In this paper we explore pseudo-random number generation on the IBM 4758 Secure Crypto Coprocessor. In particular we compare
several variants of Gennaro’s provably secure generator, proposed at Crypto 2000, with more standard techniques based on the
SHA-1 compression function. Our results show how the presence of hardware support for modular multiplication and exponentiation
affects these algorithms.