// COMPLETE THREAD

How much entropy in a key press?

3 expanded posts ยท every known parent and child

NODE 1a41e61dHow much entropy in a key press?
Can anyone tell me how many bits of entropy there are per 7-bit ASCII
character.  More specifically, a program wishes to generate a session
key by prompting the user to type N random key presses.  The characters
entered are hashed down to 128 bits by MD5 for subsequent use as a key.

What should the value of N be, such that the entropy of the user's
string does not unnecessarily exceed the entropy of the hash?
NODE 319a0401Re: How much entropy in a key press?
Shannon estimates roughly 1 bit per character of English.  

RFC 1750  D. Eastlake, S. Crocker, J. Schiller,
"Randomness Recommendations for Security" is probably useful.

Adam

| Can anyone tell me how many bits of entropy there are per 7-bit ASCII
| character.  More specifically, a program wishes to generate a session
| key by prompting the user to type N random key presses.  The characters
| entered are hashed down to 128 bits by MD5 for subsequent use as a key.
| 
| What should the value of N be, such that the entropy of the user's
| string does not unnecessarily exceed the entropy of the hash?
| 
| 

-- 
"It is seldom that liberty of any kind is lost all at once."
						       -Hume
NODE 1d5519bdRe: How much entropy in a key press?
> 
> Can anyone tell me how many bits of entropy there are per 7-bit ASCII
> character.  More specifically, a program wishes to generate a session
> key by prompting the user to type N random key presses.  The characters
> entered are hashed down to 128 bits by MD5 for subsequent use as a key.

Depends. You could use a fast timer and sample between keystrokes, then
use the least significant byte of the difference like PGP does (for DOS,
anyway).  You could change that so it samples bits instead of bytes,
but it's conceivable that you'll have less randomness that way.

I've experimented with speeding up the timer IRQs on my PC for that but
found it was superficially less random (in a pool of 256 bytes there
were more duplicates).

> What should the value of N be, such that the entropy of the user's
> string does not unnecessarily exceed the entropy of the hash?

With a decent timerr that samples bytes, I'd say 16 keystrokes. Use
a cypher overtha random data to garbe it a bit.

Rob

>