|
Botan 3.13.0
Crypto and TLS for C&
|
#include <auto_rng.h>
Public Member Functions | |
| bool | accepts_input () const override |
| void | add_entropy (const uint8_t input[], size_t length) |
| void | add_entropy (std::span< const uint8_t > input) |
| template<typename T> | |
| void | add_entropy_T (const T &t) |
| AutoSeeded_RNG (AutoSeeded_RNG &&other) noexcept | |
| AutoSeeded_RNG (const AutoSeeded_RNG &other)=delete | |
| BOTAN_FUTURE_EXPLICIT | AutoSeeded_RNG (Entropy_Sources &entropy_sources, size_t reseed_interval=RandomNumberGenerator::DefaultReseedInterval) |
| AutoSeeded_RNG (RandomNumberGenerator &underlying_rng, Entropy_Sources &entropy_sources, size_t reseed_interval=RandomNumberGenerator::DefaultReseedInterval) | |
| BOTAN_FUTURE_EXPLICIT | AutoSeeded_RNG (RandomNumberGenerator &underlying_rng, size_t reseed_interval=RandomNumberGenerator::DefaultReseedInterval) |
| BOTAN_FUTURE_EXPLICIT | AutoSeeded_RNG (size_t reseed_interval=RandomNumberGenerator::DefaultReseedInterval) |
| void | clear () override |
| void | force_reseed () |
| bool | is_seeded () const override |
| std::string | name () const override |
| uint8_t | next_byte () |
| uint8_t | next_nonzero_byte () |
| AutoSeeded_RNG & | operator= (AutoSeeded_RNG &&other)=delete |
| AutoSeeded_RNG & | operator= (const AutoSeeded_RNG &other)=delete |
| template<size_t bytes> | |
| std::array< uint8_t, bytes > | random_array () |
| template<concepts::resizable_byte_buffer T = secure_vector<uint8_t>> | |
| T | random_vec (size_t bytes) |
| void | random_vec (std::span< uint8_t > v) |
| template<concepts::resizable_byte_buffer T> | |
| void | random_vec (T &v, size_t bytes) |
| void | randomize (std::span< uint8_t > output) |
| void | randomize (uint8_t output[], size_t length) |
| void | randomize_with_input (std::span< uint8_t > output, std::span< const uint8_t > input) |
| void | randomize_with_input (uint8_t output[], size_t output_len, const uint8_t input[], size_t input_len) |
| void | randomize_with_ts_input (std::span< uint8_t > output) |
| void | randomize_with_ts_input (uint8_t output[], size_t output_len) |
| size_t | reseed (Entropy_Sources &srcs, size_t poll_bits=RandomNumberGenerator::DefaultPollBits, std::chrono::milliseconds=DefaultPollTimeout) |
| size_t | reseed_from (Entropy_Sources &srcs, size_t poll_bits=RandomNumberGenerator::DefaultPollBits) |
| void | reseed_from (RandomNumberGenerator &rng, size_t poll_bits=RandomNumberGenerator::DefaultPollBits) |
| virtual void | reseed_from_rng (RandomNumberGenerator &rng, size_t poll_bits=RandomNumberGenerator::DefaultPollBits) |
| size_t | reseed_from_sources (Entropy_Sources &srcs, size_t poll_bits=RandomNumberGenerator::DefaultPollBits) override |
| ~AutoSeeded_RNG () override | |
Static Public Attributes | |
| static constexpr size_t | DefaultPollBits = 256 |
| static constexpr auto | DefaultPollTimeout = std::chrono::milliseconds(50) |
| static constexpr size_t | DefaultReseedInterval = 1024 |
A userspace PRNG
Definition at line 21 of file auto_rng.h.
| Botan::AutoSeeded_RNG::AutoSeeded_RNG | ( | size_t | reseed_interval = RandomNumberGenerator::DefaultReseedInterval | ) |
Uses the system RNG (if available) or else a default group of entropy sources (all other systems) to gather seed material.
| reseed_interval | specifies a limit of how many times the RNG will be called before automatic reseeding is performed |
Definition at line 68 of file auto_rng.cpp.
References BOTAN_UNUSED, force_reseed(), Botan::Entropy_Sources::global_sources(), and Botan::system_rng().
