Interval continuous principle true random number generation device supporting national cryptographic security
Patent Information
- Application Number
- CN202610465431.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-04-09
- Publication Date
- 2026-09-01
AI Technical Summary
[0003]当前国家密码安全领域的随机数生成技术存在诸多致命短板,无法满足高等级密码安全刚性需求:其一,主流伪随机数生成器基于算法迭代实现,存在固定规律、周期性、可预测、可逆向破解风险,一旦算法被破解,整个密码体系彻底失效,无法用于国家关键密码场景;其二,现有物理真随机数多依赖热噪声、噪声二极管、振荡器抖动等单一熵源,易受温度、电压、电磁环境干扰,随机性均匀性、无偏性不足,最小熵不达标,且存在周期性隐患;其三,熵源信号为离散非连续状态,熵值密度低,随机数生成速率慢,无法适配高速加密场景;其四,核心随机数生成架构、芯片、校验算法均依赖境外技术,存在隐藏后门、数据泄露、恶意管控风险,国产化自主可控性极差,违反国家密码安全自主可控要求;其五,缺乏实时多维度随机性校验机制,异常熵源无法及时剔除,输出随机数存在偏差,难以通过国家密码管理局随机性检测标准,严重制约国家密码安全体系建设
[0025]1.真随机高安全性:基于区间连续物理熵源生成,无算法规律、无周期、不可预测、不可复现,最小熵≥0.9998bit/bit,安全性远超伪随机数,抵御预测攻击、逆向攻击、暴力破解能力极强。
Abstract
Description
[0001] This invention discloses a true random number generation device based on the interval continuous principle that supports national cryptographic security. It belongs to the fields of national cryptographic applications, information security encryption, and domestically produced cryptographic hardware technology, and fully complies with the national cryptographic industry standards GM / T0005-2021 "Randomness Detection Specification," GM / T 0078-2020 "Design Guidelines for Cryptographic Random Number Generation Modules," and GM / T 0103-2021 "Overall Framework of Random Number Generators." This device is based on the interval continuous physical entropy change principle, equipped with a domestically produced GZ-Crypto-RISC-V cryptographic chip and the RandomCheck-AI randomness intelligent verification model. It consists of a continuous interval physical entropy source module, an interval state acquisition unit, a STE encoding and quantization unit, a randomness verification unit, and a national cryptographic standard output interface unit. The core quantization thresholds are set as follows: minimum entropy ≥ 0.9998 bit / bit, random number generation rate ≥ 1Gbps, generation delay ≤ 1μs, randomness detection pass rate 100%, periodic length ≥ 10^12 bits, and **unreproducibility rate 100%**. By constructing a continuous, uninterrupted, aperiodic, and unpredictable physical entropy change range, multi-point synchronous high-speed acquisition of entropy source signals is achieved. These signals are then converted into a national standard binary random sequence via domestically produced STE encoding and quantization. AI-based multi-dimensional real-time randomness verification is then used to eliminate abnormal deviations before outputting highly secure true random numbers. This device features a purely domestic hardware architecture, with no reliance on foreign chips, algorithms, or architectures, and no security backdoors. Its randomness, stability, and attack resistance far surpass those of pseudo-random number generators. It can fully support high-level national cryptographic security scenarios such as government encryption, financial cryptography, communication confidentiality, and data security, providing underlying core random number support for key generation, identity authentication, and data encryption. Technical Field
[0002] This invention belongs to the fields of national commercial cryptography, information security encryption, hardware true random number generation, domestically produced cryptographic chips, and critical information infrastructure security technology. Specifically, it relates to a true random number generation device based on the interval continuous principle that supports national cryptographic security. It is particularly suitable for high-level, high-reliability, and independently controllable national cryptographic security scenarios such as government cryptographic machines, financial encryption terminals, communication security equipment, data security platforms, and cryptographic modules of critical information infrastructure. It strictly follows the various commercial cryptographic standards of the State Cryptography Administration. Background Technology
