NOTE
1.5 Message Authentication Code
Purpose, process, limitations, and HMAC.
This is a historical learning note and may contain outdated or incomplete understanding.
1. What Is a Message Authentication Code
MAC, a technique used to verify message integrity and perform authentication.
2. Message Authentication Code Properties
Integrity + authentication.
3. Purpose of a Message Authentication Code
- Ensure that data has not been tampered with – a hash function is used.
- Authenticate the sender – only the two parties have the key.
4. Message Authentication Code Process

5. Problems with Message Authentication Codes
- The key cannot be distributed effectively.
- Third-party proof cannot be provided.
- It cannot prevent the sender from denying having sent the message.
5.1. Solution
Digital signature.
6. How to Implement a Message Authentication Code
6.1. HMAC
A method of constructing a message authentication code using a hash function.

7. Advanced Message Authentication Codes
A message authentication code itself does not automatically prevent replay attacks; normally a nonce, timestamp, sequence number, or similar authenticated data is also required.
How to design an open API interface
Discussion
Sign in with GitHub to comment. Discussions are stored as GitHub Issues.View on GitHub