ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
kdf.h File Reference

SP800-108 counter-mode key derivation (HMAC-SHA256 PRF). More...

#include "protocore_config.h"

Go to the source code of this file.

Classes

struct  KdfNs
 Dispatch table. Addressed by offset, so the layout is asserted below. More...
 

Functions

 PROTOCORE_NS_LAYOUT (KdfNs, ctr_hmac_sha256)
 
proto_bool protocore_kdf_ctr_hmac_sha256 (uint8_t *work, const uint8_t *ki, size_t ki_len, const uint8_t *fixed, size_t fixed_len, uint8_t *out, size_t out_len)
 Derive out_len bytes, counter mode, HMAC-SHA256 PRF.
 

Variables

PROTOCORE_NS KdfNs Kdf PROTOCORE_UNUSED = {.ctr_hmac_sha256 = protocore_kdf_ctr_hmac_sha256}
 Module namespace.
 

Detailed Description

SP800-108 counter-mode key derivation (HMAC-SHA256 PRF).

The shared NIST SP800-108 §5.1 counter-mode KDF. SMB 3.x uses it to derive its signing and encryption keys (MS-SMB2 §3.1.4.2); the caller assembles the fixed input, keeping this independent of any protocol's label/context choices. Verified against the NIST CAVP KBKDF (KDFCTR) vectors. Built over the HmacSha256Ns entries, so which arm compresses the PRF is not visible here.

K(i) = HMAC-SHA256(Ki, [i]_32be || fixed); the blocks are concatenated for i = 1, 2, ... and the result truncated to KdfCtrArgs::out_len bytes.

work is PROTOCORE_KDF_BORROW secure bytes the CALLER took, at an address it knows. It is not held past the call, so nothing here aliases it. The caller releases it, and the pool wipes on release; this module neither takes it, holds it, releases it, nor wipes it. That is what keeps K(i), which is derived from Ki, from outliving the caller.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file kdf.h.

Function Documentation

◆ PROTOCORE_NS_LAYOUT()

PROTOCORE_NS_LAYOUT ( KdfNs  ,
ctr_hmac_sha256   
)

◆ protocore_kdf_ctr_hmac_sha256()

proto_bool protocore_kdf_ctr_hmac_sha256 ( uint8_t *  work,
const uint8_t *  ki,
size_t  ki_len,
const uint8_t *  fixed,
size_t  fixed_len,
uint8_t *  out,
size_t  out_len 
)

Derive out_len bytes, counter mode, HMAC-SHA256 PRF.

Parameters
workPROTOCORE_KDF_BORROW bytes the caller took. Not held past the call.
kithe key-derivation key (e.g. the SMB 3.x session key)
ki_lenits length in bytes
fixedthe fixed input, Label || 0x00 || Context || [L]
fixed_lenits length in bytes
outreceives out_len derived bytes
out_lennumber of output bytes, >= 1; the caller encodes L = out_len * 8 into fixed
Returns
PROTO_TRUE on success.

Variable Documentation

◆ PROTOCORE_UNUSED

PROTOCORE_NS KdfNs Kdf PROTOCORE_UNUSED = {.ctr_hmac_sha256 = protocore_kdf_ctr_hmac_sha256}

Module namespace.

Definition at line 53 of file kdf.h.