Differential Cryptanalysis of Salsa20/8

Differential Cryptanalysis of Salsa20/8
复制标题

Salsa20/8 的差分密码分析

DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Hiroki Nakashima
Hiroki Nakashima
中科院分区:
--
文献类型:
--
作者:
Y. Tsunoo;Teruo Saito;Hiroyasu Kubo;Tomoyasu Suzaki;Hiroki Nakashima

文献摘要

被引文献

相似文献

本文对2005年提出的Salsa 20流密码进行了分析。Salsa20被提交给eSTREAM,ECRYPT流密码项目。该密码使用逐位XOR、加法模2和恒定距离旋转操作,对16个32位字的内部状态进行操作。据报道,Salsa 20的4轮内部状态的微分概率存在显著的偏差。它进一步表明,使用这种偏见,它是可能的,打破256位的秘密密钥8轮减少Salsa20模型与一个较低的计算复杂度比一个穷举的密钥搜索。密码分析方法利用了加法的特性,与以前的方法相比,成功地降低了计算复杂度。
This paper presents a cryptanalysis of the Salsa20 stream cipher proposed in 2005. Salsa20 was submitted to eSTREAM, the ECRYPT Stream Cipher Project. The cipher uses bitwise XOR, addition modulo 2, and constant-distance rotation operations on an internal state of 16 32-bit words. It is reported that there is a significant bias in the differential probability for Salsa20’s 4 round internal state. It is further shown that using this bias, it is possible to break the 256-bit secret key 8-round reduced Salsa20 model with a lower computational complexity than an exhaustive key search. The cryptanalysis method exploits characteristics of addition, and succeeds in reducing the computational complexity compared to previous methods.