crystal to generate entangled photon pairs. The particles then speed away in an optical fiber to separate laboratories at opposite ends of a hallway at NIST. Once they reach the two labs, researchers measure their subsequent polarizations. This relay race is then repeated a headspinning 250,000 times per second.
All that data needs to be processed, so NIST sends off its millions of quantum coin flips to a specially designed computer program built by engineers at UC Boulder. The program then translates the measurements into 512 random bits of binary code that can then be parsed by anyone.
But utilizing CURBy is much simpler than the dizzying quantum computations required to generate true randomness. All a user needs to do is head to its website and key in the list of items you want shuffled. CURBy then will rearrange the entries based on any given day's quantumly determined randomness. The outcome is decades in the making, and would have certainly given Einstein something to think about.
'I am at all events convinced that [the Creator] does not play dice,' he famously wrote to Max Born in 1926 regarding the concepts of quantum theory.
'If God does play dice with the universe, then you can turn that into the best random number generator that the universe allows,' Shalm said.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Washington Post
a day ago
- Washington Post
Investigation into Florida condo collapse is expected to finish in 2026
More than four years after a Florida condominium collapse killed 98 people , federal investigators have yet to make a final determination of the cause — but they do have some leading theories. The National Institute of Standards and Technology, the agency handling the probe, said this week it hopes to conclude the investigation in 2026.


Forbes
3 days ago
- Forbes
Quantum Threats Reshape Commvault's Vision For Data Security
Commvault is incorporating post-quantum cryptography to address future data security risks. Data protection provider Commvault announced earlier this month that it is adding more quantum-safe capabilities to its platform to build out defenses against post-quantum cryptography. This is important because, as quantum computing shifts from theoretical to practical use, it brings a new class of cybersecurity threats. To help organizations prepare, Commvault has incorporated NIST-recommended PQC algorithms into its data protection offerings, covering both cloud and on-premises environments. The goal is to ensure long-term data security by protecting backups made today from potential decryption by future quantum systems. Over the past year, Commvault has introduced multiple post-quantum cryptography capabilities to safeguard data against future risks posed by quantum computing. PQC has important implications for customers, competitors and the broader industry, and all organizations should prepare for a quantum-driven — and quantum-safe — future. (Note: Commvault is an advisory client of my firm, Moor Insights & Strategy.) Understanding The Quantum Threat To Enterprise Data First, a little background on why this is so important. Quantum computers apply principles of quantum mechanics to process information in fundamentally different ways from classical computers. While this could unlock incredible advances in medicine, materials science, finance, AI and more, it also introduces new security concerns. This is because current encryption methods such as RSA and elliptic curve cryptography depend on mathematical problems that are very hard to reverse — unless a powerful quantum computer is involved. Once quantum computers that powerful are launched, probably in the next few years, these algorithms can potentially be broken quickly, compromising these widely used encryption methods. A crucial concern today is the 'harvest now, decrypt later' tactic, where bad actors can intercept and store encrypted data to decrypt it in the future once quantum capabilities mature. HNDL protection is especially critical for sectors with long-term data sensitivity, such as healthcare, finance and government. (Think of any setting in which sensitive information — names, dates of birth, government ID numbers, bank account numbers, medical histories and the like — remains unchanged for many years.) A survey by the Information Systems Audit and Control Association found that 63% of cybersecurity professionals believe quantum computing will shift or expand cyber risks, and half expect it to create compliance challenges. This image shows how users can enable PQC within Commvault's CommCell environment by selecting a ... More checkbox in the group configuration settings. Commvault's Post-Quantum Cryptography Response Commvault has taken a practical, multi-stage approach to quantum-era risks. In August 2024, it introduced a cryptographic agility framework, which is meant to allow organizations to adopt new cryptographic standards for PQC without major system changes. The framework includes several NIST-recommended quantum-resistant algorithms — CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON. (My colleague Paul Smith-Goodson, who has been covering quantum computing for years, went into more detail about these algorithms in the context of IBM's PQC efforts, also in August 2024.) Commvault's announcement earlier this month builds on last year's release by adding support for the Hamming Quasi-Cyclic algorithm, which uses quantum error-correcting