bk99.de entertain the web since 1997

RFC 2104: HMAC: Authenticating messages with hash functions

Summary

RFC 2104 defines HMAC, which securely combines existing hash functions with a secret key. Good cryptographic constructions use primitives with a clear security analysis. A hash alone does not prove authenticity.

Ideas

  • Inner and outer hash passes separate key and message.
  • The construction can be used with different hash functions.
  • Authentication detects tampering and confirms possession of a shared key.

Remarks

  • RFC 2104 is an informational document and not an Internet Standard.

Recommendations

  • Use HMAC through maintained libraries instead of your own constructions.
  • Use separate keys for different protocol purposes.

References

Read the RFC at the RFC Editor

Search the Web Archive