Latin dances revisited: new analytic results of Salsa20 and ChaCha

  • Authors:
  • Tsukasa Ishiguro;Shinsaku Kiyomoto;Yutaka Miyake

  • Affiliations:
  • KDDI R&D Laboratories Inc., Fujimino, Saitama, Japan;KDDI R&D Laboratories Inc., Fujimino, Saitama, Japan;KDDI R&D Laboratories Inc., Fujimino, Saitama, Japan

  • Venue:
  • ICICS'11 Proceedings of the 13th international conference on Information and communications security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we propose new attacks on 9-round Salsa20 and 8-round ChaCha. We constructed a distinguisher of double-bit differentials to improve Aumasson's single-bit differential cryptanalysis. We searched for correlations using a PC, and found strong correlations in 9-round Salsa20 and 8-round ChaCha. The complexities of the introduced attacks are 216 in 9-round Salsa20 and 2 in 8-round ChaCha, which are much less than the complexities of an exhaustive key search and existing attacks on those ciphers. The results show that an adversary can distinguish keystream bits from random bits using a few input and output pairs of an initial keys and initial vectors. This method has potential to apply to a wide range of stream ciphers; a double-bit correlation would be found in case that no single-bit correlation is found.