Cryptology ePrint Archive: Report 2001/078

The COS Stream Ciphers are Extremely Weak

Steve Babbage

Abstract: A new family of very fast stream ciphers called COS (for "crossing over system") has been proposed by Filiol and Fontaine, and seems to have been adopted for at least one commercial standard. In this note we show that the COS ciphers are very weak indeed — it requires negligible effort to reconstruct the state of the keystream generator from a very small amount of known keystream.

Category / Keywords: secret-key cryptography / COS, stream cipher, nonlinear feedback shift register, cryptanalysis

Date: received 11 Sep 2001

Contact author: steve babbage at vodafone com

Available format(s): Postscript (PS) | Compressed Postscript (PS.GZ) | PDF | BibTeX Citation

Version: 20010911:180227 (All versions of this report)

Short URL:

[ Cryptology ePrint archive ]