Alinear weakness in the Klimov-Shamir T-function
Håvard Molland, Tor Helleseth · 2005
Linear equations have always been powerful tools in cryptanalysis. In this paper, we present a general linear equation in the binary alphabet of minimum weight 3 that holds for all state lengths and all shifts of sequences generated by the T-function proposed by Klimov and Shamir. It is surprising that these linear properties exist, and they indicate that the T-functions are not as 'wild' and non-algebraic as claimed by Klimov and Shamir. We also use the equation to propose a simple algebraic attack on cryptographic T-functions