{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,5]],"date-time":"2025-04-05T21:23:49Z","timestamp":1743888229556,"version":"3.40.3"},"publisher-location":"Cham","reference-count":61,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319783802"},{"type":"electronic","value":"9783319783819"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-78381-9_17","type":"book-chapter","created":{"date-parts":[[2018,3,30]],"date-time":"2018-03-30T05:53:14Z","timestamp":1522389194000},"page":"445-467","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Optimal Forgeries Against Polynomial-Based MACs and GCM"],"prefix":"10.1007","author":[{"given":"Atul","family":"Luykx","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bart","family":"Preneel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,3,31]]},"reference":[{"key":"17_CR1","unstructured":"Specification of the 3GPP: Confidentiality and Integrity Algorithms UEA2 & UIA2; Document 2: SNOW 3G specification (2017). https:\/\/portal.3gpp.org\/desktopmodules\/Specifications\/SpecificationDetails.aspx?specificationId=2396"},{"key":"17_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1007\/978-3-662-46800-5_29","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2015","author":"MA Abdelraheem","year":"2015","unstructured":"Abdelraheem, M.A., Beelen, P., Bogdanov, A., Tischhauser, E.: Twisted polynomials and forgery attacks on GCM. In: Oswald, E., Fischlin, M. (eds.) EUROCRYPT 2015. LNCS, vol. 9056, pp. 762\u2013786. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-46800-5_29"},{"key":"17_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1007\/978-3-642-38519-3_15","volume-title":"Information Security and Cryptology","author":"K Aoki","year":"2013","unstructured":"Aoki, K., Yasuda, K.: The security and performance of \u201cGCM\u201d when short multiplications are used instead. In: Kuty\u0142owski, M., Yung, M. (eds.) Inscrypt 2012. LNCS, vol. 7763, pp. 225\u2013245. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-38519-3_15"},{"key":"17_CR4","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"345","DOI":"10.1007\/978-3-642-03317-9_21","volume-title":"Fast Software Encryption","author":"J Black","year":"2009","unstructured":"Black, J., Cochran, M.: MAC reforgeability. In: Dunkelman, O. (ed.) FSE 2009. LNCS, vol. 5665, pp. 345\u2013362. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03317-9_21"},{"issue":"111","key":"17_CR5","doi-asserted-by":"publisher","first-page":"713","DOI":"10.1090\/S0025-5718-1970-0276200-X","volume":"24","author":"ER Berlekamp","year":"1970","unstructured":"Berlekamp, E.R.: Factoring polynomials over large finite fields. Math. Comput. 24(111), 713\u2013735 (1970)","journal-title":"Math. Comput."},{"key":"17_CR6","unstructured":"Bernstein, D.J.: Stronger security bounds for permutations (2005). http:\/\/cr.yp.to\/papers.html#permutations. Accessed 9 April 2015"},{"key":"17_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"164","DOI":"10.1007\/11426639_10","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2005","author":"DJ Bernstein","year":"2005","unstructured":"Bernstein, D.J.: Stronger security bounds for Wegman-Carter-Shoup authenticators. In: Cramer, R. (ed.) EUROCRYPT 2005. LNCS, vol. 3494, pp. 164\u2013180. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11426639_10"},{"key":"17_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1007\/11502760_3","volume-title":"Fast Software Encryption","author":"DJ Bernstein","year":"2005","unstructured":"Bernstein, D.J.: The Poly1305-AES message-authentication code. In: Gilbert, H., Handschuh, H. (eds.) FSE 2005. LNCS, vol. 3557, pp. 32\u201349. