Access the full text.
Sign up today, get DeepDyve free for 14 days.
Håkan Englund, A. Maximov (2005)
Attack the Dragon
M. Matsui (1994)
Linear Cryptanalysis Method for DES Cipher
M. Matsumoto, T. Nishimura (1998)
Mersenne twister: a 623-dimensionally equidistributed uniform pseudo-random number generatorACM Trans. Model. Comput. Simul., 8
B. Kaliski, M. Robshaw (1994)
Linear Cryptanalysis Using Multiple Approximations
Miia Hermelin, J. Cho, K. Nyberg (2008)
Multidimensional Linear Cryptanalysis of Reduced Round Serpent
A. Biryukov, C. Cannière, Michaël Quisquater (2004)
On Multiple Linear Approximations
Thomas Baignères, P. Junod, S. Vaudenay (2004)
How Far Can We Go Beyond Linear Cryptanalysis?
Gregory Rose, P. Hawkes, M. Paddon, Cameron McDonald, Miriam Vries (2007)
Design and Primitive Specification for ShannonIACR Cryptol. ePrint Arch., 2007
T. Cover, Joy Thomas (2005)
Elements of Information Theory
J. Cho, J. Pieprzyk (2006)
Crossword Puzzle Attack on NLS
B. Sankur (1986)
Applications of Walsh and related functionsSignal Processing, 10
H. Cramér, H. Wold (1936)
Some Theorems on Distribution FunctionsJournal of The London Mathematical Society-second Series
Yi Lu, S. Vaudenay (2008)
Cryptanalysis of an E0-like Combiner with MemoryJournal of Cryptology, 21
A. Maximov, T. Johansson (2005)
Fast Computation of Large Distributions and Its Cryptographic Applications
J. Shanks (1969)
Computation of the Fast Walsh-Fourier TransformIEEE Transactions on Computers, C-18
In this article, we present a linear distinguishing attack on the stream cipher Shannon. Our distinguisher can distinguish the output keystream of Shannon from about 2107 keystream words while using an array of 232 counters. The distinguisher makes use of a multidimensional linear transformation instead of a 1D transformation, which is traditionally used in linear distinguishing attacks. This gives a clear improvement to the keystream requirement: we need approximately 25 times less keystream than when a 1D transformation is used. In addition, we give evidence of the correctness of the distinguisher by applying it to a smaller version of Shannon.
International Journal of Applied Cryptography – Inderscience Publishers
Published: Jan 1, 2009
Read and print from thousands of top scholarly journals.
Already have an account? Log in
Bookmark this article. You can see your Bookmarks on your DeepDyve Library.
To save an article, log in first, or sign up for a DeepDyve account if you don’t already have one.
Copy and paste the desired citation format or use the link below to download a file formatted for EndNote
Access the full text.
Sign up today, get DeepDyve free for 14 days.
All DeepDyve websites use cookies to improve your online experience. They were placed on your computer when you launched this website. You can change your cookie settings through your browser.