Loading CryptoViz...
Loading page content...Loading CryptoViz...
Loading page content...AES-GCM authenticates with a tag T = GHASH_H(C) ⊕ E_K(J0). The mask E_K(J0) depends only on the nonce, so reusing a nonce lets an attacker subtract two tags, solve for the secret GHASH key H in GF(2¹²⁸), and forge a valid tag for any message — the “forbidden attack.” Encrypt two messages under one nonce and watch authentication collapse.