A TMDTO attack against lizard

Article Type

Research Article

Publication Title

IEEE Transactions on Computers


Lizard is a very recently proposed lightweight stream cipher that claims 60 bit security against distinguishing (related to state recovery) and 80 bit security against key recovery attack. This cipher has 121 bit state size. In this paper, we first note that using c key stream bits one can recover c unknown bits of the state when t state bits are fixed to a specific pattern. This is made possible by guessing the remaining state bits. We present certain values of c; t based on the state size that helps in mounting a generic conditional TMDTO attack following the BSW sampling. For Lizard, we obtain the preprocessing complexity as 267, and the maximum of Data, Time and Memory complexity during the online phase as 254. The parameters in the online phase are significantly less than 260.

First Page


Last Page




Publication Date


This document is currently not available here.