History-free aggregate message authentication codes

Eikemeier O, Fischlin M, Götzmann JF, Lehmann A, Schröder D, Schröder P, Wagner D (2010)

Publication Status: Published

Publication Type: Authored book, Volume of book series

Publication year: 2010

Series: Security and Cryptography for Networks, SCN 2010

Pages Range: 309-328

Event location: Amalfi

ISBN: 9783642153167

DOI: 10.1007/978-3-642-15317-4_20


Aggregate message authentication codes, as introduced by Katz and Lindell (CT-RSA 2008), combine several MACs into a single value, which has roughly the same size as an ordinary MAC. These schemes reduce the communication overhead significantly and are therefore a promising approach to achieve authenticated communication in mobile ad-hoc networks, where communication is prohibitively expensive. Here we revisit the unforgeability notion for aggregate MACs and discuss that the definition does not prevent "mix-and-match" attacks in which the adversary turns several aggregates into a "fresh" combination, i.e., into a valid aggregate on a sequence of messages which the attacker has not requested before. In particular, we show concrete attacks on the previous scheme. To capture the broader class of combination attacks, we provide a stronger security notion of aggregation unforgeability. While we can provide stateful transformations lifting (non-ordered) schemes to meet our stronger security notion, for the statefree case we switch to the new notion of history-free sequential aggregation. This notion is somewhat between non-ordered and sequential schemes and basically says that the aggregation algorithm is carried out in a sequential order but must not depend on the preceding messages in the sequence, but only on the shorter input aggregate and the local message. We finally show that we can build an aggregation-unforgeable, history-free sequential MAC scheme based on general assumptions. © 2010 Springer-Verlag Berlin Heidelberg.

Authors with CRIS profile

How to cite


Eikemeier, O., Fischlin, M., Götzmann, J.-F., Lehmann, A., Schröder, D., Schröder, P., & Wagner, D. (2010). History-free aggregate message authentication codes.


Eikemeier, Oliver, et al. History-free aggregate message authentication codes. 2010.

BibTeX: Download