Perfect Message Authentication Codes
- Perfect MACs are information-theoretic authentication schemes that achieve exact forging probability bounds even against unbounded adversaries.
- They employ precise combinatorial designs and non-deterministic encodings to guarantee both optimal spoofing resistance and perfect secrecy.
- Extensions to quantum, channel-based, and keyless models illustrate diverse practical implementations and theoretical advances.
Searching arXiv for recent and foundational work on perfect message authentication codes and closely related information-theoretic authentication. A perfect message authentication code is an information-theoretic authentication mechanism whose security is specified against even unbounded adversaries, but the exact meaning of “perfect” depends on the model. In the one-time MAC literature, it refers to the strong single-query authentication setting with explicit bounds on forgery probability under uniform or non-uniform keys (Ryabko, 13 Aug 2025). In the splitting-model literature, perfect secrecy and optimal spoofing resistance are studied simultaneously through non-deterministic encodings and combinatorial designs (Huber, 2011). Closely related work shows that group-generated splitting authentication codes have perfect secrecy, that algebraic manipulation detection codes arise as a special case, and that quantum or channel-based models can realize different notions of perfect authentication under additional resources or assumptions (Paterson et al., 2021, Nikolopoulos et al., 2020, Ostrev, 2018).
1. Formal models and security criteria
In the one-time MAC setting, a scheme is a pair of algorithms
with correctness
with probability $1$ for every and . The forgery game samples from a key distribution, gives the adversary a tag on a chosen message , and asks for a forgery with ; the adversary’s advantage is
0
The same source defines a perfect MAC as an information-theoretically strong one-time MAC and derives the standard single-query forging bound under uniform keys (Ryabko, 13 Aug 2025).
In splitting authentication codes, the source set is 1, the message set is 2, and the encoding-rule set is 3. Encoding is non-deterministic: 4 and for each 5 and 6,
7
The code is 8-splitting if 9 for every $1$0 and every $1$1. Perfect secrecy in the Shannon sense is
$1$2
for every $1$3 and every $1$4. Spoofing attacks of order $1$5 observe $1$6 distinct authentic messages under the same key and then insert a new message; the deception probability is $1$7 (Huber, 2011).
The splitting-model notion of perfect authentication is parameterized by spoofing order. For $1$8,
$1$9
and the code is called 0-fold secure against spoofing if equality holds for all 1. A 2-fold secure 3-splitting code must satisfy
4
with equality defining optimality (Huber, 2011).
2. One-time perfect MACs under uniform keys
For uniform keys 5, the 2025 robustness analysis considers the event
6
for a fixed forgery attempt 7. Under the requirement that the scheme be perfectly secure, there are exactly 8 keys mapping a fixed message 9 to any single tag value, so
0
It follows that
1
This is the explicit one-time forging bound stated for the uniform-key case (Ryabko, 13 Aug 2025).
That formulation is narrower than the splitting-model literature, because it concerns a single chosen-message query and a single forgery on a different message. It is also narrower than later quantum constructions that claim zero forgery probability under a different resource model. A plausible implication is that “perfect” is not a single invariant definition across authentication theory, but a label attached to model-specific information-theoretic guarantees.
The same source emphasizes that this one-time analysis allows possibly randomized tag generation and unbounded adversaries. The structure is therefore information-theoretic at the level of the authentication game itself, rather than computational or asymptotic (Ryabko, 13 Aug 2025).
3. Robustness to non-uniform key distributions
A central refinement is the effect of biased keys. Let 2 be the real key distribution and 3 the uniform distribution on 4, with statistical distance
5
For a forgery 6, define
7
Using a subset-sum bound, the success probability under 8 satisfies
9
Because 0 in the uniform ideal case, one obtains the general bound
1
The paper states that the worst-case increase in forgery probability is exactly 2, and summarizes the conclusion as robustness of perfect MACs to small deviations from a uniform key distribution (Ryabko, 13 Aug 2025).
The same source gives two numerical examples. If 3 and 4, then
5
if instead 6, then
7
These examples make the dependence on key quality explicit: once 8, the key-distribution defect dominates the ideal forging term (Ryabko, 13 Aug 2025).
The practical recommendations in the same work are correspondingly direct: ensure 9, apply extractors or “whitening” to reduce bias, periodically test key material for statistical bias, and choose tag length 0 so that plausible 1 remains tiny relative to 2 (Ryabko, 13 Aug 2025).
4. Splitting authentication codes, perfect secrecy, and design theory
In the splitting model, authentication and secrecy are treated jointly. A 3-4 splitting design is a pair 5 with 6 points and 7 blocks, where each block is partitioned into 8 disjoint subblocks of size 9, and every 0-subset of points lies in exactly 1 blocks with the points occupying distinct subblocks. The basic counting relations include
2
together with divisibility conditions
3
for each 4, and a Fisher-type bound 5 for 6 (Huber, 2011).
The key equivalence is that there exists an optimal 7-splitting authentication code for 8 equiprobable source states, 9 messages, and
0
encoding rules, 1-fold secure, if and only if there exists a 2-3 splitting design. This result turns optimal information-theoretic authentication into a design-existence problem (Huber, 2011).
