Cryptographic analysis search space division method based on active group and necklace enumeration

By modeling the cryptanalysis search space as a necklace generation problem, active group and necklace enumeration algorithms are adopted to solve the resource exhaustion and solver stall problems of large search spaces, and efficient and systematic search space partitioning and progress indication are achieved, which is suitable for cryptanalysis tasks.

CN120614112APending Publication Date: 2025-09-09UNIV OF CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510761551.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-09
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing cryptanalysis search space partitioning methods suffer from resource exhaustion, solver stalling, lack of systematicity, poor scalability and low search efficiency when facing large search spaces. In particular, they are unable to effectively manage and provide progress indicators when dealing with a large number of active S-boxes.

Method used

A method based on active groups and necklace enumeration is used to model the search space as a necklace generation problem in combinatorial mathematics. Through active group partitioning and necklace enumeration algorithms, the large search space is systematically divided into manageable subspaces, and an automated search tool is used to perform exhaustive search.

Benefits of technology

It achieves a systematic partitioning of large search spaces, ensures the integrity and efficiency of the search, provides clear progress indication, significantly improves search time, and is applicable to various cryptanalysis tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614112A_ABST
    Figure CN120614112A_ABST
Patent Text Reader

Abstract

The invention discloses a cryptographic analysis search space division method based on active group and necklace enumeration, which comprises the following steps: 1) for a cryptographic algorithm adopting a chi function to design S boxes, carrying out preliminary division on a search space according to the number n of active S boxes in the cryptographic algorithm to obtain N subspaces with different sizes; wherein each subspace comprises an active mode in which the number of active S boxes is n; 2) grouping the active S boxes in each subspace to obtain a plurality of active groups; the active group comprises i continuous active S box sequences in the active mode; (3) each active group in each subdivision space is called as an active bead, and the inactive S boxes for separating the active groups are called inactive beads; any active mode in the subdivision space is converted into a necklace composed of active beads and inactive beads contained in the subdivision space; and 4) calculating the number of different necklaces under the same necklace configuration as the size of the corresponding subdivision space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cryptography and relates to a hierarchical partitioning method for cryptanalysis search space based on active groups and necklace enumeration. Background Art

[0002] In modern cryptanalysis, automated search tools have become an important tool for discovering cryptographic structures. This is especially true when analyzing hash functions and block ciphers, where specific differential or linear features need to be found. These structures are often too complex to construct manually or with specialized heuristic search algorithms, thus requiring automated search techniques.

[0003] However, when the search space becomes extremely large, automated search techniques face two major challenges:

[0004] 1. Resource exhaustion: For very large spaces, the solver may require impractical amounts of memory or computation time.

[0005] 2. Solver Stalling: When the search space is large and there are few or no solutions, the solver may get stuck in an infinite solving process without returning a result.

[0006] Existing space management methods attempt to address these challenges by partitioning the search space. For example, Erlacher et al. proposed a strategy to partition the space by fixing the active S-box patterns in a specific round. However, when the number of patterns becomes large (e.g., for more than 22 active S-boxes, the number of patterns exceeds 2 50 ), this approach becomes impractical.

[0007] The existing search space partitioning methods have the following disadvantages:

[0008] 1. Lack of systematicity: Existing methods usually rely on specific password structures and lack a general systematic partitioning strategy.

[0009] 2. Poor scalability: When the number of active S-boxes increases, the number of patterns grows exponentially, making it infeasible to directly enumerate all patterns.

[0010] 3. Unable to handle large search spaces: For cases with a large number of active S-boxes (e.g., n ≥ 26), existing methods cannot effectively divide and manage the search space.

[0011] 4. Lack of progress indication: In large-scale search tasks, existing methods cannot provide clear progress indication, making it difficult to evaluate the completion of the search.

[0012] 5. Low search efficiency: Existing search strategies do not fully consider the structural characteristics of the search space, resulting in low search efficiency. Summary of the Invention

[0013] In response to the problems existing in the prior art, the present invention aims to provide a hierarchical partitioning method for cryptanalysis search spaces based on active groups and necklace enumeration. This method can systematically divide large search spaces into manageable subspaces while maintaining search integrity and providing clear progress indicators. Specifically, the present invention aims to solve the following technical problems:

[0014] 1. How to systematically partition a large search space so that each subspace can be processed by an automated search tool in a reasonable amount of time.

[0015] 2. How to ensure the completeness of the division to ensure that no potential solutions are missed.

[0016] 3. How to improve search efficiency so that the search algorithm can process each subspace faster.

[0017] The key innovations of the present invention include:

[0018] 1. Active group-based space partitioning technique: By introducing the concept of active groups, the present invention provides a method to systematically partition a large search space so that each subspace can be processed in a reasonable time.

[0019] 2. Application to the necklace generation problem: The present invention models the search space partition problem as a necklace generation problem in combinatorial mathematics, which enables the present invention to systematically enumerate and count the patterns in each subspace.

[0020] Specifically, the innovation of modeling the search space partition problem as a necklace generation problem lies in:

[0021] (1) Problem transformation:

[0022] View the activity pattern of length N as a circular arrangement (necklace) where each position can be either active or inactive.

[0023] Think of consecutive groups of active S-boxes (active groups) as special beads on a necklace.

[0024] Consider rotationally equivalent active patterns as different representations of the same necklace.

[0025] (2) Mathematical foundation:

[0026] The Burnside lemma and Pólya counting theorem in combinatorics are used to deal with rotational symmetry.

[0027] Apply a fixed-content necklace enumeration algorithm to ensure accurate counting of different activity patterns.

[0028] The size of the subspace corresponding to each combination is calculated through a mathematical formula without actually enumerating all the patterns.

[0029] (3) Computational advantages:

[0030] Through the necklace representation, the size of each subspace can be directly calculated without generating all possible active patterns.

[0031] For a space with n active S-boxes, traditional methods need to enumerate C(N,n) patterns, while the necklace method only needs to process a small number of combinations.

