Congresso Brasileiro de Ciências e Tecnologias Quânticas (CBCTQ 2026) – September 21–25, 2026, Innovation District of Cantareira, Niterói–RJ, Brazil
Operational Roles of QRNG-Derived Quantum Entropy in Bitcoin Proof-of-Work Architectures Ricardo Fernandes da Silva and Paulo Vitor Batista Santos
arXiv:2609.05092v1 [cs.CR] 4 Sep 2026
Abstract— Replacing classical entropy with QRNG output does not change honest Bitcoin PoW success probability when candidate headers remain distinct. The original contribution of this paper is a reproducible benchmark that locates and measures the operational value of quantum entropy in hybrid quantum-classical mining infrastructure through two schedulerlevel observables, the entropy-efficiency factor η and the rebootdiversity index ρ. Monte Carlo and scheduler simulations with confidence intervals show parity for competent deterministic and strong-classical baselines, while QRNG value emerges in assurance-oriented scenarios involving correlated restart faults, namespace reuse, and entropy provenance. The study is therefore positioned as a simulation-based validation framework rather than as a device-level QRNG demonstration; hardware-in-the-loop validation with recorded or live QRNG streams is identified as the next experimental step. Keywords— Quantum random number generators, Bitcoin, Proof-of-Work, hybrid quantum-classical infrastructure, entropy engineering.
I. I NTRODUCTION
Quantum random number generators (QRNGs) extract entropy from genuinely quantum processes and are increasingly relevant to cryptography, certified randomness, and securitycritical platforms [5]–[9]. Bitcoin, in turn, remains the bestknown Proof-of-Work (PoW) blockchain, where miners repeatedly evaluate double-SHA-256 on candidate headers until the digest falls below the network target [1]–[4]. Because mining is often described informally as a random search, QRNGs are sometimes framed as possible mining accelerators. This paper defends a narrower and technically stronger claim. For honest mining over distinct candidate headers, block discovery is governed by the number of effective trials, not by whether header ordering is deterministic, classically pseudorandom, or QRNG-assisted. The scientifically relevant role of quantum entropy therefore lies in the surrounding control plane: entropy roots, namespace freshness, restart robustness, and auditable provisioning. Figure 1 summarizes the equivalence in effective sampling induced by different entropy strategies under distinct-header testing. When QRNG is used, it acts at the entropy root of the control plane, supporting scheduler state, namespace assignment, and reseeding policy, while the PoW hashing engine itself remains unchanged. Accordingly, any QRNG-related effect arises from orchestration quality and restart behavior rather than from a modification of the per-hash success law. Ricardo Fernandes da Silva, Academic Department of Physics, Federal Technological University of Paraná, Curitiba, Brazil, e-mail: [email protected]; Paulo Vitor Batista Santos, Foton Institute of Quantum Sciences and Technologies, Porto Alegre, Brazil, e-mail: eng.computacao [email protected].
Deterministic Enumeration
CSPRNG (Classical)
QRNG Assisted
→ Uniform Hash Space
Fig. 1. Different entropy strategies converge to the same effective sampling distribution over the hash space. Under distinct-header testing, deterministic enumeration, strong classical pseudorandomization, and QRNG-assisted scheduling differ in entropy provisioning, but not in the first-order PoW success law.
The contribution is not a new PoW law, but a reproducible operational benchmark for the disciplined integration of a quantum primitive into hybrid quantum-classical infrastructure. Specifically, the paper contributes: i) a fair comparison among deterministic, strong-classical, and QRNG-assisted schedulers under identical PoW logic; ii) two measurable observables, the entropy-efficiency factor η and the reboot-diversity index ρ, both recoverable from controller or pool logs; and iii) a correlated-restart protocol with sensitivity analysis that identifies the operational regimes in which QRNG adoption is justified on assurance grounds. Accordingly, the relevant technical question is not whether QRNG changes the PoW success law, but how quantum entropy should be integrated, measured, and audited in a larger classical distributed system. This paper does not report measurements from a physical QRNG device or from quantum hardware. Instead, it defines a reproducible benchmark and a set of observables intended to guide future device-in-the-loop experiments. This scope is important because the expected contribution of QRNG in Bitcoin-related infrastructure is not acceleration of the hashing process, but improved assurance, provenance, and robustness of entropy-dependent control services. II. R ELATED W ORK AND T ECHNICAL P OSITIONING The QRNG literature has firmly established the relevance of physical unpredictability, entropy estimation, and deployment models ranging from laboratory-scale devices to integrated photonic implementations [5], [6], [9], [23], [24]. More recently, the focus has expanded from isolated QRNG characterization toward system-level integration, including entropy-as-a-service architectures, cloud-based provisioning, and QRNG-backed post-quantum communication stacks [21], [22], [25], [26]. This body of work increasingly treats quantum randomness as an operational resource that can be embedded into hybrid infrastructures rather than as a purely standalone physical capability.
