2607004783
  • Open Access
  • Article

The Related Key Boomerang Attack on ChaCha Permutation Function

  • Nasratullah Ghafoori 1,   
  • Atsuko Miyaji 2,*

Received: 30 Apr 2026 | Revised: 29 Jul 2026 | Accepted: 31 Jul 2026 | Published: 07 Sep 2026

Abstract

The ChaCha stream cipher is widely employed in both hardware and software implementations. Although its security has been extensively studied through differential and differential-linear cryptanalysis, its vulnerability to variants of differential cryptanalysis remains largely unaddressed. This paper investigates the related-key boomerang attack on the ChaCha permutation function. The boomerang attack leverages differential analysis by decomposing the primitive into two sub-components, an approach that proves particularly efficient in cases where identifying high-probability differentials over the entire primitive is infeasible. The related-key boomerang attack incorporates four distinct yet related keys alongside the input differentials to mount the attack. This paper presents a related-key boomerang analysis of the ChaCha 6 and ChaCha 7 permutation functions. Additionally, an attack algorithm targeting reduced-round variants of ChaCha is presented, establishing a correlation among input differences, output differences, and key-bit positions. Consequently, we propose a distinguisher for the ChaCha 6 permutation function with a data complexity of approximately 22.03. Furthermore, we evaluate the ChaCha 7 variant and demonstrate that, for certain attack configurations, it exhibits no detectable bias, thereby establishing a well-defined security boundary for this attack.

References 

  • 1.

    Biham, E.; Shamir, A. Differential Cryptanalysis of DES-like Cryptosystems. J. Cryptol. 1991, 4, 3–72.

  • 2.

    National Bureau of Standards. Federal Information Processing Standards Publication (FIPS PUB) 46; Data Encryption Standard (DES); U.S. Department of Commerce: Washington, DC, USA, 1977.

  • 3.

    Knudsen, L.R. Truncated and Higher Order Differentials. In Proceedings of the Second International Workshop, Leuven, Belgium, 14–16 December 1994; Preneel, B., Ed.; Springer: Berlin, Heidelberg, Germany, 1995; pp. 196–211. https://doi.org/10.1007/3-540-60590-8_16.

  • 4.

    Biham, E.; Biryukov, A.; Shamir, A. Cryptanalysis of Skipjack Reduced to 31 Rounds Using Impossible Differentials. J. Cryptol. 2005, 18, 291–311. https://doi.org/10.1007/s00145-005-0129-3.

  • 5.

    Biham, E. New Types of Cryptanalytic Attacks Using Related Keys. J. Cryptol. 1994, 7, 229–246. https://doi.org/10.1007/BF00203965.

  • 6.

    Wagner, D. The Boomerang Attack. In Proceedings of the 6th International Workshop, FSE'99, Rome, Italy, 24–26 March 1999; Knudsen, L., Ed.; Springer: Berlin, Heidelberg, Germany, 1999; pp. 156–170. https://doi.org/10.1007/3-540-48519-8_12.

  • 7.

    Biham, E.; Dunkelman, O.; Keller, N. Related-Key Boomerang and Rectangle Attacks. In Proceedings of the 24th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Aarhus, Denmark, 22–26 May 2005; Cramer, R., Ed.; Springer: Berlin, Heidelberg, Germany, 2005; pp. 507–525. https://doi.org/10.1007/11426639_30.

  • 8.

    Dunkelman, O.; Keller, N.; Ronen, E.; et al. The Retracing Boomerang Attack. In Proceedings of the 39th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zagreb, Croatia, 10–14 May 2020; Canteaut, A., Ishai, Y., Eds.; Springer: Cham, Switzerland, 2020; pp. 280–309. https://doi.org/10.1007/978-3-030-45721-1_11.

  • 9.

    Kelsey, J.; Kohno, T.; Schneier, B. Amplified Boomerang Attacks against Reduced-Round MARS and Serpent. In Proceedings of the 7th International Workshop, FSE 2000, New York, NY, USA, 10–12 April 2000; Schneier, B., Ed.; Springer: Berlin, Heidelberg, Germany, 2001; pp. 75–93. https://doi.org/10.1007/3-540-44706-7_6.

  • 10.

    Kim, J.; Hong, S.; Preneel, B.; et al. Related-Key Boomerang and Rectangle Attacks: Theory and Experimental Analysis. IEEE Trans. Inf. Theory 2012, 58, 4948–4966. https://doi.org/10.1109/TIT.2012.2191655.

