Hawkynt

Camellia Key Wrap with Padding

RFC 5649 key wrapping with padding applied to Camellia cipher. Supports arbitrary-length plaintext by padding to 8-byte multiples and embedding length in AIV.

Properties

Property Value
Category Special Algorithms
Sub-category Key Wrapping
Security status πŸ›‘οΈ Secure
Complexity Intermediate
Inventor NIST (RFC 5649 specification with Camellia cipher)
Year 2009
Origin πŸ‡ΊπŸ‡Έ United States
Source algorithms/crypto/camelliawrappad.js

Parameters

Parameter Supported values
Key sizes 16 bytes (128 bits) to 32 bytes (256 bits) in steps of 8 bytes

Security

Status: πŸ›‘οΈ Secure

No vulnerabilities are recorded for this implementation.

Documentation

References

Test vectors

2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 β€” Self-consistency vector (RFC 5649 wrap structure, sized like RFC 5649 Β§6.2, with Camellia-128 substituted for AES; no official Camellia-KWP KAT exists) β€” single-block case (7-octet key data)

Field Value
key 000102030405060708090a0b0c0d0e0f
input 466f7250617369
expected bdcc8e794701c12804891be045dd11cb

Vector 2 β€” Self-consistency vector (RFC 5649 wrap structure, sized like RFC 5649 Β§6.1, with Camellia-192 substituted for AES; no official Camellia-KWP KAT exists) β€” multi-block case (20-octet key data, general RFC 3394 loop)

Field Value
key 5840df6e29b02af1ab493b705bf16ea1ae8338f4dcc176a8
input c37b7e6492584340bed12207808941155068f738
expected 6fe8e088d2042ea144139b1c7a46a63027226d16c01034c73b6333d4ab05884c

← All algorithms