1997-06-14 01:15:41 +00:00
|
|
|
.\" $OpenBSD: arc4random.3,v 1.2 1997/04/27 22:40:25 angelos Exp $
|
|
|
|
.\" Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de>
|
|
|
|
.\" All rights reserved.
|
|
|
|
.\"
|
|
|
|
.\" Redistribution and use in source and binary forms, with or without
|
|
|
|
.\" modification, are permitted provided that the following conditions
|
|
|
|
.\" are met:
|
|
|
|
.\" 1. Redistributions of source code must retain the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer.
|
|
|
|
.\" 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer in the
|
|
|
|
.\" documentation and/or other materials provided with the distribution.
|
|
|
|
.\" 3. All advertising materials mentioning features or use of this software
|
|
|
|
.\" must display the following acknowledgement:
|
|
|
|
.\" This product includes software developed by Niels Provos.
|
|
|
|
.\" 4. The name of the author may not be used to endorse or promote products
|
|
|
|
.\" derived from this software without specific prior written permission.
|
|
|
|
.\"
|
|
|
|
.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
|
|
|
|
.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
|
|
|
|
.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
|
|
|
|
.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
|
|
.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
|
|
|
|
.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
|
|
|
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
.\"
|
|
|
|
.\" Manual page, using -mandoc macros
|
1999-08-28 00:22:10 +00:00
|
|
|
.\" $FreeBSD$
|
1997-06-14 01:15:41 +00:00
|
|
|
.\"
|
|
|
|
.Dd April 15, 1997
|
|
|
|
.Dt ARC4RANDOM 3
|
|
|
|
.Os
|
|
|
|
.Sh NAME
|
1999-10-30 15:12:25 +00:00
|
|
|
.Nm arc4random ,
|
2008-07-21 13:52:06 +00:00
|
|
|
.Nm arc4random_buf ,
|
2008-07-22 11:33:49 +00:00
|
|
|
.Nm arc4random_uniform ,
|
1999-10-30 15:12:25 +00:00
|
|
|
.Nm arc4random_stir ,
|
1997-06-14 01:15:41 +00:00
|
|
|
.Nm arc4random_addrandom
|
2001-04-18 15:54:10 +00:00
|
|
|
.Nd arc4 random number generator
|
2000-04-21 09:42:15 +00:00
|
|
|
.Sh LIBRARY
|
|
|
|
.Lb libc
|
1997-06-14 01:15:41 +00:00
|
|
|
.Sh SYNOPSIS
|
2001-10-01 16:09:29 +00:00
|
|
|
.In stdlib.h
|
1997-06-14 01:15:41 +00:00
|
|
|
.Ft u_int32_t
|
|
|
|
.Fn arc4random "void"
|
|
|
|
.Ft void
|
2008-07-21 13:52:06 +00:00
|
|
|
.Fn arc4random_buf "void *buf" "size_t nbytes"
|
2008-07-22 11:33:49 +00:00
|
|
|
.Ft u_int32_t
|
|
|
|
.Fn arc4random_uniform "u_int32_t upper_bound"
|
2008-07-21 13:52:06 +00:00
|
|
|
.Ft void
|
1997-06-14 01:15:41 +00:00
|
|
|
.Fn arc4random_stir "void"
|
|
|
|
.Ft void
|
1997-06-14 01:28:59 +00:00
|
|
|
.Fn arc4random_addrandom "unsigned char *dat" "int datlen"
|
1997-06-14 01:15:41 +00:00
|
|
|
.Sh DESCRIPTION
|
|
|
|
The
|
2000-10-30 13:23:19 +00:00
|
|
|
.Fn arc4random
|
1997-06-14 01:15:41 +00:00
|
|
|
function uses the key stream generator employed by the
|
2000-03-02 09:14:21 +00:00
|
|
|
arc4 cipher, which uses 8*8 8 bit S-Boxes.
|
|
|
|
The S-Boxes
|
2000-10-30 13:23:19 +00:00
|
|
|
can be in about
|
1997-06-14 01:15:41 +00:00
|
|
|
.if t 2\u\s71700\s10\d
|
|
|
|
.if n (2**1700)
|
2003-05-22 13:02:28 +00:00
|
|
|
states.
