[1]
T. Iwata and Y. Seurin, “Reconsidering the Security Bound of AES-GCM-SIV”, ToSC, vol. 2017, no. 4, pp. 240–267, Dec. 2017.