[0032] Necklace enumeration takes rotational symmetry into account and automatically eliminates duplicate counting of equivalent patterns.

[0033] (4) Systematic division:

[0034] The necklace generation problem provides a natural framework for systematically partitioning the search space.

[0035] Each combination [n1,n2,…n K ] corresponds to a well-defined subspace.

[0036] The union of all combinations covers the entire search space, and the subspaces do not overlap with each other.

[0037] This necklace generation-based modeling approach is one of the core innovations of the present invention, which enables the present invention to handle large search spaces in a mathematically rigorous and computationally efficient manner.

[0038] 3. Efficient search strategy: This paper proposes a strategy to optimize the search process and improves the efficiency of automated search tools through a deep understanding of the search space structure.

[0039] 4. Complete space partitioning framework: The present invention provides a complete framework, including preliminary partitioning, further partitioning based on active groups, and processing of difficult subsets, so that the method can be applied to various cryptanalysis tasks.

[0040] The technical solution of the present invention is:

[0041] A cryptographic analysis search space partitioning method based on active groups and necklace enumeration, comprising the following steps:

[0042] 1) For a cryptographic algorithm that uses the χ function to design S-boxes, a search space is preliminarily partitioned according to the number n of active S-boxes in the cryptographic algorithm to obtain N subspaces of varying sizes; each subspace includes an active pattern with n active S-boxes, and the search space includes C(N,n) active patterns, where N is the total number of S-boxes in the cryptographic algorithm, and n∈{1,2,…,N};

[0043] 2) Grouping the active S-boxes in each subspace to obtain several active groups; the active group is a continuous sequence of i active S-boxes in the active pattern; where n i is the number of active groups containing i active S-boxes, i∈{1,2,…,K}, K is the maximum number of S-boxes allowed in an active group, K≤n, and there is at least one inactive S-box separating each active group; i The space corresponding to the active group combination containing i active S-boxes is taken as a subdivision space, and the active group combination vector corresponding to each subdivision space is [n1,n2,…,n K ];

[0044] 3) Each active group in each subdivided space is called an active bead, and the inactive S-boxes separating the active groups are called inactive beads; any active pattern in the subdivided space is converted into a necklace consisting of the active beads and inactive beads it contains, and the active group combination vector [n1,n2,…,n K ]The corresponding necklace configuration is

[0045] Among them, b i represents the active bead corresponding to the active group containing i active S-boxes, including i+1 S-boxes, i.e., i active S-boxes and an inactive S-box in front of the active group, i ≥ 0; b0 represents the inactive bead; n bi Indicates b i The number of , i∈{1,2,…,K};

[0046] 4) Calculate the number of different necklaces under the same necklace configuration as the size of the corresponding subdivision space.

[0047] Furthermore, the method of exhaustively searching each subdivision space based on the set target task is:

[0048] 1) Formal definition of the search problem: For a given necklace configuration For the active mode in the corresponding segment space, a variable is generated according to the number of S-boxes contained in each active mode and the value of each dimension in the variable is determined, where the dimension corresponding to the active S-box is 1 and the dimension corresponding to the inactive S-box is 0;

[0049] 2) For each active group of size i, introduce n i Position variable p i,j Indicates the starting position of the active group, j = 1 ~ n i ;Auxiliary variables are introduced to represent the state of each S-box and the relationship between active groups;

[0050] 3) Set constraints, which include:

[0051] Position constraint: Ensure that the positions of all active groups are within the valid range, i.e. p i,j ∈{0,1,…,N-1};

[0052] Non-overlapping constraint: For any two different active groups p i,j , p i′,j′ , (i, j) ≠ (i′, j′), if p i,j <p i′,j′ , then p i,j +i≤p i′,j′ ;

[0053] Separation constraint: For any adjacent active groups (i, j) and (i′, j′), if p i,j <p i′,j′ , then p i,j +i+1≤p i′,j′ ;

[0054] S-box state association: associate the active state of the S-box with the active group position. For the k-th position S of the S-box k , if and only if there exists an active group (i, j) such that p i,j ≤k <p i,j +i, then S k =1; k∈{0,1,...,N-1};

[0055] 5) Set encoding optimization strategy:

[0056] During the S-box encoding process, the location of the target active group is fixed to reduce the search space; the locations of multiple large active groups of the same size are specified; and the constraints that must be true are pre-calculated based on the necklace structure.

[0057] 6) Convert all constraints into an input format acceptable to the automated search tool; generate an instance of the search problem for a given necklace configuration; use the automated search tool to solve the instance and obtain all solutions that satisfy the constraints; convert each solution back to the corresponding active mode;

[0058] 7) Verify the search results to ensure that each active pattern found actually satisfies the given necklace configuration; for multiple solutions under the same configuration, check whether there is a rotation equivalence relationship between them; integrate all valid solutions into the result set to provide a complete set of candidate active patterns for cryptanalysis.

[0059] Furthermore, the target active group is the largest active group.

[0060] Furthermore, the method of grouping the active S-boxes in each subspace to obtain several active groups is as follows:

[0061] 1) Initialize a result list and create an initial active group combination. The corresponding active group combination vector is filled with 0, that is, [n1=0,n2=0,…,n K =0];

[0062] 2) Start generating the vectors [n1,n2,…,n K ]; In the recursive process, for each size of active group, starting from the minimum size 1, try to allocate 0 to the maximum possible number of active groups. For each possible allocation number, update the current combination vector and recursively process the next size of active group; when processing the largest size active group, that is, the active group of size K, check whether the number of remaining unallocated active S-boxes is an integer multiple of K. If so, assign all remaining S-boxes to the active group of size K; if not, stop the recursion for the current size of active group and update the value of the corresponding dimension in the active group combination vector;

[0063] 3) When all active groups of all sizes have been processed, check whether all active S-boxes have been allocated and there is at least one active group with a maximum size of K; if so, add the current active group combination vector to the result list.

