## CryptoDB

### Paper: Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1

Authors: Boaz Tsaban URL: http://eprint.iacr.org/2005/244 Search ePrint Search Google The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2^{2w}. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2^w outputs, using 2^{1.5w} operations. For w=32 the attack is practical, but for their recommended w=64 it is only of theoretical interest.
##### BibTeX
@misc{eprint-2005-12578,
title={Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1},
booktitle={IACR Eprint archive},
keywords={secret-key cryptography / T-functions, TF-1},
url={http://eprint.iacr.org/2005/244},
note={ boaz.tsaban@weizmann.ac.il 12990 received 25 Jul 2005, last revised 26 Jul 2005},
author={Boaz Tsaban},
year=2005
}