Parallelization solution optimization method and system for quantum cryptographic analysis Grover-mets-Simon problem

Through parallel quantum cryptographic analysis method, the search space of the Grover-meets-Simon problem is split, and the quantum register and parallel Grover-meets-Simon algorithm are used for solving, which solves the problem of difficulty in handling search and periodic search in the existing technology, and realizes more efficient quantum cryptographic analysis.

CN119966613APending Publication Date: 2025-05-09Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411956227.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-28
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

Existing quantum cryptographic analysis methods are difficult to effectively solve the search and periodic search problems involved in the Grover-meets-Simon problem.

Method used

A parallel solution optimization method for quantum cryptographic analysis Grover-meets-Simon problem is provided. By obtaining the object function, verifying whether the solution conditions of the Grover-meets-Simon problem are met, and a truncated periodic function is constructed. The solution search space is split into parallel solution high bit string periodic solution space and general solution low bit string periodic solution space, and the solution is performed using quantum registers and parallel Grover-meets-Simon algorithm.

Benefits of technology

Through parallel solution methods, the depth and implementation cost of the quantum circuit required for the Grover-meets-Simon problem are reduced, the feasibility of the solution method is improved, and the application prospects are good in the field of quantum cryptographic analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966613A_ABST
    Figure CN119966613A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of quantum cryptographic analysis, in particular to a parallelization solution optimization method and system for a quantum cryptographic analysis Grover-mets-Simon problem, and aims at solving the Grover-mets-Simon problem by verifying whether an object function in a quantum cryptographic algorithm meets a solution condition or not and constructing a truncated periodic function for the met object function. The solution search space is divided into a parallel solution high bit string period solution space and a general solution low bit string period solution space; solving the truncated periodic function in a parallel high-bit string periodic solving space by using a quantum register according to a parallel Grover-mets-Simon algorithm, so as to obtain quantum key algorithm periodic data through a plurality of parallel Simon threads; and a Grover-mets-Simon algorithm is utilized to carry out supplementary solution on the periodic function in a general low-bit string periodic solution space so as to obtain a quantum key algorithm key and periodic residual bits. According to the method, the depth, width and gate circuit expenditure of the quantum circuit required by quantum cryptographic analysis solution can be flexibly adjusted by adjusting truncation parameters.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of quantum cryptography analysis, and in particular to a parallel solution optimization method and system for a quantum cryptography analysis Grover-meets-Simon problem. Background Art

[0002] Quantum cryptographic analysis can be used to evaluate and improve the security of traditional encryption algorithms. It evaluates the strength and resilience of encryption algorithms in the face of quantum attacks by simulating attacks from quantum computers. It helps to discover possible vulnerabilities in quantum cryptographic systems and assist in making necessary improvements to quantum cryptographic systems.

[0003] Traditional quantum cryptographic analysis methods only analyze one aspect of the quantum cryptographic system, such as focusing only on the period of the encryption function or only focusing on the search problem. The Grover-meets-Simon algorithm is a quantum algorithm that combines the ideas of the Grover algorithm and the Simon algorithm. The Grover algorithm is mainly used to accelerate the search problem, and the Simon algorithm is used to find the period of the function. How to use the Grover-meets-Simon combined algorithm to solve the search and period search involved at the same time has become an urgent problem to be solved in quantum cryptographic analysis. Summary of the invention

[0004] To this end, the present invention provides a parallel solution optimization method and system for the Grover-meets-Simon problem of quantum cryptographic analysis to solve the problem that the existing quantum cryptographic analysis is incomplete.

