Stream cipher used in Bluetooth protocol for encryption. Combines four LFSRs with nonlinear combining function using majority logic. Has known cryptanalytic vulnerabilities and should not be used for new security applications.
| Property | Value |
|---|---|
| Category | Stream Ciphers |
| Sub-category | Stream Cipher |
| Security status | ❌ Broken |
| Complexity | Advanced |
| Inventor | Bluetooth SIG |
| Year | 1998 |
| Origin | Not specified |
| Source | algorithms/stream/e0.js |
| Parameter | Supported values |
|---|---|
| Key sizes | 1 byte (8 bits) to 16 bytes (128 bits) |
| Nonce sizes | 0 bytes (0 bits) |
Status: ❌ Broken
| Issue | Description | Mitigation |
|---|---|---|
| Correlation Attack | Statistical correlation attacks can recover keystream with practical complexity | Do not use for cryptographic applications - educational purposes only |
| FMS Attack | Fluhrer-Mantin-Shamir style attacks applicable to E0 structure | Algorithm has fundamental structural weaknesses |
| Algebraic Attack | Recent 2022 algebraic attacks using Gröbner bases with complexity 2^79 | Modern attacks demonstrate practical vulnerability |
1 vector ship with this algorithm and run in the test suite. Byte values are hexadecimal.
Vector 1 — E0 Test Vector (Educational)
| Field | Value |
|---|---|
key |
000102030405060708090a0b0c0d0e0f |
input |
00000000000000000000000000000000 |
expected |
f6b37e0393807025e9b6ad61e8ba3953 |