“Substitution Attacks against Message Authentication” (2019) IACR Transactions on Symmetric Cryptology, 2019(3), pp. 152–168. doi:10.13154/tosc.v2019.i3.152-168.