RFC 8937: Randomness Improvements for Security Protocols
In plain English — editorial summary, not part of the RFC
Randomness is a crucial ingredient for Transport Layer Security (TLS) and related security protocols. Weak or predictable "cryptographically secure" pseudorandom number generators (CSPRNGs) can be abused or exploited for malicious purposes. An initial entropy source that seeds a CSPRNG might be weak or broken as well, which can also lead to critical and systemic security problems. This document describes a way for security protocol implementations to augment their CSPRNGs using long-term private keys. This improves randomness from broken or otherwise subverted CSPRNGs. This document is a product of the Crypto Forum Research Group (CFRG) in the IRTF.
Document record
- Document ID
- RFC8937
- Published
- October 2020
- Authors
- C. Cremers; L. Garratt; S. Smyshlyaev; N. Sullivan; C. Wood
- Status
- INFORMATIONAL
- Stream
- IRTF
- Area
- —
- Pages
- 9
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 8725JSON Web Token Best Current PracticesCurrent
February 2020
- RFC 9323A Profile for RPKI Signed Checklists (RSCs)Current
November 2022
- RFC 8387Practical Considerations and Implementation Experiences in Securing Smart Object NetworksCurrent
May 2018
- RFC 8253PCEPS: Usage of TLS to Provide a Secure Transport for the Path Computation Element Communication Protocol (PCEP)Updated
October 2017
- RFC 9691A Profile for Resource Public Key Infrastructure (RPKI) Trust Anchor Keys (TAKs)Current
December 2024
- RFC 6518Keying and Authentication for Routing Protocols (KARP) Design GuidelinesCurrent
February 2012
- RFC 5932Camellia Cipher Suites for TLSUpdated
June 2010
- RFC 5091Identity-Based Cryptography Standard (IBCS) #1: Supersingular Curve Implementations of the BF and BB1 CryptosystemsUpdated
December 2007
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?