On the Security of a MAC by Mitchell
Takahiro Iwata · IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences · 2005
is a provably secure MAC scheme proposed by Iwata and Kurosawa [10]. NIST currently intends to specify as the modes recommendation. In August 2003, Mitchell published a note On the security of XCBC, TMAC and OMAC to propose a new variant of [16]. We call it OMAC1 In this paper, we prove that 1 is less secure than the original OMAC. We show a security gap between them. As a result, we obtain a negative answer to Mitchell's open question-OMAC1 is not provably secure even if the underlying block cipher is a PRP. Further, we point out limitations of discussion in [16].