|
int wc_HKDF_Expand(int type, const byte* inKey, word32 inKeySz, |
|
const byte* info, word32 infoSz, byte* out, word32 outSz) |
|
{ |
|
byte tmp[WC_MAX_DIGEST_SIZE]; |
|
Hmac myHmac; |
|
int ret = 0; |
|
word32 outIdx = 0; |
|
word32 hashSz = wc_HmacSizeByType(type); |
|
byte n = 0x1; |
|
|
|
ret = wc_HmacInit(&myHmac, NULL, INVALID_DEVID); |
|
if (ret != 0) |
|
return ret; |
|
|
|
while (outIdx < outSz) { |
|
int tmpSz = (n == 1) ? 0 : hashSz; |
|
word32 left = outSz - outIdx; |
|
|
|
ret = wc_HmacSetKey(&myHmac, type, inKey, inKeySz); |
|
if (ret != 0) |
|
break; |
|
ret = wc_HmacUpdate(&myHmac, tmp, tmpSz); |
|
if (ret != 0) |
|
break; |
|
ret = wc_HmacUpdate(&myHmac, info, infoSz); |
|
if (ret != 0) |
|
break; |
|
ret = wc_HmacUpdate(&myHmac, &n, 1); |
|
if (ret != 0) |
|
break; |
|
ret = wc_HmacFinal(&myHmac, tmp); |
|
if (ret != 0) |
|
break; |
|
|
|
left = min(left, hashSz); |
|
XMEMCPY(out+outIdx, tmp, left); |
|
|
|
outIdx += hashSz; |
|
n++; |
|
} |
|
|
|
wc_HmacFree(&myHmac); |
|
|
|
return ret; |
RFC 5869 section 2.3 states that the length of the output is
L <= 255*HashLenwhereHashLenis the size in octets of the the hash function's digest. However,wc_HKDF_Expandhas no such limit:wolfssl/wolfcrypt/src/hmac.c
Lines 1209 to 1252 in 5e45767
Examples from other HKDF libraries: