Compare commits

..

17 Commits

Author SHA1 Message Date
576b0190ad Update README.md 2026-04-16 16:10:03 +00:00
8f80ceaf7f Bump version to 1.2.1
All checks were successful
/ test (pull_request) Successful in 43s
2026-03-11 23:54:11 +01:00
d4c316ae00 Upgrade dependencies 2026-03-11 23:53:42 +01:00
124f6a21a3 Upgrade dependencies
All checks were successful
/ test (pull_request) Successful in 1m15s
2026-02-16 19:52:47 +01:00
ab33fe3670 split ci
All checks were successful
/ test (pull_request) Successful in 1m41s
2026-02-03 23:45:09 +01:00
f78b10f565 upgrade
Some checks failed
/ publish (pull_request) Has been cancelled
/ test (pull_request) Has been cancelled
/ publish (push) Has been cancelled
/ test (push) Has been cancelled
2026-02-03 23:42:46 +01:00
8686be3346 improve ci
Some checks failed
/ test (push) Failing after 3m43s
/ publish (push) Has been skipped
2026-01-13 18:12:43 +01:00
8644c79167 update README
small rewording, link wikipedia article
2025-12-14 14:30:18 +01:00
1537dd1be3 replace IllegalArgumentException with require 2025-12-14 00:14:55 +01:00
8552d3dd2e update README 2025-12-13 21:13:17 +01:00
9a9543a1ff bump version to 1.1.0
All checks were successful
/ publish (push) Successful in 3m59s
2025-12-13 02:34:39 +01:00
d6449e647a fix workflow 2025-12-13 01:30:59 +01:00
a43cf1467d use common plugin 2025-12-13 01:23:24 +01:00
26cff5d331 implement tests 2025-12-12 16:11:08 +01:00
8f21a346db implement common interface 2025-12-12 16:10:57 +01:00
6dec2fea74 upgrade dependencies 2025-12-12 16:06:26 +01:00
ca71d9427f add README 2025-10-04 11:58:28 +02:00
11 changed files with 315 additions and 105 deletions

View File

@@ -1,36 +0,0 @@
on:
push:
branches:
- main
env:
GIT__TOKEN: ${{ secrets.TOKEN }}
jobs:
publish:
runs-on: linux
steps:
- uses: actions/checkout@v4
- uses: actions/cache/restore@v4
with:
key: gradle
path: |
~/.gradle/caches/
~/.gradle/wrapper/
~/.konan/
- uses: actions/setup-java@v4
with:
java-version: '24'
distribution: 'temurin'
- run: ./gradlew publish
- uses: actions/cache/save@v4
with:
key: gradle
path: |
~/.gradle/caches/
~/.gradle/wrapper/
~/.konan/

View File

@@ -0,0 +1,47 @@
on:
push:
branches: [ main ]
jobs:
publish:
runs-on: linux
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Java
uses: actions/setup-java@v4
with:
java-version: '24'
distribution: 'temurin'
- name: Cache Gradle
uses: actions/cache@v4
with:
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
restore-keys: gradle
path: |
~/.gradle/caches/
~/.gradle/wrapper/
- name: Cache Konan
uses: actions/cache@v4
with:
key: konan-${{ hashFiles('**/libs.versions.toml') }}
restore-keys: konan
path: |
~/.konan/
- name: Cache Node
uses: actions/cache@v4
with:
key: node-${{ hashFiles('**/libs.versions.toml') }}
restore-keys: node
path: |
~/.gradle/nodejs
~/.gradle/yarn
- name: Publish
run: ./gradlew publish
env:
INFENDRO__TOKEN: ${{ secrets.TOKEN }}

View File

@@ -0,0 +1,28 @@
on:
pull_request:
branches: [ main ]
jobs:
test:
runs-on: linux
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Java
uses: actions/setup-java@v4
with:
java-version: '24'
distribution: 'temurin'
- name: Cache Gradle
uses: actions/cache@v4
with:
key: gradle-${{ hashFiles('**/libs.versions.toml') }}
restore-keys: gradle
path: |
~/.gradle/caches/
~/.gradle/wrapper/
- name: Test
run: ./gradlew jvmTest

