By the character of homorphism function, the authorsanalyze the security of the authenticated encryption scheme, depended on the character of one-way function and proposed by Horster, Michels and Petresen, withlow communication costs, and present a known plaint-cryphertext attack method.At the end we get the conclusion that if the one-way function is homomorphism,the scheme is insecure.