Optimal neural network difference divider searching method based on password structure

By improving the ISRN neural network structure and adaptive evolutionary optimizer, combined with the cryptographic structure to design the dataset format, the versatility and efficiency problems of the existing neural network differential distinguisher are solved, and differential distinction effects with higher accuracy and a higher number of rounds are achieved.

CN120763756APending Publication Date: 2025-10-10GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510988736.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing neural network differential discriminators lack versatility in construction, have a single neural network structure, lack adaptability in data format construction, and the differential search of evolutionary algorithms has deficiencies in accuracy and efficiency.

Method used

An improved ISRN neural network structure is constructed, the dataset format is designed in combination with the password structure, and differential search is performed through an adaptive evolutionary optimizer. The construction framework of the neural network differential discriminator is optimized, including the design of the initial convolutional layer, iterative layer and prediction layer. The SE module is introduced to enhance feature attention, and the crossover operation and mutation probability are adaptively adjusted to improve the efficiency of differential search.

Benefits of technology

The accuracy and number of rounds of the neural network differential distinguisher are improved, a general analysis method for various password structures is provided, and the effect of password analysis is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120763756A_ABST
    Figure CN120763756A_ABST
Patent Text Reader

Abstract

The invention discloses an optimal neural network differential classifier searching method based on a cryptographic structure. An existing method is improved from the three aspects of design of an ISRN neural network, data set format optimization based on a password structure, self-adaptive evolutionary optimizer construction and candidate difference set search. In the ISRN neural network design part, initial convolution layers with different convolution kernel sizes are combined with SE module adaptive screening, so that the utilization rate of the neural network to feature information is improved; in the data set format optimization part based on the password structure, more features in the differential propagation process can be provided for the data set input format of the password structure; in the self-adaptive evolutionary optimizer construction and candidate difference set search part, the information entropy evaluation is introduced, and the interlace operation and mutation probability are dynamically adjusted in different stages. The global search capability and convergence capability of the evolutionary optimizer are ensured, the search efficiency and convergence speed of the algorithm are improved, and falling into a locally optimal solution is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular to a method for searching an optimal neural network differential discriminator based on a cryptographic structure. Background Art

[0002] Differential analysis is an effective method for attacking iterative block ciphers and is also one of the important indicators for measuring the security of a block cipher. Attackers identify algorithm weaknesses by studying the non-uniformity of the differential statistical characteristics generated by the block cipher during multiple rounds of iteration, distinguishing the block cipher from random permutations. Deep learning technology has strong nonlinear fitting capabilities and can more efficiently analyze the differential distribution patterns in cryptographic algorithms. Gohr [1] For the first time, deep learning was combined with traditional differential cryptanalysis methods to construct a neural network differential distinguisher for the SPECK 32 / 64 algorithm and perform a key recovery attack based on it.

[0003] The neural network differential discriminator search method needs to consider three aspects: neural network design, data set construction and differential selection strategy. In terms of neural network design, Jain et al. [2] Use a multilayer perceptron neural network to build a discriminator and analyze the lightweight block cipher PRESENT. Bellini et al. [3] The neural network differential discriminator of TEA and RAIDEN was constructed using a feedforward convolutional neural network. In terms of dataset construction, Benamira et al. [4] An in-depth explanation of Gohr's work is provided, and an alternative strategy combining traditional machine learning algorithms with differential distribution tables is proposed. as a dataset format. Chen et al. [5] A new neural network differential discriminator that considers multiple ciphertext pairs simultaneously is proposed, which takes into account the derivative features between multiple ciphertext pairs, thereby improving the prediction accuracy of the discriminator. In terms of differential selection strategy, Hou et al. [6] Using traditional analytical methods, a high-probability differential search is performed based on a SAT / SMT solver. Bellini et al. [7] A differential search method based on evolutionary algorithm is proposed to select appropriate input differentials for the discriminator.

[0004] The above-mentioned neural network differential discriminator construction method has made contributions in different aspects, but there are still certain problems: the structure of the neural network is too simple, and there is a lack of connection between different modules; the existing data format construction is still designed for a single password and lacks adaptability to different password structures; the differential search based on the evolutionary algorithm still has defects in search accuracy and efficiency due to its single crossover operation and constant mutation probability.

[0005] References are as follows:

[0006] [1]Gohr A.Improving attacks on round-reduced speck32 / 64 using deeplearning[M] / / BOLDYREVA A,MICCIANCIO D. Advances in Cryptology – CRYPTO 2019:Vol. 11693. Cham: Springer International Publishing,2019: 150-179。

[0007] [2]Jain A,Kohli V,Mishra G. Deep learning based differentialdistinguisher for lightweight block ciphers[J]. arxiv preprint arxiv:2112.05061,2021。

[0008] [3]Bellini, Emanuele, and Matteo Rossi. "Performance comparisonbetween deep learning-based and conventional cryptographic distinguishers."Intelligent Computing: Proceedings of the 2021 Computing Conference, Volume3. Springer International Publishing, 2021。

[0009] [4]Benamira A,Gerault D,Peyrin T,et al. A deeper look at machinelearning-based cryptanalysis[M] / / CANTEAUT A,STANDAERT F X. Advances inCryptology-EUROCRYPT 2021: Vol. 12696. Cham: Springer InternationalPublishing,2021: 805-835。

[0010] [5]Chen Y, Yu H. A new neural distinguisher model considering derivedfeatures from multiple ciphertext pairs.[J]. IACR Cryptol. ePrint Arch., 2021, 2021: 310.

[0011] [6]Hou Z, Ren J, Chen S. Improve neural distinguisher for cryptanalysis[J]. Cryptology ePrint Archive, 2021.

