ISO/IEC 18031:2011
Information technology — Security techniques — Random bit generation
Information technology — Security techniques — Random bit generation
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 142
- Дата публикации:
- 8 ноября 2011 г.
- Издание:
- ISO/IEC IS 18031 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 18031:2011 specifies a conceptual model for a random bit generator for cryptographic purposes, together with the elements of this model. ISO/IEC 18031:2011 specifies the characteristics of the main elements required for a non-deterministic random bit generator, specifies the characteristics of the main elements required for a deterministic random bit generator, establishes the security requirements for both the non-deterministic and the deterministic random bit generator. Where there is a requirement to produce sequences of random numbers from random bit strings, ISO/IEC 18031:2011 gives guidelines on how this can be performed. Techniques for statistical testing of random bit generators for the purposes of independent verification or validation, and detailed designs for such generators, are outside the scope of ISO/IEC 18031:2011.
Abstract
Overview
ISO/IEC 18031:2011, "Information technology - Security techniques - Random bit generation", defines a conceptual model and security requirements for random bit generators (RBGs) used for cryptographic purposes. The standard covers both non‑deterministic random bit generators (NRBGs) and deterministic random bit generators (DRBGs), describes their main components (entropy sources, internal state, state transition and output generation functions, support and health tests), and gives guidelines for producing random numbers from random bit strings. Detailed statistical test techniques and full generator designs are explicitly out of scope.
Key Topics and Requirements
- RBG conceptual model: functional components and interactions required for secure random bit generation.
- Entropy sources: characteristics and roles of primary, physical and non‑physical entropy inputs; hybrid architectures.
- Internal state & transitions: requirements for maintaining and updating internal state securely.
- Output generation: requirements for deterministic and non‑deterministic output functions that produce cryptographic-quality bits.
- Additional inputs and support functions: use of personalization strings, reseeding, and auxiliary inputs to strengthen security.
- Health tests: continuous and startup checks for entropy sources and deterministic components to detect failures or degradation.
- Annexes and examples: normative guidance on combining RBGs, conversion methods for random numbers, and example DRBG mechanisms including Hash_DRBG, HMAC_DRBG, CTR_DRBG, Dual_EC_DRBG, MS_DRBG and others.
Practical Applications
ISO/IEC 18031 is essential for anyone designing, evaluating, or deploying cryptographic systems that require trustworthy randomness:
- Security architects & crypto engineers: design secure key generation, nonces, IVs, session keys and digital signature randomness.
- Hardware RNG designers: specify entropy source requirements and health monitoring for physical random generators.
- Software developers: build or select DRBG implementations that meet cryptographic requirements for applications (TLS, VPNs, PKI, secure tokens, IoT).
- Auditors and evaluators: assess RBG designs and operational practices against recognized security criteria. Using ISO/IEC 18031 helps reduce risks from poor randomness, such as predictable keys or repeated nonces that can compromise confidentiality and integrity.
Related Standards
ISO/IEC 18031 is typically used alongside other cryptographic and validation frameworks. Implementers often reference guidance from national standards bodies (for example, NIST DRBG recommendations and FIPS guidance) and other ISO/IEC security standards when selecting or certifying RBG implementations.
Keywords: ISO/IEC 18031, random bit generator, cryptographic RNG, entropy source, NRBG, DRBG, random number generation standard, security techniques.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 18031:2011
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 18031:2025
ДействующийInformation technology — Security techniques — Random bit generation
Overview ISO/IEC 18031:2025 - "Information technology - Security techniques - Random bit generation" defines a conceptual model and security requirements for random bit generators (RBGs) used for cry…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…