The nonlinear filter model is an old and well understood approach to the design of secure stream ciphers. Extensive research over several decades has shown how to attack stream ciphers based on this model and has identified the required security properties of the Boolean function used as the filtering function to resist such attacks. This led to the problem of constructing Boolean functions which provide adequate security \textit{and} at the same time are efficient to implement. Unfortunately, over the last two decades no fully satisfactory solutions to this problem appeared in the literature. The lack of good solutions has effectively led to the nonlinear filter model becoming more or less obsolete. This is a big loss to the cryptographic design toolkit, since the great advantages of the nonlinear filter model are its simplicity, well understood security and the potential to provide low cost solutions for hardware oriented stream ciphers. In this paper, we revive the nonlinear filter model by constructing appropriate Boolean functions which provide required security and are also efficient to implement. We put forward concrete suggestions of stream ciphers which are $κ$-bit secure against known types of attacks for $κ=80$, 128, 160, 192, 224 and 256. For the 80-bit and the 128-bit security levels, the gate count estimates of our proposals compare quite well to the famous ciphers Trivium and Grain-128a respectively, while for the 256-bit security level, we do not know of any other stream cipher design which has such a low gate count.
翻译:非线性滤波模型是一种古老且广为人知的流密码安全设计方法。数十年的深入研究表明了如何攻击基于该模型的流密码,并确定了作为滤波函数的布尔函数所需具备的安全属性以抵御此类攻击。这引出了构建既能提供足够安全性又能高效实现的布尔函数的问题。遗憾的是,过去二十年间,文献中并未出现完全令人满意的解决方案。缺乏良好解决方案实质上导致非线性滤波模型逐渐过时。这成为密码设计工具箱的重大损失,因为非线性滤波模型的显著优势在于其简洁性、安全性分析的成熟性,以及为面向硬件的流密码提供低成本解决方案的潜力。本文通过构造兼具所需安全性与高效实现特性的布尔函数,使非线性滤波模型得以复兴。我们提出了具体的流密码设计方案,这些方案针对κ=80、128、160、192、224和256位安全级别,能够抵御已知类型的攻击。在80位和128位安全级别上,我们提出的门电路数量估算分别与著名密码Trivium和Grain-128a相当;而在256位安全级别上,据我们所知,尚未有其他流密码设计能达到如此低的门电路数量。