Computer-implemented method for obtaining information associated with characteristics of entropy generated by physical entropy generator
By obtaining the percentiles from the distribution function of the output signal from the physical entropy generator, the problem of uneven generation of entropy characteristics is solved, real-time monitoring of entropy reliability is realized, and the security of encryption applications is ensured.
Patent Information
- Application Number
- CN202380068573.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-09-27
- Filing Date
- 2023-09-26
- Publication Date
- 2025-05-06
AI Technical Summary
Physical entropy generators are susceptible to the environment, resulting in uneven entropy characteristics generated, affecting their reliability. Especially in encryption applications, malicious attackers are more likely to crack encryption algorithms that rely on entropy sources.
By obtaining at least two percentiles from the distribution function of the output signal from the physical entropy generator, information associated with the generation of entropy characteristics, such as the minimum entropy amount and a reliable lower limit of the entropy period.
Real-time or periodic monitoring of the entropy characteristics of the physical entropy generator is realized to ensure that the generated entropy is reliable enough and suitable for encryption and other applications that rely on random numbers.
Smart Images

Figure CN119948456A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a computer-implemented method for obtaining information associated with properties of entropy generated by a physical entropy generator according to independent claim 1 and a computing system according to claim 13 . Background Art
[0002] Physical entropy generators have become increasingly used, particularly in the context of cryptography and simulation, where highly reliable entropy (eg, in the form of truly random numbers) needs to be obtained.
[0003] In contrast to algorithmic entropy generators like pseudo-random number generators, physical entropy generators generate truly random entropy (e.g., sequences of bits) because the entropy is obtained from an inherently unpredictable physical process. For example, phase diffusion systems, particularly the phase relationship of two differently driven laser diodes, have been employed in the past to generate entropy at high output rates (e.g., several megabits or gigabits per second).
[0004] While some physical entropy generators are in principle capable of generating entropy with a uniform probability distribution (eg, random numbers), physical entropy generators are susceptible to environmental influences and other effects that can have an impact on the properties of the entropy generated under practical conditions.
[0005] For example, the phase relationship of a laser diode driven constantly and a laser diode driven in a pulsed mode can theoretically generate random numbers with a Gaussian probability distribution. However, depending on the temperature, the phase of the laser diode driven in a pulsed mode can be biased towards a specific phase relative to the laser diode driven constantly. This affects the probability distribution and can cause a bias towards a specific phase relationship, so that even if the random numbers obtained are still almost completely random, there is no longer a Gaussian probability distribution, which makes the generated random numbers less reliable, or equivalently, this causes the physical entropy generator to provide less entropy per entropy cycle. This makes it easier for malicious attackers to crack encryption algorithms that rely on entropy sources to work. Therefore, there is a need to quantify these effects, preferably in real time.
[0006] In addition to environmental effects, the amount of entropy generated per entropy cycle of a physical entropy generator (i.e., the amount of entropy per generated random bit) or other characteristics of the entropy output by the physical entropy generator may be of interest, for example in order to determine whether the generated entropy can be used for the intended purpose (e.g., communications encryption). Summary of the invention
[0007] Target
[0008] Therefore, starting from the known prior art, one object of the present disclosure is to provide a method and a computing system for obtaining information associated with the characteristics of the entropy of a physical random number generator.
[0009] Solution
[0010] This problem is solved by a computer implemented method for obtaining information associated with a property of entropy according to the independent claim 1 and a computing system according to claim 12. Preferred embodiments are provided in the dependent claims.
[0011] A computer-implemented method according to the present invention for obtaining information associated with a characteristic of entropy generated by a physical entropy generator comprises:
[0012] obtaining at least two percentiles of a distribution function from a distribution function of a signal output by a physical entropy generator;
[0013] Information associated with a characteristic of the generated entropy is derived from the relationship of the at least two percentiles.
[0014] In particular, the distribution function may be a cumulative distribution function or a probability distribution function of the signal output by the physical entropy generator.
