hkdf library
HKDF cryptography wrappers and parametrization.
https://datatracker.ietf.org/doc/html/rfc5869
Stretches a secret that is already high entropy, a shared secret or a file
key, into one or more keys bound to a context string. It is not a password
hash; the argon2 library is the one for that.
import 'dart:convert';
import 'dart:typed_data';
import 'package:darkbio_crypto/hkdf.dart' as hkdf;
import 'package:darkbio_crypto/rand.dart' as rand;
(Uint8List, Uint8List) example() {
final secret = rand.bytes(32);
final salt = Uint8List(0);
// One secret, two independent keys bound to their purposes
final encryption = hkdf.key(secret: secret, salt: salt, info: utf8.encode('example encryption key'));
final authentication = hkdf.key(secret: secret, salt: salt, info: utf8.encode('example authentication key'));
return (encryption, authentication);
}
Functions
-
expand(
{required Uint8List prk, required Uint8List info, int length = 32}) → Uint8List -
Derives a key of
lengthbytes, using the given pseudorandom key and optional context info, skipping the extraction step. -
extract(
{required Uint8List secret, required Uint8List salt}) → Uint8List - Generates a 32-byte pseudorandom key for use with expand from an input secret and an optional independent salt.
-
key(
{required Uint8List secret, required Uint8List salt, required Uint8List info, int length = 32}) → Uint8List -
Derives a key from the secret, salt, and info using HKDF-SHA256, returning
lengthbytes that can be used as a cryptographic key.