$manlookup

EVP_KDF-HMAC-DRBG

(7ssl)

The HMAC DRBG DETERMINISTIC EVP_KDF implementation

Overview, conventions, miscellanyopenssl 3.5.6-1~deb13u2

DESCRIPTION

Support for a deterministic HMAC DRBG using the EVP_KDF API. This is similar to EVP_RAND-HMAC-DRBG(7), but uses fixed values for its entropy and nonce values. This is used to generate deterministic nonce value required by ECDSA and DSA (as defined in RFC 6979).

"HMAC-DRBG-KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

The supported parameters are:

"digest" (OSSL_DRBG_PARAM_DIGEST) <UTF8 string>
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
These parameters work as described in "PARAMETERS" in EVP_KDF(3).
"entropy" (OSSL_KDF_PARAM_HMACDRBG_ENTROPY) <octet string>
Sets the entropy bytes supplied to the HMAC-DRBG.
"nonce" (OSSL_KDF_PARAM_HMACDRBG_NONCE) <octet string>
Sets the nonce bytes supplied to the HMAC-DRBG.

NOTES

A context for KDF HMAC DRBG can be obtained by calling:

 EVP_KDF *kdf = EVP_KDF_fetch(NULL, "HMAC-DRBG-KDF", NULL);
 EVP_KDF_CTX *kdf_ctx = EVP_KDF_CTX_new(kdf, NULL);

CONFORMING TO

RFC 6979

HISTORY

The EVP_KDF-HMAC-DRBG functionality was added in OpenSSL 3.2.

See also

EVP_KDF(3)