Serge Vaudenay, Damian Vizár, Reza Reyhanitabar
We present two variants of OMD which are robust against nonce misuse. Security of OMD---a CAESAR candidate---relies on the assumption that implementations always ensure correct use of nonce (a.k.a. message number); namely that, the nonce never gets repeate ...
Springer-Verlag Berlin2014