{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T00:37:03Z","timestamp":1764981423528,"version":"3.46.0"},"reference-count":8,"publisher":"Walter de Gruyter GmbH","issue":"1","license":[{"start":{"date-parts":[[2018,1,11]],"date-time":"2018-01-11T00:00:00Z","timestamp":1515628800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018,3,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>In this article, we analyse a block cipher mode of operation for authenticated encryption known as ++AE (plus-plus-AE). We show that this mode has a fundamental flaw: the scheme does not verify the most significant bit of any block in the plaintext message. This flaw can be exploited by choosing a plaintext message and then constructing multiple forged messages in which the most significant bit of certain blocks is flipped. All of these plaintext messages will generate the same authentication tag. This forgery attack is deterministic and guaranteed to pass the ++AE integrity check. The success of the attack is independent of the underlying block cipher, key or public message number. We outline the mathematical proofs for the flaw in the ++AE algorithm. We conclude that ++AE is insecure as an authenticated encryption mode of operation.<\/jats:p>","DOI":"10.1515\/jmc-2016-0037","type":"journal-article","created":{"date-parts":[[2018,1,11]],"date-time":"2018-01-11T17:16:07Z","timestamp":1515690967000},"page":"37-42","source":"Crossref","is-referenced-by-count":1,"title":["A fundamental flaw in the ++AE authenticated encryption mode"],"prefix":"10.1515","volume":"12","author":[{"given":"Hassan","family":"Qahur Al Mahri","sequence":"first","affiliation":[{"name":"Queensland University of Technology , 2 George St. , Brisbane 4000 , Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leonie","family":"Simpson","sequence":"additional","affiliation":[{"name":"Queensland University of Technology , 2 George St. , Brisbane 4000 , Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4347-0144","authenticated-orcid":false,"given":"Harry","family":"Bartlett","sequence":"additional","affiliation":[{"name":"Queensland University of Technology , 2 George St. , Brisbane 4000 , Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ed","family":"Dawson","sequence":"additional","affiliation":[{"name":"Queensland University of Technology , 2 George St. , Brisbane 4000 , Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kenneth Koon-Ho","family":"Wong","sequence":"additional","affiliation":[{"name":"Queensland University of Technology , 2 George St. , Brisbane 4000 , Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"374","published-online":{"date-parts":[[2018,1,11]]},"reference":[{"key":"2025120600322795865_j_jmc-2016-0037_ref_001_w2aab3b7b1b1b6b1ab1b4b1Aa","doi-asserted-by":"crossref","unstructured":"M.  Bellare and C.  Namprempre,\nAuthenticated encryption: Relations among notions and analysis of the generic composition paradigm,\nAdvances in Cryptology \u2013 ASIACRYPT 2000,\nSpringer, Berlin (2000), 531\u2013545.","DOI":"10.1007\/3-540-44448-3_41"},{"key":"2025120600322795865_j_jmc-2016-0037_ref_002_w2aab3b7b1b1b6b1ab1b4b2Aa","unstructured":"D.  Bernstein,\nCryptographic competitions: CAESAR,\npreprint (2014), http:\/\/competitions.cr.yp.to\/caesar-submissions.html."},{"key":"2025120600322795865_j_jmc-2016-0037_ref_003_w2aab3b7b1b1b6b1ab1b4b3Aa","doi-asserted-by":"crossref","unstructured":"P.  Bottinelli, R.  Reyhanitabar and S.  Vaudenay,\nBreaking the IOC authenticated encryption mode,\nProgress in Cryptology \u2013 AFRICACRYPT 2014,\nSpringer, Berlin (2014), 126\u2013135.","DOI":"10.1007\/978-3-319-06734-6_8"},{"key":"2025120600322795865_j_jmc-2016-0037_ref_004_w2aab3b7b1b1b6b1ab1b4b4Aa","doi-asserted-by":"crossref","unstructured":"H. Q. A.  Mahri, L.  Simpson, H.  Bartlett, E.  Dawson and K.-H.  Wong,\nForgery attacks on ++AE authenticated encryption mode,\nProceedings of the Australasian Computer Science Week Multiconference \u2013 ACSW \u201916.\nACM, New York (2016), Article No. 33.","DOI":"10.1145\/2843043.2843355"},{"key":"2025120600322795865_j_jmc-2016-0037_ref_005_w2aab3b7b1b1b6b1ab1b4b5Aa","doi-asserted-by":"crossref","unstructured":"C.  Mitchell,\nAnalysing the IOBC authenticated encryption mode,\nInformation Security and Privacy \u2013 ACISP 2013,\nSpringer, Berlin (2013), 1\u201312.","DOI":"10.1007\/978-3-642-39059-3_1"},{"key":"2025120600322795865_j_jmc-2016-0037_ref_006_w2aab3b7b1b1b6b1ab1b4b6Aa","unstructured":"F.  Recacha,\nIOBC: A new chaining method for block ciphering (in Spanish),\nProceedings: IV Reunion Espanola de Cryptologia,\nValladolid (1996), 85\u201392."},{"key":"2025120600322795865_j_jmc-2016-0037_ref_007_w2aab3b7b1b1b6b1ab1b4b7Aa","unstructured":"F.  Recacha,\nIOC: The most lightweight authenticated encryption mode?,\npreprint (2013), http:\/\/citeseerx.ist.psu.edu\/viewdoc\/download?doi=10.1.1.298.1691&rep=rep1&type=pdf."},{"key":"2025120600322795865_j_jmc-2016-0037_ref_008_w2aab3b7b1b1b6b1ab1b4b8Aa","unstructured":"F.  Recacha,\n++AE v1.1,\npreprint (2014), http:\/\/competitions.cr.yp.to\/caesar-call.html."}],"container-title":["Journal of Mathematical Cryptology"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/www.degruyter.com\/view\/j\/jmc.2018.12.issue-1\/jmc-2016-0037\/jmc-2016-0037.xml","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0037\/xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0037\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,6]],"date-time":"2025-12-06T00:34:29Z","timestamp":1764981269000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.degruyterbrill.com\/document\/doi\/10.1515\/jmc-2016-0037\/html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,1,11]]},"references-count":8,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2018,2,9]]},"published-print":{"date-parts":[[2018,3,1]]}},"alternative-id":["10.1515\/jmc-2016-0037"],"URL":"https:\/\/doi.org\/10.1515\/jmc-2016-0037","relation":{},"ISSN":["1862-2984","1862-2976"],"issn-type":[{"type":"electronic","value":"1862-2984"},{"type":"print","value":"1862-2976"}],"subject":[],"published":{"date-parts":[[2018,1,11]]}}}