BSI AIS 20 / AIS 31 Physical TRNG Suite

German Federal Office for Information Security (BSI) AIS 20 / AIS 31 physical true random number generator test suite. Evaluates hardware entropy sources across 9 deterministic criteria: T0 Disjointness through T8 Shannon Entropy.

German BSI Standard: AIS 20 / AIS 31 defines mandatory certification criteria for physical True Random Number Generators used in security-critical devices (smart cards, HSMs, TPMs). All 9 tests operate over a fixed 20,000-bit (2,500-byte) sample window.

BSI AIS 31 Test Battery (T0–T8)

The AIS 31 suite evaluates physical entropy sources against nine deterministic statistical acceptance criteria defined by the German Federal Office for Information Security:

IDTest NamePass CriteriaDescription
T0Disjointness0 duplicate 16-bit words in 2,500 BVerifies uniqueness of 16-bit words across the sample block.
T1Monobit$9{,}654 \lt \text{count}_1 \lt 10{,}346$Number of ones in 20,000 raw bits must be within bounds.
T2Poker Test$\chi^2 \lt 46.17$ ($df=15$)Uniformity of 4-bit nibbles across 5,000 groups.
T3Runs TestRuns within BSI acceptance bandsFrequency of uninterrupted identical bit sequences (length 1–6).
T4Long RunsMax run $\lt 34$ bitsNo run of identical bits exceeding 34 consecutive positions.
T5Autocorrelation$\lvert Z_\tau \rvert \lt 3.00$ for $\tau = 1, \ldots, 16$Absence of periodic structure across 16 lag offsets.
T6Uniform DistributionUniform bit transitions (planned)Balance of 0→1 and 1→0 bit transitions.
T7Comparative TestHomogeneity $p \ge 0.01$ (planned)Consistency between successive sample blocks.
T8Shannon Entropy$H \ge 7.976$ bits/byteMinimum information density for hardware TRNG certification.

[!NOTE]
T0, T6, T7 are currently in specification stage — they display as NOT IMPLEMENTED in the dashboard. T1–T5, T8 are fully implemented and evaluated against BSI-specified acceptance bounds.

Required Sample Size

The BSI mandates evaluating a minimum of 20,000 bits (2,500 bytes) per test sequence. Streams shorter than this threshold will return INSUFFICIENT DATA for affected tests.

When to Use AIS 31

  1. Smart Card & Secure Element Certification: Mandatory pre-certification testing for random number generators embedded in ISO 7816 smart cards, SIM cards, and eSIMs seeking Common Criteria or BSI certification.
  2. Hardware Security Module (HSM) Qualification: Validating physical noise sources in network HSMs (e.g. Thales Luna, Utimaco) before submission to BSI for formal certification under AIS 20/31 scheme.
  3. TPM 2.0 Entropy Source Validation: Verifying that Trusted Platform Module hardware RNG outputs meet BSI TRNG Class PTG.2 / PTG.3 requirements under the German IT security law (IT-Sicherheitsgesetz).
  4. Avalanche Noise Diode Characterization: Characterizing and calibrating reverse-biased zener/avalanche diodes used as entropy harvesting elements in embedded cryptographic modules.

Certification Note: AIS 20 covers deterministic RNG (DRNG/DRBG) and AIS 31 covers non-deterministic physical TRNG. This tool targets AIS 31 physical TRNG evaluation. Pair with the NIST SP 800-90B suite for US FIPS 140-3 compliance testing.

Sample Size Requirement: The BSI specifies tests operate on exactly 20,000 bits (2,500 bytes) per sequence. For real device certification, multiple independent sequences must each pass all applicable tests. Drop any .bin capture of at least 2,500 bytes.