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11502760_3"},{"key":"17_CR9","unstructured":"Bernstein, D.J.: Cryptography in NaCl (2009). http:\/\/cr.yp.to\/papers.html#naclcrypto. Accessed 14 Sept 2017"},{"key":"17_CR10","unstructured":"Bellare, M., Goldreich, O., Mityagin, A.: The power of verification queries in message authentication and authenticated encryption. IACR Cryptology ePrint Archive 2004, p. 309 (2004)"},{"key":"17_CR11","doi-asserted-by":"crossref","unstructured":"Black, J., Halevi, S., Krawczyk, H., Krovetz, T., Rogaway, P.: UMAC: fast and secure message authentication. In: Wiener [Wie99], pp. 216\u2013233","DOI":"10.1007\/3-540-48405-1_14"},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Bierbrauer, J., Johansson, T., Kabatianskii, G., Smeets, B.: On families of hash functions via geometric codes and concatenation. In: Stinson [Sti94], pp. 331\u2013342","DOI":"10.1007\/3-540-48329-2_28"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Bhargavan, K., Leurent, G.: On the practical (in-)security of 64-bit block ciphers: collision attacks on HTTP over TLS and OpenVPN. In: Weippl, E.R., Katzenbeisser, S., Kruegel, C., Myers, A.C., Halevi, S. (eds.) Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 24\u201328 October 2016, Vienna, Austria, pp. 456\u2013467. ACM (2016)","DOI":"10.1145\/2976749.2978423"},{"key":"17_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"527","DOI":"10.1007\/11535218_32","volume-title":"Advances in Cryptology \u2013 CRYPTO 2005","author":"M Bellare","year":"2005","unstructured":"Bellare, M., Pietrzak, K., Rogaway, P.: Improved security analyses for CBC MACs. In: Shoup, V. (ed.) CRYPTO 2005. LNCS, vol. 3621, pp. 527\u2013545. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11535218_32"},{"key":"17_CR15","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1007\/978-1-4757-0602-4_7","volume-title":"Advances in Cryptology","author":"G Brassard","year":"1983","unstructured":"Brassard, G.: On computationally secure authentication tags requiring short secret shared keys. In: Chaum, D., Rivest, R.L., Sherman, A.T. (eds.) Advances in Cryptology, pp. 79\u201386. Springer, Boston (1983). https:\/\/doi.org\/10.1007\/978-1-4757-0602-4_7"},{"key":"17_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1007\/978-3-662-53018-4_5","volume-title":"Advances in Cryptology \u2013 CRYPTO 2016","author":"B Cogliati","year":"2016","unstructured":"Cogliati, B., Seurin, Y.: EWCDM: an efficient, beyond-birthday secure, nonce-misuse resistant MAC. In: Robshaw, M., Katz, J. (eds.) CRYPTO 2016. LNCS, vol. 9814, pp. 121\u2013149. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-53018-4_5"},{"issue":"154","key":"17_CR17","doi-asserted-by":"publisher","first-page":"587","DOI":"10.1090\/S0025-5718-1981-0606517-5","volume":"36","author":"DG Cantor","year":"1981","unstructured":"Cantor, D.G., Zassenhaus, H.: A new algorithm for factoring polynomials over finite fields. Math. Comput. 36(154), 587\u2013592 (1981)","journal-title":"Math. Comput."},{"key":"17_CR18","first-page":"65","volume":"2","author":"B den Boer","year":"1993","unstructured":"den Boer, B.: A simple and key-economical unconditional authentication scheme. J. Comput. Secur. 2, 65\u201372 (1993)","journal-title":"J. Comput. Secur."},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Etzel, M., Patel, S., Ramzan, Z.: Square hash: fast message authentication via optimized universal hash functions. In: Wiener [Wie99], pp. 234\u2013251","DOI":"10.1007\/3-540-48405-1_15"},{"key":"17_CR20","unstructured":"Ferguson, N.: Authentication weaknesses in GCM. Comments submitted to NIST Modes of Operation Process (2005)"},{"issue":"1","key":"17_CR21","doi-asserted-by":"publisher","first-page":"162","DOI":"10.1007\/s00145-017-9253-0","volume":"31","author":"S Gilboa","year":"2018","unstructured":"Gilboa, S., Gueron, S., Morris, B.: How many queries are needed to distinguish a truncated random permutation from a random function? J. Cryptol. 