HKDF is a multi-purpose key derivation function built on the HMAC message authentication code. It follows an extract-then-expand approach: the extract stage pulls a fixed-length pseudorandom key out of input keying material, and the expand stage turns that key into one or more independent pseudorandom keys of the length an application needs. HKDF was formally described in RFC 5869 in 2010, based on analysis by Hugo Krawczyk, and was proposed as a single well-analyzed building block so that protocols and applications needing key extraction, key expansion, or key hierarchies would not each invent their own derivation scheme.
Sources
Reader Challenges (0)
No disputes yet. Spotted an error or a better source? Open the first one.
Sign in to dispute this or suggest a correction.