AES-Gem (AES with Galois Extended Mode)
blog.trailofbits.com
blog.trailofbits.com
It would have been a good opportunity to leverage the AES-PRF construction (see tosc.v2018.i2.161-191 in addition to the original paper), whose overhead is negligible. But unfortunately, FIPS restrictions is why we can't have nice things.
If FIPS compliance is not a requirement, AEGIS (AEGIS-256 in particular) is a more efficient alternative and on the standard track.
But when only FIPS-approved things can be used, AES-GEM is a nice way to solve a very common problem.
My vacation plans include trying to grok at least a little bit of the xocb paper: https://dl.acm.org/doi/10.1007/978-3-031-30634-1_18
Never roll your on crypto. Always move slow and trust the process.
Moving slow is fine, but the reality is that the current options are not great for today's use cases. They're very easy to use insecurely.