METHOD FOR GENERATING RANDOM NUMBERS

DE602022015215T2Active Publication Date: 2025-05-28SPINNION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602022015215
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-05-28
Filing Date
2022-04-13
Publication Date
2025-05-28
Estimated Expiration
2042-04-13

AI Technical Summary

Technical Problem

Existing methods for generating random numbers, especially for high-security encryption, require complex hardware and calibration, making them inefficient for rapid generation of long random numbers with high entropy.

Method used

A method utilizing a digital processor to generate random numbers by interrogating internal registers, such as a timestamp register, and extracting bits to form the random number, with optional random selection of register bits and registers, allowing for high entropy and rapid generation without hardware additions.

Benefits of technology

This method achieves simplicity, high entropy, and rapid generation of very long random numbers, ensuring optimal operation without prior calibration, and allows for a double degree of randomness in each generated number.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

Technical field of the invention

[0001] The invention relates to the generation of random numbers.

[0002] Many techniques require random numbers, especially in the field of cryptography when implementing high-security encryption algorithms such as AES, RSA, Diffie-Hellman, etc. But the use of random number draws occurs in many other areas, including games of chance, probabilistic modeling techniques, or the selection of samples for statistical purposes. State of the prior art

[0003] There are multiple ways to generate random numbers, with varying levels of entropy, where entropy is defined as the measure of the effective degree of randomness (absence of deterministic character and predictability of the drawing) of the generated value.

[0004] In some cases, the generation of "pseudo-random" numbers may be sufficient, that is, numbers that are obtained by a process that is deterministic, but which produces values ​​sufficiently independent of each other to satisfy the needs of the applications considered: for example, modeling algorithms using probabilistic techniques, or sampling methods for statistical purposes.

[0005] On the other hand, particularly in the case of data encryption, it is essential that the series of random numbers delivered by the generator have no detectable link between successive numbers, that is to say that the numbers produced are absolutely impossible to predict.

[0006] The methods for generating random numbers (and not simply pseudo-random numbers) used until now are mainly based on physical, material phenomena (for example thermal or electromagnetic noise) or on an unpredictable interaction with a user, for example the erratic movements of a mouse, which are neither cyclical nor deterministic.

[0007] These generators deliver random numbers with very high entropy but they have the disadvantage of being relatively complex, because they require hardware circuitry to collect the physical phenomenon or interaction with the user, analog / digital converter circuits, an algorithmic module for generating the random digital value, etc.

[0008] Furthermore, they are poorly suited to the generation of very large random numbers (several tens or hundreds of bits), except at the cost of an excessively long response time between the request to obtain the random number and the actual delivery of the result by the generator.

[0009] The article by Marton K et al. "Randomness Assessment of an Unpredictable Random Number Generator based on hardware Performance Counters", Romanian Journal of Information Science and Technology, Vol. 20, No. 2, 2017, 136-160, proposes a technique for generating (pseudo-)random numbers by sampling the contents of one (or more) of the hardware performance counter(s) of a processor and using the result of the sampling as a source of unpredictable random value.

[0010] Hardware performance counters are dedicated registers present in recent microprocessors, used for performance monitoring ( performance monitoring ) of the processor while it is running. These counters count events (in the computer sense of the term) related to the activity of the processor: successful or missed cache accesses, progress of the instruction pipeline, etc. or even durations during which a given condition remains 'true', by counting the number of CPU cycles elapsed until this condition changes.

[0011] The highly unpredictable nature of the evolution of these counters, linked to multiple and very changing states of the processor operation, induces a high entropy allowing the generation of random number sequences. In other words, the random nature of the contents of the registers is attributed to the entropy of the system and to the multitude of processes and threads executed simultaneously.

[0012] This technique is not, however, immune to phenomena such as: cyclical evolutions of processor states, repetitive operating sequences, iterations, etc. To overcome this risk, the aforementioned article by Marton et al. describes how to carry out a "calibration" of the random number generator by a "randomness assessment" sequences produced for various generator settings, allowing the configurations that provide the best entropy to be selected.

[0013] Therefore, the implementation of this technique requires a calibration of the generator to ensure that the generation of (pseudo-)random numbers will be done with the desired level of entropy.

[0014] However, the most recent applications of high-security encryption require the very rapid generation of long random numbers with high entropy that can be guaranteed unconditionally, without prior analysis or adjustment of the generator's operating parameters.

[0015] The aim of the invention is to overcome these difficulties and limitations by proposing a technique for generating random numbers which simultaneously offers: a very great simplicity of implementation, without recourse to any hardware circuitry; the possibility of delivering random numbers as long as desired at a very high rate; a maximum entropy of the generated numbers, better than what has been proposed until now by techniques such as those of Marton et al.; the immediate guarantee of optimal operation with maximum entropy, without any recourse to prior calibration; and the possibility, in certain implementations, of making the specific operation of the random generator depend on a higher level parameter, itself modified randomly at each iteration of the process, that is to say with a double degree of randomness for each number obtained. Statement of the invention

[0016] These aims are achieved according to the invention, by a method for generating a random number implemented by means of a digital processor, comprising: a) the interrogation of an internal register of the processor, the content of the register being an evolving content which changes over time; b) the extraction at a given instant of n register bits, n ≥ 1; c) the use of n bits extracted in step b) as the constituent bit(s) of a random number of N bits to be generated; d) repeating steps a) to c) until the N bits of the random number; and e) delivering the random number to an application circuit or software.

