Technology Probability & Simulation Computer Science 18 min read Updated October 4, 2026
BY: Statistics Fundamentals Team

PRNG vs TRNG: How Random Number Generators Work

A random number generator turns an initial source of uncertainty or a stored internal state into numbers that are useful for simulation, sampling, games, and security. The mechanism matters because a sequence that is excellent for a Monte Carlo study may still be a poor choice for a password or session token.

💡
Quick answer: How do random number generators work?

Computers generate random numbers in several ways. A PRNG uses a deterministic algorithm and an internal state initialized from a seed, so its sequence can be reproduced when the same generator and state are restored. A TRNG derives uncertainty from physical measurements. Security-sensitive systems commonly combine entropy from physical or operating-system sources with a cryptographically secure PRNG that produces random bytes efficiently.

PRNG vs CSPRNG vs TRNG at a Glance

The word random covers more than one property. A generator can look statistically random yet remain predictable to someone who knows its state. It can also be deterministic and still be exactly what a reproducible simulation needs. The table separates the three categories that are most often mixed together.

FeaturePRNGCSPRNGTRNG
SourceAlgorithm + internal stateCryptographic algorithm + secret/unpredictable stateMeasured physical process
Deterministic?YesUsually yes after initializationNot in the intended source model
Reproducible?Yes, when generator/state setup is the samePossible if the exact state is restored, though that is normally undesirable in security useGenerally no
SpeedHighHigh enough for most software security needsOften lower and hardware-dependent
Best fitSimulation, sampling, games, randomized algorithmsKeys, tokens, nonces, salts, password generationEntropy collection, seeding, specialized hardware randomness
Main limitationOrdinary PRNG output may be predictable from stateSecurity depends on sound design, seeding and state protectionPhysical sources can be biased or fail and usually need testing/conditioning

What Is a Random Number Generator?

A random number generator, or RNG, is a system that produces values intended to behave randomly for a particular purpose. That purpose defines what “good randomness” means.

For a statistics course, the priority may be a long sequence with low correlation and the ability to repeat an experiment. For cryptography, the central requirement is different: an observer should not be able to predict future output from what they have already seen. A hardware entropy source has another job again. It tries to capture unpredictable information from a physical process.

This is why a single label such as “random” is too vague. Useful questions are: Is the generator deterministic? Can the sequence be reproduced? How much uncertainty enters the system? Are outputs statistically well behaved? Can an adversary predict future values?

Why Computers Need Random Numbers

Randomness is built into many ordinary computing and statistical tasks. A simulation may draw millions of values from a probability distribution. A randomized experiment may assign participants to groups. A game may shuffle a deck. A security system may create a session token that must be hard to guess.

Those jobs do not impose identical requirements. A simulation benefits from reproducibility; a login token does not. A fast general-purpose generator can be ideal for a Monte Carlo model and unacceptable for authentication. That split is the reason multiple RNG families exist.

If you are reviewing the probability ideas behind simulation, start with the site’s Statistics and Probability hub and Random Variables guide. To see repeated sampling visually, use the Sampling Distribution Simulator.

How Pseudorandom Number Generators Work

A pseudorandom number generator (PRNG) is a deterministic algorithm that expands a finite internal state into a sequence of values with useful random-like statistical behavior. “Pseudorandom” does not mean useless or low quality. It means the sequence is generated by a deterministic rule.

SeedInitial input used to initialize the generator
Internal stateThe generator's current stored configuration
AlgorithmUpdates state and produces the next output
OutputA random-looking value used by the application
PRNG pipeline: the seed initializes internal state, then a deterministic update rule produces output and advances that state.

The seed initializes state

A seed is input used to initialize a PRNG. It is not simply “the first random number.” Many generators expand the seed into a larger internal state through an initialization routine.

If the same algorithm, seed, implementation and state procedure are used, a PRNG can reproduce the same sequence. That is a feature in statistics. It allows a researcher to rerun a simulation, lets a student compare results with an instructor, and makes a failing test case easier to debug.

