7. 参考文献 (References)
7. 参考文献 (References)
本节列出 HKDF 规范使用的规范性和资料性参考文献. 规范性引用定义 HMAC,RFC 规范性关键词和 Secure Hash Standard, 是 HKDF 算法描述的直接基础. 资料性引用提供密钥派生,离散对数密钥建立,EAP-AKA',IKEv2,PANA,PKCS #5 以及 HKDF 论文等背景.
7.1. 规范性参考文献 (Normative References)
这些文献定义 HKDF 所依赖的 HMAC 和哈希函数语义.
[HMAC] Krawczyk, H., Bellare, M., and R. Canetti, "HMAC: Keyed-Hashing for Message Authentication", RFC 2104, February 1997.
[KEYWORDS] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997.
[SHS] National Institute of Standards and Technology, "Secure Hash Standard", FIPS PUB 180-3, October 2008.
7.2. 资料性参考文献 (Informative References)
这些文献说明 HKDF 在密钥建立,认证协议和密码派生场景中的相关背景.
HKDF 的安全性依赖 HMAC 和底层哈希函数的性质, 同时也常被嵌入到更大的密钥建立协议中. 因此, 规范性引用用于定义算法部件, 资料性引用用于说明 HKDF 与 IKEv2,EAP-AKA',PANA,PKCS #5 和其他密钥派生建议之间的关系. 实现者应避免把这些参考文献中的其他 KDF 语义混入 HKDF 的 extract-then-expand 结构.
[1363a] Institute of Electrical and Electronics Engineers, "IEEE Standard Specifications for Public-Key Cryptography - Amendment 1: Additional Techniques", IEEE Std 1363a-2004, 2004.
[800-108] National Institute of Standards and Technology, "Recommendation for Key Derivation Using Pseudorandom Functions", NIST Special Publication 800-108, November 2008.
[800-56A] National Institute of Standards and Technology, "Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography (Revised)", NIST Special Publication 800-56A, March 2007.
[EAP-AKA] Arkko, J., Lehtovirta, V., and P. Eronen, "Improved Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA')", RFC 5448, May 2009.
[HKDF-paper]
Krawczyk, H., "Cryptographic Extraction and Key Derivation: The HKDF Scheme", Proceedings of CRYPTO 2010 (to appear), 2010, <http://eprint.iacr.org/2010/264>.
[IKEv2] Kaufman, C., Ed., "Internet Key Exchange (IKEv2) Protocol", RFC 4306, December 2005.
[PANA] Forsberg, D., Ohba, Y., Ed., Patil, B., Tschofenig, H., and A. Yegin, "Protocol for Carrying Authentication for Network Access (PANA)", RFC 5191, May 2008.
[PKCS5] Kaliski, B., "PKCS #5: Password-Based Cryptography Specification Version 2.0", RFC 2898, September 2000.