Documentation Index
Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt
Use this file to discover all available pages before exploring further.
Overview
This module provides cryptographically secure random number generation (CSPRNG) using platform-specific secure random sources. All randomness is suitable for cryptographic key generation and security-critical operations.Core functions
csprng_bytes
Generates cryptographically secure random bytes.Output buffer to fill with random bytes
Number of random bytes to generate
csprng_u64
Generates a cryptographically secure random 64-bit unsigned integer.Random 64-bit value
Utility functions
load_le64
Loads a 64-bit integer from a byte array in little-endian format.Pointer to 8 bytes
64-bit integer in host byte order
store_le64
Stores a 64-bit integer into a byte array in little-endian format.Output buffer (must have space for 8 bytes)
Value to store
Platform-specific implementations
macOS / BSD
Usesarc4random_buf() for cryptographically secure random bytes.
Available on macOS, FreeBSD, OpenBSD, and NetBSD.
Linux
Uses thegetrandom() system call with fallback to /dev/urandom.
- Primary:
getrandom()system call (Linux 3.17+) - Fallback: Reads from
/dev/urandomifgetrandom()fails - Handles interruptions (
EINTR) automatically
Windows
UsesBCryptGenRandom() with the system-preferred RNG.
Requires
bcrypt.lib (automatically linked via pragma).Fallback (portable)
Usesstd::random_device for platforms without native secure random support.
Security properties
Cryptographic strength
All platform-specific implementations provide:- Unpredictability: Output cannot be predicted from previous values
- Uniform distribution: All bit patterns equally likely
- Sufficient entropy: Backed by hardware or OS entropy sources
- Forward secrecy: Compromise of current state doesn’t reveal past outputs
Error handling
Usage patterns
Key generation
Nonce generation
Random seed buffer
Random field element
Testing considerations
For deterministic testing:
- The CSPRNG is not seedable by design (security requirement)
- For reproducible tests, use a separate PRNG (like SHAKE256)
- Never use test-only random sources in production code
Relationship to other modules
The random module is used by:- Types (
types.hpp):make_nonce128(),rand_fp_nonzero() - Hash (
hash.hpp): Seeding XOFs and PRNGs - Key generation: Generating secret keys and randomness
- Encryption: Sampling error vectors and random masks
Performance characteristics
csprng_u64(): ~10-50 CPU cycles on modern hardwarecsprng_bytes(): ~1-5 GB/s throughput for bulk generation- Dominated by system call overhead for small requests
- Consider batching requests for small values
Related
- Types - Uses random generation for nonces and field elements
- Hash - Deterministic randomness expansion via XOF
- Field operations - Random field element generation