Authors: Markku-Juhani Olavi Saarinen


In this note we discuss a novel but simple time-memory tradeoff attack
against the stream cipher LILI-128. The attack defeats
the security advantage of having an irregular stepping function.
The attack requires 2^{46} bits of keystream, a lookup table of
2^{45} 89-bit words and computational effort which is roughly
equivalent to 2^{48} DES operations.

ePrint: https://eprint.iacr.org/2001/077

