<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>2012 Reports</title>
    <link>http://eprint.iacr.org/forum/list.php?12</link>
    <description><![CDATA[Discussion forum for Cryptology ePrint Archive reports posted in 2012. Please put the report number in the subject.]]></description>
    <language>EN</language>
    <pubDate>Sun, 09 Sep 2012 05:26:04 -0600</pubDate>
    <lastBuildDate>Sun, 09 Sep 2012 05:26:04 -0600</lastBuildDate>
    <category>2012 Reports</category>
    <generator>Phorum 5.1.22</generator>
    <ttl>600</ttl>
    <item>
      <title>Re: 2012/338</title>
      <link>http://eprint.iacr.org/forum/read.php?12,663,882#msg-882</link>
      <author>ncourtois</author>
      <description><![CDATA[MOREOVER. 
in their paper we read: 

&quot;This paper focuses on the LFSR-based multi-output stream
ciphers consisting of a linear feedback shift register (LFSR) and a multioutput filter boolean function&quot;

WHILE my paper covers already a MUCH more general case when also you have internal memory added to the non-linear filter, and when you have 0 memory bits, my framework degrades to the simple case they study here. 

The authors claimed to ignore and have promised me to update their paper on 25/06/2012... 

However to this day their paper was NOT updated. 

I must therefore ask the IACR to withdraw this paper and to blacklist the authors from eprint as perpetrators of serious scientific fraud.]]></description>
      <category>2012 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?12,663,882#msg-882</guid>
      <pubDate>Sun, 09 Sep 2012 05:26:04 -0600</pubDate>
    </item>
    <item>
      <title>2012/338</title>
      <link>http://eprint.iacr.org/forum/read.php?12,663,663#msg-663</link>
      <author>ncourtois</author>
      <description><![CDATA[In eprint/2012/338 we read:

&quot;for the first time, we propose a general algebraic attack framework on 
the multi-output stream ciphers&quot;

But in fact the authors ignore the most basic literature on the topic:
The following paper specifically covers the scenario with multiple 
outputs and provides many useful worst-case bounds on the existence of 
such attacks:

Nicolas Courtois:
Algebraic Attacks on Combiners with Memory and Several Outputs,
ICISC 2004, LNCS 3506, pp. 3-20, Springer 2005.
An extended and updated version of this paper is available at 
eprint.iacr.org/2003/125/.

=============

On page 5 we find 4 attack scenarios called S1-S4.

This is highly confusing, because, 
please note that a similar notation S12345 was used in the extended version of
Nicolas Courtois, Willi Meier: Algebraic Attacks on Stream Ciphers with 
Linear Feedback. Eurocrypt 2003, LNCS 2656, pp. 345-359, Springer.
This is available at http://www.nicolascourtois.com/toyolili.pdf

The notation S12345 is also used in extended slides by Courtois which can be found at
http://www.nicolascourtois.com/papers/toyolili_slides.pdf

The scenario S5 on page 70 is precisely the attack with multiple outputs (and also for augmented functions).
See also: 
http://eprint.iacr.org/forum/read.php?12,597,597#msg-597]]></description>
      <category>2012 Reports</category>
      <guid isPermaLink="true">http://eprint.iacr.org/forum/read.php?12,663,663#msg-663</guid>
      <pubDate>Sat, 23 Jun 2012 12:41:43 -0600</pubDate>
    </item>
  </channel>
</rss>
