On the Security of a New Variant of OMAC

OMAC is a provably secure MAC scheme which NIST currently intends to specify as the modes recommendation. In August 2003, Mitchell proposed a variant of OMAC. We call it OMAC1′′. In this paper, we prove that OMAC1′′ is less secure than original OMAC. We show a security gap between them. As a result, we obtain a negative answer to Mitchell’s open question — OMAC1′′ is not provably secure even if the underlying block cipher is a PRP.