170
D. Hurley-Smith and J. Hernandez-Castro
Black-box design is often employed by companies using licensed technology, or
who need to protect their Intellectual Property (IP). This means that schematics of
their security implementation, including RNG, may not be publicly accessible. For
lower EAL awards, such obfuscation of technical detail may extend to inspectors
and CC officials. At higher levels, non-disclosure agreements are required as a part
of the certification contract between the petitioning company and the evaluating
body. Such arrangements are expensive. Inspectors and independent testers have
to be compensated for their times and the cost falls to the company requesting an
evaluation at a given EAL. As a result, self-certification is common.
The speed with which an RNG may be read depends on a great many factors.
In situations where the RNG is fully integrated, there may be additional overheads
such as post-processing, use of a PRNG to clean TRNG output used as an entropy
source, or simply a hard limit on output size and speed. A poignant example of
this is the DESFire EV1 and EV2. These RFID cards do not directly expose their
internal TRNG to the user, requiring that the user extracts random numbers using
the authentication protocol instead. This protocol requires that both the card and
reader exchange random values as part of their authentication handshake [289].
The 16 bytes values transmitted by the card can be collected and stored in a file
for analysis using statistical tests for randomness [288]. This is a time-consuming
procedure, as Table 10.2 shows. To collect 64 MB of data from the DESFire cards,
approximately 12 days were required. The primary bottleneck in this process was
the need to complete the authentication protocol before a second handshake could
be initiated to gather additional 16-byte sequences. Attempting to terminate the
protocol by switching off the reader, thus resetting the card, proved to be even more
time-intensive [288]. This issue is shared by IoT devices, many of which implement
integrated TRNGs.
IoT devices have a plethora of ways in which PRNG and TRNG may be
implemented. The FRDM K64F board implements a TRNG, though the output is
limited to making calls internally for use, or outputting values over an I/O pin in
the form of unsigned integers. Though significantly faster than the EV1 and EV2,
this is still much slower than most standalone TRNGs. The Red Bear Duo does
not implement a local entropy source. An on-board PRNG must be supplied with
off-device entropy, with no checks or continuous tests performed on-device. In a
full-system implementation, such a device can make it difficult to identify where
the flaw in its RNG occurs.
Table 10.2 RNG output
speed of selected devices
Sample size (MB) Mean data rate (bit/s)
DESFire EV1
64
4.93 · 10 2
DESFire EV2
64
4.90 · 10 2
Quantis 16M
2100
1.27 · 10 8
Quantis 4M
2100
3.08 · 10 7
Quantis USB 4M
2100
3.11 · 10 7
Comscire PQ32MU 2100
2.48 · 10 8
ChaosKey
2100
3.07 · 10 7
D. Hurley-Smith and J. Hernandez-Castro
Black-box design is often employed by companies using licensed technology, or
who need to protect their Intellectual Property (IP). This means that schematics of
their security implementation, including RNG, may not be publicly accessible. For
lower EAL awards, such obfuscation of technical detail may extend to inspectors
and CC officials. At higher levels, non-disclosure agreements are required as a part
of the certification contract between the petitioning company and the evaluating
body. Such arrangements are expensive. Inspectors and independent testers have
to be compensated for their times and the cost falls to the company requesting an
evaluation at a given EAL. As a result, self-certification is common.
The speed with which an RNG may be read depends on a great many factors.
In situations where the RNG is fully integrated, there may be additional overheads
such as post-processing, use of a PRNG to clean TRNG output used as an entropy
source, or simply a hard limit on output size and speed. A poignant example of
this is the DESFire EV1 and EV2. These RFID cards do not directly expose their
internal TRNG to the user, requiring that the user extracts random numbers using
the authentication protocol instead. This protocol requires that both the card and
reader exchange random values as part of their authentication handshake [289].
The 16 bytes values transmitted by the card can be collected and stored in a file
for analysis using statistical tests for randomness [288]. This is a time-consuming
procedure, as Table 10.2 shows. To collect 64 MB of data from the DESFire cards,
approximately 12 days were required. The primary bottleneck in this process was
the need to complete the authentication protocol before a second handshake could
be initiated to gather additional 16-byte sequences. Attempting to terminate the
protocol by switching off the reader, thus resetting the card, proved to be even more
time-intensive [288]. This issue is shared by IoT devices, many of which implement
integrated TRNGs.
IoT devices have a plethora of ways in which PRNG and TRNG may be
implemented. The FRDM K64F board implements a TRNG, though the output is
limited to making calls internally for use, or outputting values over an I/O pin in
the form of unsigned integers. Though significantly faster than the EV1 and EV2,
this is still much slower than most standalone TRNGs. The Red Bear Duo does
not implement a local entropy source. An on-board PRNG must be supplied with
off-device entropy, with no checks or continuous tests performed on-device. In a
full-system implementation, such a device can make it difficult to identify where
the flaw in its RNG occurs.
Table 10.2 RNG output
speed of selected devices
Sample size (MB) Mean data rate (bit/s)
DESFire EV1
64
4.93 · 10 2
DESFire EV2
64
4.90 · 10 2
Quantis 16M
2100
1.27 · 10 8
Quantis 4M
2100
3.08 · 10 7
Quantis USB 4M
2100
3.11 · 10 7
Comscire PQ32MU 2100
2.48 · 10 8
ChaosKey
2100
3.07 · 10 7
