Entropy & Random / Source Combining
What you will do: Health-test two simulated raw sources, assemble their samples with SP 800-90C concatenation, condition the result, then state the assumptions the combined construction rests on.
Worked example: Load the Stuck source, detected counterexample: the health tests exclude Source A before conditioning, and Source B alone falls short of the 384 bits a 256-bit DRBG needs, so the verdict is Not enough evidence.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
Browse all Crypto Lab tools · Learn with Entropy & Randomness
For your role
- Developer / Engineer
- Set Source A to Biased toward 0x5A: the Adaptive Proportion test catches it on the raw samples in Step 2, while conditioned and expanded output would look fine — so your health tests go before conditioning, and HKDF is not a stand-in for an SP 800-90A DRBG.
- Security Architect
- Step 6 asks what a combined-source design has to state — independence, adversary control, failure handling, validation, freshness and the SP 800-90C construction class — before anyone can claim one weak source does not weaken the key.
- Researcher / Academic
- Collect raw samples, read the startup and continuous health tests in Step 2, then load each counterexample in Step 6: every verdict names the SP 800-90B or SP 800-90C clause it rests on, and the best possible outcome is “consistent with the stated assumptions”, never a validation.
- Certification & Validation Engineer
- Load each counterexample in Step 6: every verdict names the SP 800-90B or SP 800-90C clause it rests on, and the best possible outcome is “consistent with the stated assumptions”, never a validation.
Source Combining Pipeline
Where health tests, conditioning and a combined construction sit — with two simulated raw sources. Hashing, HMAC, CMAC and Hash_df run in SoftHSMv3 v0.4.23 PKCS#11 (pqctoday fork of SoftHSM2).
ML-KEM and ML-DSA key generation consume random seeds. If the entropy behind the RBG is weak or a failed source goes unnoticed, a post-quantum key is as guessable as an RSA or ECDSA one.
Where each check belongs
SP 800-90B §4.3 item 6: “Health tests shall be performed on the noise source samples before any conditioning is done.” This workshop simulates the first five boxes. Its last stage is an HKDF expansion used as a stand-in; it is not an SP 800-90A DRBG, and nothing here is an SP 800-90C construction.
Step 1: Raw noise-source samples (simulated)
Each source produces 1088 raw 8-bit samples: 1024 for the startup test and 64 for this entropy request. A “healthy” source is browser CSPRNG bytes standing in for a physical noise source. Both sources are declared to carry H = 4 bits/sample — an assumption, not a measurement — and that value sets the health-test cutoffs.
Source A condition
Source B condition
Step 6: Is the combined construction justified?
Whether combining sources protects you when one fails depends on assumptions, not on how the output looks. State them — or load a counterexample — and read the outcome. The best possible outcome here is “consistent with the stated assumptions”; nothing in this workshop is a validation.
Counterexamples
Are the sources independent?
Adversary control over Source A
How is a source failure detected and handled?
Are the entropy sources validated (SP 800-90B)?
Freshness of the input
SP 800-90C construction class
What seeds the DRBG?
From the pipeline: 0 bits credited to the 0-bit assembled bitstring; one Hash_df (SHA-256) block (256-bit output) carries at most 0 bits to the DRBG; no failed source’s samples are used.
Collect raw samples in Step 1, or load a counterexample, to see the outcome.
Standards Referenced
- NIST SP 800-90B — health tests on raw samples before conditioning (§4.3), Repetition Count and Adaptive Proportion tests (§4.4), conditioning components (§3.1.5)
- NIST SP 800-90C — entropy counting and independence (§2.3, §2.6), Get_entropy_bitstring and failure handling (§3.1), external conditioning (§3.2), construction classes (Table 1)
- NIST SP 800-90A Rev. 1 — Hash_df derivation function (§10.3.1)
Next in sequence
SP 800-90A DRBG
Seed an HMAC_DRBG and step through Instantiate → Generate → Reseed, then check the code against NIST known-answer vectors.
Try it
Load the "Stuck source, detected" counterexample. Source B is healthy — what is the verdict, and why?
Next step
Keep learning: PQC 101PQC 101 follows Entropy & Randomness, the module this tool practises, in the Foundations track.
Related content
Next in Entropy & Random