Keyed message authentication over MD5 and the SHA family. An HMAC proves a message came from someone holding the secret — a plain hash proves neither.