Interfaces for reading entropy from a PRG320 hardware random number generator (HWRNG) by Ingenieurbüro Bergmann, connected via USB serial (FTDI FT232R).
- Device: PRG320
- Interface: USB serial (appears as
/dev/ttyUSB0,/dev/ttyUSB1, ...) - Baud rate: 921600
- Output: raw bytes terminated by
\n
Multiple devices are supported simultaneously.
$ nix-shell
$ cargo build --releaseReads a single sample from /dev/ttyUSB0 and prints JSON to stdout.
$ cargo run{
"hex": "a3f1...",
"int": 174832...,
"raw": "[163, 241, ...]"
}Streams live entropy data from all connected USB serial devices.
$ cargo run --bin serveStarts two listeners:
| Port | Protocol | Description |
|---|---|---|
| 3003 | HTTP | Web UI, REST API and SSE stream |
| 3004 | TCP | Raw hex stream (newline-delimited) |
Open http://localhost:3003 in a browser. Each connected device gets a live-updating panel showing the current hex output. A Stop/Start button pauses and resumes the stream.
All endpoints return a JSON array with one entry per device. Samples are collected fresh on each request (up to 15 s timeout).
| Endpoint | Response fields |
|---|---|
GET /api |
timestamp, hex, int, raw |
GET /api/hex |
timestamp, hex |
GET /api/int |
timestamp, int |
GET /api/raw |
timestamp, raw |
timestampis Unix epoch milliseconds recorded immediately after the port read completes.rawis the debug representation of the byte slice, e.g.,[163, 241, 10].
Example:
$ curl http://localhost:3003/api/hex[{"timestamp": 1750000000123, "hex": "a3f10a..."}]$ curl -N http://localhost:3003/streamEmits one event per sample across all devices:
data: {"device":"/dev/ttyUSB0","hex":"a3f10a","int":"10743050"}
Connect with netcat to receive a continuous newline-delimited HEX stream:
$ nc localhost 3004a3f10a...
c72e91...
Each line is the hex-encoded output of one sample. Multiple concurrent clients are supported. The connection closes cleanly when the client disconnects.
rngd (from rng-tools) reads from a entropy source and writes into the kernel entropy pool (/dev/random), increasing the available entropy for cryptographic operations.
Configure the port baud rate and hand it to rngd:
$ stty -F /dev/ttyUSB0 921600 raw -echo
$ rngd -r /dev/ttyUSB0 -o /dev/randomFor multiple devices, run one rngd instance per port.
The TCP endpoint emits hex-encoded samples. Decode on the fly and pipe into rngd using a named pipe:
$ mkfifo /tmp/entropy
$ nc localhost 3004 | xxd -r -p > /tmp/entropy &
$ rngd -r /tmp/entropy -o /dev/random -frngtest (also from rng-tools) runs FIPS 140-2 statistical tests against the byte stream:
$ nix-shell -p rng-tools tinyxxd
$ nc localhost 3004 | xxd -r -p | rngtest -c 1000
rngtest 6.17
Copyright (c) 2004 by Henrique de Moraes Holschuh
This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
rngtest: starting FIPS tests...
rngtest: bits received from input: 10000032
rngtest: FIPS 140-2 successes: 500
rngtest: FIPS 140-2 failures: 0
rngtest: FIPS 140-2(2001-10-10) Monobit: 0
rngtest: FIPS 140-2(2001-10-10) Poker: 0
rngtest: FIPS 140-2(2001-10-10) Runs: 0
rngtest: FIPS 140-2(2001-10-10) Long run: 0
rngtest: FIPS 140-2(2001-10-10) Continuous run: 0
rngtest: input channel speed: (min=1.483; avg=41.093; max=19531250.000)Kibits/s
rngtest: FIPS tests speed: (min=60.551; avg=171.389; max=323.279)Mibits/s
rngtest: Program run time: 250446315 microsecondsA healthy PRG320 output should produce zero failures across all test categories.