NIST SP 800-90A
NIST SP 800-90A
Main page

NIST SP 800-90A

logo
Community Hub0 subscribers
What are your thoughts?
Be the first to start a discussion here.
Be the first to start a discussion here.
NIST SP 800-90A

NIST SP 800-90A ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. The publication contains the specification for three allegedly cryptographically secure pseudorandom number generators for use in cryptography: Hash DRBG (based on hash functions), HMAC DRBG (based on HMAC), and CTR DRBG (based on block ciphers in counter mode). Earlier versions included a fourth generator, Dual_EC_DRBG (based on elliptic curve cryptography). Dual_EC_DRBG was later reported to probably contain a kleptographic backdoor inserted by the United States National Security Agency (NSA).

As a work of the US Federal Government, NIST SP 800-90A is in the public domain and freely available.

The predecessor to NIST SP 800-90A was published by the National Institute of Standards and Technology in June 2006 as NIST SP 800-90 with the title Recommendation for Random Number Generation Using Deterministic Random Bit Generators. This 2006 publication contains the specification for four allegedly cryptographically secure pseudorandom number generators for use in cryptography: Hash_DRBG (based on hash functions), HMAC_DRBG (based on HMAC), CTR_DRBG (based on block ciphers in counter mode), and Dual_EC_DRBG (based on elliptic curve cryptography).

In March 2007, the publication NIST SP 800-90 Revised (800-90R) with the same title replaced the earlier version. Besides some minor textual clarification, there was a substantial change in the form of an additional step for Dual_EC_DRBG to provide backtracking resistance.

In January 2012, NIST SP 800-90A was published to replace NIST SP 800-90 Revised. The change notes mention that most of the revision was finished in August 2008, and that the recommendation was developed in concert with ANSI X9.82-3. Non-algorithmic changes included addition of explanations, definitions, and a rule against self-reseeding. The instantiation function for Dual_EC_DRBG was substantially revised; the appendix dedicated to justifying this DBRG received a new paragraph. The new hash functions from FIPS 180-4 were added in the discussion of hash-based

In June 2015, NIST 800-90A Revision 1 (800-90Ar1) was released. The most notable change is the removal of the dubious Dual_EC_DRBG algorithm.

Dual_EC_DBRG was not first introduced to the public in NIST SP 800-90 of 2006. It was seen in an 2004 draft of ANSI X9.82-3 as well as the official version of ISO/IEC 18031:2005. Its flaws were first proven in March 2006, when Kristian Gjøsteen published a method to predict the bias in the version found in the December 2015 draft of NIST SP 800-90. However, the subsequent publication in June 2006 did not address this flaw.

In 2007, Dan Shumow and Niels Ferguson provided a much stronger attack with the ability to recover the entire internal state with just 32 bytes of output, predicting all its future output. The unexplained constants in Dual_EC_DRBG were hypothesized to act like a public key; an attacker would use a different set of numbers (analogous to a private key) to mount the attack. Shumow and Ferguson were not able to recover the NSA's key, but they were able to construct their own pair of keys for a demonstration. In November 2007, Bruce Schneier commented on the "strange" nature of the history of this random number generator and described the Shumow and Ferguson presentation in more accessible terms.

See all
User Avatar
No comments yet.