[0003] Current random number generation technologies in the field of national cryptographic security have many fatal shortcomings and cannot meet the rigid requirements of high-level cryptographic security: First, mainstream pseudo-random number generators are based on algorithm iteration, which has the risk of fixed patterns, periodicity, predictability, and reversibility. Once the algorithm is cracked, the entire cryptographic system is completely invalidated and cannot be used in critical national cryptographic scenarios. Second, existing physical true random numbers mostly rely on single entropy sources such as thermal noise, noise diodes, and oscillator jitter, which are easily affected by temperature, voltage, and electromagnetic environment interference. They lack randomness, uniformity, and unbiasedness, fail to meet minimum entropy standards, and exhibit periodicity. Third, the entropy source signal is discrete and discontinuous, with low entropy density and slow random number generation rate, making it unsuitable for high-speed encryption scenarios; fourth, the core random number generation architecture, chip, and verification algorithm all rely on foreign technology, posing risks of hidden backdoors, data leakage, and malicious control, resulting in extremely poor domestic self-control and violating national requirements for independent control of cryptographic security; fifth, the lack of a real-time multi-dimensional randomness verification mechanism means that abnormal entropy sources cannot be eliminated in a timely manner, leading to deviations in the output random numbers and making it difficult to pass the randomness detection standards of the State Cryptography Administration, severely restricting the construction of the national cryptographic security system.
[0004] To address the aforementioned technical challenges, this invention constructs a novel physical entropy source based on the principle of interval continuity. By combining domestically produced dedicated chips with AI intelligent verification, it creates a true random number generation device that is aperiodic, unpredictable, unreproducible, and highly resistant to interference. The entire process complies with national cryptographic standards, achieving 100% independent control. Summary of the Invention
[0005] 1. Core Definition 1. Interval Continuity Principle: Construct a continuous physical entropy change interval without discontinuities, interruptions, or periods. The entropy value changes continuously and smoothly with the physical state, without discrete jumps, generating unpredictable and unreproducible high-entropy signals. 2. True random numbers: generated based on physical entropy sources, without algorithmic patterns, periodicity, unpredictability, and reproducibility, fully complying with the GM / T 0005-2021 randomness detection standard. 3. Minimum entropy: The core indicator for measuring the unpredictability of random numbers. The closer the value is to 1, the stronger the randomness. 4. STE cryptographic encoding quantization: Domestically developed proprietary encoding rules convert continuous physical entropy signals into national standard binary random sequences, without any reliance on foreign encoding. 2. Key quantization thresholds (compliant with the national cryptographic standard GM / T, directly accessible to programmers) 1. Minimum entropy: ≥0.9998 bits / bit, far exceeding the requirements of national cryptographic standards. 2. Random number generation rate: ≥1Gbps, suitable for high-speed encryption scenarios. 3. Random number generation delay: ≤1μs, low-latency output 4. Randomness test pass rate: 100% (passes GM / T 0005-2021 full-item test) 5. Periodic length: ≥10^12 bits, without periodicity. 6. Non-reproducibility rate: 100%, the same random sequence cannot be reproduced under the same conditions. 7. Environmental interference resistance: Temperature -40℃~85℃, voltage fluctuation ±15%, no change in randomness indicators. 8. Anomaly removal accuracy: 100%, real-time removal of deviation entropy source signals. 9. National cryptographic interface rate: ≥1.2Gbps, compatible with the full range of national cryptographic algorithms SM1 / SM2 / SM3 / SM4 / SM9.
[0006] E(t) = ∫t0 t α. S(x)dx + β. N(t) + γ. R(x) where: E(t): real-time entropy value over a continuous interval, uninterrupted, non-periodic, and unpredictable; α / β / γ: physical entropy source weighting coefficients, α² + β² + γ² = 1, fixed in hardware and unchangeable; S(x): continuous physical state change function (e.g., continuous electric field, magnetic field, temperature field gradual change); N(t): environmental natural disturbance function, uncontrollable and irregular; R(x): inherent random disturbance in hardware, unreplicable and uncontrollable. The integration interval is continuous and without discontinuities, ensuring the entropy source signal is continuous and without discreteness, with an entropy density ≥ 0.9999 bits / sample point.
