Differential Cryptanalysis of Salsa20/8
Differential Cryptanalysis of Salsa20/8
复制标题
Salsa20/8 的差分密码分析
DOI:
--
复制
发表时间:
2007
期刊:
影响因子:
--
通讯作者:
Hiroki Nakashima
中科院分区:
文献类型:
--
作者:
Y. Tsunoo;Teruo Saito;Hiroyasu Kubo;Tomoyasu Suzaki;Hiroki Nakashima
This paper presents a cryptanalysis of the Salsa20 stream cipher proposed in 2005. Salsa20 was submitted to eSTREAM, the ECRYPT Stream Cipher Project. The cipher uses bitwise XOR, addition modulo 2, and constant-distance rotation operations on an internal state of 16 32-bit words. It is reported that there is a significant bias in the differential probability for Salsa20’s 4 round internal state. It is further shown that using this bias, it is possible to break the 256-bit secret key 8-round reduced Salsa20 model with a lower computational complexity than an exhaustive key search. The cryptanalysis method exploits characteristics of addition, and succeeds in reducing the computational complexity compared to previous methods.