hkdf library

HKDF cryptography wrappers and parametrization.

https://datatracker.ietf.org/doc/html/rfc5869

Stretches a secret that is already high entropy, a shared secret or a file key, into one or more keys bound to a context string. It is not a password hash; the argon2 library is the one for that.

import 'dart:convert';
import 'dart:typed_data';

import 'package:darkbio_crypto/hkdf.dart' as hkdf;
import 'package:darkbio_crypto/rand.dart' as rand;

(Uint8List, Uint8List) example() {
  final secret = rand.bytes(32);
  final salt = Uint8List(0);

  // One secret, two independent keys bound to their purposes
  final encryption = hkdf.key(secret: secret, salt: salt, info: utf8.encode('example encryption key'));
  final authentication = hkdf.key(secret: secret, salt: salt, info: utf8.encode('example authentication key'));
  return (encryption, authentication);
}

Functions

expand({required Uint8List prk, required Uint8List info, int length = 32}) → Uint8List
Derives a key of length bytes, using the given pseudorandom key and optional context info, skipping the extraction step.
extract({required Uint8List secret, required Uint8List salt}) → Uint8List
Generates a 32-byte pseudorandom key for use with expand from an input secret and an optional independent salt.
key({required Uint8List secret, required Uint8List salt, required Uint8List info, int length = 32}) → Uint8List
Derives a key from the secret, salt, and info using HKDF-SHA256, returning length bytes that can be used as a cryptographic key.