Network Working Group C. Madson
Request for Comments: 2404 Cisco Systems Inc.
Category: Standards Track R. Glenn
NIST
November 1998
The Use of HMAC-SHA-1-96 within ESP and AH
1. Introduction
This memo specifies the use of SHA-1 [FIPS-180-1] combined with HMAC [RFC-2104] as a keyed authentication mechanism within the context of the Encapsulating Security Payload and the Authentication Header. The goal of HMAC-SHA-1-96 is to ensure that the packet is authentic and cannot be modified in transit.
Madson & Glenn Standards Track [Page 1]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998
In this memo, HMAC-SHA-1-96 is used within the context of ESP and AH. For further information on how the various pieces of ESP - including the confidentiality mechanism -- fit together to provide security services, refer to [ESP] and [Thayer97a]. For further information on AH, refer to [AH] and [Thayer97a].
2. Algorithm and Mode
[FIPS-180-1] describes the underlying SHA-1 algorithm, while [RFC- 2104] describes the HMAC algorithm. The HMAC algorithm provides a framework for inserting various hashing algorithms such as SHA-1.
2.1 Performance
[Bellare96a] states that "(HMAC) performance is essentially that of the underlying hash function". As of this writing no detailed performance analysis has been done of SHA-1, HMAC or HMAC combined with SHA-1. [RFC-2104] outlines an implementation modification which can improve per-packet performance without affecting interoperability.
Madson & Glenn Standards Track [Page 2]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998 3. Keying MaterialHMAC-SHA-1-96 is a secret key algorithm. While no fixed key length is specified in [RFC-2104], for use with either ESP or AH a fixed key length of 160-bits MUST be supported. Key lengths other than 160- bits MUST NOT be supported (i.e. only 160-bit keys are to be used by HMAC-SHA-1-96). A key length of 160-bits was chosen based on the recommendations in [RFC-2104] (i.e. key lengths less than the authenticator length decrease security strength and keys longer than the authenticator length do not significantly increase security strength).
4. Interaction with the ESP Cipher Mechanism
As of this writing, there are no known issues which preclude the use of the HMAC-SHA-1-96 algorithm with any specific cipher algorithm.
Madson & Glenn Standards Track [Page 3]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998 5. Security ConsiderationsThe security provided by HMAC-SHA-1-96 is based upon the strength of HMAC, and to a lesser degree, the strength of SHA-1. At the time of this writing there are no practical cryptographic attacks against HMAC-SHA-1-96.
6. Acknowledgments
This document is derived in part from previous works by Jim Hughes, those people that worked with Jim on the combined DES/CBC+HMAC-MD5 ESP transforms, the ANX bakeoff participants, and the members of the IPsec working group.
Madson & Glenn Standards Track [Page 4]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998 7. References[FIPS-180-1] NIST, FIPS PUB 180-1: Secure Hash Standard,
8. Editors' Address
Cheryl Madson Cisco Systems, Inc.
Madson & Glenn Standards Track [Page 5]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998
The IPsec working group can be contacted through the chairs:
Madson & Glenn Standards Track [Page 6]
RFC 2404 The Use of HMAC-SHA-1-96 within ESP and AH November 1998 9. Full Copyright StatementCopyright (C) The Internet Society (1998). All Rights Reserved.