Spectral analysis of ZUC-256
In this paper we develop a number of generic techniques and algorithms in spectral analysis of large linear approximations for use in cryptanalysis. We apply the developed tools for cryptanalysis of ZUC-256 and give a distinguishing attack with complexity around 2236 . Although the attack is only 220 times faster than exhaustive key search, the result indicates that ZUC-256 does not provide a sour
