Poly1305 is a message authentication code (MAC) designed by Daniel J. Bernstein and specified in RFC 8439. It provides strong authentication guarantees when used with a unique, unpredictable 32-byte key per message.
Poly1305 is typically paired with ChaCha20, as in the ChaCha20-Poly1305 AEAD construction defined in RFC 8439. The pairing is used in TLS 1.3, WireGuard, and SSH.
This implementation follows RFC 8439. It evaluates the message as a polynomial modulo the prime 2^130-5 over 16-byte blocks and produces a 128-bit (16-byte) authentication tag.
Security notes
•
The 32-byte key MUST be unique and unpredictable for each message. Two messages authenticated with the same key are enough for an attacker to recover the key and forge tags.
•
Poly1305 authenticates but does not encrypt. For authenticated encryption, use an AEAD construction like ChaCha20-Poly1305.
•
Tag verification compares tags in constant time. The tag computation uses bignum arithmetic, which is not constant-time, so it can leak timing information about the key (see RFC 8439 Sections 3 and 4).