Entropy & Random / SP 800-90A DRBG

What you will do: Instantiate HMAC_DRBG from a 32-byte entropy input, a nonce and a personalization string, then press Generate and Reseed while the Internal State Tracker shows the working key K, state value V and reseed_counter. Run the known-answer check to compare the same code with NIST vectors.

Worked example: Instantiate with the default personalization string and generate 32 bytes ten times: reseed_counter reaches 11, above the demo interval of 10, so a Reseed required banner blocks Generate until you press Reseed, which resets it to 1.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Entropy & Randomness

For your role

Developer / Engineer
Set the bytes and optional additional input, Generate several times and Reseed: the state tracker shows what your DRBG wrapper must keep between calls and when reseeding changes the output.
Security Architect
Instantiate HMAC_DRBG with a personalization string, then Generate and Reseed: the Internal State Tracker shows the Key and V vectors ratcheting, which is why a DRBG can be seeded once and reseeded on a schedule.
Researcher / Academic
Run the known-answer check: 16 NIST HMAC_DRBG vectors must match byte for byte and a one-bit flip in one entropy input must not — evidence the SP 800-90A Rev. 1 mechanism is computed correctly, and none about the entropy input.
Certification & Validation Engineer
Run the known-answer check: 16 NIST HMAC_DRBG vectors must match byte for byte and a one-bit flip must not — algorithm evidence for SP 800-90A Rev. 1, and none about the entropy input that seeds it.

SP 800-90A HMAC_DRBG

Explore the internal lifecycle of a Deterministic Random Bit Generator. This is HMAC_DRBG with SHA-256 as specified in SP 800-90A Rev. 1 §10.1.2: the working state is the Key and V values plus a reseed counter, and every step updates them with HMAC-SHA-256.

The steps shown here are the HMAC_DRBG algorithms for Instantiate (§10.1.2.3), Generate (§10.1.2.5) and Reseed (§10.1.2.4).

A DRBG is not an entropy source: its output is only as unpredictable as the entropy input it was seeded with. Here the entropy input comes from the browser’s crypto.getRandomValues() as a stand-in. SP 800-90C expects seed material for a DRBG to come from entropy sources validated against SP 800-90B.

1Instantiate Phase

Entropy Input (32 bytes)
d3b15587da4d91a918350345a40b2e0447860982bdb033911d99aafcd6d5c733
Nonce — auto (16 bytes)
9f4ca14e6f57e128acc9e142cc6e3542

2Generate & Reseed

Instantiate the DRBG first; Generate and Reseed unlock once it has a state.

Internal State Tracker

reseed_counter: 0
Instantiate DRBG to start tracking state
Working Key (K)
0000000000000000000000000000000000000000000000000000000000000000
State Value (V)
0101010101010101010101010101010101010101010101010101010101010101

Known-answer check (NIST HMAC_DRBG vectors)

Runs the same HMAC_DRBG code used above on 16 pinned SHA-256 vectors — 4 from NIST’s ACVP-Server hmacDRBG-1.0 sample set and 12 from the NIST CAVP HMAC_DRBG.rsp files. They cover prediction resistance on and off, reseed, and empty or non-empty personalization strings and additional input. Each output must equal the published answer byte for byte. The check then flips one bit in each input of two vectors — entropy input, nonce, personalization string, additional input, reseed entropy and additional input, and prediction-resistance entropy; every one of those runs must not match.

What a pass shows: this browser code computes the SP 800-90A Rev. 1 HMAC_DRBG mechanism correctly for these inputs. What it does not show: it is not a CAVP/ACVP algorithm validation, it is not an entropy-source test, and it says nothing about the quality of any entropy input.

Next in sequence

Source Combining

See where a DRBG's entropy input comes from: health-test raw source samples, condition them, and state the assumptions a combined construction depends on.

Try it

Instantiate the HMAC_DRBG, Generate twice, then Reseed. What changes in the Internal State Tracker?

Next step

Keep learning: PQC 101

PQC 101 follows Entropy & Randomness, the module this tool practises, in the Foundations track.

Next in Entropy & Random