Truncated differential cryptanalysis of five rounds of Salsa20

Paul Crowley

LShift Ltd

SASC 2006 workshop without proceedings

Abstract. We present an attack on Salsa20 reduced to five of its twenty rounds. This attack uses many clusters of truncated differentials and requires 2^165 work and 2^6 plaintexts.

Related resources