A class of random bit generators that allows for the possibility of failure, reseeding, providing entropy at the same time as requesting bytes
Minimum complete definition: newGen, genSeedLength, genBytes, reseed, reseedInfo, reseedPeriod.
Methods
newGen :: ByteString -> Either GenError gInstantiate a new random bit generator. The provided bytestring should be of length >= genSeedLength. If the bytestring is shorter then the call may fail (suggested error: NotEnoughEntropy). If the bytestring is of sufficent length the call should always succeed.
genSeedLength :: Tagged g ByteLengthLength of input entropy necessary to instantiate or reseed a generator
genBytes :: ByteLength -> g -> Either GenError (ByteString, g)genBytes len ggenerates a random ByteString of lengthlenand new generator. TheMonadCryptoRandompackage has routines useful for converting the ByteString to commonly needed values (but "cereal" or other deserialization libraries would also work).This routine can fail if the generator has gone too long without a reseed (usually this is in the ball-park of 2^48 requests). Suggested error in this cases is NeedReseed
reseedInfo :: g -> ReseedInfoIndicates how soon a reseed is needed
reseedPeriod :: g -> ReseedInfoIndicates the period between reseeds (constant for most generators).
genBytesWithEntropy :: ByteLength -> ByteString -> g -> Either GenError (ByteString, g)genBytesWithEntropy g i entropygeneratesirandom bytes and use the additional inputentropyin the generation of the requested data to increase the confidence our generated data is a secure random stream.Some generators use
entropyto perturb the state of the generator, meaning:(_,g2') <- genBytesWithEntropy len g1 ent (_,g2 ) <- genBytes len g1 g2 /= g2'But this is not required.
Default:
genBytesWithEntropy g bytes entropy = xor entropy (genBytes g bytes)reseed :: ByteString -> g -> Either GenError gIf the generator has produced too many random bytes on its existing seed it will return NeedReseed. In that case, reseed the generator using this function and a new high-entropy seed of length >= genSeedLength. Using bytestrings that are too short can result in an error (NotEnoughEntropy).
newGenIO :: IO gBy default this uses System.Entropy to obtain entropy for newGen. WARNING: The default implementation opens a file handle which will never be closed!
Instances1CryptoRandomGen
CryptoRandomGen SystemRandomDefined in crypto-api-0.13.3 · Crypto.Random