Cryptographic Hardware and Embedded Systems – CHES 2008

Volume 5154 of the series Lecture Notes in Computer Science pp 146-163

A Design for a Physical RNG with Robust Entropy Estimators

  • Wolfgang KillmannAffiliated withT-Systems ISS GmbH
  • , Werner SchindlerAffiliated withBundesamt für Sicherheit in der Informationstechnik (BSI)


We briefly address general aspects that reliable security evaluations of physical RNGs should consider. Then we discuss an efficient RNG design that is based on a pair of noisy diodes. The main contribution of this paper is the formulation and the analysis of the corresponding stochastic model which interestingly also fits to other RNG designs. We prove a theorem that provides tight lower bounds for the entropy per random bit, and we apply our results to a prototype of a particular physical RNG.


Physical RNG stochastic model entropy