Security Analysis of NIST CTR-DRBG
Viet Tung Hoang, Yaobin Shen
Abstract
We study the security of CTR-DRBG, one of NIST's recommended Pseudorandom Number Generator (PRNG) designs. Recently, Woodage and Shumow (Eurocrypt' 19), and then Cohney et al. (S&P' 20) point out some potential vulnerabilities in both NIST specification and common implementations of CTR-DRBG. While these researchers do suggest counter-measures, the security of the patched CTR-DRBG is still questionable. Our work fills this gap, proving that CTR-DRBG satisfies the robustness notion of Dodis et al. (CCS'13), the standard security goal for PRNGs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get edf7272a-28bf-4c70-9adf-b54aee9188bdCited by top-tier papers1
Ask how each one uses itRelated papers
- Pseudorandom Black Swans: Cache Attacks on CTR_DRBGShaanan Cohney, Andrew Kwong, Shahar Paz, Daniel Genkin et al.S&P 2020 · 36 citations
- Verified Correctness and Security of mbedTLS HMAC-DRBGKatherine Q. Ye, Matthew Green, Naphat Sanguansin, Lennart Beringer et al.CCS 2017 · 59 citations
- Enhancing Provable Security and Efficiency of Permutation-Based DRBGsWoohyuk Chung, Seongha Hwang, Hwigyeom Kim, Jooyoung LeeCRYPTO 2025
- Side-Channel Masking with Pseudo-Random GeneratorJean-Sébastien Coron, Aurélien Greuet, Rina ZeitounEUROCRYPT 2020 · 29 citations
- Practical State Recovery Attacks against Legacy RNG ImplementationsShaanan N. Cohney, Matthew D. Green, Nadia HeningerCCS 2018 · 21 citations
