In this paper we present the application of linear (masking) attack to SNOW 2.0 stream cipher. SNOW 2.0 was developed by Johausson and Ekdahl in 2002, as a modified version of SNOW 1.0. The key length of SNOW 2.0 is 128 bits or 256 bits, so that the bias of the output should be less than 2{sup}(-128). However, the attack with linear masking method can distinguish the output of SNOW 2.0 from a truly random bit sequence by observing 2{sup}205 rounds outputs (2{sup}210 bits).
展开▼