The AES-CMAC-96 Algorithm and Its Use with IPsec
RFC 4494, “The AES-CMAC-96 Algorithm and Its Use with IPsec”, is a Proposed Standard document published in June 2006 by JH. Song, R. Poovendran, J. Lee. The canonical text is published by the RFC Editor.
Abstract
The National Institute of Standards and Technology (NIST) has recently specified the Cipher-based Message Authentication Code (CMAC), which is equivalent to the One-Key CBC-MAC1 (OMAC1) algorithm submitted by Iwata and Kurosawa. OMAC1 efficiently reduces the key size of Extended Cipher Block Chaining mode (XCBC). This memo specifies the use of CMAC mode as an authentication mechanism of the IPsec Encapsulating Security Payload (ESP) and the Authentication Header (AH) protocols. This new algorithm is named AES-CMAC-96. [STANDARDS-TRACK]
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 4494 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 4493 The AES-CMAC Algorithm
- RFC 4495 A Resource Reservation Protocol Extension for the Reduction of Bandwidth of a Reservation Flow
- RFC 4492 Elliptic Curve Cryptography Cipher Suites for Transport Layer Security
- RFC 4496 Open Pluggable Edge Services SMTP Use Cases
- RFC 4491 Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms with the Internet X.509 Public Key Infrastructure Certificate and CRL Profile
- RFC 4497 Interworking between the Session Initiation Protocol and QSIG
- RFC 4490 Using the GOST 28147-89, GOST R 34.11-94, GOST R 34.10-94, and GOST R 34.10-2001 Algorithms with Cryptographic Message Syntax
- RFC 4498 The Managed Object Aggregation MIB