(1)
Iwata, T.; Seurin, Y. Reconsidering the Security Bound of AES-GCM-SIV. ToSC 2017, 2017, 240-267.