Internal state determines what comes next

The state is the information a deterministic generator carries between outputs. Each generation step reads the current state, computes an output, and updates the state. Knowing only a seed is not always enough to describe a generator at some later point; the complete state can be much larger.

This also explains why ordinary software is not automatically random. If a deterministic program has the same algorithm, inputs and complete state, it follows the same path.

Finite state creates a period

A PRNG has a finite number of possible internal states. Eventually it must return to a state it has used before. From that point, the same later sequence repeats. The number of steps before repetition is called the period.

Modern generators can have extremely long periods, but period length is only one quality measure. Correlation, distributional behavior and performance in high dimensions matter too. A long period does not make a generator cryptographically secure.

A Simple PRNG Example: Linear Congruential Generator

A linear congruential generator (LCG) is useful for showing the mechanism because its rule fits on one line. It is an educational example, not a recommendation for security-sensitive work.

Simple illustrative PRNG Xₙ₊₁ = (aXₙ + c) mod m

Here, Xₙ is the current state, a is a multiplier, c is an increment, and m is the modulus. For a tiny example, choose a = 5, c = 3, m = 16 and seed X₀ = 7.

Seed X₀
7
X₁
6
X₂
1
X₃
8
X₄
11
X₅
10

The numbers look irregular, yet every value is fixed by the previous state and the formula. With these parameters the tiny state space eventually cycles back. Real simulation generators use much larger states and more sophisticated update functions.

⚠️
Do not use this LCG example for passwords, tokens or keys

The formula is included to make deterministic state updates visible. Security-sensitive randomness should come from a documented cryptographic random API or CSPRNG.

What Is a True Random Number Generator?

A true random number generator (TRNG) obtains uncertainty by measuring a physical process rather than generating every output from a deterministic state-transition rule. Depending on the hardware, the source may involve thermal or electronic noise, oscillator jitter, avalanche noise, or quantum effects.

The phrase “true random” can mislead if it suggests that raw sensor readings are ready to use. Physical measurements can contain bias, environmental artifacts or hardware faults. A robust design therefore treats raw measurements as input to a pipeline, not as finished random bits.

Physical processNoise, jitter or another entropy source
MeasurementHardware samples the source
Health testsCheck whether the source behaves within expected bounds
ConditioningReduces bias and produces usable random bits
TRNG pipeline: physical uncertainty is measured, checked and often conditioned before software consumes the resulting bits.

Where TRNG Entropy Comes From

In random-number systems, entropy is a measure related to uncertainty or unpredictability in a source. It should not be confused with thermodynamic entropy. Security engineering often cares about conservative estimates of unpredictability, which is why entropy-source validation is more involved than simply watching whether zeros and ones appear evenly.

NIST SP 800-90B treats an entropy source as a designed component with a noise source, health testing and, where used, conditioning. The important idea for beginners is that physical randomness has to be measured and engineered. “Hardware” by itself is not a guarantee of security.

What Is a Cryptographically Secure PRNG?

A cryptographically secure pseudorandom number generator (CSPRNG) is a deterministic generator designed so that its output remains computationally difficult to predict under its security model. It is still a PRNG. Its security does not come from being physically nondeterministic at every output step.

A secure design depends on strong algorithms, unpredictable initialization, protected internal state and correct use of the platform API. This is why an ordinary simulation PRNG and a CSPRNG should not be placed in the same security category.

Current Python documentation illustrates the distinction clearly: the standard random module is designed for modeling and simulation and is not suitable for cryptographic purposes, while secrets is intended for cryptographically strong random values such as authentication tokens. In browsers, MDN gives the parallel warning that Math.random() is not cryptographically secure and points security-sensitive code to crypto.getRandomValues().

