You are looking at a specific version 20050730:162618 of this paper.
See the latest version.
Paper 2005/244
Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1
Boaz Tsaban
Abstract
The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2^{2w}. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2^w outputs, using 2^{1.5w} operations. For w=32 the attack is practical, but for their recommended w=64 it is only of theoretical interest.
Note: We thank Alexander Klimov for his comments.
Metadata
- Available format(s)
- PDF PS
- Category
- Secret-key cryptography
- Publication info
- Published elsewhere. Unknown where it was published
- Keywords
- T-functionsTF-1
- Contact author(s)
- boaz tsaban @ weizmann ac il
- History
- 2005-07-30: received
- Short URL
- https://ia.cr/2005/244
- License
-
CC BY