The Commons Math User Guide - Data Generation Phil Steitz

The Commons Math random package includes utilities for

  • generating random numbers
  • generating random strings
  • generating cryptographically secure sequences of random numbers or strings
  • generating random samples and permuations
  • analyzing distributions of values in an input file and generating values "like" the values in the file
  • generating data for grouped frequency distributions or histograms

The org.apache.commons.math.RandomData interface defines methods for generating random sequences of numbers. The API contracts of these methods use the following concepts:

Random sequence of numbers from a probability distribution
There is no such thing as a single "random number." What can be generated are sequences of numbers that appear to be random. When using the built-in JDK function Math.random(), sequences of values generated follow the Uniform Distribution, which means that the values are evenly spread over the interval between 0 and 1, with no sub-interval having a greater probability of containing generated values than any other interval of the same length. The mathematical concept of a probability distribution basically amounts to asserting that different ranges in the set of possible values for of a random variable have different probabilities of containing the value. Commons Math supports generating random sequences from the following probability distributions. The javadoc for the nextXxx methods in RandomDataImpl describes the algorithms used to generate random deviates from each of these distributions.
Cryptographically secure random sequences
It is possible for a sequence of numbers to appear random, but nonetheless to be predictable based on the algorithm used to generate the sequence. If in addition to randomness, strong unpredictability is required, it is best to use a secure random number generator to generate values (or strings). The nextSecureXxx methods in the RandomDataImpl implementation of the RandomData interface use the JDK SecureRandom pseudo-random number generator (PRNG) to generate cryptographically secure sequences. The setSecureAlgorithm method allows you to change the underlying PRNG. These methods are much slower than the corresponding "non-secure" versions, so they should only be used when cryptographic security is required.
Seeding pseudo-random number generators
By default, the implementation provided in RandomDataImpl uses the JDK-provided PRNG. Like other PRNGs, the JDK generator generates sequences of random numbers based on an initial "seed value". For the non-secure methods, starting with the same seed always produces the same sequence of values. Secure sequences started with the same seeds will diverge. When a new RandomDataImpl is created, the underlying random number generators are not intialized. The first call to a data generation method, or to a reSeed() method initializes the appropriate generator. If you do not explicitly seed the generator, it is by default seeded with the current time in milliseconds. Therefore, to generate sequences of random data values, you should always instantiate one RandomDataImpl and use it repeatedly instead of creating new instances for subsequent values in the sequence. For example, the following will generate a random sequence of 50 long integers between 1 and 1,000,000, using the current time in milliseconds as the seed for the JDK PRNG:

        RandomDataImpl randomData = new RandomDataImpl(); 
        for (int i = 0; i < 1000; i++) {
            value = randomData.nextLong(1, 1000000);
        }
    
The following will not in general produce a good random sequence, since the PRNG is reseeded each time through the loop with the current time in milliseconds:

        for (int i = 0; i < 1000; i++) {
            RandomDataImpl randomData = new RandomDataImpl(); 
            value = randomData.nextLong(1, 1000000);
        }
    
The following will produce the same random sequence each time it is executed:

        RandomDataImpl randomData = new RandomDataImpl(); 
        randomData.reSeed(1000);
        for (int i = 0; i = 1000; i++) {
            value = randomData.nextLong(1, 1000000);
        }
    
The following will produce a different random sequence each time it is executed.

        RandomDataImpl randomData = new RandomDataImpl(); 
        randomData.reSeedSecure(1000);
        for (int i = 0; i < 1000; i++) {
            value = randomData.nextSecureLong(1, 1000000);
        }
    

The methods nextHexString and nextSecureHexString can be used to generate random strings of hexadecimal characters. Both of these methods produce sequences of strings with good dispersion properties. The difference between the two methods is that the second is cryptographically secure. Specifically, the implementation of nextHexString(n) in RandomDataImpl uses the following simple algorithm to generate a string of n hex digits:

  1. n/2+1 binary bytes are generated using the underlying Random
  2. Each binary byte is translated into 2 hex digits
The RandomDataImpl implementation of the "secure" version, nextSecureHexString generates hex characters in 40-byte "chunks" using a 3-step process:
  1. 20 random bytes are generated using the underlying SecureRandom.
  2. SHA-1 hash is applied to yield a 20-byte binary digest.
  3. Each byte of the binary digest is converted to 2 hex digits
Similarly to the secure random number generation methods, nextSecureHexString is much slower than the non-secure version. It should be used only for applications such as generating unique session or transaction ids where predictability of subsequent ids based on observation of previous values is a security concern. If all that is needed is an even distribution of hex characters in the generated strings, the non-secure method should be used.

To select a random sample of objects in a collection, you can use the nextSample method in the RandomData interface. Specifically, if c is a collection containing at least k objects, and ranomData is a RandomDataImpl instance randomData.nextSample(c, k) will return an object[] array of length k consisting of elements randomly selected from the collection. If c contains duplicate references, there may be duplicate references in the returned array; otherwise returned elements will be unique -- i.e., the sampling is without replacement among the object references in the collection.

If randomData is a RandomDataImpl instance, and n and k are integers with k <= n, then randomData.nextPermutation(n, k) returns an int[] array of length k whose whose entries are selected randomly, without repetition, from the integers 0 through n-1 (inclusive), i.e., randomData.nextPermutation(n, k) returns a random permutation of n taken k at a time.

This is yet to be written. Any contributions will be gratefully accepted!