[0005] According to the design scheme provided by the present invention, on the one hand, a parallel solution optimization method for quantum cryptographic analysis Grover-meets-Simon problem is provided, comprising:

[0006] Obtaining an object function in a quantum cryptography algorithm, verifying whether the object function satisfies a Grover-meets-Simon problem solving condition, and constructing a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, so as to split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in a quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function;

[0007] In the parallel solution space of high-bit string periodicity, quantum registers are used to solve truncated periodic functions according to the parallel Grover-meets-Simon algorithm to obtain quantum key algorithm periodic data through multiple parallel Simon threads;

[0008] In the general solution space for solving the periodicity of low-bit strings, the Grover-meets-Simon algorithm is used to supplement the solution of the periodic function, and the key and periodic residual bits of the quantum key algorithm in quantum cryptography analysis are obtained based on the solution results.

[0009] As a parallel solution optimization method for the quantum cryptography analysis Grover-meets-Simon problem of the present invention, further, a truncated periodic function is constructed for an object function that meets the solution conditions of the Grover-meets-Simon problem, including:

[0010] The quantum key algorithm period is represented as n-bit groups, and the period representation is divided into a high-bit string period consisting of high nt bits and a low-bit string period consisting of low t bits according to the parallel parameter t, and a linear subspace set is set, and the parallel parameter linear subspace set is represented as: u is used to represent a linear subspace set A subset of

[0011] Construct nt-dimensional space 0,1} based on parallel parameter linear subspace n-t The object function is modified on the above, and based on the object function modification, high-bit string periodic functions in the high-bit string periodic solution space and low-bit string periodic functions in the general low-bit string periodic solution space are obtained for parallel solution.

[0012] As a parallel solution optimization method for the quantum cryptography analysis Grover-meets-Simon problem of the present invention, further, the truncated periodic function is solved according to the parallel Grover-meets-Simon algorithm, including:

[0013] Setting a quantum register according to a test function, wherein the test function acts on the register to check whether the bit vector output by the parallel Simon thread satisfies a rank threshold, wherein the rank threshold is set according to a search space represented by a number of periodic groupings of a quantum key algorithm;

[0014] By performing Hadamard transformation and interference on the quantum register, and using the test function to obtain the quantum superposition state of the quantum register with respect to the corresponding high-bit string periodic function;

[0015] Repeatedly apply multiple Grover iterations to the quantum superposition state to obtain a system of linear equations about the period;

[0016] The periodic data of the quantum key algorithm is obtained by solving the linear equations.

[0017] As a parallel solution optimization method for the quantum cryptography analysis Grover-meets-Simon problem of the present invention, further, the Grover-meets-Simon algorithm is used to supplement the solution of the periodic function, including:

[0018] In the general solution space for solving the low-bit string period, the quantum register is subjected to Hadamard transformation and interference, and the quantum superposition state of the quantum register with respect to the low-bit string periodic function is obtained by using a test function. The quantum superposition state is subjected to Grover iteration, and the test function is used again to measure and obtain the final quantum state of the quantum register with respect to the low-bit string periodic function, so as to obtain the remaining periodic bits and keys of the quantum key algorithm based on the final quantum state.

[0019] In another aspect, the present invention further provides a parallel solution optimization system for quantum cryptographic analysis Grover-meets-Simon problem, comprising: an initial setting module, a parallel solution module and a supplementary solution module, wherein:

[0020] An initial setting module, used to obtain an object function in a quantum cryptography algorithm, verify whether the object function satisfies a Grover-meets-Simon problem solving condition, and construct a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, and split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in a quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function;

[0021] A parallel solution module, used for solving the truncated periodic function in the parallel solution space of the high bit string periodic solution by using the quantum register and according to the parallel Grover-meets-Simon algorithm, so as to obtain the quantum key algorithm periodic data through multiple Simon threads in parallel;

[0022] The supplementary solution module is used to use the Grover-meets-Simon algorithm to supplement the solution of the periodic function in the general solution space for solving the low-bit string period, and obtain the key and period residual bits of the quantum key algorithm in quantum cryptography analysis based on the solution results.

