0 / 4
Message Authentication Code (MAC)
Put the original message and a secret key K into a hash function together, and you get a fixed-length value: the MAC. The sender attaches the MAC to the original message, and the receiver recomputes the MAC with the same key and compares it with the attached one.
Example: Alice sends Bob the message “Send $10”. The original goes as it is, with the MAC attached after it.
1 / 4
Alice: make the MAC
Alice puts the original “Send $10” and the secret key K into the hash function together and gets the MAC 3f9a. Because the key is mixed in, no one without K can produce the same value.
2 / 4
Alice → Bob: send the original with the MAC attached
Alice sends the original with the MAC attached after it. The two are not added up; they travel side by side. The secret key K is not sent, and the original is not encrypted, so anyone on the way can read it.
3 / 4
Bob: recompute the MAC
Bob puts the received original and his own copy of the same key K into the hash function and computes the MAC himself. The result is 3f9a.
4 / 4
Bob: compare the two values
The recomputed value (3f9a) matches the MAC attached to the original (3f9a). Bob confirms the original was not changed (integrity) and that Alice, who holds the same key, sent it (message authentication), so he accepts it.
1 / 6
Alice: make the MAC
Alice puts the original “Send $10” and the secret key K into the hash function together and gets the MAC 3f9a.
2 / 6
Alice → Mallory: intercepted
Alice sent the original with the MAC attached, but the attacker Mallory intercepted it on the way.
3 / 6
Mallory: change the original
Mallory changes the original to “Send $90”. To make a MAC that fits the changed original, the secret key K must go into the calculation, but Mallory does not have K. So the attached MAC 3f9a is left as it was.
4 / 6
Mallory → Bob: pass it on
The changed original and the original MAC 3f9a arrive at Bob.
5 / 6
Bob: recompute the MAC
Bob puts the received original “Send $90” and the same secret key K into the hash function and gets 81c2.
6 / 6
Bob: compare the two values
The recomputed value (81c2) differs from the attached MAC (3f9a). Bob notices that the original was changed on the way and discards the message.
1 / 6
Alice: make the hash value
Alice puts only the original “Send $10” into the hash function and gets the hash value 3f9a. No key goes in.
2 / 6
Alice → Mallory: intercepted
Alice sent the original with the hash value attached, but the attacker Mallory intercepted it on the way.
3 / 6
Mallory: change the original and the hash
Mallory changes the original to “Send $90”. Since anyone can compute the hash without a key, Mallory makes the hash value c71e of the changed original and attaches it in place of the old one.
4 / 6
Mallory → Bob: pass it on
The changed original and the newly made hash value c71e arrive at Bob.
5 / 6
Bob: recompute the hash
Bob puts the received original “Send $90” into the hash function and gets c71e.
6 / 6
Bob: compare the two values
The recomputed value (c71e) matches the attached hash value (c71e), so Bob accepts the changed message as it is. Without a key, tampering goes undetected.