[0015] The inventors have found that there is a relationship between the characteristics of the total generated entropy and the percentiles of the distribution function derived from the generated entropy source. In particular, it has been found that the quotient and difference of a particular percentile of the distribution function is related to the minimum amount of entropy, and in particular constitutes or is related to the lower limit of the entropy generated by the entropy per bit generated by the physical entropy generator. By using simple operations on the calculation of percentiles to obtain such information about the characteristics of the generated entropy, it is possible to obtain information about, for example, potential deviations or the amount of entropy generated per bit at a high rate, thereby observing whether it is necessary to modify the physical entropy generator (e.g., change its temperature, etc.).
[0016] In one embodiment, the at least two percentiles include a second quartile, a third quartile, and a fourth quartile.
[0017] The inventors surprisingly found that by determining only three quartiles of a distribution function, such as a cumulative distribution function, it is possible to determine the minimum amount of entropy generated per cycle of a physical entropy generator. For example, an entropy cycle of a physical entropy generator may be the generation of a single random bit or the generation of a single random number.
[0018] While the actual amount of entropy generated per bit is not necessarily determined in this embodiment, a reliable lower bound on the entropy generated per cycle of the physical entropy generator is obtained, which can subsequently allow a determination of whether the generated entropy is sufficiently reliable for the process (e.g. encryption) in which it is to be used.
[0019] In a more specific embodiment, the relationship includes calculating the interquartile difference of the difference between the fourth quartile and the third quartile and the difference between the third quartile and the second quartile.
[0020] In this case, the quartile difference means the difference in difference. In this embodiment, the difference between the subtraction of the fourth quartile and the third quartile and the subtraction of the third quartile and the second quartile. By using only three quartiles, the computational complexity of the process is reduced, which allows the determination of the characteristics of the entropy generated at a higher rate by the physical entropy generator, thereby allowing real-time monitoring of the behavior of the physical entropy generator and the entropy generated by it.
[0021] In a further embodiment, the deriving comprises determining that the entropy per bit generated by the physical entropy generator is greater than a minimum entropy threshold per bit if the quartile difference is less than the threshold. In particular, the threshold may be 0, but may also be any other number, depending on the actual application. The minimum entropy threshold will be a value greater than 0, and may be obtained, for example, from considerations of what requirements the entropy must meet when used later.
[0022] It has surprisingly been found that the physical entropy generator produces random bits having a certain amount of minimum entropy if the quartile difference is less than 0. Since the calculation of the difference is computationally relatively simple, this approach allows the minimum entropy generated per cycle of the physical entropy generator to be determined with reduced computational complexity, thereby increasing the frequency or rate at which such determinations can be performed, thereby allowing the characteristics of the physical entropy generator to be monitored in real time or near real time.
[0023] In one embodiment, the relationship includes calculating the quotient of the difference between the fourth quartile and the third quartile and the difference between the fourth quartile and the second quartile.
[0024] More specifically, it may be provided that the deriving comprises determining a maximum trusted minimum entropy per bit generated by the physical entropy generator based on the quotient.
[0025] It has been surprisingly found that by using the quotient of the difference between the fourth quartile and the third quartile and the difference between the fourth quartile and the second quartile, it is possible to determine an absolutely reliable minimum entropy amount or potential minimum entropy. This means that even if other determination methods of the generated minimum entropy may produce different results, the result obtained using the present embodiment constitutes the absolute minimum of all potential minimum entropy values explicitly generated for each cycle of the physical entropy generator.
[0026] In one embodiment, the computer-implemented method may further include comparing the derived information associated with the characteristic with a characteristic threshold and obtaining a comparison result therefrom, and may further include providing an output based on the comparison result.
[0027] The output may be, for example, an audible output or a visual output on a display device and may provide information to the user whether the characteristics of the physical entropy generator are sufficient in view of the application in which the entropy is to be used.
[0028] For example, if the entropy generated by each entropy cycle of the physical entropy generator is below a threshold of, for example, 0.92 bits of entropy per bit generated by the physical entropy generator, this may not be sufficient for certain applications such as encryption. Suspension of entropy generation can ensure that the entropy generated thereby is no longer used for encryption, thereby ensuring that unreliable encrypted information is not inadvertently executed.