[0023] Beneficial effects of the present invention:

[0024] The present invention aims at the case where the object function in quantum cryptography is suitable for an XOR-type function, utilizes the Grover-meets-Simon parallel solution, and flexibly adjusts the quantum circuit depth, width and gate circuit expenditure required for solving the quantum cryptography by adjusting the truncation parameter, thereby reducing the quantum circuit depth and quantum circuit implementation cost required for solving the Grover-meets-Simon problem, improving the feasibility of the solution method, and having good application prospects in the field of quantum cryptography. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 The figure is a schematic diagram of the parallel solution optimization process of the Grover-meets-Simon problem in quantum cryptography analysis in the embodiment. DETAILED DESCRIPTION

[0026] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention is further described in detail below in conjunction with the accompanying drawings and technical solutions.

[0027] Parallelized Grover-meets-Simon algorithm The parallelization methods of the Grover algorithm can be divided into internal parallelization and external parallelization. Among them, external parallelization: running several complete Grover algorithm instances in parallel, only one of the parallel instances needs to succeed; internal parallelization: dividing the search space into several non-overlapping subsets, searching each subset separately, which can reduce the number of unnecessary iterations. For S quantum machines, both parallelization methods will increase the circuit width by S and reduce the depth by Among them, internal parallelization will have more advantages in terms of attack success rate in quantum simulation attack and the demand for plaintext and ciphertext pairs under Grover oracle. Figure 1 As shown, a parallel solution optimization method for quantum cryptographic analysis Grover-meets-Simon problem is provided, including:

[0028] S101. Obtain an object function in a quantum cryptography algorithm, verify whether the object function satisfies a Grover-meets-Simon problem solving condition, and construct a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, so as to split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in the quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function.

[0029] For a function f that satisfies the Grover-meets-Simon problem, if it can be written as

[0030]

[0031] , then f is called an XOR-type function.

[0032] Check whether the object function f satisfies the properties of XOR-type functions to verify whether the object function meets the conditions for solving the Grover-meets-Simon problem.

[0033] Specifically, a truncated periodic function is constructed for the object function that satisfies the conditions for solving the Grover-meets-Simon problem, which can be designed to include:

[0034] The quantum key algorithm period is represented as n-bit groups, and the period representation is divided into a high-bit string period consisting of high nt bits and a low-bit string period consisting of low t bits according to the parallel parameter t, and a linear subspace set is set, and the parallel parameter linear subspace set is represented as: u is used to represent a linear subspace set A subset of

[0035] Construct nt-dimensional space 0,1} based on parallel parameter linear subspace n-t The object function is modified on the above, and based on the object function modification, high-bit string periodic functions in the high-bit string periodic solution space and low-bit string periodic functions in the general low-bit string periodic solution space are obtained for parallel solution.

[0036] For the shape XOR-type function f(k,x), select n-dimensional space {0,1} n Subset of Define the function, select the parallel parameter t, and take the linear subspace of dimension t definition In the space {0,1} n-t Variations on

[0037] From the properties of the function, we can see that for The cycle is The period of f is the high nt bits of s. For n-bit packet s, s l The bit string consisting of the high nt bits, s r The bit string composed of the lower t bits of , that is, s = s l ||s r .

[0038] Setting up the function It can be seen that f' is is a periodic function of s.

[0039] Set the test function test:{0,1} κ+nc+mc →{0,1}, an n-bit vector v1,...,v used to check the output of c parallel Simon threads c Whether the rank is not greater than n-1, formally defined as

[0040] The test function acting on the register state can be described as test |k,v1,...,v c ,y1,...,y c

[0041] Where dim represents the dimension of the linear space.

[0042] S102. In the parallel solution space of the high-bit string period solution, the truncated periodic function is solved using the quantum register and according to the parallel Grover-meets-Simon algorithm to obtain the quantum key algorithm periodic data through multiple parallel Simon threads.

