NIST SP 800-56C Two-Step Key Derivation Function. Extract-and-Expand pattern using HMAC for deriving cryptographic keys from shared secrets, similar to HKDF but following NIST standardized specification.
| Property | Value |
|---|---|
| Category | Key Derivation Functions |
| Sub-category | Two-Step KDF (Extract-and-Expand) |
| Security status | π‘οΈ Secure |
| Complexity | Intermediate |
| Inventor | NIST |
| Year | 2018 |
| Origin | πΊπΈ United States |
| Source | algorithms/kdf/sp800-56c.js |
| Parameter | Supported values |
|---|---|
| Key derivation sizes | 1 byte (8 bits) to 16320 bytes (130560 bits) |
| Flag | Value |
|---|---|
SaltRequired |
Yes |
NeedsKey |
Yes |
Status: π‘οΈ Secure
No vulnerabilities are recorded for this implementation.
3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β SP 800-56C - HMAC-SHA1 Test Vector 1 (2 bytes)
| Field | Value |
|---|---|
salt |
97ca00eac481e8b3556a |
label |
ae8cf2e46773a68098ea53b3 |
outputLength |
2 |
hashAlgorithm |
SHA-1 |
input |
52f4676023946c7307b5e8148d97f312623a6e88 |
expected |
1bcd |
Vector 2 β SP 800-56C - HMAC-SHA1 Test Vector 2 (4 bytes)
| Field | Value |
|---|---|
salt |
76b026053771b88e4e833962a10083835a33ddd9 |
label |
f2d44c1b59d725ad7c662ca6 |
outputLength |
4 |
hashAlgorithm |
SHA-1 |
input |
eecb51e6d59a6fe688fb591799891d9211745a13 |
expected |
bc3d9b22 |
Vector 3 β SP 800-56C - HMAC-SHA256 Test Vector 1 (3 bytes)
| Field | Value |
|---|---|
salt |
28e12e410d501368b3e8 |
label |
94d91d500177efafdc93e8b6 |
outputLength |
3 |
hashAlgorithm |
SHA-256 |
input |
b3dad1f46a18430ea0c8fbe2172922a5a42c47af40046db24d38cb11eff4ce44 |
expected |
d4c1fb |