KWP (Key Wrap with Padding) extends the standard Key Wrap algorithm to handle arbitrary-length key material by adding padding. It includes the original key length in the IV to enable proper padding removal during unwrapping. This allows secure wrapping of keys that are not multiples of 64 bits.
| Property | Value |
|---|---|
| Category | Cipher Modes |
| Sub-category | Key Wrapping Mode |
| Security status | π‘οΈ Secure |
| Complexity | Intermediate |
| Inventor | NIST |
| Year | 2012 |
| Origin | πΊπΈ United States |
| Source | algorithms/modes/kwp.js |
| Flag | Value |
|---|---|
RequiresIV |
No |
Status: π‘οΈ Secure
| Issue | Description | Mitigation |
|---|---|---|
| Length Information Leakage | KWP includes the original key length in the IV, which may leak information about the wrapped key size. | β |
| Padding Oracle Potential | Improper error handling during unwrapping could potentially leak information about padding validity. | β |
2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β RFC 5649 6 - wrap 20 octets of key data with a 192-bit KEK
| Field | Value |
|---|---|
cipher |
AES |
kek |
5840df6e29b02af1ab493b705bf16ea1ae8338f4dcc176a8 |
input |
c37b7e6492584340bed12207808941155068f738 |
expected |
138bdeaa9b8fa7fc61f97742e72248ee5ae6ae5360d1ae6a5f54f373fa543b6a |
Vector 2 β RFC 5649 6 - wrap 7 octets of key data with a 192-bit KEK
| Field | Value |
|---|---|
cipher |
AES |
kek |
5840df6e29b02af1ab493b705bf16ea1ae8338f4dcc176a8 |
input |
466f7250617369 |
expected |
afbeb0f07dfbf5419200f2ccb50bb24f |