Re: existing KDFs and their uses
Dan Brown <dbrown <at> certicom.com>
2010-01-21 16:11:58 GMT
Hi Hugo,
I just noticed NIST Special Publication 800-108, which, like
HKDF, is based on the ideas of extract-then-expand. It has HMAC and CMAC based
options. How does it fare in your view? Especially, does have it security
similar to HKDF?
Best regards,
Dan
From:
cfrg-bounces <at> irtf.org [mailto:cfrg-bounces <at> irtf.org] On Behalf Of Hugo
Krawczyk
Sent: Thursday, October 22, 2009 7:07 PM
To: David McGrew
Cc: cfrg <at> irtf.org
Subject: Re: [Cfrg] existing KDFs and their uses
David, this work that you are doing in compiling usage
scenarios and existing KDFs is VERY useful. Hopefully, you can put it as a
separate document. I am very interested to know if there is anything, except
passwords, for which plain HKDF is insufficient.
I am interested in applications that require the KDF to generate regular random
keys rather than some structured elements (such as group elements that require
dedicated group-specific techniques).
Thanks!
Hugo
---------------------------------------------------------------------
This transmission (including any attachments) may contain confidential information, privileged material (including material protected by the solicitor-client or other applicable privileges), or constitute non-public information. Any use of this information by anyone other than the intended recipient is prohibited. If you have received this transmission in error, please immediately reply to the sender and delete this information from your system. Use, dissemination, distribution, or reproduction of this transmission by unintended recipients is not authorized and may be unlawful.
_______________________________________________
Cfrg mailing list
Cfrg <at> irtf.org
http://www.irtf.org/mailman/listinfo/cfrg