Congresso Brasileiro de Ciências e Tecnologias Quânticas (CBCTQ 2026) – September 21–25, 2026, Innovation District of Cantareira, Niterói–RJ, Brazil
At the same time, the Bitcoin and PoW literature has where hprev is the previous block hash, m is the Merkle-root extensively characterized mining mechanics, pool coordination, state, tb is a timestamp bucket, nb is a nonce range, and xb adversarial incentives, and operational attack surfaces [1], [13]– is an extranonce or equivalent namespace slice. Then u is [19]. However, the interface between these two literatures estimated from the number of unique w values observed in remains insufficiently developed. In blockchain-oriented discus- controller or pool logs. The first-order discovery law becomes sions, QRNG is often assessed in ways that blur the distinction P (η) = 1 − (1 − p)ηk ≈ ηkp. (6) between consensus probability and entropy assurance. When explicit comparisons are made, QRNG is frequently contrasted Throughput parity does not imply equal assurance. A with weak or poorly specified classical sources, rather than deployment can keep η ≈ 1 in steady state and still be with a properly engineered deterministic random bit generator fragile under synchronized reboots or image-based recovery. (DRBG) consistent with NIST guidance [10]–[12]. Moreover, We therefore define a second observable. few studies introduce observables that are directly recoverable Definition 2 (Reboot-diversity index): For W workers and from operational logs and therefore suitable for reproducible reboot event t, infrastructure-level evaluation. W i 1 X h (t) (t−1) The stance adopted in this paper is deliberately narrow ρ= 1 σi ̸= σi , (7) W i=1 and therefore methodologically stronger. We do not claim any protocol-level quantum advantage in Bitcoin mining. Rather, we (t) develop a fair benchmarking framework and an instrumentation- where σi is the namespace seed or domain-separation token oriented vocabulary for assessing when QRNG insertion is assigned to worker i immediately after reboot t. Here ρ = 1 means complete post-boot diversity, whereas technically justified in mining-adjacent infrastructure. The central novelty is thus methodological: a disciplined procedure smaller values indicate repeated state. Unlike η, ρ is not a for evaluating the role of a quantum primitive within hybrid consensus quantity; it is an infrastructure-assurance metric. Together, η and ρ locate where entropy quality can matter quantum-classical systems. without altering PoW itself. A complementary finite-namespace approximation is also useful: if k work units are drawn with III. A NALYTICAL F RAMEWORK AND M EASURABLE replacement from a namespace of size N , then O BSERVABLES A Bitcoin block is accepted when H(H(Bh )) < T,
k−1 (k ≪ N ), (8) 2N which explains how overlap can arise from narrow or reused namespaces even without adversarial manipulation. E[η] ≈ 1 −
(1)
where H is SHA-256, Bh is the 80-byte block header, and T is the target implied by network difficulty [1], [3]. Under the standard assumption that double-SHA-256 outputs on distinct inputs are computationally indistinguishable from uniform values, one distinct tested header succeeds with probability
IV. S IMULATION P ROTOCOL AND VALIDATION M ETRICS
All baselines share the same header-testing logic, the same work-unit format, the same nominal work volume, and the T (2) same reseed cadence; only the entropy/control policy changes. p = 256 . 2 One simulation episode is defined as a reboot event followed Proposition 1 (Consensus neutrality): If a miner tests k by issuance of 256 work units to each of 64 workers. For each distinct candidate headers, then the probability of finding at issued unit, the simulator records the tuple w above and the least one valid block is post-boot digest of the worker namespace token. This makes P (1) = 1 − (1 − p)k ≈ kp (p ≪ 1), (3) the protocol reproducible from ordinary controller logs rather than unrealistic ASIC-level traces. No physical QRNG stream independently of whether the ordering of those k headers is used in the present implementation; the QRNG-assisted is generated by deterministic enumeration, a strong classical condition is modeled as an idealized high-entropy root to DRBG, or a QRNG-assisted entropy root. isolate the operational effect of entropy provisioning. The proposition is a baseline, not the novelty of the paper. Figure 2 summarizes the system-level separation adopted It only rules out a direct protocol-level mining advantage from in the simulations. Across