CBC-MAC
Cipher Block Chaining Message Authentication Code using a block cipher in CBC mode. Foundation for more secure variants like CMAC.
Properties
| Property |
Value |
| Category |
Message Authentication |
| Sub-category |
Block Cipher MAC |
| Security status |
⚠️ Deprecated |
| Complexity |
Beginner |
| Inventor |
Various (standard construction) |
| Year |
1976 |
| Origin |
Not specified |
| Source |
algorithms/mac/cbcmac.js |
Parameters
| Parameter |
Supported values |
| MAC sizes |
4 bytes (32 bits) to 16 bytes (128 bits) |
Capabilities
Security
Status: ⚠️ Deprecated
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Variable Length Extension Attack |
— |
CBC-MAC is insecure for variable-length messages without additional protection. An attacker can forge MACs by extending messages. |
Documentation
References
Test vectors
4 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — FIPS 113 / BouncyCastle Test #1 - Zero IV, Non-aligned
| Field |
Value |
key |
0123456789abcdef |
macSize |
4 |
input |
37363534333231204e6f77206973207468652074696d6520666f7220 |
expected |
f1d30f68 |
Vector 2 — BouncyCastle Test #2 - Explicit IV, Non-aligned
| Field |
Value |
key |
0123456789abcdef |
iv |
1234567890abcdef |
macSize |
4 |
input |
37363534333231204e6f77206973207468652074696d6520666f7220 |
expected |
58d2e77e |
Vector 3 — BouncyCastle Test #3 - Word Aligned (Zero Padding)
| Field |
Value |
key |
0123456789abcdef |
macSize |
4 |
input |
3736353433323120 |
expected |
21fb1936 |
Vector 4 — BouncyCastle Test #4 - Full MAC Length
| Field |
Value |
key |
0123456789abcdef |
macSize |
8 |
input |
37363534333231204e6f77206973207468652074696d6520666f7220 |
expected |
f1d30f6849312ca4 |
← All algorithms