Draco is a lightweight small‐state stream cipher proposed in 2022. It is designed to provide a 128‐bit security level and be provably secure against time‐memory‐data trade‐off (TMDTO) attacks. In this paper, we revisit the security of Draco against TMDTO attacks. Based on a new observation that for certain chosen initialization vectors (IVs) the state update function of Draco depends on only a small fraction of the nonvolatile internal state, a new TMDTO attack on Draco with a time complexity of 2 109.2 Draco iterations, a memory complexity of 2 109.6 bits and a data complexity of 2 64 bits is proposed. The attack is 2 5 times better in the time/memory complexity with the same data complexity compared with the existing TMDTO attack. Furthermore, the security level that Draco can theoretically provide against TMDTO attacks is analyzed. As result, another TMDTO attack on Draco with complexities all below 2 87 is proposed. The cryptanalytic result shows that the Draco stream cipher can only offer an 87‐bit security level against TMDTO attacks if the limitation on keystream length is not considered. Our results indicate that how to design a secure small‐state stream cipher still needs further exploration.
Guan et al. (Thu,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: