{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,4,24]],"date-time":"2024-04-24T00:29:18Z","timestamp":1713918558802},"reference-count":35,"publisher":"Oxford University Press (OUP)","issue":"4","license":[{"start":{"date-parts":[[2023,9,20]],"date-time":"2023-09-20T00:00:00Z","timestamp":1695168000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"name":"Defense Industrial Technology Development Program","award":["JCKY2020203C025"],"award-info":[{"award-number":["JCKY2020203C025"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,4,21]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Random numbers are very important for the security of computer system. However, generating qualified random numbers is difficult because we cannot always successfully introduce dedicated random number hardware into computer system. Although most operating systems provide random number generation capabilities, the effective entropy supply is still dependent on the hardware platform including memory and clocks etc. However, obtaining hardware events such as clocks requires system privileges, which is not conducive for entropy estimation at the application layer. In contrast, data related to the sensor hardware can be extracted directly at the application layer. These sensor data contain some randomness and may be used as a noise source. In this way, applications can use these sensors to implement their own proprietary random number generators. Before taking these sensors as the noise source, it is necessary to fully evaluate their entropy supply capability. In this paper, 300 Android smartphones and 30 iOS smartphones are selected as samples and their sensor entropy supply capabilities are comprehensively evaluated. Based on the entropy evaluation results, we give some suggestions on how to generate random numbers using these sensor data. We first design a framework for evaluating the entropy supply capability for smartphone sensors, based on the min-entropy estimation method proposed in NIST SP 800-90B. According to this framework, we simulate stationary and mobile working states for each smartphone, and collect sufficient sensor data as the min-entropy estimation dataset. The min-entropy estimation results show that in the stationary working state, each ACCELEROMETER sensor data collection can obtain at least 1.5 bits of entropy in Android, while each GYROSCOPE sensor data collection can obtain at least 20 bits of entropy in iOS. In the mobile working state, each ACCELEROMETER sensor data collection can obtain at least 1.9 bits of entropy, while each GYROSCOPE sensor data acquisition in iOS system can obtain at least 27 bits of entropy. This means that we can still get a stable entropy output from the sensor even when the smartphone is in stationary working state. Statistical analysis of the data using cross correlation methods suggests it is hard for an attacker to guess or predict the random numbers generated by a smartphone through another smartphone put in the similar external environment.<\/jats:p>","DOI":"10.1093\/comjnl\/bxad081","type":"journal-article","created":{"date-parts":[[2023,9,22]],"date-time":"2023-09-22T16:58:40Z","timestamp":1695401920000},"page":"1550-1563","source":"Crossref","is-referenced-by-count":0,"title":["An Evaluation On The Entropy Supplying Capability Of Smartphone Sensors"],"prefix":"10.1093","volume":"67","author":[{"given":"Dinghua","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Automation, Northwestern Polytechnical University , China Xi\u2019an, 710072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shihao","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Automation, Northwestern Polytechnical University , China Xi\u2019an, 710072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Automation, Northwestern Polytechnical University , China Xi\u2019an, 710072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Quan","family":"Pan","sequence":"additional","affiliation":[{"name":"School of Automation, Northwestern Polytechnical University , China Xi\u2019an, 710072, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2023,9,20]]},"reference":[{"key":"2024042316182348100_ref1","author":"Android keystore system"},{"key":"2024042316182348100_ref2","author":"Keychain services"},{"key":"2024042316182348100_ref3","author":"opsenssl"},{"key":"2024042316182348100_ref4","author":"Windows cryptography api: Next generation (cng)"},{"key":"2024042316182348100_ref5","author":"Kaslr support"},{"key":"2024042316182348100_ref6","article-title":"Overview of grsecurity\/pax security features and their implementations in mainline and linux-hardened"},{"key":"2024042316182348100_ref7","doi-asserted-by":"crossref","first-page":"476","DOI":"10.1145\/1315245.1315304","volume-title":"Proceedings of the 14th ACM conference on Computer and communications security","author":"Leo Dorrendorf","year":"2007"},{"key":"2024042316182348100_ref8","first-page":"385","volume-title":"Proceedings of the 2006 IEEE Symposium on Security and Privacy","author":"Gutterman","year":"2006"},{"key":"2024042316182348100_ref9","doi-asserted-by":"crossref","first-page":"659","DOI":"10.1145\/2508859.2516706","volume-title":"Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security","author":"Kim","year":"2013"},{"key":"2024042316182348100_ref10","first-page":"13","volume-title":"Proceedings of the Selected Areas in Cryptography (SAC 1999)","author":"Kelsey","year":"1999"},{"key":"2024042316182348100_ref11","volume-title":"The fortuna random number generator","author":"Voss"},{"key":"2024042316182348100_ref12","doi-asserted-by":"crossref","volume-title":"Analysis of the linux random number generator","author":"Gutterman","DOI":"10.1109\/SP.2006.5"},{"key":"2024042316182348100_ref13","author":"Documentation