BS ISO IEC 9797-2-2021 (2024) PDF
Name in English:
STB BS ISO IEC 9797-2-2021 (2024)
Name in Russian:
СТБ BS ISO IEC 9797-2-2021 (2024)
Original standard BS ISO IEC 9797-2-2021 (2024) in PDF full version. Additional info + preview on request
Full title and description
STB BS ISO IEC 9797-2-2021 (2024) — Information security — Message authentication codes (MACs) — Part 2: Mechanisms using a dedicated hash‑function. National adoption of ISO/IEC 9797-2:2021 presented as a British Standard national publication (BS) and offered in STB/BS packaging for 2024 distribution.
Abstract
This document specifies Message Authentication Code (MAC) algorithms that use a secret key together with a dedicated hash function (or its round‑function/sponge function) to compute an m‑bit MAC. The mechanisms defined are intended to provide data integrity and data origin authentication by detecting unauthorized modification of data. Annexes provide object identifiers, numerical examples and a security analysis of the specified MAC algorithms.
General information
- Status: Published / Current (national adoption as BS; international standard active).
- Publication date: ISO/IEC original: June 2021; national BS adoption/catalog publication: December 2024 (incorporating Corrigendum Nov 2024).
- Publisher: British Standards Institution (BS national publication of the ISO/IEC text); original publisher: ISO/IEC (JTC 1/SC 27).
- ICS / categories: 35.030 — Information technology security techniques.
- Edition / version: Edition 3 — ISO/IEC 9797-2:2021; modified by Technical Corrigendum 1 (2024).
- Number of pages: ISO text: ~52 pages (original ISO PDF); some national/BS packaged PDFs that incorporate corrigenda list ~62 pages depending on pagination and national front matter.
Scope
This part of ISO/IEC 9797 defines MAC mechanisms that use a dedicated hash‑function (or its internal functions) and a secret key to produce a fixed‑length authentication tag. It specifies three primary MAC algorithms (including MDx‑MAC and HMAC variants and a short‑input variant), parameter restrictions (key and MAC lengths), operational requirements and recommended usage considerations, and includes annexes with object identifiers, test examples and security discussions. The document does not select a specific dedicated hash function for every application — that choice and the required value of m are left to the implementer.
Key topics and requirements
- Definitions and symbols for MAC computation and verification.
- Requirements on key selection, key entropy and independence of encryption/integrity keys.
- Specification of MAC Algorithm 1 (MDx‑MAC style using dedicated hash functions), Algorithm 2 (HMAC‑style), and Algorithm 3 (short‑input variant), including truncation rules and constraints on m.
- Annexes providing object identifiers (OID), numerical examples for implementation tests, and a security analysis describing attacks and proof sketches.
- Normative requirements for using dedicated hash‑functions selected from relevant ISO/IEC hash specifications.
Typical use and users
Used by security engineers, cryptographic library developers, protocol designers, product certification bodies and organisations implementing data integrity and message authentication features. Typical applications include secure messaging, transaction integrity in financial systems, protocol message protection, and any system that requires keyed integrity/authentication using hash‑based MACs.
Related standards
ISO/IEC 9797-1 (MACs using block ciphers), ISO/IEC 10118 series (hash‑functions, especially Part 3 dedicated hash‑functions), related ISO/IEC cryptographic and information security standards and national adoptions (BS ISO/IEC versions). National publications incorporating corrigenda are available from BSI.
Keywords
Message Authentication Code, MAC, HMAC, MDx‑MAC, dedicated hash‑function, integrity, authentication, ISO/IEC 9797-2, BS ISO/IEC 9797-2, cryptography, object identifier, security analysis.
FAQ
Q: What is this standard?
A: It is Part 2 of ISO/IEC 9797 — a specification of message authentication code (MAC) mechanisms that use dedicated hash functions together with a secret key to produce authentication tags for integrity and origin authentication.
Q: What does it cover?
A: It covers the definitions, algorithm descriptions (three MAC algorithms), parameter constraints (key and MAC lengths), test examples, object identifiers and an informative security analysis explaining attacks and security bounds for the specified mechanisms.
Q: Who typically uses it?
A: Cryptographic library authors, protocol designers, implementers of secure systems (finance, telecommunications, government), and certification/assurance bodies that validate MAC implementations.
Q: Is it current or superseded?
A: The ISO/IEC 9797-2:2021 edition is the current international edition (published 2021) and has a Technical Corrigendum issued in 2024; national BS adoption documents published in late 2024 incorporate the corrigendum. Check the national publisher (BSI) or ISO for the authoritative status and corrigenda.
Q: Is it part of a series?
A: Yes — ISO/IEC 9797 is a multipart series on Message Authentication Codes. Part 1 covers MAC mechanisms using block ciphers; Part 2 covers dedicated hash‑function mechanisms; other related parts address additional methods or guidance.
Q: What are the key keywords?
A: MAC, HMAC, MDx‑MAC, dedicated hash‑function, message authentication code, integrity, ISO/IEC 9797-2, BS ISO/IEC 9797-2.