cachepc-linux

Fork of AMDESE/linux with modifications for CachePC side-channel attack
git clone https://git.sinitax.com/sinitax/cachepc-linux
Log | Files | Refs | README | LICENSE | sfeed.txt

hw_random.rst (3845B)


      1==========================================================
      2Linux support for random number generator in i8xx chipsets
      3==========================================================
      4
      5Introduction
      6============
      7
      8The hw_random framework is software that makes use of a
      9special hardware feature on your CPU or motherboard,
     10a Random Number Generator (RNG).  The software has two parts:
     11a core providing the /dev/hwrng character device and its
     12sysfs support, plus a hardware-specific driver that plugs
     13into that core.
     14
     15To make the most effective use of these mechanisms, you
     16should download the support software as well.  Download the
     17latest version of the "rng-tools" package from the
     18hw_random driver's official Web site:
     19
     20	http://sourceforge.net/projects/gkernel/
     21
     22Those tools use /dev/hwrng to fill the kernel entropy pool,
     23which is used internally and exported by the /dev/urandom and
     24/dev/random special files.
     25
     26Theory of operation
     27===================
     28
     29CHARACTER DEVICE.  Using the standard open()
     30and read() system calls, you can read random data from
     31the hardware RNG device.  This data is NOT CHECKED by any
     32fitness tests, and could potentially be bogus (if the
     33hardware is faulty or has been tampered with).  Data is only
     34output if the hardware "has-data" flag is set, but nevertheless
     35a security-conscious person would run fitness tests on the
     36data before assuming it is truly random.
     37
     38The rng-tools package uses such tests in "rngd", and lets you
     39run them by hand with a "rngtest" utility.
     40
     41/dev/hwrng is char device major 10, minor 183.
     42
     43CLASS DEVICE.  There is a /sys/class/misc/hw_random node with
     44two unique attributes, "rng_available" and "rng_current".  The
     45"rng_available" attribute lists the hardware-specific drivers
     46available, while "rng_current" lists the one which is currently
     47connected to /dev/hwrng.  If your system has more than one
     48RNG available, you may change the one used by writing a name from
     49the list in "rng_available" into "rng_current".
     50
     51==========================================================================
     52
     53
     54Hardware driver for Intel/AMD/VIA Random Number Generators (RNG)
     55	- Copyright 2000,2001 Jeff Garzik <jgarzik@pobox.com>
     56	- Copyright 2000,2001 Philipp Rumpf <prumpf@mandrakesoft.com>
     57
     58
     59About the Intel RNG hardware, from the firmware hub datasheet
     60=============================================================
     61
     62The Firmware Hub integrates a Random Number Generator (RNG)
     63using thermal noise generated from inherently random quantum
     64mechanical properties of silicon. When not generating new random
     65bits the RNG circuitry will enter a low power state. Intel will
     66provide a binary software driver to give third party software
     67access to our RNG for use as a security feature. At this time,
     68the RNG is only to be used with a system in an OS-present state.
     69
     70Intel RNG Driver notes
     71======================
     72
     73FIXME: support poll(2)
     74
     75.. note::
     76
     77	request_mem_region was removed, for three reasons:
     78
     79	1) Only one RNG is supported by this driver;
     80	2) The location used by the RNG is a fixed location in
     81	   MMIO-addressable memory;
     82	3) users with properly working BIOS e820 handling will always
     83	   have the region in which the RNG is located reserved, so
     84	   request_mem_region calls always fail for proper setups.
     85	   However, for people who use mem=XX, BIOS e820 information is
     86	   **not** in /proc/iomem, and request_mem_region(RNG_ADDR) can
     87	   succeed.
     88
     89Driver details
     90==============
     91
     92Based on:
     93	Intel 82802AB/82802AC Firmware Hub (FWH) Datasheet
     94	May 1999 Order Number: 290658-002 R
     95
     96Intel 82802 Firmware Hub:
     97	Random Number Generator
     98	Programmer's Reference Manual
     99	December 1999 Order Number: 298029-001 R
    100
    101Intel 82802 Firmware HUB Random Number Generator Driver
    102	Copyright (c) 2000 Matt Sottek <msottek@quiknet.com>
    103
    104Special thanks to Matt Sottek.  I did the "guts", he
    105did the "brains" and all the testing.