Sciweavers

FSE
2001
Springer

Bias in the LEVIATHAN Stream Cipher

13 years 9 months ago
Bias in the LEVIATHAN Stream Cipher
We show two methods of distinguishing the LEVIATHAN stream cipher from a random stream using 236 bytes of output and proportional effort; both arise from compression within the cipher. The first models the cipher as two random functions in sequence, and shows that the probability of a collision in 64-bit output blocks is doubled as a result; the second shows artifacts where the same inputs are presented to the key-dependent S-boxes in the final stage of the cipher for two successive outputs. Both distinguishers are demonstrated with experiments on a reduced variant of the cipher.
Paul Crowley, Stefan Lucks
Added 28 Jul 2010
Updated 28 Jul 2010
Type Conference
Year 2001
Where FSE
Authors Paul Crowley, Stefan Lucks
Comments (0)