Class Hkdf

java.lang.Object
ai.badmonkey.agentspaces.common.crypto.Hkdf

public final class Hkdf extends Object
HKDF (RFC 5869) with HMAC-SHA-256: extract-then-expand key derivation. The sealed group-key wrap derives its AES key-encryption key from the X25519 shared secret through this function, binding the derivation to both parties' public keys through the salt.
  • Method Details

    • derive

      public static byte[] derive(byte[] ikm, byte[] salt, byte[] info, int length)
      Derives key material.
      Parameters:
      ikm - the input keying material (a shared secret)
      salt - the salt; MAY be empty, SHOULD bind the context's identities
      info - the application- and use-specific label
      length - the number of bytes to derive, at most 255 * 32
      Returns:
      the derived bytes