31(1), 162\u2013171 (2018)","journal-title":"J. Cryptol."},{"issue":"3","key":"17_CR22","doi-asserted-by":"publisher","first-page":"405","DOI":"10.1002\/j.1538-7305.1974.tb02751.x","volume":"53","author":"EN Gilbert","year":"1974","unstructured":"Gilbert, E.N., MacWilliams, F.J., Sloane, N.J.A.: Codes which detect deception. Bell Syst. Tech. J. 53(3), 405\u2013424 (1974)","journal-title":"Bell Syst. Tech. J."},{"key":"17_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"113","DOI":"10.1007\/978-3-662-44371-2_7","volume-title":"Advances in Cryptology \u2013 CRYPTO 2014","author":"P Ga\u017ei","year":"2014","unstructured":"Ga\u017ei, P., Pietrzak, K., Ryb\u00e1r, M.: The exact PRF-security of NMAC and HMAC. In: Garay, J.A., Gennaro, R. (eds.) CRYPTO 2014. LNCS, vol. 8616, pp. 113\u2013130. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-44371-2_7"},{"issue":"2","key":"17_CR24","first-page":"145","volume":"2016","author":"P Gazi","year":"2016","unstructured":"Gazi, P., Pietrzak, K., Ryb\u00e1r, M.: The exact security of PMAC. IACR Trans. Symmetric Cryptol. 2016(2), 145\u2013161 (2016)","journal-title":"IACR Trans. Symmetric Cryptol."},{"key":"17_CR25","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"368","DOI":"10.1007\/978-3-662-47989-6_18","volume-title":"Advances in Cryptology \u2013 CRYPTO 2015","author":"P Ga\u017ei","year":"2015","unstructured":"Ga\u017ei, P., Pietrzak, K., Tessaro, S.: The exact PRF security of truncation: tight bounds for keyed sponges and truncated CBC. In: Gennaro, R., Robshaw, M. (eds.) CRYPTO 2015. LNCS, vol. 9215, pp. 368\u2013387. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-47989-6_18"},{"key":"17_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/BFb0052345","volume-title":"Fast Software Encryption","author":"S Halevi","year":"1997","unstructured":"Halevi, S., Krawczyk, H.: MMH: software message authentication in the Gbit\/second rates. In: Biham, E. (ed.) FSE 1997. LNCS, vol. 1267, pp. 172\u2013189. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/BFb0052345"},{"key":"17_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"144","DOI":"10.1007\/978-3-540-85174-5_9","volume-title":"Advances in Cryptology \u2013 CRYPTO 2008","author":"H Handschuh","year":"2008","unstructured":"Handschuh, H., Preneel, B.: Key-recovery attacks on universal hash function based MAC algorithms. In: Wagner, D. (ed.) CRYPTO 2008. LNCS, vol. 5157, pp. 144\u2013161. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-85174-5_9"},{"key":"17_CR28","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"370","DOI":"10.1007\/BFb0055742","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201998","author":"C Hall","year":"1998","unstructured":"Hall, C., Wagner, D., Kelsey, J., Schneier, B.: Building PRFs from PRPs. In: Krawczyk, H. (ed.) CRYPTO 1998. LNCS, vol. 1462, pp. 370\u2013389. Springer, Heidelberg (1998). https:\/\/doi.org\/10.1007\/BFb0055742"},{"key":"17_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1007\/978-3-642-32009-5_3","volume-title":"Advances in Cryptology \u2013 CRYPTO 2012","author":"T Iwata","year":"2012","unstructured":"Iwata, T., Ohashi, K., Minematsu, K.: Breaking and repairing GCM security proofs. In: Safavi-Naini, R., Canetti, R. (eds.) CRYPTO 2012. LNCS, vol. 7417, pp. 31\u201349. