Hkdf Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Hkdf.cs
Provides the HMAC-based Extract-and-Expand Key Derivation Function (HKDF) defined in RFC 5869, exposing the
Extract, Expand, and combined DeriveKey stages over the SHA-1 and SHA-2 family of hash
algorithms. This class cannot be instantiated.
public static class Hkdf
- Inheritance
-
Hkdf
- Inherited Members
Examples
byte[] key = Hkdf.DeriveKey(
HashAlgorithmName.SHA256,
inputKeyingMaterial: sharedSecret,
outputLength: 32,
salt: salt,
info: "app v1 traffic key"u8);
Remarks
HKDF turns input keying material that is merely high-entropy - such as a Diffie-Hellman shared secret - into one or
more cryptographically strong, fixed-length keys.
Extract(HashAlgorithmName, ReadOnlySpan<byte>, ReadOnlySpan<byte>) concentrates the entropy of the
input into a pseudorandom key (PRK) of one hash length;
Expand(HashAlgorithmName, ReadOnlySpan<byte>, int, ReadOnlySpan<byte>) stretches that PRK into output
keying material of any requested length, optionally bound to an application-specific info context.
DeriveKey(HashAlgorithmName, ReadOnlySpan<byte>, int, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
performs both stages in one call.
The surface mirrors the BCL's HKDF so the two are interchangeable. The supported hash algorithms are SHA1, SHA256, SHA384, and SHA512. Prefer the platform HKDF where it covers your need; this type exists to give the rest of the library a self-contained HKDF surface (for example, the HPKE labeled KDF).
Like the rest of the library, this implementation offers best-effort side-channel resistance and has not been independently audited.
Methods
DeriveKey(HashAlgorithmName, ReadOnlySpan<byte>, int, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Performs the RFC 5869 extract and expand stages in one call, deriving outputLength bytes of
output keying material directly from inputKeyingMaterial.
public static byte[] DeriveKey(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> inputKeyingMaterial, int outputLength, ReadOnlySpan<byte> salt = default, ReadOnlySpan<byte> info = default)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
inputKeyingMaterialReadOnlySpan<byte>The input keying material to derive from.
outputLengthintThe number of bytes to produce.
saltReadOnlySpan<byte>The optional non-secret salt. When empty, a string of hash-length zero bytes is used.
infoReadOnlySpan<byte>The optional context and application-specific information.
Returns
- byte[]
The output keying material,
outputLengthbytes long.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm.- ArgumentOutOfRangeException
outputLengthis not between 1 and 255 times the hash length.
DeriveKey(HashAlgorithmName, ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Performs the RFC 5869 extract and expand stages in one call, writing the output keying material into
output.
public static void DeriveKey(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> inputKeyingMaterial, Span<byte> output, ReadOnlySpan<byte> salt = default, ReadOnlySpan<byte> info = default)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
inputKeyingMaterialReadOnlySpan<byte>The input keying material to derive from.
outputSpan<byte>The span that receives the output keying material; its length determines how many bytes are produced.
saltReadOnlySpan<byte>The optional non-secret salt. When empty, a string of hash-length zero bytes is used.
infoReadOnlySpan<byte>The optional context and application-specific information.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm.- ArgumentOutOfRangeException
outputis empty or longer than 255 times the hash length.
Expand(HashAlgorithmName, ReadOnlySpan<byte>, int, ReadOnlySpan<byte>)
Performs the RFC 5869 expand stage, stretching pseudoRandomKey into
outputLength bytes of output keying material.
public static byte[] Expand(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> pseudoRandomKey, int outputLength, ReadOnlySpan<byte> info = default)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
pseudoRandomKeyReadOnlySpan<byte>The pseudorandom key produced by Extract(HashAlgorithmName, ReadOnlySpan<byte>, ReadOnlySpan<byte>).
outputLengthintThe number of bytes to produce.
infoReadOnlySpan<byte>The optional context and application-specific information.
Returns
- byte[]
The output keying material,
outputLengthbytes long.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm, orpseudoRandomKeyis shorter than one hash length.- ArgumentOutOfRangeException
outputLengthis not between 1 and 255 times the hash length.
Expand(HashAlgorithmName, ReadOnlySpan<byte>, Span<byte>, ReadOnlySpan<byte>)
Performs the RFC 5869 expand stage, writing the output keying material into output.
public static void Expand(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> pseudoRandomKey, Span<byte> output, ReadOnlySpan<byte> info = default)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
pseudoRandomKeyReadOnlySpan<byte>The pseudorandom key produced by Extract(HashAlgorithmName, ReadOnlySpan<byte>, ReadOnlySpan<byte>).
outputSpan<byte>The span that receives the output keying material; its length determines how many bytes are produced.
infoReadOnlySpan<byte>The optional context and application-specific information.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm, orpseudoRandomKeyis shorter than one hash length.- ArgumentOutOfRangeException
outputis empty or longer than 255 times the hash length.
Extract(HashAlgorithmName, ReadOnlySpan<byte>, ReadOnlySpan<byte>)
Performs the RFC 5869 extract stage, condensing inputKeyingMaterial into a pseudorandom key
of one hash length.
public static byte[] Extract(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> inputKeyingMaterial, ReadOnlySpan<byte> salt = default)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
inputKeyingMaterialReadOnlySpan<byte>The input keying material to extract entropy from.
saltReadOnlySpan<byte>The optional non-secret salt. When empty, a string of hash-length zero bytes is used.
Returns
- byte[]
The pseudorandom key (PRK), one hash length long.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm.
Extract(HashAlgorithmName, ReadOnlySpan<byte>, ReadOnlySpan<byte>, Span<byte>)
Performs the RFC 5869 extract stage, writing the pseudorandom key into destination.
public static int Extract(HashAlgorithmName hashAlgorithm, ReadOnlySpan<byte> inputKeyingMaterial, ReadOnlySpan<byte> salt, Span<byte> destination)
Parameters
hashAlgorithmHashAlgorithmNameThe HMAC hash algorithm to use.
inputKeyingMaterialReadOnlySpan<byte>The input keying material to extract entropy from.
saltReadOnlySpan<byte>The optional non-secret salt. When empty, a string of hash-length zero bytes is used.
destinationSpan<byte>The span that receives the pseudorandom key; must be exactly one hash length long.
Returns
- int
The number of bytes written to
destination, equal to the hash length.
Exceptions
- ArgumentException
hashAlgorithmis not a supported HKDF hash algorithm, ordestinationis not exactly one hash length long.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |