In this paper we introduce the notion of impossible fault analysis,
and present an impossible fault analysis of RC4, whose complexity
2^21 is smaller than the previously best known attack of Hoch and
Shamir (2^26), along with an even faster fault analysis of RC4,
based on different ideas, with complexity smaller than 2^16.