Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Fast and Secure CBC Type MAC Algorithms



Mridul Nandi


The CBC-MAC, or cipher block chaining message authentication code, is a well-known method to generate message authentication codes. Unfortunately, it is not forgery-secure over an arbitrary domain. There are several secure variants of CBC-MAC, among which OMAC (or one-key CBC-MAC) is a widely-used candidate. A simple variant of it, called CMAC, also has been recommended by NIST and is also used widely. Both OAMC and CMAC cost (s+1) blockcipher invocations to authenticate an s-block message, and it takes only one blockcipher key. In this paper we propose two secure and efficient variants of CBC-MAC. Our constructions cost only s block cipher encryptions to authenticate an s-block message, for all s >= 2. Moreover, GCBC2 needs only one block cipher encryption for almost all single block messages, and for all other single block messages, it costs two block cipher encryptions. We have also defined a class of generalized CBC-MAC constructions, and proved a sufficient condition for prf-security. In particular, we have provided an unified prf-security analysis of CBC-type constructions, e.g., XCBC, TMAC and our proposals GCBC1 and GCBC2.
Proceedings Title
Fast Software Encryption (Lecture Notes in Computer Science)
Conference Dates
February 22-25, 2009
Conference Location
Conference Title
16th International Workshop on Fast Software Encryption (FSE 2009)


CBC-MAC, OMAC, padding rule, prf-security


Nandi, M. (2009), Fast and Secure CBC Type MAC Algorithms, Fast Software Encryption (Lecture Notes in Computer Science), Leuven, -1, [online], (Accessed July 18, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created July 21, 2009, Updated November 10, 2018