Hi Joe,
Thanks for your question.
There was an error in a previous version of our paper. The number of keystream needed in the attack on Toyocrypt should be 128 bits from each of 4 (or 8) re-sy
Forum: 2009 Reports
For the Toyocrypt complexities, how is it possible to recover a 128-bit state given 4 (or 8) bits of keystream without brute-forcing the last 124 (or 120) bits?
Forum: 2009 Reports