Randomness Recommendations for Security
RFC 1750, “Randomness Recommendations for Security”, is an Informational document published in December 1994 by D. Eastlake 3rd, S. Crocker, J. Schiller. It has been obsoleted by RFC 4086 — refer to the newer document for the authoritative version. The canonical text is published by the RFC Editor.
Abstract
Choosing random quantities to foil a resourceful and motivated adversary is surprisingly difficult. This paper points out many pitfalls in using traditional pseudo-random number generation techniques for choosing such quantities. It recommends the use of truly random hardware techniques and shows that the existing hardware on many systems can be used for this purpose. This memo provides information for the Internet community. This memo does not specify an Internet standard of any kind.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 1750 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 1749 IEEE 802.5 Station Source Routing MIB using SMIv2
- RFC 1751 A Convention for Human-Readable 128-bit Keys
- RFC 1748 IEEE 802.5 MIB using SMIv2
- RFC 1753 IPng Technical Requirements Of the Nimrod Routing and Addressing Architecture
- RFC 1746 Ways to Define User Expectations
- RFC 1745 BGP4/IDRP for IP---OSPF Interaction
- RFC 1744 Observations on the Management of the Internet Address Space
- RFC 1743 IEEE 802.5 MIB using SMIv2