Struct rand_hc::Hc128Rng

source ·
pub struct Hc128Rng(_);
Expand description

A cryptographically secure random number generator that uses the HC-128 algorithm.

HC-128 is a stream cipher designed by Hongjun Wu1, that we use as an RNG. It is selected as one of the “stream ciphers suitable for widespread adoption” by eSTREAM2.

HC-128 is an array based RNG. In this it is similar to RC-4 and ISAAC before it, but those have never been proven cryptographically secure (or have even been significantly compromised, as in the case of RC-43).

Because HC-128 works with simple indexing into a large array and with a few operations that parallelize well, it has very good performance. The size of the array it needs, 4kb, can however be a disadvantage.

This implementation is not based on the version of HC-128 submitted to the eSTREAM contest, but on a later version by the author with a few small improvements from December 15, 20094.

HC-128 has no known weaknesses that are easier to exploit than doing a brute-force search of 2128. A very comprehensive analysis of the current state of known attacks / weaknesses of HC-128 is given in Some Results On Analysis And Implementation Of HC-128 Stream Cipher5.

The average cycle length is expected to be 21024*32+10-1 = 232777. We support seeding with a 256-bit array, which matches the 128-bit key concatenated with a 128-bit IV from the stream cipher.

This implementation uses an output buffer of sixteen u32 words, and uses BlockRng to implement the RngCore methods.

References


  1. Hongjun Wu (2008). “The Stream Cipher HC-128”. The eSTREAM Finalists, LNCS 4986, pp. 39–47, Springer-Verlag. 

  2. eSTREAM: the ECRYPT Stream Cipher Project 

  3. Internet Engineering Task Force (February 2015), “Prohibiting RC4 Cipher Suites”

  4. Hongjun Wu, Stream Ciphers HC-128 and HC-256 

  5. Shashwat Raizada (January 2015),“Some Results On Analysis And Implementation Of HC-128 Stream Cipher”

Trait Implementations

Returns a copy of the value. Read more
Performs copy-assignment from source. Read more
Formats the value using the given formatter. Read more
Return the next random u32. Read more
Return the next random u64. Read more
Fill dest with random data. Read more
Fill dest entirely with random data. Read more
Seed type, which is restricted to types mutably-dereferencable as u8 arrays (we recommend [u8; N] for some N). Read more
Create a new PRNG using the given seed. Read more
Create a new PRNG seeded from another Rng. Read more
Create a new PRNG using a u64 seed. Read more

Auto Trait Implementations

Blanket Implementations

Gets the TypeId of self. Read more
Immutably borrows from an owned value. Read more
Mutably borrows from an owned value. Read more

Returns the argument unchanged.

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

The type returned in the event of a conversion error.
Performs the conversion.
The type returned in the event of a conversion error.
Performs the conversion.