<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article  PUBLIC "-//NLM//DTD Journal Publishing DTD v3.0 20080202//EN" "http://dtd.nlm.nih.gov/publishing/3.0/journalpublishing3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="3.0" xml:lang="en" article-type="research article"><front><journal-meta><journal-id journal-id-type="publisher-id">CS</journal-id><journal-title-group><journal-title>Circuits and Systems</journal-title></journal-title-group><issn pub-type="epub">2153-1285</issn><publisher><publisher-name>Scientific Research Publishing</publisher-name></publisher></journal-meta><article-meta><article-id pub-id-type="doi">10.4236/cs.2013.42022</article-id><article-id pub-id-type="publisher-id">CS-29860</article-id><article-categories><subj-group subj-group-type="heading"><subject>Articles</subject></subj-group><subj-group subj-group-type="Discipline-v2"><subject>Computer Science&amp;Communications</subject><subject> Engineering</subject><subject> Physics&amp;Mathematics</subject></subj-group></article-categories><title-group><article-title>
 
 
  The Nonlinear Filter Boolean Function of LILI-128 Stream Cipher Generator Is Successfully Broken Based on the Complexity of Nonlinear 0 1 Symbol Sequence
 
</article-title></title-group><contrib-group><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>iangao</surname><given-names>Huang</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref><xref ref-type="corresp" rid="cor1"><sup>*</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Chao</surname><given-names>Wang</given-names></name><xref ref-type="aff" rid="aff2"><sup>2</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Wei</surname><given-names>Huang</given-names></name><xref ref-type="aff" rid="aff3"><sup>3</sup></xref></contrib><contrib contrib-type="author" xlink:type="simple"><name name-style="western"><surname>Junxian</surname><given-names>Li</given-names></name><xref ref-type="aff" rid="aff1"><sup>1</sup></xref></contrib></contrib-group><aff id="aff1"><addr-line>Beijing Institute of Technology, Zhuhai Campus, Zhuhai, China</addr-line></aff><aff id="aff2"><addr-line>Computer Center, Chang’an University, Xi’an, China</addr-line></aff><aff id="aff3"><addr-line>Research Institute of Electronics, Xi’an, China</addr-line></aff><author-notes><corresp id="cor1">* E-mail:<email>xiangaohuang@yahoo.com.cn(IH)</email>;</corresp></author-notes><pub-date pub-type="epub"><day>17</day><month>04</month><year>2013</year></pub-date><volume>04</volume><issue>02</issue><fpage>165</fpage><lpage>168</lpage><history><date date-type="received"><day>January</day>	<month>24,</month>	<year>2013</year></date><date date-type="rev-recd"><day>February</day>	<month>24,</month>	<year>2013</year>	</date><date date-type="accepted"><day>March</day>	<month>4,</month>	<year>2013</year></date></history><permissions><copyright-statement>&#169; Copyright  2014 by authors and Scientific Research Publishing Inc. </copyright-statement><copyright-year>2014</copyright-year><license><license-p>This work is licensed under the Creative Commons Attribution International License (CC BY). http://creativecommons.org/licenses/by/4.0/</license-p></license></permissions><abstract><p>
 
 
   The nonlinear filter Boolean function of LILI-128 stream cipher generator is studied in this paper. First we measure the complexity of the stream ciphers sequence of LILI-128 stream cipher generator and obtain the shortest bit stream sequence reconstructed Boolean function of nonlinear filter in LILI-128 stream cipher generator. Then the least nonlinear Boolean function of generating stream cipher sequence is reconstructed by clusterig, nonlinear predictive and nonlinear synchronization from shortest bit stream sequence. We have verified the correctness of our reconstruction result by simulating the block diagram of Lili-128 keystream generator using our getting Boolean function and implement designers’ reference module of Lili-128 stream cipher public online, and two methods produce the same synchronous keystream sequence under same initial state, so that our research work proves that the nonlinear Boolean function of LILI-128 stream cipher generator is successfully broken.
