CryptoDB
Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1
Authors: | |
---|---|
Download: | |
Abstract: | The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2^{2w}. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2^w outputs, using 2^{1.5w} operations. For w=32 the attack is practical, but for their recommended w=64 it is only of theoretical interest. |
BibTeX
@misc{eprint-2005-12578, title={Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1}, booktitle={IACR Eprint archive}, keywords={secret-key cryptography / T-functions, TF-1}, url={http://eprint.iacr.org/2005/244}, note={ boaz.tsaban@weizmann.ac.il 12990 received 25 Jul 2005, last revised 26 Jul 2005}, author={Boaz Tsaban}, year=2005 }