[0043] Specifically, solving the truncated periodic function may include:

[0044] Setting a quantum register according to a test function, wherein the test function acts on the register to check whether the bit vector output by the parallel Simon thread satisfies a rank threshold, wherein the rank threshold is set according to a search space represented by a number of periodic groupings of a quantum key algorithm;

[0045] By performing Hadamard transformation and interference on the quantum register, and using the test function to obtain the quantum superposition state of the quantum register with respect to the corresponding high-bit string periodic function;

[0046] Repeatedly apply multiple Grover iterations to the quantum superposition state to obtain a system of linear equations about the period;

[0047] The periodic data of the quantum key algorithm is obtained by solving the linear equations.

[0048] For the above truncated function The optimized parallel Grover-meets-Simon algorithm is used to solve the period s l , the process can be described as:

[0049] 1) Prepare the register of (κ-t)+(nt)c'+mc' qubits|0 κ-t >|0 (n-t)c' >|0 mc'>.

[0050] 2) Apply transformations to registers get Among them, H a Represents a composite call of Hadamard transform, I M represents the identity transformation on the matrix M.

[0051] 3) Apply transformation to registers get

[0052] 4) Apply transformations to registers The new state |ψ> is of the form

[0053] 5) Repeat the Grover iteration D for |ψ> r times |ψ> O test , we get the state |φ>=(D |ψ> O test ) r |ψ>;

[0054] 6) Measure the first (κ-t)+(nt)c' bits of |φ>, and get and v1,...,v c' .

[0055] 7) Solve the system of equations s l ·v i =1,i=1,2,...,c', we can get the period s l .

[0056] S103. In a general solution space for solving the period of a low-bit string, a Grover-meets-Simon algorithm is used to supplement the solution of the periodic function, and a key and periodic residual bits of a quantum key algorithm in quantum cryptography analysis are obtained based on the solution result.

[0057] Specifically, in the general solution space for solving the low-bit string period, the quantum superposition state of the quantum register with respect to the low-bit string periodic function is obtained by using a test function through Hadamard transformation and interference on the quantum register, and Grover iteration is performed on the quantum superposition state. The test function is again used to measure and obtain the final quantum state of the quantum register with respect to the low-bit string periodic function, so as to obtain the remaining periodic bits and keys of the quantum key algorithm based on the final quantum state.

[0058] Apply the general Grover-meets-Simon algorithm to solve the key k and the remaining bits of the period s. Apply the general Grover-meets-Simon algorithm to the function f', and define the function f': {0,1}t ×{0,1} n →{0,1} m , when When f' is a periodic function about s. l The result obtained in the previous step is further solved. and s=s l ||s r This part requires 2 n / 2 Iterations, each of which calls only O(n) f′ quantum queries. Therefore, the cost of this part is negligible in terms of the overall attack.

[0059] Furthermore, based on the above method, an embodiment of the present invention also provides a parallel solution optimization system for quantum cryptographic analysis Grover-meets-Simon problem, comprising: an initial setting module, a parallel solution module and a supplementary solution module, wherein:

[0060] An initial setting module, used to obtain an object function in a quantum cryptography algorithm, verify whether the object function satisfies a Grover-meets-Simon problem solving condition, and construct a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, and split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in a quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function;

[0061] A parallel solution module, used for solving the truncated periodic function in the parallel solution space of the high bit string periodic solution by using the quantum register and according to the parallel Grover-meets-Simon algorithm, so as to obtain the quantum key algorithm periodic data through multiple Simon threads in parallel;

[0062] The supplementary solution module is used to use the Grover-meets-Simon algorithm to supplement the solution of the periodic function in the general solution space for solving the low-bit string period, and obtain the key and period residual bits of the quantum key algorithm in quantum cryptography analysis based on the solution results.

[0063] To verify the effectiveness of this solution, the following is a further explanation in conjunction with the MAC algorithm:

[0064] Function f is taken from the MAC algorithm SUM-ECBC. SUM-ECBC is the first MAC algorithm that has been proven to have security beyond the birthday bound. It is an encryption algorithm based on the summation operation. It generates a fixed-length output by summing the encrypted blocks to encrypt the data. The working principle of SUM-ECBC is based on the summation operation. It divides the input data into multiple blocks and sums these blocks. The specific steps are as follows:

[0065] Data chunking: Divide the input data into multiple chunks, each with a fixed size.

