Cryptanalysis of Sosemanuk and SNOW 2.0 Using Linear Masks

  • Authors:
  • Jung-Keun Lee;Dong Hoon Lee;Sangwoo Park

  • Affiliations:
  • ETRI Network & Communication Security Division, Daejeon, Korea;ETRI Network & Communication Security Division, Daejeon, Korea;ETRI Network & Communication Security Division, Daejeon, Korea

  • Venue:
  • ASIACRYPT '08 Proceedings of the 14th International Conference on the Theory and Application of Cryptology and Information Security: Advances in Cryptology
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present a correlation attack on Sosemanuk withcomplexity less than 2150. Sosemanuk is a softwareoriented stream cipher proposed by Berbain et al. to the eSTREAMcall for stream cipher and has been selected in the finalportfolio. Sosemanuk consists of a linear feedback shiftregister(LFSR) of ten 32-bit words and a finite state machine(FSM)of two 32-bit words. By combining linear approximation relationsregarding the FSM update function, the FSM output function and thekeystream output function, it is possible to derive linearapproximation relations with correlation -2-21.41involving only the keystream words and the LFSR initial state.Using such linear approximation relations, we mount a correlationattack with complexity 2147.88 and success probability99% to recover the initial internal state of 384 bits. We alsomount a correlation attack on SNOW 2.0 with complexity2204.38.