key function

Uint8List key({
  1. required Uint8List password,
  2. required Uint8List salt,
  3. int time = 3,
  4. int memory = 65536,
  5. int threads = 4,
  6. int length = 32,
})

Derives a key from the password, salt and cost parameters using Argon2id, returning length bytes that can be used as a cryptographic key.

RFC 9106 Section 4 recommends time 1, memory 2 GiB (2 * 1024 * 1024 KiB) and threads 4. Its second recommendation, the defaults here, uses time 3, memory 64 MiB (64 * 1024 KiB) and threads 4. Both use a random 16-byte salt and a 32-byte output.

time is the number of passes and memory is the total working memory in KiB. threads is Argon2's lane count, an algorithm parameter that changes the derived key; it does not select how many threads run. Store the salt and all cost parameters so the same key can be derived on other devices. The derivation blocks the calling isolate until it finishes.

Throws if any of these input limits are violated:

  • time must be 1 to 2^32 - 1.
  • threads must be 1 to 16777215.
  • memory must be 8 * threads to 2^32 - 1 KiB.
  • salt must be 8 to 2^32 - 1 bytes.
  • password must be at most 2^32 - 1 bytes.
  • length must be 4 to 2^32 - 1 bytes.

Also throws if the working memory cannot be allocated.

Implementation

Uint8List key({
  required Uint8List password,
  required Uint8List salt,
  int time = 3,
  int memory = 65536,
  int threads = 4,
  int length = 32,
}) {
  _checkUint32(time, 'time');
  _checkUint32(memory, 'memory');
  _checkUint32(threads, 'threads');
  _checkUint32(length, 'length');
  return ffi.argon2Key(
    password: password,
    salt: salt,
    time: time,
    memory: memory,
    threads: threads,
    keyLength: BigInt.from(length),
  );
}