You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于SecureRandom.getInstance("DRBG")实际算法及配置检测的技术问询

DRBG in Java 9: What Algorithm Is Really Used, and How to Configure/Check It?

Great question—let's unpack this clearly, since Java 9's DRBG implementation can feel a bit opaque at first.

First off: What does SecureRandom.getInstance("DRBG") actually use under the hood?

When you call this method, the exact DRBG mechanism (Hash_DRBG, HMAC_DRBG, or CTR_DRBG) isn't fixed out of the box. Java 9's implementation follows NIST SP 800-90Ar1, which requires all three mechanisms to be supported, but leaves the default choice up to the JVM vendor. For most standard distributions like OpenJDK, the default is typically CTR_DRBG or Hash_DRBG, optimized for your platform's performance and security needs.

How to configure which DRBG algorithm to use

You have two main ways to specify the DRBG type explicitly:

1. Use DRBGParameters when creating the SecureRandom instance

Java 9 added the DRBGParameters class to let you fine-tune the DRBG configuration, including the exact mechanism. Here's a concrete example for each type:

import java.security.SecureRandom;
import java.security.spec.DRBGParameters;

// Example 1: Initialize Hash_DRBG with 256-bit security strength
DRBGParameters hashParams = DRBGParameters.instantiation(
    DRBGParameters.Capability.PR_AND_RESEED, // Supports prediction resistance + reseeding
    null, // No personalization string
    null, // No additional input
    256,
    "Hash_DRBG"
);
SecureRandom hashDrbg = SecureRandom.getInstance("DRBG", hashParams);

// Example 2: Initialize HMAC_DRBG
DRBGParameters hmacParams = DRBGParameters.instantiation(
    DRBGParameters.Capability.RESEED_ONLY,
    "my-personalization".getBytes(),
    null,
    256,
    "HMAC_DRBG"
);
SecureRandom hmacDrbg = SecureRandom.getInstance("DRBG", hmacParams);

// Example 3: Initialize CTR_DRBG
DRBGParameters ctrParams = DRBGParameters.instantiation(
    DRBGParameters.Capability.NONE,
    null,
    null,
    256,
    "CTR_DRBG"
);
SecureRandom ctrDrbg = SecureRandom.getInstance("DRBG", ctrParams);

2. Adjust system properties (for application-wide defaults)

You can set system properties to change the default DRBG behavior across your entire app. Check your JRE's java.security file for vendor-specific options, but common ones include:

  • securerandom.drbg.config: Lets you define default parameters (including mechanism type) for DRBG instances.
  • For OpenJDK, you might use org.openjdk.javax.crypto.drbg.Default to set the default DRBG type directly.

How to detect which DRBG algorithm is actually in use

The getAlgorithm() method will just return "DRBG", so you need a few workarounds to see the real mechanism:

1. Use reflection (for programmatic checks)

While reflection isn't future-proof, it works for most standard JVMs. Here's a quick snippet:

import java.lang.reflect.Field;
import java.security.SecureRandom;

public class DRBGChecker {
    public static void main(String[] args) throws Exception {
        SecureRandom drbg = SecureRandom.getInstance("DRBG");
        
        // Access the underlying implementation (OpenJDK-specific, but works for most)
        Field implField = SecureRandom.class.getDeclaredField("impl");
        implField.setAccessible(true);
        Object drbgImpl = implField.get(drbg);
        
        // The class name will reveal the type—e.g., sun.security.provider.DRBG.HashDRBG
        System.out.println("Actual DRBG mechanism: " + drbgImpl.getClass().getSimpleName());
    }
}

2. Enable debug logging

Start your JVM with the -Djava.security.debug=drbg flag. This will print detailed debug output about the DRBG instance initialization, including the exact mechanism, security strength, and configuration settings. Look for lines like:

DRBG: Instantiated DRBG of type CTR_DRBG with security strength 256

3. Check the security provider documentation

If you're using a non-standard JVM (like Oracle JDK, or a vendor-specific implementation), check their docs—many will document the default DRBG type and how to inspect it.

Quick recap of NIST SP 800-90Ar1 requirements

NIST's SP 800-90Ar1 mandates that all Java 9+ implementations support Hash_DRBG, HMAC_DRBG, and CTR_DRBG. However, it doesn't enforce a single default—vendors choose based on platform-specific tradeoffs between performance and security.


内容的提问来源于stack exchange,提问作者Maarten Bodewes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 08:14:44