[0007] Sraw =n1 ∑i=1n E(ti )+ΔSnoise n: Number of simultaneous multi-point samples, n=16, high-speed simultaneous sampling E(ti): Entropy value of a single sampling point ΔSnoise: Interference noise removal amount, real-time removal of environmental interference. Sampling frequency: 1GHz, sampling precision: 16bit, original data stream is distortion-free.
[0008] STECrypto =Hash(Sraw )⊕KGM ⊕IDEntropy ⊕CRCCrypto Hash(Sraw): The original entropy stream hash value (256 bits, using the national cryptographic SM3 algorithm). KGM: 256-bit national-level proprietary key, hardware-generated TRNG, no overseas keys. IDEntropy: A unique identifier (64-bit) for entropy sources, distinguishing different entropy source modules. CRCCrypto: Cryptographic verification code (32 bits) to prevent quantization distortion. ⊕: Underlying bitwise XOR encoding; the encoding is irreversible, immutable, and unpredictable. Quantization output: Standard binary random sequence (0 / 1), unbiasedness 1:1 ± 0.001
[0009] P0 / 1 = N0 + N1 N0 × 100% P0 / 1 represents the percentage of 0 / 1 bits, requiring 49.95% ≤ P ≤ 50.05% to meet the unbiasedness requirement.
[0010] Hmin = -log2(maxP(x)) requires Hmin ≥ 0.9998 bits / bit to meet the unpredictability standard.
[0011] χ2=∑Ei (Oi -Ei )2 ≤χ0.012 The chi-square test is passed, and the randomness meets the national cryptographic standard.
[0012] Chip model: GZ-Crypto-RISC-V, a national-level cryptographic chip with a main frequency of 2.0GHz, cryptographic computing power ≥5.0TOPS, a purely domestic architecture, with no foreign IP cores, no foreign components, and no technical backdoors. It integrates entropy source acquisition, STE encoding quantization, randomness verification, and national-level cryptographic interface hardware acceleration units. It features a wide temperature range, high anti-interference capabilities, and protection against physical attacks, and complies with GM / T0028-2021 "Security Technical Requirements for Cryptographic Modules".
[0013] asm; Continuous entropy source acquisition command ENTROPY_COLLECT rD, rSource; 16-point synchronous high-speed acquisition of entropy source signals, executed in a single cycle; Continuous entropy value calibration command ENTROPY_CALIB rD, rRaw; Continuous entropy value calibration, eliminating environmental interference, executed in two cycles; STE cryptographic encoding quantization command STE_CRYPTO_ENCODE rD, rEntropy; Entropy flow to national cryptographic standard random sequence, executed in two cycles; Randomness national cryptographic verification command RANDOM_CHECK rD, rSeq; GM / T 0005 full-item randomness verification, executed in a single cycle; Abnormal entropy source removal command ABNORMAL_REMOVE rD, rStatus; Real-time removal of abnormal deviation sequences, executed in a single cycle; National cryptographic standard output command GM_OUTPUT rD, rRandom; High-speed output of true random numbers from the national cryptographic interface, executed in a single cycle; Hardware anti-attack detection command ATTACK_CHECK rD, rHardware; Physical attack monitoring, single-cycle execution chip integrates national cryptographic SM3 hash module, hardware true random number solidification module, and side-channel attack prevention unit, with full hardware acceleration and no software algorithm intervention, eliminating the risk of algorithm cracking.
[0014] 1. Model Architecture: A hybrid architecture of DNN+CNN with national cryptographic standard, with only 8.2M parameters, INT8 quantization, embedded hardware deployment, built on a domestic deep learning framework, with no dependence on foreign frameworks, and optimized for multi-dimensional randomness verification of true random numbers.
[0015] 2. Core functions of the model: continuous entropy source quality assessment, multi-point sampling signal calibration, STE encoding quantization optimization, GM / T 0005 full-item randomness detection, real-time identification of abnormal entropy sources, adaptive elimination of environmental interference, and hardware anti-attack monitoring.
