2019
DOI: 10.1007/s10623-019-00674-1
|View full text |Cite
|
Sign up to set email alerts
|

New cube distinguishers on NFSR-based stream ciphers

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
3
0

Year Published

2019
2019
2023
2023

Publication Types

Select...
5
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 13 publications
(3 citation statements)
references
References 14 publications
0
3
0
Order By: Relevance
“…Various cryptanalytic techniques have been applied to the proposed stream cipher. It is resistant to several attacks such as distinguisher attacks [19], and correlation attacks, and the keystream generated by it has good statistical properties like large period, high entropy, and high linear complexity [20]. It has been shown that retrieving the key or initial vector given the keystream is extremely difficult based on the correlation tests.…”
Section: Security Analysis Of Proposed Designmentioning
confidence: 99%
See 1 more Smart Citation
“…Various cryptanalytic techniques have been applied to the proposed stream cipher. It is resistant to several attacks such as distinguisher attacks [19], and correlation attacks, and the keystream generated by it has good statistical properties like large period, high entropy, and high linear complexity [20]. It has been shown that retrieving the key or initial vector given the keystream is extremely difficult based on the correlation tests.…”
Section: Security Analysis Of Proposed Designmentioning
confidence: 99%
“…The fact of linear combinations between internal automaton states that occur with a biased probability can be used as a basis for distinguishing attacks [19]. The existence of such relations seems implausible given the presence of carry cells.…”
Section: A Distinguisher Attackmentioning
confidence: 99%
“…We apply our degree evaluation algorithm and superpoly recovery algorithm for Trivium. First we apply our algorithm on three cubes proposed in [KRSM20], which was tested to have zero-sum distinguisher till 842 rounds. We found they do not have zero-sum for some rounds, but two of them still have 841-round zero-sum distinguisher, which is the maximum number of rounds found so far for Trivium.…”
Section: Introductionmentioning
confidence: 99%