Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Bridging the Gap between Standards on Random Number Generation: Comparison of SP 800-90 Series and AIS 20/31

Published

Author(s)

Elaine Barker, John Kelsey, Kerry McKay, Johannes Mittmann, Matthias Peter, Werner Schindler, Meltem Sonmez Turan

Abstract

This report studies the cryptographic random number generation standards and guidelines written by BSI and NIST, namely AIS 20/31 and SP 800-90 Series. The aim of this report is to compare these publications, focusing on the similarities and differences of their terminology, assumptions, and requirements. The report also aims to improve the communications between all involved parties, promote a shared understanding, and reduce and resolve inconsistencies in related standards.
Citation
NIST Interagency/Internal Report (NISTIR) - 8446
Report Number
8446

Keywords

cryptographic random number generation, entropy, terminology, validation

Citation

Barker, E. , Kelsey, J. , McKay, K. , Mittmann, J. , Peter, M. , Schindler, W. and Sonmez Turan, M. (2026), Bridging the Gap between Standards on Random Number Generation: Comparison of SP 800-90 Series and AIS 20/31, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.IR.8446, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=959366 (Accessed January 30, 2026)

Issues

If you have any questions about this publication or are having problems accessing it, please contact [email protected].

Created January 29, 2026
Was this page helpful?