Device-Independent Certification of Maximal Randomness from Pure Entangled Two-Qutrit States Using Non-Projective Measurements

While it has recently been demonstrated how to certify the maximal amount of randomness from any pure two-qubit entangled state in a device-independent way, the problem of optimal randomness certification from entangled states of higher local dimension remains open. Here we introduce a method for device-independent certification of the maximal possible amount of 2log23 random bits using pure bipartite entangled two-qutrit states and extremal nine-outcome general non-projective measurements. To this aim, we exploit a device-independent method for certification of the full Weyl–Heisenberg basis in three-dimensional Hilbert spaces together with a one-sided device-independent method for certification of two-qutrit partially entangled states.


Introduction
The intrinsic randomness of quantum theory manifested in the outcomes of quantum measurement is one of the most intriguing features of quantum mechanics [1]. Even more remarkable is the fact that quantum technologies allow us to generate certifiable randomness with an unprecedented level of security [2]. Protocols designed for randomness certification ensure both the generation of completely random bits and their privacy, which for instance introduces new possibilities in designing protocols for tasks such as quantum cryptography and quantum key distribution [3].
Since the pioneering works on randomness certification [4] (see also Ref. [2]), significant progress has been made both in theoretical and experimental aspects [5][6][7][8]. It was shown, for instance, in Ref. [9], that maximal violation of the Salavrakos-Augusiak-Tura-Wittek-Acín-Pironio (SATWAP) Bell inequality [10] enables self-testing the maximally entangled state of two-qudits of arbitrary local dimension, which in turn allows certifying log 2 d bits of randomness by using projective measurements. On the other hand, we know that non-projective measurements, also known as positive-operator valued measures (POVM), can be used to generate more randomness in a given dimension than projective ones. The intuitive reason behind this is the existence of extremal d 2 -outcome non-projective measurements in d-dimensional Hilbert spaces, which consequently might give rise to 2 log 2 d random bits [11]. In fact, a method for certification of two bits of local randomness in dimension two by exploiting such non-projective measurements was introduced in Ref. [12].
Similar research was conducted in Ref. [13], where the authors exploited Gisin's elegant Bell inequality [14] instead of the Clauser-Horne-Shimony-Holt (CHSH) inequalities used in Ref. [12]. Later, in Ref. [15] it was shown how to certify the maximal amount of local randomness independently of the degree of entanglement of two-qubit states.
While significant progress has been made in understanding the possibility of deviceindependent randomness certification from entangled states of the lowest possible dimen-

Scenario
Since we are concerned with the device-independent certification of randomness, we consider an adversarial Bell scenario, consisting of two parties, Alice and Bob, and an adversary, Eve. Alice and Bob cannot trust their devices in this scheme because Eve, a malicious eavesdropper, could have full control of all of their resources. An example of Eve's strategy might be to use extra dimensions of the Hilbert space hidden in the devices to learn about the results of Alice's and Bob's measurements. Eve may also try to entangle with the subsystems of our protagonists Alice and Bob and create correlations, which will allow her to obtain some information on the outputs of the experiment. Nevertheless, the strength of the randomness certification techniques lies in the possibility to prove that, despite any attacks, Eve cannot learn anything about the results of Alice's and Bob's measurements. Security of the protocol is demonstrated if they both observe strong correlations in their measurement statistics, i.e., correlations that exhibit the maximal quantum violation of a given Bell inequality.
We construct the following scenario to certify randomness from pure bipartite entangled states of local dimension three in a device-independent way. Alice and Bob perform local measurements on their quantum subsystems, labelled by A and B, which they receive from the preparation device P operated by Charlie and consisting of two inputs p = 1, 2. Preparation P 1 corresponds to preparing a state ρ 1 AB and P 2 a state ρ 2 AB . Both preparations can be purified as |Ψ 1 ABE and |Ψ 2 ABE , respectively. Charlie can freely choose the input of the preparation device.
Alice's device has nine inputs labelled by j = 0, . . . , 8 and Bob's device has four inputs labelled by k = 0, 1, 2, 3. The first eight measurements of Alice and all measurements of Bob result in three outputs, labelled by a for Alice and b for Bob such that a, b = 0, 1, 2. The ninth measurement on Alice's side corresponding to j = 8 is a nine-outcome measurement. We employ this additional measurement to certify randomness from its outcomes. A schematic representation of our scenario is presented in Figure 1. It is necessary here to assume that the measurements are independent of the input of the preparation device.
Alice, Bob, and Charlie now collect statistics for each input and the corresponding outputs, which allows them to reconstruct the probability distribution p = {p(a, b|j, k, p)}, where p(a, b|j, k, p) is the probability that outcomes a and b are obtained when performing measurements j and k on the subsystems A and B given the preparation p. Using this scenario, one can first certify the full Weyl-Heisenberg basis (Section 3.1), then any entangled state of local dimension d = 3, and, finally, the optimal amount of randomness from entangled states of local dimension d = 3 (Section 3.2).

