عنوان مقاله [English]
WG is a new synchronous hardware oriented stream cipher, corresponding to Profile 2 of the ECRYPT call for stream cipher primitives.Its key length is variable between 80 and 128 bits. The WG cipher has been designed to produce key stream with guaranteed randomness properties. In this paper we present a linear approximation based distinguishing attack against a simplified version (without Trace Function) of WG 128. Our attack requires 232 output words of key stream generator to distinguish the output of simplified version of WG 128 from a truly random bit sequence.