Paper 2026/1837

Enhanced Differential-Linear Cryptanalysis of ChaCha Based on Bit Puncturing

Xinhai Wang, Information Engineering University, Zhengzhou 450001, China
Lin Ding, Information Engineering University, Zhengzhou 450001, China
Zhengting Li, Information Engineering University, Zhengzhou 450001, China
Honglei Wang, Information Engineering University, Zhengzhou 450001, China
Jiang Wan, Information Engineering University, Zhengzhou 450001, China
Bin Hu, Information Engineering University, Zhengzhou 450001, China
Abstract

ChaCha is one of the most extensively deployed symmetric ciphers. The security margin of ChaCha is directly related to the safety of many widely used lightweight security protocols and operating systems for constrained devices, such as TLS 1.3, SSH, Noise, WireGuard, S/MIME 4.0, Linux, Android, Chromium/Chrome, Firefox and Safari. This paper introduces a novel \textit{guessed key covering technique}. The objective of this technique is to identify partitioning-based functions whose required key bits are covered by those guessed for bit puncturing-based functions, enabling them to be processed jointly. Building on this, we propose a refined framework for differential-linear cryptanalysis of ChaCha called \texttt{ReBitP}, which combines the ideas of the bit puncturing technique, the partitioning technique and a two-phase distillation strategy. The key insight of \texttt{ReBitP} is to incorporate a carefully selected set of functions that are evaluated using the partitioning technique with different tail lengths into the first phase, without requiring additional key bits to be guessed. This early filtering via parity checks simultaneously lowers the time cost of the first phase and the time complexity of constructing the distillation table in the second phase. As applications, enhanced key recovery attacks on 7- and 7.5-round ChaCha256 are presented, achieving time complexities of $2^{142.08}$ and $2^{242.02}$, respectively. The cryptanalytic results are $2^{6.12}$ and $2^{1.58}$ times faster than the existing attacks, respectively. So far as we know, these are the best known key recovery attacks on 7- and 7.5-round ChaCha256. This definitely demonstrates the superiority of the refined framework \texttt{ReBitP}.

Metadata
Available format(s)
PDF
Category
Attacks and cryptanalysis
Publication info
Published elsewhere. Minor revision. IEEE Internet of Things Journal
DOI
10.1109/JIOT.2026.3704689
Keywords
Stream cipherChaChaDifferential-linear attackBit puncturing
Contact author(s)
dinglin_cipher @ 163 com
History
2026-09-01: approved
2026-08-30: received
See all versions
Short URL
https://ia.cr/2026/1837
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1837,
      author = {Xinhai Wang and Lin Ding and Zhengting Li and Honglei Wang and Jiang Wan and Bin Hu},
      title = {Enhanced Differential-Linear Cryptanalysis of {ChaCha} Based on Bit Puncturing},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1837},
      year = {2026},
      doi = {10.1109/JIOT.2026.3704689},
      url = {https://eprint.iacr.org/2026/1837}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.