Keyboard Timing
In this section, I’ll develop an alternate method of
seeding a SecureRandom. This method is based on
measuring the timing of keyboard events, a method that has been used
for years in PGP (Pretty Good Privacy, a popular cryptography
application). The basic idea is to measure the time between
successive keystrokes using a fast timer (a resolution of 1
millisecond or better is preferable). For each keystroke, one or two
low-order bits of timing information will appear random. Take as many
bits as you need to seed your PRNG. Even a very good, very consistent
typist will probably not be able to type with millisecond precision,
which means the seed bits are truly random.
This method does require that the user type data for a few seconds,
which is not particularly user friendly. In contrast, the
self-seeding algorithm in SecureRandom has no
impact on your user interface, except that it will hang up your
application for a few seconds the first time it is run. The method
presented here, however, is under your control.
Seeder
The
Seeder class listens to
KeyEvents and builds up a seed value of a certain
length. When the seed is completed, Seeder will
fire off an ActionEvent. Seeder
doesn’t care where the keyboard events come from; it just
implements the KeyListener interface. We’ll
make Seeder part of the
oreilly.jonathan.util
package, so that we can easily use it
later.
package oreilly.jonathan.util; import java.awt.AWTEventMulticaster; import java.awt.event.*; public class ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access