Linear models for a time-variant permutation generator
- 1 January 1999
- journal article
- Published by Institute of Electrical and Electronics Engineers (IEEE) in IEEE Transactions on Information Theory
- Vol. 45 (7) , 2374-2382
- https://doi.org/10.1109/18.796378
Abstract
A keystream generator, known as RC4, consisting of a permutation table that slowly varies in time under the control of itself, is analyzed by the linear model approach. The objective is to find linear relations among the keystream bits that hold with probability different from one half by using the linear sequential circuit approximation method. To estimate the corresponding correlation coefficients, some interesting correlation properties of random Boolean functions are derived. It is thus shown that the second binary derivative of the least significant hit output sequence is correlated to 1 with the correlation coefficient close to 15·2-3n where n is the variable word size of RC4. The output sequence length required for the linear statistical weakness detection is then around 64n/225. The result can be used to distinguish RC4 from other keystream generators and to determine the unknown parameter n, as well as for the plaintext uncertainty reduction if n is smallKeywords
This publication has 13 references indexed in Scilit:
- Resynchronization Weaknesses in Synchronous Stream CiphersPublished by Springer Nature ,2001
- Random Mapping StatisticsPublished by Springer Nature ,2001
- Correlation Via Linear Sequential Circuit Approximation of Combiners with MemoryPublished by Springer Nature ,2001
- Linear models for keystream generatorsIEEE Transactions on Computers, 1996
- Towards Fast Correlation Attacks on Irregularly Clocked Shift RegistersPublished by Springer Nature ,1995
- Correlation properties of combiners with memory in stream ciphersJournal of Cryptology, 1992
- Minimal linear equivalent analysis of a variable-memory binary sequence generatorIEEE Transactions on Information Theory, 1990
- Fast correlation attacks on certain stream ciphersJournal of Cryptology, 1989
- Correlation-immunity of nonlinear combining functions for cryptographic applications (Corresp.)IEEE Transactions on Information Theory, 1984
- Uniform Random Number GeneratorsJournal of the ACM, 1965