Abstract :
A number of keystream generators can be attacked by guessing the contents of one shift register and then checking to see whether this guess is consistent with the observed keystream. Where the target register is n bits long, this gives an attack of complexity 2n-0(1). A further optimisation is presented which appears to reduce the complexity to about 2n2/ in many cases of practical interest.