The Security of ChaCha20-Poly1305 in the Multi-User Setting
Jean Paul Degabriele, Jérôme Govinden, Felix Günther, Kenneth G. Paterson
Abstract
The ChaCha20-Poly1305 AEAD scheme is being increasingly widely deployed in practice. Practitioners need proven security bounds in order to set data limits and rekeying intervals for the scheme. But the formal security analysis of ChaCha20-Poly1305 currently lags behind that of AES-GCM. The only extant analysis (Procter, 2014) contains a flaw and is only for the single-user setting. We rectify this situation. We prove a multi-user security bound on the AEAD security of ChaCha20-Poly1305 and establish the tightness of each term in our bound through matching attacks. We show how our bound differs both qualitatively and quantitatively from the known bounds for AES-GCM, highlighting how subtle design choices lead to distinctive security properties. We translate our bound to the nonce-randomized setting employed in TLS 1.3 and elsewhere, and we additionally improve the corresponding security bounds for GCM. Finally, we provide a simple yet stronger variant of ChaCha20-Poly1305 that addresses the deficiencies highlighted by our analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 635f9674-852e-410d-a345-a9ad19170c80Cited by top-tier papers4
- SoK: Efficient Design and Implementation of Polynomial Hash Functions over Prime FieldsJean Paul Degabriele, Jan Gilcher, Jérôme Govinden, Kenneth G. PatersonS&P 2024 · 8 citations
- We Really Need to Talk About Session Tickets: A Large-Scale Analysis of Cryptographic Dangers with TLS Session TicketsSven Hebrok, Simon Nachtigall, Marcel Maehren, Nurullah Erinola et al.USENIX Security 2023
- SoK: Decoding the Enigma of Encrypted Network Traffic ClassifiersNimesha Wickramasinghe, Arash Shaghaghi, Gene Tsudik, Sanjay K. JhaS&P 2025
- The OCH Authenticated Encryption SchemeSanketh Menda, Mihir Bellare, Viet Tung Hoang, Julia Len et al.CCS 2025
Builds on1
Related papers
- Multi-User Security of CCM Authenticated Encryption ModeXiangyang Zhang, Yaobin Shen, Lei WangCCS 2024 · 2 citations
- Implementing and Proving the TLS 1.3 Record LayerAntoine Delignat-Lavaud, Cédric Fournet, Markulf Kohlweiss, Jonathan Protzenko et al.S&P 2017 · 20 citations
- A Robust Variant of ChaCha20-Poly1305Tim Beyne, Yu Long Chen, Michiel VerbauwhedeCRYPTO 2026 · 1 citation
- How to Abuse and Fix Authenticated Encryption Without Key CommitmentAnge Albertini, Thai Duong, Shay Gueron, Stefan Kölbl et al.USENIX Security 2022
- The Multi-User Security of Triple Encryption, Revisited: Exact Security, Strengthening, and Application to TDESYusuke Naito, Yu Sasaki, Takeshi Sugawara, Kan YasudaCCS 2022 · 7 citations