[0064] Furthermore, a necklace enumeration algorithm with fixed content is used to calculate the number of different necklaces under the same necklace configuration as the size of the corresponding subdivision space.

[0065] Furthermore, the cryptographic algorithm is Ascon algorithm or Keccak algorithm.

[0066] A cryptographic algorithm security assessment method is characterized by dividing the cryptographic analysis search space based on the above method to obtain multiple subdivision spaces; then exhaustively searching each subdivision space based on a set target task, and then evaluating the security of the cryptographic algorithm for the target task based on the search results of each subdivision space.

[0067] Furthermore, the target tasks are differential cryptanalysis, linear cryptanalysis and collision attack analysis.

[0068] A server, characterized in that it includes a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the above method.

[0069] A computer-readable storage medium stores a computer program thereon, wherein the computer program implements the above method when executed by a processor.

[0070] The advantages of the present invention are as follows:

[0071] 1. Systematic and Complete: The present invention provides a systematic approach to partition the search space, ensuring that all possible solutions are considered without missing any potential solution.

[0072] 2. Scalability: Even for the case with a large number of active S-boxes (e.g., n ≥ 26), our method can effectively partition and manage the search space, overcoming the limitations of existing methods.

[0073] 3. Computational efficiency: By dividing the large search space into smaller subspaces, this method significantly improves search efficiency. For some combinations, the search time can be reduced to one-third or even half of the original time.

[0074] 4. Progress Indication: Since the size of each subspace can be calculated exactly, this method provides a clear progress indication, making it possible to evaluate the completion of the search.

[0075] 5. Generality: Although this method was developed in the context of cryptanalysis, its basic principles can be applied to various fields that require processing large search spaces.

[0076] 6. Practical application results: In practical applications, this method has been successfully used to discover improved cryptographic structures, such as differential collision characteristics and Meet-in-the-Middle structures, thereby achieving more effective attacks on cryptographic algorithms. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] Figure 1 An example of an active pattern with 8 S-boxes and its 8 equivalent patterns.

[0078] Figure 2 Examples of active groups and active beads.

[0079] Figure 3 An example of a necklace with 15 beads corresponding to the combination [n1=3,n2=3,n3=1,n4=0,n5=1].

[0080] Figure 4 Flowchart of search space partitioning method and application. DETAILED DESCRIPTION

[0081] The present invention will be described in further detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not used to limit the scope of the present invention.

[0082] Explanation of terms

[0083] Automated search: The process of using a computer program to automatically explore a large search space to find solutions that meet specific criteria.

[0084] Necklace problem: A problem in combinatorics that studies equivalence classes among circular permutations, where permutations obtained by rotation are considered equivalent.

[0085] S-box: Abbreviation for Substitution box, a nonlinear substitution component in cryptographic algorithms that maps input bit strings to output bit strings to provide obfuscation properties.

[0086] The χ function is a typical bit-level nonlinear transformation, commonly used in symmetric cryptographic structures. It introduces nonlinearity through logical operations between local bits, typically performing an XOR operation on each bit and a NOT AND operation on adjacent bits. The χ function is simple and hardware-friendly, making it widely used as the primary nonlinear component in algorithms such as Keccak (SHA-3) and Ascon.

[0087] Active S-boxes: In differential cryptanalysis, an S-box is called an "active S-box" if the differential of its inputs is non-zero. The number and distribution of active S-boxes have a significant impact on the security of cryptographic algorithms.

[0088] Active pattern: In cryptanalysis, it describes the distribution of active S-boxes in the differential signature.

[0089] Active group: A continuous sequence of active S-boxes.

[0090] combination: A vector describing the distribution of active groups of different sizes.

[0091] Symbols and functions represent:

[0092] F2={0,1}: represents a binary domain, that is, a set containing only 0 and 1.

[0093] C(n,k): represents the number of combinations of selecting k elements from n elements. The calculation formula is

[0094] Represents the smallest integer greater than or equal to x, rounded up to the nearest integer.

[0095] Represents the largest integer less than or equal to x, rounded to the floor.

[0096] Euler function, which represents the number of positive integers less than or equal to d and coprime to d.

[0097] n: represents the total number of active S-boxes.

[0098] K: represents the maximum number of active S-boxes allowed in the active group.

[0099] n i : represents the number of active groups of size i, where i∈{1,2,…,K}.

[0100] n K : Specifically refers to the number of active groups of size K.

[0101] ∑: summation symbol, e.g. represents i·n from i=1 to i=K i The sum of .

[0102] b i : denotes the beads representing the active group of size i, where i ≥ 0. In particular, b0 denotes an inactive bead.

[0103] Indicates b i The number of beads. For i>0, Equal to n i .

[0104] m: represents the total number of beads in the necklace.

[0105] m1: represents the maximum number of beads selected in the further partitioning of the difficult subset, usually 2 or 3.

[0106] represents the number of ways to assign m / d positions to K+1 beads, so that each bead i can be used

[0107] d|m: means d divides m, that is, m is a multiple of d.

[0108] N: represents the total number of single-round function S-boxes of the cryptographic algorithm to be analyzed.

[0109] L: represents the total length of the S-box arrangement. In the cyclic structure, L=N.

[0110] This paper proposes a method for partitioning the cryptanalysis search space based on the necklace enumeration algorithm. This method systematically partitions the large search space by using the necklace generation problem in combinatorial mathematics. The method includes the following key steps:

[0111] 1. Preliminary division based on the number of active S-boxes

[0112] First, for cryptographic algorithms that use the chi-box function to design S-boxes, particularly Ascon and Keccak, this paper preliminarily partitions the search space based on the number n of active S-boxes in the algorithm. For a cryptographic algorithm with N S-boxes, the overall search space is the combination of all active patterns with the number of active S-boxes from 1 to N.

