Cryptanalysis of the Stream Cipher DECIM

  • Hongjun Wu
  • Bart Preneel
Part of the Lecture Notes in Computer Science book series (LNCS, volume 4047)

Abstract

DECIM is a hardware oriented stream cipher with an 80-bit key and a 64-bit IV. In this paper, we point out two serious flaws in DECIM. One flaw is in the initialization of DECIM. It allows to recover about half of the key bits bit-by-bit when one key is used with about 220 random IVs; only the first two bytes of each keystream are needed in the attack. The amount of computation required in the attack is negligible. Another flaw is in the keystream generation algorithm of DECIM. The keystream is heavily biased: any two adjacent keystream bits are equal with probability about \({1 \over 2}+2^{-9}\). A message could be recovered from the ciphertext if that message is encrypted by DECIM for about 218 times. DECIM with an 80-bit key and an 80-bit IV is also vulnerable to these attacks.

References

  1. 1.
    Berbain, C., Billet, O., Canteaut, A., Courtois, N., Debraize, B., Gilbert, H., Goubin, L., Gouget, A., Granboulan, L., Lauradoux, C., Minier, M., Pornin, T., Sibert, H.: Decim - A New Stream Cipher for Hardware Applications. ECRYPT Stream Cipher Project Report, /004 (2005), Available at, http://www.ecrypt.eu.org/stream/
  2. 2.
    Berbain, C., Billet, O., Canteaut, A., Courtois, N., Debraize, B., Gilbert, H., Goubin, L., Gouget, A., Granboulan, L., Lauradoux, C., Minier, M., Pornin, T., Sibert, H.: DECIM v2. ECRYPT Stream Cipher Project Report 2006/004. Available at, http://www.ecrypt.eu.org/stream/
  3. 3.
    Coppersmith, D., Krawczyk, H., Mansour, Y.: The Shrinking Generator. In: Stinson, D.R. (ed.) CRYPTO 1993. LNCS, vol. 773, pp. 22–39. Springer, Heidelberg (1994)Google Scholar
  4. 4.
    ECRYPT Stream Cipher Project, http://www.ecrypt.eu.org/stream/
  5. 5.
    Mantin, I., Shamir, A.: A Practical Attack on Broadcast RC4. In: Matsui, M. (ed.) FSE 2001. LNCS, vol. 2355, pp. 152–164. Springer, Heidelberg (2002)CrossRefGoogle Scholar
  6. 6.
    Meier, W., Staffelbach, O.: The Self-Shrinking Generator. In: De Santis, A. (ed.) EUROCRYPT 1994. LNCS, vol. 950, pp. 205–214. Springer, Heidelberg (1994)CrossRefGoogle Scholar

Copyright information

© Springer-Verlag Berlin Heidelberg 2006

Authors and Affiliations

  • Hongjun Wu
    • 1
  • Bart Preneel
    • 1
  1. 1.Katholieke Universiteit Leuven, ESAT/SCD-COSICLeuven-HeverleeBelgium

Personalised recommendations