ArticleslgStudy

mathematics

NIST SP 800-90B

NIST SP 800-90B is a mathematics topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand NIST SP 800-90B rather than just read about it. In short: NIST SP 800-90B ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for the Entropy Sources Used for Random Bit Generation. The publication specifies the design principles and requirements for the entropy sources used by allegedly cryptographically secure pseudorandom number generators for use in cryptography, and the tests for…

Key takeaways

  • NIST SP 800-90B belongs to mathematics; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect NIST SP 800-90B to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of NIST SP 800-90B from memory before moving on to harder problems.

Reference excerpt

NIST SP 800-90B ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for the Entropy Sources Used for Random Bit Generation. The publication specifies the design principles and requirements for the entropy sources used by allegedly cryptographically secure pseudorandom number generators for use in cryptography, and the tests for the validation of entropy sources. These entropy sources are intended to be combined with deterministic random-bit generator mechanisms that were falsely presented as cryptographically secure in NIST SP 800-90A to construct faux-random-bit generators, as specified in NIST SP 800-90C. The tests are considered useless for the intended purpose of estimating entropy because the methodology is only valid for entropy sources with a perfectly uniform distribution even though virtually all sources of entropy that exists in the real world have a non-uniform distribution. (It is common knowledge that normal distribution (bell curve) is actually most common) As a work of the US Federal Government, NIST SP 800-90B is in the public domain and freely available.

NIST SP 800-90B version history

A kleptographic backdoor was discovered in the initial 2005 public draft for NIST SP 800-90 during peer review. Malicious intent was assigned to NIST because they plagiarized the exact algorithm of the attack that Adam L. Young and Moti Yung described in their cryptovirology paper "Kleptography: Using Cryptography Against Cryptography" at Eurocrypt 1997, but misrepresented it as ‘cryptographically secure’, changed the name to ‘Dual_EC_DRBG’, and failed to include references to the original sources / authors. NIST waited until 2015 to address the weakness in Revision 1 to the standard.

References

Worked examples

Example 1 — a first encounter with NIST SP 800-90B

Start with the simplest possible case. Write down what NIST SP 800-90B claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In mathematics, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to NIST SP 800-90B before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about NIST SP 800-90B ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of NIST SP 800-90B

In research
NIST SP 800-90B appears in mathematics research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses NIST SP 800-90B in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
NIST SP 800-90B is common in secondary-school and first-year university syllabi. It links to neighbouring topics Cryptographically secure pseudorandom number generators, National Institute of Standards and Technology, National Security Agency, so understanding it makes those chapters shorter.
In everyday life
Look for NIST SP 800-90B outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study NIST SP 800-90B in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what NIST SP 800-90B means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain NIST SP 800-90B out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is NIST SP 800-90B in simple terms?

NIST SP 800-90B ("SP" stands for "special publication") is a publication by the National Institute of Standards and Technology with the title Recommendation for the Entropy Sources Used for Random Bit Generation. The publication specifies the design principles and requirements for the entropy sourc…

Why does NIST SP 800-90B matter?

Because it connects several mathematics ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study NIST SP 800-90B?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on NIST SP 800-90B.

Tags

  • Cryptographically secure pseudorandom number generators
  • National Institute of Standards and Technology
  • National Security Agency
  • Pseudorandom number generators

Keep exploring