  • 11.

    Jakimoski, G.; Desmedt, Y. Related-Key Differential Cryptanalysis of 192-bit Key AES Variants. In Proceedings of the 10th Annual International Workshop, SAC 2003, Ottawa, Canada, 14–15 August 2003; Matsui, M., Zuccherato, R.J., Eds.; Springer: Berlin, Heidelberg, Germany, 2004; pp. 227–237. https://doi.org/10.1007/978-3-540-24654-1_15.

  • 12.

    Biham, E.; Dunkelman, O.; Keller, N. New Cryptanalytic Results on IDEA. In Proceedings of the 12th International Conference on the Theory and Application of Cryptology and Information Security, Shanghai, China, 3–7 December 2006; Lai, X., Chen, K., Eds.; Springer: Berlin, Heidelberg, Germany, 2006; pp. 412–427. https://doi.org/10.1007/11935230_27.

  • 13.

    Bernstein, D.J. ChaCha, a Variant of Salsa20. In Workshop Record of SASC; Springer: Heidelberg, Germany, 2008; Vol. 8, pp. 3–5.

  • 14.

    Vaudenay, S. Provable Security for Block Ciphers by Decorrelation. In Proceedings of the 15th Annual Symposium on Theoretical Aspects of Computer Science, Paris, France, 25–27 February 1998; Morvan, M., Meinel, C., Krob, D., Eds.; Springer: Berlin, Heidelberg, Germany, 1998; pp. 249–275. https://doi.org/10.1007/BFb0028566.

  • 15.

    Choudhuri, A.R.; Maitra, S. Significantly Improved Multi-bit Differentials for Reduced Round Salsa and ChaCha. IACR Trans. Symmetric Cryptol. 2017, 2016, 261–287. https://doi.org/10.13154/tosc.v2016.i2.261-287.

  • 16.

    Coutinho, M.; Souza Neto, T.C. Improved Linear Approximations to ARX Ciphers and Attacks against ChaCha. In Proceedings of the 40th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zagreb, Croatia, 17–21 October 2021; Canteaut, A., Standaert, F.X., Eds.; Springer: Cham, Switzerland, 2021; pp. 711–740. https://doi.org/10.1007/978-3-030-77870-5_25.

  • 17.

    Aumasson, J.P.; Fischer, S.; Khazaei, S.; et al. New Features of Latin Dances: Analysis of Salsa, ChaCha, and Rumba. In Proceedings of the 15th International Workshop, FSE 2008, Lausanne, Switzerland, 10–13 February 2008; Nyberg, K., Ed.; Springer: Berlin, Heidelberg, Germany, 2008; pp. 470–488. https://doi.org/10.1007/978-3-540-71039-4_30.

  • 18.

    Beierle, C.; Broll, M.; Canale, F.; et al. Improved Differential-Linear Attacks with Applications to ARX Ciphers. J. Cryptol. 2022, 35, 29. https://doi.org/10.1007/s00145-022-09437-z.

  • 19.

    Shi, Z.; Zhang, B.; Feng, D.; et al. Improved Key Recovery Attacks on Reduced-Round Salsa20 and ChaCha. In Proceedings of the 15th International Conference, ICISC 2012, Seoul, Korea, 28–30 November 2012; Kwon, T., Lee, M.K., Kwon, D., Eds.; Springer: Berlin, Heidelberg, Germany, 2013; pp. 369–380. https://doi.org/10.1007/978-3-642-37682-5_24.

  • 20.

    Ghafoori, N.; Miyaji, A. The Amplified Boomerang Attack on ChaCha. In Proceedings of the 8th International Conference, MobiSec 2024, Sapporo, Japan, 17–19 December 2024; Jo, H., Shin, S., Merlo, A., Eds.; Springer: Singapore, 2026; pp. 118–132. https://doi.org/10.1007/978-981-95-0172-4_8.

  • 21.

    Coutinho, M.; Passos, I.; Vásquez, J.C.G.; et al. Latin Dances Reloaded: Improved Cryptanalysis Against Salsa and ChaCha, and the Proposal of Forró. J. Cryptol. 2023, 36, 18. https://doi.org/10.1007/s00145-023-09455-5.

  • 22.

