TRIVIUM's output partially autocancels

Michael Vielhaber

Abstract: The eStream cipher proposal TRIVIUM outputs an XOR sum of six internal state bits. These in turn are obtained from 18 bits linearly, plus six ANDings of two bits each.

We show that 4 of the 18 linear terms cancel between themselves.

Category / Keywords: secret-key cryptography / cryptanalysis

Date: received 3 Sep 2008

