Generate pseudo-random number sequences in parallel using multiple generators with salted initial states

By generating salt values ​​containing pseudo-random numbers in a parallel processing environment and creating a set of pseudo-random numbers generators with unique index values, the problem of generating pseudo-random numbers sequences with good statistical characteristics in a parallel processing environment is solved, and efficient pseudo-random numbers generation on multi-threaded and vector processing hardware is realized.

CN114008585BActive Publication Date: 2025-05-02ORACLE INT CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080044450.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-08-22
Filing Date
2020-05-07
Publication Date
2025-05-02
Estimated Expiration
2040-05-07

Smart Images

  • Figure CN114008585B_ABST
    Figure CN114008585B_ABST
Patent Text Reader

Abstract

Embodiments include constructing a set of pseudo-random number generators (PRNGs) with known or unknown bases using unique salt water values, which include a salt value for the set and a different index value for each PRNG in the set. Additional parameters for such PRNGs are based on the corresponding salt water values ​​of the PRNGs, thereby ensuring that the PRNGs in the set have different state cycles. Embodiments select pseudo-random salt values ​​for each set so that PRNGs from different sets may have different additional parameters. According to an embodiment, a stream of generators in a set is created by a splitter that carries the salt value of the set and combines the salt value with the index value of the generator to generate additional parameters for the salt processing of the PRNG in the stream. According to an embodiment, such a stream can be executed in parallel by multiple threads.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to pseudo-random number generators, and more particularly to computational techniques for generating sets, sequences or streams of pseudo-random numbers with good statistical quality using a splittable pseudo-random number generator. Background Art

[0002] Many computing algorithms and applications rely on sources of pseudo-random numbers or bit strings, i.e., deterministic algorithms, devices, processes or methods that provide a set, sequence or stream of numbers or bit strings that appear or behave as if they were generated by a truly random source for appropriate purposes. One class of applications that utilize pseudo-random numbers is the so-called "Monte Carlo" methods. Another class of applications that utilize pseudo-random numbers is Markov chains.

[0003] The quality of a source of pseudorandom numbers can be judged by applying any of a number of statistical tests to its output. One widely used test is the DieHarder software suite [3]. One of the more rigorous tests in this suite is the one by Marsaglia and Tsang

[13] . Another is the statistical test suite from NIST

[15] . Perhaps the best known today is TestU01 [16, 10], including its most rigorous set of tests, called BigCrush. Another lesser-known modern test suite is PractRand [5].

[0004] There is a large literature on sequential algorithms for generating sequences of pseudorandom numbers. One sequential algorithm that is widely regarded as being of very high quality is the Mersenne twister

[14] . It is also possible to generate "true" random numbers by using the results of physical processes that are believed to have random behavior. One source of such bits available on the Internet is the "HotBits" generator

[20] .

[0005] There is a close relationship between the generation of pseudorandom numbers and the generation of hash values ​​for data structures. In particular, one can in principle generate a stream of pseudorandom numbers by applying an appropriate hash function to a stream of consecutive integers. Some hash functions are constructed by first reducing a large data structure to integers of a fixed size and then applying a finalizer, which can be a mixing function that "mixes" the values ​​of the individual bits used to represent the integer. An example of this approach is the MurmurHash3 algorithm [1], which uses a 64-bit finalizer when generating a 64-bit hash. Stafford

[17] discusses variations of this 64-bit finalizer function, each of which takes a 64-bit input and produces a 64-bit result. Each of these functions is bijective: different inputs produce different results. Each of these functions also has good avalanche statistics, meaning that, on average, for all possible inputs, changing just one bit of the input will give about a 50% chance of changing that output bit for each of the 64 output bits. Both the MurmurHash3 mixing function and the Stafford variant achieve mixing by applying a series of alternating xorshift steps and multiplication steps; for some integer shift distance k, the xorshift step transforms the input value z into z XOR(z SHIFTRIGHT k), and for some multiplier a, the multiplication step transforms the input value z into zxa. The intuition behind these steps is that the xorshift step uses information in the high-order bits to modify the low-order bits, while the multiplication step uses information in the low-order bits to modify the high-order bits. In other words, in the xorshift step, information flows from left to right, while in the multiplication step, information flows from right to left. Therefore, alternating these steps can achieve good mixing by letting information sway back and forth within the word, so that eventually every input bit can affect every output bit.

[0006] Sequential algorithms do not typically produce pseudo-random numbers with the desired statistical properties when run in parallel. Therefore, a more difficult problem than generating a sequence of pseudo-random numbers by a sequential approach is to provide a deterministic algorithm, device, process, or method that can be used by multiple shared control threads executing in parallel in such a way that each thread can independently generate a sequence of pseudo-random numbers, while a single set of numbers generated by all threads together still has good statistical properties. When parallel processing hardware such as a cluster of central processing units (CPUs) is used to perform calculations for applications such as Monte Carlo simulations, it is desirable to have such a deterministic algorithm, device, process, or method. When vector processing or SIMD hardware such as one or more graphics processing units (GPUs) is used to perform that type of calculation, it is also desirable to have such a deterministic algorithm, device, process, or method.

[0007] The Java programming language has included the class java.util.Random since its inception, instances of which are objects that provide, among other things, a nextLong() method that, when called, repeatedly produces a stream of pseudorandom values. Over the years, some shortcomings in its design have become apparent. First, it has a relatively small period (2 48 ). Second, its output does not pass the DieHarder test; in other words, java.util.Random is not a very good pseudo-random number generator by today's standards. Third, although its methods are thread-safe, it performs poorly when shared by multiple threads. Fourth, if the programmer attempts to sidestep the third disadvantage by creating a new random number generator object for each thread, there is no guarantee that this strategy will produce a collective collection of pseudo-random values ​​that is statistically as good as the collection of values ​​produced by a single random number generator object. Java 7 introduced the new class java.util.concurrent.ThreadLocalRandom to address the third disadvantage. However, it uses the same underlying mathematical algorithm as java.util.Random, so it still suffers from the first, second, and fourth disadvantages.

[0008] The implementation of java.util.concurrent.ThreadLocalRandom was inspired in part by the work done by Leiserson, Schardl, and Sukha

[12] , in which they described an algorithm they called DOTMIX. DOTMIX allows computational tasks running in parallel to independently generate pseudorandom sequences. In the model described by Leiserson, Schardl, and Sukha, the computation initially consists of a single task, and any task may at any time spawn new tasks, synchronize with tasks it spawned (wait for them to complete), or generate pseudorandom numbers. The basic idea is that each such action (spawn, sync, or generate) is associated with a unique "lineage", which is an ordered vector of integers. The computation occurs within each spawn, sync, or generate operation, ensuring that each action within the set of all actions executed by all tasks will have a different lineage. Furthermore, a generate operation produces pseudorandom numbers by performing a two-part mathematical computation on the generate operation's lineage: a dot product with the coefficient vectors, followed by a "mix" operation that conceptually "scrambles" the result of the dot product. The name "DOTMIX" comes from this two-part process of the dot product followed by the mix function. The coefficient vector is extracted from a fixed table before the initial task begins execution, which is ideally defined by some truly random process. Note that the dot product is a linear function that linearly combines the elements of the spectrum when the coefficient vector is considered fixed.

[0009] Steele, Lea, and Flood [7] describe a distantly related algorithm they call SPLITMIX that also allows computational tasks running in parallel to independently generate pseudorandom sequences. However, the algorithm is not particularly bound to parallel task structures, nor to actions such as spawn and sync. Rather, it is object-oriented: each pseudorandom number generator (PRNG) object contains some state and supports at least two methods, generate and split. The generate method advances the object's internal state and returns a pseudorandom value (usually a 64-bit integer); the split method advances the object's internal state and returns a newly created PRNG object. The paper provides some mathematical proof, based on a mathematical proof by Leiserson, Schardl, and Sukha, for why the outputs of two objects are likely to be statistically independent. The version of SPLITMIX adapted for use in the class SplittableRandom in JDK8 (Java Development Kit Release 8) uses 127 bits of internal state per object, in the form of two 64-bit integers, one of which is required to be odd. For some purposes, this may be a sufficient amount of internal state, but for other purposes, 127 bits of internal state may not provide sufficiently strong statistical independence guarantees.

[0010] L'Ecuyer [9] provides a table describing, for various computer word lengths, the constant a which, when used to construct a linear congruential generator, produces generators with particularly good figures of merit based on the lattice structure determined by the generator's output. In particular, the values ​​a=3202034522624059733 and a=3935559000370003845 are listed as being suitable for any odd number c in the form x'=ax+c mod 2 64 , and the value a = 2685821657736338717 is listed as being suitable for use in the form x' = ax mod 2 64 Used in the generator.

[0011] L'Ecuyer[8, Figure 3] describes a way to create high-quality and very long-period PRNGs by combining two or more multiplicative linear congruential generators (MLCGs), noting that the period of the combined generators can be easily "split" (partitioned) into separate parts because each underlying generator can be so partitioned. However, the splitting needs to be "planned in advance" rather than being performed on demand at any time by any thread. The technique linearly combines two or more MLCGs; for each pseudorandom value to be generated as a whole, the technique uses each MLCG generated value and then computes the sum of these generated values ​​modulo some fixed integer m. The result is a pseudorandomly chosen non-negative value less than m.

