Paper 2025/2128

Refined Linear Approximations for ARX Ciphers and Their Application to ChaCha

Yurie Okada, The University of Osaka
Atsuki Nagai, KDDI (Japan)
Atsuko Miyaji, The University of Osaka
Abstract

ARX-based ciphers such as Salsa20 and ChaCha achieve high performance using only modular addition, rotation, and XOR. While ARX constructions are widely deployed in practice, linear and differential-linear cryptanalysis often reveal non-negligible biases in their reduced-round variants. Previous work has shown that a 7-round distinguisher on ChaCha is feasible, requiring about \(2^{214}\) operations and relying on a linear approximation with a theoretical bias of \(2^{-53}\). However, such theoretical approximations significantly deviate from experimental observations. In this work, we resolve these discrepancies by introducing new fundamental linear approximations for two consecutive additions over three independent variables. We rigorously derive the exact probabilities of these approximations, demonstrating that the conventional independence assumption leads to systematic errors in bias estimation. Applying our theorem to ChaCha, we refine the probabilities of key approximations used in previous attacks. Our refined estimates closely match experimentally observed biases, reducing the gap between theory and practice. These results provide a more accurate foundation for future differential-linear cryptanalysis of ChaCha and other ARX-based designs.

Note: This preprint has not undergone peer review or any post-submission improvements or corrections. The Version of Record of this contribution is published in the proceedings of INDOCRYPT 2025.

Metadata
Available format(s)
-- withdrawn --
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. INDOCRYPT 2025
Keywords
ARXPiling-up LemmaChaChalinear approximation
Contact author(s)
yurie okada @ cy2sec comm eng osaka-u ac jp
at-nagai @ kddi com
miyaji @ comm eng osaka-u ac jp
History
2025-11-23: withdrawn
2025-11-21: received
See all versions
Short URL
https://ia.cr/2025/2128
License
Creative Commons Attribution
CC BY
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.