PBKDF2
Password-Based Key Derivation Function 2 (PBKDF2) using HMAC-SHA1 for key stretching. Converts passwords into cryptographic keys through iterative hashing. Educational implementation demonstrating key derivation principles.
Properties
| Property |
Value |
| Category |
Key Derivation Functions |
| Sub-category |
Key Derivation Function |
| Security status |
π Educational Only |
| Complexity |
Intermediate |
| Inventor |
RSA Laboratories |
| Year |
2000 |
| Origin |
πΊπΈ United States |
| Source |
algorithms/kdf/pbkdf2.js |
Parameters
| Parameter |
Supported values |
| Output sizes |
1 byte (8 bits) to 128 bytes (1024 bits) |
Capabilities
| Flag |
Value |
SaltRequired |
Yes |
Security
Status: π Educational Only
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Timing Attacks |
Use constant-time comparison for password verification and sufficient iteration counts |
β |
| Insufficient Iteration Count |
Use minimum 100,000 iterations for 2023. Increase over time as computing power grows |
β |
Documentation
References
Test vectors
2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β RFC 6070 Test Vector 1: password/salt, 1 iteration
| Field |
Value |
salt |
73616c74 |
iterations |
1 |
outputSize |
20 |
input |
70617373776f7264 |
expected |
0c60c80f961f0e71f3a9b524af6012062fe037a6 |
Vector 2 β RFC 6070 Test Vector 2: password/salt, 2 iterations
| Field |
Value |
salt |
73616c74 |
iterations |
2 |
outputSize |
20 |
input |
70617373776f7264 |
expected |
ea6c014dc72d6f8ccd1ed92ace1d41f0d8de8957 |
β All algorithms