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-32009-5_3"},{"key":"17_CR30","doi-asserted-by":"crossref","unstructured":"Igoe, K., Solinas, J.: AES Galois Counter Mode for the secure shell transport layer protocol. RFC 5647, August 2009","DOI":"10.17487\/rfc5647"},{"key":"17_CR31","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"149","DOI":"10.1007\/3-540-69053-0_12","volume-title":"Advances in Cryptology \u2014 EUROCRYPT 1997","author":"T Johansson","year":"1997","unstructured":"Johansson, T.: Bucket hashing with a small key size. In: Fumy, W. (ed.) EUROCRYPT 1997. LNCS, vol. 1233, pp. 149\u2013162. Springer, Heidelberg (1997). https:\/\/doi.org\/10.1007\/3-540-69053-0_12"},{"key":"17_CR32","unstructured":"Joux, A.: Comments on the draft GCM specification - authentication failures in NIST version of GCM. http:\/\/csrc.nist.gov\/groups\/ST\/toolkit\/BCM\/documents\/comments\/800-38_Series-Drafts\/GCM\/Joux_comments.pdf"},{"key":"17_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"327","DOI":"10.1007\/978-3-540-74462-7_23","volume-title":"Selected Areas in Cryptography","author":"T Krovetz","year":"2007","unstructured":"Krovetz, T.: Message authentication on 64-bit architectures. In: Biham, E., Youssef, A.M. (eds.) SAC 2006. LNCS, vol. 4356, pp. 327\u2013341. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74462-7_23"},{"key":"17_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1007\/978-3-540-25937-4_26","volume-title":"Fast Software Encryption","author":"T Kohno","year":"2004","unstructured":"Kohno, T., Viega, J., Whiting, D.: CWC: a high-performance conventional authenticated encryption mode. In: Roy, B., Meier, W. (eds.) FSE 2004. LNCS, vol. 3017, pp. 408\u2013426. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-25937-4_26"},{"issue":"12","key":"17_CR35","doi-asserted-by":"publisher","first-page":"1484","DOI":"10.1109\/TC.2005.195","volume":"54","author":"J-P Kaps","year":"2005","unstructured":"Kaps, J.-P., Y\u00fcksel, K., Sunar, B.: Energy scalable universal hashing. IEEE Trans. Comput. 54(12), 1484\u20131495 (2005)","journal-title":"IEEE Trans. Comput."},{"key":"17_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"575","DOI":"10.1007\/978-3-319-70697-9_20","volume-title":"Advances in Cryptology \u2013 ASIACRYPT 2017","author":"A Luykx","year":"2017","unstructured":"Luykx, A., Mennink, B., Paterson, K.G.: Analyzing multi-key security degradation. In: Takagi, T., Peyrin, T. (eds.) ASIACRYPT 2017. LNCS, vol. 10625, pp. 575\u2013605. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-70697-9_20"},{"key":"17_CR37","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"596","DOI":"10.1007\/978-3-662-49890-3_23","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2016","author":"A Luykx","year":"2016","unstructured":"Luykx, A., Preneel, B., Szepieniec, A., Yasuda, K.: On the influence of message length in PMAC\u2019s security bounds. In: Fischlin, M., Coron, J.-S. (eds.) EUROCRYPT 2016. LNCS, vol. 9665, pp. 596\u2013621. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-49890-3_23"},{"key":"17_CR38","unstructured":"McGrew, D.A., Fluhrer, S.R.: Multiple forgery attacks against message authentication codes. Cryptology ePrint Archive, Report 2005\/161 (2005). http:\/\/eprint.iacr.org\/2005\/161"},{"key":"17_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"556","DOI":"10.1007\/978-3-319-63697-9_19","volume-title":"Advances in Cryptology \u2013 CRYPTO 2017","author":"B Mennink","year":"2017","unstructured":"Mennink, B., Neves, S.: Encrypted Davies-Meyer and its dual: towards optimal security using mirror theory. In: Katz, J., Shacham, H. (eds.) CRYPTO 2017. LNCS, vol. 10403, pp. 556\u2013583. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-63697-9_19"},{"key":"17_CR40","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"343","DOI":"10.1007\/978-3-540-30556-9_27","volume-title":"Progress in Cryptology - INDOCRYPT 2004","author":"DA McGrew","year":"2004","unstructured":"McGrew, D.A., Viega, J.: The security and performance of the Galois\/Counter Mode (GCM) of operation. In: Canteaut, A., Viswanathan, K. (eds.) INDOCRYPT 2004. LNCS, vol. 3348, pp. 343\u2013355. Springer, Heidelberg (2004). https:\/\/doi.org\/10.1007\/978-3-540-30556-9_27"},{"key":"17_CR41","doi-asserted-by":"crossref","unstructured":"McGrew, D.A., Viega, J.: The security and performance of the Galois\/Counter Mode of operation (Full Version). IACR Cryptology ePrint Archive 2004, p. 193 (2004)","DOI":"10.1007\/978-3-540-30556-9_27"},{"key":"17_CR42","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"127","DOI":"10.1007\/978-3-319-31517-1_7","volume-title":"Progress in Cryptology \u2013 AFRICACRYPT 2016","author":"J Mattsson","year":"2016","unstructured":"Mattsson, J., Westerlund, M.: Authentication key recovery on Galois\/Counter Mode (GCM). In: Pointcheval, D., Nitaj, A., Rachidi, T. (eds.) AFRICACRYPT 2016. LNCS, vol. 9646, pp. 127\u2013143. