Entropy & Random / QRNG Demo

What you will do: Compare a simulated QRNG sample, a CSPRNG sample and a deliberately broken PRNG on the same visual checks and SP 800-90B health tests, shown as separate groups.

Worked example: Run the checks on all three samples: only the weak PRNG stands out, because the simulated QRNG and the CSPRNG are the same kind of output.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Entropy & Randomness

For your role

Researcher / Academic
Generate CSPRNG and Run the Checks on All Three Samples: the visual checks and the SP 800-90B health tests for the Simulated QRNG, the CSPRNG and the Weak PRNG sit side by side in separate groups, and the page states that the Simulated QRNG sample is produced by crypto.getRandomValues, not quantum hardware.
Curious Explorer
Press Run the Checks on All Three Samples and look at which source stands out: only the weak one does. The “quantum” sample here is simulated with ordinary computer randomness, and even a real quantum device could not be told apart from a good computer generator by these checks.

Simulation — no QRNG hardware involved. The “QRNG” sample below is generated on load (and on Try Another Sample) by the browser’s crypto.getRandomValues() — the same classical CSPRNG call the “CSPRNG” panel uses. It stands in for QRNG output so you can see the data flow and the tests; nothing here comes from a quantum device.

This tool compares three samples side by side: a simulated “QRNG” sample, a fresh sample from your browser's CSPRNG (Web Crypto API), and a deliberately broken weak PRNG. The first two are the same kind of output, so any difference in their results is sampling noise. The weak PRNG should visibly fail several tests, which shows what the tests can catch.

What this demo shows

  • Simple statistical tests catch grossly broken output, like the weak PRNG's.
  • Good output from different generators looks the same to these tests.

What it does not show

  • Anything about a real QRNG — no quantum device is involved.
  • How much entropy any source has. SP 800-90B estimates entropy from at least 1,000,000 raw noise-source samples, not from 64 or 128 bytes of final output.
  • That any source is validated or certified.
Sample Size:
Simulated

Simulated QRNG

crypto.getRandomValues() stand-in
a3fadd51 299eb023 07299aca 312cdf72 897d3c71 3567e53b 327dd2eb ec862e2e 1ae202b5 f07fb6aa 138491f5 ea56cadc 1a433074 862524a9 2d09d222 6b8edb9d
00
40
80
C0

CSPRNG (OS Entropy)

Browser Web Crypto API
No data yet — click Generate CSPRNG
Broken

Weak PRNG

Math.random() & 0x0F · high nibble forced to 0
0202000f 050c0f0a 060f0600 04010608 01000200 0009090c 050b030e 0f090a0a 0f0c0a03 02090f07 0c0a0e0b 0c0d0d07 00010807 0909080e 07010107 060e0403
00
40
80
C0

Try it

After Run the Checks on All Three Samples, how do the Simulated QRNG and the CSPRNG compare?

Next step

Keep learning: PQC 101

PQC 101 follows Entropy & Randomness, the module this tool practises, in the Foundations track.

Next in Entropy & Random