codes to resist quantum decryption. But rather than focusing only on algorithm support, Commvault also emphasizes operational integration. Its Risk Analysis tools help organizations identify sensitive data, allowing quantum-resistant encryption to be applied where it's most needed. The crypto-agility framework offered by Commvault allows organizations to shift between cryptographic methods via relatively simple configuration changes, without needing to overhaul their existing environments. This flexibility helps minimize disruptions and lowers the costs associated with adapting to new standards as they emerge. Securing Critical Industries For The Quantum Era Commvault's PQC features should be especially helpful to organizations in healthcare, finance and government as they address compliance needs, ensure continuity and — most importantly — protect data that is held for decades. As touched on above, these industries are especially at risk for deferred decryption attacks, so implementing PQC features now should help address the risk of HNDL exploits later. Besides the benefits already mentioned, this could help organizations using Commvault maintain trust among regulators, customers and partners for the long haul. As data protection standards in these industries become stricter in anticipation of quantum threats, solutions that incorporate quantum-resistant encryption are increasingly necessary. Forward-looking IT organizations are already adopting these technologies. For instance, the Nevada Department of Transportation has adopted Commvault's PQC tools to meet government security requirements and protect sensitive information. The company also cited Peter Hands, CISO of the British Medical Association, who said, 'Commvault's rapid integration of NIST's quantum-resistant standards, particularly HQC, gives us great confidence that our critical information is protected now and well into the future.' The adoption of PQC is accelerating as both technological developments and regulatory requirements create a framework for organizations to address emerging threats from quantum computing. In the United States, for instance, federal agencies have been instructed to integrate post-quantum standards into their procurement and operational practices. Similar regulatory efforts are taking place in the European Union and other jurisdictions, where updates to data protection frameworks increasingly include provisions for quantum-safe encryption. To maintain security and compatibility during the transition, many organizations are implementing hybrid encryption methods that combine traditional and quantum-resistant algorithms. This approach allows for gradual migration to fully quantum-resistant systems while enabling protection against both current and future threats. PQC Challenges And The Push For Wider Adoption Commvault's phased introduction of PQC capabilities is a step forward, but current support is mostly limited to cloud-based customers using particular software versions. This creates a gap for organizations relying on hybrid or on-premises environments, which are still widely used in sensitive sectors like those already mentioned. To address this, Commvault would benefit from providing a clear roadmap for extending PQC support across all deployment models. Such a roadmap should outline which software versions will be supported, specify the technical requirements and offer a realistic timeline for implementation. The broader data protection market is also shifting as major technology providers such as IBM and Microsoft integrate quantum-safe features into their platforms. Other data protection vendors, such as Cohesity, Veeam and Rubrik, are expected to follow suit as industry standards become more established. This means Commvault will likely face growing competition in offering robust PQC solutions. Keeping pace will require not only technical expansion but also practical guidance for customers on how to adopt and apply PQC in various enterprise scenarios. Flexibility and clear communication about available features and best practices will be important for supporting a wide range of customer environments and needs. Aligning Data Security Strategies For A Quantum Future Commvault's early efforts in post-quantum cryptography and crypto-agility demonstrate a commitment to long-term data security. However, maintaining progress will depend on expanding access to PQC features for all customers, providing transparent information about costs and continuing to work closely with regulatory bodies. Quantum computing presents both new risks and opportunities. As traditional encryption methods become more vulnerable, the need for quantum-resistant security will grow. Commvault's PQC features offer a practical way for organizations to protect data that must remain secure for years. By focusing on adaptability, compliance and targeted encryption strategies, Commvault helps customers build stronger defenses for the future. The timeline for quantum decryption could be shorter than many anticipate, making it important for organizations to start preparing now. For enterprises, taking early action is important to avoid exposure and regulatory issues. For vendors, ongoing improvements in accessibility, transparency and alignment with emerging standards will determine long-term success. Simplifying the path to quantum readiness will be a key factor in supporting customers through this transition.