    <!--?xml:namespace prefix = o /-->
     
 
</p></abstract><kwd-group><kwd>LILI-128 Stream Cipher; Clock Control; Boolean Function; Complexity; Attack</kwd></kwd-group></article-meta></front><body><sec id="s1"><title>1. Introduction</title><p>Our society greatly depends on security of communications, financial transactions, telematic services, internet and mobile networks [<xref ref-type="bibr" rid="scirp.29860-ref1">1</xref>] which in turn present new challenges for protecting the information from unauthorized eavesdropping. Cryptography mainly uses two types of symmetric algorithms, block ciphers and stream ciphers. The block ciphers have become widely used technology. As an example AES is a secure block cipher that offers excellent performance on a variety of hardware and software environments. On the other hand, the stream ciphers are widely used in secure communication because of high throughput, less complex hardware circuitry and very little error propagation which has attracted much attention. An important class of stream ciphers is based on a mixture of linear feedback shift register (LFSR), nonlinear filter generators and also clock-controlled generators [2,3]. LILI-128 stream cipher is an example which is designed by Dawson, Clark, Golic, Millan, Penna and Simpson, which submitted to NESSIE (New European Schemes for Signatures, Integrity and Encryption) as a candidate cipher [<xref ref-type="bibr" rid="scirp.29860-ref3">3</xref>]. According to the final report, LILI- 128 stream cipher was rejected in the first round of NESSIE. In this work we will discuss basic structure and the attack of LILI-128 stream cipher. We particularly study the filter Boolean function of LILI-128 stream cipher generator.</p></sec><sec id="s2"><title>2. The Structure of LILI-128</title><p>The structure of the LILI-128 keystream generators is illustrated in <xref ref-type="fig" rid="fig1">Figure 1</xref>. It uses two binary LFSR<sub>c</sub> and LFSR<sub>d</sub> and two functions f<sub>c</sub> and f<sub>d</sub> to generate a pseudorandom binary keystream sequence. At initialization, 128 bit key provides the initial states of the LFSR<sub>c</sub> and LFSR<sub>d</sub>.</p><p>The generator can be divided into two subsystems based on the functions they perform: the clock control subsystem and data generation subsystem. The clock control subsystem produces an integer sequence that is used to control data generation subsystem. The feedback polynomial of the LFSR<sub>c</sub> is chosen to be the primitive polynomial</p><disp-formula id="scirp.29860-formula115696"><label>(1)</label><graphic position="anchor" xlink:href="5-7600234\ad0621c8-5339-49f8-a983-13e5d11fc2b6.jpg"  xlink:type="simple"/></disp-formula><p>Since <img src="5-7600234\65121ae7-a09a-4cd3-9d32-612486ea979b.jpg" /> is primitive, the LFSR<sub>c</sub> produce a maximum-length sequence of period<img src="5-7600234\891a8e21-373e-4663-93e7-03a7e02ed9dd.jpg" />. The function f<sub>c</sub> takes two bits as input and produced an integer c<sub>k</sub> such that<img src="5-7600234\3e4c3bef-a092-44c2-8fb2-52ac67c0b382.jpg" />. The value of c<sub>k</sub> is calculated as</p><disp-formula id="scirp.29860-formula115697"><label>(2)</label><graphic position="anchor" xlink:href="5-7600234\4cf6ecda-5168-4e05-9709-21a963739522.jpg"  xlink:type="simple"/></disp-formula><p>The LFSR<sub>d</sub> is clocked by c<sub>k</sub> at least once and at most four times, which is given as fllows:</p><disp-formula id="scirp.29860-formula115698"><label>(3)</label><graphic position="anchor" xlink:href="5-7600234\4a4f4c02-4c9f-4f1c-80dd-a77c467be3cd.jpg"  xlink:type="simple"/></disp-formula><p>since <img src="5-7600234\a8167489-2272-4701-aa53-01e75a960a21.jpg" /> is a primitive polynomial, a period of <img src="5-7600234\d8a20430-8a29-4b76-88f5-0c900f39f8e9.jpg" /> at maximum is guaranteed for LFSR<sub>d</sub> output sequence. The contents of 10 different stages of LFSR<sub>d</sub> are input to a nonlinear filter function f<sub>d</sub>. The output z<sub>k</sub> of nonlinear filter function f<sub>d</sub> is the keystream sequence.