BSI AIS 20 / AIS 31 Physical TRNG Suite
German Federal Office for Information Security (BSI) AIS 20 / AIS 31 physical true random number generator test suite. Evaluates hardware entropy sources across 9 deterministic criteria: T0 Disjointness through T8 Shannon Entropy.
BSI AIS 31 Test Battery (T0–T8)
The AIS 31 suite evaluates physical entropy sources against nine deterministic statistical acceptance criteria defined by the German Federal Office for Information Security:
| ID | Test Name | Pass Criteria | Description |
|---|---|---|---|
| T0 | Disjointness | 0 duplicate 16-bit words in 2,500 B | Verifies uniqueness of 16-bit words across the sample block. |
| T1 | Monobit | $9{,}654 \lt \text{count}_1 \lt 10{,}346$ | Number of ones in 20,000 raw bits must be within bounds. |
| T2 | Poker Test | $\chi^2 \lt 46.17$ ($df=15$) | Uniformity of 4-bit nibbles across 5,000 groups. |
| T3 | Runs Test | Runs within BSI acceptance bands | Frequency of uninterrupted identical bit sequences (length 1–6). |
| T4 | Long Runs | Max run $\lt 34$ bits | No run of identical bits exceeding 34 consecutive positions. |
| T5 | Autocorrelation | $\lvert Z_\tau \rvert \lt 3.00$ for $\tau = 1, \ldots, 16$ | Absence of periodic structure across 16 lag offsets. |
| T6 | Uniform Distribution | Uniform bit transitions (planned) | Balance of 0→1 and 1→0 bit transitions. |
| T7 | Comparative Test | Homogeneity $p \ge 0.01$ (planned) | Consistency between successive sample blocks. |
| T8 | Shannon Entropy | $H \ge 7.976$ bits/byte | Minimum information density for hardware TRNG certification. |
[!NOTE]
T0, T6, T7 are currently in specification stage — they display asNOT IMPLEMENTEDin the dashboard. T1–T5, T8 are fully implemented and evaluated against BSI-specified acceptance bounds.
Required Sample Size
The BSI mandates evaluating a minimum of 20,000 bits (2,500 bytes) per test sequence. Streams shorter than this threshold will return INSUFFICIENT DATA for affected tests.
When to Use AIS 31
- Smart Card & Secure Element Certification: Mandatory pre-certification testing for random number generators embedded in ISO 7816 smart cards, SIM cards, and eSIMs seeking Common Criteria or BSI certification.
- Hardware Security Module (HSM) Qualification: Validating physical noise sources in network HSMs (e.g. Thales Luna, Utimaco) before submission to BSI for formal certification under AIS 20/31 scheme.
- TPM 2.0 Entropy Source Validation: Verifying that Trusted Platform Module hardware RNG outputs meet BSI TRNG Class PTG.2 / PTG.3 requirements under the German IT security law (IT-Sicherheitsgesetz).
- Avalanche Noise Diode Characterization: Characterizing and calibrating reverse-biased zener/avalanche diodes used as entropy harvesting elements in embedded cryptographic modules.
.bin capture of at least 2,500 bytes.