A Linear Distinguishing Attack on Scream

Alexander Maximov, Thomas P. Johansson · IEEE Transactions on Information Theory · 2007

A linear distinguishing attack on the stream cipher Scream is proposed. When the keystream is of length 298words, the distinguisher has a detectable advantage. When the keystream length is around 2120the advantage is very close to 1. This shows certain weaknesses of Scream. In the process, the paper introduces new general ideas on how to improve the performance of linear distinguishing attacks on stream ciphers.

Read the paper · More papers on PaperTik