35
README.md Normal file
View File

@@ -0,0 +1,35 @@
# kdf.kt
`kdf.kt` is a Kotlin Multiplatform library that provides common [Key Derivation Functions](https://en.wikipedia.org/wiki/Key_derivation_function).
Supported algorithms:
- PBKDF2
## Installation
Add the following to your `build.gradle.kts`.
```kotlin
repositories {
maven("https://git.infendro.com/api/packages/Infendro/maven")
}
dependencies {
implementation("com.infendro:kdf:1.2.1")
}
```
## Usage
```kotlin
fun main() {
// create a PBKDF2 instance using HMAC SHA-256
// this example uses 32 bytes of length and 100_000 iterations
val kdf = PBKDF2(32, 100_000, `SHA-256`())
// securely hash value with some salt
val value = "password".encodeToByteArray()
val salt = "salt".encodeToByteArray()
val hash = kdf.hash(value, salt)
}
```

View File

@@ -1,57 +1,46 @@
group = "com.infendro" @file:OptIn(ExperimentalWasmDsl::class)
version = "1.0.3"
repositories { import com.infendro.plugin.infendro
maven("https://git.infendro.com/api/packages/Infendro/maven") import com.infendro.plugin.token
mavenCentral() import org.jetbrains.kotlin.gradle.ExperimentalWasmDsl
}
group = "com.infendro"
version = "1.2.1"
plugins { plugins {
alias(libs.plugins.infendro)
alias(libs.plugins.multiplatform) alias(libs.plugins.multiplatform)
id("maven-publish") id("maven-publish")
} }
kotlin { kotlin {
jvm() jvm()
js {
nodejs()
}
linuxX64() linuxX64()
linuxArm64()
mingwX64()
macosX64()
macosArm64()
js { nodejs() }
wasmJs { nodejs() }
wasmWasi { nodejs() }
repositories {
infendro()
mavenCentral()
}
sourceSets { sourceSets {
commonMain.dependencies { commonMain.dependencies {
implementation(libs.mac) implementation(libs.bytes)
implementation(libs.hash) implementation(libs.hash)
implementation(libs.bytearray) implementation(libs.mac)
}
commonTest.dependencies {
implementation(libs.test)
} }
} }
} }
publishing { publishing.repositories {
repositories { infendro(token)
maven {
url = uri("https://git.infendro.com/api/packages/Infendro/maven")
authentication.create("header", HttpHeaderAuthentication::class)
credentials(HttpHeaderCredentials::class) {
val token = secret("git.token") ?: throw GradleException()
name = "Authorization"
value = "token $token"
}
}
}
}
fun secret(
key: String,
): String? {
val property = key
val environment = key
.uppercase()
.replace(".", "__")
val prop = properties[property] as String?
val env = System.getenv(environment)
return prop ?: env
} }

View File

@@ -1,13 +1,16 @@
[versions] [versions]
kotlin = "2.2.10" infendro = "1.1.0"
mac = "1.1.2" kotlin = "2.3.0"
hash = "1.2.2" bytes = "1.4.2"
bytearray = "1.1.1" hash = "1.7.0"
mac = "1.5.0"
[plugins] [plugins]
infendro = { id = "com.infendro.plugin", version.ref = "infendro" }
multiplatform = { id = "org.jetbrains.kotlin.multiplatform", version.ref = "kotlin" } multiplatform = { id = "org.jetbrains.kotlin.multiplatform", version.ref = "kotlin" }
[libraries] [libraries]
mac = { module = "com.infendro:mac", version.ref = "mac" } bytes = { module = "com.infendro:bytes", version.ref = "bytes" }
hash = { module = "com.infendro:hash", version.ref = "hash" } hash = { module = "com.infendro:hash", version.ref = "hash" }
bytearray = { module = "com.infendro:bytearray", version.ref = "bytearray" } mac = { module = "com.infendro:mac", version.ref = "mac" }
test = { module = "org.jetbrains.kotlin:kotlin-test", version.ref = "kotlin" }

