RFC 2104: HMAC: Authenticating messages with hash functions
Summary
RFC 2104 defines HMAC, which securely combines existing hash functions with a secret key. Good cryptographic constructions use primitives with a clear security analysis. A hash alone does not prove authenticity.
Ideas
- Inner and outer hash passes separate key and message.
- The construction can be used with different hash functions.
- Authentication detects tampering and confirms possession of a shared key.
Remarks
- RFC 2104 is an informational document and not an Internet Standard.
Recommendations
- Use HMAC through maintained libraries instead of your own constructions.
- Use separate keys for different protocol purposes.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.