I-D Action: draft-eastlake-randomness3-00.txt

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



A New Internet-Draft is available from the on-line Internet-Drafts directories.


	Title           : Randomness Requirements for Security
	Author(s)       : Donald E. Eastlake
                          Steve Crocker
                          Charlie Kaufman
                          Jeffrey I. Schiller
	Filename        : draft-eastlake-randomness3-00.txt
	Pages           : 53
	Date            : 2013-11-05

Abstract:
   Security systems are built on strong cryptographic algorithms that
   foil pattern analysis attempts. However, the security of these
   systems is dependent on generating secret quantities for passwords,
   cryptographic keys, and similar values. The use of pseudo-random
   processes to generate secret quantities can result in pseudo-
   security.  For example, the sophisticated attacker of these security
   systems may find it easier to reproduce the environment that produced
   the secret quantities, searching a resulting small set of
   possibilities, than to locate the quantities in the whole of the
   potential number space.

   Choosing random quantities to foil a resourceful and motivated
   adversary can be surprisingly difficult. This document points out
   many pitfalls in using poor entropy sources or traditional pseudo-
   random number generation techniques for generating such quantities.
   It recommends the use of multiple sources with a strong mixing
   function, so that no single source need be fully trusted, and
   provides techniques for extending a random seed to a larger quantity
   of pseudo-random material in a cryptographically secure way. And it
   gives examples of how large such quantities need to be for some
   applications. This document obsoletes RFC 4086.



The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-eastlake-randomness3

There's also a htmlized version available at:
http://tools.ietf.org/html/draft-eastlake-randomness3-00


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt




[Index of Archives]     [IETF]     [IETF Discussion]     [Linux Kernel]

  Powered by Linux