In information security, message authentication or data origin authentication is a property that a message has not been modified while in transit (data integrity) and that the receiving party can verify the source of the message.[1]
Description
Message authentication or data origin authentication is an information security property that indicates that a message has not been modified while in transit (data integrity) and that the receiving party can verify the source of the message.[1] Message authentication does not necessarily include the property of non-repudiation.[2][3]
Techniques
Message authentication is typically achieved by using message authentication codes (MACs), authenticated encryption (AE), or digital signatures.[2] The message authentication code, also known as digital authenticator, is used as an integrity check based on a secret key shared by two parties to authenticate information transmitted between them.[4] It is based on using a cryptographic hash or symmetric encryption algorithm.[5] The authentication key is only shared by exactly two parties (e.g. communicating devices), and the authentication will fail in the existence of a third party possessing the key since the algorithm will no longer be able to detect forgeries (i.e. to be able to validate the unique source of the message).[6] In addition, the key must also be randomly generated to avoid its recovery through brute-force searches and related-key attacks designed to identify it from the messages transiting the medium.[6]
Algunos criptógrafos distinguen entre los sistemas de "autenticación de mensajes sin secreto" —que permiten al receptor verificar el origen del mensaje, pero no ocultan su contenido en texto plano— y los sistemas de cifrado autenticados . [ 7 ] Algunos criptógrafos han investigado sistemas de canales subliminales que envían mensajes que aparentan utilizar un sistema de "autenticación de mensajes sin secreto", pero que en realidad también transmiten un mensaje secreto.
Conceptos relacionados
La autenticación del origen de los datos y el no repudio también se han estudiado en el marco de la criptografía cuántica. [ 8 ] [ 9 ]
Véase también
Referencias
- 1 2 Mihir Bellare . "Capítulo 7: Autenticación de mensajes" (PDF) . CSE 207: Criptografía moderna . Apuntes de clase para el curso de criptografía. Archivado del original (PDF) el 09-10-2018 . Recuperado el 11-05-2015 .
- 1 2 Alfred J. Menezes ; Paul C. van Oorschot ; Scott A. Vanstone . "Capítulo 9 - Funciones hash e integridad de datos" (PDF) . Manual de criptografía aplicada . pág. 361. Archivado del original el 3 de febrero de 2021. Recuperado el 11 de mayo de 2015 .
- ↑ "Autenticación del origen de los datos" . Seguridad de los servicios web . Red de desarrolladores de Microsoft . 14 de julio de 2010. Archivado del original el 19 de mayo de 2017. Consultado el 11 de mayo de 2015 .
- ↑ Patel, Dhiren (2008). Seguridad de la información: Teoría y práctica . Nueva Delhi: Prentice Hall India Private Ltd. pág. 124. ISBN 978-81-203-3351-2.
- ↑ Jacobs, Stuart (2011). Ingeniería de la seguridad de la información: La aplicación de conceptos de ingeniería de sistemas para lograr la garantía de la información . Hoboken, NJ: John Wiley & Sons. pág. 108. ISBN 978-0-470-56512-4.
- 1 2 Walker, Jesse (2013). «Capítulo 13 – Seguridad en Internet». En Vacca, John R. (ed.). Manual de seguridad informática y de la información (3.ª ed.). Morgan Kaufmann Publishers. págs. 256–257 . doi : 10.1016/B978-0-12-803843-7.00013-2 . ISBN 978-0-12-803843-7.
- ↑ Longo, G.; Marchi, M.; Sgarro, A. (4 de mayo de 2014). Geometrías, códigos y criptografía . Springer. pág. 188. ISBN 978-3-7091-2838-1Archivado del original el 9 de enero de 2024. Consultado el 8 de julio de 2015 .
- ^ Pirandola, S.; Andersen, UL; Banchi, L.; Berta, M.; Bunandar, D.; Colbeck, R.; Englund, D.; Gehring, T.; Lupo, C.; Ottaviani, C.; Pereira, J. (2020). "Avances en criptografía cuántica". Avances en Óptica y Fotónica . 12 (4): 1012–1236 . arXiv : 1906.01645 . Código Bib : 2020AdOP...12.1012P . doi : 10.1364/AOP.361502 . S2CID 174799187 .
- ↑ Nikolopoulos, Georgios M.; Fischlin, Marc (2020). "Autenticación del origen de datos segura desde el punto de vista de la teoría de la información con recursos cuánticos y clásicos" . Cryptography . 4 (4): 31. arXiv : 2011.06849 . doi : 10.3390/cryptography4040031 . S2CID 226956062 .
- Detección y corrección de errores
- Teoría de la criptografía