A Time-Memory Tradeoff Attack Against LILI-128

Markku-Juhani Olavi Saarinen

Abstract: In this note we discuss a novel but simple time-memory tradeoff attack against the stream cipher LILI-128. The attack defeats the security advantage of having an irregular stepping function. The attack requires $2^{46}$ bits of keystream, a lookup table of $2^{45}$ 89-bit words and computational effort which is roughly equivalent to $2^{48}$ DES operations.

Category / Keywords: secret-key cryptography / stream ciphers, nonlinear filter generators, time-memory tradeoff

Date: received 10 Sep 2001, last revised 16 Oct 2001