[0029] Furthermore, the method may include performing the deriving and the derivation periodically or continuously or based on receiving an indicator indicating that the deriving and / or the derivation is to be performed.
[0030] The continuous derivation of information associated with the characteristics of the generated entropy allows real-time monitoring of these characteristics. However, this can be computationally expensive, or can even reduce the frequency at which entropy can be generated. Therefore, it is also advantageous to derive information associated with the characteristics of characteristic entropy only periodically (e.g., once per second or every 10 seconds or every minute or every hour, or depending on the number of entropy cycles of the physical entropy generator that have been executed after the information associated with the characteristics of the generated entropy is finally determined). Derivation of corresponding information depending on an indicator indicating that the acquisition and / or derivation to be performed can cover obtaining sensor information from a temperature sensor or a vibration sensor associated with the physical entropy generator, which indicates the temperature or vibration (or other characteristics) of or associated with the physical entropy generator. If the information exceeds a specific threshold value that is generally considered to have an impact on the generated entropy, acquisition and / or derivation can be performed to ensure that even under these changing conditions, the generated entropy exhibits the desired characteristics. Alternatively, the derived information can be used to determine the action that needs to be taken. This can ensure the reliable generation and use of entropy.
[0031] In particular, it can be provided that the acquisition and derivation are performed periodically, and the period is less than 1 minute or less than 1 second or less than 1 millisecond. These time periods are particularly advantageous and allow the characteristics of the generated entropy to be observed on a time scale that ensures that the entropy is generated at a high rate, while the generated entropy is generally reliable enough or generally exhibits expected characteristics.
[0032] In one embodiment, the method further comprises obtaining a distribution function from a signal output by the physical entropy generator. By directly obtaining the distribution function from the signal output by the physical entropy generator, percentiles can be further obtained with reduced computational effort.
[0033] The present disclosure also relates to a computing system comprising a programmable circuit programmed with computer-executable instructions which, when executed, cause the computing system to perform a computer-implemented method according to any one of the preceding embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A schematic depiction of an exemplary physical entropy generator is shown;
[0035] Figure 2 A flow chart of a method according to an embodiment is shown;
[0036] Figure 3 A flow diagram of another method of taking action based on derived information associated with a characteristic of entropy according to one embodiment is shown. DETAILED DESCRIPTION
[0037] Figure 1 An exemplary physical entropy generator 100 is shown. This exemplary physical entropy generator 100 is provided herein for illustration purposes only and is not intended to be limiting. Rather, the present invention may be implemented with any physical entropy generator.
[0038] The output of this physical entropy generator is depicted as a bit sequence 160 having a value of 0 or 1. However, the physical entropy generator may also generate random numbers having arbitrary values, as will be explained below, and the physical entropy generator according to embodiments of the present disclosure is not limited to an entropy generator that generates the bit sequence 160 as an output.
[0039] However, for further discussion, the present example of the physical entropy generator 100 will be used as reference.
[0040] The physical entropy generator 100 may exemplarily include two laser sources 101 and 102. The first laser source may be driven in a constant mode, ie, may emit a laser beam 111 continuously.
[0041] The second laser source 102 may be driven in a pulse mode such that the laser source 102 alternately emits laser pulses 121 and does not emit laser pulses.
[0042] For example, the first laser source 101 and the second laser source 102 may be implemented as laser diodes, but this is not limiting. For example, the laser source 101 and / or the laser source 102 may also be implemented as a vertical cavity surface emitting laser (VCSEL) or other laser sources.
[0043] like Figure 1As shown, the laser beam 111 and the laser beam 121 arrive at the optical component 130 in the propagation direction, and the optical component 130 is designed to combine the laser beam 111 and the laser beam 121 into a combined laser beam 131. For example, the component 130 may include one or more mirrors arranged to change the propagation direction of the laser beam 111 and the laser beam 121.
[0044] The combined laser beam 131 then further propagates to the photodetector 140. There, the received combined laser beam 131 will be detected, and the detected signal is converted into an electrical signal according to the intensity of the combined laser beam 131.