[0016] 3. Inference process: Entropy source signal acquisition → AI entropy value calibration → STE encoding quantization → multi-dimensional randomness verification → anomaly removal → national cryptographic standard output → real-time closed-loop optimization.
[0017] 4. Core performance indicators of the model: inference latency ≤ 0.5μs, randomness detection accuracy 100%, anomaly recognition rate 100%, and environmental interference rejection rate ≥ 99.99%.
[0018] 5. Loss function: Entropy uniformity loss + minimum entropy loss + unbiasedness loss + national cryptographic detection pass rate loss, four constraints to ensure that the output random numbers fully comply with the national cryptographic standard.
[0019] This device consists of five core units, all electrically connected, hardware-coordinated, and without software dependencies. It features a purely domestically produced hardware architecture with no foreign components. 1. Continuous Interval Physical Entropy Source Module: The core entropy source unit, based on the principle of interval continuity, constructs a continuous physical entropy change field, generating aperiodic, unpredictable, and unreproducible continuous high-entropy signals. 2. Interval state acquisition unit: Equipped with domestically produced chips, it performs 16-point synchronous high-speed sampling, acquires continuous entropy source signals in real time, eliminates environmental interference, and outputs raw high-entropy data stream. 3. STE Encoding and Quantization Unit: The continuous entropy stream is quantized using STE national cryptographic encoding and converted into a binary random sequence, completing the lossless conversion from continuous signal to digital random number. 4. Randomness Verification Unit: Through AI model + national cryptographic standard algorithm, it detects the uniformity, minimum entropy, unbiasedness and non-periodicity of random numbers in real time, and eliminates 100% abnormal sequences. 5. National Cryptographic Standard Output Interface Unit: In accordance with the GM / T 0103-2021 standard, it outputs true random numbers, is compatible with the entire series of national cryptographic algorithm devices, and supports high-speed and stable calls.
[0020] 1. The hardware constructs a continuous, uninterrupted, non-periodic, and uncontrollable physical entropy change range (electric field / magnetic field changes continuously and gradually). 2. Generate a real-time continuous entropy signal according to the formula for the interval continuous entropy source, with an entropy density ≥ 0.9999 bits / sample point. 3. The entropy source parameters are fixed in the hardware and cannot be changed or copied, with no external intervention interface. 4. Environmental interference resistant design; temperature, voltage, and electromagnetic interference do not affect the continuity and randomness of the entropy source.
[0021] 1. The chip executes entropy source acquisition instructions, performing 16-point synchronous high-speed sampling at a sampling frequency of 1GHz. 2. Calculate the original entropy flow according to the multi-point sampling formula, and remove environmental interference noise in real time. 3. The raw data stream is transmitted to the STE encoding and quantization unit without distortion or delay. 4. Acquisition latency ≤ 0.3μs, ensuring high-speed generation requirements.
[0022] 1. Substitute the original entropy stream into the STE cryptographic encoding formula to generate a 256-bit national-level cryptographic code. 2. Quantize and convert into a standard binary random sequence with uniform 0 / 1 distribution. 3. The encoding and quantization process is implemented in hardware, without software algorithms, making it uncrackable. 4. Quantization delay ≤ 0.4μs, with no sequence distortion or bias.
[0023] 1. The AI model performs comprehensive detection of random sequences, including uniformity, minimum entropy, aperiodicity, and unbiasedness. 2. Determine whether the sequence meets the standards according to the national cryptographic verification formula. 3. Abnormal sequences are 100% removed in real time, and entropy source signals are regenerated. 4. Verification delay ≤ 0.2μs, ensuring that the output random numbers are 100% compliant with national cryptographic standards.
