ConceptioArchiveNIST
NISTpublic full text

NIST SP 800-22r1-upd1: A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications

Andrew Rukhin (NIST); Juan Soto (NIST); James Nechvatal (NIST); Miles Smid (NIST); Elaine Barker (NIST); Stefan Leigh (NIST); Mark Levenson (NIST); Mark Vangel (NIST); David Banks (NIST); N. Heckert (NIST); James Dray (NIST); San Vo (NIST); Lawrence Bassham (NIST) · National Institute of Standards and Technology (NIST)
NIST · Standards · License: Public Domain
Open Source ↗
accesscontrolcomputersecurityidentityincidentresponsenistriskmanagement
cybersecurity, computer security, cryptography, access control, incident response, privacy, identity, risk management, NIST

You are viewing this page in an unauthorized frame window. This is a potential security issue, you are being redirected to https://csrc.nist.gov . An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Search CSRC MENU Search Search Projects Publications Expand or Collapse Drafts for Public Comment All Public Drafts Final Pubs FIPS (standards) Special Publications (SP s ) IR (interagency/internal reports) CSWP (cybersecurity white papers) ITL Bulletins Project Descriptions Journal Articles Conference Papers Books Topics Expand or Collapse Security & Privacy Applications Technologies Sectors Laws & Regulations Activities & Products News & Updates Events Glossary About CSRC Expand or Collapse Computer Security Division Cryptographic Technology Software Security Group Hardware Security Group Security Engineering and Risk Management Applied Cybersecurity Division Cybersecurity and Privacy Applications National Cybersecurity Center of Excellence (NCCoE) National Initiative for Cybersecurity Education (NICE) Contact Us Information Technology Laboratory Computer Security Resource Center Publications NIST SP 800-22 Rev. 1 A Statistical Test Suite for Random and Pseudorandom Number Generators for Cryptographic Applications Share to Facebook Share to X Share to LinkedIn Share ia Email Documentation Topics Date Published: April 2010 Supersedes: SP 800-22 Rev. 1 (08/01/2008) Planning Note ( 04/19/2022 ): This publication has been reviewed, and NIST has decided to REVISE it. See the full announcement and Crypto Publication Review Project for more details. Author(s) Andrew Rukhin (NIST) , Juan Soto (NIST) , James Nechvatal (NIST) , Miles Smid (NIST) , Elaine Barker (NIST) , Stefan Leigh (NIST) , Mark Levenson (NIST) , Mark Vangel (NIST) , David Banks (NIST) , N. Heckert (NIST) , James Dray (NIST) , San Vo (NIST) , Lawrence Bassham (NIST) Abstract This paper discusses some aspects of selecting and testing random and pseudorandom number generators. The outputs of such generators may be used in many cryptographic applications, such as the generation of key material. Generators suitable for use in cryptographic applications may need to meet stronger requirements than for other applications. In particular, their outputs must be unpredictable in the absence of knowledge of the inputs. Some criteria for characterizing and selecting appropriate generators are discussed in this document. The subject of statistical testing and its relation to cryptanalysis is also discussed, and some recommended statistical tests are provided. These tests may be useful as a first step in determining whether or not a generator is suitable for a particular cryptographic application. However, no set of statistical tests can absolutely certify a generator as appropriate for usage in a particular application, i.e., statistical testing cannot serve as a substitute for cryptanalysis. The design and cryptanalysis of generators is outside the scope of this paper. This paper discusses some aspects of selecting and testing random and pseudorandom number generators. The outputs of such generators may be used in many cryptographic applications, such as the generation of key material. Generators suitable for use in cryptographic applications may need to meet... See full abstract This paper discusses some aspects of selecting and testing random and pseudorandom number generators. The outputs of such generators may be used in many cryptographic applications, such as the generation of key material. Generators suitable for use in cryptographic applications may need to meet stronger requirements than for other applications. In particular, their outputs must be unpredictable in the absence of knowledge of the inputs. Some criteria for characterizing and selecting appropriate generators are discussed in this document. The subject of statistical testing and its relation to cryptanalysis is also discussed, and some recommended statistical tests are provided. These tests may be useful as a first step in determining whether or not a generator is suitable for a particular cryptographic application. However, no set of statistical tests can absolutely certify a generator as appropriate for usage in a particular application, i.e., statistical testing cannot serve as a substitute for cryptanalysis. The design and cryptanalysis of generators is outside the scope of this paper. Hide full abstract Keywords random number generator ; statistical tests ; P-value ; hypothesis test Control Families Assessment, Authorization and Monitoring ; System and Communications Protection Documentation Publication: https://doi.org/10.6028/NIST.SP.800-22r1a Download URL Supplemental Material: None available Document History: 04/30/10: SP 800-22 Rev. 1 (Final) Topics Security and Privacy random number generation , testing & validation HEADQUARTERS 100 Bureau Drive Gaithersburg, MD 20899 X (link is external) facebook (link is external) linkedin (link is external) instagram (link is external) youtube (link is external) rss govdelivery (link is external) Want updates about CSRC and our publications? Subscribe Contact Us | Our Other Offices Send inquiries to [email protected] Site Privacy Accessibility Privacy Program Copyrights Vulnerability Disclosure No Fear Act Policy FOIA Environmental Policy Scientific Integrity Information Quality Standards Commerce.gov Science.gov USA.gov Vote.gov

Related documents

Record · ID 2982 · SHA-256 f062052c9264890f
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.