[0045] In more detail, the combined laser beam 131 constitutes an interference beam of the laser beam 111 and the laser beam 121. Since the first laser source 101 is driven in a constant mode and the second laser source 102 is driven in a pulsed mode, the laser beam 111 and the laser beam 121 will have a random relative phase relationship. This causes the interference beam 131 to have a random intensity, so that the electrical signal output by the photodetector (here represented as 141) has an arbitrary / random intensity. The output signal 141 of the photodetector 140 can be, for example, a current or voltage signal.
[0046] exist Figure 1 In the exemplary embodiment of the physical entropy generator 100 shown, the output signal 141 is then provided to the comparator 150. In addition, a reference signal (eg, a reference voltage or a reference current) 151 is introduced into the comparator so that the output signal 141 and the reference signal 151 are compared by the comparator 150.
[0047] The output of the comparator then depends on the relationship between the output signal 141 and the reference signal 151. For example, if the reference signal 141 is obtained by constructive interference of the laser beam 111 and the laser beam 121 at the photodetector 140, the output signal 141 can be greater than the reference signal 151, so the output of the comparator 150 can be a bit with a value of "1" associated with this particular cycle of the physical entropy generator. In this case, in response to the second laser source 102 having emitted the laser pulse 121, the cycle constitutes the signal output of the photodetector. Alternatively, if the output signal 141 is less than the reference signal 151, the output of the comparator 150 can be a bit with a value of "0" for this particular cycle of the physical entropy generator 100.
[0048] When laser pulses 121 are continuously generated with the second laser source 102 and the corresponding output signal is obtained from the photodetector 140, a bit sequence 160 is obtained. Depending on the frequency at which the second laser source 102 is driven in a pulsed mode (i.e., according to the number of laser pulses emitted per time period, for example per second), the corresponding frequency of the output bits is obtained. For example, if the second laser source is driven in a pulsed mode so as to generate one million laser pulses per second, one million bits will also be generated per second as the output 160 of the physical entropy generator 100.
[0049] As mentioned above, the physical entropy generator 100 is not limited to the implementation explained above, and is particularly not limited to outputting a bit sequence 160 as an output. The physical entropy generator can also output a number. For example, the physical entropy generator can output an output signal 141 of a photodetector. The output signal 141 (e.g., a voltage or current) has a specific value, and the value is random as described above. Therefore, it itself already constitutes a random number, and in some applications, if a specific simulation requires a random number, it can also be used, for example, as an input for the simulation.
[0050] The physical entropy generator 100 may also include or may be associated with one or more sensors 170, which may determine environmental characteristics or characteristics associated with the physical entropy generator 100 itself. For example, a sensor 170 capable of determining the temperature of the surrounding environment of the physical entropy generator 100 may be provided. Alternatively or additionally, a sensor 170 capable of determining the temperature of any one or both of the laser source 101 and the laser beam 102 may be provided. Alternatively or additionally, a humidity sensor may be provided as the sensor 170 or as part of the sensor 170 in order to measure the humidity around the physical entropy generator. Furthermore, a vibration sensor 170 may be provided to determine whether the physical entropy generator has experienced any vibration. Furthermore, for example, a sensor 170 for determining the stability of a reference signal may be provided. As will be explained below, these sensors may be used to provide an indication based on which actions according to Figure 2 and Figure 3 Any of the methods of in order to derive information associated with the characteristics of the entropy generated by the physical entropy generator 100 and take appropriate action if necessary.
[0051] In general, the physical entropy generator 100 is affected by the environment, but also by the changes in the components of the physical entropy generator 100 itself. For example, the interference signal 131 depends on the conditions of the driving laser source 101 and / or the laser source 102. For example, the phase relationship between the first laser beam 111 and the second laser beam 121 is affected by the temperature of the second laser source 102 and is biased towards a specific value. For example, if the temperature of the second laser source increases, the phase difference between the first laser beam 111 and the second laser beam 121 is more likely to be in a narrower value range than at a lower temperature. This does not mean that a specific phase relationship can be predicted because the phase relationship is governed by the laws of quantum mechanics, but this still causes the output 160 to be biased towards a specific value. This means that the probability distribution function (and cumulative distribution function) associated with the physical entropy generator varies with temperature. For example, depending on the temperature of the second laser source 102, there may be more bits with a value of 1 in the output than bits with a value of 0, statistically, rather than a uniform and uniformly distributed output of bits with a value of 1 or 0. This has an impact on the amount of entropy actually generated per cycle by the physical entropy generator, and therefore on the amount of entropy actually provided per bit in the signal 160 output by the physical entropy generator.
