ChaCha20-Poly1305

De wiki.nexiat.fr
Aller à la navigation Aller à la recherche

Portail > Algorithmes

ChaCha20-Poly1305 est un mode AEAD (RFC 8439) associant le chiffrement par flot ChaCha20 au MAC Poly1305. C'est l'alternative de référence à AES-GCM, particulièrement efficace en logiciel.

Construction

  • Chiffrement : ChaCha20 génère le keystream XORé au clair.
  • Authentification : Poly1305, MAC rapide, calcule un tag sur le chiffré et les données associées. Sa clé d'authentification est dérivée par ChaCha20 (clé à usage unique par message).
  • Sortie : chiffré + tag de 128 bits.

Paramètres

Paramètre Valeur
Clé 256 bits
Nonce 96 bits (RFC 8439) ; 192 bits pour XChaCha20-Poly1305
Tag 128 bits
AAD Optionnelles, authentifiées non chiffrées

Pourquoi le choisir

  • Rapide en logiciel sans accélération matérielle → idéal mobile, embarqué, environnements sans AES-NI.
  • Temps constant par conception (pas de tables) → robustesse face aux canaux auxiliaires.
  • Déployé à grande échelle : TLS 1.3, WireGuard, SSH, etc.

Nonce et XChaCha20-Poly1305

Comme AES-GCM, le mode exige un nonce unique par clé. La variante XChaCha20-Poly1305 (nonce de 192 bits) permet de générer le nonce aléatoirement sans crainte de collision — précieux quand un compteur strict est difficile à maintenir.

AES-GCM ou ChaCha20-Poly1305 ?

Critère AES-GCM ChaCha20-Poly1305
Matériel AES-NI Idéal Bon
Sans AES-NI (mobile/IoT) Plus lent, risque timing Idéal
Temps constant logiciel Selon implémentation Par conception
Nonce aléatoire AES-GCM-SIV requis XChaCha20-Poly1305

Les négociations TLS choisissent souvent l'un ou l'autre selon les capacités matérielles du client.

Points clés à retenir

  • AEAD = ChaCha20 (chiffrement) + Poly1305 (MAC), tag 128 bits, clé 256 bits.
  • Excellent en logiciel et constant en temps → mobile/embarqué, WireGuard, TLS 1.3.
  • Nonce unique requis ; XChaCha20-Poly1305 autorise un nonce aléatoire (192 bits).
  • Complément naturel d'AES-GCM selon la présence d'AES-NI.

Voir aussi

Cryptographie symétrique — Portail
Fondamentaux Principe · Bloc et flot · Modes opératoires · Padding · IV et nonces
Intégrité / auth. MAC et HMAC · AEAD
Gestion des clés Aléa / CSPRNG · KDF · Échange de clés · Stockage / rotation
Algorithmes AES · ChaCha20/Salsa20 · DES / 3DES · Blowfish et Twofish · RC4 · Camellia, ARIA et SM4 · AES-GCM · ChaCha20-Poly1305 · Hachage
Applications Données au repos · En transit / hybride
Sécurité avancée Attaques · Conformité · Post-quantique