[0113] Among them, there are n active S-box subspaces, n∈{1,2,…,N}, with a total of C(N,n) active modes, each representing 2 2n Due to the translation invariance of the cryptographic algorithm, rotating an active pattern will produce N equivalent patterns, so the total number of different active patterns is reduced by approximately N times.

[0114] After a preliminary partitioning, the overall search space is divided into N subspaces of varying sizes (the size is the number of active patterns contained in the subspace). Each subspace contains n active patterns with n active S-boxes (n∈{1,2,…,N}). The number of different active patterns is approximately C(N,n) / N. A subspace contains approximately C(N,n) active patterns. All active patterns in the same subspace share a common characteristic: they contain n active S-boxes.

[0115] 2. Further division based on active groups

[0116] For each active pattern subspace with n active S-boxes, this paper introduces the concept of "active groups" to group adjacent active S-boxes. An active group is a sequence of i consecutive active S-boxes in an active pattern of n active S-boxes, where i∈{1,2,…,K}, K is the maximum number of S-boxes allowed in an active group, and K≤n. Active groups are separated by at least one inactive S-box.

[0117] The concept of active groups can be elaborated in the following way:

[0118] (1) Formal definition of active groups:

[0119] -Given an active pattern with N S-boxes, where 1 represents an active S-box and 0 represents an inactive S-box;

[0120] - An active group is a sequence of consecutive 1s surrounded by 0s on both ends (or located at the boundaries of the pattern);

[0121] -The size of an active group is the number of consecutive 1s in that active group.

[0122] (2) Characteristics of the active group:

[0123] -Each active group contains at least 1 active S-box and at most K active S-boxes;

[0124] - There is at least one inactive S-box between two adjacent active groups;

[0125] -Activity groups can cross pattern boundaries (because patterns are cyclic);

[0126] -A pattern with n active S-boxes can contain multiple active groups of different sizes.

[0127] (3) Representation of active groups:

[0128] - For each active group of size i, i.e., an active group containing i active S-boxes, the present invention uses n i Indicates the number of active groups of this size;

[0129] - An active pattern can be represented by the vector [n1,n2,…,n K ] to represent the distribution of its active groups.

[0130] (4) Examples of active groups are Figure 2 As shown:

[0131] Consider an active mode with N = 32 S-boxes and n = 17 active S-boxes. The following shows a specific example of active mode 01, where active S-boxes are marked as 1 and inactive S-boxes are marked as 0, to illustrate the distribution of active groups:

[0132] "10111000101000011111001100110101"

[0133] exist Figure 2 In the active pattern, the distribution of active S-boxes forms the following active groups:

[0134] - Three active groups of size i=1: distributed at position 8, position 12 and position 24. Note that the positions here are counted starting from 0;

[0135] - three active groups of size i=2: positions 10-11, positions 16-17, and positions 28-29;

[0136] - an active group of size i=3: positions 1-3;

[0137] - an active group of size i=5: positions 18-22;

[0138] Therefore, the active group distribution of this active pattern can be expressed as [n1=3, n2=3, n3=1, n4=0, n5=1], where K=5.

[0139] By introducing the concept of active groups, the present invention can further divide the subspace with n active S-boxes into smaller subdivision spaces, each of which corresponds to a specific active group distribution, that is, Figure 2 The following section formally defines the active group distribution as the active group combination and introduces an algorithm for generating all subdivisions of a small space (i.e., active combinations).

[0140] This partitioning method greatly reduces the size of the search space, making it possible to search efficiently even for situations with a large number of active S-boxes.

[0141] 3. Definition and Generation of Active Group Combinations

[0142] To specifically illustrate how to further divide the subspace of an active pattern with n active S-boxes into subdivision spaces, the present invention defines "active group combinations" to represent subdivision spaces. Given K (referring to the maximum group size of active patterns), each active group combination corresponds to a subdivision space, and is represented by a vector [n1,n2,…,n K ] indicates that, as defined above, n i Specifies the number of active groups of size i. The combination vector corresponding to each subdivision space has the following characteristics:

[0143] -n K ≥1, indicating that the active patterns in the segmented space all contain at least one active group with the maximum size (i.e., K);

[0144] -n i ≥0, where i∈{1,2,…,K-1}, indicating that there can be multiple or no active groups of other sizes;

[0145] - Ensure that the total number of active S-boxes is n.

[0146] To systematically illustrate how to partition a subspace with n active S-boxes (i.e., the set of all active patterns determined by parameters n, N) into a series of vectors [n1, n2, ..., n K ] represents the process of subdividing the space, the present invention adopts a recursive backtracking algorithm to enumerate the vectors [n1,n2,…,n K ], then the corresponding subspaces are divided by generating all the subdivision spaces.

[0147] Given parameters n, K, N (where K ≤ n), the basic idea of ​​the algorithm is to assign the possible number of active groups of each size from small to large, that is, to determine n1, n2, ... n K The specific value of ensures that the total number of active S-boxes is n, that is And there is at least one active group with a maximum size of K, that is, n K ≥1. The specific implementation is divided into the following steps:

[0148] First, the algorithm initializes an empty list to store the results and creates an initial active group combination, with the corresponding vectors all filled with 0, i.e. [n1=0,n2=0,…,n K =0].

[0149] Then, we start to generate the vectors [n1,n2,…,n K ] process. In the recursive process, the algorithm tries to assign 0 to the maximum possible number of active groups, i.e., n, for each size of active group (i.e., each branch), i.e., the number of active S-boxes is i. Starting from the minimum size 1, the algorithm tries to assign 0 to the maximum possible number of active groups, i.e., n i ≥ 0. For each possible number of allocations, the algorithm updates the current combination vector and recursively processes the next size of the active group.

[0150] When processing the largest active group, that is, the active group of size K, the algorithm checks whether the number of remaining unassigned active S-boxes is an integer multiple of K. If so, all remaining S-boxes are assigned to the active group of size K; if not, this branch does not produce a valid active group combination, and the recursion for the current active group size is stopped.