[0012] In the mid-1990s, Augustsson [2] implemented L'Ecuyer's algorithm in pure functional form as part of the Haskell standard library System.Random; the code in that library, now dated 2001, contains a kernel with two functions, stdNext and stdSplit. The implementation of stdNext is a faithful reproduction of L'Ecuyer's algorithm [8, Figure 3 ], but the stdSplit method does not split the cycles in the way that L'Ecuyer suggests; rather, it uses an ad hoc, on-demand approach that by its own admission "has no statistical basis" but is structurally no different from SPLITMIX, except that it does not attempt to compute "random" values ​​with which to initialize newly generated objects.

[0013] Claessen and Palka [4] review an application that exposes a serious flaw in the stdSplit function in the Haskell standard library System.Random, and then describe a high-level implementation of the same purely functional API that is similar in spirit to DOTMIX: it generates pseudorandom values ​​by encoding the paths in a split tree as sequences of numbers, then applying a cryptographically strong hash function. Their path encoding and hash function are designed to allow the incremental computation of successive pseudorandom values ​​in constant time, independent of the path length.

[0014] L'Ecuyer et al.

[11] describe an object-oriented C++ PRNG package, RngStream, which supports converting its very long period (approximately 2 191 ) is repeatedly split into streams and substreams. The package uses a combined multi-recursive generator called MRG32k3a[6], where the outputs of two smaller generators are added together. The period of the two smaller generators is and where m1 and m2 are different prime numbers, which are chosen so that (m1-1) / 2 and (m2-1) / 2 are relatively prime. Therefore, the period of the entire generator is It is one-half the product of the smaller generator period. In fact, m1 = 4294967087 = 2 32 -209 and m2 = 4294944443 = 2 32 -22853, so the period is about 2 191 Given an instance of such a generator, there are situations where you can "jump" a long way forward along the state cycle (such as 2 76 or 2 127 ). In fact, by starting from a specific state, you can repeatedly jump forward 2 127 , to obtain a set of "stream start states"; then from each such state we can repeatedly jump forward 2 76 to obtain the set of “subflow start states”. Under very reasonable practical assumptions, the application will need no more than 2 60 streams, no more than 2 from each stream 51 substreams, and no more than 2 76 This approach ensures that the parts of the state loop traversed by the subflows will not overlap.

[0015] Vigna et al. [18, 19] discussed and analyzed various designs of xorshift generators, whose specific instances have names such as xoroshirol28**, xoroshiro128+, and xoshiro256**.

[0016] The methods described in this section are methods that could be employed, but are not necessarily methods that have been previously conceived or employed. Therefore, unless otherwise indicated, it should not be assumed that any method described in this section is prior art simply because it is included in this section. In addition, it should not be assumed that any method described in this section is well-known, routine, or conventional simply because it is included in this section. Summary of the invention

[0017] According to one aspect of the present disclosure, a computer-implemented method is provided, comprising: generating a salt value comprising a first pseudo-random number; creating each PRNG of a set of PRNGs based on a pseudo-random number generator PRNG-specific salt value, the PRNG-specific salt value comprising (a) at least a portion of the salt value and (b) an index value unique to each PRNG in the set of PRNGs; and enabling the two or more PRNGs in the set of PRNGs to generate pseudo-random numbers in parallel by running the two or more PRNGs in the set of PRNGs on corresponding two or more threads of a multi-threaded processor; wherein the method is executed by one or more computing devices.

[0018] In one example, the method further includes: receiving a request for a specific PRNG in a set of PRNGs to generate a pseudo-random number; wherein the specific PRNG is created based on a specific salt water value; in response to receiving the request for the specific PRNG to generate a pseudo-random number, the specific PRNG generates a pseudo-random number using at least a portion of the specific salt water value; and the specific PRNG returns the generated pseudo-random number as a response to the request to generate a pseudo-random number.

[0019] In one example, creating each PRNG in the set of PRNGs based on a PRNG-specific saline value includes creating the specific PRNG based on the specific saline value by having additional parameters of the specific PRNG include at least a portion of the specific saline value.

[0020] In one example, creating each PRNG in a set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; the method also includes generating the specific salt water value by: determining a number of bits, wherein a group of bits including the determined number of bits is at least capable of representing a known cardinality of the set of PRNGs, filling a first group of bits in a representation of the specific salt water value with the specific portion of the salt value, and filling a second group of bits in a representation of the specific salt water value with the specific index value, wherein the number of bits in the second group of bits is the determined number of bits.

[0021] In one example, creating each PRNG in a set of PRNGs based on a PRNG-specific saltwater value includes creating a specific PRNG based on a specific saltwater value, the specific saltwater value including a specific portion of a saltwater value and a specific index value unique to the specific PRNG; the method also includes generating the specific saltwater value by: filling a first group of bits in a representation of the specific saltwater value with a sliding boundary index value, wherein the number of bits in the first group of bits is predetermined, wherein the sliding boundary index value identifies a specific bit in the representation of the specific saltwater value, filling a second group of bits with the specific index value, wherein the boundary of the second group of bits is the specific bit in the representation of the specific saltwater value, and filling a third group of bits with the specific portion of the saltwater value, wherein the third group of bits includes bits of the representation of the specific saltwater value that are not in the first group of bits and not in the second group of bits.

[0022] In one example, creating each PRNG in a set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; the method further includes generating the specific salt water value by setting a flag bit of each of one or more first bit groups in a representation of the specific salt water value to indicate that each bit group includes salt value information, wherein the one or more first bit groups collectively represent the specific portion of the salt value, and setting an index flag bit of one or more second bit groups in a representation of the specific salt water value to indicate a boundary bit of the specific index value, wherein the one or more second bit groups collectively represent the specific index value.

[0023] In one example, creating each PRNG of a set of PRNGs based on a PRNG-specific saltwater value includes creating a specific PRNG based on a specific saltwater value, the specific saltwater value including a specific portion of a salt value and a specific index value unique to the specific PRNG; the method also includes generating the specific saltwater value by: in a representation of the specific saltwater value, filling a first set of one or more bit groups with the specific portion of the salt value, wherein each bit group in the first set of one or more bit groups represents a value that does not satisfy a boundary value test, in the representation of the specific saltwater value, filling a boundary bit group with a value that satisfies the boundary value test, and in the representation of the specific saltwater value, filling a second set of one or more bit groups with the specific index value, wherein the boundary bit group is located between the first set of one or more bit groups and the second set of one or more bit groups in the representation of the specific saltwater value.

[0024] In one example, a boundary value test tests whether the value represented by the bits is the largest number representable by the bits.

[0025] In one example, creating the set of PRNGs is performed in parallel by at least two threads of a processor running corresponding PRNG generators using the same salt value.

[0026] In one example, each PRNG in the set of PRNGs utilizes a xorshift generator algorithm from a group of xorshift generator algorithms including xoroshiro64; xoroshiro128; xoshiro256; xoshiro512; and xoroshiro1024.

[0027] In one example, the method further includes: receiving a request to create a second set of PRNGs; in response to receiving the request to create the second set of PRNGs, creating the second set of PRNGs by: generating a second salt value including a second pseudo-random number, wherein the second pseudo-random number is different from the first pseudo-random number, and creating each PRNG in the second set of PRNGs based on the PRNG-specific salt value, wherein the salt value includes (a) at least a portion of the second salt value and (b) an index value unique to each PRNG in the second set of PRNGs. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In the attached picture:

[0029] Figure 1 Depicted is a flow chart for generating pseudorandom numbers by non-linearly combining two or more component pseudorandom numbers generated from two or more auxiliary pseudorandom number generators.

[0030] Figure 2 is a block diagram of a computer system upon which an embodiment may be implemented.

[0031] Figure 3 Depicted are software systems that may be used in embodiments. DETAILED DESCRIPTION

[0032] In the following description, for the purpose of explanation, many specific details are set forth to provide a thorough understanding of the present invention. However, it will be apparent that the present invention can be practiced without these specific details. In other cases, well-known structures and devices are shown in block diagram form to avoid unnecessary confusion of the present invention.

[0033] General Overview

[0034] The SPLITMIX algorithm used in the SplittableRandom class in JDK8 is very satisfactory in many respects, but has three possible drawbacks: (a) its state space is 127 bits, which may be too small for large-scale applications, and (b) the period (state cycle length) of any single instance is only 2 64 , and (c) it does have some known statistical weaknesses, even for single instances (but the probability of them being impeded is low).

[0035] In the TwoLCG algorithm, a nonlinear mixing function is used to combine the outputs of two linear congruential generators (LCGs). This doubles the state space to 254 bits and the speed is roughly the same, but the period of any instance is still at most 2 64 , and it is not clear whether the period of any instance is always 2 64 (It may be smaller).

[0036] Both SPLITMIX and TwoLCG make it unlikely that two different instances will have the same state cycle, and even if they do, they may traverse different parts of the state cycle. However, if they do traverse the same (or overlapping) part of the state cycle, the result will be highly undesirable correlation between sequences that should be statistically independent. It would be desirable to provide a way to guarantee that within a particular set or collection of instances, no two instances have the same state cycle.

[0037] An embodiment provides such guarantees for a set or collection of instances that are created "all at the same time"; furthermore, it also behaves similarly to SPLITMIX and TWOLCG, making it unlikely that two different instances created independently, or as part of two different collections, will have the same state cycle.