[0052] Other effects or degradations of the assumed completely random output from the physical entropy generator include, but are not limited to, bias and skewness of the probability distribution.
[0053] In the context of the present invention, random numbers or random bit sequences can also be used, for example, to encrypt communications or data, or for simulations that require random numbers as input. Therefore, it is advantageous if the characteristics of the entropy generated by the physical entropy generator (e.g., a bit sequence or a random number sequence) can be determined, for example, whether the amount of entropy per bit generated by the entropy generator is above a minimum entropy threshold. For example, the minimum entropy threshold may be required in order to ensure sufficiently high encryption reliability, or to ensure reasonable output of a simulation performed using the entropy generated by the physical entropy generator 100.
[0054] Figure 2 A flow diagram of one embodiment of a computer-implemented method is depicted for obtaining information associated with the characteristics of entropy generated by the physical entropy generator illustrated above. The method can be executed on a general-purpose computer or a specially designed computer / hardware, such as hardware including an FPGA or any other suitable hardware.
[0055] It should be noted that according to Figure 2 The method does not need to be relative to Figure 1 The embodiments are performed using a physical entropy generator consistent with the embodiment, but other physical entropy generators can also be used, or the method can also be applied in the environment of those physical entropy generators.
[0056] according to Figure 2 The method 200 of the embodiment in the embodiment starts at a first step, obtaining or receiving a signal generated by a physical entropy generator. For example, the signal can be a bit sequence 160 output by the physical entropy generator, or in other embodiments, a random number sequence such as an output signal 141 of the photodetector 140. Alternatively, an analog-to-digital converter (ADC) can be provided after the photodetector 140 (not shown), which converts the output of the photodetector 140 into a binary signal. This can cover the output value 1 if the signal of the photodetector 140 is greater than a threshold applied to the ADC, and the output value 0 if the signal of the photodetector 140 is less than the threshold. For further description, references to random number sequences or bit sequences or random bit sequences will be understood to include random number sequences and random bit sequences.
[0057] From the signal, a distribution function, in particular a cumulative distribution function or a probability distribution function, may then be obtained in step 202. The distribution function may be obtained directly from the signal itself "on the fly", i.e. when the signal is received, or in any other reasonable way.
[0058] In particular, the obtaining of the distribution function can be performed as a computer-implemented method. A corresponding computer may include a comparator, which is a physical component that can perform the comparison very quickly, making it possible to obtain the distribution function on a time scale that corresponds to the time scale over which the physical entropy generator generates entropy, such that Figure 2 This method does not cause any delay in random number or bit generation.
[0059] In particular, a method for obtaining a cumulative distribution function from a signal may include receiving a signal at a first port of a 1-bit comparator and applying a step signal at a second port of the comparator. The step signal may be a signal having a step range that is less than the signal range received from a physical entropy generator. The method for obtaining a cumulative distribution function may include applying a step signal having a first value of the step signal to a second port, and in a subsequent step occurring after the first step, the value of the step signal is increased or decreased by a specific value, which may be referred to as a step range, and is compared again with the signal value in the previous step. The method may also include collecting output values at an output port of the comparator for each of these steps, thereby collecting the output value of each step, and obtaining a cumulative distribution function from a set of output values.
[0060] Since the signal received at the computing system usually also exhibits the same statistical properties at different points in time, the value of the step signal can be increased in subsequently executed steps without affecting the cumulative distribution function actually obtained, as long as the time scale is large enough. Alternatively, it is also possible to use the received signal multiple times as input to the comparator in order to apply different values of the step signal to exactly the same signal, thereby obtaining the cumulative distribution function.