[0151] When all active group sizes have been processed, the algorithm checks whether all active S-boxes have been allocated (remaining 0) and there is at least one active group of maximum size K (the number of groups of size K ≥ 1). If these conditions are met, the current combination vector is added to the result list.

[0152] The following is a standard pseudocode representation of the algorithm:

[0153]

[0154]

[0155] Through this recursive method, the present invention can systematically generate vectors corresponding to all active group combinations that meet the constraints. In other words, for all possible n and K, that is, K≤n, n≤N, all active group combination vectors [n1,n2,…,n K ] together define a complete partition of the subspace with n active S-boxes.

[0156] For example, when n=5, K=3, and N≥5, the vectors of all combinations generated by the algorithm are listed as follows:

[0157] -[n1=5,n2=0,n3=0]: indicates that the active group combination includes 5 active groups of size 1, and all active modes in the corresponding segmentation space have and only have 5 active groups of size 1.

[0158] -[n1=3,n2=1,n3=0]: indicates that this active group combination includes three active groups of size 1 and one active group of size 2. All active patterns in the corresponding segment space have only three active groups of size 1 and one active group of size 2. There are no other active groups.

[0159] -[n1=1,n2=2,n3=0]: indicates that the active group combination includes one active group of size 1 and two active groups of size 2, and all active patterns in the segmented space also have corresponding characteristics.

[0160] -[n1=2,n2=0,n3=1]: indicates that the active group combination includes two active groups of size 1 and one active group of size 3. Similarly, all active patterns in the segmented space also have corresponding characteristics.

[0161] -[n1=0,n2=1,n3=1]: indicates that the active group combination includes one active group of size 2 and one active group of size 3. Similarly, all active patterns in the segmented space also have corresponding characteristics.

[0162] The vector of each active group combination represents a specific subdivision space. All active patterns in this subdivision space have the number of active groups specified by the specific vector. Therefore, each subdivision space does not intersect, and the union of the subdivision spaces represented by these vectors constitutes a complete subspace with n active S-boxes.

[0163] 4. Active mode counting based on necklace enumeration

[0164] Step 3: The subspace represented by the parameters n,N, i.e., the subspace of all active patterns with n active S-boxes among N S-boxes, is further divided into the active group combination vectors [n1,n2,…,n K ] defines a subdivision space, thus completing the complete division of the word space. To determine the number of active patterns contained in a specific subdivision space, the present invention uses the “fixed content necklace enumeration” algorithm to calculate each active group combination vector [n1, n2, ..., n K ] in the active mode.

[0165] In this approach, each active group in the active group combination is considered a bead, called an "active bead," and the inactive S-boxes that separate these active groups are also considered beads, called "inactive beads." Therefore, any active pattern in the subdivision space corresponding to the active group combination can be conceptualized as a necklace composed of active beads and inactive beads.

[0166] Specifically, this invention abstracts the active patterns in the subdivided space into a necklace with fixed types and numbers of beads in the permutation and combination, and uses the necklace enumeration algorithm to calculate the number of active patterns in each subdivided space, thereby giving the size of the corresponding subdivided space. The specific steps are as follows:

[0167] (1) Definition of beads:

[0168] - Active beads: include the active group and the inactive S-box in front of it. That is, each active group of size i corresponds to one active bead, and the active bead corresponding to the active group of size i contains i+1 S-boxes (including the inactive S-box in front of the active group).

[0169] - Inactive beads: represent inactive S-boxes that are not associated with any active group.

[0170] exist Figure 2 There is also a diagram of the beads, including active beads and inactive beads.

[0171] (2) Necklace means:

[0172] -Set b i represents the active bead corresponding to an active group of size i, where i ≥ 0, and includes i + 1 S-boxes, i.e., the i active S-boxes and the inactive S-box at the front of the active group. In particular, b0 represents an inactive bead, i.e., an inactive S-box that has no relationship with any active bead.

[0173] -set up Indicates b i The number of beads. When i>0, Equal to n i , that is, the active group combination vector [n1,n2,…,n K ] in the .

[0174] -For the active group combination vector [n1,n2,…,n K ], the necklace configuration corresponding to the active mode in the subdivision space can be recorded as in Indicates the number of inactive beads.

[0175] Taking N=64 as an example, for n=27, K=3:

[0176] -The necklace configuration of the active mode in the subdivision space corresponding to the active group combination vector [n1=27] is in

[0177] -The necklace configuration of the active mode in the subdivision space corresponding to the active group combination vector [n1=9,n2=6,n3=2] is in

[0178] Figure 3 An example of necklace representation of active patterns in the subdivision space corresponding to the active group combination vector [n1=3,n2=3,n3=1,n4=0,n5=1] is given. In this example, all active patterns in the subdivision space have 32 S-boxes, of which n=17 are active S-boxes.

[0179] As you can see, the active groups and inactive S-boxes of all active modes in the segmented space correspond to 15 beads. Among them, green beads represent active groups with 1 active S-box, which is 3 in total; brown beads represent active groups with 2 active S-boxes, which is also 3 in total; blue beads represent active groups with 3 active S-boxes, which is 1 in total; purple beads represent active groups with 5 active S-boxes, which is 1 in total; and white beads represent inactive beads, representing all inactive S-boxes except the inactive S-boxes contained in the active groups, which is 7 in total.

[0180] Therefore, the final configuration of this necklace is expressed as

[0181] (3) Necklace enumeration algorithm:

[0182] -Given the active group combination vector [n1,n2,…,n K ], the active modes in the corresponding subdivision space all follow the same necklace configuration In other words, given a necklace configuration, if we can calculate the number of necklaces that satisfy the same necklace configuration, we can get the corresponding number of active modes and then determine the size of the segmentation space.

[0183] The present invention uses the "fixed content necklace enumeration" algorithm in combinatorial mathematics to calculate the number of different necklaces under the same necklace configuration, thereby calculating the size of the corresponding subdivision space.