Figure 1.
Randomness certification scenario for d = 3. Alice and Bob have access to untrusted devices, and they apply measurements F j and G k , respectively. The preparation box distributes two different bipartite states ρ 1 AB for the preparation P 1 and ρ 2 AB for the preparation P 2 . After collecting the measurements statistics p one can device-independently certify Bob's measurements based on Alice's inputs j = 0, 1, 2, 3, 4, 5 and Bob's inputs k = 0, 1, 2, 3. The preparation P 2 can be certified to be any pure entangled state of local dimension 3 with inputs j = 6, 7 and k = 0, 1. Randomness certification is based on the preparation P 2 and 9-outcome measurement corresponding to the input j = 8.
Let us now discuss potential strategies for Eve that need to be taken into account to ensure that the generated randomness is not accessible by her. For example, suppose Alice wants to generate randomness from the outcomes of one of her measurements. Then the aim for Eve is to guess Alice's outputs with the highest possible probability. To do so, Eve can prepare Alice's and Bob's systems in any way compatible with the given statistics p by using quantum resources while remaining undetected. Therefore, we can characterize Eve's strategy S applied for the attack using four major points:

1.
Eve, for instance, may know the input of the preparation device p and the inputs of Alice and Bob x, y, but she cannot change them.

2.
Eve might possess some subsystem E correlated with both parties. Consequently, the state shared among Alice and Bob is defined by Since there is no restriction on Eve's subsystem, we can safely assume here that ρ ABE is pure and write ρ ABE = |Ψ ABE Ψ ABE |. Eve's influence remains undetected if it cannot be observed in the statistics p obtained by Alice and Bob, i.e., Now let us define the local guessing probability, that is, the probability that Eve's guess agrees with Alice's output [12]: where the supremum is taken over all strategies S p , consisting of the shared state ρ ABE , Bob's measurements {G k b }, and Eve's measurements {Z a } that reproduce the statistics p. The amount of random bits obtained from Bob's measurements is quantified with the min-entropy of the guessing probability H min = − log 2 G(j, p). Now let us say more about the additional ninth measurement on Alice's side. We can assume it to be a nine-outcome POVM {R a }, which, applied on Alice's part of an entangled qutrit state, gives completely random results, i.e., Tr[R a ρ A ] = 1/9, ∀a. Apart from the above conditions, we require that POVM {R a } should reproduce the statistics given by Equation (1), that is, any of Eve's attempt of learning of Alice's outputs remains undetected. We present an example of a measurement construction meeting the above properties in the Section 3.3. Our goal is to prove that Eve's guessing probability related to Alice's j-th input and consistent with the statistics p, does not allow Eve to learn anything about Alice's outputs, i.e., G(j, p) = 1/9. Such a situation will provide us with 2 log 2 3 bits of private randomness. To sum up, we certify randomness based on the correlations, which minimize Eve's guessing probability, and these correlations are obtained by measuring POVM {R a } on Alice's subsystem. For that purpose, we employ an arbitrary entangled state of local dimension 3 certified with the extended Bell scenario and the W-H operators on Bob's side certified with the use of a Bell test.