[0038] In an embodiment, an instance of a pseudo-random number generator includes a linear congruential generator ("L"), an xorshift generator ("X"), and a mixing function ("M"). Each output of the entire "LXM" pseudo-random number generator is calculated by taking one output from the linear congruential generator (LCG) and one output from the xorshift generator, and then passing their sum to the mixing function (which may be a hash operation such as a MurmurHash3 finalizer or may just be the identity function, i.e., no operation). The LCG has an additional parameter a; instances with different additional parameters necessarily have different state cycles.

[0039] According to an embodiment, the size of the state space of the LCG and the size of the state space of the xorshift generator can be selected independently. An LCG with m state bits will have 2 m cycle, an xorshift with n state bits will have 2 n -1 period. Because 2 m and 2 n -1 are coprime, so the period of the combined LXM generator will be their product, i.e., 2 m (2 n -1). Depending on the target architecture, reasonable choices for m might be 32, 64, and 128, and reasonable choices for n might be 64, 128, 256, 512, and 1024.

[0040] Embodiments use a novel approach to constructing sets of such LXM generators. Note that during the execution of a program using a pseudo-random number generator, many such sets may be created, or only one such set may be created. Furthermore, when the set creation begins, the final total size of the set may or may not be known. Embodiments ensure that different generators within the same set have different additional parameters by giving each generator in a given set a different integer index. Embodiments also make it highly likely that generators in two different sets will have different additional parameters (even if they may happen to have the same integer index within their corresponding sets) by also selecting a pseudo-random "salt" value for each set. The additional parameters for a given generator are calculated based on its index and the salt value of its set. Embodiments employ a novel technique for combining index and salt so that as much salt as possible is used for each index; this combined value is referred to herein as a "brine".

[0041] There is evidence that two PRNGs with different additional parameters will produce statistically independent pseudo-random numbers. Specifically, different additional parameters will cause the corresponding PRNG to have different periodic state cycles. Therefore, when compared with itself, with other PRNGs in the same set, or with other PRNGs running in parallel that may be from another set, the embodiment produces a PRNG with good statistical properties. Thus, the benefits of the embodiment include a significantly smaller probability of statistical correlation between multiple generators used by parallel tasks (than the probability provided by SPLITMIX), and a guarantee that the state cycle is different for each PRNG in the generator set created by a single call to the splits operation.

[0042] As described in detail herein, embodiments provide deterministic algorithms, devices, processes and / or methods that can be used by multiple shared control threads in a computer processor that is executed in parallel. Specifically, each thread can independently use a PRNG to generate a sequence of pseudo-random numbers, and a single set of numbers generated by all threads together still has good statistical properties. In fact, embodiments generate a set of PRNGs based on a common salt value so that each PRNG in the set also has good statistical properties. This good statistical property includes the output of each individual PRNG, the output of the PRNG in a given set, and the output of the PRNG from different sets containing pseudo-random numbers, which are either guaranteed to be statistically independent, or are very likely to be statistically independent.

[0043] For example, based on the use of saltwater values ​​within the PRNG set, the embodiment guarantees different initial values ​​for each PRNG of the PRNG set. Because there is strong evidence that PRNGs initialized with different initial values ​​produce statistically independent pseudo-random numbers, the embodiment ensures that the pseudo-random numbers generated by the PRNG set are statistically independent, even when the PRNGs are run in parallel using parallel processing hardware such as a central processing unit (CPU) cluster. Such parallel-generated statistically independent pseudo-random numbers are particularly useful for algorithms that rely heavily on pseudo-random numbers processed in parallel, such as Monte Carlo simulations. In addition, the embodiment is beneficial when vector processing or SIMD hardware, such as one or more graphics processing units (GPUs), is used to perform that type of calculation.

[0044] In addition, it is likely that the PRNGs generated in different sets will also generate statistically independent pseudo-random numbers. Specifically, according to an embodiment, the salt water value used to create the PRNG includes a portion of the pseudo-random salt value, which increases the likelihood that the pseudo-random numbers generated by two PRNGs from different sets will generate statistically independent pseudo-random numbers. The embodiments described herein are about as fast as SplitMix and do not appear to have any of its weaknesses. In addition, when the sets of generators are created all at once, the embodiments provide a stronger guarantee of statistical independence of multiple generators.

[0045] Salted Splittable Pseudo-Random Number Generator

[0046] Embodiments generate pseudo-random values ​​by using multiple sub-generators (at least one of which has parameters selected from an algorithm family) and combining their outputs. After their outputs are combined, a mixing function can then be applied. Embodiments also provide support for a SPLITMIX algorithm-style on-demand split method that creates a new generator and a second on-demand splits method that creates a new set of generators.

[0047] One embodiment uses 255 bits of internal state in the form of four 64-bit integers, one of which needs to be odd. These four 64-bit integers are referred to herein as a, s, x0, and x1; a must be odd, and in addition at least one of x0 and x1 must be non-zero. Once the values ​​of a, s, x0, and x1 are selected for any instance of the PRNG, s, x0, and x1 represent variable state that can be changed when a generate or split or splits operations are performed, but a, once selected, is constant for that instance. Therefore, a PRNG instance can be considered a member of a PRNG family, each of which has 192 bits of state (s, x0, and x1) and is also parameterized by an additional 63 bits of information (the 63 high-order bits of a, whose low-order bits are always 1).

[0048] In addition, an embodiment utilizes a 64-bit fixed integer constant m that is the same for all instances of the method. According to an embodiment, the PRNG utilizes two sub-generators: a linear congruential generator and a xorshift generator. The linear congruential generator uses a multiplier m and has additional parameters a and state s. In one embodiment, m=3935559000370003845. The xorshift generator has states x0 and x1. In one embodiment, the algorithm of the xorshift generator is xoroshiro128:

[0049] (1) z:=s+x0

[0050] (2)s:=3935559000370003845*s+a

[0051] (3)x1:=x1XORx0

[0052] (4)x0:=x0 ROTATELEFT 24

[0053] (5)x0:=x0 XOR x1 XOR(x1 SHIFTLEFT 16)

[0054] (6)x1:=x1ROTATELEFT 37

[0055] (7)returnz

[0056] Figure 1: Pseudo code reflecting the embodiment

[0057] The overall technique for performing the generate operation can be described by the pseudocode in Figure 1. Line (1) adds the outputs of the two subgenerators (using the generator outputs and then advancing the generator is an optimization; if an optimizing compiler is being used, this can increase potential instruction parallelism). Line (2) advances the state of the linear congruential generator. Lines (3) through (6) advance the state of the xorshift generator by performing the four steps of the xoroshiro128 algorithm; these four steps utilize bitwise exclusive or (XOR), shift left (SHIFTLEFT), and rotate (ROTATELEFT) operations.

[0058]

[0059] Figure 2: Java code reflecting the embodiment

[0060] In order to perform the sorted argumentless split operation supported by the SPLITMIX algorithm, this embodiment (as shown in FIG. 2 ) simply performs four generate operations to obtain four 64-bit integers; forces the first integer to be an odd integer by using a bitwise OR operation on the integer constant 1; if the third and fourth integers are both zero, then replace the third integer with a non-zero value; and then use all four 64-bit integers as the initial values ​​a, s, x0, and x1 of the newly created PRNG instance, respectively.

[0061] On the other hand, in order to perform a split operation using the independent variable of providing saline (such operation is a novel aspect of the embodiments described herein), this embodiment (such as Figure 2 ) creates a 64-bit integer by shifting the salt water to the left by one position, then using a bitwise OR operation with the integer constant 1 (so that the result will be an odd number), then using three generate operations to obtain a total of four 64-bit integers; if the third and fourth integers are both zero, then replace the third of the four integers with a non-zero value; then all four 64-bit integers are used as the initial values ​​a, s, x0, x1, respectively, for the newly created PRNG instance. Note that the value calculated from the salt water is used to initialize the additional parameter a.

[0062] As described above, an example implementation of this embodiment can be described in the Java programming language, as shown in Figure 2. The public constructor takes four long (64-bit) integer arguments, and if the third and fourth values ​​are both zero, then the work of forcing the first to be odd and replacing the third with a non-zero value (in this example, the non-zero value is 1) is performed. The generate() method performs the same calculations as the pseudocode in Figure 1. If it is desired to use a mixing function (such as murmurhash3), then the statement "return z;" is replaced with "return murmurhash3(z);". The split() method calls the generate() method four times and uses the four results as arguments to the constructor to create a new PRNG object. The split(long) method shifts the brine argument left by one position, calls the generate() method three times, and uses the four results as arguments to the constructor to create a new PRNG object.

[0063] Create a collection of salted PRNGs with known radix

[0064] In the case of creating a set of PRNG objects based on salt water values, where the cardinality of the set to be created is known in advance, the cardinality of the set is referred to as n. In one embodiment, a pseudo-randomly selected 64-bit salt value is first calculated; it is chosen so that the k lowest bits of the value are 0, where k is the smallest integer such that 2 kis not less than n. But the 64-k high-order bits of the salt value are chosen pseudo-randomly. Then a for loop is used to generate index values ​​from 0 to n-1. In each iteration, the split method is called with the salt water argument, which is calculated as the bitwise OR of the salt value and the index value for that iteration. Figure 3 below shows an additional Java method makePrngVector of the class L64X128Random, which creates a collection of n such PRNG objects and returns them as a "vector" of collected PRNG objects.

