Exact Bias of Linear TRNG Correctors -- Spectral Approach

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Skorski, Maciej, Soto, Francisco-Javier, Günlü, Onur
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913151493079040
author Skorski, Maciej
Soto, Francisco-Javier
Günlü, Onur
author_facet Skorski, Maciej
Soto, Francisco-Javier
Günlü, Onur
contents Using Fourier analysis, this paper establishes near-optimal security bounds for linear correctors commonly used in True Random Number Generators (TRNGs), expressed through code weight enumerators and input bias parameters. We provide the first near-tight bias characterization in total variation, by interpolating between optimal $\ell_\infty$ and $\ell_2$ norm results. Our bounds improve security assessments by an order of magnitude over previously known (overly conservative) estimates. Across $\sim $20,000 codes, we examine fundamental trade-offs between compression efficiency, cryptographic security, and hardware complexity. Achieving 80-bit security with 10\% input bias typically requires sacrificing more than 50\% of the code rate and incurs increased hardware cost. This quantifies the inherent cost of randomness extraction in hardware TRNG implementations.
format Preprint
id arxiv_https___arxiv_org_abs_2509_26393
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Exact Bias of Linear TRNG Correctors -- Spectral Approach
Skorski, Maciej
Soto, Francisco-Javier
Günlü, Onur
Cryptography and Security
Information Theory
94A60, 94B05, 42B05, 60G50
E.3; G.2.1; B.2.4
Using Fourier analysis, this paper establishes near-optimal security bounds for linear correctors commonly used in True Random Number Generators (TRNGs), expressed through code weight enumerators and input bias parameters. We provide the first near-tight bias characterization in total variation, by interpolating between optimal $\ell_\infty$ and $\ell_2$ norm results. Our bounds improve security assessments by an order of magnitude over previously known (overly conservative) estimates. Across $\sim $20,000 codes, we examine fundamental trade-offs between compression efficiency, cryptographic security, and hardware complexity. Achieving 80-bit security with 10\% input bias typically requires sacrificing more than 50\% of the code rate and incurs increased hardware cost. This quantifies the inherent cost of randomness extraction in hardware TRNG implementations.
title Exact Bias of Linear TRNG Correctors -- Spectral Approach
topic Cryptography and Security
Information Theory
94A60, 94B05, 42B05, 60G50
E.3; G.2.1; B.2.4
url https://arxiv.org/abs/2509.26393