Randomness Improvements for Security Protocols
RFC 8937, “Randomness Improvements for Security Protocols”, is an Informational document published in October 2020 by C. Cremers, L. Garratt, S. Smyshlyaev, N. Sullivan, C. Wood. The canonical text is published by the RFC Editor.
Abstract
Randomness is a crucial ingredient for Transport Layer Security (TLS) and related security protocols. Weak or predictable "cryptographically secure" pseudorandom number generators (CSPRNGs) can be abused or exploited for malicious purposes. An initial entropy source that seeds a CSPRNG might be weak or broken as well, which can also lead to critical and systemic security problems. This document describes a way for security protocol implementations to augment their CSPRNGs using long-term private keys. This improves randomness from broken or otherwise subverted CSPRNGs.
This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 8937 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8936 Poll-Based Security Event Token Delivery Using HTTP
- RFC 8938 Deterministic Networking Data Plane Framework
- RFC 8935 Push-Based Security Event Token Delivery Using HTTP
- RFC 8939 Deterministic Networking Data Plane: IP
- RFC 8934 PCE Communication Protocol Extensions for Label Switched Path Scheduling with Stateful PCE
- RFC 8940 Extensible Authentication Protocol Session-Id Derivation for EAP Subscriber Identity Module , EAP Authentication and Key Agreement , and Protected EAP
- RFC 8933 Update to the Cryptographic Message Syntax for Algorithm Identifier Protection
- RFC 8932 Recommendations for DNS Privacy Service Operators