Network Working Group P. Metzger
Request for Comments: 1828 Piermont
Category: Standards Track W. Simpson
Daydreamer
August 1995
IP Authentication using Keyed MD5
Metzger & Simpson Standards Track [Page i]
RFC 1828 AH MD5 August 1995 1. IntroductionThe Authentication Header (AH) [RFC-1826] provides integrity and authentication for IP datagrams. This specification describes the AH use of keys with Message Digest 5 (MD5) [RFC-1321].
1.1. Keys
The secret authentication key shared between the communicating parties SHOULD be a cryptographically strong random number, not a guessable string of any sort.
1.2. Data Size
MD5's 128-bit output is naturally 64-bit aligned. Typically, there is no further padding of the Authentication Data field.
1.3. Performance
MD5 software speeds are adequate for commonly deployed LAN and WAN links, but reportedly are too slow for newer link technologies [RFC- 1810].
Metzger & Simpson Standards Track [Page 1]
RFC 1828 AH MD5 August 1995 2. CalculationThe 128-bit digest is calculated as described in [RFC-1321]. The specification of MD5 includes a portable 'C' programming language description of the MD5 algorithm.
Metzger & Simpson Standards Track [Page 2]
RFC 1828 AH MD5 August 1995
This attack requires approximately 24 days. The same form of attack is useful on any iterated n-bit hash function, and the time is entirely due to the 128-bit length of the MD5 hash.
Metzger & Simpson Standards Track [Page 3]
RFC 1828 AH MD5 August 1995
[RFC-1321]
Metzger & Simpson Standards Track [Page 4]
RFC 1828 AH MD5 August 1995
Author's Address