ChaCha20-Poly1305
Aller à la navigation
Aller à la recherche
Portail > Algorithmes
ChaCha20-Poly1305 est un mode AEAD (RFC 8439) associant le chiffrement par flot ChaCha20 au MAC Poly1305. C'est l'alternative de référence à AES-GCM, particulièrement efficace en logiciel.
Construction
- Chiffrement : ChaCha20 génère le keystream XORé au clair.
- Authentification : Poly1305, MAC rapide, calcule un tag sur le chiffré et les données associées. Sa clé d'authentification est dérivée par ChaCha20 (clé à usage unique par message).
- Sortie : chiffré + tag de 128 bits.
Paramètres
| Paramètre | Valeur |
|---|---|
| Clé | 256 bits |
| Nonce | 96 bits (RFC 8439) ; 192 bits pour XChaCha20-Poly1305 |
| Tag | 128 bits |
| AAD | Optionnelles, authentifiées non chiffrées |
Pourquoi le choisir
- Rapide en logiciel sans accélération matérielle → idéal mobile, embarqué, environnements sans AES-NI.
- Temps constant par conception (pas de tables) → robustesse face aux canaux auxiliaires.
- Déployé à grande échelle : TLS 1.3, WireGuard, SSH, etc.
Nonce et XChaCha20-Poly1305
Comme AES-GCM, le mode exige un nonce unique par clé. La variante XChaCha20-Poly1305 (nonce de 192 bits) permet de générer le nonce aléatoirement sans crainte de collision — précieux quand un compteur strict est difficile à maintenir.
AES-GCM ou ChaCha20-Poly1305 ?
| Critère | AES-GCM | ChaCha20-Poly1305 |
|---|---|---|
| Matériel AES-NI | Idéal | Bon |
| Sans AES-NI (mobile/IoT) | Plus lent, risque timing | Idéal |
| Temps constant logiciel | Selon implémentation | Par conception |
| Nonce aléatoire | AES-GCM-SIV requis | XChaCha20-Poly1305 |
Les négociations TLS choisissent souvent l'un ou l'autre selon les capacités matérielles du client.
Points clés à retenir
- AEAD = ChaCha20 (chiffrement) + Poly1305 (MAC), tag 128 bits, clé 256 bits.
- Excellent en logiciel et constant en temps → mobile/embarqué, WireGuard, TLS 1.3.
- Nonce unique requis ; XChaCha20-Poly1305 autorise un nonce aléatoire (192 bits).
- Complément naturel d'AES-GCM selon la présence d'AES-NI.
Voir aussi
| Cryptographie symétrique — Portail | |
|---|---|
| Fondamentaux | Principe · Bloc et flot · Modes opératoires · Padding · IV et nonces |
| Intégrité / auth. | MAC et HMAC · AEAD |
| Gestion des clés | Aléa / CSPRNG · KDF · Échange de clés · Stockage / rotation |
| Algorithmes | AES · ChaCha20/Salsa20 · DES / 3DES · Blowfish et Twofish · RC4 · Camellia, ARIA et SM4 · AES-GCM · ChaCha20-Poly1305 · Hachage |
| Applications | Données au repos · En transit / hybride |
| Sécurité avancée | Attaques · Conformité · Post-quantique |