</p></sec><sec id="s3"><title>3. Security Analysis</title><p>LILI-128 stream cipher are a long period around 2<sup>128</sup>, high linear complexity which is conjectured to be at least 2<sup>68</sup>, and good statistics regarding the distribution of zeroes and ones, so designers claim that the LILI-128 keystream generator can resist currently known styles of attack. Some methods [4-7] of breaking it have been proposed, since LILI-128 stream cipher was publicized in 2000. The methods have already been shown that some attack break the LILI-128 stream cipher more efficiently than an exhaustive search for its secret key. However, most of the attack methods consider only the complexity of time or memory for search for its secret key. For example, Time-Memory Tradeoff Attack [<xref ref-type="bibr" rid="scirp.29860-ref4">4</xref>] needs approximately 2<sup>46</sup> bits, and Correlation Attack [<xref ref-type="bibr" rid="scirp.29860-ref5">5</xref>] needs approximately about 2<sup>23</sup> bits. While algebraic Attack [<xref ref-type="bibr" rid="scirp.29860-ref6">6</xref>] needs approximately 2<sup>18</sup> bits. Even a new attack method [<xref ref-type="bibr" rid="scirp.29860-ref7">7</xref>] requires a mere 2<sup>7</sup> bits of keystream, but needs 2<sup>99</sup> − 1 computations. The above styles of attack are only quailtative analysis, without an actual example of the successful attack. In 2005, designers summarize recently published styles of attack on the LILI-128 stream cipher, and assert that LILI-128 remains unbroken [<xref ref-type="bibr" rid="scirp.29860-ref8">8</xref>]. They encourage further analysis of the LILI-128 stream cipher.</p></sec><sec id="s4"><title>4. The Expression of the Nonlinear Filter Function f<sub>d</sub></title><p>In <xref ref-type="fig" rid="fig1">Figure 1</xref>, designers do not publicize the expression of the nonlinear filter function f<sub>d</sub>. Up to now, all attacks explain only that LILI-128 has lower complexity as designers claim, and do not get the expression of the nonlinear filter function f<sub>d</sub>. The aim which we attack LILI- 128 is the expression of the nonlinear filter function f<sub>d</sub>. The reference module of LILI-128 is got from the Information Security Institute’s webpage: http://www.isi.qut.</p><p>edu.au/resources/lili/. We implement the reference module on ASCII initial value “yyyy yyyyyyyyyyy y” and get the keystream sequence of LILI-128, and study the expression of the nonlinear filter function f<sub>d</sub>. First, we determine the least keystream bit amount of expressing the nonlinear filter function f<sub>d</sub> from the LILI-128 kystream sequence by means of measuring the complexity of the LILI-128 kystream sequence. The least keystream bit amount of expressing the nonlinear filter function f<sub>d</sub> is not equal for differ initial state. The least keystream bit amount is approximately 2<sup>12</sup> - 2<sup>13</sup> bits. We reconstruct the expression f<sub>d</sub> from Shortest bit stream sequence by clusterig, nonlinear predictive and nonlinear synchronization, which has 46 items from liner items to nonlinear polynomials with 6 orders as follows:</p><disp-formula id="scirp.29860-formula115699"><label>(4)</label><graphic position="anchor" xlink:href="5-7600234\1f6ed0b5-84a3-4506-9763-ae0190479574.jpg"  xlink:type="simple"/></disp-formula></sec><sec id="s5"><title>5. Verifying the Correctness for the Filter Boolean Function f<sub>d</sub></title><p>If we describe LILI-128 keystream generator by MATLAB, the