SSL.Crypto.HKDF (ex_ssl v0.16.7)

Copy Markdown View Source

HKDF and TLS 1.3 labeled key derivation.

Only the SHA-256 and SHA-384 cipher-suite hashes are supported.

Summary

Types

error()

@type error() ::
  {:error, :unsupported_hash}
  | {:error, {:length_out_of_range, pos_integer()}}
  | {:error, {:label_length_out_of_range, {1, 249}}}
  | {:error, {:context_length_out_of_range, 255}}
  | {:error, {:invalid_transcript_hash_length, pos_integer()}}

hash()

@type hash() :: :sha256 | :sha384

Functions

derive_secret(hash, secret, label, transcript_hash)

@spec derive_secret(atom(), binary(), binary(), binary()) :: binary() | error()

expand(hash, prk, info, length)

@spec expand(atom(), binary(), binary(), integer()) :: binary() | error()

expand_label(hash, secret, label, context, length)

@spec expand_label(atom(), binary(), binary(), binary(), integer()) ::
  binary() | error()

extract(hash, salt, ikm)

@spec extract(atom(), binary(), binary()) :: binary() | error()