[0024] 1. Verified true random numbers are output at high speed via a national cryptographic standard interface. 2. Output rate ≥ 1Gbps, compatible with various national cryptographic devices. 3. Hardware encryption during the output process to prevent theft, tampering, and side-channel attacks. 4. No foreign technology is involved throughout the entire process, ensuring independent control and safety. Beneficial effects
[0025] 1. Truly random and highly secure: Generated based on a continuous physical entropy source within an interval, it has no algorithmic patterns, no periodicity, is unpredictable and unreproducible, with a minimum entropy ≥ 0.9998 bit / bit. Its security far exceeds that of pseudo-random numbers, and it has extremely strong resistance to prediction attacks, reverse engineering attacks, and brute-force attacks. 2. Fully compliant with national cryptographic standards: 100% passed the full-item randomness test of GM / T 0005-2021, and complies with national cryptographic standards such as GM / T0078 and GM / T 0103, and can be directly used for national commercial cryptographic product certification. 3. Fully independent and controllable: Purely domestic hardware architecture, with no reliance on foreign technologies in the entire process of chips, encoding, verification, and interfaces, and no security backdoors, ensuring national cryptographic security and sovereignty. 4. High stability and anti-interference: The continuous range entropy source has extremely strong anti-environment interference capability. The randomness index remains unchanged within a wide temperature range and wide voltage range, and the fault-free operation time is ≥100,000 hours. 5. High speed and low latency: Generation rate ≥1Gbps, latency ≤1μs, suitable for high-speed encryption, real-time key generation and other scenarios, with strong versatility. 6. Intelligent and reliable verification: AI performs multi-dimensional real-time verification, eliminating 100% of abnormal sequences, and outputting stable random numbers with no need for manual maintenance. Detailed Implementation
[0026] 1. Application scenario: Cryptographic machines for banking and finance, core key generation, transaction encryption, and identity authentication, requiring high-level national cryptographic compliant random numbers. 2. Implementation process: (1) The device is deployed inside the financial cryptographic machine, with pure hardware integration and no external interface. (2) A high-entropy signal is generated by a continuous interval entropy source and 16 points are collected synchronously. (3) STE encoding quantization generates a random sequence and AI randomness verification meets the standard. (4) The national cryptographic interface outputs true random numbers to provide key generation support for the cryptographic machine. (5) Real-time anti-attack monitoring ensures the security of financial cryptography. 3. Implementation results: Random number generation rate of 1.2Gbps, 100% passing national cryptographic testing, non-periodic and unreproducible, effectively resisting various cryptographic attacks, ensuring secure and reliable encryption of financial transactions, and fully domestically produced and controllable.
[0027] 1. Application scenarios: Encrypted terminals for government affairs involving classified information, including document encryption, data transmission of classified information, and identity authentication. 2. Implementation process: (1) The device is integrated into the government encryption terminal and operates stably over a wide temperature range. (2) The continuous entropy source outputs stably and collects data at high speed. (3) AI verification removes anomalies and outputs according to national cryptographic standards. (4) It provides underlying true random number support for government encryption. 3. Implementation results: Minimum entropy of 0.9999bit / bit, unbiasedness meets the standard, resists electromagnetic interference, and ensures that government data encryption is leak-free and unbreakable, meeting the requirements for independent and controllable government cryptography security.
[0028] 1. Application scenario: Cryptographic modules for national critical information infrastructure, providing encryption and security protection for infrastructure data. 2. Implementation process: (1) The device is deployed on the infrastructure security platform as the core cryptographic module. (2) Continuous entropy source is continuously generated and high-speed random number output is performed. (3) Real-time verification of randomness throughout the process ensures the security of the cryptographic module. 3. Implementation results: Stable operation without faults, random number quality meets standards, resists various network attacks, and the cryptographic security of critical infrastructure is fully guaranteed.
