Typical application of HMAC in authentication

Source: Internet
Author: User
Tags hmac
A typical application of HMAC is in "Challenge/Response" (Challenge/response) identity authentication. Certification Process (1) The client sends a validation request to the server first. (2) When the server receives this request, a random number is generated and transmitted over the network to the client (this is a challenge). (3) The client provides the random number received to Epass, which is used by Epass to perform a hmac-md5 operation with the key stored in epass and a result to be passed to the server as the authentication evidence (in response). (4) At the same time, the server also uses this random number and stored in the server database of the customer key for the hmac-md5 operation, if the server operation results and the client returns the same response results, the client is considered a legitimate user security analysis by the above introduction, We can see that the HMAC algorithm is more like a cryptographic algorithm, it introduces a key, its security is not completely dependent on the hash algorithm used, security mainly has the following assurances: (1) The use of the key is agreed by the parties in advance, third parties can not know. The application process introduced by 3.2 shows that, as a third party that illegally intercepts information, the information that can be obtained is only a random number of "challenges" and an HMAC result as a "response", and it is not possible to derive the key from these two data. Unable to replicate a consistent response because the key is not known

Typical application of HMAC in authentication

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.