[0065]

[0066] Figure 3: Java code to construct a vector of PRNG objects using salt water

[0067] If the integer n-1 can be represented as an (unsigned) binary value using at most m bits, then the lower m bits of the computed salt value will be zero. Therefore, the n brine values ​​computed for n calls to the split method will be different, since each will have a different index value in its lower m bits. As a result, no two of the n PRNG objects in the set will have the same additional parameters. In fact, the 64-m high-order bits of the brine contain values ​​that, once pseudo-randomly selected for use by all PRNG objects in the set, will still make it relatively unlikely that two PRNG objects will have the same additional parameters, even if they were created as part of two different sets, or if one was created as part of a set and the other was created by a call to split().

[0068] Creating a collection of salted PRNGs with unknown radix - sliding boundary pointers

[0069] Sometimes it is necessary to create a collection of PRNG objects, where the cardinality of the collection to be created is unknown in advance. In one embodiment, the class L64X128Random provides a method makePrngGenerator to obtain a PRNG-generator object representing a collection, and each time its generatePrng method is called, a new L64X128Random object is created for the collection and returned. When a PRNG-generator object (represented by the inner class PrngGenerator) is created by the method makePrngGenerator, a pseudo-randomly selected 64-bit salt value is first calculated and saved as part of the PRNG-generator object, and then the salt is used to create a brine each time the generatePrng method is called.

[0070] The idea is to have a sliding boundary between the salt value used for a set and the index of a given PRNG in the set, within the salt value created for a given set. This sliding boundary ensures that the salt values ​​for different PRNGs in a given set are distinct and that there are no accidental collisions between salt values ​​for different PRNGs in a set. Furthermore, the pseudo-random salt value used in the salt value for each set increases the likelihood that PRNGs from different sets will produce pseudo-random numbers that are statistically independent of each other.

[0071] According to an embodiment, a set of six boundary pointer bits in a representation of a given brine value represents a sliding boundary pointer that is initialized to bit 0. The sliding boundary pointer value tracks bits within the brine value representation that include the boundary between salt value bits and index value bits within the brine value representation. According to an embodiment, this set of six bits are high-order bits in the representation of the brine value. The value b represented by the set of boundary pointer bits is a bit index that refers to a bit in the brine value representation. Thus, according to an embodiment, within the representation of a given brine value, the value of b in the 6-bit boundary pointer field indicates that the b low-order bits of the brine value are index bits, and the 58-b bits to their left are salt bits that have been pseudo-randomly selected. In this embodiment, the description of the positions of the boundary pointer bits, salt bits, and index bits is a non-limiting example.

[0072] According to an embodiment, to create a PrngGenerator configured to generate a PRNG one by one, a salt value is initially calculated by generating a 64-bit pseudo-random value. The creation of the salt value is initiated by shifting the salt value to the right by 6 positions, introducing 6 0 bits on the left to indicate that the boundary between the salt and the index is on the right side of the salt value representation. Note that if assuming 2 58 is a practical upper limit on the number of times the generatePrng method is called, then the salt water value of any two such calls will be different. The following Figure 4 shows the sample Java code of this method.

[0073]

[0074] Figure 4: Java code for creating a generator of PRNG objects using salt water

[0075] An example of the functionality of Figure 4 is presented with a simplified brine value having 7 bits, of which 3 bits are reserved for a boundary pointer. The salt value portion represented in the brine value is 101, the current index is 1, and the current boundary pointer points to bit #1 in the brine value representation, i.e., brine = 001 101 1The next time a new PRNG is generated for the collection, the PrngGenerator object increments the index to 2, and now two index bits are needed to represent the index value, i.e., index = 10. Therefore, the boundary pointer value becomes 010. To accommodate the larger index representation, one of the salt bits is negated, making salt = 10. Thus, the salt value for the next PRNG is 010 10 10 .

[0076] When a new PRNG is subsequently generated for the set, the index grows to 3, and two index bits are still required to represent the index value, i.e., index = 11. Therefore, the boundary pointer value is still 010, and the salt value of this new PRNG is 010 10 11 Although the last four bits of the salt value happen to be the same as the salt value of the previous PRNG, the boundary pointer value must be different. Therefore, for a 64-bit salt value, given that the upper limit on the number of PRNGs in the set is 2 58 ,This technique guarantees that all salt values ​​in the set are unique.

[0077] Set to create a salted PRNG with unknown radix - bitset with flags

[0078] In another embodiment, method makePrngGenerator and inner class PrngGenerator of class L64X128Random are used in much the same way, but use a different representation for the salt, in order to advantageously use a faster test to determine if the salt value needs to be adjusted, and a faster way to adjust the salt.

[0079] The idea is again to have a sliding boundary between the salt and the index in the salted value, but use a unary representation instead of a binary representation to track it. Specifically, in each 8-bit byte of a 64-bit word, let the high-order bit be a flag bit. The boundary between the salt and the index is just to the right of the flag bit that is 1 in the leftmost byte.

[0080] The salt is initially calculated by generating a 64-bit pseudo-random value, setting the flag bit of each 8-bit byte to 0 and the lowest byte to 0, then setting the flag bit of the lowest byte to 1. Whenever the index gets large enough to "hit" the lowest 1 bit of the salt, the salt is shifted left by 8 positions.

[0081] Note that if Assumption 2 55is a practical upper bound on the number of times generatePrng can be called, then the salt value of any two such calls will be different. Also note that since the shift operation in split(long) discards the leftmost salt bit (in Figure 2), the practical upper bound on the number of times generatePrng can be called is 2 55 instead of 2 63 .

[0082] Figure 5 below shows sample Java code for this method.

[0083]

[0084] Figure 5: Java code for creating a generator of PRNG objects using salt water

[0085] For example, the salt value for a particular PRNG from a given set is 0 0100111 0 0011101 0 1111011 0 1101010 0 1010001 0 1011110 0 0011010 11111111 . The high-order bits of each byte representing the salt value in the salt water value representation are flag bits, which indicate that the byte contains salt data (i.e., 0). In addition, the boundary bits between the bits representing the salt value and the bits representing the index value are additional flag bits, whose values ​​are different from the flag bits indicating the salt value, which indicate the start of the index value bits. In this example, the index value is located in the 7 low-order bits of the salt water value representation. However, according to one or more embodiments, the index value can be located elsewhere in the salt water value representation, such as in the high-order bits.

[0086] In the example salt water value given above, the index value is the maximum value representable with the available 7 index bits. Therefore, when the next PRNG is requested for the set, the index of the PRNG (10000000) exceeds the capacity of the current index bits, and the salt is shifted left by 8 bits to make room for the larger index value as follows: 0 0011101 0 1111011 0 1101010 0 1010001 0 1011110 0 0011010 1 0000000 10000000. In this case, the index now has 15 bits of space, even though the index value can be represented by 8 bits. Note that after the first flag bit indicates the start of the index data with a value of 1, the remaining low-order bits are the index data. Therefore, the 1 at the beginning of the last byte is not interpreted as a flag, but rather as index data. In addition, since the boundary marker position moves each time the index bits are extended, each value generated using the new boundary marker position is guaranteed to be unique because a salt marker value must have existed at that position before the extension.

[0087] Create a set of salted PRNGs with unknown radix - boundary indicator bits

[0088] In another embodiment, method makePrngGenerator and inner class PrngGenerator of class L64X128Random are used in much the same way, but another representation is used for the salt in order to advantageously get more "randomness" into each salt water value.

[0089] The idea is again to have a sliding boundary between the salt and the index in the salted value, and the idea is again by partitioning the 64-bit word into groups of bits and identifying the leftmost group that has some particular characteristic. Let k be a fixed integer between 2 and 63, and let the word be partitioned into groups of k bits starting from the left end (with possible remaining groups of bits less than k on the right end). The boundary between the salt and the index is just to the right of the leftmost group of all 1 bits.

[0090] The salt is initially calculated by generating a 64-bit pseudo-random value, and then using that value to calculate the k A series of "numbers" with base -1; each such number can be represented using k bits, but no such number satisfies boundary value tests, e.g., represents the maximum value that the number could possibly represent. The rightmost group of k bits is set to all 1 bits, and any partial group to the right of it is set to all 0 bits. Whenever the index gets large enough to "hit" the lowest 1 bit of the salt, the salt is shifted left by k positions.

[0091] Note that if Assumption 2 64-k is a practical upper limit on the number of times the generatePrng method is called, then the salt water values ​​for any two such calls will be different. The following Figure 6 shows the Java code of an embodiment of this method, where k=4. When k is 4, 5, or 6, the waste of salt values ​​for sliding boundary representation is generally minimized.

[0092] Note that FIG6 performs arithmetic to uniformly select from the possible values ​​(minus the values ​​that satisfy the bounds test) for each digit in the salt portion of the brine value. Additionally, this technique is able to preserve the highest range of possible salt values ​​of the variable radix brine representation techniques described herein. However, the algorithm required for this technique may make the technique prohibitive when a brine-based PRNG generator is implemented in hardware. For hardware encoding, one of the previous variable radix brine representation techniques may be more efficient because the arithmetic required is simpler than that required for this technique. Combined with the following Figure 1 The description of gives an example of representing the salt water values ​​as shown in Figure 6.