stages of LFSR<sub>c</sub> be labeled s[<xref ref-type="bibr" rid="scirp.29860-ref1">1</xref>], s[<xref ref-type="bibr" rid="scirp.29860-ref2">2</xref>],∙∙∙, s[<xref ref-type="bibr" rid="scirp.29860-ref39">39</xref>] from left to right. At every time, we have the following formula to calculate the feedback bit:</p><disp-formula id="scirp.29860-formula115700"><label>(5)</label><graphic position="anchor" xlink:href="5-7600234\559035df-4b7b-4921-af4c-fbb54cebfe9f.jpg"  xlink:type="simple"/></disp-formula><p>where <img src="5-7600234\045d662c-b49c-4ca8-aad4-1f3b46aa3d2d.jpg" /> indicates the addition modulo 2. Let the LFSR<sub>c</sub> shift left, and s[<xref ref-type="bibr" rid="scirp.29860-ref38">38</xref>] = w. Sequentially circulating, the LFSR<sub>c</sub> will produce a linear pseudorandom sequence. The function f<sub>c</sub> is given by</p><disp-formula id="scirp.29860-formula115701"><label>(6)</label><graphic position="anchor" xlink:href="5-7600234\e5c624ac-f7f6-42c0-977c-43179a087fb1.jpg"  xlink:type="simple"/></disp-formula><p>The stages of LFSR<sub>d</sub> be labeled u[<xref ref-type="bibr" rid="scirp.29860-ref1">1</xref>], u[<xref ref-type="bibr" rid="scirp.29860-ref2">2</xref>], ∙∙∙, u[<xref ref-type="bibr" rid="scirp.29860-ref89">89</xref>] from left to right. At time k, the feedback bit is calculated by the following formula</p><disp-formula id="scirp.29860-formula115702"><label>(7)</label><graphic position="anchor" xlink:href="5-7600234\55fa0c12-6b9f-4a83-8157-e40898fccc14.jpg"  xlink:type="simple"/></disp-formula><p>where <img src="5-7600234\0a7bb2fd-e30b-4553-9ab5-52847b7bd362.jpg" /> indicates the addition modulo 2. Let the LFSR<sub>d</sub> shift left, and u[<xref ref-type="bibr" rid="scirp.29860-ref89">89</xref>] = w. According to above circulation, the LFSR<sub>d</sub> will produce a linear pseudorandom sequence. We map the set: (1, 2, 3, 4, 5, 6, 7, 8, 9, 10) into the set: (1, 2, 4, 8, 13, 21, 31, 45, 66, 81), the f<sub>d</sub> is given by:</p><disp-formula id="scirp.29860-formula115703"><label>(8)</label><graphic position="anchor" xlink:href="5-7600234\8692fa7d-d563-47ba-b3b9-67cd0e4f7f36.jpg"  xlink:type="simple"/></disp-formula><p>We simulate the keystream sequence of LILI-128 in <xref ref-type="fig" rid="fig1">Figure 1</xref> using (6) by 128 bits initial values which are ASCII “yyyyyyyyyyyyyyyy”. Compare simulating result with the result of implementing the reference module, and two methods produce the same synchronous keystream sequence under same initial state “yyyyyyyyyyyyyyyy”. We verify the nonlinear filter function f<sub>d</sub> again by initial state “ggggggggggggggg” and “123456789abcdefg”, and obtain all the same synchronous keystream sequence, so that the validation work indicates we have successfully broken the nonlinear filter Boolean function of LILI-128 stream cipher generator.</p></sec><sec id="s6"><title>6. Conclusion</title><p>In the design of LILI-128, Designers made an attempt to confuse the linear pseudorandom binary sequence with the long period P<sub>c</sub> = 2<sup>89</sup> – 1 by the clock-control with the long period P<sub>c</sub> = 2<sup>39</sup> – 1 and get high linear complexity of keystream sequence. The nonlinear sequence is generated through the nonlinear filter function f<sub>d</sub> with 46 items and the most algebraic 6 orders to withstand all kinds of currently known attack. The LILI-128 keystream generator certainly resists currently known styles of attack, but it does not withstand our attack. The currently known styles of attack based on time complexity and memory complexity of arithmetic. The attacks do not consider the complexity of keystream sequence oneself. We get the least bit amount of the attack by measuring the complexity of the keystream sequence of LILI-128 and the nonlinear filter function