Substitution Attacks against Message Authentication. (2019). IACR Transactions on Symmetric Cryptology, 2019(3), 152-168. https://doi.org/10.13154/tosc.v2019.i3.152-168