arXiv · cs/0507063
Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1
Abstract
The internal state of the Klimov-Shamir number generator TF-1 consists of four words of size w bits each, whereas its intended strength is 2^{2w}. We exploit an asymmetry in its output function to show that the internal state can be recovered after having 2^w outputs, using 2^{1.5w} operations. For w=32 the attack is practical, but for their recommended w=64 it is only of theoretical interest.
Explore related subjects
Keep this discovery
Boaz Tsaban. 2007-05-20. Theoretical cryptanalysis of the Klimov-Shamir number generator TF-1. https://doi.org/10.1007/s00145-007-0564-4
Cite the original work for its findings. Save a collection to share your selection of sources.