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-31517-1_7"},{"key":"17_CR43","unstructured":"National Institute of Standards and Technology. DES Modes of Operation. FIPS 81, December 1980"},{"key":"17_CR44","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"385","DOI":"10.1007\/978-3-662-48116-5_19","volume-title":"Fast Software Encryption","author":"Y Niwa","year":"2015","unstructured":"Niwa, Y., Ohashi, K., Minematsu, K., Iwata, T.: GCM security bounds reconsidered. In: Leander, G. (ed.) FSE 2015. LNCS, vol. 9054, pp. 385\u2013407. Springer, Heidelberg (2015). https:\/\/doi.org\/10.1007\/978-3-662-48116-5_19"},{"key":"17_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1007\/978-3-662-43933-3_15","volume-title":"Fast Software Encryption","author":"G Procter","year":"2014","unstructured":"Procter, G., Cid, C.: On weak keys and forgery attacks against polynomial-based MAC schemes. In: Moriai, S. (ed.) FSE 2013. LNCS, vol. 8424, pp. 287\u2013304. Springer, Heidelberg (2014). https:\/\/doi.org\/10.1007\/978-3-662-43933-3_15"},{"issue":"4","key":"17_CR46","doi-asserted-by":"publisher","first-page":"769","DOI":"10.1007\/s00145-014-9178-9","volume":"28","author":"G Procter","year":"2015","unstructured":"Procter, G., Cid, C.: On weak keys and forgery attacks against polynomial-based MAC schemes. J. Cryptol. 28(4), 769\u2013795 (2015)","journal-title":"J. Cryptol."},{"key":"17_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1007\/11787006_15","volume-title":"Automata, Languages and Programming","author":"K Pietrzak","year":"2006","unstructured":"Pietrzak, K.: A tight bound for EMAC. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) ICALP 2006. LNCS, vol. 4052, pp. 168\u2013179. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11787006_15"},{"issue":"1","key":"17_CR48","doi-asserted-by":"publisher","first-page":"188","DOI":"10.1109\/18.746787","volume":"45","author":"B Preneel","year":"1999","unstructured":"Preneel, B., van Oorschot, P.C.: On the security of iterated message authentication codes. IEEE Trans. Inf. Theor. 45(1), 188\u2013199 (1999)","journal-title":"IEEE Trans. Inf. Theor."},{"key":"17_CR49","unstructured":"Saarinen, M.-J.O.: SGCM: The Sophie Germain Counter Mode. Cryptology ePrint Archive, Report 2011\/326 (2011). http:\/\/eprint.iacr.org\/2011\/326"},{"key":"17_CR50","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"216","DOI":"10.1007\/978-3-642-34047-5_13","volume-title":"Fast Software Encryption","author":"M-JO Saarinen","year":"2012","unstructured":"Saarinen, M.-J.O.: Cycling attacks on GCM, GHASH and other polynomial MACs and Hashes. In: Canteaut, A. (ed.) FSE 2012. LNCS, vol. 7549, pp. 216\u2013225. Springer, Heidelberg (2012). https:\/\/doi.org\/10.1007\/978-3-642-34047-5_13"},{"key":"17_CR51","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"313","DOI":"10.1007\/3-540-68697-5_24","volume-title":"Advances in Cryptology \u2014 CRYPTO 1996","author":"V Shoup","year":"1996","unstructured":"Shoup, V.: On fast and provably secure message authentication based on universal hashing. In: Koblitz, N. (ed.) CRYPTO 1996. LNCS, vol. 1109, pp. 313\u2013328. Springer, Heidelberg (1996). https:\/\/doi.org\/10.1007\/3-540-68697-5_24"},{"key":"17_CR52","first-page":"381","volume-title":"Contemporary