International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1

Authors:
Boaz Tsaban
Download:
URL: http://eprint.iacr.org/2005/244
Search ePrint
Search Google
Abstract: The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2^{2w}. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2^w outputs, using 2^{1.5w} operations. For w=32 the attack is practical, but for their recommended w=64 it is only of theoretical interest.
BibTeX
@misc{eprint-2005-12578,
  title={Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1},
  booktitle={IACR Eprint archive},
  keywords={secret-key cryptography / T-functions, TF-1},
  url={http://eprint.iacr.org/2005/244},
  note={ boaz.tsaban@weizmann.ac.il 12990 received 25 Jul 2005, last revised 26 Jul 2005},
  author={Boaz Tsaban},
  year=2005
}