View File

@@ -1 +1,6 @@
rootProject.name = "kdf" rootProject.name = "kdf"
pluginManagement.repositories {
maven("https://git.infendro.com/api/packages/Infendro/maven")
mavenCentral()
}

View File

@@ -0,0 +1,15 @@
package com.infendro.kdf
interface KDF {
val bytes: Int
val bits: Int
get() = bytes * 8
fun hashInto(value: ByteArray, salt: ByteArray, destination: ByteArray, destinationOffset: Int = 0)
fun hash(value: ByteArray, salt: ByteArray): ByteArray {
val result = ByteArray(bytes)
hashInto(value, salt, result)
return result
}
}

View File

@@ -1,39 +1,41 @@
package com.infendro.kdf package com.infendro.kdf
import com.infendro.bytearray.addAll import com.infendro.bytes.bytearray.xorWith
import com.infendro.bytearray.toByteArray import com.infendro.bytes.int.toByteArray
import com.infendro.bytearray.xor
import com.infendro.hash.HashFunction import com.infendro.hash.HashFunction
import com.infendro.kdf.util.ceilDiv
import com.infendro.mac.HMAC import com.infendro.mac.HMAC
class PBKDF2( class PBKDF2(
private val function: HashFunction, override val bytes: Int,
) { private val iterations: Int,
function: HashFunction,
) : KDF {
init {
require(bytes > 0)
require(iterations > 0)
}
private val hmac = HMAC(function) private val hmac = HMAC(function)
private val buffer = ByteArray(hmac.bytes)
fun hash( override fun hashInto(value: ByteArray, salt: ByteArray, destination: ByteArray, destinationOffset: Int) {
value: ByteArray, hmac.init(value)
salt: ByteArray,
iterations: Int,
length: Int,
): ByteArray {
val key = buildList {
for (i in 1..(length + function.bytes - 1) / function.bytes) {
val input = salt + i.toUInt().toByteArray()
var u = hmac.hash(value, input) for (block in 1..bytes.ceilDiv(hmac.bytes)) {
var result = u val offset = (block - 1) * hmac.bytes
repeat(iterations - 1) { val bytes = minOf(bytes - offset, hmac.bytes)
u = hmac.hash(value, u)
result = result xor u
}
addAll(result) hmac.update(salt)
hmac.update(block.toByteArray())
hmac.digestInto(buffer)
buffer.copyInto(destination, destinationOffset + offset, endIndex = bytes)
repeat(iterations - 1) {
hmac.update(buffer)
hmac.digestInto(buffer)
val offset = destinationOffset + offset
destination.xorWith(buffer, offset, offset + bytes)
} }
} }
return key
.take(length)
.toByteArray()
} }
} }

View File

@@ -0,0 +1,4 @@
package com.infendro.kdf.util
internal fun Int.ceilDiv(n: Int): Int =
(this + n - 1) / n

