BS ISO IEC 18031-2025 PDF
Name in English:
STB BS ISO IEC 18031-2025
Name in Russian:
СТБ BS ISO IEC 18031-2025
Original standard BS ISO IEC 18031-2025 in PDF full version. Additional info + preview on request
Full title and description
STB BS ISO/IEC 18031-2025 — Information technology — Security techniques — Random bit generation. This entry describes the British adoption (BS ISO/IEC 18031:2025) of the ISO/IEC 18031 third edition (2025), which defines a conceptual model, element characteristics and security requirements for both non‑deterministic and deterministic random bit generators for cryptographic use.
Abstract
This standard specifies a conceptual model for random bit generators used in cryptographic applications, describes the main elements for non‑deterministic and deterministic generators, and establishes security requirements for those elements. It explicitly excludes detailed generator designs and statistical testing techniques for independent verification/validation.
General information
- Status: Published / Definitive (ISO edition published; British adoption published as BS ISO/IEC 18031:2025).
- Publication date: ISO edition published February 2025 (effective date cited as 3 February 2025); British adoption published in February 2025 (BS listings show early‑ to mid‑February 2025 publication).
- Publisher: International Organization for Standardization / IEC (original international standard); British Standards Institution (BS adoption/publisher for BS ISO/IEC 18031:2025).
- ICS / categories: 35.030 (IT security) — includes related ICS entries for information coding and cryptographic techniques.
- Edition / version: Edition 3 (2025).
- Number of pages: ISO edition: 94 pages (international PDF); British edition listings commonly show ~104 pages for the BS formatted publication (publisher formatting may change page count).
Scope
The standard defines a conceptual model and the constituent elements of a random bit generator for cryptographic purposes, specifying required characteristics and security requirements for both non‑deterministic and deterministic random bit generators. It does not provide detailed generator designs or mandate statistical test suites for independent validation. The document is intended to sit alongside related cryptographic module and testing standards.
Key topics and requirements
- Conceptual model for random bit generation for cryptographic applications (architecture and element relationships).
- Characteristics and requirements for non‑deterministic random bit generators (NRBGs).
- Characteristics and requirements for deterministic random bit generators (DRBGs), including entropy sources and reseeding considerations.
- Security requirements and design considerations to resist prediction, state compromise and other cryptographic attacks.
- Guidance on producing random number sequences from random bit strings; explicit exclusion of detailed statistical test specifications and full implementation designs.
Typical use and users
Security architects, cryptographic module designers, hardware RNG and software RNG implementers, product security evaluators, certification and compliance bodies, and technical procurement teams use this standard to define acceptable RNG behaviour and security requirements in cryptographic systems and modules.
Related standards
Standards commonly referenced alongside ISO/IEC 18031 include ISO/IEC 19790 (security requirements for cryptographic modules), ISO/IEC 20543 (test and analysis methods for random bit generators in certain evaluation contexts), and related hash and randomness references such as ISO/IEC 10118‑3. These references are cited in normative and informative sections of the document.
Keywords
random bit generator, RNG, NRBG, DRBG, cryptographic random, entropy source, reseeding, security requirements, ISO/IEC 18031, BS ISO/IEC 18031:2025.
FAQ
Q: What is this standard?
A: ISO/IEC 18031:2025 (published as the third edition in 2025 and adopted by BSI as BS ISO/IEC 18031:2025) is an international standard that defines a conceptual model and security requirements for random bit generators used in cryptography.
Q: What does it cover?
A: It covers the model, element descriptions and required characteristics for non‑deterministic and deterministic random bit generators and sets out security requirements; it does not provide full implementation designs or exhaustive statistical test specifications for independent validation.
Q: Who typically uses it?
A: Cryptographic engineers, RNG implementers (hardware and software), security evaluators, certification labs, product security architects and procurement/compliance teams use it to define, assess and procure RNGs suitable for cryptographic applications.
Q: Is it current or superseded?
A: As of the 2025 publication it is the current edition; it supersedes and replaces the prior ISO/IEC 18031:2011 series (and its amendments/corrigenda). Users should verify the effective publication date in their locale (early February 2025) for adoption details.
Q: Is it part of a series?
A: It is part of the ISO/IEC JTC 1/SC 27 family of IT security standards and is commonly used in conjunction with standards for cryptographic modules and testing (for example ISO/IEC 19790 and ISO/IEC 20543).
Q: What are the key keywords?
A: RNG, random bit generator, NRBG, DRBG, entropy, reseeding, cryptographic randomness, security requirements, ISO/IEC 18031, BS ISO/IEC 18031:2025.