SSCP Systems Security Certified PractitionerCryptographyMedium

A system administrator is configuring a new web server and needs to generate a strong, random key for its TLS certificate. The process requires a source of true randomness to ensure the cryptographic strength of the generated key. Which of the following is considered the BEST source for generating cryptographically strong random numbers?

  1. AUser-provided input, such as mouse movements and keyboard timings
  2. BPseudorandom Number Generator (PRNG) seeded with the system time
  3. CLinear Congruential Generator (LCG) algorithm
  4. DHardware Random Number Generator (HRNG) utilizing physical phenomena
Show answer & explanation

Correct answer: D. Hardware Random Number Generator (HRNG) utilizing physical phenomena

Hardware Random Number Generators (HRNGs) utilize unpredictable physical phenomena (e.g., thermal noise, atmospheric static) to produce true random numbers. This provides the highest quality of entropy for cryptographic key generation, making them superior to software-based PRNGs for critical security applications.

Why the other options are wrong

  • A. While user input can contribute to entropy, it's often insufficient and too slow to be the sole or primary source for generating cryptographically strong keys for a server.
  • B. PRNGs are deterministic and, when seeded with predictable inputs like system time, can produce predictable outputs, making them weak for cryptographic keys.
  • C. LCGs are simple PRNGs known for their predictability and are not suitable for cryptographic purposes.

Hardware Random Number Generator (HRNG)

A physical device that generates random numbers from a physical process, such as thermal noise or quantum phenomena, providing high-quality entropy suitable for cryptographic applications.

  • Produces 'true' random numbers, unlike software PRNGs.
  • Essential for generating strong cryptographic keys and nonces.
  • Less predictable and therefore more secure than software-based random number generators.

Memory trick: Randomness: Hardware is True, Software is Pseudotrue!

More Cryptography questions