[0093]

[0094] Figure 6: Java code for creating a generator of PRNG objects using salt water

[0095] A collection of salted PRNGs passed in a stream

[0096] In one embodiment, it is desirable to pass a collection of PRNG objects in the form of a Java stream that can allow operations such as serial or parallel computation of multiple calls to functions of each PRNG object in the stream. An embodiment creates such a stream by defining a "splitter" class and then constructing a stream using an appropriate instance of that class.

[0097] Figure 7 below shows sample Java code for two (overloaded) definitions of the method splits of class L64X128Random. The first does not accept any arguments and constructs a stream of indeterminate length (in fact, one of the lengths is at most 2). 63 -1); it calculates the salt according to the same method used in Figure 6 (the parameter k in Figure 6 is called SALT_SHIFT in Figures 7 and 8). The second accepts an argument n indicating the number of PRNG objects to create; it calculates the salt according to the same method used in Figure 3. In this way, the salt is calculated in one of two different ways, depending on whether the number of PRNG objects to be created is known in advance.

[0098]

[0099] Figure 7: Java code reflecting the embodiment

[0100] Figure 8 below shows sample Java code that defines a class SaltSpliterator. Its constructor accepts four arguments: the pseudo-random number generator that created it (needed to call its split() and split(long) methods), the inclusive lower and exclusive upper bounds on the range of integer indices for which the PRNG object is generated, and the salt value. The method trySplit() attempts to divide the remaining range into (approximately) halves and creates a new splitter object that will process one of the halves (the lower half) while this splitter retains the other half (the upper half); if this is not possible, null is returned. (This ability to divide the splitter into two independent splitters that use the same salt value enables parallel execution).

[0101] The current SaltSpliterator object occupies the LOW half of the interval (from index to m) and the new SaltSpliterator object occupies the HIGH half of the interval (from m to fence). The reason is that the constructor of the new object will ensure that the salt is shifted if necessary; if the current object occupies the upper half, then the trySplit method must also check whether the salt must be shifted, but if the current object occupies the lower half, then trySplit does not need to shift the salt.

[0102] In the case where the new SaltSpliterator object occupies the HIGH half of the interval of the original SaltSpliterator object (i.e., from m to fence), the SaltSpliterator object's constructor adjusts the salt value as necessary to accommodate index values ​​starting from the new index (formerly m), which may be significantly larger than the index of the original SaltSpliterator object. Specifically, given the representation of the sliding boundary used in Figures 7 and 8, the SaltSpliterator object's constructor shifts the salt value by k positions (represented as SALT_SHIFT in the constructor) as many times as necessary to accommodate the representation of the current index. In the case of a known cardinality of the collection, the salt value is configured so that the index will always fit in the space allocated for the index bits in the salt water value representation. Thus, when splitting a new SaltSpliterator object for a collection with a known cardinality, the salt value never needs to be reconfigured.

[0103] Method tryAdvance attempts to create a new PRNG object for just index as the current value of the index field; if successful, it passes this new PRNG object to the given consumer function, decrements the size of the range by 1 to indicate that the index value has been processed, and then returns true, but if it fails (because the remaining range is empty) then it returns false. Method forEachRemaining processes the entire remaining (possibly empty) range, creating a new PRNG object for each index in the remaining range and passing it to the given consumer function; it also updates the index field to indicate that the remaining range is empty. The novel portions of the example Java code of FIG8 include the use of rng.split() in method trySplit() and the use of (rng.split(salt|i) to compute and pass the salt solution in methods tryAdvance and forEachRemaining.

[0104]

[0105]

[0106] FIG8: Java code reflecting the embodiment (continued from FIG7)

[0107] Example stream implementation to create a collection with known cardinality

[0108] Figure 1 A flowchart 100 for creating a PRNG of a collection using salt water values ​​is depicted. Specifically, at step 102, a request to create a PRNG of a collection is received. For example, the processor causes the splits method (see FIG. 7 ) to be executed on a Stream of type Stream. <l64x128random>, where the parameter 3 indicates that the SaltSpliterator objects in the stream are to be configured to create a collection of PRNGs with a cardinality of 3. The processor also causes a tryAdvance method or a forEachRemaining method to be called on the stream, which causes the stream to: add a PRNG of the collection to the stream; or create all remaining PRNGs for the collection in the stream, respectively. Note that this is a non-limiting example, and such a request to create a collection may include a request to a PrngGenerator object to create a single PRNG in the collection using the generatePrng method. Note that the collection of PRNGs may include only one PRNG.

[0109] According to an embodiment, steps 104 and 106 of flowchart 100 are performed as part of creating a set of PRNGs in response to receiving a request to create a set of PRNGs.

[0110] At step 104, a salt value including a pseudo-random number is generated. For example, the splits method in FIG. 7 pseudo-randomly generates a 64-bit salt value and passes at least a portion of the salt value to the SaltSpliterator constructor. For illustration, the pseudo-random 64-bit salt value is 0010 01111001 1101 1111 1011 0110 1010 1101 0001 0101 1110 10011010 11001011.

[0111] At step 106, each PRNG of the set of PRNGs is created based on a respective salt value that includes (a) at least a portion of the salt value and (b) a respective index value that is unique to the respective PRNG within the set of PRNGs. For example, the splits method masks some of the lowest order bits such that the number of masked bits is a size sufficient to represent values ​​as large as the cardinality of the requested set. Continuing with the above example, 2 bits are sufficient to represent numbers as large as 3, and thus, the splits method prepares the salt value to be passed to the SaltSpliterator constructor to accept index information by setting the lowest order two bits of the salt value to 0, as follows: 0010 0111 1001 1101 1111 1011 0110 1010 1101 0001 0101 111010011010 1100 10 00 .

[0112] To further illustrate, the processor uses the SaltSpliterator object initialized above to create the three required PRNGs for the requested collection, where each PRNG is associated with a corresponding index value unique to the PRNG among the collection's PRNGs. The following indicates the salt water values ​​of the PRNGs generated given the example parameters above:

[0113] PRNG[0]: Index value = 00; Salt water value = 0010 0111 1001 1101 11111011 0110 10101101 0001 0101 1110 1001 1010 1100 10 00 ;

[0114] PRNG[1]: Index value = 01; Salt water value = 0010 0111 1001 1101 11111011 0110 10101101 0001 0101 1110 1001 1010 1100 10 01 ;as well as

[0115] PRNG[2]: Index value = 10; Salt water value = 0010 0111 1001 1101 11111011 0110 10101101 0001 0101 1110 1001 1010 1100 10 10 .

[0116] The salt water value is passed to the split method of the PRNG, as shown in Figure 8, which results in the creation of a new PRNG based on the salt water value of the PRNG. Thus, each PRNG is instantiated with a salt water value that is guaranteed to be unique among the PRNGs in the collection.

[0117] The pseudo-random numbers generated by any PRNG in the set are generated based at least in part on the salt value of the PRNG. Specifically, when the generate method is called on an instantiated PRNG[0] object, PRNG[0] generates the requested pseudo-random numbers using the salt value with which it was instantiated, e.g., as an additional parameter (a) used in the generate method of FIG. 2 .

[0118] Specifically, the value of a is based on the brine value passed into the split method that accepts a brine parameter. The brine value is shifted left by 1 and then forced to odd before it is assigned as an additional parameter to the new PRNG object. Therefore, the additional parameter for PRNG[0] is based on the brine value of the instantiated object, because the value of a is the brine value shifted left and forced to odd, as follows: 010011110011 1011 1111 0110 1101 0101 1010 0010 1011 1101 0011 0101 10010 00 1. Thus, the generation method utilizes this adapted salt water value to generate a new pseudo-random number, as indicated above.

[0119] Example stream implementation for creating a collection with unknown cardinality

[0120] To illustrate the use of a saltwater value to create a PRNG for a collection in the context of a request for a collection of unknown cardinality, the processor uses the splits method (see Figure 7) on the Stream <l64x128random>The processor also causes the tryAdvance method to be called on the stream, which causes the stream to add a PRNG to the collection by calling the accept method of the stream's consumer. In Figure 8 above, the SaltSpliterator implements a sliding boundary indicator in the salt value of the collection, where the bit group size is k=4, as depicted in Figure 6.

[0121] Specifically, the salt value for the set is initially calculated by generating a 64-bit pseudo-random base value referred to as bits in Figure 7. Based on the example boundary value test described above, the salt value is initialized using the boundary number with the maximum representable value as the leftmost digit (or highest order four bits) in the salt value representation. The bit value is used to generate random numbers for the salt value (each number is represented by k bits). Due to the example boundary value test, each randomly generated number has a value less than the maximum representable value. The randomly generated numbers are shifted into the salt value representation to the left of the boundary number until the boundary number is located in the lowest order position in the representation. Note that if there are any remaining digits, that is, for k values ​​that are not evenly divided into 64 bits, then these bits are maintained to the right of the boundary number and can be used to represent index information. For illustration, the example salt value generated by the splits() method is: 0xA04C427B456ED91 F (The only number with a maximum value is the lowest order number).

