Randomness Requirements for Security
RFC 4086, “Randomness Requirements for Security”, is a Best Current Practice document published in June 2005 by D. Eastlake 3rd, J. Schiller, S. Crocker. It obsoletes RFC 1750. The canonical text is published by the RFC Editor.
Abstract
Security systems are built on strong cryptographic algorithms that foil pattern analysis attempts. However, the security of these systems is dependent on generating secret quantities for passwords, cryptographic keys, and similar quantities. The use of pseudo-random processes to generate secret quantities can result in pseudo-security. A sophisticated attacker may find it easier to reproduce the environment that produced the secret quantities and to search the resulting small set of possibilities than to locate the quantities in the whole of the potential number space.
Choosing random quantities to foil a resourceful and motivated adversary is surprisingly difficult. This document points out many pitfalls in using poor entropy sources or traditional pseudo-random number generation techniques for generating such quantities. It recommends the use of truly random hardware techniques and shows that the existing hardware on many systems can be used for this purpose. It provides suggestions to ameliorate the problem when a hardware solution is not available, and it gives examples of how large such quantities need to be for some applications. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
What “Best Current Practice” means
Documents the IETF community's recommended operational or procedural practice rather than a protocol specification.
The canonical text of RFC 4086 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4085 Embedding Globally-Routable Internet Addresses Considered Harmful
- RFC 4087 IP Tunnel MIB
- RFC 4084 Terminology for Describing Internet Connectivity
- RFC 4088 Uniform Resource Identifier Scheme for the Simple Network Management Protocol
- RFC 4083 Input 3rd-Generation Partnership Project Release 5 Requirements on the Session Initiation Protocol
- RFC 4089 IAB and IESG Recommendation for IETF Administrative Restructuring
- RFC 4082 Timed Efficient Stream Loss-Tolerant Authentication : Multicast Source Authentication Transform Introduction
- RFC 4090 Fast Reroute Extensions to RSVP-TE for LSP Tunnels