The ChaCha stream cipher is widely employed in both hardware and software implementations. Although its security has been extensively studied through differential and differential-linear cryptanalysis, its vulnerability to variants of differential cryptanalysis remains largely unaddressed. This paper investigates the related-key boomerang attack on the ChaCha permutation function. The boomerang attack leverages differential analysis by decomposing the primitive into two sub-components, an approach that proves particularly efficient in cases where identifying high-probability differentials over the entire primitive is infeasible. The related-key boomerang attack incorporates four distinct yet related keys alongside the input differentials to mount the attack. This paper presents a related-key boomerang analysis of the ChaCha 6 and ChaCha 7 permutation functions. Additionally, an attack algorithm targeting reduced-round variants of ChaCha is presented, establishing a correlation among input differences, output differences, and key-bit positions. Consequently, we propose a distinguisher for the ChaCha 6 permutation function with a data complexity of approximately 22.03. Furthermore, we evaluate the ChaCha 7 variant and demonstrate that, for certain attack configurations, it exhibits no detectable bias, thereby establishing a well-defined security boundary for this attack.