all baselines, the PoW hashing QRNG substitution alone. The operational question is whether path, work-unit structure, and nominal workload remain fixed, imperfect entropy handling reduces the number of distinct work while only the entropy provisioning and scheduler-control opportunities actually explored. Let k be the number of issued layer are varied. This separation is central to the simulation work units in a measurement window and let u ≤ k be the design because it isolates QRNG-related effects to orchestration, number of distinct work units effectively explored. namespace assignment, and reseeding policy rather than to the Definition 1 (Entropy-efficiency factor): hashing engine itself. u The four baselines are as follows. B1 uses deterministic 0 < η ≤ 1. (4) η= , k partitioning with disjoint counter spaces and explicit reboot To make η measurable from scheduler logs, we use the counters for domain separation. B2 is a strong classical baseline work-unit identifier in which namespace tokens are derived from an independent w = (hprev , m, tb , nb , xb ), (5) classical entropy source plus a properly conditioned DRBG
Congresso Brasileiro de Ciências e Tecnologias Quânticas (CBCTQ 2026) – September 21–25, 2026, Innovation District of Cantareira, Niterói–RJ, Brazil
TABLE I R EPRODUCIBLE PROTOCOL PARAMETERS . Parameter
Value
PoW validation sweep
k = 103 , p = 10−3 , 3 × 104 windows per η 104 reboot episodes W = 64 256 units 20% workers restored from 6 cached images 50% of restored workers keep previous local state before reseeding resumes 95% CI on episode means
Scheduler episodes Workers per episode Issued work per worker Correlated-restart control State reuse in degraded control Confidence interval
QRNG / Entropy Source
Scheduler Control Plane
TABLE II S IMULATION - DERIVED SCHEDULER METRICS WITH 95% CONFIDENCE INTERVALS . Baseline Deterministic (B1) Strong classical (B2) QRNG-assisted (B3) Correlated-restart (B4)
η̂
ρ̂
P̂ (η̂)/P (1)
1.000 1.000 1.000 0.962±0.0004
1.000 1.000 1.000 0.899±0.0006
1.000 1.000 1.000 0.978
Workers / ASICs
PoW Hashing
Fig. 2. Architectural separation between entropy provisioning, scheduler control, and PoW execution. QRNG, when present, affects seeding, reseeding, and namespace management in the control plane, while the PoW hashing engine remains unchanged.
chain consistent with the NIST SP 800-90 series [10]–[12]. This strong-classical baseline is methodologically important because it prevents an unfair comparison between QRNG and a deliberately weak or underspecified classical entropy source. In practical terms, B2 represents the best classical engineering case considered in this study: an independent classical entropy source combined with a properly instantiated and conditioned DRBG chain under standard NIST assumptions. Under this benchmark, parity between B2 and B3 in fault-free regimes should not be read as a null result, but as evidence that QRNG is properly evaluated on assurance, provenance, and restart robustness rather than on a fictitious modification of the PoW success law. B3 is QRNG-assisted in the modeled sense: the scheduler logic and DRBG chain are preserved, but the entropy root is replaced by an idealized high-entropy seed stream representing the interface that would be supplied by a physical QRNG in a device-in-the-loop implementation. B4 is a correlated-restart control: after each reboot, 20% of workers are restored from one of six cached images, and half of those workers retain the previous local state until fresh reseeding resumes. This is not a caricatured broken RNG; it is a deployment-style fault model aimed at image reuse and brownout recovery. The protocol has two parts. First, we validate the law P (η) with Monte Carlo over η ∈ {0.75, 0.80, . . . , 1.00}. Second, we run the scheduler simulation and estimate η̂ from unique workunit identifiers and ρ̂ from post-boot token diversity. To make replication explicit, the package accompanying this submission includes the figure file used in the paper and a compact Python script that regenerates the curve and the summary metrics from the parameter set in Table I. Figure 3 confirms the analytical law and separates two questions that are often conflated: whether good entropy
Fig. 3. Normalized discovery probability versus entropy-efficiency factor η. Monte Carlo points with 95% confidence intervals follow the exact law. Competent baselines B1–B3 cluster at η ≈ 1, while the correlated-restart control B4 falls on the same curve at lower effective coverage.
