Cryptanalysis of Salsa and ChaCha: Revisited

Cryptanalysis of Salsa and ChaCha: Revisited
复制标题

DOI:
10.1007/978-3-319-90775-8_26
复制
发表时间:
2017-12
期刊:
--
影响因子:
--
通讯作者:
K. K. Deepthi-K.;K. Singh
K. K. Deepthi-K.;K. Singh
中科院分区:
其他
文献类型:
--
作者:
K. K. Deepthi-K.;K. Singh

文献摘要

被引文献

相似文献

流密码是一种基本的密码原语,它为通过不安全信道的通信提供保密性。欧盟ECRYPT网络组织了一个项目,用于识别适合广泛采用的新流,其中密码可以提供更高的安全级别。最后,该项目的结果确定了新的流密码,称为eSTREAM。Salsa 20是建立在伪随机函数上的eSTREAM密码之一。在本文中,我们的贡献是两个阶段。第一阶段有两个部分。在WCC 2015中,Maitra等人[9]通过反转一轮Salsa 20来解释有效状态的特征。在第一部分中,我们通过反转一轮Salsa 20重新回顾了Maitra等人[9]对有效态的刻画。我们发现在第一轮中一个比特的改变会导致有效的初始状态。在第二部分中,Maitra等人。[9]提到,描述所有这些状态将是一个有趣的组合问题。我们已经描述了导致有效初始状态的另外九个值。在第二阶段,FSE 2008 Aumasson等人[1]攻击了Salsa 20/7 within time和ChaCha 6 within time的128位密钥。在此之后,据我们所知,这种攻击没有任何改进。本文对Salsa 20/7和ChaCha 6的128位密钥进行了时间内攻击。Maitra [8]改进了Salsa 20/8和ChaCha 7的攻击,通过选择与256密钥位相对应的适当IV。应用相同的概念,我们已经在时间内攻击了Salsa 20/7和ChaCha 7的128个密钥位。
Stream cipher is one of the basic cryptographic primitives that provide the confidentiality of communication through insecure channel. EU ECRYPT network has organized a project for identifying new stream suitable for widespread adoption where the ciphers can provide a more security levels. Finally the result of the project has identified new stream ciphers referred as eSTREAM. Salsa20 is one of the eSTREAM cipher built on a pseudorandom function. In this paper our contribution is two phases. First phase have two parts. In WCC 2015, Maitra et al. [9] explained characterization of valid states by reversing one round of Salsa20. In first part, we have revisited the Maitra et al. [9] characterization of valid states by reversing one round of Salsa20. We found there is a mistake in one bit change inandword in first round will result in valid initial state. In second part, Maitra et al. [9] as mentioned that it would be an interesting combinatorial problem to characterize all such states. We have characterized nine more values which lead to valid initial states. The combinations,,,,,,,andwhich characterized as valid states.In second phase, FSE 2008 Aumasson et al. [1] attacked 128-key bit of Salsa20/7 withintime and ChaCha6 in withintime. After this with best of our knowledge there does not exist any improvement on this attack. In this paper we have attacked 128-key bit of Salsa20/7 withintime and ChaCha6 withintime. Maitra [8] improved the attack on Salsa20/8 and ChaCha7 by choosing proper IVs corresponding to the 256-key bit. Applying the same concept we have attacked 128-key bit of Salsa20/7 within timeand ChaCha7 within time.