Stream cipher Trivium is one of the seven finalists of the eSTREAM project.In this paper,we apply linear cryptanalysis to the simplified Trivium with the initialization of 288 rounds.The equation,which involves the key bits,initial vector bits and the first keystream bit in linear approximations for 288-round Trivium of Turan,is corrected.In addition,when special Key bits and IV bits are allowed to be chosen,the algorithm to search the linear approximations with the biggest linear bias is presented.Based on this algorithm,3 linear approximations with the same linear bias 2-25are found,which is better than Turan's 2-31.
Read full abstract