A LINEARIZATION ATTACK ON MODIFIED E0 ALGORITHM

(整期优先)网络出版时间:2006-03-13
/ 1
AlinearizationattackontheKeyStreamGenerator(KSG)ofthemodifiedE0algorithmproposedbyHermelin[ProceedingsofICISC'99,SpringerLNCS1787,2000,17-29]isgiveninthispaper.TheinitialvaluecanberecoveredbyalinearizationattackwithO(260.52)operationsbysolvingaSystemofLinearEquations(SLE)withatmost220.538unknowns.FrederikArmknecht[CryptologyePrintArchive,2002/191]proposedalinearizationattackontheKSGofE0algorithmwith0(270.341)operationsbysolvinganSLEwithatmost224.056unknowns,sothemodificationproposedbyHermelinreducestheabilityofE0toresistthelinearizationattackbycomparingwiththeresultsofFrederikAnnknecht.