Entropy & Random / Entropy Testing

What you will do: Load a 64-byte sample (Generate Random, All Zeros, Repeating Pattern, Incrementing, or Paste Hex), press Run the checks, and read each group separately: visual checks, health tests, estimators (not run here) and primitive self-checks.

Worked example: Load Repeating Pattern (deadbeef repeated over 64 bytes) and run: the visual checks flag the pattern, and each result shows its value, its cutoff and the limit of a 64-byte sample.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Entropy & Randomness

For your role

Developer / Engineer
Paste Hex from your own generator's output and run the static tests to see the grouped results; Run reference samples under Primitive self-checks compares SHA-256 and HMAC with public NIST ACVP-Server reference samples — algorithm correctness only, not an entropy test.
Security Architect
Use the Bit Flipper and the Live Monitor to see which corruption the checks notice and which they miss; the point for a design is that ML-KEM and ML-DSA key generation depends on entropy these output checks cannot measure.
Researcher / Academic
Load Generate Random, then All Zeros, Repeating Pattern and Incrementing under Static Tests: the grouped results show which visual check and which SP 800-90B health test each bad sample trips — Incrementing trips no health test at all — and the page says an entropy estimate needs the NIST SP 800-90B EntropyAssessment tool on raw data.
Certification & Validation Engineer
Run the Static Tests and read the grouped results: the two SP 800-90B health tests are reported apart from the visual checks, and the page points to the NIST SP 800-90B EntropyAssessment tool for the estimate an entropy-source validation needs.

Entropy Testing Dashboard

Load a data sample and run the checks. Results appear in four separate groups: visual checks, SP 800-90B health tests, SP 800-90B entropy estimators (not run here) and primitive self-checks. None of them, alone or added up, tells you whether a source is unpredictable.

Data Source

These are simplified educational implementations. An SP 800-90B entropy assessment uses the NIST SP 800-90B EntropyAssessment tool (github.com/usnistgov/SP800-90B_EntropyAssessment) on at least 1,000,000 raw noise-source samples plus restart data (SP 800-90B §3.1.1).

Related Products

Hardware entropy sources and HSMs that provide NIST-validated entropy for production use are tracked in the Migrate catalog → Hardware Security Modules. No standalone entropy-source products are currently cataloged; contributions welcome via the issue tracker.

Primitive self-checks (SHA-256, HMAC) — not entropy or RBG tests

FIPS 180-4 · FIPS 198-1 — algorithm correctness only

Click Run reference samples to run 4 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity..

Reference samples from the public NIST ACVP-Server repository · FIPS 180-4 · FIPS 198-1 — algorithm correctness only · Generated keys are for educational use only.

Next in sequence

Source Combining

Health-test raw source samples before conditioning, and see why random-looking conditioned output is not evidence about the source.

Try it

Load Repeating Pattern and run the checks. Which SP 800-90B health test signals a failure, and why?

Next step

Keep learning: PQC 101

PQC 101 follows Entropy & Randomness, the module this tool practises, in the Foundations track.

Next in Entropy & Random