Skip to main content

Module xof

Module xof 

Source
Expand description

§Extendable-output functions

An extendable-output function (XOF) hashes input of any length into output of any length. It can serve as a hash with a chosen output size, a key-derivation step that turns one secret into several keys, or a deterministic generator that expands a seed.

Shake128 and Shake256 are the SHAKE functions from FIPS 202. TurboShake128 and TurboShake256 (RFC 9861) run the same sponge with 12 Keccak rounds instead of 24, so they are about twice as fast with the same security claims. The 128 and 256 suffixes give the security level in bits.

Absorb input with update, then call finalize to get a reader. Each squeeze call continues the same output stream, so squeezing 32 bytes twice gives the same bytes as squeezing 64 once. with_domain selects a custom domain byte in 0x01..=0x7f; different domains give unrelated outputs for the same input.

An XOF is not a MAC. Output is only secret if the input is.

§Example

use dryoc::xof::TurboShake128;

let mut xof = TurboShake128::new();
xof.update(b"input keying material");
let mut reader = xof.finalize();
let encryption_key = reader.squeeze_to_vec(32);
let mac_key = reader.squeeze_to_vec(32);
assert_ne!(encryption_key, mac_key);

// One-shot output of any length.
let digest = dryoc::xof::Shake256::compute_to_vec(b"hello", 64);
assert_eq!(digest.len(), 64);

Structs§

Shake128
SHAKE128 extendable-output function (FIPS 202).
Shake256
SHAKE256 extendable-output function (FIPS 202).
Shake128Reader
Output stream of a finalized Shake128.
Shake256Reader
Output stream of a finalized Shake256.
TurboShake128
TurboSHAKE128 extendable-output function (RFC 9861).
TurboShake256
TurboSHAKE256 extendable-output function (RFC 9861).
TurboShake128Reader
Output stream of a finalized TurboShake128.
TurboShake256Reader
Output stream of a finalized TurboShake256.