Great Circle Associates Firewalls
(December 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: FEI...RFC1750 on Randomness Recommendations for Security
From: <rebar @ ins . com> (Lawrence J. Rebarchik)
Date: Thu, 29 Dec 1994 08:29:19 -0800
To: firewalls @ greatcircle . com

Folks,
This arrived in my mailbox this morning, though it'd be interesting for
folks on this list.

A new Request for Comments is now available in online RFC libraries.


        RFC 1750:

        Title:      Randomness Recommendations for Security
        Author:     D. Eastlake, 3rd, S. Crocker & J. Schiller
        Date:       December 1994
        Mailbox:    dee @
 lkg .
 dec .
 com, crocker @
 cybercash .
 com,
                    jis @
 mit .
 edu
        Pages:      25
        Characters: 73,842
        Updates/Obsoletes:  none

        URL:        ftp://ds.internic.net/rfc/rfc1750.txt


Security systems today are built on increasingly strong cryptographic
algorithms that foil pattern analysis attempts. However, the security
of these systems is dependent on generating secret quantities for
passwords, cryptographic keys, and similar quantities.  The use of
pseudo-random processes to generate secret quantities can result in
pseudo-security.  The sophisticated attacker of these security systems
may find it easier to reproduce the environment that produced the
secret quantities, searching the resulting small set of possibilities,
than to locate the quantities in the whole of the number space.
Choosing random quantities to foil a resourceful and motivated
adversary is surprisingly difficult.  This paper points out many
pitfalls in using traditional pseudo-random number generation
techniques for choosing such quantities.  It recommends the use of
truly random hardware techniques and shows that the existing hardware
on many systems can be used for this purpose.  It provides suggestions
to ameliorate the problem when a hardware solution is not available.
And it gives examples of how large such quantities need to be for some
particular applications.

This memo provides information for the Internet community.  This memo
does not specify an Internet standard of any kind.  Distribution of
this memo is unlimited.

Larry


Attachment: Get_RFC1750_on_Randomness_Recom
Description: Mac BinHex archive

Attachment: Get_rfc1750.txt
Description: Mac BinHex archive

Indexed By Date Previous: Re: Doorknob twisting
From: "Barry J. Archer" <boatmens!bja @ uustar . starnet . net>
Next: Re: TIS FWTK, DNS, forwarders et al. - slave didn't do it.
From: "Ken Paquette" <ken @ VNET . IBM . COM>
Indexed By Thread Previous: Re: Encapsulation & Security
From: Bernhard . Schneck @ Physik . TU-Muenchen . DE
Next: Re: Firewalls-Digest V3 #476
From: skerste @ sed . csc . com (Scott S. Kerstetter)

Google
 
Search Internet Search www.greatcircle.com