ISO/IEC 9797-1:2011
Information technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using a block cipher
Information technology — Security techniques — Message Authentication Codes (MACs) — Part 1: Mechanisms using a block cipher
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 40
- Дата публикации:
- 1 марта 2011 г.
- Издание:
- ISO/IEC IS 9797 edition 2 version 1
- ICS:
- 35.030
ISO/IEC 9797-1:2011 specifies six MAC algorithms that use a secret key and an n-bit block cipher to calculate an m-bit MAC. ISO/IEC 9797-1:2011 can be applied to the security services of any security architecture, process, or application. Key management mechanisms are outside the scope of ISO/IEC 9797-1:2011. ISO/IEC 9797-1:2011 specifies object identifiers that can be used to identify each mechanism in accordance with ISO/IEC 8825-1. Numerical examples and a security analysis of each of the six specified algorithms are provided, and the relationship of ISO/IEC 9797-1:2011 to previous standards is explained.
Abstract
Overview
ISO/IEC 9797-1:2011 - Information technology - Security techniques - Message Authentication Codes (MACs) - Part 1: Mechanisms using a block cipher specifies six standardized MAC algorithms that compute an m‑bit MAC from a message and a secret key using an n‑bit block cipher. The standard is applicable to security services across architectures, processes, and applications that require data integrity and message authentication. It includes algorithm models, numerical examples, object identifiers, and a security analysis; key management is explicitly outside its scope.
Key topics and technical requirements
- Six MAC algorithms based on an n‑bit block cipher (the first being the well‑known CBC‑MAC and five related variants).
- Algorithm model steps documented in detail:
- Key derivation (two methods)
- Padding (four methods)
- Splitting, iteration, final iteration
- Output transformation (three methods)
- Truncation
- Variants and recommendations:
- MAC Algorithm 4: transformation at start and end; suited where MAC key length is twice the block cipher key length.
- MAC Algorithm 5: optimized for minimal encryptions - single block‑cipher key setup but requires a longer internal key.
- MAC Algorithm 6: optimized variant of Algorithm 2 for efficiency.
- Normative and informative material:
- Object identifiers for each mechanism (per ISO/IEC 8825‑1).
- Numerical examples (Annex B) and a security analysis (Annex C).
- Comparison with previous standards (Annex D).
- Referenced standards: e.g., ISO/IEC 18033‑3 (block ciphers) is referenced for underlying cipher requirements.
Applications and who uses it
ISO/IEC 9797-1:2011 is used wherever authenticated integrity of messages is required:
- Security architects and systems designers incorporating MACs into protocols and applications.
- Cryptographic library and secure software developers implementing MAC algorithms (CBC‑MAC and variants).
- Hardware vendors building secure modules (HSMs, TPMs) that provide MAC services.
- Certification bodies and compliance teams specifying standard object identifiers and validated algorithms.
- Network, payment, and IoT solution providers that require interoperable message authentication.
Practical applications include transaction authentication, firmware integrity checks, secure logging, protocol message protection, and any service requiring efficient block‑cipher‑based MACs.
Related standards
- ISO/IEC 9797‑2 (MACs using dedicated hash functions)
- ISO/IEC 9797‑3 (MACs using universal hash functions)
- ISO/IEC 18033‑3 (block cipher specifications)
- ISO/IEC 8825‑1 (object identifier encoding)
Keywords: ISO/IEC 9797-1:2011, Message Authentication Codes, MAC, CBC‑MAC, block cipher, data integrity, security standard, ISO.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9797-1:2011
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 8825-1:2015
ОтменёнInformation technology — ASN.1 encoding rules: Specification of Basic Encoding Rules (BER), Canonical Encodin…
ISO/IEC 18033-3:2010
ДействующийInformation technology — Security techniques — Encryption algorithms — Part 3: Block ciphers
Overview ISO/IEC 18033-3:2010 - "Information technology - Security techniques - Encryption algorithms - Part 3: Block ciphers" is the international standard that specifies a set of block cipher algor…
ISO/IEC 9797-2:2021
ДействующийInformation security — Message authentication codes (MACs) — Part 2: Mechanisms using a dedicated hash-functi…
Overview ISO/IEC 9797-2:2021 - Information security - Message authentication codes (MACs) - Part 2: Mechanisms using a dedicated hash-function - specifies standardized MAC algorithms that derive an m…
ISO/IEC 9797-3:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 3: Mechanisms using…
Overview ISO/IEC 9797-3:2011 - "Information technology - Security techniques - Message Authentication Codes (MACs) - Part 3: Mechanisms using a universal hash-function" - specifies MAC algorithms tha…