Figure 5. Algorithm PRFCTR (tPRF CounTeR mode). $$ F $$ is a TPRF. The tweak starts with the 0 bit for domain separation with respect to calls in $$ \mathtt{BKCond}$$.
All published articles are preserved here permanently: