Skip to main content

Module blake2

Module blake2 

Source
Expand description

RFC 7693 BLAKE2b.

Not FIPS-approved. BLAKE2b is here because Argon2 is defined in terms of it: ic_kdf::argon2 needs both the plain hash and the variable-length H' construction built on top of it. It is a perfectly good general-purpose hash — faster than SHA-512 on 64-bit hardware, and keyed without needing HMAC — but the ontology marks it not-approved, so ic-fips blocks it in approved mode.

Unlike the SHA-2 and SHA-3 types, BLAKE2b has a variable output length chosen at construction, which does not fit the fixed-size Digest contract. It therefore exposes its own API rather than pretending to be a fixed-width digest.

Structs§

Blake2b
A BLAKE2b hasher with a caller-chosen output length.

Constants§

BLOCK_LEN
Block size in bytes.
MAX_KEY_LEN
Largest key accepted in keyed mode.
MAX_OUTPUT_LEN
Largest digest this produces.

Functions§

blake2b_long
The Argon2 variable-length hash H'.