Duplex-based authenticated encryption modes with a sufficiently large key length are proven to be secure up the birthday bound $$2^{\frac{c}{2}}$$ , where c is capacity. However this not known tight and complexity of best generic attack, which based on multicollisions, much larger: it reaches $$\frac{2^c}{\alpha }$$ $$\alpha $$ represents small security loss factor. There thus an uncertainty tr...