
Random numbers and stream ciphers 343
however c ryptographically very weak. The shrinking generator [22] uses the
results of two LFSRs, called A and S. The output bits are generated by the
A sequence, and their output is controlled by the S sequence. At each stage
new bits a
k
and s
k
are obtained. If s
k
is one, then a
k
is output as the next
generated bit; if s
k
is z e ro, new bits of the A and S sequences are produced.
Suppo se A is produced by x
4
+ x + 1 and seeded with [0, 0, 1, 1], and S by
x
5
+ x
2
+ 1 seeded with [0, 0, 0, 1, 1]. Then:
S : 0 0 0 1 1 0 1 1 1 0 1 0 1 0 0 0 0 1 0 0
A : 0 0 1 1 0 1 0 1 1 1 1 0 0 0 1 0 0 1 1 0
output: 1 0 0 1 1 1 0 1
The output ...