4 ms·
so, what are "key-derivation functions"?
by mcc1ane 5y ago
so, what are "key-derivation functions"?
- criticaltinker 5y agoPretty much synonymous with "cryptographic hash functions" [1], just referring to a specific use-case. > derive one or more keys from a common secret value (which is sometimes also referred to as "key diversification"). > Such use may prevent an attacker who obtains a derived key from learning useful information about either the input secret value or any of the other derived keys [1] https://en.wikipedia.org/wiki/Key_derivation_function https://en.wikipedia.org/wiki/Key_derivation_function
- some_furry 5y agoNot quite. A key derivation function needs to have a lot of the same properties as a pseudorandom function (which is the space cryptographic hash functions occupy), but with additional requirements. 1. It needs a secret input. This is the password (for Password KDFs) or Initial Key Material. Cryptographic hash functions do not. 2. It needs to satisfy a stronger security model. See section 3 of this paper, especially definition 7: https://eprint.iacr.org/2010/264.pdf https://eprint.iacr.org/2010/264.pdf There's some overlap (Argon2id, scrypt) between PHFs and KDFs. There's exclusion in both categories. Bcrypt is a PHF, not a KDF. HKDF is a KDF, not a PHF.