A Practical Attack on Broadcast RC4

  • Itsik Mantin
  • Adi Shamir
Conference paper
Part of the Lecture Notes in Computer Science book series (LNCS, volume 2355)


RC4 is the most widely deployed stream cipher in software applications. In this paper we describe a major statistical weakness in RC4, which makes it trivial to distinguish between short outputs of RC4 and random strings by analyzing their second bytes. This weakness can be used to mount a practical ciphertext-only attack on RC4 in some broadcast applications, in which the same plaintext is sent to multiple recipients under different keys.


Stream Cipher Random String Predictive State Random Source Broadcast Application 
Copyright information

© Springer-Verlag Berlin Heidelberg 2002

Authors and Affiliations

  • Itsik Mantin
    • 1
  • Adi Shamir
    • 1
  1. 1.Computer Science DepartmentThe Weizmann InstituteRehovotIsrael

