Learning path

Full curriculum

Full curriculum

Unit content

Message authentication codes

A message authentication code (MAC) uses a shared secret key to protect the integrity and authenticity of a message.

The sender computes a tag

$$t=\operatorname{MAC}_k(m),$$

and sends the message together with the tag. A receiver that knows $k$ recomputes or verifies the tag.

An adversary who can modify the message but does not know the key should not be able to produce a valid tag for a new modified message.

A MAC does not provide confidentiality: the authenticated message may remain completely readable. Its purpose is to make unauthorized modification or forgery detectable.

MACs also do not provide public proof of who created a message, because every party that knows the shared key can generate valid tags. Digital signatures use a different key model when public verifiability is required.

Authentication tags must cover the complete context that matters, not merely the obvious payload; omitted fields can remain vulnerable to undetected substitution.