简介:AlinearizationattackontheKeyStreamGenerator(KSG)ofthemodifiedE0algorithmproposedbyHermelin[ProceedingsofICISC'99,SpringerLNCS1787,2000,17-29]isgiveninthispaper.TheinitialvaluecanberecoveredbyalinearizationattackwithO(260.52)operationsbysolvingaSystemofLinearEquations(SLE)withatmost220.538unknowns.FrederikArmknecht[CryptologyePrintArchive,2002/191]proposedalinearizationattackontheKSGofE0algorithmwith0(270.341)operationsbysolvinganSLEwithatmost224.056unknowns,sothemodificationproposedbyHermelinreducestheabilityofE0toresistthelinearizationattackbycomparingwiththeresultsofFrederikAnnknecht.