Structurally aggregate message authentication codes
Yuta Ishii, Mitsuru Tada,
In an aggregate MAC scheme, plural (single) tags can be put together so that we can decrease the tag size and thereby the communication cost. The aggregation ways are classified roughly into two types, parallel-type aggregations and serial-type ones. In the former-type ones, a valid aggregate tag does not refer to, so far, the order for generating the single tags to make the aggregate tag, whereas in the latter-type ones, a valid aggregate tag can assure the generating order. Then we can see the former-type ones in ,  and the latter-type ones in , . In this paper, we extend those schemes, and present an aggregate MAC scheme in which a valid aggregate tag can assure the structural generating orders which can be represented by a series-parallel graph, and show the security for the proposed scheme.