[noise] BLAKE2X as KDF

Trevor Perrin trevp at trevp.net
Wed Aug 17 00:40:01 PDT 2016


On Tue, Aug 16, 2016 at 5:53 PM, Jason A. Donenfeld <Jason at zx2c4.com> wrote:

>
> https://blake2.net/blake2x.pdf
>
> Have you seen this yet? Looks like it might be a nice candidate for a KDF
> in Noise.
>

I think we'd need a very strong reason to change the core design at this
point, and I don't see much advantage to this vs the current HKDF design.

Any performance savings vs HKDF would be small, and I like using a
conservative and consistent KDF across all hash functions.

I guess these questions about BLAKE2 modes come up often enough I should
write up a more detailed rationale, for the spec.


Trevor
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://moderncrypto.org/mail-archive/noise/attachments/20160817/6c593366/attachment.html>


More information about the Noise mailing list