A method for iterating the multiple invocations of a pseudorandom function in order to derive the keying material with a required length.
Sources:
NIST SP 800-108r1
[August 2022 (Includes updates as of 02-02-2024)]