Python: reproducible simulation randomness import random rng = random.Random(12345) values = [rng.random() for _ in range(3)] # Re-create the same generator setup to reproduce the sequence. rng_again = random.Random(12345) values_again = [rng_again.random() for _ in range(3)]

The example above is useful for teaching and simulation. For secrets, use the platform’s documented secure randomness interface instead of swapping in a time-based seed or another easy-to-guess value.

How Modern Random-Number Systems Combine Entropy and PRNGs

PRNG versus TRNG is not always an either-or architecture. Modern secure systems often collect entropy, use it to initialize or refresh secure state, then expand that state with a fast CSPRNG. This combines external unpredictability with efficient deterministic generation.

Entropy sourcesHardware and/or operating-system events
System random stateEntropy is accumulated and managed
CSPRNGSecure deterministic generation
Application bytesTokens, nonces, salts and other random values
A common secure architecture combines entropy sources with a cryptographic deterministic generator. NIST SP 800-90C formalizes constructions that combine the concepts defined in SP 800-90A and SP 800-90B.

Statistical Randomness vs Cryptographic Security

Statistical tests look for patterns that would be unlikely under a target model. Examples include unexpected bias, runs, serial dependence and other distributional defects. Passing such tests is useful evidence that a generator does not show certain obvious problems.

It is not proof of security. A deterministic generator could pass a large battery of statistical tests while remaining predictable to someone who knows its state. NIST’s statistical-test guidance makes this separation explicit: statistical testing cannot replace cryptanalysis.

The reverse point matters too. A generator designed for security still needs sound implementation and good entropy. The label “cryptographic” is not a shortcut around engineering.

How Random Numbers Are Used in Statistics

Statistics often favors high-quality noncryptographic PRNGs because they are fast, reproducible and designed to support repeated numerical work. Common uses include Monte Carlo simulation, bootstrap methods, random sampling, permutation procedures and stochastic algorithms.

A Monte Carlo calculation may require millions or billions of generated values. Reproducibility lets another analyst run the same experiment with the same software setup and inspect the same sequence. That is very different from a security token, where predictability would defeat the purpose.

For related concepts, see Sampling Distributions, Bootstrap Sampling, and Markov Chain Monte Carlo.

Why Seeds Matter in Reproducible Research

Suppose a researcher runs a simulation with seed 12345 and records the software version and generator configuration. A collaborator can recreate the same setup and obtain the same pseudorandom stream. This makes it much easier to check a result, isolate a bug or compare two methods under identical random inputs.

The wording “same seed gives the same sequence” needs one qualification: it is safest within the same generator and compatible implementation. Different algorithms can interpret the same seed differently, and software defaults can change over time. A reproducible workflow should therefore record the seed, generator choice and relevant software version.

✓
Reproducibility is a feature, not a defect

For simulation and teaching, controlled repeatability is often exactly what you want. For security secrets, it is the opposite: the state must be unpredictable and protected.

How Randomness Tests Work

A randomness test does not ask whether a sequence “feels random.” It checks a specific statistical property. One test may look for too many long runs of identical bits. Another may examine frequency balance or correlations. A test suite combines multiple checks because no single statistic captures every defect.

Results are interpreted probabilistically. An occasional unusual test result can occur even for a sound generator, while repeated or systematic failures can indicate a problem. For cryptographic generators, statistical testing is only one layer of evaluation. Algorithm design, entropy quality and adversarial unpredictability require separate analysis.

Common RNG Misconceptions

“PRNG means fake randomness.”

PRNGs are deterministic, but high-quality PRNGs can have excellent statistical behavior and are standard tools for simulation and sampling.

“TRNG is always better.”

TRNGs and PRNGs solve different problems. Physical sources can be slower, biased or faulty and often require conditioning.

“A long period means secure.”

Period tells you when a deterministic state cycle repeats. It does not guarantee unpredictability against an attacker.

“Time is a secure seed.”

A timestamp can add variation, but it may have limited unpredictability. Security-sensitive code should use the platform’s secure random facility.

