USB True Random Number Generator
entropykey.co.uk
entropykey.co.uk
My impression of the HW random number generator industry was that it was all snake oil, only the people selling them didn't necessarily know that was true.
Se also: http://web.archive.org/web/20011027002011/http://dilbert.com...
[edit] The technical section of the webpage[1] directly addresses most of the problems that the RS-232 devices I looked into a number of years ago had; namely it detects when the diodes are going bad, and tries to not exceed the estimated entropy rate (the RS-232 devices just blindly XORed them together at a predefined bitrate; boxes typically had 4 diodes, since 1 or more was bad in almost all shipping boxes). My experience was so bad with those devices though that I would want to spend a lot of time with any HW device before trusting it.
How do you judge the quality of a series of random numbers?
I would collect the bit stream then run the result through SHA256 in 256 bit batches.
In general I find that snake oil salesmen don't realize that they're snake oil salesmen.
One of the problems of that approach is the low quality of the built in A/D converter of the PIC, another the ease with which powerline hum and other electromagnetic noise made it into the circuitry. We did get the circuit to work, but it was hard to duplicate with lots of fiddling required before we had a series of 4 of them good enough for production use.
A typical test run would take a week and it was not rare to see 'good' performance on a test run of a day while still having to discard components after a week.
They were used to power an online casino.
There is a whole set of tests that you can run to determine the quality of your random data, hashing functions applied to the output of a less than perfect RNG will only fool the most naive of such tests.
Of course it all depends on the quality desired, in my case I had to satisfy all those tests and it was surprisingly hard to do, it's one of the few contracting jobs that I ever landed fixed price that I actually lost money on, the upside is that I learned an awful lot, especially about PCB layout, ground planes, power supply stabilization and semiconductor behaviour as well as analyzing such a system over an extended period.
It's the weirdest thing to be able to graph a perfect sinewave extrapolated from long term analysis of the summation of a few billion samples when looking for 50 or 100 Hz influences, especially if those samples pass most tests for randomness with flying colours. Circuits containing both analog and digital components are a black art, and my hat is definitely off to those that do this for a living and have turned it in to a science. Dabblers like me would do better to know the limits of their knowledge, I did eventually get it to work but if such a job came my way again I'd decline in spite of knowing more now about the subject than back then when I first took that job.
You might claim that the hardness guarantees of PRNGs are not enough for you -- they are based on some assumptions after all -- but that is a specious objection, because those are the same assumptions that underlie all of digital security and e-commerce.
all PRNGs have cycles: that is, they'll produce random numbers x[1], x[2], ... , x[n], then random number x[n+1] = x[1], x[n+2] = x[2], .... often n isn't as big as you'd like, and sometimes there are correlations among x[i] and x[i+k] you really don't want (linear congruent generators have this problem).
the PRNG is a deterministic function of its seed. the hash is a deterministic function of the output. if you do the math and calculate the entropy (this isn't hard) you'll see that the total entropy is still 80 bits because the distributions of the PRNG output given the seed, and of the hash given the output have no entropy. the marginal entropy of the PRNG is 80 bits if you don't observe the seed.
another way of seeing this is via the data processing inequality: http://www.neng.usu.edu/classes/ece/7680/lecture3/node2.html
if you're going to generate another 80 bits of entropy, then simply use this as the seed for another PRNG. this, sure, i agree, will get you more entropy, because you're adding more entropy to the system from an external source (such as the advertised device).
If I understand both correctly, the Quantis one generates a random number that didn't exist before generation due to quantum measurement principles, whereas the Simtec one uses a high noise environment in which the number does exist before measurement.
The device the article is about measures electron flow through an electronic component through which 'usually' no electrons flow. That electrons flow in this device, is because they tunnel through the potential barrier. That's a quantum effect if there ever was one.
Converting the presence of electron flow into a number means you construct these numbers on the fly. The numbers did not 'exist before', for any reasonable meaning of that term.
Yes, you can buy "quantum generators" for only £36!
Seriously though, the noise that Simtec is measuring is unpredictable and based on a quantum process (electron tunnelling.)
Another similar method is to take static from radio waves. While random it's unfortunately hackable by someone who has a radio transmitter and can get close enough to your antenna (the same can be done with the microphone).
I worked at a poker startup and sourcing random numbers is both a political and mathematical nightmare.
I mean, the Universe wouldn't vanish or explode. We'd just all be dead, and it'd stop being interesting, the same way your magnesium strip is pretty boring and useless once it's finished burning.
> "...it has a pair of devices that are wired up in such a way that as a high potential is applied across them, where electrons do not normally flow in this direction and would be blocked, the high voltage compresses the semiconduction gap sufficiently that the occasional stray electron will quantum tunnel through the P-N junction. (This is sometimes referred to as avalanche noise.) When this happens is unpredictable, and this is what the Entropy Key measures."
'Unpredictable' would qualify as random.