On the Unbearable Lightness of FIPS 140-2 Randomness Tests

On the Unbearable Lightness of FIPS 140-2 Randomness Tests
复制标题

DOI:
10.1109/tifs.2020.2988505
复制
发表时间:
2022-01-01
影响因子:
6.8
通讯作者:
Hernandez-Castro, Julio
Hernandez-Castro, Julio
中科院分区:
计算机科学1区
文献类型:
--
作者:
Hurley-Smith, Darren;Patsakis, Constantinos;Hernandez-Castro, Julio

文献摘要

被引文献

相似文献

随机数生成对于许多应用至关重要。游戏、赌博,尤其是密码学都需要统一且不可预测的随机数。为了测试所谓的随机源是否具有随机序列中常见的特定特征,使用了一系列统计测试。这些是评估随机数生成器的基本工具,也是实现它们的安全系统认证途径的一部分。尽管之前已经对此主题进行过研究(Becker,2013),但 RNG 制造商和供应商在其 RNG 验证过程中继续使用已知可靠性可疑的统计测试。我们的研究表明,FIPS-140-2 无法有效识别对抗性偏见,即使是非常原始的偏见。具体来说,这项工作说明了 FIPS 140 系列测试无法检测三个明显有缺陷的 PRNG 中的偏差。尽管已被官方标准弃用,但这些测试仍然被广泛使用,例如在许多 True RNG (TRNG) 设计中纳入的硬件级自测试方案中。它们也很受工程师和密码学家的欢迎,因为它们可以快速评估安全原语和协议的随机性特征,甚至也受到旨在向潜在客户推销其产品的随机性特征的制造商的欢迎。下面,我们提出了三个设计有偏差的 RNG,以明确详细地展示任何 FIPS 140-2 测试都无法检测到简单、明显的偏差。其中一个 RNG 存在后门,会泄露关键材料,而其他 RNG 的输出序列的不可预测性显着降低。为了使我们的观点更加简单,我们展示了包含图像的文件如何欺骗 FIPS 140 系列测试。最后,我们讨论了影响创建随机信标的有趣且活跃的项目的安全问题。他们的作者仅使用 FIPS 140 系列测试来测试随机性的质量,我们将展示这如何导致他们产生可预测的输出,尽管通过 FIPS 却无法通过其他随机性测试,这是灾难性的。
Random number generation is critical to many applications. Gaming, gambling, and particularly cryptography all require random numbers that are uniform and unpredictable. For testing whether supposedly random sources feature particular characteristics commonly found in random sequences, batteries of statistical tests are used. These are fundamental tools in the evaluation of random number generators and form part of the pathway to certification of secure systems implementing them. Although there have been previous studies into this subject (Becker, 2013), RNG manufacturers and vendors continue to use statistical tests known to be of dubious reliability, in their RNG verification processes. Our research shows that FIPS-140-2 cannot identify adversarial biases effectively, even very primitive ones. Concretely, this work illustrates the inability of the FIPS 140 family of tests to detect bias in three obviously flawed PRNGs. Deprecated by official standards, these tests are nevertheless still widely used, for example in hardware-level self-test schemes incorporated into the design of many True RNGs (TRNGs). They are also popular with engineers and cryptographers for quickly assessing the randomness characteristics of security primitives and protocols, and even with manufacturers aiming to market the randomness features of their products to potential customers. In the following, we present three biased-by-design RNGs to show in explicit detail how simple, glaringly obvious biases are not detected by any of the FIPS 140-2 tests. One of these RNGs is backdoored, leaking key material, while others suffer from significantly reduced unpredictability in their output sequences. To make our point even more straightforward, we show how files containing images can also fool the FIPS 140 family of tests. We end with a discussion on the security issues affecting an interesting and active project to create a randomness beacon. Their authors only tested the quality of their randomness with the FIPS 140 family of tests, and we will show how this has led them to produce predictable output that, albeit passing FIPS fails other randomness tests quite catastrophically.