Non-Local Scenario and Bell Inequality
In Ref. [17], the authors presented a modification of the Buhrmann-Massar Bell inequality [21] to show self-testing of the maximally entangled state of two-qutrits and three mutually unbiased bases on each site. In our work, we apply this certification scenario to self-test the complete set of W-H operators in dimension three. Later this result is used for the certification of randomness from the measurement F 8 = {R a }. The main idea behind self-testing of the full W-H basis is taken from Refs. [12,15] and consists in using the Bell inequality from Ref. [17] twice. Below we introduce crucial elements needed to present self-testing results.
Throughout this work, we use the correlation picture or, equivalently, the observable picture to describe all correlations observed between Alice and Bob, i.e., where ω = exp(2πi/3) and l, m = 0, 1, 2. The above formula is a two-dimensional Fourier transform of the conditional probabilities p(ab|jk). Operators A l|j , B m|k provide us with an alternative description of the measurements {F a|j } and {G b|k } [17], and are defined by Fourier transform in the following way: Let us note here that we make no assumptions about Alice's and Bob's measurements or the shared state; in fact, we consider a fully general situation of ρ AB being mixed and Alice's and Bob's measurement being POVMs. In such a general situation, the above measurement operators A l|j satisfy A † l|j A l|j ≤ 1 and A l|j A † l|j ≤ 1 for any l and j, and A 0|j = 1 for any j (the same holds for B m|k operators).
Since in our scenario we are dealing with three-outcome measurements, it is not difficult to observe that A 2|j = A † 1|j . Therefore, by also taking into account the fact that A 0|j = 1, this implies that measurement is fully determined by a single operator A 1|j , which, for simplicity, we denote as A j ; analogously for Bob's measurements, we denote B k ≡ B 1|k . In the case of the measurements F j and G k being projective, A l|j and B m|k are all unitary operators whose spectra are 1, ω, ω 2 , and can be represented as A l|j = A l j and B m|k = B m k , where the superscripts l and m are operator powers of the unitary quantum observables A j and B k , such that A d j = B d k = 1. In this case the expectation values (3) can be expressed as: Let us introduce now the Bell inequality used in our scenario. We consider a slightly simplified Bell operator from [17] for d = 3, which is sufficient for our purposes. The modification results from the omission of the identity term, and now the Bell operator is given by: where λ = e −iπ/18 , and h.c. stands for the hermitian conjugation. The corresponding Bell inequality is defined as: where β L is its classical bound, that is, the maximal value of the Bell expression W 1 over all correlations admitting the local-realistic description, and it amounts to: Moreover, the maximal quantum value of the above Bell inequality was found in Ref. [17] to be: It is achieved by the maximally entangled state of two qutrits: and the following choice of Bob's observables: where: and |3 ≡ |0 . It is worth noticing that the eigenvectors of B i form mutually unbiased bases in C 3 . At the same time, Alice's optimal observables can be expressed as the following linear combinations of the above optimal observables of Bob: where * denotes the complex conjugation in the standard basis. The above Bell inequality can be used for device-independent characterization of Bob's measurements. In fact, it follows from Ref. [17] that if it is maximally violated by correlations obtained from the first preparation |Ψ 1 ABE and the measurements B i (i = 0, 1, 2), then the latter are projective. Moreover, dim(H B ) = 3 · t B for some positive integer t B , or, equivalently, H B = (C 3 ) B ⊗ (C t B ) B , and there exists a unitary operation U B : H B → H B such that: where the operators Q 1 , Q 2 are orthogonal projectors satisfying Q 1 + Q 2 = 1 B . These two projectors identify the orthogonal subspaces corresponding to two inequivalent sets of observables maximally violating the Bell inequality (7) that are related via transposition.
Regarding the side of Alice, we can draw a similar conclusion as for Bob's subsystem, and we can also determine the form of the first preparation |Ψ 1 ABE [17]. However, we will not use their explicit forms in what follows; therefore, we do not present them here. In fact, the aim of performing the Bell test on the first preparation is to certify Bob's measurements.

