I've had a quick flick through this paper but I can't quite grasp the attack. In particular I can't see whether the attack is asserted to work no matter how many initialization rounds Trivium uses or whether it is shown to use too few. Can anyone shed any light? Cheers!
Paul Crowley, www.ciphergoth.org
Edited 1 time(s). Last edit at 04-Dec-2008 14:09 by ciphergoth.