Referenced by AutoSeeded_RNG(), AutoSeeded_RNG(), operator=(), and operator=().
| Botan::AutoSeeded_RNG::AutoSeeded_RNG | ( | RandomNumberGenerator & | underlying_rng, |
| size_t | reseed_interval = RandomNumberGenerator::DefaultReseedInterval ) |
Create an AutoSeeded_RNG which will get seed material from some other RNG instance. For example you could provide a reference to the system RNG or a hardware RNG.
| underlying_rng | is a reference to some RNG which will be used to perform the periodic reseeding |
| reseed_interval | specifies a limit of how many times the RNG will be called before automatic reseeding is performed |
Definition at line 48 of file auto_rng.cpp.
References force_reseed(), and Botan::RandomNumberGenerator::RandomNumberGenerator().
| Botan::AutoSeeded_RNG::AutoSeeded_RNG | ( | Entropy_Sources & | entropy_sources, |
| size_t | reseed_interval = RandomNumberGenerator::DefaultReseedInterval ) |
Create an AutoSeeded_RNG which will get seed material from a set of entropy sources.
| entropy_sources | will be polled to perform reseeding periodically |
| reseed_interval | specifies a limit of how many times the RNG will be called before automatic reseeding is performed |
Definition at line 54 of file auto_rng.cpp.
References force_reseed().
| Botan::AutoSeeded_RNG::AutoSeeded_RNG | ( | RandomNumberGenerator & | underlying_rng, |
| Entropy_Sources & | entropy_sources, | ||
| size_t | reseed_interval = RandomNumberGenerator::DefaultReseedInterval ) |
Create an AutoSeeded_RNG which will get seed material from both an underlying RNG and a set of entropy sources.
| underlying_rng | is a reference to some RNG which will be used to perform the periodic reseeding |
| entropy_sources | will be polled to perform reseeding periodically |
| reseed_interval | specifies a limit of how many times the RNG will be called before automatic reseeding is performed |
Definition at line 60 of file auto_rng.cpp.
References force_reseed(), and Botan::RandomNumberGenerator::RandomNumberGenerator().
|
delete |
References AutoSeeded_RNG().
|
defaultnoexcept |
Move constructor
References AutoSeeded_RNG().
|
overridedefault |
|
inlineoverridevirtual |
Test whether this RNG accepts externally provided input
Implements Botan::RandomNumberGenerator.
Definition at line 33 of file auto_rng.h.
|
inlineinherited |
Incorporate some additional data into the RNG state
| input | a byte array containing the entropy to be added |
| length | the number of bytes in input |
Definition at line 121 of file rng.h.
References add_entropy().
Referenced by add_entropy().
|
inlineinherited |
Incorporate some additional data into the RNG state. For example adding nonces or timestamps from a peer's protocol message can help hedge against VM state rollback attacks. A few RNG types do not accept any externally provided input, in which case this function is a no-op.
| input | a byte array containing the entropy to be added |
Definition at line 114 of file rng.h.
References fill_bytes_with_input().
Referenced by add_entropy_T(), Botan::ChaCha_RNG::ChaCha_RNG(), Botan::Stateful_RNG::initialize_with(), Botan::Getentropy::poll(), Botan::Intel_Rdseed::poll(), and reseed_from_rng().
|
inlineinherited |
Incorporate some additional data into the RNG state.
Definition at line 128 of file rng.h.
References add_entropy().
Referenced by Botan::Win32_EntropySource::poll().
|
overridevirtual |
Clear all internally held values of this RNG
Implements Botan::RandomNumberGenerator.
Definition at line 94 of file auto_rng.cpp.
| void Botan::AutoSeeded_RNG::force_reseed | ( | ) |
Mark state as requiring a reseed on next use
Definition at line 81 of file auto_rng.cpp.
Referenced by AutoSeeded_RNG(), AutoSeeded_RNG(), AutoSeeded_RNG(), and AutoSeeded_RNG().
|
overridevirtual |
Test whether this RNG has been seeded
Implements Botan::RandomNumberGenerator.
Definition at line 90 of file auto_rng.cpp.
|
overridevirtual |
Return the name of this RNG type
Implements Botan::RandomNumberGenerator.
