6 ms·
Just out of layman's curiosity, what would be the problem or difficulty of somehow connecting a more compact type of radio telescope that detects some level of
by shadowprofile77 6y ago
Just out of layman's curiosity, what would be the problem or difficulty of somehow connecting a more compact type of radio telescope that detects some level of cosmic background radiation and hooking that up to a computer. Would this not be a guaranteed way of generating truly random numbers for any need flawlessly?
I know that serious radio telescopes cost way more than any random person could afford to pay but I've certainly seen plans for smaller DIY homemade models.
- stingraycharles 6y agoYou’re not too far off. There’s for example the Quantis random number generator, which uses photons: https://www.idquantique.com/random-number-generation/products/quantis-random-number-generator/ https://www.idquantique.com/random-number-generation/product... From the brochure: “ Photons - light particles - are sent one by one onto a semi-transparent mirror and detected. The exclusive events (reflection - transmission) are associated to « 0 » - « 1 » bit values.”
- mceachen 6y agoAny stochastic data source may not (and almost certainly isn't) evenly distributed--it'll probably follow some normal distribution. Your PRNG that reads from your telescope would need to compensate for this. As far as using radiation to generate random numbers, check out https://www.fourmilab.ch/hotbits/ https://www.fourmilab.ch/hotbits/
- shadowprofile77 6y agoYour claim makes me a bit skeptical unless im misunderstanding something here... I'd assume that a data source of pure natural radiation would be genuinely random even if its distribution isn't even, and that using anything in your computer to compensate for it would actually do the opposite: reduce randomness with damaging bias. It reminds me of a story from Cryptonomicon in which a character mentions a secretary grabbing randomly spun number balls from a tumbling device while blindfolded (if I remember the objects right) and not liking the results when she had to write them down because they didn't look random enough to her, so she starts peeking and slightly "correcting", and thus ruins a number of one-time pads
- dfox 6y agoThe signal coming from typical radiation detector is analog pulse train which you have to somehow convert into useful binary data. Simply sampling this analog value at some regular interval will create samples that are hugely biased to small number of values (and distribution between these values has more to do with measurement uncertainty than with the supposedly random phenomena you are trying to measure) so you need some kind of processing step to get useful random numbers. Typical radiation based TRNG works by comparing the analog value from the sensor against some kind of threshold (usually in analog hardware) and producing stream of digital samples from that which is then either directly passed through von Neumann whitening algorithm or converted into stream of pulse times from which only few low-order bits are taken and whitened (in fact, the end result is mostly same as whitening the bit stream directly, but timing the pulse lengths is slightly more efficient). One can argue that "quantum TRNG" based on semi-transparent mirror produces unbiased output, but that is not true in practice because of manufacturing (the mirror will not be perfectly semi-transaparent) and implementation (producing and measuring single photons is hard) constraints. The point is that you are going to do some kind of whitening anyway and you then have essentially three choices: 1) design something which requires only von Neuman-style whitening where there still are arbitrary parameter choices hidden in the hardware 2) Design some non-trivial, but still simple entropy-extraction/whitening algorithm (ie. take 16b sample and discard top 10 and bottom one bit). 3) just take the measurement results and pass it through some kind of CSPRNG or sponge function. Third variant is what makes most sense for most applications because mostly you either don't care about the randomness that much or you want to use it for cryptographic purposes. And if you want to do cryptography then philosophical arguments about the cryptography-based whitening not being "truly random" do not make sense, because your application itself is based on belief that the crypto primitives used are "random enough".
- rmrfstar 6y agoFacts I looked up to understand this comment: * Bias in a bit-stream means any deviation from IID Bernoulli trials with p=0.5 * Von Neumann whitening addresses the IID Bernoulli case for p!=0.5 by looking at bit pairs. It takes the first bit when they differ, and no bits when they match. This works because (1,0) and (0,1) both occur with equal probability p(1-p). * NIST wrote a remarkably accessible document [1] [1] https://csrc.nist.gov/csrc/media/publications/sp/800-90b/draft/documents/draft-sp800-90b.pdf https://csrc.nist.gov/csrc/media/publications/sp/800-90b/dra...
- rini17 6y agoIf the distribution non-evenness result is, say, 1000 bits of entropy in every 1024 bits of RNG output, but we save circuitry and have simple auditable RNG then it's worth it. I'm not going to lose sleep over my RSA key having effectively 4000 bits instead of 4096 when it was generated by maximally simple and transparent process. As compared to complicated crypto whitening that everyone thinks "must have".
- dfox 6y agoThe bias of unwhitened output of almost any TRNG is hugely biased. For almost anything based on detecting some kind of radiation (which at the same time are exactly the kinds of TRNGs that are truly random according to current understanding of physics, not only practically impossible to predict) you are on the order of one bit of entropy per 1024bits of output, not 1000.
- rini17 6y agoThat is an overkill. Measuring time between geiger detector events with 555-like counter is okay with me, it's still simple enough to be fully auditable and the bias is not so tragic.
- Animats 6y agoA small radiation source works well, although the data rate is low.[1] The idea is to count the number of events (beta particles here) per time interval. Do this twice. If count A > count B, output a 1. If count A < count B, output a 0. If count A = count B, skip that result. Von Neumann came up with that trick. Don't use the low-order bit of the count. That has a bias. [1] https://www.fourmilab.ch/hotbits/ https://www.fourmilab.ch/hotbits/
- DanBC 6y agoThe Von Neumann extractor is interesting. > Von Neumann’s originally proposes the following technique for getting an unbiased result from a biased coin : > > If independence of successive tosses is assumed, we can reconstruct a 50-50 chance out of even a badly biased coin by tossing twice. If we get heads-heads or tails-tails, we reject the tosses and try again. If we get heads-tails (or tails-heads), we accept the result as heads (or tails).
- ImaCake 6y agoThat is a fantastic resource. It never occured to me that such a thing would exist, but now that I know it does, I find it hard to think of how it wouldn't - since so much of the internet would rely on these kind of tricks to keep working. Only practical use for me would be to confound markers trying to reproduce my RNG's in statistics assignments.
- CorrectHorseBat 6y agoFor one thing it would not work if the attacker has physical access to your machine.
- DanBC 6y agoThe problems with that approach come from trying to de-skew the data, and then from sampling the data into whatever port you're using. Here's a document from 1997 that looks at some hardware RNGs and how they fail: http://www.robertnz.net/true_rng.html http://www.robertnz.net/true_rng.html