Network Working Group C. Madson
Request for Comments: 2403 Cisco Systems Inc.
Category: Standards Track R. Glenn
NIST
November 1998
The Use of HMAC-MD5-96 within ESP and AH
1. Introduction
This memo specifies the use of MD5 [RFC-1321] combined with HMAC [RFC-2104] as a keyed authentication mechanism within the context of the Encapsulating Security Payload and the Authentication Header. The goal of HMAC-MD5-96 is to ensure that the packet is authentic and cannot be modified in transit.
Madson & Glenn Standards Track [Page 1]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC-2119].
2. Algorithm and Mode
[RFC-1321] describes the underlying MD5 algorithm, while [RFC-2104] describes the HMAC algorithm. The HMAC algorithm provides a framework for inserting various hashing algorithms such as MD5.
2.1 Performance
[Bellare96a] states that "(HMAC) performance is essentially that of the underlying hash function". [RFC-1810] provides some performance analysis and recommendations of the use of MD5 with Internet protocols. As of this writing no performance analysis has been done of HMAC or HMAC combined with MD5.
Madson & Glenn Standards Track [Page 2]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998 3. Keying MaterialHMAC-MD5-96 is a secret key algorithm. While no fixed key length is specified in [RFC-2104], for use with either ESP or AH a fixed key length of 128-bits MUST be supported. Key lengths other than 128- bits MUST NOT be supported (i.e. only 128-bit keys are to be used by HMAC-MD5-96). A key length of 128-bits was chosen based on the recommendations in [RFC-2104] (i.e. key lengths less than the authenticator length decrease security strength and keys longer than the authenticator length do not significantly increase security strength).
4. Interaction with the ESP Cipher Mechanism
As of this writing, there are no known issues which preclude the use of the HMAC-MD5-96 algorithm with any specific cipher algorithm.
Madson & Glenn Standards Track [Page 3]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998 5. Security ConsiderationsThe security provided by HMAC-MD5-96 is based upon the strength of HMAC, and to a lesser degree, the strength of MD5. [RFC-2104] claims that HMAC does not depend upon the property of strong collision resistance, which is important to consider when evaluating the use of MD5, an algorithm which has, under recent scrutiny, been shown to be much less collision-resistant than was first thought. At the time of this writing there are no practical cryptographic attacks against HMAC-MD5-96.
Madson & Glenn Standards Track [Page 4]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998 6. AcknowledgmentsThis document is derived in part from previous works by Jim Hughes, those people that worked with Jim on the combined DES/CBC+HMAC-MD5 ESP transforms, the ANX bakeoff participants, and the members of the IPsec working group.
7. References
[RFC-1321] Rivest, R., "MD5 Digest Algorithm", RFC 1321, April
Madson & Glenn Standards Track [Page 5]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998 8. Editors' AddressCheryl Madson Cisco Systems, Inc.
Madson & Glenn Standards Track [Page 6]
RFC 2403 The Use of HMAC-MD5-96 within ESP and AH November 1998 9. Full Copyright StatementCopyright (C) The Internet Society (1998). All Rights Reserved.