Abstract
The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2 2w. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2 w outputs, using 2 1.5w operations. For w = 32 the attack is practical, but for their recommended w = 64 it is only of theoretical interest. © 2007 International Association for Cryptologic Research.
Author supplied keywords
Cite
CITATION STYLE
Tsaban, B. (2007). Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1. Journal of Cryptology, 20(3), 389–392. https://doi.org/10.1007/s00145-007-0564-4
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.