An algorithm is given for the reconstruction of the initial state of a key-stream generator (KSG) consisting of a short linear feedback shift register (length >or=30), whose clock is controlled by an algebraically simple internal KSG. The algorithm is based on the fact that the expected number of possible binary linear feedback shift register initial states exponentially decreases with the length of the known part of the output sequence.
展开▼