In this paper, we point out some weaknesses in the Salsa20 core function that could be exploited to obtain up to 2/sup 31/ collisions for its full (20 rounds) version. We first find an invariant for its main building block, the /b quarterround/ function, that is then extended to the /b rowround/ and /b columnround/ functions. This allows us to find an input subset of size 2/sup 32/ for which the Salsa20 core behaves exactly as the transformation f(x) = 2x. An attacker can take advantage of this for constructing 2/sup 31/ collisions for any number of rounds. We finally show another weakness in the form of a differential characteristic with probability one that proves that the Salsa20 core does not have 2/sup nd/ preimage resistance.
Hernandez-Castro, J. C., Quisquater, J.-J., & Tapiador, J. M. E. (2008). On the Salsa20 core function. Fast Software Encryption. 15th International Workshop, FSE 2008, p. 462-469. https://hdl.handle.net/2078.5/228716