A fixed string that is prepended to the plaintext within the authenticated-encryption function of a key-wrap algorithm, in order to enable the verification of the integrity of the plaintext within the authenticated-decryption function.
Source(s):
NIST SP 800-38F
See checksum.
Source(s):
CNSSI 4009-2015