Differential-linear cryptanalysis against ChaCha based on automated tools
Abstract ChaCha is a widely deployed ARX stream cipher used in modern secure-communication protocols. Reduced-round cryptanalysis assesses its security margin and tests automated methods without implying a threat to the full 20-round cipher. We combine MILP search, GPU correlation estimation, and MIQCP-based prediction. MILP finds 128 one-round differential characteristics and enumerates 61 paths whose differential weights are at most 14. GPU measurements resolve 39 paths, whose signed weighted sum is $$2^{-31.16}$$ 2 - 31.16 . Following the widely used practical strategy of truncated enumeration of dominant paths, this value gives 7- and 7.5-round distinguisher data complexities of $$2^{160.20}$$ 2 160.20 and $$2^{245.00}$$ 2 245.00 . Applying the same four-round estimate to ReBitP gives data/time complexities of $$2^{125.91}/2^{140.00}$$ 2 125.91 / 2 140.00 and $$2^{122.96}/2^{241.31}$$ 2 122.96 / 2 241.31 . The MIQCP comparison quantifies substantial gaps between predicted and measured correlation weights and identifies concrete directions for refining ChaCha correlation models. Together, these results provide a reproducible path-cluster analysis, lower data and time complexity estimates for 7- and 7.5-round ChaCha, and experimentally grounded directions for automated correlation estimation.
Authors
- 任桂燕
- Shuai Liu (ORCID: https://orcid.org/0000-0002-0699-2296)
- Bo Yu (ORCID: https://orcid.org/0000-0001-6576-5555)
- Bing Sun
- Chao Li
Publication Details
- Journal
- Cybersecurity
- Published
- 2026-10-09
- DOI
- https://doi.org/10.1186/s42400-026-00671-7
- Primary Topic
- Cryptographic Implementations and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00