HMAC
Hash-based Message Authentication Code as defined in RFC 2104. Provides cryptographic authentication and integrity verification using any cryptographic hash function.
Properties
| Property |
Value |
| Category |
Message Authentication |
| Sub-category |
HMAC |
| Security status |
🛡️ Secure |
| Complexity |
Intermediate |
| Inventor |
Mihir Bellare, Ran Canetti, Hugo Krawczyk |
| Year |
1996 |
| Origin |
🇺🇸 United States |
| Source |
algorithms/mac/hmac.js |
Parameters
| Parameter |
Supported values |
| MAC sizes |
16 bytes (128 bits) to 64 bytes (512 bits) |
Capabilities
Security
Status: 🛡️ Secure
Known vulnerabilities
| Issue |
Description |
Mitigation |
| Weak Hash Function |
Use modern hash functions like SHA-256 or SHA-512 instead of MD5 or SHA-1 |
— |
| Key Reuse |
Use unique keys for different applications and contexts |
— |
Documentation
References
Test vectors
2 vectors ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — HMAC-MD5 Botan Vector 1 - ‘Hi There’
| Field |
Value |
key |
0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b |
hashFunction |
4d4435 |
input |
4869205468657265 |
expected |
9294727a3638bb1c13f48ef8158bfc9d |
Vector 2 — HMAC-MD5 Botan Vector 2 - ‘Test With Truncation’
| Field |
Value |
key |
0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c |
hashFunction |
4d4435 |
input |
546573742057697468205472756e636174696f6e |
expected |
56461ef2342edc00f9bab995690efd4c |
← All algorithms