English

Computing the biases of parity-check relations

Cryptography and Security 2009-04-29 v1

Abstract

A divide-and-conquer cryptanalysis can often be mounted against some keystream generators composed of several (nonlinear) independent devices combined by a Boolean function. In particular, any parity-check relation derived from the periods of some constituent sequences usually leads to a distinguishing attack whose complexity is determined by the bias of the relation. However, estimating this bias is a difficult problem since the piling-up lemma cannot be used. Here, we give two exact expressions for this bias. Most notably, these expressions lead to a new algorithm for computing the bias of a parity-check relation, and they also provide some simple formulae for this bias in some particular cases which are commonly used in cryptography.

Keywords

Cite

@article{arxiv.0904.4412,
  title  = {Computing the biases of parity-check relations},
  author = {Anne Canteaut and Maria Naya-Plasencia},
  journal= {arXiv preprint arXiv:0904.4412},
  year   = {2009}
}
R2 v1 2026-06-21T12:55:55.188Z