Chapter 10
Challenges in Certifying Small-Scale
(IoT) Hardware Random Number
Generators
Darren Hurley-Smith and Julio Hernandez-Castro
Abstract This chapter focuses on the testing and certification of Random Number
Generators (RNG). Statistical testing is required to identify whether sequences
produced by RNG demonstrate non-random characteristics. These can include
structures within their output, repetition of sequences, and any other form of
predictability. Certification of computer security systems draws on such evaluations
to determine whether a given RNG implementation contributes to a secure, robust
security system. Recently, small-scale hardware RNGs have been targeted at IoT
devices, especially those requiring security. This, however, introduces new technical
challenges; low computational resources for post-processing and evaluation of onboard RNGs being just two examples. Can we rely on the current suite of statistical
tests? What other challenges are encountered when evaluating RNG?
10.1 Introduction
Randomly generated values are sought after for a variety of applications, in which
they are often vital. Cryptographic systems require random values to ensure that
generated keys are unpredictable, making brute force attacks against those keys
unfeasible. Even in the entertainment industry, there is a demand for randomness:
lotteries and games both rely on random number generation to guarantee the fairness
of the game in question.
However, random number generation is a non-trivial task. Deterministic Random
Number Generators (DRNG), also known as Pseudo-Random Number Generators
(PRNG), are incapable of truly random output [514]. PRNG achieve an appropriate
degree of randomness by using an initial seed value to populate a proportionally
far longer sequence of apparently random output. This form of random number
generation is only unpredictable if the seed value remains unknown. To this end,
D. Hurley-Smith () · J. Hernandez-Castro
University of Kent, Canterbury, UK
e-mail: darren.hurley-smith@rhul.ac.uk
© The Author(s) 2021
G. Avoine, J. Hernandez-Castro (eds.), Security of Ubiquitous Computing Systems,
https://doi.org/10.1007/978-3-030-10591-4_10
165
Précédent

- 173/268

Suivant