[0017] Characteristically of the invention, the method further comprises, before step b), a step of selection by a random or pseudo-random process of those of the nbits of the register which will be extracted in step b), and / or selection by a random or pseudo-random process of one of a plurality of potentially interrogable internal registers of the processor, and selection of the n bits of the selected register, in particular selection by a random or pseudo-random process of at least one of the bits of the selected register.

[0018] According to various advantageous subsidiary implementation forms: at least one internal register of the processor comprises an internal timestamp register counting pulses of a sequencing clock of the processor, in particular a register for counting pulses directly from an oscillator of the clock; at least one internal register of the processor comprises a register for counting events of the processor; steps a) to e) are executed within a firmware of the processor; nbits extracted in step b) are the least significant bit(s) of the register; the given time of extraction of the n bits in step b) is an instant determined by a random or pseudo-random process; and / or the given instant of extraction of the n bits in step b) is an instant determined in response to a request received from the application circuit or software. Brief description of the drawings

[0019] We will now set out examples of implementation of the invention, with reference to the appended drawings where the same references designate identical or functionally similar elements from one figure to another. There Figure 1 schematically illustrates a digital processor with the various blocks to which it is interfaced, the whole being used for implementing the method of the invention. Figure 2 explains how to generate a random number by querying a system register. Figure 1 . There Figure 3 is a flowchart showing the successive steps of implementing the method of the invention. The Figure 4 is a diagram describing an improved mode of implementation of the invention, combining several random selection techniques to obtain the value to be generated. Detailed description of the invention

[0020] There Figure 1 schematically represents an architecture of a digital processor system, which is conventional in itself.

[0021] A microprocessor or microcomputer 10 is interfaced by data buses 12, addresses 14 and control buses 16 respectively to memory circuits 18, to external peripherals 20 and to internal resources 22.

[0022] The general sequencing of the processor 10 is ensured by a clock circuit 24 comprising an oscillator 26 controlled by a quartz 28. The periods of the oscillator 26 feed a timestamp register 30 counting the pulses which will be used to define the rate of the successive CPU cycles of the processor 10 after reduction of the frequency by a divider 32. The content of the timestamp register 30 is an evolving content, varying permanently at the rate of the pulses of the sequencing clock 24.

[0023] The principle of the invention, schematized Figure 2 , consists of reading one or more bits ( n bits, with n ≥ 1) of a fast-changing register of the processor, in particular (but not limited to) the timestamp register 30, and use these n bits to constitute the N bits of a 34-bit random number of N bits ( N ≥ n ) .

[0024] If n < N,the process is repeated until the completion of the N bits of the number 34.

[0025] It is possible to extract, indifferently, for example one bit at a time ( n = 1), half a byte ( n = 4), one byte ( n = 8), etc., to obtain the N bits of random number 34, with no specific limitation on the number N , and therefore on the length of the random number obtained.

[0026] In most microprocessors, the timestamp register ( timestamp) is an accessible and queryable register. For example, in Intel (registered trademark) processors this timestamp register is a 64-bit register called TSC ( TimeStamp Counter ) , and it can be queried by a low-level RDTCP instruction ( Read TSC and Processor ID ) . This counter reflects the number of pulses produced by the sequencing clock since the register was initially reset.

[0027] Advantageously, the extracted bit(s) are the least significant bits (LSB) of the register, which are bits whose value is totally unpredictable at a given instant given the very high clock frequencies of current processors, typically several gigahertz, i.e. every nanosecond the last bits of the timestamp register are modified several times.

[0028] Furthermore, the execution time of the register query instruction is itself subject to unpredictable randomness, which increases the randomness of the value of the bit(s) read when this query is actually performed. Indeed, the architecture of microcomputers at the hardware level induces irregularities in the sequencing of microinstruction execution due to hardware interrupts (external events that trigger the execution of specific software and that imperatively interrupt the execution of other software), but also due to the necessary coordination of several cores that execute tasks in parallel.

[0029] In addition, above the hardware layer are several software layers that run themselves with different priority levels and in permanent competition with external events and other software running concurrently.

[0030] It is therefore impossible to predict when a particular micro-instruction of an application software will actually be executed and, consequently, to determine in advance the value of the bits of the timestamp register at that time, particularly that of the least significant bits, at the time when the register reading instruction will actually be executed.

[0031] There Figure 3 presents a flowchart 100 schematically illustrating the successive steps of the method for obtaining the random number 34 following the reception (block 110) of a request to generate a random number: a) querying the timestamp register 30 (block 120); b) extracting the n bits from the register (block 130); c) using this or these bits to constitute the random number (block 140); d) if the random number is not complete (test 150), repeating steps 120 to 130; and finally e) delivering the random number (block 160) as a response to the request received in step 110.