[0066] Sum operation: Perform a sum operation on each block to generate a fixed-length output.

[0067] Encrypted output: The summation result is used as the encrypted output.

[0068] SUM-ECBC uses four independent (block cipher) keys, calling two CBC-MACs respectively and outputting the results after XOR. The block cipher using key K is called E K , with E K The CBC-MAC of the underlying block cipher is denoted as CBC-MAC[E K ]. When the message length is 2n bits, SUM-ECBC can be described as

[0069]

[0070] Where K = (K1, K2, K3, K4), K i ∈{0,1} κ .

[0071] 1. Initial Setup

[0072] For a given key K, any β0,β1∈{0,1} n ,remember Setting Function

[0073] Test f(α k ,x) is α k =s1 / s2 is a periodic function about x, with a period

[0074] Select the parallel parameter t according to the computing environment. Define the function Shape thereby exist About x l With period s l .

[0075] Setting up the function It can be seen that f' is is a periodic function of s.

[0076] 2. Truncation-Parallel Solution

[0077] According to the set parameters, execute the truncation-parallel solution. Set the quantum registers and execute the parallelized Grover-meets-Simon algorithm according to the solution description to solve the object About x l The period of l .

[0078] 3. Supplementary Solution

[0079] Apply the general Grover-meets-Simon algorithm to the periodic function f', where s l The result obtained in the previous step is further solved. and s=s l ||s r .

[0080] All the keys of SUM-ECBC can be calculated, thus realizing quantum key recovery attack to evaluate the security of SUM-ECBC.

[0081] Through the above steps of solving SUM-ECBC, it can be seen that this solution can be applied to parallelize the Grover-meets-Simon problem for XOR-type functions. Compared with the general parallelized Grover-meets-Simon method, it can flexibly adjust the quantum circuit depth, width and gate circuit overhead required for the solution by adjusting the truncation parameters, and has good application prospects in the field of quantum cryptographic analysis and evaluation.

[0082] Unless otherwise specifically stated, the relative steps, numerical expressions and values ​​of the components and steps set forth in these embodiments do not limit the scope of the present invention.

[0083] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0084] The units and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A person of ordinary skill in the art may use different methods to implement the described functions for each specific application, but such implementation is not considered to be beyond the scope of the present invention.

[0085] Those skilled in the art will appreciate that all or part of the steps in the above method can be completed by instructing related hardware through a program, and the program can be stored in a computer-readable storage medium, such as a read-only memory, a disk or an optical disk. Optionally, all or part of the steps in the above embodiment can also be implemented using one or more integrated circuits, and accordingly, each module / unit in the above embodiment can be implemented in the form of hardware or in the form of software function modules. The present invention is not limited to any specific form of combination of hardware and software.

[0086] Finally, it should be noted that the above-described embodiments are only specific implementations of the present invention, which are used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention is described in detail with reference to the above-described embodiments, ordinary technicians in the field should understand that any technician familiar with the technical field can still modify the technical solutions recorded in the above-described embodiments within the technical scope disclosed by the present invention, or can easily think of changes, or make equivalent replacements for some of the technical features therein; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A parallel solution optimization method for quantum cryptographic analysis Grover-meets-Simon problem, characterized in that: Include: Obtaining an object function in a quantum cryptography algorithm, verifying whether the object function satisfies a Grover-meets-Simon problem solving condition, and constructing a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, so as to split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in a quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function; In the parallel solution space of high-bit string periodicity, quantum registers are used to solve truncated periodic functions according to the parallel Grover-meets-Simon algorithm to obtain quantum key algorithm periodic data through multiple parallel Simon threads; In the general solution space for solving the periodicity of low-bit strings, the Grover-meets-Simon algorithm is used to supplement the solution of the periodic function, and the key and periodic residual bits of the quantum key algorithm in quantum cryptography analysis are obtained based on the solution results.

