What is a random number generator?

A random number generator (RNG) is a system that produces random or pseudorandom numbers. Whether the next number can actually be predicted depends on the kind of generator. Some generators draw on a physical process, some compute their numbers with an algorithm, and some algorithms are built so that even someone who has seen their output cannot predict what comes next. Looking random and being unpredictable are different properties, and most of this article is about the difference.

Hardware random number generators

A hardware random number generator (HRNG), also called a true random number generator (TRNG), derives its numbers from a physical process. The oldest ones are large enough to watch: a flipped coin, a rolled die, a roulette wheel. Mechanics describes each of them completely, yet a well-made wheel is still unpredictable in practice, because tiny differences in how each spin starts grow into entirely different outcomes.

Modern hardware generators measure microscopic phenomena instead: shot noise and thermal noise in electronic circuits, atmospheric noise, quantum effects. These are good sources of entropy — unpredictability that can be measured — but a physical source is not perfect by nature: it can be biased, it can drift and it can fail, so its quality has to be assessed and monitored, and its output processed further where necessary, which is what standards such as NIST SP 800-90B describe. Hardware sources are used where the guarantee matters most — above all in cryptography, where they supply the unpredictable starting material for the keys behind protocols such as Transport Layer Security (TLS).

Pseudorandom number generators

The alternative to a physical device is an algorithm. A pseudorandom number generator (PRNG) produces a sequence that looks random but is completely determined by an initial value called the seed. Give the same seed to the same algorithm and you get the same sequence every time. That is a weakness wherever a result must be unpredictable and the seed or the internal state can be guessed or reconstructed, and a strength wherever a result must be reproducible — a simulation or a test can be run again exactly. PRNGs are also fast, cheap and easy to implement, which is why most software relies on them. Well-known families include the linear congruential generator (LCG), the xorshift generators and the Mersenne Twister.

Mersenne Twister

The Mersenne Twister, published in 1997 by Makoto Matsumoto and Takuji Nishimura, is one of the most widely used pseudorandom number generators and the default in many programming languages. Its name comes from its period — the length of the sequence before it repeats — which in the standard variant, MT19937, is the Mersenne prime 219937 − 1. It passes most statistical tests of randomness and suits simulations well. It was not designed to keep secrets, however: from 624 consecutive 32-bit outputs anyone can reconstruct its internal state and predict every value that follows, so it must not be used for keys, passwords or anything else that has to stay unpredictable.

Cryptographically secure generators and entropy

Many applications need both things at once: the speed of an algorithm and the unpredictability of a physical source. The answer is a cryptographically secure pseudorandom number generator (CSPRNG). It is still a PRNG, but one built so that seeing part of its output gives no practical way to predict the rest, and it is seeded, and regularly reseeded, from a source of real entropy. A seed from a physical source does not make an ordinary PRNG secure; the algorithm has to be designed for it. A physical source such as thermal noise or the timing of hardware events supplies a small amount of true randomness, and the CSPRNG stretches it into an output stream at a much higher rate. This combination is what an operating system offers to the programs running on it, and it is what "random number generator" usually means in practice today. It produces encryption keys, session tokens and passwords.

Random numbers in the browser

JavaScript gives a web page two built-in ways to get random values, and they belong to different classes. Math.random() is an ordinary PRNG: the language standard leaves the algorithm to each browser and promises nothing about security — fine for an animation, unfit for a draw that somebody might contest. The other is the Web Crypto API. Its crypto.getRandomValues() method returns cryptographically strong random values, produced by a CSPRNG that is seeded with the entropy of the operating system.

Our online random number generator uses the Web Crypto API for every draw, and the numbers are produced in your browser rather than on a server. The same source drives the other generators on this site, whether you roll dice, flip a coin or generate a password.

From random bits to a number in your range

A cryptographically secure generator is only half of a fair draw. It delivers raw bits, and the program still has to turn them into a number in your range — and this is where bias can creep in. Suppose the source gives the values 0 to 9 with equal chances and you need a number from 0 to 5. Taking the remainder after dividing by 6 looks natural, but 0, 1, 2 and 3 can then each come up in two ways and 4 and 5 in only one, so each of the numbers 0 to 3 has a 20% chance, and 4 and 5 only 10% each. One way to remove the bias is to discard the values that do not fit and draw again; the random number generator guides go into this in detail.

Two more things surprise people. Repeats are normal: when a whole number from 1 to 10 is drawn independently and every number is equally likely, the number just drawn has the same 1 in 10 chance of coming up again as any other. A draw without repeats is a different kind of draw, not a more random one. And a fair generator alone does not make a whole procedure fair: the list of entrants and the number of attempts matter just as much, as our guide on how to pick a random contest winner explains.