Your company here — click to reach over 10,000 unique daily visitors

EVP_KDF-PVKKDF.7ossl - Man Page

The PVK EVP_KDF implementation


Support for computing the PVK KDF PIN-based KDF through the EVP_KDF API.

The EVP_KDF-PVKKDF algorithm implements a PVK PIN-based key derivation function; it derives a key from a password using a salt.


"PVKKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

Supported parameters

The supported parameters are:

"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>

These parameters work as described in "PARAMETERS" in EVP_KDF(3).


A typical application of this algorithm is to derive keying material for an encryption algorithm from a password in the "pass" and a salt in "salt".

No assumption is made regarding the given password; it is simply treated as a byte sequence.

The legacy provider needs to be available in order to access this algorithm.

See Also

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), OSSL_PROVIDER-legacy(7)


This functionality was added in OpenSSL 3.2.


2024-07-09 3.2.2 OpenSSL