Skip to main content

HMAC-based key derivation function (HKDF) standalone implementation using pure Python.

Project description

HMAC-based key derivation function (HKDF) standalone implementation using pure Python.

PyPI version and link. Read the Docs documentation status. GitHub Actions status. Coveralls test coverage summary.

Description and Purpose

This library contains a pure-Python implementation of the HMAC-based key derivation function (HKDF) as specified in RFC 5869. The order and names of arguments within the function signatures in this implementation deviate from the specification in order to adhere more closely to typical Python conventions (such as having arguments with default values follow arguments without default values).

This library has been created and is maintained because other standalone implementations (such as the hkdf package) are not actively maintained and implementations available in larger libraries such as cryptography are not standalone.

Installation and Usage

This library is available as a package on PyPI:

python -m pip install hkdfs

The library can be imported in the usual manner:

import hkdfs
from hkdfs import hkdfs

Examples

A few basic usage examples are provided below:

>>> hkdfs(128, bytes([123])).hex()[:73]
'bd54b22aa1447254436981928dc26b3bdce94772283d3d8a50ad1654745ca6be4e1b14127'
>>> import hashlib
>>> hkdfs(
...     length=1024,
...     key=bytes([1]),
...     salt=bytes([2]),
...     info=bytes([3]),
...     hash=hashlib.sha512
... ).hex()[:73]
'1277a50c8cd05020dc073bd129cd84214270a0468e936c496fafee48c10a613a1a3b10fd2'

Development

All installation and development dependencies are fully specified in pyproject.toml. The project.optional-dependencies object is used to specify optional requirements for various development tasks. This makes it possible to specify additional options (such as docs, lint, and so on) when performing installation using pip:

python -m pip install ".[docs,lint]"

Documentation

The documentation can be generated automatically from the source files using Sphinx:

python -m pip install ".[docs]"
cd docs
sphinx-apidoc -f -E --templatedir=_templates -o _source .. && make html

Testing and Conventions

All unit tests are executed and their coverage is measured when using pytest (see the pyproject.toml file for configuration details):

python -m pip install ".[test]"
python -m pytest

The subset of the unit tests included in the module itself and can be executed using doctest:

python src/hkdfs/hkdfs.py -v

Style conventions are enforced using Pylint:

python -m pip install ".[lint]"
python -m pylint src/hkdfs

Acknowledgments

Materials consulted throughout the implementation of this library include RFC 5869, the example implementation in the Wikipedia article about the HKDF function, and the source code of the hkdf package.

Contributions

In order to contribute to the source code, open an issue or submit a pull request on the GitHub page for this library.

Versioning

The version number format for this library and the changes to the library associated with version number increments conform with Semantic Versioning 2.0.0.

Publishing

This library can be published as a package on PyPI via the GitHub Actions workflow found in .github/workflows/build-publish-sign-release.yml that follows the recommendations found in the Python Packaging User Guide.

Ensure that the correct version number appears in pyproject.toml, and that any links in this README document to the Read the Docs documentation of this package (or its dependencies) have appropriate version numbers. Also ensure that the Read the Docs project for this library has an automation rule that activates and sets as the default all tagged versions.

To publish the package, create and push a tag for the version being published (replacing ?.?.? with the version number):

git tag ?.?.?
git push origin ?.?.?

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

hkdfs-0.1.0.tar.gz (9.7 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

hkdfs-0.1.0-py3-none-any.whl (8.0 kB view details)

Uploaded Python 3

File details

Details for the file hkdfs-0.1.0.tar.gz.

File metadata

  • Download URL: hkdfs-0.1.0.tar.gz
  • Upload date:
  • Size: 9.7 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for hkdfs-0.1.0.tar.gz
Algorithm Hash digest
SHA256 6da7295206191bbb178651bc3b0ca3824ca4bd4c7e7af36fee14a164f773a003
MD5 0f9bec574e3343ac2ff149ba242a33d6
BLAKE2b-256 f3684e230321971ee4246574ff5f1768aceac85deb8aaf8e4dcbe7364271f0d9

See more details on using hashes here.

Provenance

The following attestation bundles were made for hkdfs-0.1.0.tar.gz:

Publisher: build-publish-sign-release.yml on NillionNetwork/hkdfs

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file hkdfs-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: hkdfs-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 8.0 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.7

File hashes

Hashes for hkdfs-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 7a86fe521cc6022c464c2b5f60089809c39d173f48db2dc11da22d7e4de7e019
MD5 099db15ddeeb0ea14a843b277ff33935
BLAKE2b-256 3296c182257b49858e81bba04544817b86034239d5db347e464db1e14ad60fa5

See more details on using hashes here.

Provenance

The following attestation bundles were made for hkdfs-0.1.0-py3-none-any.whl:

Publisher: build-publish-sign-release.yml on NillionNetwork/hkdfs

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page