Security Analysis of NIST Key Derivation Using Pseudorandom Functions
Abstract Key derivation functions can be used to derive variable-length random strings that serve as cryptographic keys. They are integral to many widely-used communication protocols such as TLS, IPsec and Signal. NIST SP 800-108 specifies several key derivation functions based on pseudorandom functions such as and , that can be used to derive additional keys from an existing cryptographic key. This standard either explicitly or implicitly requests their KDFs to be variable output length pseudorandom function, collision resistant, and preimage resistant, which are also demanded by practical applications. Yet, since the publication of this standard dating back to the year of 2008, until now, there is no formal analysis to justify these security properties of KDFs. In this work, we give the formal security analysis of key derivation functions in NIST SP 800-108. We show both positive and negative results regarding these key derivation functions. For KCTR-CMAC, KFB-CMAC, and KDPL-CMAC that are key derivation functions based on CMAC in counter mode, feedback mode, and double-pipeline mode respectively, we prove that all of them are secure variable output length pseudorandom functions and preimage resistant. We show that KFB-CMAC and KDPL-CMAC are collision resistant. While for KCTR-CMAC, we can mount constant-time collision attack against it. For KCTR-HMAC, KFB-HMAC, and KDPL-HMAC that are key derivation functions based on HMAC in modes, we show that all of them behave like variable output length pseudorandom functions. When the key of these key derivation functions is of variable length, they suffer from collision attacks. For the case when the key of these key derivation function is of fixed length and less than $$d-1$$ d - 1 bits where d is the input block size of the underlying compression function, we can prove that they are collision resistant and preimage resistant. Finally, we extend our analysis to the plain CMAC-based KDFs for which mitigation techniques against key-control attacks do not apply, as well as to the KMAC-based KDF.
Authors
- Yaobin Shen (ORCID: https://orcid.org/0000-0002-9549-4538)
- Lei Wang (ORCID: https://orcid.org/0000-0002-9090-5289)
- Dawu Gu
Publication Details
- Journal
- Journal of Cryptology
- Published
- 2026-09-28
- DOI
- https://doi.org/10.1007/s00145-026-09588-3
- Primary Topic
- Cryptographic Implementations and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00