The AES-XCBC-MAC-96 Algorithm and Its Use With IPsec
RFC 3566, “The AES-XCBC-MAC-96 Algorithm and Its Use With IPsec”, is a Proposed Standard document published in September 2003 by S. Frankel, H. Herbert. The canonical text is published by the RFC Editor.
Abstract
A Message Authentication Code (MAC) is a key-dependent one way hash function. One popular way to construct a MAC algorithm is to use a block cipher in conjunction with the Cipher-Block-Chaining (CBC) mode of operation. The classic CBC-MAC algorithm, while secure for messages of a pre-selected fixed length, has been shown to be insecure across messages of varying lengths such as the type found in typical IP datagrams. This memo specifies the use of AES in CBC mode with a set of extensions to overcome this limitation. This new algorithm is named AES-XCBC-MAC-96. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 3566 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 3565 Use of the Advanced Encryption Standard Encryption Algorithm in Cryptographic Message Syntax
- RFC 3567 Intermediate System to Intermediate System Cryptographic Authentication
- RFC 3564 Requirements for Support of Differentiated Services-aware MPLS Traffic Engineering
- RFC 3568 Known Content Network Request-Routing Mechanisms
- RFC 3563 Cooperative Agreement Between the ISOC/IETF and ISO/IEC Joint Technical Committee 1/Sub Committee 6 on IS-IS Routing Protocol Development
- RFC 3569 An Overview of Source-Specific Multicast
- RFC 3562 Key Management Considerations for the TCP MD5 Signature Option
- RFC 3570 Content Internetworking Scenarios