Chosen IV Attack on Stream Cipher WG

Hongjun Wu, Bart Preneel · 2005

Stream cipher WG [3] is a hardware oriented cipher. In this paper, we point out that the WG stream cipher is vulnerable to the chosen IV attacks. For WG with 80-bit key and 80-bit IV, 48 bits of the secret key could be recovered with about 2 chosen IVs . For WG with 80-bit key and 64-bit IV, 29-bit information of the secret key could be recovered with probability 2 -5 and with about 2 chosen IVs. For each chosen IV, only the first four keystram bits are needed in the attack.

Read the paper · More papers on PaperTik