Abstract
Authenticated encryption scheme is very useful for transmitting a confidential message in insecure networks. Recently, Tzeng et al. proposed a convertible authenticated encryption scheme with message linkages. However, this paper points out that Tzeng et al.'s scheme cannot provide forward secrecy and then proposes an improvement that can provide forward secrecy for practical application.