{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T08:11:03Z","timestamp":1785831063008,"version":"3.56.0"},"publisher-location":"Cham","reference-count":19,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031911064","type":"print"},{"value":"9783031911071","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-91107-1_15","type":"book-chapter","created":{"date-parts":[[2025,4,26]],"date-time":"2025-04-26T15:29:12Z","timestamp":1745681352000},"page":"427-457","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Improved Cryptanalysis of\u00a0ChaCha: Beating PNBs with\u00a0Bit Puncturing"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7749-8925","authenticated-orcid":false,"given":"Antonio","family":"Fl\u00f3rez-Guti\u00e9rrez","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6839-4777","authenticated-orcid":false,"given":"Yosuke","family":"Todo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,27]]},"reference":[{"key":"15_CR1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"470","DOI":"10.1007\/978-3-540-71039-4_30","volume-title":"Fast Software Encryption","author":"J-P Aumasson","year":"2008","unstructured":"Aumasson, J.-P., Fischer, S., Khazaei, S., Meier, W., Rechberger, C.: New features of Latin dances: analysis of salsa, ChaCha, and rumba. In: Nyberg, K. (ed.) FSE 2008. LNCS, vol. 5086, pp. 470\u2013488. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-71039-4_30"},{"key":"15_CR2","doi-asserted-by":"publisher","unstructured":"Beierle, C., et al.: Improved differential-linear attacks with applications to ARX ciphers. J. Cryptol. 35(4), 29 (2022). https:\/\/doi.org\/10.1007\/s00145-022-09437-z","DOI":"10.1007\/s00145-022-09437-z"},{"key":"15_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"329","DOI":"10.1007\/978-3-030-56877-1_12","volume-title":"Advances in Cryptology \u2013 CRYPTO 2020","author":"C Beierle","year":"2020","unstructured":"Beierle, C., Leander, G., Todo, Y.: Improved differential-linear attacks with applications to ARX ciphers. In: Micciancio, D., Ristenpart, T. (eds.) CRYPTO 2020. LNCS, vol. 12172, pp. 329\u2013358. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-56877-1_12"},{"key":"15_CR4","doi-asserted-by":"publisher","unstructured":"Bellini, E., G\u00e9rault, D., Grados, J., Makarim, R.H., Peyrin, T.: Boosting differential-linear cryptanalysis of chacha7 with MILP. IACR Trans. Symmetric Cryptol. 2023(2), 189\u2013223 (2023). https:\/\/doi.org\/10.46586\/tosc.v2023.i2.189-223","DOI":"10.46586\/tosc.v2023.i2.189-223"},{"key":"15_CR5","unstructured":"Bernstein, D.J.: ChaCha, a variant of Salsa20 (2008). http:\/\/cr.yp.to\/chacha.html"},{"key":"15_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/978-3-319-13051-4_4","volume-title":"Selected Areas in Cryptography \u2013 SAC 2014","author":"E Biham","year":"2014","unstructured":"Biham, E., Carmeli, Y.: An improvement of linear cryptanalysis with addition operations with applications to FEAL-8X. In: Joux, A., Youssef, A. (eds.) SAC 2014. LNCS, vol. 8781, pp. 59\u201376. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-13051-4_4"},{"key":"15_CR7","doi-asserted-by":"publisher","unstructured":"Choudhuri, A.R., Maitra, S.: Significantly improved multi-bit differentials for reduced round salsa and chacha. IACR Trans. Symmetric Cryptol. 2016(2), 261\u2013287 (2016). https:\/\/doi.org\/10.13154\/tosc.v2016.i2.261-287","DOI":"10.13154\/tosc.v2016.i2.261-287"},{"key":"15_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1007\/978-3-540-76788-6_7","volume-title":"Information Security and Cryptology - ICISC 2007","author":"B Collard","year":"2007","unstructured":"Collard, B., Standaert, F.-X., Quisquater, J.-J.: Improving the time complexity of Matsui\u2019s linear cryptanalysis. In: Nam, K.-H., Rhee, G. (eds.) ICISC 2007. LNCS, vol. 4817, pp. 77\u201388. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-76788-6_7"},{"key":"15_CR9","unstructured":"Coutinho, M., Neto, T.C.S.: New multi-bit differentials to improve attacks against chacha. IACR Cryptol. ePrint Arch. 350 (2020). https:\/\/eprint.iacr.org\/2020\/350"},{"key":"15_CR10","doi-asserted-by":"publisher","unstructured":"Dey, S.: Advancing the idea of probabilistic neutral bits: first key recovery attack on 7.5 round chacha. IEEE Trans. Inf. Theory 70(8), 6091\u20136106 (2024). https:\/\/doi.org\/10.1109\/TIT.2024.3389874","DOI":"10.1109\/TIT.2024.3389874"},{"key":"15_CR11","doi-asserted-by":"publisher","unstructured":"Dey, S., Garai, H.K., Sarkar, S., Sharma, N.K.: Revamped differential-linear cryptanalysis on reduced round chacha. In: Dunkelman, O., Dziembowski, S. (eds.) Advances in Cryptology - EUROCRYPT 2022 - 41st Annual International Conference on the Theory and Applications of Cryptographic Techniques, Trondheim, Norway, 30 May\u20133 June 2022, Proceedings, Part III. Lecture Notes in Computer Science, vol. 13277, pp. 86\u2013114. