Attacking the IV Setup of Stream Cipher LEX
Hongjun Wu, Bart Preneel · 2005
In this paper, we point out that the initialization of stream cipher LEX is weak. If a key is used with about 2 random IVs, and 20,000 keystream bytes are generated from each IV, then the key could be recovered easily.