RFC 8937 · INFORMATIONAL · 2020

Randomness Improvements for Security Protocols

Overview

RFC 8937, “Randomness Improvements for Security Protocols”, is an Informational document published in October 2020 by C. Cremers, L. Garratt, S. Smyshlyaev, N. Sullivan, C. Wood. The canonical text is published by the RFC Editor.

Abstract

Randomness is a crucial ingredient for Transport Layer Security (TLS) and related security protocols. Weak or predictable "cryptographically secure" pseudorandom number generators (CSPRNGs) can be abused or exploited for malicious purposes. An initial entropy source that seeds a CSPRNG might be weak or broken as well, which can also lead to critical and systemic security problems. This document describes a way for security protocol implementations to augment their CSPRNGs using long-term private keys. This improves randomness from broken or otherwise subverted CSPRNGs.

This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 8937 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2020

Who Is Online

In total there are 284 users online: 0 registered, 274 guests and 10 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler Other Spider PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372