    Dey, C.; Sarkar, S. A New Distinguishing Attack on Reduced Round ChaCha Permutation. Sci. Rep. 2023, 13, 13958. https://doi.org/10.1038/s41598-023-39849-1.

  • 23.

    Bellini, E.; Gerault, D.; Grados, J.; et al. Boosting Differential-Linear Cryptanalysis of ChaCha7 with MILP. IACR Trans. Symmetric Cryptol. 2023, 2023, 189–223. https://doi.org/10.46586/tosc.v2023.i2.189-223.

  • 24.

    Watanabe, R.; Ghafoori, N.; Miyaji, A. Improved Differential-Linear Cryptanalysis of Reduced Rounds of ChaCha. In Proceedings of the 24th International Conference, WISA 2023, Jeju Island, South Korea, 23–25 August 2023; Kim, H., Youn, J., Eds.; Springer: Singapore, 2024; pp. 269–281. https://doi.org/10.1007/978-981-99-8024-6_21.

  • 25.

    Okada, Y.; Watanabe, R.; Ghafoori, N.; et al. Improved Differential-Linear Cryptanalysis of Reduced Rounds of ChaCha Permutation. IEICE Trans. Fundam. Electron. Commun. Comput. Sci. 2025, E108.A, 1175–1195. https://doi.org/10.1587/transfun.2024DMP0008.

  • 26.

    Dey, S.; Garai, H.K.; Sarkar, S.; et al. Revamped Differential-Linear Cryptanalysis on Reduced Round ChaCha. In Proceedings of the 41st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Trondheim, Norway, 30 May–3 June 2022; Dunkelman, O., Dziembowski, S., Eds.; Springer: Cham, Switzerland, 2022; pp. 86–114. https://doi.org/10.1007/978-3-031-07082-2_4.

  • 27.

    Miyashita, S.; Ito, R.; Miyaji, A. PNB-Focused Differential Cryptanalysis of ChaCha Stream Cipher. In Proceedings of the 27th Australasian Conference, ACISP 2022, Wollongong, NSW, Australia, 28–30 November 2022; Nguyen, K., Yang, G., Guo, F., et al., Eds.; Springer: Cham, Switzerland, 2022; pp. 46–66. https://doi.org/10.1007/978-3-031-22301-3_3.

  • 28.

    Wang, S.; Liu, M.; Hou, S.; et al. Moving a Step of ChaCha in Syncopated Rhythm. In Proceedings of the 43rd Annual International Cryptology Conference, CRYPTO 2023, Santa Barbara, CA, USA, 20–24 August 2023; Handschuh, H., Lysyanskaya, A., Eds.; Springer: Cham, Switzerland, 2023; pp. 273–304. https://doi.org/10.1007/978-3-031-38548-3_10.

  • 29.

    Ghafoori, N.; Miyaji, A.; Ito, R.; et al. PNB Based Differential Cryptanalysis of Salsa20 and ChaCha. IEICE Trans. Inf. Syst. 2023, 106, 1407–1422. https://doi.org/10.1587/transinf.2022ICP0015.

  • 30.

    Ghafoori, N.; Miyaji, A. Higher-Order Differential-Linear Cryptanalysis of ChaCha Stream Cipher. IEEE Access 2024, 12, 13386–13399. https://doi.org/10.1109/ACCESS.2024.3356868.

  • 31.

    Ghafoori, N. A Study on Differential Cryptanalysis of Salsa20 and ChaCha Stream Ciphers. Ph.D. Thesis, Osaka University, Suita, Osaka, Japan, 2024. https://doi.org/10.18910/101457.

  • 32.

    Aumasson, J.P. Too Much Crypto. Cryptology ePrint Archive 2019, Paper 2019/1492.

  • 33.

    Isobe, T.; Sasaki, Y.; Chen, J. Related-key Boomerang Attacks on KATAN32/48/64. In Proceedings of the 18th Australasian Conference, ACISP 2013, Brisbane, Australia, 1–3 July 2013; Boyd, C., Simpson, L., Eds.; Springer: Berlin, Heidelberg, Germany, 2013; pp. 268–285.

Share this article:
How to Cite
Ghafoori, N.; Miyaji, A. The Related Key Boomerang Attack on ChaCha Permutation Function . Pragmatic Cybersecurity 2026, 1 (2), 16. https://doi.org/10.53941/pc.2026.100016.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.
Article Metrics
56
Article Views
0
Citations