Subverting MAC: How authentication in mobile environment can be undermined
Fatema Al Mansoori, Joonsang Baek, Khaled Salah · 2016
Due to its efficiency, message authentication code (MAC) has widely been used to provide data integrity and authentication in the mobile computing environment. Subverting MAC schemes will have serious consequences as it undermines the authentication services that the MAC schemes are supposed to offer in such environment, for example, authentication for mobile payments and secure software updates in mobile devices. Subverting cryptographic schemes and protocols by subliminally modifying or replacing some parts of legitimate implementation of cryptography is newly conceptualized as “algorithmic substitution attack (ASA)”, and is receiving a great deal of attention recently. In this paper, we investigate issues related to the ASA on MAC: First, we formalize security notions for MAC against ASA. We then show that the randomized MAC, a popular scheme proposed to improve the security of MAC, is vulnerable to ASA. Furthermore, we discuss how our subversion attack can be applied to the EAP-PSK protocol (a pre-shared key extensible authentication protocol method), widely used in wireless networks including IEEE 802.11.