Related Key Chosen IV Attack on Stream Cipher Espresso Variant

Ming Xing Wang, Dong Dai Lin · 2017

The stream cipher Espresso was proposed by Elena Dubrova and Martin Hell in Cryptography and Communications in 2015, which employs the nonlinear feedback shift register (NLFSR) of Galois configuration as a main building block. This Galois configuration of NLFSR is transformed into its equivalent Fibonacci configuration, and then stream cipher Espresso is changed into the stream cipher Espresso variant denoted by Espresso-a. The structures of both Grain and Espresso-a are similar. Therefore, by virtue of slide attack used in the analysis of Grain, Related key chosen IV attack on the stream cipher Espresso-a is mounted. It is shown that the attack on Espresso-a recovers the 128-bit secret key with only two pairs of related key-IVs, no more than 242 chosen IVs and 264 computational complexity. Thus stream cipher Espresso is not secure for 128-bit secret key.

Read the paper · More papers on PaperTik