MILP-aided Cryptanalysis of Round Reduced ChaCha

Najwa Aaraj and Florian Caullery and Marc Manzano

Abstract: The inclusion of ChaCha20 and Poly1305 into the list of supported ciphers in TLS 1.3 necessitates a security evaluation of those ciphers with all the state-of-the-art tools and innovative cryptanalysis methodologies. Mixed Integer Linear Programming (MILP) has been successfully applied to find more accurate characteristics of several ciphers such as SIMON and SPECK. In our research, we use MILP-aided cryptanalysis to search for differential characteristics, linear approximations and integral properties of ChaCha. We are able to find differential trails up to 2 rounds and linear trails up to 1 round. However, no integral distinguisher has been found, even for 1 round.

Category / Keywords: secret-key cryptography / cryptanalysis, stream ciphers, ARX

Original Publication (in the same form): NISK 2017

Date: received 29 Nov 2017

Contact author: manzanomarc at gmail com

Version: 20171130:234018 (All versions of this report)

