Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Android Application Security Essentials

You're reading from   Android Application Security Essentials Security has been a bit of a hot topic with Android so this guide is a timely way to ensure your apps are safe. Includes everything from Android security architecture to safeguarding mobile payments.

Arrow left icon
Product type Paperback
Published in Aug 2013
Publisher Packt
ISBN-13 9781849515603
Length 218 pages
Edition 1st Edition
Languages
Tools
Arrow right icon
Author (1):
Arrow left icon
Pragati Rai Pragati Rai
Author Profile Icon Pragati Rai
Pragati Rai
Arrow right icon
View More author details
Toc

Table of Contents (12) Chapters Close

Preface 1. The Android Security Model – the Big Picture FREE CHAPTER 2. Application Building Blocks 3. Permissions 4. Defining the Application's Policy File 5. Respect Your Users 6. Your Tools – Crypto APIs 7. Securing Application Data 8. Android in the Enterprise 9. Testing for Security 10. Looking into the Future Index

Message Authentication Codes


A Message Authentication Code (MAC) is a tag or checksum that is appended to a message to ascertain its authenticity and integrity. Authentication is provided by the possession of a secret key, and verifying accidental or intentional changes in the message provides integrity. The following figure illustrates the working of a MAC:

A MAC can be generated using different methods: by using a one time pad or one time secret key, by using a hash function, and by using a stream cipher or by using a block cipher and output the final block as a checksum. An example of the last method is DES with the CBC mode.

A hash function is used to create a checksum called Hashed MAC (HMAC). This hash is then encrypted with a symmetric key and appended to the message. This is the most popular method of generating the MAC. Some examples of this kind of MAC are AES 128 with SHA1 and AES 256 with SHA1.

Android provides the capability to generate an HMAC by using the javax.crypto.Mac class...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image