Key wrapping algorithm using GOST 28147-89 block cipher with MAC authentication. Wraps keys by encrypting blocks and appending a 4-byte MAC for integrity verification.
| Property | Value |
|---|---|
| Category | Special Algorithms |
| Sub-category | Key Wrapping |
| Security status | ⚠️ Deprecated |
| Complexity | Intermediate |
| Inventor | Soviet/Russian standard committee |
| Year | 1989 |
| Origin | 🇷🇺 Russia |
| Source | algorithms/crypto/gost28147wrap.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 32 bytes (256 bits) |
Status: ⚠️ Deprecated
| Issue | Description | Mitigation |
|---|---|---|
| Deprecated standard | GOST 28147-89 has been superseded by newer Russian standards (Kuznyechik/Magma in GOST R 34.12-2015). | Use modern key wrap algorithms like AES Key Wrap (RFC 3394) for new applications. |
| Fixed key size requirement | GOST 28147-89 Key Wrap requires exactly 32 bytes (256 bits) of key material for wrapping. Plaintext must be exactly 32 bytes (4 blocks). | Ensure proper key derivation and size validation before wrapping operations. |
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — GOST 28147-89 Key Wrap - 32-byte key material with UKM
| Field | Value |
|---|---|
key |
546d203368656c326973652073736e62206167796967747473656865202c3d73 |
ukm |
1234567890abcdef |
input |
000102030405060708090a0b0c0d0e0f101112131415161718191a1b1c1d1e1f |
expected |
c38aa7f55384318ae9cf31fd318321eb 9b8c95186ecfb5daec6b76079ddbea7c 37650afa |