IV Ek ⊕ Plaintext Ciphertext ⊕ MultH Ek Ek ⊕ Ciphertext Plaintext MultH ⊕ MultH [len(A)]64 || [len(C)]64 MultH ⊕ Associated Data ⊕ Auth Tag = Authentication
IV Ek ⊕ Plaintext Ciphertext ⊕ MultH Ek Ek ⊕ Ciphertext Plaintext MultH ⊕ MultH [len(A)]64 || [len(C)]64 MultH ⊕ Associated Data ⊕ Auth Tag = Ek 0 H H = Ek(0)
IV Ek ⊕ Plaintext Ciphertext ⊕ MultH Ek Ek ⊕ Ciphertext Plaintext MultH ⊕ MultH [len(A)]64 || [len(C)]64 MultH ⊕ Associated Data ⊕ Auth Tag = 這邊和加密時顛倒 其他都⼀樣