Learning path

Full curriculum

Full curriculum

Unit content

Cryptographic randomness, nonces and replay

Security mechanisms often require values that an adversary cannot predict before they are generated.

A cryptographically secure random generator is designed so that observing previous outputs does not make future outputs feasibly predictable under its security assumptions.

Randomness is used for secret keys, bearer tokens and some protocol challenges. Ordinary simulation-oriented pseudorandom generators may produce statistically plausible values while still being predictable from a small internal state, making them unsuitable for secrets.

A nonce is a value intended to be used only once in a particular protocol context. It does not always need to be secret or random, but it must satisfy the uniqueness or unpredictability requirement of the construction that uses it.

Nonces can prevent replay attacks by making an old authenticated message invalid in a new protocol instance. Reusing a nonce where a cryptographic construction requires uniqueness can instead destroy its security.

The required property—randomness, unpredictability or uniqueness—must be taken from the protocol, not guessed from the word “nonce.”