Generalization of Roos bias in RC4 and some results on key-keystream relations
Sabyasachi Dey, Santanu Sarkar · Journal of Mathematical Cryptology · 2018
Abstract RC4 has attracted many cryptologists due to its simple structure. In [9], Paterson, Poettering and Schuldt reported the results of a large scale computation of RC4 biases. Among the biases reported by them, we try to theoretically analyze a few which show very interesting visual patterns. We first study the bias which relates the key stream byte z i {z_{i}} with i - k [ 0 ] {i-k[0]} , where k [ 0 ] {k[0]} is the first byte of the secret key. We then present a generalization of the Roos bias. In 1995, Roos observed the bias of initial bytes S [ i ] {S[i]} of the permutation after KSA towards f i = ∑ r = 1 i r + ∑ r = 0 i K [ r ] {f_{i}=\sum_{r=1}^{i}r+\sum_{r=0}^{i}K[r]} . Here we study the probability of S [ i ] {S[i]} equaling f y = ∑ r = 1 y r + ∑ r = 0 y K [ r ]