GCM/GMAC Zero-Length Nonce Attack
Arxiv
pdf
2026-08-01T00:00:00
arXiv Paper — PDF not available.
Only the Executive Summary is available here. To read or download the full paper, visit the
arXiv abstract page.
Abstract
In this note, we show a simple attack that can recover the hash key of GCM and GMAC by using a zero length nonce. After recovering the hash key, the adversary can forge an arbitrary ciphertext or message as she wants. We note that the ISO/IEC version of GCM and GMAC allows the nonce to be a zero length string, while the NIST version of GCM and GMAC explicitly requires the nonce to be at least one bit. Hence, our attack works for the ISO/IEC version and cannot work for the NIST version.
Loading executive summary...