Cryptology ePrint Archive: Report 2018/342

MergeMAC: A MAC for Authentication with Strict Time Constraints and Limited Bandwidth

Ralph Ankele and Florian Böhl and Simon Friedberger

Abstract: This paper presents MergeMAC, a MAC that is particularly suitable for environments with strict time requirements and extremely limited bandwidth. MergeMAC computes the MAC by splitting the message into two parts. We use a pseudorandom function (PRF) to map messages to random bit strings and then merge them with a very efficient keyless function. The advantage of this approach is that the outputs of the PRF can be cached for frequently needed message parts. We demonstrate the merits of MergeMAC for authenticating messages on the CAN bus where bandwidth is extremely limited and caching can be used to recover parts of the message counter instead of transmitting it. We recommend an instantiation of the merging function MERGE and analyze the security of our construction. Requirements for a merging function are formally defined and the resulting EUF-CMA security of MergeMAC is proven.

Category / Keywords: secret-key cryptography / Symmetric-key cryptography, message authentication code, lightweight, efficient, automotive, CAN bus

Original Publication (in the same form): ACNS 2018 Applied Cryptography & Network security

Date: received 11 Apr 2018

Contact author: ralph ankele 2015 at live rhul ac uk

Available format(s): PDF | BibTeX Citation

Version: 20180416:211435 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]