### Paper: The COS Stream Ciphers are Extremely Weak

Authors: Steve Babbage URL: http://eprint.iacr.org/2001/078 Search ePrint Search Google A new family of very fast stream ciphers called COS (for "crossing over system") has been proposed by Filiol and Fontaine, and seems to have been adopted for at least one commercial standard. In this note we show that the COS ciphers are very weak indeed ? it requires negligible effort to reconstruct the state of the keystream generator from a very small amount of known keystream.
