Weaknesses in the Pseudorandom Bit Generation Algorithms of the Stream Ciphers TPypy and TPy.
Gautham Sekar, Souradyuti Paul, Bart Preneel · 2007
The stream ciphers Py, Py6 were designed by Biham and Seberry for the ECRYPT-eSTREAM project in 2005. However, due to several cryptanalytic attacks on them, a strengthened version Pypy was proposed to rule out those attacks. The ciphers were promoted to the ‘Focus ’ ciphers of the Phase II of the eSTREAM project. The impressive speed of the ciphers made them the forerunners in the competition. Unfortunately, even the new cipher Pypy was found to retain weaknesses, forcing the designers to again go for modifications. As a result, three new ciphers TPypy, TPy and TPy6 were built. Among all the members of the Py-family of ciphers, the TPypy is conjectured to be the strongest. Although TPy and TPy6 have been recently attacked, there is no known attack on the TPypy. The main achievement of the paper is the detection of input-output correlations (the relations occur with probability 1) of TPypy that allow us to build a distinguisher with 2 281 output words (collected from as many randomly selected keys) and comparable time. The cipher TPypy was claimed by the designers to be secure with key size up to 256 bytes, i.e., 2048 bits. Our results establish that the TPypy fails to provide adequate security if the key size is longer than 35 bytes, i.e., 280 bits. Because of remarkable similarities between the TPypy and the TPy, our attacks are shown to be effective for TPy also. The paper also points out how the other members of the Py-family (i.e., Pypy and Py) are also weak against the current attacks.