Using Fourier analysis, this paper establishes near-optimal security bounds for linear correctors commonly used in True Random Number Generators (TRNGs), expressed through code weight enumerators and input bias parameters. We provide the first near-tight bias characterization in total variation, by interpolating between optimal $\ell_\infty$ and $\ell_2$ norm results. Our bounds improve security assessments by an order of magnitude over previously known (overly conservative) estimates. Across $\sim $20,000 codes, we examine fundamental trade-offs between compression efficiency, cryptographic security, and hardware complexity. Achieving 80-bit security with 10\% input bias typically requires sacrificing more than 50\% of the code rate and incurs increased hardware cost. This quantifies the inherent cost of randomness extraction in hardware TRNG implementations.
翻译:利用傅里叶分析,本文建立了真随机数发生器(TRNG)中常用线性校正器的近最优安全界限,并通过码重枚举器和输入偏差参数加以表达。通过在最优$\ell_\infty$范数与$\ell_2$范数结果之间进行插值,我们首次给出了总变差距离下近乎紧致的偏差刻画。相较于先前已知的(过度保守的)估计,我们的界限将安全性评估改进了一个数量级。在对约20000个码字的分析中,我们考察了压缩效率、密码安全性与硬件复杂度之间的基本权衡。当输入偏差为10%时,实现80位安全性通常需要牺牲超过50%的码率,并带来硬件成本的增加。这量化了硬件TRNG实现中随机性提取的固有代价。