Cryptography Worldcryptographyworld.com

Section 4 — The Pad

What random has to mean

True randomness is not a feeling of unpredictability — it is a mathematical condition, and most things that seem random are not.

SectionThe Pad
RegisterEntry 15 of 22
LengthShort entry
Torn cipher tables and telegram forms scattered beside an old encryption device
The one system in the register with a proof behind it, and the only one whose difficulty is entirely logistical.Photograph — collection credit

The standard that most processes fail

When cryptographers say a one-time pad key must be random, they mean something precise: each symbol is statistically independent of every other symbol, and the distribution across the alphabet is uniform. No symbol carries information about what came before or what comes next. This is not a matter of seeming sufficiently jumbled. It is a condition that can, in principle, be tested — and that most everyday processes fail.

A human choosing "random" numbers is the worst offender. People avoid repetition, cluster around certain digits, and follow unconscious patterns that are measurable and exploitable. A shift worker filling a pad notebook by hand, however conscientious, is not producing randomness — they are producing a record of cognitive bias. Any key material generated this way weakens the guarantee that Claude Shannon proved in 1949: the proof holds only when the key is genuinely, mathematically random.

A thick codebook open at a page of word groups
A codebook replaces whole phrases with groups. Its security lasts exactly as long as the last copy stays in the room.Photograph — collection credit

Pseudorandom number generators — the algorithms that computers use to simulate randomness — are subtler failures. A good one produces output indistinguishable from random by standard statistical tests. But it is still a deterministic process: given the same seed, it produces the same sequence, and anyone who learns the seed can reconstruct the key in its entirety. For most computational purposes this is acceptable. For a one-time pad it is catastrophic, because the security proof makes no allowance for a key that could, even in principle, be reconstructed.

True randomness requires a physical process whose outcome is genuinely unpredictable: radioactive decay, thermal noise in an electronic circuit, photon arrival times at a half-silvered mirror. These are sources whose outputs cannot be derived from prior knowledge, however complete that knowledge is. Even then, the raw physical output must be carefully conditioned — biases in hardware removed, correlations checked — before the material can be trusted as key.

The gap between "looks random enough" and "is random" is where the one-time pad's mathematical perfection meets the messy world of its implementation. The proof is airtight. The requirement it imposes on key generation is not something human attention or clever software can reliably satisfy.

A sealed envelope with a signature across the flap
A signature across the flap proves the envelope was not opened. It says nothing about whether the contents were read.Photo: Melike B / Pexels