TLS 1.2 Pseudorandom Function using HMAC-SHA-256. Modern TLS key derivation supporting arbitrary hash functions. Uses P_hash construction with single PRF instead of dual MD5+SHA-1.
| Property | Value |
|---|---|
| Category | Key Derivation Functions |
| Sub-category | Key Derivation Function |
| Security status | π‘οΈ Secure |
| Complexity | Intermediate |
| Inventor | IETF TLS Working Group |
| Year | 2008 |
| Origin | πΊπΈ United States |
| Source | algorithms/kdf/tls-prf.js |
| Parameter | Supported values |
|---|---|
| Output sizes | 1 byte (8 bits) to 1024 bytes (8192 bits) |
| Flag | Value |
|---|---|
SaltRequired |
Yes |
Status: π‘οΈ Secure
No vulnerabilities are recorded for this implementation.
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 β IETF TLS 1.2 SHA-256 Test Vector
| Field | Value |
|---|---|
salt |
a0ba9f936cda311827a6f796ffd5198c |
label |
74657374206c6162656c |
outputSize |
100 |
input |
9bbe436ba940f017b17652849a71db35 |
expected |
e3f229ba727be17b8d122620557cd453 c2aab21d07c3d495329b52d4e61edb5a 6b301791e90d35c9c9a46b4e14baf9af 0fa022f7077def17abfd3797c0564bab 4fbc91666e9def9b97fce34f796789ba a48082d122ee42c5a72e5a5110fff701 87347b66 |