[0032] It should be noted that the process just described has several particularly significant advantages: no addition of hardware to the pre-existing circuits of the digital processor, since no interaction with the outside (to use a physical phenomenon) or with the user is necessary; simple and universal implementation, the timestamp register existing on all digital processors; very high degree of entropy; and possibility of obtaining very long random numbers in a very short time.

[0033] In practice, the generation process can be implemented at several levels: entirely and directly within the firmware ( firmware ) of the processor; from this firmware to feed a higher level application software layer, therefore from the processor to the application layer (which avoids difficulties due to access protections to the microprocessor, since in this case it is the latter which internally generates and delivers the random number); or conversely, from the application layer to the processor, at the request of the application. A high level application ( User Mode) generally not having the privileges to directly access the processor registers, the implementation can be done at two levels with i) one module running at a high privilege level to access the processor registers and ii) a second module communicating with the first and interfaced to the high-level program by an appropriate API.

[0034] Characteristically of the invention, the method for generating a random number set out above further provides, in order to maximize the overall entropy of the process, to select, randomly or pseudo-randomly, at each iteration the position of the n bits which will be extracted from the internal register(s) (instead of systematically taking, as in the example described above, the least significant bits).

[0035] A variation is to vary the number nand / or the order of the bits extracted from the interrogated register, also randomly or pseudo-randomly, at each interrogation step. In other words, the value n is in this case itself random instead of being predefined, as is the order in which the n bits (if more than one bit) are used to make up the random number.

[0036] Another variation is, instead of simply copying the n bits extracted to constitute the N bits of the random number, to use these n bits by modifying them, for example by inverting or permuting them according to a random or pseudo-random process, by summing all of them or by summing some of them, etc.

[0037] Also characteristic of the invention, the method for generating a random number set out above provides, as a variant or in addition, to use several of the internal registers of the processor to extract bits therefrom, with a process for selecting the register used for each extraction which itself depends on a random or pseudo-random process, that is to say that the register from which the n bits are extracted can change from one iteration to another, in a non-deterministic way.

[0038] There Figure 4 presents a diagram 200 describing a universal and improved implementation mode of this sixth variant, combining several random selection techniques to obtain the value to be generated.

[0039] The first step (block 210) consists of determining the type of processor used with which random numbers are to be generated. Once this processor is recognized, a table of registers that can be used to implement the method is established (block 220), with the number of registers that can be used for this purpose, and for each its address and length. These registers are illustrated in R1, R2, R3, ... R(n) on the Figure 4 , each of them consisting of a series of bits b0, b1, b2, ... b(n).

[0040] The generation process can then begin, with first of all a first random or pseudo-random selection of one of the registers referenced in the table (block 230), then a second selection, also random or pseudo-random, of one of the bits of the register thus selected (block 240) - or of several bits of this register, with the different variants explained above.

[0041] These steps 230 and 240 are repeated (block 250) until the random number to be generated is completed (block 250), which can then be output to the requesting application.

[0042] A variant, which can optionally be combined with the previous techniques, consists of using several of the processor's internal registers to extract one or more bits, and applying a combinational process, for example an XOR, between the bits extracted from the different registers interrogated.

Claims

1. A random number generation method implemented by means of a digital processor (10), comprising: a) searching (120) an internal register (30) of the processor, wherein the content of the register is an evolutive content which changes over time; b) extracting (130) at a given time n bits from the register, n ≥ 1; c) using (140) the n bits extracted at step b) as bit(s) for forming a random number of N bits (34) to be generated; d) reiterating steps a) to c) until obtaining the N bits of the random number; and e) providing (160) the random number to an application circuit or software, characterized in that the method further comprises, before step b), a step of selecting, by a random of pseudo-random process, the n bits of the register which will be extracted at step b), and / or of selecting, by a random of pseudo-random process, one register among a plurality of internal registers of the processor that may be potentially searched and selecting the n bits from the selected register, in particular selecting, by a random or pseudo-random process, at least one of the bits of the selected register.

2. The method of claim 1, wherein at least one internal register (30) of the processor comprises an internal timestamp register which counts pulses of a clock (24) for sequencing the processor.

3. The method of claim 2, wherein the internal timestamp register is a register which counts pulses directly outputted from an oscillator (26) of the clock (24).

4. The method of claim 1, wherein at least one internal register (30) of the processor comprises a register which counts processor events.

5. The method of claim 1, wherein steps a) to e) are carried out within a firmware of the processor.

6. The method of claim 1, wherein the n bits extracted at step b) are the least significant bit(s) of the register.

7. The method of claim 1, wherein the given time of extraction of the n bits at step b) is a time which is determined by a random or pseudo-random process.

8. The method of claim 1, wherein the given time of extraction of the n bits at step b) is a time determined in response to a request received from the application circuit or software.