2019-12-16 19:38:45 +00:00
|
|
|
import nimcrypto
|
|
|
|
|
2021-12-20 12:14:50 +00:00
|
|
|
proc hkdf*(HashType: typedesc, ikm, salt, info: openArray[byte],
|
|
|
|
output: var openArray[byte]) =
|
2019-12-16 19:38:45 +00:00
|
|
|
var ctx: HMAC[HashType]
|
|
|
|
ctx.init(salt)
|
2020-04-24 13:40:30 +00:00
|
|
|
ctx.update(ikm)
|
2019-12-16 19:38:45 +00:00
|
|
|
let prk = ctx.finish().data
|
|
|
|
const hashLen = HashType.bits div 8
|
|
|
|
|
|
|
|
var t: MDigest[HashType.bits]
|
|
|
|
|
|
|
|
var numIters = output.len div hashLen
|
|
|
|
if output.len mod hashLen != 0:
|
|
|
|
inc numIters
|
|
|
|
|
|
|
|
for i in 0 ..< numIters:
|
|
|
|
ctx.init(prk)
|
|
|
|
if i != 0:
|
|
|
|
ctx.update(t.data)
|
|
|
|
ctx.update(info)
|
|
|
|
ctx.update([uint8(i + 1)])
|
|
|
|
t = ctx.finish()
|
|
|
|
let iStart = i * hashLen
|
|
|
|
var sz = hashLen
|
|
|
|
if iStart + sz >= output.len:
|
|
|
|
sz = output.len - iStart
|
|
|
|
copyMem(addr output[iStart], addr t.data, sz)
|
|
|
|
|
|
|
|
ctx.clear()
|