论文部分内容阅读
A linearization attack on the Key Stream Generator (KSG) of the modified E0 algorithm proposed by Hermelin [Proceedings of ICISC’99, Springer LNCS 1787, 2000, 17-29] is given in this paper. The initial value can be recovered by a linearization attack with O(260.52) operations by solving a System of Linear Equations (SLE) with at most 220.538 unknowns. Frederik Armknecht [Cryptology ePrint Archive, 2002/191] proposed a linearization attack on the KSG of E0 algorithm with 0(270.341) operations by solving an SLE with at most 224.056 unknowns, so the modification proposed by Hermelin reduces the ability of E0 to resist the linearization attack by comparing with the results of Frederik Annknecht.
A linearization attack on the Key Stream Generator (KSG) of the modified E0 algorithm proposed by Hermelin [Proceedings of ICISC’99, Springer LNCS 1787, 2000, 17-29] is given in this paper. The initial value can be recovered by a Frederik Armknecht [Cryptology ePrint Archive, 2002/191] proposed a linearization attack on the KSG of E0 algorithm with 0 (270.341) proposed a linearization attack with O (260.52) operations by solving a System of Linear Equations (SLE) with at most 220.538 unknowns. operations by solving an SLE with at most 224.056 unknowns, so the modification proposed by Hermelin reduces the ability of E0 to resist the linearization attack by comparing with the results of Frederik Annknecht.