Abstract:
We describe an algorithm extending the previously proposed method of key recovery of a filter generator. The algorithm is based on an approximation of the combining function by algebraically degenerate functions. We give estimates of the computational complexity, reliability, and the amount of memory used by the method. Examples of application of the method are considered, in particular, for the analysis of the LILI-128 cipher.