简介:Thispaperpresentsanewmethodforresynchronizationattack,whichisthecombinationofthedifferentialcryptanalysisandalgebraicattack.Byusingthenewmethodonegetsasystemoflinearequationsorlow-degreeequationsaboutinitialkeys,andthesolutionofthesystemofequationsresultsintherecoveryoftheinitialkeys.Thismethodhasalowercomputationalcomplexityandbetterperformanceofattackincontrasttotheknownmethods.Accordingly,thedesignoftheresynchronizationstreamgeneratorsshouldbereconsideredtomakethemstrongenoughtoavoidourattacks.WhenimplementedtotheToyocrypt,ourmethodgainsthecomputationalcomplexityofO(217),andthatofO(267)forLILI-128.