Backtracking Resistance

February 8, 2018

How Can We Help?

Backtracking Resistance

You are here:
< Back

Backtracking resistance is provided relative to time T if there is assurance that an adversary who has knowledge of the internal state of the Deterministic Random Bit Generator (DRBG) at some time subsequent to time T would be unable to distinguish between observations of ideal random bitstrings and (previously unseen) bitstrings that were output by the DRBG prior to time T. The complementary assurance is called Prediction Resistance.
SOURCE: SP 800-90A