Entropy & Random / Source Combining

What you will do: Health-test two simulated raw sources, assemble their samples with SP 800-90C concatenation, condition the result, then state the assumptions the combined construction rests on.

Worked example: Load the Stuck source, detected counterexample: the health tests exclude Source A before conditioning, and Source B alone falls short of the 384 bits a 256-bit DRBG needs, so the verdict is Not enough evidence.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Entropy & Randomness

For your role

Developer / Engineer
Set Source A to Biased toward 0x5A: the Adaptive Proportion test catches it on the raw samples in Step 2, while conditioned and expanded output would look fine — so your health tests go before conditioning, and HKDF is not a stand-in for an SP 800-90A DRBG.
Security Architect
Step 6 asks what a combined-source design has to state — independence, adversary control, failure handling, validation, freshness and the SP 800-90C construction class — before anyone can claim one weak source does not weaken the key.
Researcher / Academic
Collect raw samples, read the startup and continuous health tests in Step 2, then load each counterexample in Step 6: every verdict names the SP 800-90B or SP 800-90C clause it rests on, and the best possible outcome is “consistent with the stated assumptions”, never a validation.
Certification & Validation Engineer
Load each counterexample in Step 6: every verdict names the SP 800-90B or SP 800-90C clause it rests on, and the best possible outcome is “consistent with the stated assumptions”, never a validation.

Source Combining Pipeline

Where health tests, conditioning and a combined construction sit — with two simulated raw sources. Hashing, HMAC, CMAC and Hash_df run in SoftHSMv3 v0.4.23 PKCS#11 (pqctoday fork of SoftHSM2).

ML-KEM and ML-DSA key generation consume random seeds. If the entropy behind the RBG is weak or a failed source goes unnoticed, a post-quantum key is as guessable as an RSA or ECDSA one.

Where each check belongs

Noise sourceRaw samplesHealth tests (SP 800-90B §4.4)Conditioning (optional)Entropy-source outputSP 800-90C construction + DRBGConsumer

SP 800-90B §4.3 item 6: “Health tests shall be performed on the noise source samples before any conditioning is done.” This workshop simulates the first five boxes. Its last stage is an HKDF expansion used as a stand-in; it is not an SP 800-90A DRBG, and nothing here is an SP 800-90C construction.

Step 1: Raw noise-source samples (simulated)

Each source produces 1088 raw 8-bit samples: 1024 for the startup test and 64 for this entropy request. A “healthy” source is browser CSPRNG bytes standing in for a physical noise source. Both sources are declared to carry H = 4 bits/sample — an assumption, not a measurement — and that value sets the health-test cutoffs.

Source A condition

Source A:

Source B condition

Source B:

Step 6: Is the combined construction justified?

Whether combining sources protects you when one fails depends on assumptions, not on how the output looks. State them — or load a counterexample — and read the outcome. The best possible outcome here is “consistent with the stated assumptions”; nothing in this workshop is a validation.

Counterexamples

Are the sources independent?

Adversary control over Source A

How is a source failure detected and handled?

Are the entropy sources validated (SP 800-90B)?

Freshness of the input

SP 800-90C construction class

What seeds the DRBG?

From the pipeline: 0 bits credited to the 0-bit assembled bitstring; one Hash_df (SHA-256) block (256-bit output) carries at most 0 bits to the DRBG; no failed source’s samples are used.

Collect raw samples in Step 1, or load a counterexample, to see the outcome.

Standards Referenced

  • NIST SP 800-90B — health tests on raw samples before conditioning (§4.3), Repetition Count and Adaptive Proportion tests (§4.4), conditioning components (§3.1.5)
  • NIST SP 800-90C — entropy counting and independence (§2.3, §2.6), Get_entropy_bitstring and failure handling (§3.1), external conditioning (§3.2), construction classes (Table 1)
  • NIST SP 800-90A Rev. 1 — Hash_df derivation function (§10.3.1)

Next in sequence

SP 800-90A DRBG

Seed an HMAC_DRBG and step through Instantiate → Generate → Reseed, then check the code against NIST known-answer vectors.

Try it

Load the "Stuck source, detected" counterexample. Source B is healthy — what is the verdict, and why?

Next step

Keep learning: PQC 101

PQC 101 follows Entropy & Randomness, the module this tool practises, in the Foundations track.

Next in Entropy & Random