Steering Inequality
In this subsection, we recall the steering inequality introduced in Ref. [20], and we show how to use it for certification of the second preparation.
Let us again consider Alice and Bob performing measurements on some quantum state |Ψ 2 ABE . For a moment, assume that one of the measuring devices, let us say that belonging to Bob, is trusted and performs fixed measurements; Alice's measurement device remains untrusted. Let us then consider the steering inequality constructed in Ref. [20]: where W 3 is a steering operator given by: where: Coefficients γ and δ k are functions of three positive numbers α i such that α 2 1 + α 2 2 + α 2 3 = 1. Then, β L is the classical bound of (14). Although we do not know its explicit form for any α i , it was proven in Ref. [20] that for any α i > 0 it is strictly lower than the maximal quantum value of W 3 , β Q = 3.
Recall also that α i are Schmidt coefficients of the following state: which maximally violates the inequality (7) for observables on the trusted side fixed to be Z and X, where we denoted α α α = (α 1 , α 2 , α 3 ). Importantly, we can employ the above steering inequality to device-independently certify the second preparation |Ψ 2 ABE . To this end, we use it together with Bob's observables B 0 and B 1 , which, with the aid of the Bell inequality (6) (see Section 2.2), are certified to be of the form (13). Precisely, we can determine the form of Alice's observables A 6 and A 7 in the sense that up to some unitary U A : H A → H A we have: such thatP 1 ,P 2 are orthogonal projectors satisfyingP 1 +P 2 = 1 A . Moreover, the joint state corresponding to the second preparation |Ψ 2 ABE up to the unitaries acting on Alice's and Bob's systems can be expressed as: Therefore, the expression (19) constitutes a self-testing statement for any entangled state in dimension three.

Certification of Full Weyl-Heisenberg Basis in d = 3
In this subsection we present a method for device-independent certification of a full W-H basis, which, up to some phases, consists of the operators W p,q := X p Z q , with p, q = 0, 1, 2. We begin by observing that the eigenvectors of the particular subset of the W-H operators W p,q = X p Z q , that is, {Z, X, XZ, XZ 2 } are mutually unbiased for d = 3.
Let M r denote subsequent elements of this subset, where r = 0, 1, 2, 3 and Π (b) r denote the projectors constructed from the eigenvectors of M r , where b = 0, 1, 2 labels the outcomes of a given observable. Operators M r can be written in terms of the spectral decomposition as: Let us note that multiplying the operators M r with powers of ω or taking conjugate transpose results just in relabeling M r 's outcomes. Now let us observe that apart from the identity, the remaining W-H operators {Z 2 , X 2 , X 2 Z, X 2 Z 2 } can be obtained from the set {M r } through a suitable rearrangement of the eigenvalues: The conclusion from the above consideration is that it is enough to certify only 4 particular observables out of a full W-H basis, while the remaining ones can be obtained by adequately relabelling the outcomes.
As shown in Section 2.2, the maximal violation of the Bell inequality (7) allows one to certify three such particular observables. To certify the fourth one we consider another Bell operator given by: Notice that while Alice's measurements in this Bell operator are all different from those used in W 1 , on Bob's side the two measurements B 0 and B 2 are same.
We aim to prove that observation of the maximum violation of the Bell inequality (7) by the two different sets of observables corresponding to the Bell operators W 1 and W 2 self-tests the complete W-H basis in dimension three up to the unitary and transposition equivalences. First, maximal violation of (7) by W 1 implies that Bob's measurements are projective and that the corresponding observables B i with i = 0, 1, 2 are of the form (13). Second, it follows from Ref. [17] that maximal violation of the same inequality by W 2 implies that B 3 is a quantum observable too and that B 0 , B † 2 and B 3 must satisfy the following relations: These conditions can be used to reconstruct the fourth observable of Bob, B 3 . Precisely, plugging the forms of B 0 and B 2 into the second relation in (23), one immediately finds that: Let us refer here to the fact that we cannot distinguish between optimal measurements used in the device-independent scenario and their transpositions based only on the correlations p observed in a Bell experiment. We call this ambiguity transposition inequivalence. For this reason, we are unable to perform a full tomography of the POVM on Alice's side. In other words, it is not possible to completely reconstruct the elements of the POVM implemented on Alice's side from the joint correlations. Consequently, we cannot certify the maximum randomness directly from the POVM elements. Nevertheless, in the following section, we present a way to overcome this difficulty. We show how to certify maximal randomness from the POVM on Alice's side without certifying the measurement itself.
To summarize this section, we managed to certify four observables on Bob's side by using the two Bell operators W 1 and W 2 . Then, we observe that with a proper relabeling (21) we can construct the other four elements of the W-H basis. With the identity operator, we can then have the complete set of nine W-H operators in dimension three. For the convenience of further calculations, up to certain relabeling of the outcomes, let us express the certified observables B k as follows: where p, q = 0, 1, 2.

