Network Working Group P. Metzger
Request for Comments: 1852 Piermont
Category: Experimental W. Simpson
Daydreamer
September 1995
IP Authentication using Keyed SHA
Metzger & Simpson Experimental [Page 1]
RFC 1852 AH SHA September 1995 1. IntroductionThe Authentication Header (AH) [RFC-1826] provides integrity and authentication for IP datagrams. This specification describes the AH use of keys with the Secure Hash Algorithm (SHA) [FIPS-180-1].
1.1. Keys
The secret authentication key shared between the communicating parties SHOULD be a cryptographically strong random number, not a guessable string of any sort.
1.2. Data Size
SHA's 160-bit output is naturally 32-bit aligned. However, many implementations require 64-bit alignment of the following headers, in which case an additional 32 bits of padding is added, either before or after the SHA output.
1.3. Performance
Preliminary results indicate that SHA is 62% as fast as MD5, and 80% as fast as DES hashing. That is,
Metzger & Simpson Experimental [Page 2]
RFC 1852 AH SHA September 1995
SHA < DES < MD5
2. Calculation
The 160-bit digest is calculated as described in [FIPS-180-1]. At the time of writing, a portable C language implementation of SHA is available via FTP from ftp://rand.org/pub/jim/sha.tar.gz.
Metzger & Simpson Experimental [Page 3]
RFC 1852 AH SHA September 1995
Security Considerations
Metzger & Simpson Experimental [Page 4]
RFC 1852 AH SHA September 1995
References
Metzger & Simpson Experimental [Page 5]
RFC 1852 AH SHA September 1995
Author's Address