ciphergoth.org > Cryptology > Salsa20
Paul Crowley
LShift Ltd
SASC 2006 workshop without proceedings
Abstract. We present an attack on Salsa20 reduced to five of its twenty rounds. This attack uses many clusters of truncated differentials and requires 2^165 work and 2^6 plaintexts.