The Boomerang Attack on ChaCha Stream Cipher Permutation

Nasratullah Ghafoori, Atsuko Miyaji · 2024

The ChaCha stream cipher, deployed in TLS 1.3, plays a significant role in internet security. ChaCha's security has been well-studied against differential and differential-linear attacks. However, its resilience against variations of differential cryptanalysis has remained uncertain over the past decade. For the first time, we study the security of the ChaCha against boomerang cryptanalysis. The boomerang attack is a variation of differential cryptanalysis. It combines two separate differential properties from different parts of a cipher into a new differ-ential for the entire cipher, and it occurs with a probability of$p^{2}q^{2}$, which requires both properties to be satisfied twice. We also show that for some attack positions in ChaCha, the probability could increase to$p^{2}$, which further improves the attack complexity of ChaCha. In addition, we introduce an algorithm for boomerang attacks on the ChaCha. To illustrate the effectiveness of boomerang cryptanalysis, we attack ChaCha 6 and ChaCha 7. We found that a boomerang attack with a total of$2^{4.587}$and$2^{5.99}$adaptively chosen plaintext and ciphertext is needed to distinguish ChaCha 6 and ChaCha 7 from a random permutation, respectively.

Read the paper · More papers on PaperTik