Near Collision Attack on the Grain v1 Stream Cipher
Near Collision Attack on the Grain v1 Stream Cipher
复制标题
DOI:
10.1007/978-3-662-43933-3_27
复制
发表时间:
2013-03
期刊:
影响因子:
--
通讯作者:
Bin Zhang;Zhenqi Li;D. Feng;D. Lin
中科院分区:
文献类型:
--
作者:
Bin Zhang;Zhenqi Li;D. Feng;D. Lin
Grain v1 is one of thefinalists selected in the final portfolio by the eSTREAM project. It has an elegant and compact structure, especially suitable for a constrained hardware environment. Though a number of potential weaknesses have been identified, no key recovery attack on the original design in the single key model has been found yet. In this paper, we propose a key recovery attack, called near collision attack, on Grain v1. The attack utilizes the compact NFSR-LFSR combined structure of Grain v1 and works even if all of the previous identified weaknesses have been sewed and if a perfect key/IV initialization algorithm is adopted. Our idea is to identify near collisions of the internal states at different time instants and restore the states accordingly. Combined with the BSW sampling and the non-uniform distribution of internal state differences for a fixed keystream difference, our attack has been verified on a reduced version of Grain v1 in experiments. An extrapolation of the results under some assumption indicates an attack on Grain v1 for any fixed IV incipher ticks after the pre-computation ofticks, given-bit memory andkeystream bits, which is the best key recovery attack against Grain v1 so far. Hopefully, it provides some new insights on such compact stream ciphers.