1/22
Vocabulary flashcards covering randomness, entropy, PRNG security properties, OS-level randomness interfaces, Key Derivation Functions (KDFs), and key management principles.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Entropy
A measurement in information theory used to judge how much randomness a string contains, where high entropy indicates low predictability and low information.
Uniformly random
A state where all possible values in a set are equally likely to be selected; for 8 bits, the chance of picking any specific combination is 1/256.
True Random Number Generators (TRNGs)
Nondeterministic generators that use external unpredictable physical phenomena, such as thermal noise, to extract randomness based on infinite unknown variables.
Pseudorandom Number Generators (PRNGs)
Algorithms that generate a sequence of random numbers based on an initial secret called a seed; they are deterministic and rely on enough unknown variables to make results hard to predict.
Deterministic Random Bit Generators (DRBGs)
The specific term used by NIST to refer to pseudorandom number generators (PRNGs).
Forward Secrecy
A security property of a PRNG ensuring that if an attacker compromises the current state, they cannot retrieve previously generated random numbers.
Backward Secrecy
A security property, also known as "healing," where re-seeding a PRNG with new entropy prevents an attacker who has obtained the state from determining future pseudorandom numbers.
/dev/random
A special file in Unix-like systems that provides random numbers but blocks the program until initial seeding is complete.
/dev/urandom
A special file in Unix-like systems providing random numbers from a CSPRNG that never blocks, though it may have low entropy if used too early after booting.
getrandom
A system call available in Linux and FreeBSD that acts similarly to /dev/urandom but will block if not enough entropy is available for initialization.
BCryptGenRandom
The system call used to obtain randomness on the Windows operating system.
Verifiable Random Function (VRF)
A construction to obtain random numbers in a verifiable way, where a signer uses a private key and a public seed to produce a random digest and a signature as proof.
Key Derivation Function (KDF)
A deterministic construction used to derive one or more uniformly random keys from a secret that has high entropy but may be biased.
HMAC-based Key Derivation Function (HKDF)
The most popular KDF, defined in RFC 5869, which is typically built on top of HMAC and SHA-2.
HKDF-Extract
A component of HKDF that removes biases from a secret input to produce a uniformly random secret, often utilizing an optional salt.
HKDF-Expand
A component of HKDF that takes a uniformly random secret and produces an arbitrary length output, often using an optional info argument for domain separation.
Salt (HKDF)
An input used in HKDF-Extract to differentiate different usages of the function within the same protocol; it is not required to be secret.
Info (HKDF)
A customization argument used in HKDF-Expand to differentiate a specific implementation or protocol from others.
Related Outputs
A property of HKDF where calling the function several times with the same arguments except for output length results in the same output truncated differently.
Extended Output Functions (XOFs)
Functions like SHAKE and cSHAKE that can act as KDFs because they do not expect uniformly random input and can produce practically infinite uniformly random output.
Key Management
The field and practice of storing secret keys, rotating them to heal from potential compromises, and revoking them if they are leaked.
Key Rotation
A defense-in-depth technique where keys are periodically replaced with new ones and assigned expiration dates to limit the impact of a breach.
Key Revocation
The process of canceling a key immediately once it is known to be compromised, often involving a system that checks the status of a key before use.