SSCP Systems Security Certified PractitionerCryptographyEasy

A software developer is creating an application that requires a cryptographically secure random number generator for generating session keys. The operating system's default pseudo-random number generator (PRNG) is available, but the developer is concerned about its suitability for security-critical functions. Which characteristic is most important for a cryptographically secure random number generator (CSRNG) that the PRNG might lack?

  1. AHigh speed of generation
  2. BLow memory footprint
  3. CReproducibility for debugging
  4. DUnpredictability of output
Show answer & explanation

Correct answer: D. Unpredictability of output

The primary characteristic distinguishing a cryptographically secure random number generator from a general-purpose PRNG is the unpredictability of its output. For security-critical functions like key generation, an attacker must not be able to guess future outputs based on past outputs or the generator's state.

Why the other options are wrong

  • A. High speed is desirable but secondary to security for CSRNGs; some secure methods can be slower.
  • B. Low memory footprint is a general software optimization, not a defining cryptographic security characteristic.
  • C. Reproducibility is antithetical to cryptographic security, as it implies predictability.

Cryptographically Secure Random Number Generator (CSRNG)

A random number generator suitable for cryptographic applications, where the output is computationally indistinguishable from true randomness, especially in terms of unpredictability.

  • Outputs are unpredictable, even if internal state is known.
  • Must withstand malicious attempts to predict future values.
  • Often seeded with high-entropy sources from the environment.

Memory trick: CSRNGs are like secret dice, you can never guess the next roll.

More Cryptography questions