There is an elaborate discussion on the breaking of TLCG on the link below, where they show how to break the generator with known parameters given the most significant bits. Problem with LLL reduction on truncated LCG schemes
I tried to apply the same principles when given the least significant bits but with no success. On the paper by Frieze et al they discuss it briefly and mention substituting *x = 2s0*x(1) + x(2)* that helps a little bit but I cant figure out what the value of s0 is supposed to be. Is the anyone who can help.?