Certification of Randomness
We can finally proceed to the randomness certification. As discussed before, the last ingredient of our scheme is the nine-outcome POVM that Alice performs on her subsystem. Since the state on which F 8 acts is certified to be (19), without loss of generality, we can consider this measurement to be a POVM acting on a state of dimension 3 · t where t is some positive integer. Let us denote the POVM under consideration by {R a }, where a = 0, 1, . . . , 8 represents the outcomes of the measurement. The correlations between the outcomes of non-ideal POVM and Bob's observables B p,q (25) should equal those of the ideal setup, as expressed in Equation (1). This means that: where {R a } represents some ideal extremal POVM. Let us recall that POVMs of a fixed number of outcomes form a convex set, and given that POVM is called extremal if it cannot be decomposed as a convex mixture of other POVMs, we will now demonstrate that the above construction provides the certification of maximal amount of local randomness from the non-ideal POVM.
Let us note here that the ideal POVM elements R a used in definition (26) can be written as: which follows from the fact that R a belongs to a three-dimensional Hilbert space and P = ∑ 2 i=0 α i |i i|, such that α i = 0 for all i. For a remark, let us note that operators P −1 X k Z l * P −1 form a complete operator basis for measurements acting on threedimensional Hilbert space. Using the fact that |ψ(α α α) = √ 3P ⊗ 1 B |Φ , where: let us now look at the right-hand side of Equation (26), which, after a simple computation, gives: Hence, from (26) we have that: Next we can substitute (19) into (30) and obtain: where from now on, we will use the notationR a = U ARa U † A , and U B B p,q U † B is given by Equation (25).
Since {R a } acts on a subsystem of dimension 3 · t, without loss of generality, we can decompose its elements as:R whereR a k,l act on H A . Now we can insert an expression forR a (32), the state |Ψ 2 ABE from (19), and Bob's measurements B p,q (25) into Equation (30) to find the following formulas: for p = 0 and all q, and for p = 1, 2 and all q. Inspired by Acín et al. [12], we define the following normalized states: Let us now define the following operators in terms of coefficients (37) and (38): It is easy to check that the operatorsR b,e a are valid POVMs, that is, they satisfy the following properties,R b,e a ≥ 0 and ∑ aR b,e a = 1. To see this, using Equation (37) let us rewrite the decompositions of the operators given by Equation (39) as follows: From the fact thatR a ≥ 0 and ∑ aRa = 1 and from the above equation, it then follows thatR 1,e a ≥ 0 and ∑ aR 1,e a = 1. Therefore, the coefficientsr a;1,e p,q define a family of valid POVMs with the operatorsR 1,e . Note that the operatorsR 2,e a are a transposition of the operatorsR 1,e a . Thus, the coefficientsr a;2,e p,q also define a family of POVMs with the operatorsR 2,e .
Using Equations (39) and (40), we have the following expression from Equation (36): which can be understood as a convex decomposition of the ideal POVM {R a } in terms of the POVMsR b,e with the respective weights q b,e . However, the POVM {R a } is extremal and cannot be expressed as a convex combination of other POVMs. Thus, we haver a;b,e p,q = r a p,q for all b, e and ∑ b,e q b,e = 1. Finally, rewriting the guessing probability (2) of Eve for outcomes of Alice's POVM {R a }, we have: Using Equations (19) and (32) in the above equation, we arrive at: Now, using Equation (33), we can simplify (44) as follows: where we have used the constraint onr a;b,a 0,0 as argued in the previous paragraph. Now, choosing an ideal POVM {R a } (27) such that r a 0,0 = 1/9 ∀a, and using it for the guessing probability from Equation (45), gives G(j = 8, p) = 1/9. This implies that using the scheme mentioned above, Alice can securely generate − log 2 G = 2 log 2 3 bits of randomness from any partially entangled two-qutrit state provided that there exist extremal POVMs that satisfy the condition (46). As a final remark here let us note that Equation (29) for p, q = 0, 0 gives: which is equivalent to the expression where ρ A = Tr B (|ψ(α α α) ψ(α α α)|). In the following section we present the construction of the extremal POVM, which satisfies the condition (46).

