Rotational analysis of ChaCha permutation
From MaRDI portal
Abstract: We show that the underlying permutation of ChaCha20 stream cipher does not behave as a random permutation for up to 17 rounds with respect to rotational cryptanalysis. In particular, we derive a lower and an upper bound for the rotational probability through ChaCha quarter round, we show how to extend the bound to a full round and then to the full permutation. The obtained bounds show that the probability to find what we call a parallel rotational collision is, for example, less than for 17 rounds of ChaCha permutation, while for a random permutation of the same input size, this probability is . We remark that our distinguisher is not an attack to ChaCha20 stream cipher, but rather a theoretical analysis of its internal permutation from the point of view of rotational cryptanalysis.
Recommendations
- Rotational Cryptanalysis of Salsa Core Function
- Rotational cryptanalysis of ARX revisited
- Chosen IV cryptanalysis on reduced round \texttt{ChaCha} and \texttt{Salsa}
- Rotational-linear attack: a new framework of cryptanalysis on ARX ciphers with applications to Chaskey
- Improved analysis for reduced round Salsa and ChaCha
Cites work
- BLAKE2: simpler, smaller, fast as MD5
- Can a differential attack work for an arbitrarily large number of rounds?
- Cryptanalysis of hash functions on the MD4-family.
- scientific article; zbMATH DE number 1774199 (Why is no real title available?)
- Markov Ciphers and Differential Cryptanalysis
- On the Salsa20 Core Function
- Rotational cryptanalysis of ARX revisited
- SPHINCS: practical stateless hash-based signatures
Cited in
(4)
This page was built for publication: Rotational analysis of ChaCha permutation
Report a bug (only for logged in users!)Click here to report a bug for this page (MaRDI item Q6047438)