|
|
|
|
The
|
2003-05-01 19:09:16 +00:00
|
|
|
.Fn arc4random
|
|
|
|
function returns pseudo-random numbers in the range of 0 to
|
|
|
|
.if t 2\u\s731\s10\d\(mi1,
|
2003-07-31 06:18:24 +00:00
|
|
|
.if n (2**32)\(mi1,
|
2003-05-01 19:09:16 +00:00
|
|
|
and therefore has twice the range of
|
2003-07-31 06:18:24 +00:00
|
|
|
.Xr rand 3
|
|
|
|
and
|
|
|
|
.Xr random 3 .
|
1997-06-14 01:15:41 +00:00
|
|
|
.Pp
|
2008-07-21 13:52:06 +00:00
|
|
|
.Fn arc4random_buf
|
|
|
|
function fills the region
|
|
|
|
.Fa buf
|
|
|
|
of length
|
|
|
|
.Fa nbytes
|
|
|
|
with ARC4-derived random data.
|
|
|
|
.Pp
|
2008-07-22 11:33:49 +00:00
|
|
|
.Fn arc4random_uniform
|
|
|
|
will return a uniformly distributed random number less than
|
|
|
|
.Fa upper_bound .
|
|
|
|
.Fn arc4random_uniform
|
|
|
|
is recommended over constructions like
|
|
|
|
.Dq Li arc4random() % upper_bound
|
|
|
|
as it avoids "modulo bias" when the upper bound is not a power of two.
|
|
|
|
.Pp
|
1997-06-14 01:15:41 +00:00
|
|
|
The
|
|
|
|
.Fn arc4random_stir
|
2000-10-30 13:23:19 +00:00
|
|
|
function reads data from
|
1997-06-14 01:15:41 +00:00
|
|
|
.Pa /dev/urandom
|
1999-05-09 13:46:31 +00:00
|
|
|
and uses it to permute the S-Boxes via
|
1997-06-14 01:15:41 +00:00
|
|
|
.Fn arc4random_addrandom .
|
|
|
|
.Pp
|
2000-10-30 13:23:19 +00:00
|
|
|
There is no need to call
|
1997-06-14 01:15:41 +00:00
|
|
|
.Fn arc4random_stir
|
|
|
|
before using
|
|
|
|
.Fn arc4random
|
2008-07-21 13:52:06 +00:00
|
|
|
functions family, since
|
|
|
|
they automatically initialize themselves.
|
2003-05-01 19:09:16 +00:00
|
|
|
.Sh EXAMPLES
|
|
|
|
The following produces a drop-in replacement for the traditional
|
|
|
|
.Fn rand
|
|
|
|
and
|
|
|
|
.Fn random
|
|
|
|
functions using
|
|
|
|
.Fn arc4random :
|
|
|
|
.Pp
|
2003-05-22 13:02:28 +00:00
|
|
|
.Dl "#define foo4random() (arc4random() % ((unsigned)RAND_MAX + 1))"
|
1997-06-14 01:15:41 +00:00
|
|
|
.Sh SEE ALSO
|
|
|
|
.Xr rand 3 ,
|
|
|
|
.Xr random 3 ,
|
|
|
|
.Xr srandomdev 3
|
|
|
|
.Sh HISTORY
|
2000-10-30 13:23:19 +00:00
|
|
|
.Pa RC4
|
2000-03-02 09:14:21 +00:00
|
|
|
has been designed by RSA Data Security, Inc.
|
|
|
|
It was posted anonymously
|
1997-06-14 01:15:41 +00:00
|
|
|
to the USENET and was confirmed to be equivalent by several sources who
|
2000-03-02 09:14:21 +00:00
|
|
|
had access to the original cipher.
|
2000-10-30 13:23:19 +00:00
|
|
|
Since
|
1997-06-14 01:15:41 +00:00
|
|
|
.Pa RC4
|
2000-10-30 13:23:19 +00:00
|
|
|
used to be a trade secret, the cipher is now referred to as
|
1997-06-14 01:15:41 +00:00
|
|
|
.Pa ARC4 .
|