[0061] It should be understood that step 201 and step 202 are not essential for the present invention. It is sufficient to provide a distribution function of the output signal of the physical entropy generator in some way. It can also be specified that step 201 and step 202 do not include obtaining a complete distribution function, but only a portion of the distribution function. Embodiments of the present disclosure also include obtaining only percentiles of the distribution function. In this case, step 202 is understood to be optional, and the method of the present invention basically only needs to obtain at least two percentiles, which are optionally obtained from a distribution function of a portion of the distribution function obtained in step 202.
[0062] After the distribution function is optionally obtained in step 202, the method can be carried out in step 203, wherein at least two percentiles of the distribution function are obtained. In particular, the percentiles can be quantiles of the distribution function. Although these can be obtained from a "complete" distribution function, it is also possible to obtain the percentiles in step 203 without having to obtain the complete distribution function in advance in step 202 as described above. Furthermore, within the present invention, the percentiles are obtained without having obtained the distribution function in advance at all, so that step 202 can also be completely omitted.
[0063] For example, consider a cumulative distribution function (CDF) of the form
[0064]
[0065] Here, CDF is the inverse sine function convolved with a Gaussian function, where Erfc represents 1-Erf, where Erf is the well-known error function And a is composed of gives the distance between the peaks of the inverse sine function, and σ is given by characterizes the mean noise, and CM is the centroid of the cumulative distribution function, while z represents the comparator value. It is possible to obtain at least the quartiles Q0 to Q4 numerically. In particular, the value of z can be set to a value z=0.25k, where k∈[0;4] to obtain the corresponding quartile Q k Or percentiles. In addition, other values are also possible, so that other percentiles are obtained from the cumulative distribution function in step 203.
[0066] After obtaining at least two percentiles in step 203, the method proceeds to step 204, where a relationship of at least two percentiles is obtained. This can be any relationship, for example, a difference or quotient of at least two percentiles or any combination thereof.
[0067] However, particularly with respect to determining the minimum entropy or minimum credible entropy, it has been found that the difference of percentiles and the quotient of percentiles or a combination of percentile differences provides useful information about this particular characteristic of the generated entropy (i.e., the minimum entropy or a lower bound on the entropy generated per entropy cycle or the maximum credible minimum entropy per entropy cycle). Other relationships may also be used, such as to determine the deviation or skewness of the distribution function as a characteristic of the generated entropy.
[0068] In particular, in the case of determining the minimum entropy obtained for each cycle generated by the physical entropy generator (eg, for each bit generated by the physical entropy generator), the inventors have found that if the difference ΔQ 4332 =(Q4-Q4)-(Q3-Q2) is less than 0, then the device or physical entropy generator generates at least the minimum value S min The amount of entropy per bit.
[0069] For example, for the above cumulative distribution function, it can be shown that the minimum entropy is theoretically at least 0.92 bits per cycle, that is, an amount of 0.92 bits of entropy per bit generated is truly random.
[0070] The inventors also discovered that in order to find the maximum credible minimum entropy generated by the physical entropy generator in each entropy cycle, the relationship A maximum or upper limit is established for the calculated minimum entropy that can still be considered credible. For example, this amount can be larger than the minimum entropy calculated above, especially in the case of the cumulative distribution function specified above, where this maximum credible minimum entropy is 0.941 bits per entropy period. This means that a real system, no matter how it actually behaves, will only generate bits where only the amount corresponding to the maximum credible minimum entropy can be reliably assumed to be truly random, even if the empirically calculated minimum entropy is larger than this theoretical amount.
[0071] In a subsequent step 205, corresponding information associated with the characteristics of the entropy generated by the physical entropy generator can be obtained from the calculated relationship. For example, as described above, the minimum entropy of the actual system can be determined by using the quartile difference obtained from ΔQ4332. In step 205, the minimum entropy generated by each cycle of the physical entropy generator can be determined based on the relationship.
[0072] Additionally or alternatively, from the cumulative distribution function, and in particular the relation This can be used in step 205 to derive the maximum credible minimum entropy generated by each entropy cycle of the physical entropy generator. In this case, the minimum entropy and the maximum credible minimum entropy constitute information about a specific characteristic of the entropy, i.e. the quality of entropy generated per bit or the amount of entropy generated per bit. Other characteristics and information about other characteristics can also be determined in this step, such as the deviation or skewness of the cumulative distribution function.
