Security Analysis of NIST Key Derivation Using Pseudorandom Functions

Abstract Key derivation functions can be used to derive variable-length random strings that serve as cryptographic keys. They are integral to many widely-used communication protocols such as TLS, IPsec and Signal. NIST SP 800-108 specifies several key derivation functions based on pseudorandom functions such as and , that can be used to derive additional keys from an existing cryptographic key. This standard either explicitly or implicitly requests their KDFs to be variable output length pseudorandom function, collision resistant, and preimage resistant, which are also demanded by practical applications. Yet, since the publication of this standard dating back to the year of 2008, until now, there is no formal analysis to justify these security properties of KDFs. In this work, we give the formal security analysis of key derivation functions in NIST SP 800-108. We show both positive and negative results regarding these key derivation functions. For KCTR-CMAC, KFB-CMAC, and KDPL-CMAC that are key derivation functions based on CMAC in counter mode, feedback mode, and double-pipeline mode respectively, we prove that all of them are secure variable output length pseudorandom functions and preimage resistant. We show that KFB-CMAC and KDPL-CMAC are collision resistant. While for KCTR-CMAC, we can mount constant-time collision attack against it. For KCTR-HMAC, KFB-HMAC, and KDPL-HMAC that are key derivation functions based on HMAC in modes, we show that all of them behave like variable output length pseudorandom functions. When the key of these key derivation functions is of variable length, they suffer from collision attacks. For the case when the key of these key derivation function is of fixed length and less than $$d-1$$ d - 1 bits where d is the input block size of the underlying compression function, we can prove that they are collision resistant and preimage resistant. Finally, we extend our analysis to the plain CMAC-based KDFs for which mitigation techniques against key-control attacks do not apply, as well as to the KMAC-based KDF.

Authors

Publication Details

Journal
Journal of Cryptology
Published
2026-09-28
DOI
https://doi.org/10.1007/s00145-026-09588-3
Primary Topic
Cryptographic Implementations and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Security Analysis of NIST Key Derivation Using Pseudorandom Functions

Yaobin Shen, Lei Wang, Dawu Gu
Journal of Cryptology
Cryptographic Implementations and Security
article

Security Analysis of NIST Key Derivation Using Pseudorandom Functions

Yaobin Shen, Lei Wang, Dawu Gu
article en

Abstract

Abstract Key derivation functions can be used to derive variable-length random strings that serve as cryptographic keys. They are integral to many widely-used communication protocols such as TLS, IPsec and Signal. NIST SP 800-108 specifies several key derivation functions based on pseudorandom functions such as and , that can be used to derive additional keys from an existing cryptographic key. This standard either explicitly or implicitly requests their KDFs to be variable output length pseudorandom function, collision resistant, and preimage resistant, which are also demanded by practical applications. Yet, since the publication of this standard dating back to the year of 2008, until now, there is no formal analysis to justify these security properties of KDFs. In this work, we give the formal security analysis of key derivation functions in NIST SP 800-108. We show both positive and negative results regarding these key derivation functions. For KCTR-CMAC, KFB-CMAC, and KDPL-CMAC that are key derivation functions based on CMAC in counter mode, feedback mode, and double-pipeline mode respectively, we prove that all of them are secure variable output length pseudorandom functions and preimage resistant. We show that KFB-CMAC and KDPL-CMAC are collision resistant. While for KCTR-CMAC, we can mount constant-time collision attack against it. For KCTR-HMAC, KFB-HMAC, and KDPL-HMAC that are key derivation functions based on HMAC in modes, we show that all of them behave like variable output length pseudorandom functions. When the key of these key derivation functions is of variable length, they suffer from collision attacks. For the case when the key of these key derivation function is of fixed length and less than $$d-1$$ d - 1 bits where d is the input block size of the underlying compression function, we can prove that they are collision resistant and preimage resistant. Finally, we extend our analysis to the plain CMAC-based KDFs for which mitigation techniques against key-control attacks do not apply, as well as to the KMAC-based KDF.

Journal of CryptologyVol. 39(4)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Cryptographic Implementations and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.