“Passing tests proves cryptographic safety.”

Statistical tests can detect certain patterns. They do not prove resistance to state recovery or prediction.

“CSPRNG means physical randomness every time.”

A CSPRNG is normally deterministic after initialization. Its output security comes from strong state, algorithms and proper seeding.

Which Type of RNG Should You Use?

Simulation

Use a quality PRNG

Prioritize speed, statistical quality, long usable streams and reproducibility. Record the generator and seed when reproducibility matters.

Passwords, tokens, keys

Use a CSPRNG through a secure platform API

Do not build your own security generator from a general-purpose PRNG, timestamp or simple formula.

Entropy collection

Use a validated entropy source or TRNG design

Physical sources should be monitored and conditioned according to the system’s requirements.

Games and procedural generation

Usually use a general-purpose PRNG

Repeatable worlds and deterministic replays can be valuable. Security-sensitive or adversarial settings may need a CSPRNG instead.

If you simply want to generate values for an exercise, try the site’s Random Number Generator or the visual Random Number Generator tool. For list selection, use the Random Name Picker. For password creation, use the dedicated Random Password Generator rather than assuming an ordinary random-number function is suitable for security.

FAQs About Random Number Generators

Some are generated deterministically by PRNGs, so the sequence can be reproduced from the same state. Other systems collect entropy from physical processes. Secure operating-system random facilities often combine entropy collection with a CSPRNG, so a simple yes-or-no answer misses how modern systems are built.

A PRNG uses a deterministic algorithm and internal state to produce random-looking values. A TRNG measures a physical process to obtain unpredictable information. PRNGs are fast and reproducible; TRNGs provide physical entropy but may require health testing and conditioning.

A CSPRNG is a cryptographically secure pseudorandom number generator. It is a deterministic generator designed to make future outputs computationally difficult to predict when it is correctly initialized and its internal state remains protected.

A seed is input used to initialize a generator’s internal state. In simulation, saving the seed and generator setup can make a run reproducible. In security, the initialization material needs sufficient unpredictability and should come from a secure source.

Because an ordinary PRNG is deterministic. The same compatible generator, initialization procedure and seed lead to the same initial state, so the same state-update rules reproduce the same sequence. Different generators or software versions are not guaranteed to interpret the same seed identically.

Yes. A PRNG has finite state, so eventually it must revisit a previous state and repeat the following sequence. Good generators can have periods so large that repetition is irrelevant for normal use, but a long period alone does not establish quality or security.

No. Current MDN documentation states that Math.random() does not provide cryptographically secure random numbers. Browser code that needs security-sensitive random values should use the Web Crypto API, such as crypto.getRandomValues(), or a higher-level secure API suited to the task.

PRNGs are fast, reproducible and convenient, which makes them well suited to simulation and numerical work. Secure systems can also use physical or operating-system entropy to seed a CSPRNG, then generate large amounts of unpredictable output efficiently.

Key Takeaways

PRNG: deterministic generation from state. Best known for simulation, sampling and reproducible numerical work.

CSPRNG: deterministic generation engineered for computational unpredictability. Use it for security-sensitive randomness.

TRNG: physical entropy generation. Raw measurements usually need engineering controls such as health tests and conditioning.

Modern secure systems often combine them: entropy initializes secure state, then a CSPRNG produces application-ready random bytes efficiently.

Sources and Technical References

Security and implementation details can change, so this page favors current standards and official documentation for software-specific claims.

  1. NIST SP 800-90A Rev. 1: Deterministic Random Bit Generators
  2. NIST SP 800-90B: Entropy Sources Used for Random Bit Generation
  3. NIST SP 800-90C: Random Bit Generator Constructions
  4. NIST SP 800-22 Rev. 1a: Statistical Test Suite for Random and Pseudorandom Number Generators
  5. MDN: Math.random()
  6. MDN: Crypto.getRandomValues()
  7. Python documentation: random
  8. Python documentation: secrets