cmac

package
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 2, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package cmac implements the AES-CMAC message authentication code of NIST SP 800-38B, also published as RFC 4493.

CCSDS 355.0-B-2 clause E2 names it as the baseline authentication algorithm for telecommand: AES-CMAC with a 256-bit key and a 128-bit tag. The Go standard library has AES but no CMAC, so it is implemented here rather than pulled in as a dependency, pkg/ takes none.

How it works

CMAC is CBC-MAC with the flaw fixed. Plain CBC-MAC is forgeable across messages of different lengths, so CMAC derives two subkeys from the block cipher and mixes one of them into the final block: K1 when the message is a whole number of blocks, K2 when it had to be padded. Which subkey was used is therefore bound into the tag, and the length ambiguity disappears.

Index

Constants

View Source
const BlockSize = aes.BlockSize

BlockSize is the AES block size in octets, and the size of a CMAC tag.

Variables

View Source
var ErrInvalidTagLength = errors.New("invalid CMAC tag length: must be 1 to 16 octets")

ErrInvalidTagLength indicates a truncation length outside 1 to 16 octets.

Functions

This section is empty.

Types

type CMAC

type CMAC struct {
	// contains filtered or unexported fields
}

CMAC holds the subkeys derived from a key, so a caller authenticating many messages under one key derives them once.

func New

func New(key []byte) (*CMAC, error)

New returns a CMAC for the given AES key. The key must be 16, 24 or 32 octets; CCSDS 355.0-B-2 clause E2a requires 32.

func (*CMAC) Sum

func (c *CMAC) Sum(message []byte) []byte

Sum returns the 128-bit CMAC tag of message.

func (*CMAC) SumTruncated

func (c *CMAC) SumTruncated(message []byte, length int) ([]byte, error)

SumTruncated returns the leading length octets of the tag.

SP 800-38B clause 6.4 permits truncation and warns that a shorter tag weakens the forgery bound. CCSDS 355.0-B-2 clause E2c specifies the full 128 bits, so a caller following the baseline has no reason to truncate.

func (*CMAC) Verify

func (c *CMAC) Verify(message, tag []byte) bool

Verify reports whether tag authenticates message.

The comparison is constant time. Comparing tags with bytes.Equal would leak how many leading octets a forgery got right, which is enough to find the rest one octet at a time.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL