Message Authenticator Algorithm
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
top
The Message Authenticator Algorithm (MAA) was one of the first cryptographic functions for computing a message authentication code (MAC).
Contents
β’ History
β’ Attacks
β’ References
β’ External links
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
History
It was designed in 1983 by Donald Davies and David Clayden at the National Physical Laboratory (United Kingdom) in response to a request of the UK Bankers Automated Clearing Services. The MAA was one of the first Message Authentication Code algorithms to gain widespread acceptance.
Development and standardization
Attacks
Later, cryptanalysis of MAA revealed various weaknesses, including feasible brute-force attacks, existence of collision clusters, and key-recovery techniques.cite-ref-6[6]cite-ref-7[7]cite-ref-8[8]cite-ref-9[9] For this reason, MAA was withdrawn from ISO standards in 2002 but continued to be used as a prominent case study for assessing various formal methods.cite-ref-10[10]
Formal specifications of the MAA
The MAA has been used as a prominent case study for assessing various formal methods.
In the early 1990s, the NPL developed three formal specifications of the MAA: one in Z,cite-ref-11[11] one in LOTOS,cite-ref-12[12] and one in VDM.cite-ref-13[13]cite-ref-14[14] The VDM specification became part of the 1992 revision of the International Standard 8731-2, and three implementations were manually derived from that latter specification: C, Miranda, and Modula-2.cite-ref-15[15]
Other formal models of the MAA have been developed. In 2017, a complete formal specification of the MAA as a large term rewriting system was published;cite-ref-16[16] From this specification, implementations of the MAA in fifteen different languages have been generated automatically. In 2018, two new formal specifications of the MAA, in LOTOS and LNT, have been published.cite-ref-17[17]
References
cite-note-11. β citerefdavies1985Davies, Donald W. (1985). "A Message Authenticator Algorithm Suitable for a Mainframe Computer". Advances in Cryptology β Proceedings of the Workshop on the Theory and Application of Cryptographic Techniques (CRYPTOβ84), Santa Barbara, CA, USA. Lecture Notes in Computer Science. Vol. 196. Springer. pp. 393β400. doi:10.1007/3-540-39568-7_30.
cite-note-22. β citerefdaviesclayden1988Davies, Donald W.; Clayden, David O. (1988). The Message Authenticator Algorithm (MAA) and its Implementation (PDF) (NPL Report DITC 109/88). Teddington, Middlesex, UK: National Physical Laboratory.
cite-note-33. β citerefinternational-organization-for-standardization1987International Organization for Standardization (1987). International Standard 8731-2. Approved Algorithms for Message Authentication β Part 2: Message Authenticator Algorithm (MAA) (Report). Geneva.
cite-note-44. β citerefinternational-organization-for-standardization1992International Organization for Standardization (1992). International Standard 8731-2. Approved Algorithms for Message Authentication β Part 2: Message Authenticator Algorithm (MAA) (Report). Geneva.
cite-note-55. β citerefinternational-organization-for-standardization1990International Organization for Standardization (1990). International Standard 8730. Requirements for Message Authentication (Wholesale) (Report). Geneva.
cite-note-66. β citerefpreneelvan-oorschot1996Preneel, Bart; van Oorschot, Paul C. (1996). On the Security of Two MAC Algorithms. Advances in Cryptology β Proceedings of the International Conference on the Theory and Application of Cryptographic Techniques (EUROCRYPTβ96), Saragossa, Spain. Lecture Notes in Computer Science. Vol. 1070. Springer. pp. 19β32. doi:10.1007/3-540-68339-9_3.
cite-note-88. β citerefpreneelrumenvan-oorschot1997Preneel, Bart; Rumen, Vincent; van Oorschot, Paul C. (1997). "Security Analysis of the Message Authenticator Algorithm (MAA) -journal=European Transactions on Telecommunications". 8 (5): 455β470. doi:10.1002/ett.4460080504. {{cite journal}}: Cite journal requires |journal= (help)
cite-note-99. β citerefrijmenpreneelde-win1996Rijmen, Vincent; Preneel, Bart; De Win, Erik (1996). Key Recovery and Collision Clusters for MAA (PDF). Proceedings of the 1st International Conference on Security in Communication Networks (SCNβ96).
cite-note-1111. β citerefm-k-f-lai1991M. K. F. Lai (1991). A Formal Interpretation of the MAA Standard in Z (NPL Report DITC 184/91). Teddington, Middlesex, UK: National Physical Laboratory.
cite-note-1212. β citerefharold-b-munster1991Harold B. Munster (1991). LOTOS Specification of the MAA Standard, with an Evaluation of LOTOS (PDF) (NPL Report DITC 191/91). Teddington, Middlesex, UK: National Physical Laboratory. Archived from the original (PDF) on 2017-07-06.
cite-note-1313. β citerefgraeme-i-parking-o-neill1990Graeme I. Parkin; G. OβNeill (1990). Specification of the MAA Standard in VDM (NPL Report DITC 160/90). National Physical Laboratory, Teddington, Middlesex, UK.
cite-note-1414. β citerefgraeme-i-parking-o-neill1991Graeme I. Parkin; G. OβNeill (1991). SΓΈren Prehn; W. J. Toetenel (eds.). Specification of the MAA Standard in VDM. Formal Software Development β Proceedings (Volume 1) of the 4th International Symposium of VDM Europe (VDMβ91), Noordwijkerhout, The Netherlands. Lecture Notes in Computer Science. Vol. 551. Springer. pp. 526β544. doi:10.1007/3-540-54834-3_31.
cite-note-1515. β citerefr-p-lampard1991R. P. Lampard (1991). An Implementation of MAA from a VDM Specification (NPL Technical Memorandum DITC 50/91). Teddington, Middlesex, UK: National Physical Laboratory.
cite-note-1616. β citerefgaravelmarsso2017Garavel, Hubert; Marsso, Lina (2017). A Large Term Rewrite System Modelling a Pioneering Cryptographic Algorithm. Proceedings of the 2nd Workshop on Models for Formal Analysis of Real Systems (MARS'17), Uppsala, Sweden. Electronic Proceedings in Theoretical Computer Science. Vol. 244. pp. 129β183. arXiv:1703.06573. doi:10.4204/EPTCS.244.6.
cite-note-1717. β citerefgaravelmarsso2018Garavel, Hubert; Marsso, Lina (2018). Comparative Study of Eight Formal Specifications of the Message Authenticator Algorithm. Proceedings of the 3nd Workshop on Models for Formal Analysis of Real Systems (MARS'18) and 6th International Workshop on Verification and Program Transformation (MARS/VPT 2018), Thessaloniki, Greece. Electronic Proceedings in Theoretical Computer Science. Vol. 268. pp. 41β87. arXiv:1803.10322. doi:10.4204/EPTCS.268.2.
External links
β’ http://www.cix.co.uk/~klockstone/maa.htm
β’ http://www.mars-workshop.org/repository/012-MAA.html