Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

The Entropy Problem: Random Data and Secure Cryptography

PKWARE

By PKWAREProductivity Protected

Share on social media

The strength of any cryptosystem depends in large part on the unpredictability of the data used in the encryption process. Unfortunately, some of today’s most commonly used sources of “random” data depend on inputs that have the potential to inject predictable data, and therefore weakness, into the process.

What Entropy Actually Means

Random data sits alongside strong algorithms and sound key management as a foundation of cryptography. It feeds key generation, key wrapping, authentication, and many other routine functions.

Randomness is described as entropy, meaning unpredictability, and it can be measured with statistical tests. Data with an entropy value of zero is completely deterministic. Data with a value of one is full entropy, and it is genuinely random. Nobody can predict a given bit in the stream with better than 50 percent accuracy.

This matters because AES-256 is strong enough that brute force is pointless. Even the most powerful computers would need billions of years to try every key. Feed predictable data into the key generation process, though, and you create shortcuts. Any flaw in the original source of entropy carries through to the end, and the ciphertext inherits it.

Where Common Approaches Fall Short

Random data is usually drawn from a physical generator, a software-based generator, or a combination of the two. Both have limits.

Hardware generators collect entropy by measuring events expected to be random. That might be ambient sound or cosmic background radiation from outside the machine, or hard drive activity, voltage fluctuation, and keyboard and mouse input from inside it. There is a theoretical concern that those events could be manipulated to produce predictable output. The practical concern is throughput. Most physical generators produce data slowly, which forces a compromise between how much entropy you get and how fast cryptographic work completes.

Software generators, known as PRNGs, take a seed value and expand it algorithmically into a stream much longer than the seed itself. They deliver far better throughput, and several approaches have been certified by NIST as cryptographically secure and acceptable in high-security settings.

The Quantum Question

That certification has a horizon. Even high-performance generators certified as cryptographically secure today may prove insufficiently random once large-scale quantum computers arrive. The expectation is that quantum computing will break the asymmetric keys underpinning public key infrastructure, while remaining ineffective against a truly random AES-256 key.

Generators that measure quantum physical processes produce genuinely random data at rates up to 1 Gb per second, which removes the throughput compromise for government bodies and other organizations handling highly sensitive information.

Four Limits of Software Generators

A PRNG has no intrinsic entropy and can never produce genuinely random data, because the algorithms are deterministic by design. The same seed always produces the same output.

Poorly designed or outdated algorithms generate predictable data, and the flaw is usually hard to spot until someone has already exploited it. Even a cryptographically secure generator depends on being configured and implemented correctly, and an implementation fault is equally hard to find in advance. Algorithms can also be weakened deliberately. Dual_EC_DRBG was in widespread use until 2014, when NIST removed it from its guidance over a reported backdoor.

There is also the problem of running low. Generators that draw entropy from system information struggle during and shortly after startup, when activity is predictable and users are not yet doing much. Virtual machines are worse, because they often lack direct access to the system and user activity that would fill the entropy pool, and several machine images created from the same initial state will tend to produce identical output.

How These Weaknesses Get Attacked

Attackers can analyze a generator’s output stream for patterns, which is impractical against a cryptographically secure implementation but a real concern with a weak algorithm. They can work from the inputs instead: every PRNG is deterministic, so knowing the seed reproduces the output, and a low-entropy seed can sometimes simply be guessed. That is not theoretical. In the early days of the internet a low-entropy generator let attackers decrypt Netscape’s SSL traffic using consumer hardware. Where the seed cannot be guessed, it can sometimes be manipulated instead.

This whitepaper explains:

  • Why random matters
  • Common approaches and their weaknesses
  • How to roll out enterprise-wide encryption management

Download The Whitepaper

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.