Uh oh!
There was an error while loading. Please reload this page.
Add Counter and Feedback KDFs from NIST SP 800-108 - #202
Conversation
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
SalusaSecondus
commented
May 3, 2026
@tarcieri , @newpavlov Friendly ping on this. |
SalusaSecondus
commented
May 30, 2026
@tarcieri , @newpavlov , a friendly ping again. (I figure about monthly isn't too frequent.) |
tarcieri
commented
May 31, 2026
Sorry this has been very far on the backburner for me. We're still trying to get stable releases of everything out. |
This is my attempt to implement some of the NIST SP 800-108 KDFs as requested in #75 . That standard defines a large family of KDFs and so rather than defining a single construction, I needed a way for developers to configure the specific KDF they need. I'm doing this with an enum called
ContextComponentwhich allows them to build up a specific context. To avoid memory allocation, I place a hard cap at 16 elements, though expect 5 to be sufficient in practice.While I have added test vectors from CAVP for these cases, they do not cover all of the configurations described in the standard. Specifically, they do not cover encoding the length of the output nor use of K0. Please double-check my logic and implementation around these.
I have not added implementations of either Double Pipeline or KMAC KDFs at this time.
As always, all naming (struct, crate, etc.) is up for change.