Claims
1. A true random number generation device based on the interval continuity principle supporting national cryptographic security, characterized in that, It includes a continuous interval physical entropy source module, an interval state acquisition unit, a STE encoding and quantization unit, a randomness verification unit, and a national cryptographic standard output interface unit. Each unit is purely hardware electrically connected and works together, and the entire process is domestically produced without any reliance on foreign technology. Based on the principle of continuous physical entropy change in intervals, a continuous physical entropy field without discontinuities, without periodicity, and unpredictable is constructed. High-entropy data streams are obtained through multi-point synchronous high-speed sampling, and then converted into binary random sequences by STE national cryptographic encoding. After AI multi-dimensional randomness verification, true random numbers that fully comply with the national cryptographic standards GM / T 0005-2021, GM / T 0078-2020, and GM / T 0103-2021 are output. The minimum entropy is set to ≥0.9998 bit / bit, the generation rate is ≥1Gbps, the generation delay is ≤1μs, and the randomness detection pass rate is 100%.
2. The apparatus according to claim 1, characterized in that, The physical entropy source of the continuous interval adopts the mathematical model E(t)=∫t0 t α. S(x)dx+β. N(t)+γ. R(x), with a sum of squares of weight coefficients of 1, continuous integration interval without discontinuities, entropy density ≥0.9999bit / sampling point, periodic length ≥10^12bit, and non-reproducibility rate of 100%.
3. The apparatus according to claim 1, characterized in that, The interval state acquisition adopts the 16-point synchronous sampling formula Sraw = n1 ∑i=1n E(ti )+ΔSnoise, with a sampling frequency of 1GHz and a sampling accuracy of 16bit. Environmental interference is eliminated in real time, and the original data stream is distortion-free.
4. The apparatus according to claim 1, characterized in that, STE cryptographic encoding quantization rules are as follows STECrypto = Hash(Sraw) ⊕ KGM ⊕ IDEntropy ⊕ CRCCrypto, using the national cryptographic SM3 hash algorithm, with a 256-bit national cryptographic key hard-coded in hardware, the encoding is irreversible, and the quantized output binary random sequence 0 / 1 accounts for 49.95%~50.05%.
5. The apparatus according to claim 1, characterized in that, Randomness verification uses the uniformity formula P0 / 1 = N0 + N1 (N0 × 100%, minimum entropy formula) Hmin = −log2 (maxP(x)), Chi-square test formula χ2=∑Ei (Oi −Ei )2 ≤χ0.012, the accuracy of abnormal sequence removal is 100%.
6. The apparatus according to claim 1, characterized in that, Equipped with the domestically produced GZ-Crypto-RISC-V cryptographic chip, the instruction set includes dedicated instructions such as ENTROPY_COLLECT, ENTROPY_CALIB, STE_CRYPTO_ENCODE, RANDOM_CHECK, ABNORMAL_REMOVE, GM_OUTPUT, and ATTACK_CHECK. The chip's main frequency is ≥2.0GHz, meeting the security requirements of GM / T0028-2021 cryptographic modules.
7. The apparatus according to claim 1, characterized in that, Multi-dimensional detection is achieved through the RandomCheck-AI randomness intelligent verification model, with model inference latency ≤0.5μs, environmental interference rejection rate ≥99.99%, and no software dependency in embedded hardware deployment.
8. The apparatus according to claim 1, characterized in that, The national cryptographic standard output interface conforms to GM / T0103-2021, with an output rate of ≥1.2Gbps. It is compatible with the full series of national cryptographic algorithms SM1 / SM2 / SM3 / SM4 / SM9 and is suitable for high-level national cryptographic security scenarios in government affairs, finance, communications, and critical information infrastructure.
9. A method for generating true random numbers based on the interval continuity principle to support national cryptographic security, characterized in that, Includes the following steps: A continuous, uninterrupted physical entropy change interval is constructed to generate a high-entropy signal; 16 points are synchronously and at high speed to acquire entropy source signals and eliminate interference; the signal is quantized and converted into a random sequence through STE national cryptographic encoding; AI multi-dimensional verification of the national cryptographic compliance of random numbers; and true random numbers are output through the national cryptographic interface. The entire process is implemented in hardware and is domestically produced and independently controllable.
10. A national cryptographic terminal device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the interval continuous principle true random number generation method supporting national cryptographic security as described in claim 9.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the interval continuous principle true random number generation method supporting national cryptographic security as described in claim 9.