Key points are not available for this paper at this time.
A new implementation of the GHASH function has been recently committed to a Git version of Open SSL, to speed up AES-GCM. We identified a bug in that implementation, and made sure it was quickly fixed before trickling into an official Open SSL trunk. Here, we use this (already fixed) bug as a real example that demonstrates the fragility of AES-GCM's authentication algorithm (GHASH). One might expect that incorrect MAC tag generation would only cause legitimate message-tag pairs to fail authentication (which is already a serious problem). However, since GHASH is a "polynomial evaluation" MAC, the bug can be exploited for actual message forgery.
Gueron et al. (2014) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: