Introduction
A Message Authentication Code, or MAC, is a cryptographic value used to verify two things: the message was not changed, and the message was created by someone who knows a shared secret key.
This MAC is different from a MAC address in computer networks. Here, MAC means Message Authentication Code, which belongs to cryptography and network security.
Why Plain Hashing Is Not Enough
A normal hash function can detect whether data changed. If the sender and receiver both calculate the same hash for a message, the message is likely unchanged.
However, a plain hash does not prove who created the message. Anyone can take a modified message, calculate a fresh hash, and send both together.
For example:
Original message => Transfer Rs. 1000
Attacker changes it => Transfer Rs. 9000
Attacker also creates a new hash for the modified message
When the receiver checks the hash, it may still match the modified message. This shows the limitation of plain hashing: it checks data integrity only when the hash itself is trusted.
What Is a Message Authentication Code?
A Message Authentication Code uses both the message and a shared secret key to generate a short authentication value. This value is attached to the message and verified by the receiver.
The simplified idea is:
Message + Secret Key => MAC value
Only someone who knows the secret key should be able to generate a valid MAC for that message. If an attacker changes the message, they cannot create the correct MAC without the key.
A MAC provides:
Integrity: The receiver can detect if the message was modified.
Authentication: The receiver can verify that the sender likely knew the shared secret key.
Tamper detection: Modified messages fail verification.
Protection against fake messages: Attackers cannot easily create valid messages without the key.
How MAC Verification Works
MAC verification requires the sender and receiver to already share the same secret key. The key itself should not be sent with the message.
A simple MAC flow looks like:
The message and shared key are used to generate a MAC.
The message and MAC are sent to the receiver.
The receiver recalculates the MAC using the same shared key.
The received and calculated MAC values are compared.
If both MAC values match, the receiver accepts the message. If they do not match, the message is rejected because either the message, the MAC, or both may have been changed.
MAC and HMAC in Cryptography
What Is HMAC?
HMAC stands for Hash-Based Message Authentication Code. It is a widely used type of MAC that combines a cryptographic hash function with a secret key.
HMAC uses three main inputs:
Message: The data being protected.
Secret key: A shared key known to sender and receiver.
Hash function: A cryptographic hash function such as SHA-256 or SHA-512.
Common examples include:
HMAC-SHA256: HMAC using SHA-256.
HMAC-SHA384: HMAC using SHA-384.
HMAC-SHA512: HMAC using SHA-512.
HMAC is stronger than simply doing hash(message + key) because it follows a proper construction designed for message authentication.
Hash vs MAC vs HMAC
Feature | Plain Hash | MAC | HMAC |
|---|---|---|---|
Uses message | Yes | Yes | Yes |
Uses secret key | No | Yes | Yes |
Checks integrity | Yes | Yes | Yes |
Authenticates sender | No | Yes | Yes |
Based on hash function | Usually yes | Not always | Yes |
Example | SHA-256(file) | MAC(message, key) | HMAC-SHA256(message, key) |
A plain hash checks whether data matches a fingerprint. A MAC checks whether the data matches and whether the sender knew the shared secret. HMAC is a common hash-based way to create a MAC.
Where HMAC Is Used
HMAC appears in many real systems where servers need to verify that a request or message is genuine.
API request signing: A client signs an API request using a secret key, and the server verifies the signature before accepting it.
Webhook verification: Payment providers, Git platforms, and external services use HMAC signatures to prove that webhook payloads are genuine.
JWT HS256: Some JSON Web Tokens are signed using HMAC with SHA-256.
Cloud signed requests: Cloud platforms use HMAC-style signatures to verify request authenticity.
Secure protocols: HMAC is used in several cryptographic protocols for message authentication and integrity checking.
For example, in payment webhooks, a backend should not trust a browser saying that payment is successful. Instead, the payment provider sends a webhook with an HMAC signature. The backend verifies the signature using the shared secret before updating the payment status.
What MAC and HMAC Do Not Provide
MAC and HMAC provide integrity and authentication, but they do not hide the message content. If the message is sent in plain text, others may still be able to read it.
To protect secrecy, encryption is required. In secure systems, encryption and authentication are often used together.
MAC and HMAC also do not provide non-repudiation in the same way digital signatures do. Since both sender and receiver share the same secret key, either party could technically generate a valid MAC. Digital signatures use public and private keys, which makes them better for proving who signed something.
Summary
A Message Authentication Code verifies that a message was not modified and that it came from someone who knows a shared secret key. HMAC is a common type of MAC that combines a cryptographic hash function with a secret key.
Plain hashes provide integrity, but they do not authenticate the sender. MAC and HMAC add secret-key-based authentication, making them useful in APIs, webhooks, JWTs, cloud requests, and secure communication protocols. In simple terms, a hash checks data, while HMAC checks both data and secret ownership.
Be the first to add a comment.