%% You should probably cite draft-irtf-cfrg-randomness-improvements instead of this I-D. @techreport{sullivan-randomness-improvements-00, number = {draft-sullivan-randomness-improvements-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-sullivan-randomness-improvements/00/}, author = {Luke Garratt and Nick Sullivan}, title = {{Randomness Improvements for Security Protocols}}, pagetotal = 5, year = 2017, month = oct, day = 30, abstract = {Randomness is a crucial ingredient for TLS and related transport security protocols. Weak or predictable cryptographically-strong pseudorandom number generators (CSPRNGs) can be abused or exploited for malicious purposes. See the Dual EC random number backdoor for a relevant example of this problem. This document describes a way for security protocol participants to mix their long-term private key into the entropy pool from which random values are derived. This may help mitigate problems that stem from broken CSPRNGs.}, }