2006Unpublished venueRequires access

A Reconfigurable Hardware Unit for the HMAC Algorithm

Esam Khan, M. Watheq El‐Kharashi, Fayez Gebali, Mostafa Abd‐El‐Barr

Open publisher page 5 citations

Abstract

HMAC is a shared-key security algorithm that uses hash functions for message authentication and data integrity. The most popular hash functions used with HMAC are MD5, SHA-1, and RIPEMD-160, which are all based on the function MD4. IPSec uses HMAC with these three hash functions for message authentication. In addition, these hash functions can be used with other security applications, such as digital signature. In a previous work, we designed a unified engine that implements the three hash algorithms. In this work, we integrated the HMAC algorithm into that engine to form a reconfigurable HMAC-hash unit, which implements six standard security algorithms and can be reconfigured at runtime to perform any one of them. We applied the pipelining principle to the design of the HMAC-hash unit. Hence, the larger the message size, the better the throughput. Compared to other work, we achieve better throughput than those integrating three or more hash functions and a comparable throughput to those integrating two hash functions. We achieve comparable results to those integrating HMAC with some hash functions. The area utilization of the designed unit is less than 33% of the available logic on the FPGA chip we used. Thus, the designed unit can fit on a single FPGA chip as an SoC.

About this research paper

What this paper is about

HMAC is a shared-key security algorithm that uses hash functions for message authentication and data integrity. The most popular hash functions used with HMAC are MD5, SHA-1, and RIPEMD-160, which are all based on the function MD4. IPSec uses HMAC with these three hash functions for message authentication. In addition, these hash functions can be used with other security applications, such as digital signature. In a previous work, we designed a unified engine that implements the three hash algorithms. In this work, we integrated the HMAC algorithm into that engine to form a reconfigurable HMAC-hash unit, which implements six standard security algorithms and can be reconfigured at runtime to perform any one of them. We applied the pipelining principle to the design of the HMAC-hash unit. Hence, the larger the message size, the better the throughput. Compared to other work, we achieve better throughput than those integrating three or more hash functions and a comparable throughput to those integrating two hash functions. We achieve comparable results to those integrating HMAC with some hash functions. The area utilization of the designed unit is less than 33% of the available logic on the FPGA chip we used. Thus, the designed unit can fit on a single FPGA chip as an SoC.

Why it matters

OpenAlex reports 5 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

HMAC is a shared-key security algorithm that uses hash functions for message authentication and data integrity. The most popular hash functions used with HMAC are MD5, SHA-1, and RIPEMD-160, which are all based on the function MD4. IPSec uses HMAC with these three hash functions for message authentication. In addition, these hash functions can be used with other security applications, such as digital signature. In a previous work, we designed a unified engine that implements the three hash algorithms. In this work, we integrated the HMAC algorithm into that engine to form a reconfigurable HMAC-hash unit, which implements six standard security algorithms and can be reconfigured at runtime to perform any one of them. We applied the pipelining principle to the design of the HMAC-hash unit. Hence, the larger the message size, the better the throughput. Compared to other work, we achieve better throughput than those integrating three or more hash functions and a comparable throughput to those integrating two hash functions. We achieve comparable results to those integrating HMAC with some hash functions. The area utilization of the designed unit is less than 33% of the available logic on the FPGA chip we used. Thus, the designed unit can fit on a single FPGA chip as an SoC.

Key concepts: Hash-based message authentication code, Hash function, MD5, Computer science, Secure Hash Algorithm, Cryptographic hash function, SHA-2, Message authentication code

Related papers

Back to paper searchBrowse research topicsOriginal source
A Reconfigurable Hardware Unit for the HMAC Algorithm — Research Paper | ScholarLens