Cryptographic Extraction and Key Derivation: The HKDF Scheme

被引:0
|
作者
Krawczyk, Hugo [1 ]
机构
[1] IBM TJ Watson Res Ctr, Hawthorne, NY USA
来源
关键词
DIFFIE-HELLMAN; RANDOMNESS; SECURITY; GENERATOR; CASCADE; BOUNDS; HMAC;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In spite of the central role of key derivation functions (KDF) in applied cryptography, there has been little formal work addressing the design and analysis of general multi-purpose KDFs. In practice, most KDFs. (including those widely standardized) follow ad-hoc approaches that treat cryptographic hash functions as perfectly random functions. In this paper we close some gaps between theory and practice by contributing to the study and engineering of KDFs in several ways. We provide detailed rationale for the design of KDFs based on the extract-then-expand approach; we present the first general and rigorous definition of KDFs and their security that we base on the notion of computational extractors; we specify a concrete fully practical KDF based on the HMAC construction; and we provide an analysis of this construction based on the extraction and pseudorandom properties of HMAC. The resultant KDF design can support a large variety of KDF applications under suitable assumptions on the underlying hash function; particular attention and effort is devoted to minimizing these assumptions as much as possible for each usage scenario. Beyond the theoretical interest in modeling KDFs, this work is intended to address two important and timely needs of cryptographic applications: (i) providing a single hash-based KDF design that can be standardized for use in multiple and diverse applications, and (ii) providing a conservative, yet efficient, design that exercises much care in the way it; utilizes a cryptographic hash function. (The HMAC-based scheme presented here, named HKDF, is being standardized by the IETF.)
引用
收藏
页码:631 / 648
页数:18
相关论文
共 50 条
  • [21] A DYNAMIC CRYPTOGRAPHIC KEY ASSIGNMENT SCHEME IN A TREE STRUCTURE
    LIAW, HT
    WANG, SJ
    LEI, CL
    COMPUTERS & MATHEMATICS WITH APPLICATIONS, 1993, 25 (06) : 109 - 114
  • [22] Cryptographic key assignment scheme for hierarchical access control
    Wu, TC
    Chang, CC
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2001, 16 (01): : 25 - 28
  • [23] An improvement of cryptographic key assignment scheme in a user hierarchy
    Chen, TS
    Huang, GS
    Tasi, CC
    Chang, NT
    2002 IEEE REGION 10 CONFERENCE ON COMPUTERS, COMMUNICATIONS, CONTROL AND POWER ENGINEERING, VOLS I-III, PROCEEDINGS, 2002, : 133 - 136
  • [24] On the Security Analysis of Weak Cryptographic Primitive Based Key Derivation Function
    Chuah, Chai Wen
    Deris, Mustafa Mat
    Dawson, Edward
    INFORMATION SCIENCE AND APPLICATIONS 2017, ICISA 2017, 2017, 424 : 231 - 240
  • [25] Key derivation algorithms for monotone access structures in cryptographic file systems
    Srivatsa, Mudhakar
    Liu, Ling
    COMPUTER SECURITY - ESORICS 2006, PROCEEDINGS, 2006, 4189 : 347 - +
  • [26] Multi-Biometrics Based Cryptographic Key Regeneration Scheme
    Kanade, Sanjay
    Petrovska-Delacretaz, Dijana
    Dorizzi, Bernadette
    2009 IEEE 3RD INTERNATIONAL CONFERENCE ON BIOMETRICS: THEORY, APPLICATIONS AND SYSTEMS, 2009, : 333 - 339
  • [27] CRYPTOGRAPHIC KEY ASSIGNMENT SCHEME FOR ACCESS-CONTROL IN A HIERARCHY
    CHANG, CC
    HWANG, RJ
    WU, TC
    INFORMATION SYSTEMS, 1992, 17 (03) : 243 - 247
  • [28] The Novel Cryptographic Key Generation and Distribution Scheme for Smart Grid
    Wang, Zhidong
    Liu, Piao
    Lin, Peixia
    Yang, Zhibin
    Liang, Mei
    Zuo, Hanmu
    2015 5TH INTERNATIONAL CONFERENCE ON ELECTRIC UTILITY DEREGULATION AND RESTRUCTURING AND POWER TECHNOLOGIES (DRPT 2015), 2015, : 873 - 875
  • [29] A symmetric neural cryptographic key generation scheme for Iot security
    Arindam Sarkar
    Applied Intelligence, 2023, 53 : 9344 - 9367
  • [30] A symmetric neural cryptographic key generation scheme for Iot security
    Sarkar, Arindam
    APPLIED INTELLIGENCE, 2023, 53 (08) : 9344 - 9367