Documentation
¶
Overview ¶
Package cmac implements the AES-CMAC message authentication code of NIST SP 800-38B, also published as RFC 4493.
CCSDS 355.0-B-2 clause E2 names it as the baseline authentication algorithm for telecommand: AES-CMAC with a 256-bit key and a 128-bit tag. The Go standard library has AES but no CMAC, so it is implemented here rather than pulled in as a dependency, pkg/ takes none.
How it works ¶
CMAC is CBC-MAC with the flaw fixed. Plain CBC-MAC is forgeable across messages of different lengths, so CMAC derives two subkeys from the block cipher and mixes one of them into the final block: K1 when the message is a whole number of blocks, K2 when it had to be padded. Which subkey was used is therefore bound into the tag, and the length ambiguity disappears.
Index ¶
Constants ¶
const BlockSize = aes.BlockSize
BlockSize is the AES block size in octets, and the size of a CMAC tag.
Variables ¶
var ErrInvalidTagLength = errors.New("invalid CMAC tag length: must be 1 to 16 octets")
ErrInvalidTagLength indicates a truncation length outside 1 to 16 octets.
Functions ¶
This section is empty.
Types ¶
type CMAC ¶
type CMAC struct {
// contains filtered or unexported fields
}
CMAC holds the subkeys derived from a key, so a caller authenticating many messages under one key derives them once.
func New ¶
New returns a CMAC for the given AES key. The key must be 16, 24 or 32 octets; CCSDS 355.0-B-2 clause E2a requires 32.
func (*CMAC) SumTruncated ¶
SumTruncated returns the leading length octets of the tag.
SP 800-38B clause 6.4 permits truncation and warns that a shorter tag weakens the forgery bound. CCSDS 355.0-B-2 clause E2c specifies the full 128 bits, so a caller following the baseline has no reason to truncate.