[0184] -The algorithm is based on Burnside's lemma and Pólya's counting theorem, taking rotational symmetry into account.

[0185] -In a specific implementation, the present invention uses a recursive method to generate all possible necklaces and eliminates rotationally equivalent necklaces by merging equivalence classes.

[0186] (4) Counting formula:

[0187] - For a necklace with m beads, there are The number of different necklaces can be calculated using the following formula:

[0188]

[0189] in:

[0190] - is the Euler function, which represents the number of positive integers less than or equal to d and coprime to d;

[0191] -P is the polynomial coefficient, which means The number of ways to allocate positions to K+1 beads, so that each bead i can be used Second-rate;

[0192] -d|m means d divides m.

[0193] This counting formula is based on Burnside's lemma and Pólya's counting theorem. The calculation process and significance are explained in detail below:

[0194] a. Theoretical basis of the formula

[0195] Burnside's lemma states that under a permutation group G, the number of equivalence classes is equal to the average number of fixed points under all permutations. In the necklace problem, G is the rotation group, and since the necklace is circular, rotation operations produce equivalent permutations.

[0196] The Pólya Counting Theorem further extends the Burnside Lemma, providing a systematic method for counting the number of equivalence classes. When applied to necklace enumeration, the invention focuses on the different arrangements of beads under rotation operations.

[0197] b. Parameter explanation

[0198] -m: indicates the total number of beads in the necklace,

[0199] -d|m: means d divides m, and the sum is performed on all factors d of m;

[0200] - Euler function, calculates the number of positive integers less than or equal to d and coprime to d.

[0201] For example:

[0202] - Indicates that The number of ways to assign positions to K+1 beads;

[0203] This value can be calculated using the following polynomial coefficient formula:

[0204]

[0205] Note that the premise for this formula to be calculated correctly is And each bi The beads just appeared Second-rate.

[0206] c. Calculation Example

[0207] Consider a simple example: n = 5, K = 3, N = 64, where one active group combination vector is [n1 = 2, n2 = 0, n3 = 1], meaning that the active pattern in the corresponding segment space has two active groups of size 1 and one active group of size 3. In this example, we first calculate the corresponding necklace configuration based on the segment space vector, and then use the formula described above to calculate the number of different active patterns in the segment space.

[0208] -First calculate m:

[0209] (inactive beads);

[0210] m = N - 8 + 2 + 1 = N - 5 = 59 (total number of beads);

[0211] -The factors of m include: 1 and 59 (m is a prime number);

[0212] - (because 59 is a prime number);

[0213] - For d=1:

[0214] - For d=59:

[0215] (Note: This assumes When d=59, both are 0, and more complex calculation is actually required);

[0216] -According to the formula:

[0217] Therefore, in the subdivision space where the active group combination vector is [n1=2, n2=0, n3=1], there are about 30 different active modes in total, taking rotational symmetry into account.

[0218] d. Intuitive understanding of the formula

[0219] This formula essentially counts the number of different necklace arrangements under rotational symmetry. The part represents the average value, and The other part counts the number of permutations that remain invariant under various rotation operations.

[0220] In particular, d can be understood as the step size of the rotation. When d = 1, the case of no rotation is considered; when d > 1, the case of rotating the necklace is considered. The arrangement remains unchanged after the positions.

[0221] Through this necklace enumeration method, the present invention can accurately count the number of different active patterns in each subdivision space represented by the active group combination, thereby estimating the size of each subdivision space. This counting method takes into account rotational symmetry, ensuring that the present invention does not double-count equivalent active patterns.

[0222] Through this systematic partitioning method, the present invention first divides a large search space, i.e., a search space consisting of all active patterns with N S-boxes, where n are active S-boxes, into subspaces based on the number n of active S-boxes, where each active pattern in the subspace has n active S-boxes.

[0223] Then, the subspace is further divided into subdivision spaces by active group combinations, and the number of active patterns in each subdivision space is calculated using the necklace enumeration algorithm.

[0224] In this way, the large, non-exhaustible search space is divided into subdivisions that can be processed in a reasonable amount of time. This approach ensures the completeness of the search while providing a clear indication of progress.

[0225] 5. Automatic search of segmented spaces corresponding to necklace configurations

[0226] Once the size of each subdivision is determined through the necklace enumeration algorithm, the next step is to exhaustively search each subdivision. Each necklace configuration corresponds to a subdivision. For each subdivision, the present invention uses automated search tools to model and solve. By building a search model for each subdivision and solving the automated search model, the present invention determines whether the target solution exists in the corresponding subdivision.

[0227] This section will introduce how to transform the problem of traversing the subdivision space into an automated search problem based on the concept of necklace configuration, and how to efficiently search all possible solutions.

[0228] (1) Formal definition of the search problem:

[0229] -Given necklace configuration For the active patterns in the corresponding segmented space, the present invention searches out all active patterns with necklace configurations by writing relevant constraints into the automatic search model. In other words, the active patterns searched out by the automatic search model have active groups of size i;

[0230] - Depending on the search problem and the automation tool chosen, map the number of S-boxes in the active pattern to a variable and define whether each S-box is active (value 1) or inactive (value 0);

[0231] The goal of the search problem is to find all active patterns that satisfy the active group combination conditions. Specifically, given an active group combination vector [n1,n2,…,n K ], the active modes in the corresponding subdivision space all follow the same necklace configuration That is, the number of active groups of size i in all active modes is The target of the search is all such active modes.

[0232] (2) Constraint modeling:

[0233] - Constraints based on necklace configuration: ensure that the distribution of active S-boxes satisfies the specified distribution of the number of active groups;

[0234] - Continuity constraint: ensures that each active group consists of consecutive active S-boxes;

[0235] -Separation constraint: ensure that there is at least one inactive S-box between adjacent active groups;

[0236] - Cyclic constraints: Consider the cyclic nature of activity patterns and handle activity groups that cross boundaries.

