Improved cryptanalysis of Py

Paul Crowley · 2006

We improve on the best known cryptanalysis of the stream cipher Py by using a hidden Markov model for the carry bits in addition operations where a certain distinguishing event takes place, and constructing from it an "optimal distinguisher" for the bias in the output bits which makes more use of the information available. We provide a general means to e#ciently measure the e#cacy of such a hidden Markov model based distinguisher, and show that our attack improves on the previous distinguisher by a factor of 2 in the number of samples needed. Given 2 bytes of output we can distinguish Py from random with advantage greater than 2 , or given only a single stream of 2 bytes we have advantage 0.03.

Read the paper · More papers on PaperTik