Hawkynt

SP800-56C

NIST SP 800-56C Two-Step Key Derivation Function. Extract-and-Expand pattern using HMAC for deriving cryptographic keys from shared secrets, similar to HKDF but following NIST standardized specification.

Properties

Property Value
Category Key Derivation Functions
Sub-category Two-Step KDF (Extract-and-Expand)
Security status πŸ›‘οΈ Secure
Complexity Intermediate
Inventor NIST
Year 2018
Origin πŸ‡ΊπŸ‡Έ United States
Source algorithms/kdf/sp800-56c.js

Parameters

Parameter Supported values
Key derivation sizes 1 byte (8 bits) to 16320 bytes (130560 bits)

Capabilities

Flag Value
SaltRequired Yes
NeedsKey Yes

Security

Status: πŸ›‘οΈ Secure

No vulnerabilities are recorded for this implementation.

Documentation

References

Test vectors

3 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 β€” SP 800-56C - HMAC-SHA1 Test Vector 1 (2 bytes)

Field Value
salt 97ca00eac481e8b3556a
label ae8cf2e46773a68098ea53b3
outputLength 2
hashAlgorithm SHA-1
input 52f4676023946c7307b5e8148d97f312623a6e88
expected 1bcd

Vector 2 β€” SP 800-56C - HMAC-SHA1 Test Vector 2 (4 bytes)

Field Value
salt 76b026053771b88e4e833962a10083835a33ddd9
label f2d44c1b59d725ad7c662ca6
outputLength 4
hashAlgorithm SHA-1
input eecb51e6d59a6fe688fb591799891d9211745a13
expected bc3d9b22

Vector 3 β€” SP 800-56C - HMAC-SHA256 Test Vector 1 (3 bytes)

Field Value
salt 28e12e410d501368b3e8
label 94d91d500177efafdc93e8b6
outputLength 3
hashAlgorithm SHA-256
input b3dad1f46a18430ea0c8fbe2172922a5a42c47af40046db24d38cb11eff4ce44
expected d4c1fb

← All algorithms