[0122] Whenever the index value of the collection becomes large enough to "hit" the lowest 1 bit of the salt value, the salt value is shifted left by k positions. For example, the SaltSpliterator object initiated during the splits method generates a salt value based on the example given above (e.g., 0xA04C427B456ED91F). Since there is no room for the index value in the generated salt value, the salt value is automatically shifted left by k positions, resulting in a salt value of 0x04C427B456ED91F0. The resulting SaltSpliterator object bases each new PRNG on at least a portion of this salt value. Specifically, the tryAdvance method causes the PRNG to split based on a salt value that includes the current salt value of the collection ORed with the current index, which results in a new PRNG based on this unique salt value. Additionally, if the next index does not fit into the bits to the right of the bounding index number, then the tryAdvance method shifts the salt value by k positions.

[0123] Alternatives and extensions

[0124] Without departing from the spirit and scope of the present invention, the embodiments may perform any, more than one, or all of the following:

[0125] • Using a subgenerator other than a linear congruential generator, where the subgenerator is one of a family of generators characterized by parameters that select or characterize the family members.

[0126] • Using more than two sub-generators, as long as at least one of the sub-generators is characterized by parameters initialized with salt water.

[0127] Using more than two subgenerators, as long as at least one is a linear congruential generator,

[0128] With the additional parameter of initializing with salt water.

[0129] Implement a linear congruential generator (LCG) using arithmetic operations on integers of sizes other than 64 bits.

[0130] o In one embodiment, the LCG uses a 16-bit multiplier, a 16-bit additional parameter, and a 16-bit state.

[0131] o In one embodiment, the LCG uses a 16-bit multiplier, a 16-bit additional parameter, and a 32-bit state.

[0132] o In one embodiment, the LCG uses 16-bit multipliers, 32-bit additional parameters, and 32-bit state.

[0133] o In one embodiment, the LCG uses a 32-bit multiplier, a 16-bit additional parameter, and a 32-bit state.

[0134] o In one embodiment, the LCG uses 32-bit multipliers, 32-bit additional parameters, and 32-bit state.

[0135] o In one embodiment, the LCG uses 32-bit multipliers, 32-bit additional parameters, and 64-bit state.

[0136] o In one embodiment, the LCG uses 32-bit multipliers, 64-bit additional parameters, and 64-bit state.

[0137] o In one embodiment, the LCG uses 64-bit multipliers, 32-bit additional parameters, and 64-bit state.

[0138] o In one embodiment, the LCG uses 64-bit multipliers, 64-bit additional parameters, and 128-bit state.

[0139] o In one embodiment, the LCG uses 64-bit multipliers, 128-bit additional parameters, and 128-bit state.

[0140] o In one embodiment, the LCG uses 128-bit multipliers, 64-bit additional parameters, and 128-bit state.

[0141] o In one embodiment, the LCG uses a 128-bit multiplier, 128-bit additional parameters, and 128-bit state.

[0142] Implement the xorshift generator using arithmetic operations on integers of sizes other than 64 bits.

[0143] o In one embodiment, the xorshift generator uses two 32-bit status words.

[0144] o In one embodiment, the xorshift generator uses four 32-bit status words.

[0145] o In one embodiment, the xorshift generator uses four 64-bit status words.

[0146] o In one embodiment, the xorshift generator uses eight 64-bit status words.

[0147] o In one embodiment, the xorshift generator uses sixteen 64-bit status words.

[0148] Use various xorshift-style algorithms.

[0149] o In one embodiment, the xorshift generator algorithm is xoroshiro64.

[0150] o In one embodiment, the xorshift generator algorithm is xoroshiro128.

[0151] o In one embodiment, the xorshift generator algorithm is xoshiro256.

[0152] ○ In one embodiment, the xorshift generator algorithm is xoshiro512.

[0153] o In one embodiment, the xorshift generator algorithm is xoroshiro1024. o Using a multiplier other than the specific multiplier value 3935559000370003845. For example,

[0154] Any of the multiplier values ​​given in Table 4 of L'Ecuyer [9] may be used.

[0155] An optional blending step can be used after the outputs of the sub-generators are added.

[0156] Alternative random or pseudo-random sources may be used to select salts for new sets of PRNGs.

[0157] Some or all of the salt may be calculated based on process environment characteristics that are known to be or may be different from other process environment characteristics, such as:

[0158] ○Thread ID

[0159] ○Process ID

[0160] ○ Processor ID (such as hardware serial number)

[0161] ○ Network interface ID (such as MAC address)

[0162] ○IP address

[0163] ○Time of day and / or date

[0164] The index can be expressed with a brine value at some position other than the right-hand end.

[0165] Salt can be represented by the value of brine at some position other than the left-hand end.

[0166] The boundary between the salt and the index can be determined by identifying the rightmost (rather than the leftmost) bitfield with certain specific characteristics.

[0167] Aspects of the embodiments include, but are not limited to:

[0168] In a pseudo-random number generator using at least one sub-generator that is an LCG, additional parameters for LCG components of two or more different generators are intentionally chosen to be different to ensure that state cycles of the two or more different generators are different.

[0169] When creating a collection of pseudorandom number generators, use different integer indices to construct different additional parameters for different generators in the collection.

[0170] When creating an ensemble of pseudo-random number generators, use a randomly or pseudo-randomly chosen "salt" value from the ensemble as part of the calculation of each additional parameter.

[0171] When creating a collection of pseudo-random number generators, an additional parameter is calculated by combining the salt value and the index.

[0172] When creating a collection of pseudo-random number generators, additional parameters are computed by combining a salt value and an index in such a way that all additional parameters computed for the collection will be different. When creating a collection of pseudo-random number generators, additional parameters are computed by combining a salt value and an index in such a way that all additional parameters computed for the collection will be different, even if no upper limit is known in advance on the number of PRNG objects to be created as part of the collection.

[0173] A method of combining a salt value and an index where the total number of PRNG objects to be created as part of the set is known in advance and used to determine how many bits of salt to use.

[0174] A method of combining a salt value and an index, wherein the total number of PRNG objects to be created as part of a set is not known in advance, and wherein the number of bits of the index in the salt value can be determined by performing calculations on the salt value.

[0175] A method of combining a salt value and an index wherein the total number of PRNG objects to be created as part of a set is not known in advance, and wherein the number of bits of the index in the salt value is encoded in a specific bit field within the salt value.

[0176] A method of combining a salt value and an index, wherein the total number of PRNG objects to be created as part of a set is not known in advance, and wherein the number of bits of the index in the salt value can be determined by examining a plurality of bit fields within the salt value and identifying a leftmost (or rightmost) flag bit of the plurality of fields having a value equal to a particular value (such as 1).

[0177] A method of combining a salt value and an index where the total number of PRNG objects to be created as part of a set is not known in advance, and where the number of bits of the index in the salt value can be determined by examining multiple bit fields within the salt value and identifying that the leftmost (or rightmost) of the multiple fields has some other specific characteristic, such as being equal to a specific value (e.g., all 1 bits).

[0178] A method for defining a stream of PRNG objects by using a splitter that accepts a salt value and calculates the appropriate salt water value for each PRNG object created.

[0179] While the SPLITMIX algorithm used in JDK8 has 127 bits of state (of which 64 bits are updated during each generate operation) and uses 9 64-bit arithmetic operations per 64 bits generated, an embodiment uses 255 bits of state (of which 192 bits are updated during each generate operation) and uses 9 64-bit arithmetic operations per 64 bits generated. Another embodiment uses 383 bits of state (of which 320 bits are updated during each generate operation) and uses 10 64-bit arithmetic operations per 64 bits generated.

[0180] refer to

[0181] [1] Austin Appleby. Murmurhash3, April 3, 2011. Project wiki entry. http: / / code.google.com / p / smhasher / wiki / MurmurHash3 Accessed September 10, 2013.

[0182] [2] Lennart Augustsson. Personal communication, August 30, 2013. The Haskell source code for System.Random is available at https: / / hackage.haskell.org / package / random.

[0183] [3] Robert G. Brown, Dirk Eddelbuettel, and David Bauer. Dieharder: A random number test suite, version 3.31.1, 2003-2006. http: / / www.phy.duke.edu / ~rgb / General / dieharder.php Accessed September 10, 2013.

[0184] [4] Koen Claessen and Michal Palka. Splittable pseudorandom number generators using cryptographic hashing. In Proc. ACM SIGPLAN Haskell Symp., pp. 47–58, 2013.

[0185] [5] Chris Doty-Humphrey. PractRand version 0.90, July 2014. Website at http: / / pracrand.sourceforge.net.

[0186] [6]Gregory W. Fischer, Ziv Carmon, Dan Ariely, Gal Zauberman and Pierre L'Ecuyer. Good parameters and implementations for combined multiple recursiverandom number generators. Operations Research, 47(1):159-164, January 1999.

[0187] [7] Guy L. Steele Jr., Doug Lea, and Christine H. Flood. Fast splittable pseudorandom number generators. In Proc. 2014 ACM International Conference on Object Oriented Programming Systems, Languages, and Applications, OOPSLA’14, pages 453 - 472, New York, 2014. ACM.

[0188] [8] Pierre L’Ecuyer. Efficient and portable combined random number generators. Comm. ACM, 31(6):742 - 751, June 1988.

[0189] [9] Pierre L’Ecuyer. Tables of linear congruential generators of different sizes and good lattice structure. Mathematics of Computation, 68(225):249 - 260, January 1999.

[0190]

[10] Pierre L’Ecuyer and Richard Simard. TestU01: A C library for empirical testing of random number generators. ACM Trans. Math. Softw., 33(4), August 2007.