f<sub>d</sub> from the least keystream bit amount by the phase space reconstruction, Clustering, nonlinear prediction and nonlinear synchronization. In this paper, our research work has made a great breakthrough in stream cipher analysis, breaks the dream that stream cipher of LILI-128 is not attacked, and will bring the importance influence on stream cipher design. We only publish our research result and do not expatiate the specific theory and algorithm of attacking LILI-128 stream cipher because our attack method has important application in attacking military stream cipher. Reader verifies above f<sub>d</sub> first of all. And then f<sub>d</sub> is redesigned. The stream cipher sequence of LILI-128 output is obtained by simulating <xref ref-type="fig" rid="fig1">Figure 1</xref> given an ASCII initial state. Reader sends the ASCII initial state and the stream cipher sequence whose length is 2<sup>13</sup> bits to us. We will return f<sub>d</sub> to him. The Boolean function f<sub>d</sub> of nonlinear filter is got from known stream ciphers sequence, which belongs to research areas of blind signal processing.</p></sec><sec id="s7"><title>REFERENCES</title></sec></body><back><ref-list><title>References</title><ref id="scirp.29860-ref1"><label>1</label><mixed-citation publication-type="other" xlink:type="simple">B. Schneier, “Applied Cryptography,” 2nd Edition, John Wiley and Sons, Hoboken, 1996.</mixed-citation></ref><ref id="scirp.29860-ref2"><label>2</label><mixed-citation publication-type="other" xlink:type="simple">R. E. Atani, et al., “Alamout: A New Synchronous Stream Cipher with Authentication,” IEEE Proceedings of the 1st International Conference on Wireless Communication, Vehicular Technology, Information Theory and Aerospace &amp; Electronic Systems Technology, 17-20 May 2009, pp. 4244-4067.</mixed-citation></ref><ref id="scirp.29860-ref3"><label>3</label><mixed-citation publication-type="other" xlink:type="simple">E. Dawson, A. Clark, J. Golic, W. Millan, L. Penna and L. Simpson, “The LILI-128 Keystream Generator,” NESSIE Proceedings of the Fist Open NESSIE Workshop, Leuven, November 2000. Http://www. cryponessie.org.</mixed-citation></ref><ref id="scirp.29860-ref4"><label>4</label><mixed-citation publication-type="other" xlink:type="simple">M. J. O. Saarinen, “A Time-Memory Trade of Attack against LILI-128,” In: Fast Software Encryption (Lecture Notes in Computer Science), Springer-Verlag, Berlin, 2002, pp. 231-236. doi:10.1007/3-540-45661-9_18</mixed-citation></ref><ref id="scirp.29860-ref5"><label>5</label><mixed-citation publication-type="other" xlink:type="simple">H. Molland and T. Helleseth, “An Improve Correlation Attack against Irregular Clocked and Filtered Keystream Generators,” In: Advance in Cryptology-Crypto 2004 (Lecture Notes in Computer Science), Springer-Verlag, Berlin, 2004, pp. 373-389.  
doi:10.1007/978-3-540-28628-8_23</mixed-citation></ref><ref id="scirp.29860-ref6"><label>6</label><mixed-citation publication-type="other" xlink:type="simple">N. T. Courtois, “Fast Algebraic Attack on Stream Ciphers with Linear Feedback,” In: Advance in Cryptology-Crypto 2003 (Lecture Notes in Computer Science), Springer-Verlag, Berlin, 2003, pp. 176-194.</mixed-citation></ref><ref id="scirp.29860-ref7"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Y. Tsunoo, T. Saito, M. Shigeri, H. Kubo and K. Minematsu, “Shorter Bit Sequence Is Enough to Break Stream Cipher LILI-128,” IEEE Transactions on Information Theory, Vol. 51, 2005, pp. 4312-4319.  
doi:10.1109/TIT.2005.859285</mixed-citation></ref><ref id="scirp.29860-ref8"><label>8</label><mixed-citation publication-type="other" xlink:type="simple">W. Millan and E. Dawson, “LILI-II Is Not Broken,” 2005. 
http//eprint.iacr.org/complete/2005/234</mixed-citation></ref></ref-list></back></article>