ChaCha20Poly1305 has multi-key AE and integrity limit identical to single-user case (just that v is counted across all keys), multi-key confdentiality limit is bounded at very low levels
multi-key GCM bound improved: the above work shows that the constant additive 2^-48 term can be waived without further side-effects on the dominant terms
Added multi-key bounds from https://doi.org/10.1145/3460120.3484814 (CCS 2021).
v
is counted across all keys), multi-key confdentiality limit is bounded at very low levels