1. A General Model for MAC Generation Using Direct Injection
- Author
-
Mufeed Juma ALMashrafi, Kenneth Koon-Ho Wong, Leonie Simpson, Ed Dawson, and Harry Bartlett
- Subjects
Nonlinear filter ,Computer science ,Hash function ,Matrix representation ,SOBER-128 ,State (computer science) ,Collision ,Algorithm ,Stream cipher ,Generator (mathematics) - Abstract
This paper presents a model for generating a MAC tag by injecting the input message directly into the internal state of a nonlinear filter generator. This model generalises a similar model for unkeyed hash functions proposed by Nakano et al. We develop a matrix representation for the accumulation phase of our model and use it to analyse the security of the model against man-in-the-middle forgery attacks based on collisions in the final register contents. The results of this analysis show that some conclusions of Nakano et al regarding the security of their model are incorrect. We also use our results to comment on several recent MAC proposals which can be considered as instances of our model and specify choices of options within the model which should prevent the type of forgery discussed here. In particular, suitable initialisation of the register and active use of a secure nonlinear filter will prevent an attacker from finding a collision in the final register contents which could result in a forged MAC.
- Published
- 2013
- Full Text
- View/download PDF