RFC 4086: Randomness Requirements for Security
In plain English — editorial summary, not part of the RFC
Security systems are built on strong cryptographic algorithms that foil pattern analysis attempts. However, the security of these systems is dependent on generating secret quantities for passwords, cryptographic keys, and similar quantities. The use of pseudo-random processes to generate secret quantities can result in pseudo-security. A sophisticated attacker may find it easier to reproduce the environment that produced the secret quantities and to search the resulting small set of possibilities than to locate the quantities in the whole of the potential number space. Choosing random quantities to foil a resourceful and motivated adversary is surprisingly difficult. This document points out many pitfalls in using poor entropy sources or traditional pseudo-random number generation techniques for generating such quantities. It recommends the use of truly random hardware techniques and shows that the existing hardware on many systems can be used for this purpose. It provides suggestions to ameliorate the problem when a hardware solution is not available, and it gives examples of how large such quantities need to be for some applications. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
Document record
- Document ID
- RFC4086
- Published
- June 2005
- Authors
- D. Eastlake 3rd; J. Schiller; S. Crocker
- Status
- BEST CURRENT PRACTICE
- Stream
- IETF
- Area
- —
- Pages
- 48
- Also known as
- BCP106
- Obsoletes:
- RFC 1750
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 3679Unused Dynamic Host Configuration Protocol (DHCP) Option CodesUpdated
January 2004
- RFC 4895Authenticated Chunks for the Stream Control Transmission Protocol (SCTP)Current
August 2007
- RFC 3228IANA Considerations for IPv4 Internet Group Management Protocol (IGMP)Obsoleted
February 2002
- RFC 3171IANA Guidelines for IPv4 Multicast Address AssignmentsObsoleted
August 2001
- RFC 2939Procedures and IANA Guidelines for Definition of New DHCP Options and Message TypesCurrent
September 2000
- RFC 5237IANA Allocation Guidelines for the Protocol FieldCurrent
February 2008
- RFC 2754RPS IANA IssuesObsoleted
January 2000
- RFC 2434Guidelines for Writing an IANA Considerations Section in RFCsObsoleted
October 1998
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?