Construction of Extremal Qutrit POVM
D'Ariano and collaborators [11] have classified all extremal POVMs with discrete output sets. According to this classification, an extremal POVM {R a } with d 2 outcomes must necessarily be rank-one, and its elements must be linearly independent. Linear independence of the POVM elements can be verified with the condition ∑ a s a R a = O, where O is the zero matrix, satisfied if and only if all s a = 0. We also require that POVM elements acting on Alice's subsystem give equal probabilities, i.e., Tr[R a ρ A ] = 1/9 for all a and ρ A . Finding a general class of POVMs that meets all the above conditions for any partially entangled state proved to be a demanding task. Below we present a construction provided in Ref. [20] that fulfills the above requirements for a well-defined subset of entangled two-qutrit states.
To construct an extremal POVM, all of the above coefficients defining it must satisfy 0 < λ i < 1and 0 < µ j < 1, for i = 0, . . . , 8, and j = 0, 1, 2. The above inequalities must be strict, as otherwise, if one of them equals 0 or 1, the operators R b are not linearly independent and thus do not form an extremal POVM. Solving the set of inequalities that emerge from the above constraints, one obtains α 0 > 1/3 and α 2 > 1/3. By relabeling the indices in (50) and (51) we can generalize the constraint on α 0 and α 2 to the requirement that any two out of three α's have to be greater than 1/3. Let us recall at this point that up to local unitaries any bipartite state of local dimension three can be expressed using Schmidt decomposition in the form of Equation (17). Therefore, the above POVMs give rise to 2 log 2 3 bits of randomness if any two Schmidt coefficients of the state are greater than 1/3.
Using the Monte Carlo method [22], we have checked that the above condition is satisfied by 92.6% states out of 10 7 randomly generated ones. It remains an open problem to find an extremal POVM that would generate maximal randomness from any entangled state in dimension three.

Discussion
In our work, we introduced a method for device-independent certification of maximal randomness from pure entangled states in dimension three using non-projective measurements. For this purpose, we exploited the extended Bell scenario introduced recently in Ref. [20], which combines device-independent certification of local measurements with one-sided device-independent certification of pure entangled states. In fact, we first showed how to certify the complete set of W-H operators in dimension three by using the selftesting scheme proposed in Ref. [17]. Then, by using the steering scenario proposed in [20], we provided certification of any entangled state in dimension three. These two components finally allowed us to achieve the main goal of the paper, that is, to certify 2 log 2 3 random bits by performing generalized measurements on Alice's subsystem of partially-entangled two-qutrit states. In fact, we verified numerically that the constructed POVM that we used in our scheme covers a significant subset of 92.6% of bipartite entangled states.
Several interesting directions for further research emerge from our work. First, it would be extremely interesting to understand what is the maximal amount of global randomness that can be certified from entangled quantum states of local dimension d by performing non-projective measurements on both subsystems. Whereas the known theoretical limit says that at most 4 log 2 d bits of randomness can be created in this way, it is unclear whether this limit is achievable. In fact, it was shown recently in Ref. [15] that in the case of two-qubit systems, 3.9527 bits of randomness is actually the maximal amount that can be generated in a device-independent way. This intriguing observation comes from the fact that an adversary can use some of the global correlations obtained with non-projective qubit measurements to infer information about the outcomes of a Bell experiment. Therefore, understanding the fundamental limit for generating global randomness from two-qudit states in the non-local scenario remains a very interesting challenge. Another interesting problem for further research is to provide constructions of d 2 -outcome extremal POVMs that can be used to generate randomness from any, even arbitrarily small, entangled states.