modular p and sufficiently many of the most significant bits of three consecutive outputs of the inversive generator
one can disclose the shift b and the initial value if those outputs do not lie in a small set
by the method of using the shortest vector in the lattice to approximate the unknown vector.The result of this paper shows that we should be careful when we use the inversive generator in a cryptosystem.