HkdfSha384 class

HKDF-SHA384 (RFC 5869) — the same extract-then-expand construction as HkdfSha256 at a 48-byte hash.

Present because it is the KDF in the only published HPKE suite for ML-KEM-1024 (IANA KDF id 0x0002, alongside KEM 0x0042 and AES-256-GCM), and because CNSA 2.0 specifies SHA-384 alongside ML-KEM-1024. Using HKDF-SHA256 there would mean a suite with no third-party vector.

RFC 5869 publishes test vectors for SHA-256 and SHA-1 only, so this is attested instead by the HPKE working group's 0x0042 key-schedule vector, which exercises it end to end — see test/rfc9180_hpke_test.dart.

Constructors

HkdfSha384()

Properties

hashCode → int
The hash code for this object.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

deriveKey(Uint8List ikm, {Uint8List? salt, Uint8List? info, required int length}) → Uint8List
The fused extract-then-expand form, as HkdfSha256.deriveKey.
expand(Uint8List prk, {Uint8List? info, required int length}) → Uint8List
RFC 5869 Expand, truncated to length.
extract(Uint8List ikm, {Uint8List? salt}) → Uint8List
RFC 5869 Extract: PRK = HMAC-SHA384(salt, ikm).

Constants

hashLen → const int
SHA-384 output size in bytes.