pub struct Hkdf<M: Mac>(/* private fields */);Expand description
HKDF instantiated with the MAC M.
Implementations§
Source§impl<M: Mac> Hkdf<M>
impl<M: Mac> Hkdf<M>
Sourcepub fn extract(salt: &[u8], ikm: &[u8], prk: &mut [u8]) -> Result<()>
pub fn extract(salt: &[u8], ikm: &[u8], prk: &mut [u8]) -> Result<()>
HKDF-Extract: compress arbitrary input keying material into a PRK.
An empty salt is replaced by HashLen zero bytes, as RFC 5869 requires.
Sourcepub fn expand(prk: &[u8], info: &[u8], out: &mut [u8]) -> Result<()>
pub fn expand(prk: &[u8], info: &[u8], out: &mut [u8]) -> Result<()>
HKDF-Expand: stretch a PRK to out.len() bytes bound to info.
Keys a MAC with prk for every block of output. Deriving several
outputs from one PRK – TLS 1.3 takes a key, an IV and a finished key
from each traffic secret – is cheaper through Self::expand_from,
which keys once.
Sourcepub fn expand_from(keyed: &M, info: &[u8], out: &mut [u8]) -> Result<()>where
M: Clone,
pub fn expand_from(keyed: &M, info: &[u8], out: &mut [u8]) -> Result<()>where
M: Clone,
HKDF-Expand from a MAC already keyed with the PRK.
keyed is M::new(prk), made once and kept. Each block of output
starts from a clone of it rather than from the key, so the key setup
– for HMAC, two compressions of the padded key – is paid when keyed
is made and not again per call or per block. The output is exactly
Self::expand’s for the same PRK.
RFC 5869 requires the PRK to be at least HashLen bytes. expand
checks that; here the key is already inside keyed, so making it from
a PRK of the right length is the caller’s part.