Welcome!
To use the personalized features of this site, please log in or register.
If you have forgotten your username or password, we can help.
My Menu
Saved Items

On the Security of Two MAC Algorithms

Bart PreneelContact Information and Paul C. van OorschotContact Information

(5)  Dept. Electrical Engineering-ESAT, Katholieke Universiteit Leuven, Kardinaal Mercierlaan 94, B-3001, Heverlee, Belgium
(6)  Bell-Northern Research, Box 3511, Station C, Ottawa, Ontario, K1Y 4H7, Canada
Abstract
The security of two message authentication code (MAC) al- gorithms is considered: the MD5-based envelope method (RFC 1828), and the banking standard MAA (ISO 8731-2). Customization of a general MAC forgery attack allows improvements in both cases. For the envelope method, the forgery attack is extended to allow key recovery; for example, a 128-bit key can be recovered using 267 known text-MAC pairs and time plus 213 chosen texts. For MAA, internal collisions are found with fewer and shorter messages than previously by exploiting the algorithm’s internal structure; consequently, the number of chosen texts (each 256 Kbyte long) for a forgery can be reduced by two orders of mag- nitude, e.g. from 224 to 217. This attack can be extended to one requiring only short messages (224 messages shorter than 1 Kbyte) to circumvent the special MAA mode for long messages. Moreover, certain internal collisions allow key recovery, and weak keys for MAA are identified.
N.F.W.O. postdoctoral researcher, sponsored by the National Fund for Scientific Research (Belgium).

Contact Information Bart Preneel
Email: bart.preneel@esat.kuleuven.ac.be

Contact Information Paul C. van Oorschot
Email: paulv@bnr.ca
Fulltext Preview (Small, Large)
Image of the first page of the fulltext

References secured to subscribers.



Export this chapter
Export this chapter as RIS | Text
 
Referenced by
1 newer article

  1. Preneel, B. (1999) On the security of iterated message authentication codes. IEEE Transactions on Information Theory 45(1)
    [CrossRef]
Remote Address: 38.107.191.109 • Server: mpweb20
HTTP User Agent: CCBot/1.0 (+http://www.commoncrawl.org/bot.html)