SSCP Systems Security Certified PractitionerCryptographyEasy
A software developer is creating an application that requires a cryptographically secure random number generator for generating session keys. The operating system's default pseudo-random number generator (PRNG) is available, but the developer is concerned about its suitability for security-critical functions. Which characteristic is most important for a cryptographically secure random number generator (CSRNG) that the PRNG might lack?
- AHigh speed of generation
- BLow memory footprint
- CReproducibility for debugging
- DUnpredictability of output
Show answer & explanationAnswer & explanation
Correct answer: D. Unpredictability of output
The primary characteristic distinguishing a cryptographically secure random number generator from a general-purpose PRNG is the unpredictability of its output. For security-critical functions like key generation, an attacker must not be able to guess future outputs based on past outputs or the generator's state.
Why the other options are wrong
- A. High speed is desirable but secondary to security for CSRNGs; some secure methods can be slower.
- B. Low memory footprint is a general software optimization, not a defining cryptographic security characteristic.
- C. Reproducibility is antithetical to cryptographic security, as it implies predictability.
Cryptographically Secure Random Number Generator (CSRNG)
A random number generator suitable for cryptographic applications, where the output is computationally indistinguishable from true randomness, especially in terms of unpredictability.
- Outputs are unpredictable, even if internal state is known.
- Must withstand malicious attempts to predict future values.
- Often seeded with high-entropy sources from the environment.
Memory trick: CSRNGs are like secret dice, you can never guess the next roll.