ISO/IEC 9797-2:2021
Information security — Message authentication codes (MACs) — Part 2: Mechanisms using a dedicated hash-function
Information security — Message authentication codes (MACs) — Part 2: Mechanisms using a dedicated hash-function
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 52
- Дата публикации:
- 23 июня 2021 г.
- Издание:
- ISO/IEC IS 9797 edition 3 version 1
- ICS:
- 35.030
This document specifies MAC algorithms that use a secret key and a hash-function (or its round-function or sponge function) to calculate an m-bit MAC. These mechanisms can be used as data integrity mechanisms to verify that data has not been altered in an unauthorized manner. NOTE A general framework for the provision of integrity services is specified in ISO/IEC 10181‑6.
Abstract
Overview
ISO/IEC 9797-2:2021 - Information security - Message authentication codes (MACs) - Part 2: Mechanisms using a dedicated hash-function - specifies standardized MAC algorithms that derive an m‑bit MAC from a secret key and a dedicated hash-function (or its round- or sponge-function). These MAC mechanisms are intended as data integrity primitives to verify that data has not been altered in an unauthorized manner. The third edition (2021) updates algorithm options and adds Keccak-based MAC variants.
Key topics
- MAC algorithms and variants: The standard defines multiple MAC algorithms (Algorithms 1–4) with stepwise procedures such as key expansion, modification of constants/IV, hashing operation (or round-function/sponge application), output transformation, and truncation.
- Dedicated hash-functions: Specifies use of dedicated hash primitives (examples in the standard include RIPEMD‑128/160, SHA‑1, SHA‑224/256/384/512, SM3 and Keccak-based functions). Algorithm 4 includes KMAC/KMACXOF constructions based on Keccak.
- Encoding and padding: Rules for integer/byte encoding, string encoding and padding for input preparation are included.
- Efficiency and constants: Sections address computational efficiency and procedures for computing constants and IV modifications for each dedicated hash-function.
- Security analysis: Annex C provides an informative security analysis of the MAC algorithms and design rationale.
Applications
- Message authentication in network protocols (TLS-like or custom secure channels)
- Data integrity verification for storage, logs, and firmware images
- Authentication tokens and secure APIs where keyed integrity is required
- Cryptographic protocol design and implementation (smart cards, IoT devices, servers) Practical users include cryptographers, security architects, protocol designers, firmware and software implementers, and compliance officers who must select or validate MAC mechanisms for secure systems.
Who should use this standard
- Implementers building MAC-enabled libraries or hardware who need interoperable, standardized MAC definitions
- Security engineers designing integrity services that rely on hash-based MACs
- Auditors and evaluators assessing cryptographic compliance and conformance to ISO/IEC standards
Related standards
- ISO/IEC 10118-3 - Dedicated hash-functions (normative reference)
- ISO/IEC 10181‑6 - Framework for integrity services (informative note)
- Other parts of the ISO/IEC 9797 series for complementary MAC guidance
Keywords: ISO/IEC 9797-2:2021, message authentication codes, MAC, dedicated hash-function, data integrity, KMAC, Keccak, SHA‑256, SM3, RIPEMD, MAC algorithms.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 9797-2:2021
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 10118-3:2018
ДействующийIT Security techniques — Hash-functions — Part 3: Dedicated hash-functions
Overview ISO/IEC 10118-3:2018 - IT Security techniques - Hash-functions - Part 3: Dedicated hash‑functions specifies a set of specially designed (dedicated) cryptographic hash‑functions. The standard…
ISO/IEC 10181-6:1996
ДействующийInformation technology — Open Systems Interconnection — Security frameworks for open systems: Integrity frame…
Overview ISO/IEC 10181-6:1996 - Information technology - Open Systems Interconnection - Security frameworks for open systems: Integrity framework - defines a general integrity framework for open syst…
ISO/IEC 9797-3:2011
ДействующийInformation technology — Security techniques — Message Authentication Codes (MACs) — Part 3: Mechanisms using…
Overview ISO/IEC 9797-3:2011 - "Information technology - Security techniques - Message Authentication Codes (MACs) - Part 3: Mechanisms using a universal hash-function" - specifies MAC algorithms tha…