Chosen Ciphertext Attack on a New Class of Self-Synchronizing Stream Ciphers

At Indocrypt’2002, Arnault et al. proposed a new class of self-synchronizing stream ciphers combining LFSR and FCSR architectures. It was claimed to be resistant to known attacks. In this paper, we show that such a self-synchronizing stream cipher is extremely vulnerable to chosen ciphertext attack. We can restore the secret keys easily from one chosen ciphertext with little computation. For the parameters given in the original design, it takes less than one second to restore the secret keys on a Pentium 4 processor.