[0237] (3) Application of automated search tools:

[0238] - The present invention converts the above constraints into a form suitable for processing by automated search tools;

[0239] - For each active group of size i, the present invention introduces n i Position variable p i,j (j from 1 to n i ), indicating the starting position of the active group;

[0240] - Auxiliary variables are introduced to represent the state of each S-box (active or inactive) and the relationship between active groups.

[0241] (4) Mathematical representation of constraints:

[0242] - Position constraint: Ensure that the positions of all active groups are within the valid range, i.e. p i,j ∈{0,1,…,N-1};

[0243] - Non-overlapping constraint: For any two different active groups, they cannot overlap, that is:

[0244] For any (i,j)≠(i′,j′), if p i,j <p i′,j′ , then p i,j +i≤p i′,j′ (Special handling is required for loop situations);

[0245] -Separation constraint: There is at least one inactive S-box between adjacent active groups, which can be expressed as:

[0246] For any adjacent active groups (i, j) and (i′, j′), if p i,j <p i′,j′ , then p i,j +i+1≤p i′,j′ ;

[0247] - S-box state association: associate the active state of the S-box with the active group position, for each S-box position k (k∈{0,1,...,N-1}): S k = 1 if and only if there exists an active group (i, j) such that p i,j ≤k <p i,j +i.

[0248] (5) Coding optimization strategy:

[0249] Symmetry breaking: Due to the rotational symmetry of the necklace, when building the model and encoding the S-box, the present invention can fix the position of a certain active group (usually the largest active group) to reduce the search space;

[0250] -Specified location: For a subdivided space containing multiple (more than two) large active groups of the same size, the present invention can specify the locations of these active groups in a small range, further reducing redundant searches;

[0251] - Pre-calculated constraints: Based on the characteristics of the necklace structure, certain constraints that must be true are pre-calculated.

[0252] (6) Search algorithm implementation:

[0253] -Convert all constraints into an input format acceptable to automated search tools;

[0254] - For a given necklace configuration, generate an instance of the search problem;

[0255] -Use automated search tools to solve the instance and obtain all solutions that satisfy the constraints;

[0256] - Convert each solution back to the corresponding active mode;

[0257] - If necessary, perform post-processing to ensure the accuracy and completeness of the results.

[0258] (7) Parallel search strategy:

[0259] - Since the searches between different necklace configurations are independent of each other, the present invention can process multiple configurations in parallel;

[0260] -For particularly complex configurations, the search space can be further divided and multi-threaded or distributed computing methods can be adopted;

[0261] -Design dynamic task allocation strategies to ensure efficient utilization of computing resources.

[0262] (8) Result verification and integration:

[0263] - Validate the search results to ensure that each active pattern found actually satisfies the given necklace configuration;

[0264] - For multiple solutions under the same configuration, check whether there is rotational equivalence between them;

[0265] -Integrate all valid solutions into the result set, providing a complete set of candidate active patterns for cryptanalysis.

[0266] Through this systematic, automated search approach, the present invention can efficiently explore the subdivided space corresponding to each necklace configuration, finding all active patterns that meet the conditions. This approach combines the theoretical advantages of necklace enumeration with the practicality of automated search tools, making it possible to thoroughly explore large search spaces.

[0267] The main methods and corresponding application flowcharts proposed by the entire invention are as follows: Figure 4 shown.

[0268] To fully understand the practicality and importance of this invention, it's important to highlight a core challenge facing the field of cryptanalysis: in symmetric cryptanalysis, finding key cryptographic structures (such as differential paths, linear features, and collision structures) is fundamental to effective attacks. However, as the complexity of cryptographic algorithms increases, the search space for relevant features grows exponentially. Traditional automated search methods often run into resource exhaustion and solution stagnation when faced with large numbers of active S-boxes (e.g., n ≥ 26), making it difficult to obtain results within an acceptable timeframe. This severely hinders the in-depth development of cryptographic security assessments.

[0269] The present invention proposes a solution to the above-mentioned problem. By introducing the active group and necklace enumeration theory, the originally unmanageable huge search space is divided into multiple subspaces with clear structure, mutual independence and moderate size, so that each subspace can be exhaustively searched by automated tools such as SAT and SMT within a reasonable time range.

[0270] This division is based on solid combinatorial mathematics theory (such as Pólya's counting theorem and Burnside's lemma), has structural integrity and non-overlap, avoids repeated searches and wastes resources, and provides clear progress indicators and resource allocation strategies, significantly improving search efficiency and controllability.

[0271] Specifically, in practical applications, the search space partitioning method of the present invention can be widely applied to the following cryptanalysis tasks:

[0272] Differential Cryptanalysis: The system searches for differential paths with specific active S-box patterns (applicable to algorithms such as Keccak and Ascon), which is particularly effective when the number of active S-boxes is large.

[0273] Linear cryptanalysis: Assists in constructing paths that satisfy specific linear mask distributions, improving the efficiency of linear feature searches;

[0274] Collision attack analysis: Constructing intermediate state collision paths in hash functions to improve the detection rate of collision paths;

[0275] Meet-in-the-Middle attack: Improves matching speed and accuracy by hierarchically dividing the front and back search spaces.

[0276] Cryptographic Algorithm Design Evaluation: This is used to systematically explore attack paths during the design phase of a new algorithm and to assist in evaluating its resistance to differential / linear analysis.

[0277] In actual research, this invention has been successfully applied to the structural security analysis tasks of multiple cryptographic algorithms. Experimental results show that when dealing with complex path construction, the search time can be shortened from several days to several hours, greatly improving the completion and scalability of cryptographic analysis tasks, and providing a systematic and effective support tool for cryptographic research and engineering practice.