Definition at line 98 of file auto_rng.cpp.
|
inlineinherited |
Return a random byte
| PRNG_Unseeded | if the RNG fails because it has not enough entropy |
| Exception | if the RNG fails |
Definition at line 292 of file rng.h.
References fill_bytes_with_input().
Referenced by next_nonzero_byte(), and Botan::random_prime().
|
inlineinherited |
Generate a single random byte which is not zero
| PRNG_Unseeded | if the RNG fails because it has not enough entropy |
| Exception | if the RNG fails |
Definition at line 304 of file rng.h.
References next_byte().
|
delete |
References AutoSeeded_RNG().
|
delete |
References AutoSeeded_RNG().
|
inlineinherited |
Create a std::array of bytes random bytes
Definition at line 280 of file rng.h.
References random_vec().
|
inlineinherited |
Create some byte container type and fill it with some random bytes.
| T | the desired byte container type (e.g std::vector<uint8_t>) |
| bytes | number of random bytes to initialize the container with |
bytes random bytes Definition at line 270 of file rng.h.
References random_vec().
|
inlineinherited |
Fill a given byte container with bytes random bytes
| v | the container to be filled with bytes random bytes |
Definition at line 244 of file rng.h.
References randomize().
Referenced by Botan::Classic_McEliece_PrivateKey::Classic_McEliece_PrivateKey(), Botan::TLS::Client_Key_Exchange::Client_Key_Exchange(), Botan::TLS::Client_Key_Exchange::Client_Key_Exchange(), Botan::PK_Decryptor::decrypt_or_random(), Botan::Dilithium_PrivateKey::Dilithium_PrivateKey(), Botan::Ed25519_PrivateKey::Ed25519_PrivateKey(), Botan::Kyber_KEM_Encryptor::encapsulate(), Botan::ML_KEM_Encryptor::encapsulate(), Botan::TLS::Session::encrypt(), Botan::KeyPair::encryption_consistency_check(), Botan::FrodoKEM_PrivateKey::FrodoKEM_PrivateKey(), Botan::generate_bcrypt(), Botan::Kyber_PrivateKey::Kyber_PrivateKey(), Botan::TLS::make_hello_random(), Botan::OctetString::OctetString(), random_array(), random_vec(), random_vec(), Botan::BigInt::randomize(), reseed_from_rng(), Botan::SphincsPlus_PrivateKey::SphincsPlus_PrivateKey(), Botan::X25519_PrivateKey::X25519_PrivateKey(), and Botan::XMSS_PublicKey::XMSS_PublicKey().
|
inlineinherited |
Resize a given byte container to bytes and fill it with random bytes
| T | the desired byte container type (e.g std::vector<uint8_t>) |
| v | the container to be filled with bytes random bytes |
| bytes | number of random bytes to initialize the container with |
Definition at line 255 of file rng.h.
References random_vec().
|
inlineinherited |
Randomize a byte array.
May block shortly if e.g. the RNG is not yet initialized or a retry because of insufficient entropy is needed.
| output | the byte array to hold the random output. |
| PRNG_Unseeded | if the RNG fails because it has not enough entropy |
| Exception | if the RNG fails |
Definition at line 86 of file rng.h.
References fill_bytes_with_input().
Referenced by Botan::TLS::Connection_Cipher_State::aead_nonce(), Botan::argon2_generate_pwhash(), Botan::BlindedScalarBits< C, WindowBits+1 >::BlindedScalarBits(), botan_system_rng_get(), Botan::CryptoBox::encrypt(), Botan::PKCS12::export_to(), Botan::generate_dsa_primes(), Botan::generate_passhash9(), Botan::pkcs12_pbe_encrypt(), Botan::IntMod< MontgomeryRep< ScalarParams > >::random(), Botan::X509_Serial_Number::random(), Botan::random_gf2m(), Botan::McEliece_PublicKeyInternal::random_plaintext_element(), Botan::random_prime(), random_vec(), Botan::Sodium::randombytes_buf(), randomize_with_ts_input(), Botan::KeyPair::signature_consistency_check(), Botan::RTSS_Share::split(), and Botan::UUID::UUID().
|
inlineinherited |
Randomize a byte array
| output | the byte array to hold the random output |
| length | the number of bytes to generate |
Definition at line 93 of file rng.h.
References randomize().