engineering prevents avoidable overlap, and whether QRNG changes the PoW law itself. The answer to the first is yes under failure-prone infrastructure; the answer to the second is no. Table II makes the main simulation result precise: under competent design, deterministic, strong-classical, and modeled QRNG-assisted baselines are indistinguishable because all keep η ≈ 1. By contrast, the correlated-restart control shows measurable losses in both η and ρ, while the normalized success rate remains on the exact curve predicted by P (η). A sensitivity sweep on the correlated-restart fraction from 0 to 30% moved η̂ from 1.000 to 0.928 and ρ̂ from 1.000 to 0.852, with the measured normalized success probability staying within 0.003 of the exact curve throughout. This graded response strengthens the evidential section beyond a single stress point and shows that the observables track the theory monotonically. V. D ISCUSSION The results do not imply that QRNGs are irrelevant to mining ecosystems. Rather, they show that the appropriate benchmark is assurance, not consensus acceleration. QRNGs can strengthen the trustworthiness of the entropy root used to instantiate or reseed deterministic services, improve restart robustness in distributed controller fleets, and support defensible claims about entropy provenance in audited devices [11], [12], [22], [25], [26]. These are legitimate and technically meaningful roles for a quantum primitive within hybrid quantum-classical infrastructure.
Congresso Brasileiro de Ciências e Tecnologias Quânticas (CBCTQ 2026) – September 21–25, 2026, Innovation District of Cantareira, Niterói–RJ, Brazil
TABLE III D EPLOYMENT- ORIENTED INTERPRETATION OF QRNG ADOPTION .
A final methodological lesson is that fair benchmarking of quantum entropy in hybrid infrastructure requires strict control of confounders. Scheduler logic, work-unit format, nominal Scenario Recommended interpretation work volume, namespace size, and reseed cadence must remain Single well-partitioned No throughput case for QRNG; adoption fixed while only the entropy root varies; otherwise, a QRNG miner is mainly justified when assurance or design may appear to outperform alternatives simply because it certification requirements dominate. Coordinated pool or Strong entropy helps preserve namespace was coupled to a better scheduler or a broader namespace controller fleet freshness, identifier uniqueness, and restart policy. Reported results should therefore include η and ρ diversity. alongside discovery probability, so that any measured gain Audited appliance in a QRNG is justified by entropy provenance, mining stack defense-in-depth, and stronger trust in the can be attributed to effective coverage or post-boot diversity entropy root. rather than being misread as a change in PoW itself. The benchmarking logic developed here extends beyond the specific Bitcoin case studied in this paper. The same issue This distinction is methodologically important. A rigorous arises whenever a quantum primitive is inserted into a larger contribution in quantum technologies does not need to claim deterministic workload after initialization, including QRNGa direct algorithmic advantage over a mature classical work- backed entropy services, embedded post-quantum stacks, and load. It can instead identify a technically justified insertion controller layers for quantum communication systems. In such point for a quantum primitive, define observables for future settings, the central question is rarely whether the quantum validation, and compare that primitive fairly against competent primitive accelerates the main computation. The relevant classical baselines. In that sense, the present work is closer question is whether it improves the quality, traceability, and to quantum information engineering, secure quantum-classical resilience of the randomness-dependent services that surround integration, and deployable infrastructure design than to a that computation. generic blockchain optimization study. The threat model is intentionally narrow. We assume an honVI. C ONCLUSION est PoW engine and focus on failures in randomness-dependent support