and analysis of the linux random number generator"},{"key":"2024042316182348100_ref14","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1016\/j.dam.2016.07.019","article-title":"Probability distributions for the linux entropy estimator","volume":"241","author":"YongjinYeom","year":"2018","journal-title":"Discrete Applied Mathematics"},{"key":"2024042316182348100_ref15","first-page":"559","volume-title":"Proceedings of the IEEE International Conference on Communications","author":"Mingshu","year":"2022"},{"key":"2024042316182348100_ref16","first-page":"709","volume-title":"Proceedings of the 2013 Seventh International Conference on Innovative Mobile and Internet Services in Ubiquitous Computing","author":"Lee","year":"2013"},{"key":"2024042316182348100_ref17","doi-asserted-by":"crossref","first-page":"220302","DOI":"10.1007\/s11432-019-2906-y","article-title":"Security in edge-assisted internet of things: challenges and solutions","volume":"63","author":"Shen","journal-title":"Science China Information Sciences"},{"key":"2024042316182348100_ref18","doi-asserted-by":"crossref","first-page":"1497","DOI":"10.1145\/2508859.2516758","volume-title":"Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security","author":"Jan-Erik Ekberg","year":"2013"},{"key":"2024042316182348100_ref19","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1145\/2462096.2462122","volume-title":"Proceedings of the sixth ACM conference on Security and privacy in wireless and mobile networks","author":"Hennebert","year":"2013"},{"key":"2024042316182348100_ref20","article-title":"Nist special publication 800-90b: recommendation for the entropy sources used for random bit generation","volume-title":"NIST Special Publication","author":"Turan"},{"key":"2024042316182348100_ref21","doi-asserted-by":"crossref","first-page":"239","DOI":"10.1109\/SIITME.2014.6967037","volume-title":"Proceedings of the IEEE 20th International Symposium for Design and Technology in Electronic Packaging (SIITME)","author":"Marghescu","year":"2014"},{"key":"2024042316182348100_ref22","first-page":"773","volume-title":"Proceedings of the IEEE\/ACS 11th International Conference on Computer Systems and Applications (AICCSA)","author":"Loutfi","year":"2014"},{"key":"2024042316182348100_ref23","doi-asserted-by":"crossref","article-title":"A statistical test suite for random and pseudorandom number generators for cryptographic applications","author":"Rukhin","DOI":"10.6028\/NIST.SP.800-22"},{"key":"2024042316182348100_ref24","first-page":"21","volume-title":"Proceedings of the 10th International Conference on Communication and Network Security","author":"Lv","year":"2020"},{"key":"2024042316182348100_ref25","author":"Sensors"},{"key":"2024042316182348100_ref26","first-page":"544","volume-title":"Proceedings of the Cryptographic Hardware and Embedded Systems (CHES)","author":"Ma","year":"2014"},{"key":"2024042316182348100_ref27","doi-asserted-by":"crossref","first-page":"1331","DOI":"10.1109\/TIFS.2013.2271423","article-title":"A worst-case-aware design methodology for noise-tolerant oscillator-based true random number generator with stochastic behavior modeling [j]","volume":"8","author":"Amaki","journal-title":"IEEE Transactions on Information Forensics and Security (TIFS)"},{"key":"2024042316182348100_ref28","first-page":"165","volume-title":"Proceedings of the Topics in Cryptology (CT-RSA 2017)","author":"Yuan Ma","year":"2017"},{"key":"2024042316182348100_ref29","author":"ISO\/IEC JTC 1\/SC 27 Berlin Germany ISO\/IEC 18031: information technology \u2013 security techniques \u2013 random bit generation"},{"key":"2024042316182348100_ref30","doi-asserted-by":"crossref","first-page":"6511","DOI":"10.1364\/OE.25.006511","article-title":"Real-time fast physical random number generator with a photonic integrated circuit [j]","volume":"25","author":"Ugajin","year":"2017","journal-title":"Opt. Express"},{"key":"2024042316182348100_ref31","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevA.87.062327","article-title":"Post processing for quantum random number generators: entropy evaluation and randomness extraction [j]","volume":"87","author":"Ma","year":"2013","journal-title":"Phys. Rev. A"},{"key":"2024042316182348100_ref32","doi-asserted-by":"crossref","article-title":"A statistical test suite for random and pseudorandom number generators for cryptographic applications","author":"Bassham","DOI":"10.6028\/NIST.SP.800-22r1a"},{"key":"2024042316182348100_ref33","first-page":"1","article-title":"High-efficiency min-entropy estimation based on neural network for random number generators [j]","volume":"2020","author":"Lv","year":"2020","journal-title":"Security and Communication Networks"},{"key":"2024042316182348100_ref34","author":"permission"},{"key":"2024042316182348100_ref35","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-319-68075-0","volume-title":"Fundamentals of Probability and Stochastic Processes with Applications to Communications","author":"Park","year":"2018"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/4\/1550\/57295692\/bxad081.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/67\/4\/1550\/57295692\/bxad081.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,23]],"date-time":"2024-04-23T16:49:52Z","timestamp":1713890992000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/67\/4\/1550\/7241316"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,9,20]]},"references-count":35,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2023,9,20]]},"published-print":{"date-parts":[[2024,4,21]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxad081","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2024,4]]},"published":{"date-parts":[[2023,9,20]]}}}