[0278] While specific embodiments of the present invention have been disclosed for illustrative purposes, intended to facilitate understanding and implementation of the present invention, those skilled in the art will appreciate that various substitutions, variations, and modifications are possible without departing from the spirit and scope of the present invention and the appended claims. Therefore, the present invention should not be limited to the disclosure of the preferred embodiments, and the scope of protection claimed in the present invention shall be determined by the scope of the claims.

Claims

1. A method for partitioning a cryptanalysis search space based on active groups and necklace enumeration, comprising the following steps: 1) For a cryptographic algorithm that uses the χ function to design S-boxes, a search space is preliminarily partitioned according to the number n of active S-boxes in the cryptographic algorithm to obtain N subspaces of varying sizes; each subspace includes an active pattern with n active S-boxes, and the search space includes C(N,n) active patterns, where N is the total number of S-boxes in the cryptographic algorithm, and n∈{1,2,…,N}; 2) Grouping the active S-boxes in each subspace to obtain several active groups; the active group is a continuous sequence of i active S-boxes in the active pattern; where n i is the number of active groups containing i active S-boxes, i∈{1,2,…,K}, K is the maximum number of S-boxes allowed in an active group, K≤n, and there is at least one inactive S-box separating each active group; i The space corresponding to the active group combination containing i active S-boxes is taken as a subdivision space, and the active group combination vector corresponding to each subdivision space is [n1,n2,…,n K ]; 3) Each active group in each subdivided space is called an active bead, and the inactive S-boxes separating the active groups are called inactive beads; any active pattern in the subdivided space is converted into a necklace consisting of the active beads and inactive beads it contains, and the active group combination vector [n1,n2,…,n K ]The corresponding necklace configuration is Among them, b i represents the active bead corresponding to the active group containing i active S-boxes, including i+1 S-boxes, i.e., i active S-boxes and 1 inactive S-box in front of the active group, i ≥ 0; b0 represents the inactive bead; Indicates b i The number of , i∈{1,2,…,K}; 4) Calculate the number of different necklaces under the same necklace configuration as the size of the corresponding subdivision space.

2. The method according to claim 1, characterized in that The method for exhaustively searching each subdivision space based on the set target task is: 1) Formal definition of the search problem: For a given necklace configuration For the active mode in the corresponding segment space, a variable is generated according to the number of S-boxes contained in each active mode and the value of each dimension in the variable is determined, where the dimension corresponding to the active S-box is 1 and the dimension corresponding to the inactive S-box is 0; 2) For each active group of size i, introduce n i Position variable p i,j Indicates the starting position of the active group, j = 1 ~ n i ; Introduction Auxiliary variables to represent the state of each S-box and the relationship between active groups; 3) Set constraints, including: Position constraint: Ensure that the positions of all active groups are within the valid range, i.e. p i,j ∈{0,1,…,N-1}; Non-overlapping constraint: For any two different active groups p i,j , p i′,j′ , (i, j) ≠ (i′, j′), if p i,j <p i′,j′ , then p i,j +i≤p i′,j′ ; Separation constraint: For any adjacent active groups (i, j) and (i′, j′), if p i,j <p i′,j′ , then p i,j +i+1≤p i′,j′ ; S-box state association: associate the active state of the S-box with the active group position. For the k-th position S of the S-box k , if and only if there exists an active group (i, j) such that p i,j ≤k <p i,j +i, then S k =1; k∈{0,1,...,N-1}; 5) Set encoding optimization strategy: During the S-box encoding process, the location of the target active group is fixed to reduce the search space; the locations of multiple large active groups of the same size are specified; and the constraints that must be true are pre-calculated based on the necklace structure. 6) Convert all constraints into an input format acceptable to the automated search tool; generate an instance of the search problem for a given necklace configuration; use the automated search tool to solve the instance and obtain all solutions that satisfy the constraints; convert each solution back to the corresponding active mode; 7) Verify the search results to ensure that each active pattern found actually satisfies the given necklace configuration; for multiple solutions under the same configuration, check whether there is a rotation equivalence relationship between them; integrate all valid solutions into the result set to provide a complete set of candidate active patterns for cryptanalysis.

3. The method according to claim 2, characterized in that The target active group is the largest active group.

4. The method according to claim 1, 2 or 3, characterized in that: The method of grouping the active S-boxes in each subspace to obtain several active groups is as follows: 1) Initialize a result list and create an initial active group combination. The corresponding active group combination vector is filled with 0, that is, [n1=0,n2=0,…,n K =0]; 2) Start generating the vectors [n1,n2,…,n K ]; In the recursive process, for each size of active group, starting from the minimum size 1, try to allocate 0 to the maximum possible number of active groups. For each possible allocation number, update the current combination vector and recursively process the next size of active group; when processing the largest size active group, that is, the active group of size K, check whether the number of remaining unallocated active S-boxes is an integer multiple of K. If so, assign all remaining S-boxes to the active group of size K; if not, stop the recursion for the current size of active group and update the value of the corresponding dimension in the active group combination vector; 3) When all active groups of all sizes have been processed, check whether all active S-boxes have been allocated and there is at least one active group with a maximum size of K; If so, add the current active group combination vector to the result list.

5. The method according to claim 1, 2 or 3, characterized in that: The fixed-content necklace enumeration algorithm is used to calculate the number of different necklaces under the same necklace configuration as the size of the corresponding subdivision space.

6. The method according to claim 1, characterized in that The cryptographic algorithms are Ascon algorithm and Keccak algorithm.

7. A cryptographic algorithm security assessment method, characterized in that: The cryptographic analysis search space is divided based on the method described in claim 1 to obtain multiple subdivision spaces; then, an exhaustive search is performed on each subdivision space based on the set target task, and then the security of the cryptographic algorithm for the target task is evaluated based on the search results of each subdivision space.

8. The method according to claim 7, characterized in that The target tasks are differential cryptanalysis, linear cryptanalysis and collision attack analysis.

9. A server, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program comprises instructions for executing the method according to any one of claims 1 to 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.