[0191]

[11] Pierre L’Ecuyer, Richard Simard, E. Jack Chen, and W. David Kelton. An object - oriented random - number package with many long streams and substreams. Operations Research, 50(6):1073 - 1075, November 2002.

[0192]

[12] Charles E. Leiserson, Tao B. Schardl, and Jim Sukha. Deterministic parallel random-number generation for dynamic-multithreading platforms. In Proc. 17th ACM SIGPLAN Symp. Principles and Practice of Parallel Programming, pages 193 - 204, New York, 2012. ACM.

[0193]

[13] George Marsaglia and Wai Wan Tsang. Some difficult-to-pass tests of randomness. Journal of Statistical Software, 7(3): 1 - 9, 1 2002.

[0194]

[14] Makoto Matsumoto and Takuji Nishimura. Mersenne Twister: A 623-dimensionally equi distributed uniform pseudo-random number generator. ACM Trans. Model. Comput. Simul., 8(1): 3 - 30, January 1998.

[0195]

[15] Andrew Rukhin, Juan Soto, James Nechvatal, Miles Smid, Elaine Barker, Stefan Leigh, Mark Levenson, Mark Vangel, David Banks, Alan Heckert, James Dray and San Vo; revised by Lawrence EBassham III. A statistical test suite for random and pseudorandom number generators for cryptographic applications. Technical Report Special Publication 800-22 Revision 1a, Information Technology Laboratory, National Institute of Standards and Technology, Gaithersburg, Maryland, April 2010. http: / / csrc.nist.gov / publications / nistpubs / 800-22-rev1a / SP800-22rev1a.pdf.

[0196]

[16] Richard Simard. TestU01 version 1.2.3, August 2009. Website at http: / / www.iro.umontreal.ca / ~simardr / testu01 / tu01.html.

[0197]

[17] David Stafford. Better bit mixing: Improving on MurmurHash3’s 64-bit finalizer, September 28, 2011. Blog "Twiddling the Bits.” http: / / zimbry.blogspot.com / 2011 / 09 / better-bit-mixing-improving-on.html Accessed September 10, 2013.

[0198]

[18] Sebastiano Vigna. An experimental exploration of Marsaglia's xorshift generators, scrambled. ACM Trans. Math. Softw., 42(4):30:1-30:23, June 2016.

[0199]

[19] Sebastiano Vigna. xoshiro / xoroshiro generators and the PRNGshootout, 2019.

[0200]

[20] John Walker. HotBits: Genuine random numbers, generated by radioactive decay. The website is at http: / / www.fourmilab.ch / hotbits / .

[0201] Hardware Overview

[0202] According to one embodiment, the technology described herein is implemented by one or more special-purpose computing devices. The special-purpose computing device can be hard-wired to perform the technology, or can include digital electronic devices such as one or more application-specific integrated circuits (ASICs) or field programmable gate arrays (FPGAs) that are permanently programmed to perform the technology, or can include one or more general-purpose hardware processors programmed to perform the technology according to program instructions in firmware, memory, other storage devices, or combinations thereof. Such special-purpose computing devices can also merge customized hard-wired logic, ASICs or FPGAs with customized programming to implement the technology. The special-purpose computing device can be a desktop computer system, a portable computer system, a handheld device, a networking device, or any other device that combines hard-wiring and / or program logic to implement the technology.

[0203] For example, Figure 2 2 is a block diagram illustrating a computer system 200 upon which embodiments of the present invention may be implemented. Computer system 200 includes a bus 202 or other communication mechanism for communicating information, and a hardware processor 204 coupled to bus 202 for processing information. Hardware processor 204 may be, for example, a general purpose microprocessor.

[0204] Computer system 200 also includes a main memory 206, such as a random access memory (RAM) or other dynamic storage device, coupled to bus 202 for storing information and instructions to be executed by processor 204. Main memory 206 may also be used to store temporary variables or other intermediate information during execution of instructions to be executed by processor 204. When stored in a non-transitory storage medium accessible to processor 204, such instructions render computer system 200 into a special-purpose machine customized to perform the operations specified in the instructions.

[0205] Computer system 200 also includes a read only memory (ROM) 208 or other static storage device coupled to bus 202 for storing static information and instructions for processor 204. A storage device 210, such as a magnetic disk, optical disk, or solid state drive, is provided and coupled to bus 202 for storing information and instructions.

[0206] The computer system 200 may be coupled to a display 212, such as a cathode ray tube (CRT), via the bus 202 for displaying information to a computer user. An input device 214, including alphanumeric and other keys, is coupled to the bus 202 for communicating information and command selections to the processor 204. Another type of user input device is a cursor control 216, such as a mouse, trackball, or cursor direction keys, for communicating directional information and command selections to the processor 204 and for controlling cursor movement on the display 212. Such input devices typically have two degrees of freedom in two axes, a first axis (e.g., x) and a second axis (e.g., y), to allow the device to specify a position within a plane.

[0207] The computer system 200 may implement the techniques described herein using custom hardwired logic, one or more ASICs or FPGAs, firmware, and / or program logic that is combined with the computer system to enable the computer system 200 or program the computer system 200 as a special purpose machine. According to one embodiment of the invention, the techniques herein are performed by the computer system 200 in response to the processor 204 executing one or more sequences of one or more instructions contained in the main memory 206. Such instructions may be read into the main memory 206 from another storage medium, such as the storage device 210. Execution of the sequences of instructions contained in the main memory 206 causes the processor 204 to perform the process steps described herein. In alternative embodiments, hardwired circuitry may be used in place of or in combination with software instructions.

[0208] As used herein, the term "storage medium" refers to any non-transient medium that stores data and / or instructions that cause a machine to operate in a particular manner. Such storage media may include non-volatile media and / or volatile media. Non-volatile media include, for example, optical disks, magnetic disks, or solid-state drives, such as storage device 210. Volatile media include dynamic memory, such as main memory 206. Common forms of storage media include, for example, floppy disks, flexible disks, hard disks, solid-state drives, magnetic tapes, or any other magnetic data storage medium, CD-ROMs, any other optical data storage medium, any physical medium with a hole pattern, RAM, PROM and EPROM, FLASH-EPROM, NVRAM, any other memory chip or cassette tape.

[0209] Storage media are distinct from transmission media but can be used in conjunction with them. Transmission media participate in the transfer of information between storage media. For example, transmission media include coaxial cables, copper wire, and optical fiber, including the wiring that comprises bus 202. Transmission media can also take the form of acoustic or light waves, such as those generated in radio wave and infrared data communications.

[0210] Various forms of media may be involved in carrying one or more sequences of one or more instructions to processor 204 for execution. For example, the instructions may initially be carried on a disk or solid-state drive of a remote computer. The remote computer may load the instructions into its dynamic memory and send the instructions over a telephone line using a modem. A modem local to computer system 200 may receive the data on the telephone line and use an infrared transmitter to convert the data into an infrared signal. An infrared detector may receive the data carried in the infrared signal and appropriate circuitry may place the data on bus 202. Bus 202 carries the data to main memory 206, from which processor 204 retrieves and executes the instructions. The instructions received by main memory 206 may optionally be stored on storage device 210 before or after execution by processor 204.

[0211] Computer system 200 also includes a communication interface 218 coupled to bus 202. Communication interface 218 provides bidirectional data communication coupled to network link 220, wherein network link 220 is connected to local network 222. For example, communication interface 218 can be an integrated services digital network (ISDN) card, a cable modem, a satellite modem, or a modem that provides a data communication connection to a corresponding type of telephone line. As another example, communication interface 218 can be a LAN card that provides a data communication connection to a compatible local area network (LAN). A wireless link can also be implemented. In any such implementation, communication interface 218 sends and receives electrical, electromagnetic or optical signals that carry digital signal streams representing various types of information.

[0212] The network link 220 typically provides data communication to other data devices through one or more networks. For example. The network link 220 can provide a connection to a host computer 224 or to data equipment operated by an Internet Service Provider (ISP) 226 through a local network 222. The ISP 226, in turn, provides data communication services through a global packet data communication network now commonly referred to as the "Internet" 228. Both the local network 222 and the Internet 228 use electrical, electromagnetic, or optical signals that carry digital data streams. The signals through the various networks and the signals on the network link 220 and through the communication interface 218 are example forms of transmission media, where the signals bring the digital data to the computer system 200 or carry the digital data from the computer system 200.

[0213] Computer system 200 can send messages and receive data, including program code, through the network(s), network link 220, and communication interface 218. In the Internet example, server 230 can send requested code corresponding to a program through Internet 228, ISP 226, local network 222, and communication interface 218.

[0214] The received code may be executed by processor 204 as it is received, and / or stored in storage device 210 or other non-volatile storage for later execution.

[0215] Software Overview

[0216] Figure 3 is a block diagram of a basic software system 300 that may be used to control the operation of computer system 200. Software system 300 and its components, including their connections, relationships, and functions, are exemplary only and are not intended to limit implementation of the example embodiment(s). Other software systems suitable for implementing the example embodiment(s) may have different components, including components with different connections, relationships, and functions.

[0217] A software system 300 is provided for directing the operation of the computer system 200. The software system 300, which may be stored on system memory (RAM) 206 and fixed storage (eg, hard disk or flash memory) 210, includes a kernel or operating system (OS) 310.

