Lecture Notes in Computer Science, 2007, Volume 4593/2007, 274-289, DOI: 10.1007/978-3-540-74619-5_18

Two General Attacks on Pomaranch-Like Keystream Generators

Håkan Englund, Martin Hell and Thomas Johansson

View Related Documents

Abstract

Two general attacks that can be applied to all versions and variants of the Pomaranch stream cipher are presented. The attacks are demonstrated on all versions and succeed with complexity less than exhaustive keysearch. The first attack is a distinguisher which needs keystream from only one or a few IVs to succeed. The attack is not only successful on Pomaranch Version 3 but has also less computational complexity than all previously known distinguishers for the first two versions of the cipher. The second attack is an attack which requires keystream from an amount of IVs exponential in the state size. It can be used as a distinguisher but it can also be used to predict future keystream bits corresponding to an IV if the first few bits are known. The attack will succeed on all versions of Pomaranch with complexities much lower than previously known attacks.

Keywords  Stream ciphers - distinguishing attack - resynchronization attack - eSTREAM - Pomaranch

Fulltext Preview

Image of the first page of the fulltext document