services, including repeated post-boot state, predictable For honest Bitcoin PoW, QRNG substitution is consensusnamespace seeds, image-based recovery, and avoidable overlap. neutral: the block-discovery law depends on the number of We do not model selfish mining, block withholding, ASIC distinct tested headers, not on whether candidate ordering is reverse engineering, or device-level latency and cost profiles deterministic, classically pseudorandom, or QRNG-assisted. [17]–[20]. These limitations define the scope of the analysis The contribution of this paper is therefore methodological, rather than weaken its central result. operational, and reproducible rather than protocol-altering or Trusted entropy throughput should not be confused with device-level. By introducing η and ρ, benchmarking QRNG PoW throughput. Let Rh denote the nominal header-testing against a strong classical baseline under identical scheduler rate of the mining engine, let s be the number of entropy bits logic, and incorporating a realistic correlated-restart control injected into a DRBG or namespace generator at each reseed, with confidence-bounded simulations, we show where quantum and let τ be the reseed interval. The required trusted entropy entropy can matter and how its effect can be measured. The throughput is practical implication is direct: QRNGs are most strongly s Rreq = . (9) justified as high-assurance entropy roots for mining-adjacent τ hybrid infrastructure, particularly in seeding, provisioning, In realistic deployments, Rreq can be orders of magnitude restart robustness, and auditable entropy provenance. From a deployment perspective, the decision rule is straightsmaller than Rh . This clarifies why QRNG need not operate inside the per-hash loop to be useful: it can serve at the entropy forward. If a mining stack already partitions namespaces deterroot of the control plane while deterministic logic continues ministically, recovers cleanly from reboots, and does not require strong external assurance arguments, then a well-engineered to drive the high-rate PoW engine. The main limitation of the present study is the absence classical entropy source combined with a validated DRBG may of device-level validation using physical QRNG hardware be sufficient. If, however, operators require auditable entropy or recorded QRNG bitstreams. The QRNG-assisted baseline provenance, robust synchronized-restart recovery, or defensible should therefore be interpreted as an idealized entropy-root reseeding policy across distributed controllers, then QRNG model, not as a characterization of a specific QRNG implemen- becomes technically justified without any need to invoke a tation. A natural next step is a device-in-the-loop replication fictitious consensus accelerator. In this sense, the negative result in which the scheduler is reseeded using raw or conditioned on PoW speedup becomes a positive engineering guideline for output from an actual QRNG. Such a study should record the real deployments. QRNG source model, raw-bit throughput, conditioning method, More broadly, the methodological lesson extends beyond health-test results, estimated min-entropy, reseed cadence, the specific case studied here. Many near-term quantum latency distribution, and failure/restart behavior. The resulting technologies are likely to appear first as carefully delimited operational logs would allow direct comparison of η, ρ, and subsystems embedded within larger classical infrastructures, Rreq against the deterministic and strong-classical baselines rather than as stand-alone replacements for entire computational defined here. workloads. A rigorous contribution in such settings is one that
Congresso Brasileiro de Ciências e Tecnologias Quânticas (CBCTQ 2026) – September 21–25, 2026, Innovation District of Cantareira, Niterói–RJ, Brazil