Yahoo
4 days ago
- Yahoo
QuSecure Names Gregory Donovan Vice President of Revenue as Demand for its Post-Quantum Cryptography and Cryptographic Agility Solutions Grows
Donovan Brings Critical Enterprise Leadership as Company Expands in Cybersecurity Market SAN MATEO, Calif., June 25, 2025--(BUSINESS WIRE)--QuSecure™, Inc., a leader in post-quantum cryptography (PQC) cryptographic agility, today announced it has named Gregory Donovan, a prominent revenue executive in the cybersecurity industry, as its new Vice President of Revenue. This is a strategic and necessary move for the company as it sees rising interest in both private and public sector cybersecurity teams starting their needed PQC migrations to gain quantum protection for critical data anywhere it travels. "I was impressed with the leadership and approach that QuSecure has taken to solve what could be a trillion-dollar problem in the market," Donovan said. "I chose QuSecure for that very reason – how it can provide PQC and cryptographic agility now and how I see our innovation evolving to solve current cybersecurity issues while preparing for larger quantum threats." Late last year the National Institute for Standards and Technology (NIST) directed security leaders to begin adopting new standards for addressing the quantum threat immediately. In recent White House Executive Orders, it has been made clear that it is a priority for the U.S. government to resolve cryptographic debt as the quantum threat approaches and bad actors harvest sensitive data now to stockpile for later decryption. For high-risk use cases, the requirement for meeting these standards was pulled in by 5 years compared to previous guidance – with additional advancement expected in this timeline. Technology vendors involved with National Security Systems are required to support post-quantum cryptography by 2027. Donovan brings years of enterprise and global sales experience to QuSecure. Most recently, he was with Keyfactor, a leading PKI cybersecurity company focused on the Fortune 500; and prior to that he served as Chief Growth Officer at Cognition, where he led go-to-market strategies and activities for an industrial automation/AI company. Donovan has also held key roles with ScentAir, ADP and SAP/Fieldglass. He earned a Bachelor of Science from Penn State University and resides in Charleston, SC. "I'm excited about the rapid growth that Gregory will help QuSecure capitalize on," said Rebecca Krauthamer, co-founder and CEO of QuSecure. "As we see the adoption curve accelerating, his deep experience leading and scaling high-performing sales teams and delivering impressive revenue results come at a critical time for our growth. He has a solid track record of building proven sales strategies that span multiple industries that matter deeply to us, including cybersecurity and AI, and across private and public sectors. We will rely on his extensive experience and deep industry connections as we work to exceed our aggressive goals for 2025 and beyond." QuSecure ensures that sensitive data remains secure even as quantum computing and AI advance. It provides software-only security architecture that overlays onto a customer's pre-existing infrastructure, simplifying the migration to modern cryptographic standards without performance impact. Its flagship product, QuProtect, is the industry's first cryptographic-agility platform that elegantly facilitates the upgrade to PQC and managed cryptographic visibility and orchestration, and QuSecure is proud to have the most crypto-agility deployments of any organization globally. QuSecure's diverse roster of customers includes the United States Army and Air Force, key players in the telecommunications and energy sectors, leading financial institutions, and global cloud services providers. About QuSecure QuSecure is a leader in quantum-safe cybersecurity with a mission to use the advent of quantum computing to act as a catalyst to fix the foundation of data security infrastructure. The QuProtect platform can be purchased through the AWS Marketplace or direct outreach to QuSecure, Accenture, Dell, Cisco, or Carahsoft. QuSecure's quantum-resilient and crypto-agile solutions provide the lowest friction transition path to inventory your cryptographic communications and transition to quantum-resiliency anytime, anywhere, on any device, and across any organization. For more information, see View source version on Contacts Dan Spaldingdspalding@ (408) 960-9297 Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data