A practical distinguisher for the Shannon cipher |
| |
Authors: | Zahra Ahmadian [Author Vitae] Javad Mohajeri [Author Vitae] |
| |
Affiliation: | a Department of Electrical Engineering, Sharif University of Technology, Tehran, Iran b Electronics Research Center, Sharif University of Technology, Tehran, Iran c Department of Information and Computer Science, Helsinki University of Technology, Finland |
| |
Abstract: | In this paper, we present a practical linear distinguisher on the Shannon stream cipher. Shannon is a synchronous stream cipher that uses at most 256-bit secret key. In the specification for Shannon, designers state that the intention of the design is to make sure that there are no distinguishing attacks on Shannon requiring less than 280 keystream words and less than 2128 computations. In this work we use the Crossword Puzzle attack technique to construct a distinguisher which requires a keystream of length about 231 words with workload about 231. |
| |
Keywords: | Stream ciphers Shannon Distinguishing attack Crossword Puzzle attack Linear cryptanalysis |
本文献已被 ScienceDirect 等数据库收录! |
|