For perfect secrecy, the 2011 construction uses cyclic 4-5 splitting designs with no short orbit. In that setting, the induced 6 encoding matrix is balanced in each column, and each message occurs equally often in each column. If each of the 7 keys is used with probability 8, then Shannon’s condition
9
follows immediately. The construction therefore yields optimal 0-splitting authentication codes with perfect secrecy in the general case where the number of keys may differ from the number of messages, extending earlier work that covered only the special case 1 via external difference families (Huber, 2011).
The same paper gives concrete examples, including a 2-3 cyclic splitting design generated by the base blocks 4 and 5, which yields an optimal one-fold secure 6-splitting authentication code with 7 messages and 8 keys. More generally, for 9 and 00, it constructs a cyclic 01-02 splitting design, hence 03 keys (Huber, 2011).
5. Group-generated constructions, equitable ordering, and AMD codes
A broader design-theoretic framework is given by group-generated splitting authentication codes. A splitting set system 04 is group-generated if there is an abelian subgroup 05 whose action on 06 is regular. For such systems, the corresponding splitting A-code has perfect secrecy and optimal impersonation probability. If it is 07-splitting, it also meets the standard lower bound on substitution success; if it is generated from an AMD code, then its substitution probability equals the AMD parameter (Paterson et al., 2021).
This perfect-secrecy result is explained by regularity: each 08 occurs equally often in each part 09, hence
10
for all 11. The same paper introduces equitably ordered splitting BIBDs. A 12-splitting BIBD is equitably ordered if every point occurs exactly 13 times in each part, where
14
Such equitable ordering immediately yields perfect secrecy, because for each message-tag pair the number of keys mapping the source to the tag is independent of the source index (Paterson et al., 2021).
The existence theory is unusually explicit. For example, an equitably ordered 15-splitting BIBD exists if and only if
16
and the solvable pairs listed in the paper include 17 as well as all cases with 18. Additional conditions are
19
20
21
and
22
with the stated possible exceptions at 23 and 24 in the relevant cases (Paterson et al., 2021).
The same work establishes a precise correspondence with algebraic manipulation detection codes. The development of a weak 25-AMD code yields a group-generated 26 splitting set system whose corresponding A-code has perfect secrecy and substitution success 27 for uniformly distributed sources; the strong AMD case gives substitution success 28 for any source distribution. Conversely, any group-generated symmetric 29 splitting code with perfect secrecy and substitution success 30 gives rise to a strong 31-AMD code by restricting to the block containing a fixed point (Paterson et al., 2021).
6. Alternative realizations and adjacent notions of perfection
One adjacent direction is the artificial-noise-aided MAC. Here a standard deterministic MAC 32 is converted to bipolar form, perturbed by i.i.d. Gaussian noise 33, and quantized: 34 The adversary sees a memoryless channel with transition law
35
The paper analyzes three performance metrics—completeness error, false acceptance probability, and conditional equivocation about the key—and shows how to balance them. Its information-theoretic bounds include
36
and when 37, any ML decoder has 38 exponentially in 39. The paper states that “perfect” authentication is approached when 40, 41, and 42, rather than achieved as an exact finite-model equality (Wu et al., 2015).
A second adjacent direction is quantum authentication. The 2020 quantum paper first states that passive prepare-and-measure quantum message-authentication schemes cannot do better than their classical counterparts, and then gives an interactive entanglement-assisted scheme which ideally authenticates an 43-bit classical message with an 44-bit classical key. Alice and Bob share 45 EPR pairs and an 46-bit uniformly random classical key, Alice sends a 47-qubit register, and Bob performs Bell-basis checks. The claimed security objective is exact: for any adversary operation on the transmitted register, the probability that Bob both accepts and outputs 48 is exactly 49. The comparison table in the same source states key length 50 for a classical Wegman–Carter MAC with 51, versus key length 52 for the quantum construction, at the cost of 53 ebits and one round of quantum communication (Nikolopoulos et al., 2020).
A third direction removes the shared key entirely. Under a channel model in which Alice’s channel to Bob is strictly less noisy than Eve’s channel to Bob, one can construct a statistically secure authenticated channel of rate
54
The encoder uses random coding, the decoder uses unique jointly 55-typical decoding, and both decoding error and forgery-acceptance probability vanish exponentially in block length. The same work formulates the result in the Abstract-Cryptography framework, proving composable security by constructing an authenticated channel resource from the noisy real resource without any shared secret key (Ostrev, 2018).
Taken together, these variants show that perfect message authentication code is best understood as a family of information-theoretic authentication notions. In some papers it denotes optimal one-time forging resistance under uniform keys; in others it is coupled to perfect secrecy in a splitting code; in still others it denotes zero forgery in a quantum interactive protocol or asymptotically vanishing forgery in a noisy-channel construction. The technical commonality is that authentication guarantees are derived from exact combinatorial balance, channel asymmetry, or quantum correlations, rather than from computational hardness assumptions.