Understand KeyWrap primitives (KW, KWP, TKW)
mainNIST SP 800 38f defines three keywrap primitives used for wrapping cryptographic keys. They all use a 6-round construction based on a strong pseudorandom permutation (W).
- KW (Key Wrap): Uses AES. Input size must be a multiple of 8 bytes. Defined in RFC 3394.
- KWP (Key Wrap with Padding): Uses AES. Adds padding to allow arbitrary length inputs. Defined in RFC 5649.
- TKW (TripleDES Key Wrap): Uses TripleDES. Input size must be a multiple of 8 bytes.
Note: For KWP, it is recommended to disallow keys of size 8 or smaller (wrappings of size 16 bytes) to avoid theoretical vulnerabilities related to the breaking of the strong pseudorandom property for small plaintexts.