[0073] Figure 2 The method described in the embodiment can be performed only once, for example, when the physical entropy generator 100 is activated or after the accumulation time has passed. Alternatively or additionally, the method of any one of the above embodiments can be performed periodically. For example, the method of any one of the above embodiments can be performed every millisecond or every second or every 10 seconds or every minute or at any other technically reasonable interval.
[0074] For example, the period of executing the method of any one of the above embodiments may depend on the variability of the characteristics of the physical entropy generator. In particular, if the environmental conditions or internal conditions of the physical entropy generator are expected to change within a small time scale (e.g., a few seconds) to the extent that the quality or characteristics of the entropy generated by the physical entropy generator are affected, the method of any one of the above embodiments may be executed every second or every 2 seconds. On the contrary, if it is known that the physical entropy generator is also stable under changing environmental conditions, it is sufficient to ensure the reliability of the generated entropy over a relatively long time scale (which will also be combined with the reliability of the generated entropy). Figure 3 Explanation will be given), therefore, it is sufficient to execute the method of the above embodiment only once every minute or every 20 minutes, etc.
[0075] Alternatively or additionally, the method of any of the above embodiments may also be executed based on receiving an indication to obtain and / or derive an indicator to be executed, that is, at least steps 204 to 205 will be executed. Figure 2 When using the methods described, it is also possible to recalculate or obtain the distribution function for a specific system.
[0076] The indicator may be derived from information obtained from one or more sensors, such as those already combined with Figure 1 For example, if the temperature of the laser source 102 rises above a certain threshold or falls below a certain threshold, and this is determined by the sensor 170, an indication (e.g., a signal) may be generated representing this information, i.e., the temperature of the second laser source 102 falls below a certain threshold or exceeds a certain threshold. Based on and in response to this, actions according to the description may be performed. Figure 2 A method as in any one of the described embodiments.
[0077] This may be advantageous, for example, in order to take into account changes in the environment or internal conditions of the physical entropy generator, which changes may affect the characteristics of the generated entropy to be monitored.
[0078] in this case, Figure 3 Embodiments are shown in which actions are taken based on derived information associated with characteristics of entropy.
[0079] The method 300 starts with step 301 corresponding to step 205, namely obtaining information associated with the characteristics of the entropy generated by the entropy generator from the relationship of the corresponding percentiles. For example, the minimum entropy may have been determined in step 205 or step 301, respectively.
[0080] In a subsequent step, the information associated with the characteristic of the entropy generated by the physical entropy generator is compared with the characteristic threshold 302 to obtain a comparison result. In this case, the characteristic threshold is a numerical value. Therefore, in this embodiment, the corresponding information will also be assumed to be a numerical value. For example, as described above, the information can constitute or can be a minimum entropy.
[0081] The characteristic threshold may be a preset characteristic threshold and may be defined, for example, based on requirements associated with the entropy generated by the physical entropy generator. For example, for encrypted information, it may be advantageous if the minimum entropy generated by the physical entropy generator at each entropy period is fairly high and is not less than 0.9 or 0.94 bits / bit of generated entropy (i.e., each entropy period). By comparing the derived minimum entropy with the characteristic threshold (e.g., determining a quotient or a difference), a comparison result 302 is obtained. The comparison result may indicate that the derived information is less than the characteristic threshold 303 or greater than the characteristic threshold 304.
[0082] exist Figure 3 In the embodiment of the method, the method then proceeds depending on whether the information is less than the characteristic threshold (step 303) or greater than the characteristic threshold (step 304). The case where the derived information is equal to the characteristic threshold can be summarized in step 303 or step 304, or can be ignored.
[0083] In any case, if it is determined that the derived information is less than the characteristic threshold 303, a first action 331 is taken. For example, in embodiments where the information constitutes a minimum entropy and it is determined in step 303 that the obtained minimum entropy is less than the characteristic threshold, action 331 may include outputting information to a user (e.g., a sound signal or visual information on a display) indicating that the minimum entropy reliably generated by the physical entropy generator is below the characteristic threshold and that additional actions may be necessary.