[0218] OS 310 manages low-level aspects of computer operation, including managing the execution of processes, memory allocation, file input and output (I / O), and device I / O. One or more applications, represented as 302A, 302B, 302C ... 302N, may be "loaded" (e.g., transferred from fixed storage 210 into memory 206) for execution by system 300. Applications or other software intended for use on computer system 200 may also be stored as a set of downloadable computer-executable instructions, for example, for downloading and installation from an Internet location (e.g., a Web server, application store, or other online service).

[0219] The software system 300 includes a graphical user interface (GUI) 315 for receiving user commands and data in a graphical manner (e.g., "clicks" or "touch gestures"). The system 300 can, in turn, act on these inputs according to instructions from the operating system 310 and / or the (one or more) applications 302. The GUI 315 is also used to display the results of the operations from the OS 310 and the (one or more) applications 302, so that the user can provide additional input or terminate the session (e.g., log out).

[0220] The OS 310 may execute directly on the bare hardware 320 (e.g., the processor(s) 204) of the computer system 200. Alternatively, a hypervisor or virtual machine monitor (VMM) 330 may be inserted between the bare hardware 320 and the OS 310. In this configuration, the VMM 330 acts as a software "shim" or virtualization layer between the OS 310 and the bare hardware 320 of the computer system 200.

[0221] VMM 330 instantiates and runs one or more virtual machine instances ("guest machines"). Each guest machine includes a "guest" operating system, such as OS 310, and one or more applications designed to execute on the guest operating system, such as (one or more) application 302. VMM 330 provides a virtual operating platform to the guest operating system and manages the execution of the guest operating system.

[0222] In some cases, VMM 330 can allow a guest operating system to run as if it were running directly on bare hardware 320 of computer system 200. In these cases, the same version of the guest operating system that is configured to execute directly on bare hardware 320 can also execute on VMM 330 without modification or reconfiguration. In other words, in some cases, VMM 330 can provide full hardware and CPU virtualization to the guest operating system.

[0223] In other cases, the guest operating system may be specially designed or configured to execute on VMM 330 to improve efficiency. In these cases, the guest operating system "knows" that it is executing on a virtual machine monitor. In other words, in some cases, VMM 330 may provide paravirtualization to the guest operating system.

[0224] A computer system process includes an allocation of hardware processor time, and an allocation of memory (physical and / or virtual) for storing instructions executed by the hardware processor, for storing data generated by the hardware processor in executing instructions, and / or for storing hardware processor state (e.g., contents of registers) between allocations of hardware processor time when the computer system process is not running. A computer system process runs under the control of an operating system and may run under the control of other programs executing on the computer system.

[0225] cloud computing

[0226] The term "cloud computing" is generally used herein to describe a computing model that enables on-demand access to a shared pool of computing resources, such as computer networks, servers, software applications, and services, and allows resources to be rapidly provisioned and released with minimal management effort or service provider interaction.

[0227] A cloud computing environment (sometimes called a cloud environment or just a cloud) can be implemented in a variety of different ways to best suit different needs. For example, in a public cloud environment, the underlying computing infrastructure is owned by an organization that provides its cloud services to other organizations or the public. In contrast, a private cloud environment is typically used only by or within a single organization. A community cloud is intended to be shared by several organizations within a community; while a hybrid cloud includes two or more types of clouds (e.g., private, community, or public) that are bound together by data and application portability.

[0228] In general, the cloud computing model enables some of those responsibilities that may have previously been provided by an organization's own information technology department to be delivered as a service layer within a cloud environment for consumption by consumers (whether internal or external to the organization, depending on the public / private nature of the cloud). Depending on the specific implementation, the precise definition of the components or features provided by or within each cloud service layer may vary, but common examples include: Software as a Service (SaaS), in which consumers use software applications running on the cloud infrastructure, while the SaaS provider manages or controls the underlying cloud infrastructure and applications. Platform as a Service (PaaS), in which consumers can develop, deploy, and otherwise control their own applications using software programming languages ​​and development tools supported by the PaaS provider, while the PaaS provider manages or controls other aspects of the cloud environment (i.e., all aspects of the runtime execution environment). Infrastructure as a Service (IaaS), in which consumers can deploy and run arbitrary software applications, and / or provision processing, storage, networking, and other basic computing resources, while the IaaS provider manages or controls the underlying physical cloud infrastructure (i.e., all aspects below the operating system layer). Database as a Service (DBaaS), in which the consumer uses a database server or database management system running on a cloud infrastructure, while the DbaaS provider manages or controls the underlying cloud infrastructure, applications, and servers, including one or more database servers.

[0229] In the foregoing specification, embodiments of the present invention have been described with reference to numerous specific details that may vary from implementation to implementation. Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive. The sole and exclusive indicator of the scope of the invention, and what the applicants intend to be the scope of the invention, is the literal and equivalent range of the set of claims issued from this application, in the specific form in which such claims are distributed, including any subsequent corrections.

Claims

1. A computer-implemented method comprising: generating a salt value including a first pseudo-random number; creating each PRNG of the set of PRNGs based on a pseudo-random number generator PRNG-specific salt water value, the PRNG-specific salt water value comprising (a) at least a portion of a salt value and (b) an index value unique to said each PRNG within the set of PRNGs; and causing two or more of the set of PRNGs to generate pseudo-random numbers in parallel by running the two or more PRNGs of the set of PRNGs on respective two or more threads of a multi-threaded processor; The method is executed by one or more computing devices.

2. The method of claim 1, further comprising: receiving a request for a particular PRNG from a set of PRNGs to generate a pseudo-random number; wherein the particular PRNG is created based on a particular salt water value; In response to receiving a request for the specific PRNG to generate a pseudo-random number, the specific PRNG generates a pseudo-random number using at least a portion of the specific salt water value; and The particular PRNG returns a generated pseudo-random number as a response to a request to generate a pseudo-random number.

3. The method of claim 1 , wherein creating each PRNG in the set of PRNGs based on a PRNG-specific saline value comprises creating the specific PRNG based on at least a portion of the specific saline value including an additional parameter of the specific PRNG.

4. The method of claim 1, wherein: Creating each PRNG in the set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; The method further comprises generating the specific salt water value by: determining a number of bits, wherein a set of bits including the determined number of bits is at least capable of representing a known cardinality of a set of PRNGs, filling a first set of bits in a representation of said particular salt water value with said particular portion of the salt value, and A second set of bits in the representation of the particular salt water value is populated with the particular index value, wherein the number of bits in the second set of bits is the determined number of bits.

5. The method of claim 1, wherein: Creating each PRNG in the set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; The method further comprises generating the specific salt water value by: filling a first group of bits with a sliding boundary index value in the representation of the particular salt water value, wherein the number of bits in the first group is predetermined, wherein a sliding boundary index value identifies a particular bit in the representation of said particular saline value, filling a second set of bits with the particular index value, the boundaries of the second set of bits being the particular bits in the representation of the particular saline value, and A third set of bits is populated with the particular portion of the salt value, the third set of bits comprising bits of the representation of the particular salt water value that are not in the first set of bits and not in the second set of bits.

6. The method of claim 1, wherein: Creating each PRNG in the set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; The method further comprises generating the specific salt water value by: setting a flag bit of each of one or more first bit groups in the representation of the specific salt water value to indicate that each bit group includes salt value information, wherein the one or more first bits collectively represent the specific portion of the salt value, and setting one or more index flag bits of a second bit group in the representation of the specific salt water value to indicate a boundary bit of the specific index value, The one or more second bit groups collectively represent the specific index value.

7. The method of claim 1, wherein: Creating each PRNG of the set of PRNGs based on a PRNG-specific salt water value includes creating a specific PRNG based on a specific salt water value, the specific salt water value including a specific portion of a salt value and a specific index value unique to the specific PRNG; The method further comprises generating the specific salt water value by: filling a first set of one or more bits with the particular portion of the salt value in a representation of the particular salt water value, wherein each bit group in the first set of one or more bit groups represents a value that does not satisfy a boundary value test, filling the boundary bits with values ​​that satisfy the boundary value test in the representation of the particular salt water value, and populating a second set of one or more bits with the particular index value in a representation of the particular salt water value, The boundary bit group is located between the first set of one or more bits and the second set of one or more bits in the representation of the particular salt water value.

8. A method as claimed in claim 7, wherein the boundary value test tests whether the value represented by the bits is the maximum number representable by the bits.

9. The method of claim 1, wherein creating the set of PRNGs is performed in parallel by at least two threads of a processor running corresponding PRNG generators using the same salt value.

10. The method of claim 1, wherein each PRNG in the set of PRNGs utilizes a xorshift generator algorithm from a group of xorshift generator algorithms consisting of xoroshiro64; xoroshiro128; xoshiro256; xoshiro512; and xoroshiro1024.

11. The method of claim 1 , further comprising: receiving a request to create a second set of PRNGs; In response to receiving the request to create a second set of PRNGs, creating the second set of PRNGs by: generating a second salt value comprising a second pseudorandom number, wherein the second pseudo-random number is different from the first pseudo-random number, and Each PRNG in the second set of PRNGs is created based on a PRNG-specific salt value that includes (a) at least a portion of a second salt value and (b) an index value unique to each PRNG in the second set of PRNGs.

Citation Information

Patent Citations

  • Information processing system

    JP2007142504A

  • Method and system for generating unpredictable pseudo-random numbers

    US20130129088A1