Hawkynt

CFB-MAC

Cipher Feedback Mode MAC uses a block cipher in CFB mode to generate message authentication codes. Standardized in ISO/IEC 9797-1:1999.

Properties

Property Value
Category Message Authentication
Sub-category Block Cipher MAC
Security status 🎓 Educational Only
Complexity Intermediate
Inventor ISO/IEC JTC 1/SC 27
Year 1999
Origin 🌐 International
Source algorithms/mac/cfbmac.js

Parameters

Parameter Supported values
MAC sizes 4 bytes (32 bits) to 16 bytes (128 bits)

Capabilities

Flag Value
NeedsKey Yes

Security

Status: 🎓 Educational Only

Known vulnerabilities

Issue Description Mitigation
Length Extension — CFB-MAC is vulnerable to message length extension attacks. Use CMAC or HMAC for production.

Documentation

References

Test vectors

2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.

Vector 1 — BouncyCastle MacTest Vector 1 - DES CFB-MAC with IV

Field Value
key 0123456789abcdef
iv 1234567890abcdef
macSize 4
input 37363534333231204e6f77206973207468652074696d6520666f7220
expected cd647403

Vector 2 — BouncyCastle MacTest Vector 2 - DES CFB-MAC, block-aligned 8 byte message

Field Value
key 0123456789abcdef
iv 1234567890abcdef
macSize 4
input 3736353433323120
expected 3af549c9

← All algorithms