Skip to main content

Module kdf

Module kdf 

Source
Expand description

§Key derivation functions

Kdf derives separate, context-bound subkeys from one random master key. It implements libsodium’s BLAKE2b-based crypto_kdf construction.

Use Kdf when an application needs several keys for different purposes. Assign each purpose a distinct context and subkey ID so that it produces a different subkey.

§Rustaceous API example

use base64::Engine as _;
use base64::engine::general_purpose;
use dryoc::kdf::*;

// Generate a random main key with the default stack-allocated type.
let key = StackKdf::generate();
let subkey_id = 0;

let subkey = key
    .derive_subkey_to_vec(subkey_id, 32)
    .expect("derive failed");
println!(
    "Subkey {}: {}",
    subkey_id,
    general_purpose::STANDARD.encode(&subkey)
);

§Additional resources

Modules§

protectedprotected
Protected memory type aliases for Kdf

Structs§

Kdf
Key derivation implementation based on Blake2b, compatible with libsodium’s crypto_kdf_* functions.

Type Aliases§

Context
Stack-allocated context type alias for key derivation with Kdf.
Key
Stack-allocated key type alias for key derivation with Kdf.
StackKdf
Stack-allocated type alias for Kdf. Provided for convenience.