tls_kdf.c File Reference

TLS key derivation functions. More...

#include "core/crypto.h"
#include "kdf/tls_kdf.h"
#include "kdf/hkdf.h"
#include "mac/hmac.h"

Go to the source code of this file.

Macros

#define TRACE_LEVEL   CRYPTO_TRACE_LEVEL
 

Functions

error_t tlsPrf (const uint8_t *secret, size_t secretLen, const char_t *label, const uint8_t *seed, size_t seedLen, uint8_t *output, size_t outputLen)
 Pseudorandom function (TLS 1.0 and 1.1) More...
 
error_t tls12Prf (const HashAlgo *hashAlgo, const uint8_t *secret, size_t secretLen, const char_t *label, const uint8_t *seed, size_t seedLen, uint8_t *output, size_t outputLen)
 Pseudorandom function (TLS 1.2) More...
 
error_t hkdfExpandLabel (const HashAlgo *hashAlgo, const uint8_t *secret, size_t secretLen, const char_t *prefix, const char_t *label, const uint8_t *context, size_t contextLen, uint8_t *output, size_t outputLen)
 HKDF-Expand-Label function (TLS 1.3) More...
 

Detailed Description

TLS key derivation functions.

License

SPDX-License-Identifier: GPL-2.0-or-later

Copyright (C) 2010-2026 Oryx Embedded SARL. All rights reserved.

This file is part of CycloneCRYPTO Open.

This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.

This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.

You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.

Author
Oryx Embedded SARL (www.oryx-embedded.com)
Version
2.6.6

Definition in file tls_kdf.c.

Macro Definition Documentation

◆ TRACE_LEVEL

#define TRACE_LEVEL   CRYPTO_TRACE_LEVEL

Definition at line 32 of file tls_kdf.c.

Function Documentation

◆ hkdfExpandLabel()

error_t hkdfExpandLabel ( const HashAlgo *  hashAlgo,
const uint8_t *  secret,
size_t  secretLen,
const char_t *  prefix,
const char_t *  label,
const uint8_t *  context,
size_t  contextLen,
uint8_t *  output,
size_t  outputLen 
)

HKDF-Expand-Label function (TLS 1.3)

Parameters
[in]hashAlgoHash function used by HKDF
[in]secretPointer to the secret
[in]secretLenLength of the secret
[in]prefixLabel prefix ("tls13 " for TLS, "dtls13" for DTLS)
[in]labelIdentifying label (NULL-terminated string)
[in]contextPointer to the upper-layer context
[in]contextLenLength of the upper-layer context
[out]outputPointer to the output
[in]outputLenDesired output length
Returns
Error code

Definition at line 270 of file tls_kdf.c.

◆ tls12Prf()

error_t tls12Prf ( const HashAlgo *  hashAlgo,
const uint8_t *  secret,
size_t  secretLen,
const char_t *  label,
const uint8_t *  seed,
size_t  seedLen,
uint8_t *  output,
size_t  outputLen 
)

Pseudorandom function (TLS 1.2)

The pseudorandom function (PRF) takes as input a secret, a seed, and an identifying label and produces an output of arbitrary length. This function is used to expand secrets into blocks of data for the purpose of key generation

Parameters
[in]hashAlgoHash function used to compute PRF
[in]secretPointer to the secret
[in]secretLenLength of the secret
[in]labelIdentifying label (NULL-terminated string)
[in]seedPointer to the seed
[in]seedLenLength of the seed
[out]outputPointer to the output
[in]outputLenDesired output length
Returns
Error code

Definition at line 187 of file tls_kdf.c.

◆ tlsPrf()

error_t tlsPrf ( const uint8_t *  secret,
size_t  secretLen,
const char_t *  label,
const uint8_t *  seed,
size_t  seedLen,
uint8_t *  output,
size_t  outputLen 
)

Pseudorandom function (TLS 1.0 and 1.1)

The pseudorandom function (PRF) takes as input a secret, a seed, and an identifying label and produces an output of arbitrary length. This function is used to expand secrets into blocks of data for the purpose of key generation

Parameters
[in]secretPointer to the secret
[in]secretLenLength of the secret
[in]labelIdentifying label (NULL-terminated string)
[in]seedPointer to the seed
[in]seedLenLength of the seed
[out]outputPointer to the output
[in]outputLenDesired output length
Returns
Error code

Definition at line 62 of file tls_kdf.c.