A Message Authentication Code (MAC) is a fixed-size cryptographic tag generated from an arbitrary-length message and a shared secret key using a keyed hash or block-cipher-based algorithm, providing simultaneous data integrity verification and authentication of the sender to any party holding the same secret key. Unlike digital signatures, MACs are symmetric and do not provide non-repudiation.

Content

  • The theoretical basis for MACs emerged from Shannon’s information-theoretic treatment of authentication (1949), which established that an unconditionally secure authentication scheme requires keys as long as the message. Practical computationally-secure constructions were developed from the 1970s alongside symmetric block ciphers. CBC-MAC — applying a block cipher in cipher-block-chaining mode and retaining the final ciphertext block as the tag — was an early practical construction. However, CBC-MAC has subtle security limitations (it is not secure for variable-length messages without padding), leading to the standardisation of CMAC (NIST SP 800-38B, 2005).
  • HMAC (Krawczyk, Bellare, and Canetti, 1996) standardised a provably secure MAC construction based on iterated hash functions: HMAC-K(m) = H((K⊕opad) || H((K⊕ipad) || m)), where H is a cryptographic hash and opad/ipad are fixed padding constants. HMAC’s security reduces to the PRF security of the underlying hash, making it robust even if the hash has length-extension vulnerabilities. Polynomial authentication codes (Poly1305, by Bernstein) use finite-field arithmetic and achieve extremely high throughput in software, making them the basis of the ChaCha20-Poly1305 AEAD construction used in TLS 1.3, WireGuard, and Signal.
  • In the TLS 1.3 handshake, MACs are subsumed within Authenticated Encryption with Associated Data (AEAD) constructions — AES-GCM and ChaCha20-Poly1305 — that simultaneously encrypt and authenticate in a single pass, eliminating the “MAC-then-encrypt vs encrypt-then-MAC” ordering vulnerabilities that plagued earlier protocol versions. IPsec’s Encapsulating Security Payload (ESP) and Authentication Header (AH) use HMAC-SHA256 or AES-GMAC as integrity algorithms. Message-level MACs also protect API authentication tokens (HMAC-based CSRF tokens, AWS Signature Version 4 request signing).
  • By 2024–2025, MAC algorithms are considered cryptographically sound when constructed from SHA-2, SHA-3, or AES primitives with appropriate key lengths. Post-quantum considerations affect Digital Signature schemes more acutely than MACs, since MACs rely on symmetric primitives that offer quadratic Grover speedup resistance — doubling key length (e.g., 256-bit keys) restores security margins. Research attention focuses on lightweight MAC designs (GIFT-COFB, Ascon-MAC) for constrained IoT devices under NIST lightweight cryptography standardisation, and on decentralised MAC schemes for threshold-authenticated distributed systems.