Key Derivation Functions Intermediate
HKDF: HMAC-Based Key Derivation
TLS 1.3 and the Signal Protocol both lean on the same small, elegant primitive to turn a shared secret into however many separate keys they actually need. Here's how HKDF's extract-then-expand design works.