Institutional Repository
| improved key recovery attacks on reduced-round salsa20 and chacha | |
| Shi Zhenqing; Zhang Bin; Feng Dengguo; Wu Wenling | |
| 2013 | |
| Conference Name | 15th International Conference on Information Security and Cryptology, ICISC 2012 |
| Source | Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) |
| Pages | 337-351 |
| Conference Date | November 28, 2012 - November 30, 2012 |
| Conference Place | Seoul, Korea, Republic of |
| Indexed Type | EI |
| ISSN | 0302-9743 |
| ISBN | 9783642376818 |
| Department | (1) Institute of Software Chinese Academy of Sciences Beijing 100190 China; (2) Institute of Information Engineering Chinese Academy of Sciences Beijing 100195 China |
| English Abstract | Salsa20 is a stream cipher designed by Bernstein in 2005 and Salsa20/12 has been selected into the final portfolio of the eSTREAM Project. ChaCha is a variant of Salsa20 with faster diffusion for similar performance. The previous best results on Salsa20 and ChaCha proposed by Aumasson et al. exploits the differential properties combined with the probabilistic neutral bits (PNB). In this paper, we extend their approach by considering a new type of distinguishers, named (column and row) chaining distinguishers. Besides, we exhibit new high probability second-order differential trails not covered by the previous methods, generalize the notion of PNB to probabilistic neutral vectors (PNV) and show that the set of PNV is no smaller than that of PNB. Based on these findings, we present improved key recovery attacks on reduced-round Salsa20 and ChaCha. Both time and data complexities of our attacks are smaller than those of the best former results. © 2013 Springer-Verlag.; Salsa20 is a stream cipher designed by Bernstein in 2005 and Salsa20/12 has been selected into the final portfolio of the eSTREAM Project. ChaCha is a variant of Salsa20 with faster diffusion for similar performance. The previous best results on Salsa20 and ChaCha proposed by Aumasson et al. exploits the differential properties combined with the probabilistic neutral bits (PNB). In this paper, we extend their approach by considering a new type of distinguishers, named (column and row) chaining distinguishers. Besides, we exhibit new high probability second-order differential trails not covered by the previous methods, generalize the notion of PNB to probabilistic neutral vectors (PNV) and show that the set of PNV is no smaller than that of PNB. Based on these findings, we present improved key recovery attacks on reduced-round Salsa20 and ChaCha. Both time and data complexities of our attacks are smaller than those of the best former results. © 2013 Springer-Verlag. |
| Keyword | Security Of Data |
| Language | 英语 |
| Content Type | 会议论文 |
| URI | http://ir.iscas.ac.cn/handle/311060/15979 |
| Collection | 中国科学院软件研究所 |
| Recommended Citation GB/T 7714 | Shi Zhenqing,Zhang Bin,Feng Dengguo,et al. improved key recovery attacks on reduced-round salsa20 and chacha[C],2013:337-351. |
| Files in This Item: | There are no files associated with this item. | |||||
Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.
Edit Comment