Notes on the Salsa20 key size
Daniel J. Bernstein · 2005
Some ciphers aim for high security levels; other ciphers don’t. Some ciphers aim for high speed in software; other ciphers don’t. Some ciphers aim for high speed in hardware; other ciphers don’t. Salsa20 simultaneously aims for a high security level, high speed in software, and high speed in hardware. Some cipher designers sacrice security level in an attempt to obtain the highest speed. Specically , some ciphers use an 80-bit key, exposing themselves to 80-bit brute-force searches. More ciphers use a 128-bit key. For comparison, I recommend using 256-bit keys. Theoreticians often propose foolish \mathematical ciphers in which attacks are provably equivalent to integer factorization. A typical cipher of this type has key size, and time, growing as roughly the cube of the number of bits of conjectured security. Better-designed ciphers don’t allow factorization attacks and have time growing much more slowly with conjectured security level; but one still expects a considerable performance gap between 80-bit security and