2018•International Journal for Research in Applied Science and Engineering TechnologyOpen access

An Enhanced Hash-based Message Authentication Code using BCrypt

Jerone B. Alimpia

Open full text 1 citations

Abstract

Many message authentication codes like HMAC depend on its underlying cryptographic algorithm. Unfortunately most of these algorithms are very fast that permits the attacker to easily establish a brute-force attack for key-retrieval. In this paper, it presents a method of solving the issue by applying BCrypt Expensive Key Setup function to derive the secret key of HMAC. As a result, the modification helps the algorithm to strengthen its resistance to exhaustive search and it protects against key recovery attacks. This work also presents results of comparing time-complexity in performing key-recovery attack for both original and modified version of HMAC.

Open-access reader

About this research paper

What this paper is about

Many message authentication codes like HMAC depend on its underlying cryptographic algorithm. Unfortunately most of these algorithms are very fast that permits the attacker to easily establish a brute-force attack for key-retrieval. In this paper, it presents a method of solving the issue by applying BCrypt Expensive Key Setup function to derive the secret key of HMAC. As a result, the modification helps the algorithm to strengthen its resistance to exhaustive search and it protects against key recovery attacks. This work also presents results of comparing time-complexity in performing key-recovery attack for both original and modified version of HMAC.

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Many message authentication codes like HMAC depend on its underlying cryptographic algorithm. Unfortunately most of these algorithms are very fast that permits the attacker to easily establish a brute-force attack for key-retrieval. In this paper, it presents a method of solving the issue by applying BCrypt Expensive Key Setup function to derive the secret key of HMAC. As a result, the modification helps the algorithm to strengthen its resistance to exhaustive search and it protects against key recovery attacks. This work also presents results of comparing time-complexity in performing key-recovery attack for both original and modified version of HMAC.

Key concepts: Hash function, Hash-based message authentication code, Computer science, Message authentication code, Code (set theory), Computer security, Programming language, Cryptography

Related papers

Back to paper searchBrowse research topicsOriginal source
An Enhanced Hash-based Message Authentication Code using BCrypt — Research Paper | ScholarLens