ChaCha20
More info
- Creator
- Daniel J. Bernstein
- Released
- Type
- Stream cipher
- License
- Public domain
- Spec
- RFC 8439
- Wikipedia
- en.wikipedia.org
Modern stream cipher by Daniel J. Bernstein (2008) — fast in pure software on CPUs that lack AES acceleration.
An evolution of Salsa20. 256-bit key, 96-bit nonce, 20 rounds. In practice always paired with the Poly1305 MAC to form the AEAD construction ChaCha20-Poly1305 (RFC 8439). Standard in TLS 1.3, WireGuard, Signal, OpenSSH and age-encryption.
Beats AES-GCM on devices without AES-NI (older phones, ARM microcontrollers); smaller edge on modern x86. Constant-time implementation is easy → less prone to timing attacks than naive AES.