Advancing the Idea of Probabilistic Neutral Bits: First Key Recovery Attack on 7.5 Round ChaCha

Sabyasachi Dey · IEEE Transactions on Information Theory · 2024

The existing differential-linear attacks against ChaCha are based on the idea of probabilistic neutral bits (PNB), which are the key bits with less influence on the distinguisher. This paper presents a novel approach, which is based on bringing about some transformation in the PNB-based attack procedure that significantly improves upon existing attacks. Unlike previous methods that focused on finding PNBs for the entire linear combination of multiple bits of output difference, we separately identify PNBs for each output difference bit that constitutes the linear combination. This divide-and-conquer approach helps to reduce the number of operations to observe the PNB-based differential-linear correlation, providing significant gain in the attack complexity. Specifically, we present an attack on 7-round ChaCha256 that is 213.91 times faster than the existing best attack. We are able to produce the first-ever attack on the 7.5-round ChaCha256. Apart from these, this idea also provides significant improvement on 7.25-round ChaCha256, as well as the 6-round and 6.5 round versions of ChaCha128.

Read the paper · More papers on PaperTik