[0084] Alternatively, the action taken in step 331 may include suspending entropy generation by the physical entropy generator to ensure that unreliable entropy is not used, for example, for encrypted communications. Other actions may also be taken depending on the situation. For example, in one embodiment, if the second laser source 102 (see Figure 1 ) increases so that the generated minimum entropy drops below a characteristic threshold, action 331 may further include activating a cooling system to cool the second laser source 102.
[0085] Alternatively, if it is determined in step 304 that the obtained information is greater than the characteristic threshold, another action 341 that is not similar to action 331 can be taken. For example, information about the confirmation that the generated entropy meets a specific requirement can be output. In addition, in step 304, based on this finding, entropy generation can continue.
[0086] Although, in the above example, the situation where the derived information is less than the characteristic threshold (step 303) is considered to be unfavorable for the state of the system or the generated entropy, this is not necessarily the case for all embodiments. It is also possible that if the derived information indicates that it is less than the characteristic threshold 303, the system is working properly, while exceeding the specific characteristic threshold 304 indicates a physical entropy generator failure. In this case, the actions taken according to step 331 and step 341 can be exchanged.
[0087] The present invention also includes a computing system including a programmable circuit programmed with computer executable instructions, which, when executed, cause the corresponding computing system to perform a computer-implemented method according to any one of the above embodiments. In particular, the computing system can be implemented as a general-purpose computer. Alternatively, it can also be implemented as an FPGA or other programmed or programmable circuit.
Claims
1. A computer-implemented method for obtaining information associated with a characteristic of entropy generated by a physical entropy generator, the method comprising: obtaining at least two percentiles of the distribution function from a distribution function of a signal output by the physical entropy generator; Information associated with a characteristic of the generated entropy is derived from the relationship of the at least two percentiles.
2. The computer-implemented method of claim 1, wherein the distribution function is a cumulative distribution function or a probability distribution function of the signal output by a physical entropy generator.
3. The computer-implemented method of claim 1 or 2, wherein the at least two percentiles include a second quartile, a third quartile, and a fourth quartile. 4 . The computer-implemented method of claim 3 , wherein the relationship comprises calculating an interquartile difference of a difference between the fourth quartile and the third quartile and a difference between the third quartile and the second quartile.
5. The computer-implemented method of claim 4, wherein the deriving comprises: If the interquartile difference is less than a threshold, it is determined that the entropy per bit generated by the physical entropy generator is greater than a minimum entropy per bit threshold.
6. The computer-implemented method of any one of claims 3 to 5, wherein the relationship comprises calculating a quotient of a difference between the fourth quartile and the third quartile and a difference between the fourth quartile and the second quartile.
7. The computer-implemented method of claim 6, wherein the deriving comprises determining a maximum credible minimum entropy per bit generated by the physical entropy generator based on the quotient.
8. The computer-implemented method according to any one of claims 1 to 7, further comprising comparing the derived information associated with the characteristic with a characteristic threshold and obtaining a comparison result therefrom; The computer-implemented method also includes providing an output based on the comparison.
9. The computer-implemented method of claim 8, further comprising outputting information and / or suspending the entropy generation if the comparison result indicates that the entropy generated by the physical entropy generator is below the characteristic threshold.
10. A computer-implemented method according to any one of claims 1 to 9, wherein the method comprises performing the obtaining and the deriving periodically or continuously or based on receiving an indicator indicating that the obtaining and / or the deriving is to be performed. 11 . The computer-implemented method of claim 10 , wherein the obtaining and the deriving are performed periodically, and the period is less than 1 minute, less than 1 second, or less than 1 millisecond.
12. A computer-implemented method according to any one of claims 1 to 11, wherein the method further comprises obtaining the distribution function from the signal output by the physical entropy generator.
13. A computing system comprising programmable circuitry programmed with computer executable instructions which, when executed, cause the computing system to perform the computer implemented method according to any one of claims 1 to 12.