2. The parallel solution optimization method for the quantum cryptographic analysis Grover-meets-Simon problem according to claim 1 is characterized in that: Construct a truncated periodic function for the object function that meets the Grover-meets-Simon problem solution conditions, including: The quantum key algorithm period is represented as n-bit groups, and the period representation is divided into a high-bit string period consisting of high nt bits and a low-bit string period consisting of low t bits according to the parallel parameter t, and a linear subspace set is set, and the parallel parameter linear subspace set is represented as: u is used to represent a linear subspace set A subset of Construct nt-dimensional space 0,1} based on parallel parameter linear subspace n-t The object function is modified on the above, and based on the object function modification, high-bit string periodic functions in the high-bit string periodic solution space and low-bit string periodic functions in the general low-bit string periodic solution space are obtained for parallel solution.

3. The parallel solution optimization method for the quantum cryptographic analysis Grover-meets-Simon problem according to claim 2 is characterized in that: Solve the truncated periodic function according to the parallel Grover-meets-Simon algorithm, including: Setting a quantum register according to a test function, wherein the test function acts on the register to check whether the bit vector output by the parallel Simon thread satisfies a rank threshold, wherein the rank threshold is set according to a search space represented by a number of periodic groupings of a quantum key algorithm; By performing Hadamard transformation and interference on the quantum register, and using the test function to obtain the quantum superposition state of the quantum register with respect to the corresponding high-bit string periodic function; Repeatedly apply multiple Grover iterations to the quantum superposition state to obtain a system of linear equations about the period; The periodic data of the quantum key algorithm is obtained by solving the linear equations.

4. The parallel solution optimization method for the quantum cryptographic analysis Grover-meets-Simon problem according to claim 2 or 3, characterized in that: The Grover-meets-Simon algorithm is used to supplement the solution of periodic functions, including: In the general solution space for solving the low-bit string period, the quantum register is subjected to Hadamard transformation and interference, and the quantum superposition state of the quantum register with respect to the low-bit string periodic function is obtained by using a test function. The quantum superposition state is subjected to Grover iteration, and the test function is used again to measure and obtain the final quantum state of the quantum register with respect to the low-bit string periodic function, so as to obtain the remaining periodic bits and keys of the quantum key algorithm based on the final quantum state.

5. A parallel solution optimization system for quantum cryptographic analysis Grover-meets-Simon problem, characterized in that: It includes: initial setting module, parallel solution module and supplementary solution module, among which, An initial setting module, used to obtain an object function in a quantum cryptography algorithm, verify whether the object function satisfies a Grover-meets-Simon problem solving condition, and construct a truncated periodic function for the object function that satisfies the Grover-meets-Simon problem solving condition, and split the solution search space into a parallel solution space for high-bit string periodic solution and a general solution space for low-bit string periodic solution, wherein the object function includes an encryption function and an encryption function variant function in a quantum cryptography algorithm, and the Grover-meets-Simon problem solving condition is represented by an XOR-type function; A parallel solution module is used to solve the truncated periodic function in a parallel solution space of a high-bit string periodic solution by using a quantum register and according to a parallel Grover-meets-Simon algorithm, so as to obtain quantum key algorithm periodic data through multiple Simon threads in parallel; The supplementary solution module is used to use the Grover-meets-Simon algorithm to supplement the solution of the periodic function in the general solution space for solving the low-bit string period, and obtain the key and period residual bits of the quantum key algorithm in quantum cryptography analysis based on the solution results.

6. An electronic device, characterized in that: include: at least one processor, and a memory coupled to the at least one processor; The memory stores a computer program, and the computer program can be executed by the at least one processor to implement the method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed, the method according to any one of claims 1 to 4 can be implemented.

Citation Information

Cited By

  • Quantum key recovery attack method and system

    CN121644079A