identifies the appropriate insertion point, states clearly what does and does not improve, and defines observables that enable independent validation. The present work argues that QRNG in Bitcoin-related infrastructure should be evaluated precisely in those terms. Future work should therefore prioritize hardware-in-the-loop validation with actual QRNG devices or recorded QRNG streams, allowing the proposed observables to be tested under real entropy throughput, latency, conditioning, and health-test constraints. R EFERENCES [1] S. Nakamoto, “Bitcoin: A Peer-to-Peer Electronic Cash System,” 2008. [2] Bitcoin Developer Documentation, “Mining,” developer documentation, accessed Apr. 2026. [3] A. M. Antonopoulos, Mastering Bitcoin, 2nd ed. Sebastopol, CA, USA: O’Reilly Media, 2017. [4] National Institute of Standards and Technology, Secure Hash Standard (SHS), FIPS PUB 180-4, Aug. 2015. [5] M. Herrero-Collantes and J. C. Garcia-Escartin, “Quantum random number generators,” Rev. Mod. Phys., vol. 89, no. 1, p. 015004, 2017. [6] X. Ma, X. Yuan, Z. Cao, B. Qi, and Z. Zhang, “Quantum random number generation,” npj Quantum Information, vol. 2, p. 16021, 2016. [7] S. Pironio et al., “Random numbers certified by Bell’s theorem,” Nature, vol. 464, no. 7291, pp. 1021–1024, 2010. [8] A. Acín and L. Masanes, “Certified randomness in quantum physics,” Nature, vol. 540, no. 7632, pp. 213–219, 2016. [9] V. Mannalatha, S. Mishra, and A. Pathak, “A comprehensive review of quantum random number generators: concepts, classification and the origin of randomness,” Quantum Information Processing, vol. 22, p. 439, 2023. [10] E. Barker and J. Kelsey, Recommendation for Random Number Generation Using Deterministic Random Bit Generators, NIST SP 800-90A Rev. 1, Jun. 2015. [11] E. Barker, J. Kelsey, M. Sönmez Turan, K. A. McKay, M. Baish, and M. Boyle, Recommendation for the Entropy Sources Used for Random Bit Generation, NIST SP 800-90B, Jan. 2018. [12] E. Barker, J. Kelsey, K. McKay, A. Roginsky, and M. Sönmez Turan, Recommendation for Random Bit Generator (RBG) Constructions, NIST SP 800-90C, Sep. 2025. [13] J. Bonneau, A. Miller, J. Clark, A. Narayanan, J. A. Kroll, and E. W. Felten, “SoK: Research perspectives and challenges for Bitcoin and cryptocurrencies,” in Proc. IEEE Symp. Security and Privacy, 2015, pp. 104–121. [14] A. Gervais, G. O. Karame, V. Capkun, and S. Capkun, “On the security and performance of Proof-of-Work blockchains,” in Proc. ACM CCS, 2016, pp. 3–16. [15] M. Rosenfeld, “Analysis of Bitcoin pooled mining reward systems,” arXiv:1112.4980, 2011. [16] J. A. Kroll, I. C. Davey, and E. W. Felten, “The economics of Bitcoin mining, or Bitcoin in the presence of adversaries,” in Proc. Workshop on the Economics of Information Security, 2013. [17] I. Eyal and E. G. Sirer, “Majority is not enough: Bitcoin mining is vulnerable,” in Financial Cryptography and Data Security, LNCS 8437, 2014, pp. 436–454. [18] I. Eyal, “The miner’s dilemma,” in Proc. IEEE Symp. Security and Privacy, 2015. [19] L. Luu, R. Saha, I. Parameshwaran, P. Saxena, and A. Hobor, “On power splitting games in distributed computation: The case of Bitcoin pooled mining,” in Proc. IEEE 28th Computer Security Foundations Symposium, 2015, pp. 397–411. [20] A. de Vries, “Bitcoin’s growing energy problem,” Joule, vol. 2, no. 5, pp. 801–805, 2018. [21] A. T. Vassilev and R. Staples, “Entropy as a Service: Unlocking Cryptography’s Full Potential,” Computer, vol. 49, no. 9, pp. 98–102, 2016. [22] L. Huang, H. Zhou, K. Feng, and C. Xie, “Quantum random number cloud platform,” npj Quantum Information, vol. 7, p. 107, 2021. [23] D. G. Marangon et al., “A fast and robust quantum random number generator with a self-contained integrated photonic randomness core,” Nature Electronics, vol. 7, pp. 396–404, 2024.
[24] O. M. Crampton et al., “A 2-Gbps low-SWaP quantum random number generator with photonic integrated circuits for satellite applications,” npj Quantum Information, vol. 11, p. 153, 2025. [25] P. A. Blanco, L. Trigo Vidarte, M. Romeu Casas, J. R. Martínez Saavedra, F. de la Iglesia, J. Mur-Petit, and V. Pruneri, “Integration of quantum random number generators with post-quantum cryptography algorithms,” in Proc. 25th Anniversary International Conference on Transparent Optical Networks (ICTON), 2025, pp. 1–5. [26] J. Blanco-Romero, Y. M. Garcia-Niño, F. Almenares Mendoza, D. DíazSánchez, C. García-Rubio, and C. Campo, “Post-Quantum Entropy as a Service for Embedded Systems,” arXiv:2603.10274, 2026.