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-07082-2_4","DOI":"10.1007\/978-3-031-07082-2_4"},{"key":"15_CR12","doi-asserted-by":"publisher","unstructured":"Dey, S., Garai, H.K., Sarkar, S., Sharma, N.K.: Enhanced differential-linear attacks on reduced round chacha. IEEE Trans. Inf. Theory 69(8), 5318\u20135336 (2023). https:\/\/doi.org\/10.1109\/TIT.2023.3269790","DOI":"10.1109\/TIT.2023.3269790"},{"key":"15_CR13","doi-asserted-by":"publisher","unstructured":"Fl\u00f3rez-Guti\u00e9rrez, A., Todo, Y.: Improving linear key recovery attacks using walsh spectrum puncturing. In: Joye, M., Leander, G. (eds.) Advances in Cryptology - EUROCRYPT 2024 - 43rd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Zurich, Switzerland, 26\u201330 May 2024, Proceedings, Part I. Lecture Notes in Computer Science, vol. 14651, pp. 187\u2013216. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-58716-0_7","DOI":"10.1007\/978-3-031-58716-0_7"},{"key":"15_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/3-540-48658-5_3","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201994","author":"SK Langford","year":"1994","unstructured":"Langford, S.K., Hellman, M.E.: Differential-linear cryptanalysis. In: Desmedt, Y.G. (ed.) CRYPTO 1994. LNCS, vol. 839, pp. 17\u201325. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48658-5_3"},{"key":"15_CR15","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1007\/978-3-662-49890-3_14","volume-title":"Advances in Cryptology \u2013 EUROCRYPT 2016","author":"G Leurent","year":"2016","unstructured":"Leurent, G.: Improved differential-linear cryptanalysis of 7-round chaskey with partitioning. In: Fischlin, M., Coron, J.-S. (eds.) EUROCRYPT 2016. LNCS, vol. 9665, pp. 344\u2013371. Springer, Heidelberg (2016). https:\/\/doi.org\/10.1007\/978-3-662-49890-3_14"},{"key":"15_CR16","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-48658-5_1","volume-title":"Advances in Cryptology \u2014 CRYPTO \u201994","author":"M Matsui","year":"1994","unstructured":"Matsui, M.: The first experimental cryptanalysis of the data encryption standard. In: Desmedt, Y.G. (ed.) CRYPTO 1994. LNCS, vol. 839, pp. 1\u201311. Springer, Heidelberg (1994). https:\/\/doi.org\/10.1007\/3-540-48658-5_1"},{"key":"15_CR17","doi-asserted-by":"publisher","unstructured":"Schulte-Geers, E.: On CCZ-equivalence of addition mod $$2^n$$. Des. Codes Cryptogr. 66(1-3), 111\u2013127 (2013). https:\/\/doi.org\/10.1007\/s10623-012-9668-4","DOI":"10.1007\/s10623-012-9668-4"},{"key":"15_CR18","doi-asserted-by":"publisher","unstructured":"Wang, S., Liu, M., Hou, S., Lin, D.: Moving a step of chacha in syncopated rhythm. In: Handschuh, H., Lysyanskaya, A. (eds.) Advances in Cryptology - CRYPTO 2023 - 43rd Annual International Cryptology Conference, CRYPTO 2023, Santa Barbara, CA, USA, 20\u201324 August 2023, Proceedings, Part III. Lecture Notes in Computer Science, vol. 14083, pp. 273\u2013304. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-38548-3_10","DOI":"10.1007\/978-3-031-38548-3_10"},{"key":"15_CR19","doi-asserted-by":"publisher","unstructured":"Xu, Z., Xu, H., Tan, L., Qi, W.: Differential-linear cryptanalysis of reduced round chacha. IACR Trans. Symmetric Cryptol. 2024(2), 166\u2013189 (2024). https:\/\/doi.org\/10.46586\/tosc.v2024.i2.166-189","DOI":"10.46586\/tosc.v2024.i2.166-189"}],"container-title":["Lecture Notes in Computer Science","Advances in Cryptology \u2013 EUROCRYPT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-91107-1_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,26]],"date-time":"2025-04-26T15:29:13Z","timestamp":1745681353000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-91107-1_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031911064","9783031911071"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-91107-1_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"27 April 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"EUROCRYPT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Annual International Conference on the Theory and Applications of Cryptographic Techniques","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Madrid","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 May 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 May 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"44","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eurocrypt2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eurocrypt.iacr.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}