Referenced by randomize().
|
inlineinherited |
Incorporate entropy into the RNG state then produce output. Some RNG types implement this using a single operation, default calls add_entropy + randomize in sequence.
Use this to further bind the outputs to your current process/protocol state. For instance if generating a new key for use in a session, include a session ID or other such value. See NIST SP 800-90 A, B, C series for more ideas.
| output | buffer to hold the random output |
| input | entropy buffer to incorporate |
| PRNG_Unseeded | if the RNG fails because it has not enough entropy |
| Exception | if the RNG fails |
| Exception | may throw if the RNG accepts input, but adding the entropy failed. |
Definition at line 148 of file rng.h.
References fill_bytes_with_input().
Referenced by Botan::System_RNG::fill_bytes_with_input(), and randomize_with_input().
|
inlineinherited |
Randomize a byte array, first incorporating additional input
| output | the byte array to hold the random output |
| output_len | the number of bytes to generate |
| input | a byte array containing the entropy to be added |
| input_len | the number of bytes in input |
Definition at line 159 of file rng.h.
References randomize_with_input().
|
inherited |
This calls randomize_with_input using system specific values
This first attempts to provide input to the underlying RNG from some system specific source. If a system RNG is available, it is queried and the output from the system RNG is used as the additional input. Otherwise 12 bytes consisting of the local clock plus the current process ID are used.
For a stateful RNG that was already correctly seeded with sufficient cryptographically secure material, using non-random but potentially unique data as the extra input can help protect against problems with fork, VM state rollback, or other cases where somehow an RNG state is duplicated. If both of the duplicated RNG states later incorporate some input, even predictable input, their outputs will diverge.
| output | buffer to hold the random output |
| PRNG_Unseeded | if the RNG fails because it has not enough entropy |
| Exception | if the RNG fails |
| Exception | may throw if the RNG accepts input, but adding the entropy failed. |
Definition at line 26 of file rng.cpp.
References accepts_input(), fill_bytes_with_input(), Botan::OS::get_high_resolution_clock(), Botan::OS::get_process_id(), randomize(), Botan::store_le(), and Botan::system_rng().
Referenced by randomize_with_ts_input().
|
inlineinherited |
Randomize a byte array, using timestamps as additional input
| output | the byte array to hold the random output |
| output_len | the number of bytes to generate |
Definition at line 190 of file rng.h.
References randomize_with_ts_input().
|
inlineinherited |
Poll provided sources for up to poll_bits bits of entropy. Returns estimate of the number of bits collected.
Sets the seeded state to true if enough entropy was added.
TODO(Botan4) remove this function
Definition at line 337 of file rng.h.
References DefaultPollBits, DefaultPollTimeout, RandomNumberGenerator(), reseed(), and reseed_from().
Referenced by reseed().
|
inlineinherited |
Poll provided sources for up to poll_bits bits of entropy. Returns estimate of the number of bits collected. Sets the seeded state to true if enough entropy was added.
Definition at line 219 of file rng.h.
References DefaultPollBits, and reseed_from_sources().
Referenced by reseed().
|
inlineinherited |
Reseed by reading specified bits from the RNG
Sets the seeded state to true if enough entropy was added.
Definition at line 230 of file rng.h.
References DefaultPollBits, RandomNumberGenerator(), and reseed_from_rng().
|
virtualinherited |
Reseed by reading specified bits from the RNG
Sets the seeded state to true if enough entropy was added.
Reimplemented in Botan::Stateful_RNG.
Definition at line 65 of file rng.cpp.
References accepts_input(), add_entropy(), random_vec(), and RandomNumberGenerator().
Referenced by reseed_from(), and Botan::Stateful_RNG::reseed_from_rng().
|
overridevirtual |
Poll the provided sources for entropy and reseed from them
| srcs | the entropy sources to poll |
| poll_bits | the number of bits to collect |
Reimplemented from Botan::RandomNumberGenerator.
Definition at line 102 of file auto_rng.cpp.
|
staticconstexprinherited |
Number of entropy bits polled for reseeding userspace RNGs like HMAC_DRBG
Definition at line 50 of file rng.h.
Referenced by reseed(), reseed_from(), and reseed_from().
|
staticconstexprinherited |
|
staticconstexprinherited |