English

Rotational analysis of ChaCha permutation

Combinatorics 2020-09-01 v1 Information Theory math.IT

Abstract

We show that the underlying permutation of ChaCha20 stream cipher does not behave as a random permutation for up to 17 rounds with respect to rotational cryptanalysis. In particular, we derive a lower and an upper bound for the rotational probability through ChaCha quarter round, we show how to extend the bound to a full round and then to the full permutation. The obtained bounds show that the probability to find what we call a parallel rotational collision is, for example, less than 24882^{-488} for 17 rounds of ChaCha permutation, while for a random permutation of the same input size, this probability is 25112^{-511}. We remark that our distinguisher is not an attack to ChaCha20 stream cipher, but rather a theoretical analysis of its internal permutation from the point of view of rotational cryptanalysis.

Cite

@article{arxiv.2008.13406,
  title  = {Rotational analysis of ChaCha permutation},
  author = {Stefano Barbero and Emanuele Bellini and Rusydi Makarim},
  journal= {arXiv preprint arXiv:2008.13406},
  year   = {2020}
}
R2 v1 2026-06-23T18:12:06.909Z