Related Experiment Video
Updated: Nov 27, 2025

Author Spotlight: Advancing the Study of Brain-Heart Interplay with a Comprehensive EEGLAB Plugin for Multimodal Signal Analysis
Published on: April 26, 2024
Heartbeats Do Not Make Good Pseudo-Random Number Generators: An Analysis of the Randomness of Inter-Pulse Intervals
Lara Ortiz-Martin1, Pablo Picazo-Sanchez2, Pedro Peris-Lopez1
1Department of Computer Science, Carlos III University of Madrid, 28911 Leganés, Spain.
This study investigates whether the timing between heartbeats, known as inter-pulse intervals, can reliably generate secure random numbers for encryption. By testing large public datasets, the researchers found that these biological signals lack the necessary randomness for cryptographic use, challenging current security protocols.
Area of Science:
- Cybersecurity research within Inter-Pulse Intervals analytics
- Biometric authentication systems engineering
Background:
No prior work had resolved the true entropy potential of human cardiac rhythms for secure data encryption. That uncertainty drove the need for rigorous statistical validation of biometric signal sources. It was already known that wearable medical devices require robust authentication mechanisms to protect sensitive patient information. Researchers previously suggested that the timing between consecutive heartbeats might serve as a viable foundation for generating cryptographic keys. This gap motivated a comprehensive evaluation of whether these biological signals possess sufficient unpredictability. Prior research has shown that various authentication protocols rely on this assumption without extensive empirical verification. The field lacked a large-scale analysis to confirm if these physiological patterns meet the strict requirements for random number generation. This study addresses the discrepancy between theoretical proposals and the practical statistical properties of cardiac data.
Purpose Of The Study:
The aim of this study is to determine if the timing between heartbeats can serve as a reliable source of entropy for cryptographic applications. Researchers sought to investigate the widespread assumption that these biological signals are suitable for secure biometric authentication. The project addresses the growing concern regarding the security of wearable and implantable medical devices. Many existing protocols rely on the unpredictability of cardiac rhythms without sufficient empirical validation. This study was motivated by the need to verify whether such physiological data meets the rigorous standards required for generating secure keys. The authors identified a gap in the literature where theoretical proposals lacked large-scale statistical evidence. By analyzing a massive collection of public data, the team intended to resolve the uncertainty surrounding this biometric approach. This work provides a critical assessment of the feasibility of using cardiac signals for future security schemes.
Main Methods:
The review approach involved a large-scale statistical examination of 19 public electrocardiogram datasets. Researchers accessed these files through the Physionet repository to ensure a diverse and representative sample size. The team processed signals from 1353 distinct subjects to evaluate the consistency of their findings. They extracted the timing between consecutive heartbeats to form the primary data for analysis. A standard battery of randomness tests was then applied to these extracted values. This systematic procedure allowed the investigators to quantify the entropy present within the cardiac rhythms. The design focused on comparing these biological measurements against established mathematical criteria for unpredictability. This rigorous methodology ensured that the evaluation remained independent of specific device hardware or proprietary software constraints.
Main Results:
The key findings from the literature indicate that inter-pulse intervals do not function as a high-quality source of randomness. Statistical analysis of the 1353 subjects revealed significant patterns that contradict the assumption of unpredictability. The tests consistently showed that these biological signals fail to meet the standards required for cryptographic purposes. This result holds true across the various sampling frequencies and recording lengths present in the public datasets. The data suggests that the entropy levels are insufficient for generating secure keys in modern authentication protocols. These findings directly challenge the validity of previous research that proposed using cardiac timing for security. The study provides evidence that these signals contain predictable structures that could be exploited. Consequently, the reliance on such metrics for encryption is statistically unsupported by the observed data.
Conclusions:
The authors demonstrate that heartbeat timing fails to provide a reliable source of entropy for cryptographic applications. Their findings suggest that current authentication protocols relying on this biological signal may be inherently insecure. The researchers propose that designers must reconsider the use of these intervals for generating secure keys. This synthesis indicates that physiological signals do not inherently possess the statistical complexity required for high-level security. The study implies that future schemes should avoid relying solely on these cardiac metrics for randomness. These results highlight a significant limitation in existing biometric security frameworks. The authors conclude that further exploration is needed to identify more robust alternatives for device authentication. Their work serves as a warning against the unverified adoption of biological rhythms in cryptographic system design.
Frequently Asked Questions
The researchers propose that inter-pulse intervals lack sufficient entropy for secure cryptographic operations. Statistical testing revealed that these biological signals do not meet the randomness requirements necessary for generating reliable encryption keys, unlike traditional pseudo-random number generators.
The study utilized a standard battery of randomness tests to evaluate the statistical properties of the extracted data. These tests measure various indicators of unpredictability, such as frequency distribution and serial correlation, to determine if the signals behave like true random sequences.
Large-scale analysis was necessary because smaller samples might fail to capture the underlying patterns or lack of randomness in cardiac rhythms. By examining 1353 subjects, the authors ensured their conclusions were not skewed by individual variations or short recording durations.
The researchers used 19 public electrocardiogram datasets from the Physionet repository. This data type provided the raw timing information between heartbeats, allowing the team to extract the intervals needed for their statistical evaluation of entropy.
The team measured the time elapsed between consecutive heartbeats across varying sampling frequencies and recording lengths. They compared these measurements against standard statistical benchmarks to see if the intervals exhibited the complexity required for secure key generation.
The authors state that their findings challenge the security of existing authentication protocols. They suggest that designers must move away from these specific biological signals when developing future systems that require high levels of cryptographic protection.
Related Concept Videos
Pulse rhythm
Conversely, an irregular pulse pattern is termed dysrhythmia, stemming from disruptions in cardiac...
Disturbances in Heart Rhythm
Arrhythmias are categorized by their speed, rhythm, and origin. A slow heart...
Special considerations while measuring pulse
Pulse
The pulse serves as a clinical...
Pulse
Pulse Rate and its Significance
Pulse rate, often measured in beats per minute (bpm), reflects the heart rate (HR), which is influenced by numerous factors such as stress, physical activity, and hormonal changes. A normal resting adult pulse rate falls...
Regulation of Pulse