View File

@@ -0,0 +1,118 @@
package com.infendro.kdf
import com.infendro.hash.sha2.`SHA-256`
import kotlin.test.Test
import kotlin.test.assertContentEquals
class `PBKDF2 Test` {
@Test
fun `32 bytes 1 iteration`() {
val function = PBKDF2(32, 1, `SHA-256`())
val expected = byteArrayOf(
+0x12, +0x0f, -0x4a, -0x31, -0x04, -0x08, -0x4d, +0x2c,
+0x43, -0x19, +0x22, +0x52, +0x56, -0x3c, -0x08, +0x37,
-0x58, +0x65, +0x48, -0x37, +0x2c, -0x34, +0x35, +0x48,
+0x08, +0x05, -0x68, +0x7c, -0x49, +0x0b, -0x1f, +0x7b,
)
val actual = function.hash(
"password".encodeToByteArray(),
"salt".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
@Test
fun `32 bytes 2 iterations`() {
val function = PBKDF2(32, 2, `SHA-256`())
val expected = byteArrayOf(
-0x52, +0x4d, +0x0c, -0x6b, -0x51, +0x6b, +0x46, -0x2d,
+0x2d, +0x0a, -0x21, -0x07, +0x28, -0x10, +0x6d, -0x30,
+0x2a, +0x30, +0x3f, -0x72, -0x0d, -0x3e, +0x51, -0x21,
-0x2a, -0x1e, -0x28, +0x5a, -0x6b, +0x47, +0x4c, +0x43,
)
val actual = function.hash(
"password".encodeToByteArray(),
"salt".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
@Test
fun `32 bytes 4096 iterations`() {
val function = PBKDF2(32, 4096, `SHA-256`())
val expected = byteArrayOf(
-0x3b, -0x1c, +0x78, -0x2b, -0x6e, -0x78, -0x38, +0x41,
-0x56, +0x53, +0x0d, -0x4a, -0x7c, +0x5c, +0x4c, -0x73,
-0x6a, +0x28, -0x6d, -0x60, +0x01, -0x32, +0x4e, +0x11,
-0x5c, -0x6a, +0x38, +0x73, -0x56, -0x68, +0x13, +0x4a,
)
val actual = function.hash(
"password".encodeToByteArray(),
"salt".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
@Test
fun `40 bytes 4096 iterations`() {
val function = PBKDF2(40, 4096, `SHA-256`())
val expected = byteArrayOf(
-0x3b, -0x1c, +0x78, -0x2b, -0x6e, -0x78, -0x38, +0x41,
-0x56, +0x53, +0x0d, -0x4a, -0x7c, +0x5c, +0x4c, -0x73,
-0x6a, +0x28, -0x6d, -0x60, +0x01, -0x32, +0x4e, +0x11,
-0x5c, -0x6a, +0x38, +0x73, -0x56, -0x68, +0x13, +0x4a,
-0x09, -0x53, -0x68, -0x3f, -0x4c, +0x58, -0x32, +0x3f,
)
val actual = function.hash(
"password".encodeToByteArray(),
"salt".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
@Test
fun `64 bytes 1 iteration`() {
val function = PBKDF2(64, 1, `SHA-256`())
val expected = byteArrayOf(
+0x55, -0x54, +0x04, +0x6e, +0x56, -0x1d, +0x08, -0x61,
-0x14, +0x16, -0x6f, -0x3e, +0x25, +0x44, -0x4a, +0x05,
-0x07, +0x41, -0x7b, +0x21, +0x6d, -0x22, +0x04, +0x65,
-0x1a, -0x75, -0x63, +0x57, -0x3e, +0x0d, -0x54, -0x44,
+0x49, -0x36, -0x64, -0x34, -0x0f, +0x79, -0x4a, +0x45,
-0x67, +0x16, +0x64, -0x4d, -0x63, +0x77, -0x11, +0x31,
+0x7c, +0x71, -0x48, +0x45, -0x4f, -0x1d, +0x0b, -0x2b,
+0x09, +0x11, +0x20, +0x41, -0x2d, -0x5f, -0x69, -0x7d,
)
val actual = function.hash(
"passwd".encodeToByteArray(),
"salt".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
@Test
fun `64 bytes 80000 iterations`() {
val function = PBKDF2(64, 80_000, `SHA-256`())
val expected = byteArrayOf(
+0x4d, -0x24, -0x28, -0x0a, +0x0b, -0x68, -0x42, +0x21,
-0x7d, +0x0c, -0x12, +0x5e, -0x0e, +0x27, +0x01, -0x07,
+0x64, +0x1a, +0x44, +0x18, -0x30, +0x4c, +0x04, +0x14,
-0x52, -0x01, +0x08, -0x79, +0x6b, +0x34, -0x55, +0x56,
-0x5f, -0x2c, +0x25, -0x5f, +0x22, +0x58, +0x33, +0x54,
-0x66, -0x25, -0x7c, +0x1b, +0x51, -0x37, -0x4d, +0x17,
+0x6a, +0x27, +0x2b, -0x22, -0x45, -0x5f, -0x30, +0x78,
+0x47, -0x71, +0x62, -0x4d, -0x69, -0x0d, +0x3c, -0x73,
)
val actual = function.hash(
"Password".encodeToByteArray(),
"NaCl".encodeToByteArray(),
)
assertContentEquals(expected, actual)
}
}