Paper 2019/1492

Too Much Crypto

Jean-Philippe Aumasson
Abstract

We argue that ChaCha, BLAKE2, SHA-3, and even AES have overly generous security margins: they do more rounds than are needed for their intended security levels, and therefore spend unnecessary computation on symmetric cryptography. This is partly the result of a process failure. Designers initially, and rightly, choose conservative security margins (the gap between the highest round count then reached by cryptanalysis and the round count specified) but these margins are seldom revisited: round counts are not adjusted to reflect the lack of effective cryptanalytic progress, nor are they chosen to make security margins consistent across primitive families. This article reviews cryptanalytic progress over the last 25 years, distinguishing between attacks that improve academic records and attacks that plausibly affect real systems. We revisit the round counts of AES, BLAKE2, ChaCha, and SHA-3, and propose reduced-round variants that are up to 150% faster while retaining a comparable practical security profile. More broadly, our goal is to make round-count selection a more intentional, consistent, and evidence-based engineering decision, rather than an inherited, subjective, conservative constant.

Note: Presented at Real-World Crypto 2020. April 4, 2023: Updated the link to the NCC report. May 24, 2021: Fixed a calculus error (see https://twitter.com/laughinghan/status/1394844992531689476) and adds a few lines to the conclusion. July 6, 2026: Updated wrt new cryptanalysis, improved the text clarity.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
cryptanalysisAESBLAKE2ChaChaSHA-3
Contact author(s)
jeanphilippe aumasson @ gmail com
History
2026-07-07: last of 8 revisions
2019-12-30: received
See all versions
Short URL
https://ia.cr/2019/1492
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2019/1492,
      author = {Jean-Philippe Aumasson},
      title = {Too Much Crypto},
      howpublished = {Cryptology {ePrint} Archive, Paper 2019/1492},
      year = {2019},
      url = {https://eprint.iacr.org/2019/1492}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.