Cryptology: The Science of Information Integrity","author":"GJ Simmons","year":"1991","unstructured":"Simmons, G.J.: A survey of information authentication. In: Simmons, G.J. (ed.) Contemporary Cryptology: The Science of Information Integrity, pp. 381\u2013419. IEEE Press, New York (1991)"},{"key":"17_CR53","doi-asserted-by":"crossref","unstructured":"Salowey, J.A., McGrew, D.A., Choudhury, A.: AES Galois Counter Mode (GCM) Cipher Suites for TLS. RFC 5288, August 2008","DOI":"10.17487\/rfc5288"},{"key":"17_CR54","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"74","DOI":"10.1007\/3-540-46766-1_5","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201991","author":"DR Stinson","year":"1992","unstructured":"Stinson, D.R.: Universal hashing and authentication codes. In: Feigenbaum, J. (ed.) CRYPTO 1991. LNCS, vol. 576, pp. 74\u201385. Springer, Heidelberg (1992). https:\/\/doi.org\/10.1007\/3-540-46766-1_5"},{"key":"17_CR55","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48329-2","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 93","year":"1994","unstructured":"Stinson, D.R. (ed.): CRYPTO 1993. LNCS, vol. 773. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48329-2"},{"key":"17_CR56","doi-asserted-by":"crossref","unstructured":"Taylor, R.: An integrity check value algorithm for stream ciphers. In: Stinson [Sti94], pp. 40\u201348","DOI":"10.1007\/3-540-48329-2_4"},{"key":"17_CR57","doi-asserted-by":"crossref","unstructured":"Viega, J., McGrew, D.A.: The use of Galois Message Authentication Code (GMAC) in IPsec ESP and AH. RFC 4543, May 2006","DOI":"10.17487\/rfc4543"},{"issue":"3","key":"17_CR58","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1016\/0022-0000(81)90033-7","volume":"22","author":"MN Wegman","year":"1981","unstructured":"Wegman, M.N., Carter, L.: New hash functions and their use in authentication and set equality. J. Comput. Syst. Sci. 22(3), 265\u2013279 (1981)","journal-title":"J. Comput. Syst. Sci."},{"key":"17_CR59","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48405-1","volume-title":"Advances in Cryptology \u2014 CRYPTO\u2019 99","year":"1999","unstructured":"Wiener, M. (ed.): CRYPTO 1999. LNCS, vol. 1666. Springer, Heidelberg (1999). https:\/\/doi.org\/10.1007\/3-540-48405-1"},{"key":"17_CR60","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/978-3-319-02937-5_2","volume-title":"Cryptology and Network Security","author":"B Zhu","year":"2013","unstructured":"Zhu, B., Tan, Y., Gong, G.: Revisiting MAC forgeries, weak keys and provable security of galois\/counter mode of operation. In: Abdalla, M., Nita-Rotaru, C., Dahab, R. (eds.) CANS 2013. LNCS, vol. 8257, pp. 20\u201338. Springer, Cham (2013). https:\/\/doi.org\/10.1007\/978-3-319-02937-5_2"},{"key":"17_CR61","unstructured":"Zheng, K., Wang, P.: A uniform class of weak keys for universal hash functions. Cryptology ePrint Archive, Report 2017\/436 (2017). http:\/\/eprint.iacr.org\/2017\/436"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2018"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-78381-9_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T18:20:41Z","timestamp":1710267641000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-78381-9_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319783802","9783319783819"],"references-count":61,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-78381-9_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"31 March 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tel Aviv","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 April 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 May 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"37","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2018\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}