[0012] [7]Bellini, Emanuele, et al. "A cipher-agnostic neural training pipeline with automated finding of good input differences." IACR Transactionson Symmetric Cryptology 2023.3 (2023): 184-212.

[0013] This paper addresses the challenges of existing methods in the background art and proposes a method for searching for optimal neural network differential discriminators based on cryptographic structures. This method proposes a universal framework for constructing neural network differential discriminators for different cryptographic structures. Compared to existing methods, this method improves the accuracy and number of rounds of neural network differential discriminators. Furthermore, it is no longer limited to a single specific algorithm, but provides a universal analysis method for cryptographic algorithms with SPN, Feistel, and ARX structures.

[0014] The technical solution for achieving the purpose of the present invention is:

[0015] The present invention provides a method for searching an optimal neural network differential discriminator based on a cryptographic structure, comprising the following steps:

[0016] (1) Construction of ISRN neural network:

[0017] The ISRN neural network structure is an improved variant of the ResNet structure, consisting of an initial convolutional layer, an iterative layer, and a prediction layer. The initial convolution uses four convolutional layers with different convolution kernel sizes to process the input data in parallel. At the same time, a Squeeze-and-Excitation (SE) module is introduced between the residual blocks of the iterative layer. This module can adaptively adjust the weight of each channel through squeezing and excitation operations, enhancing the focus on important feature channels.

[0018] (2) Construction of the data set S based on the password structure:

[0019] Different dataset formats are given according to the characteristics of the cryptographic structure, and the differential propagation characteristics between some intermediate states and ciphertext pairs are converted into information that can be learned by the neural network. The generated ciphertext pairs with differential information are recombined into dataset S according to the dataset formats corresponding to different cryptographic structures.

[0020] (3) Initial neural network differential discriminator Training and validation:

[0021] Use the neural network ISRN with strong classification ability built in step (1) to learn and train the differential information in the data set S generated in step (2). The trained initial neural network differential discriminator Ability to classify data belonging to ciphertext distribution and random distribution respectively;

[0022] (4) Construction of adaptive evolutionary optimizer and search for candidate difference sets:

[0023] The random number generator generates an initial population starting_population consisting of n random differences, using the deviation score Evaluate the quality of candidate differential individuals and construct an evolutionary optimizer in combination with machine learning algorithms to perform differential search. At the same time, during the search process, information entropy is introduced. Evaluate the diversity of the differential population to dynamically adjust crossover operations and mutation probabilities , after the iteration converges, x differences are returned The candidate differential set candidates is used as the differential search result;

[0024] (5) Output optimal neural network differential discriminator :

[0025] The difference found in step (4) is used to construct the dataset based on the password structure in step (2) to obtain the dataset , and use it as the initial neural network differential discriminator obtained in step (3) The input has the highest accuracy As the final neural network differential discriminator .

[0026] The beneficial effects of the present invention are:

[0027] (1) By optimizing the neural network structure, data set input format, and differential screening strategy in the neural network differential discriminator search model, the present invention successfully constructs a neural network differential discriminator with a higher number of rounds and a higher success rate.

[0028] (2) A universal optimal neural network differential analysis method is provided for cryptographic algorithms with various different password structures, which provides a unified and effective analysis perspective and improves the effect of password analysis. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 Schematic diagram of the ISRN neural network structure in the method of the present invention;

[0030] Figure 2 Schematic diagram of the data set format of the SPN structure in the method of the present invention;

[0031] Figure 3 Schematic diagram of the data set format of the Feistel structure in the method of the present invention. DETAILED DESCRIPTION

[0032] The present invention will be further described in detail below with reference to the embodiments and drawings, but the present invention is not limited thereto.

[0033] Example

[0034] The optimal neural network differential discriminator search method based on the password structure includes the following steps:

[0035] (1) Construction of ISRN neural network:

[0036] The ISRN neural network structure is an improved variant of the ResNet structure, consisting of an initial convolutional layer, an iterative layer, and a prediction layer. The initial convolution uses four convolutional layers with different convolution kernel sizes to process the input data in parallel. At the same time, the SE module is introduced between the residual blocks of the iterative layer. This module can adaptively adjust the weight of each channel through squeezing and excitation operations, enhancing the focus on important feature channels.

[0037] (2) Construction of the data set S based on the password structure:

[0038] Different dataset formats are given according to the characteristics of the cryptographic structure, and the differential propagation characteristics between some intermediate states and ciphertext pairs are converted into information that can be learned by the neural network. The generated ciphertext pairs with differential information are recombined into dataset S according to the dataset formats corresponding to different cryptographic structures.

[0039] (3) Initial neural network differential discriminator Training and validation:

[0040] Use the neural network ISRN built in step (1) to learn the differential information in the data set S generated in step (2), and the trained initial neural network differential discriminator Ability to classify data belonging to ciphertext distribution and random distribution respectively;

[0041] (4) Construction of adaptive evolutionary optimizer and search for candidate difference sets:

[0042] The random number generator generates an initial population starting_population consisting of n random differences, using the deviation score Evaluate the quality of candidate differential individuals and construct an evolutionary optimizer in combination with machine learning algorithms to perform differential search. At the same time, during the search process, information entropy is introduced. Evaluate the diversity of differential populations to dynamically adjust crossover operations and mutation probabilities , after the iteration converges, x differences are returned The candidate differential set candidates is used as the differential search result;

[0043] (5) Output optimal neural network differential discriminator :

[0044] The difference found in step (4) is used to construct the dataset based on the password structure in step (2) to obtain the dataset , and use it as the initial neural network differential discriminator obtained in step (3) The input has the highest accuracy As the final neural network differential discriminator .

[0045] Furthermore, the ISRN neural network described in step (1) is constructed as follows: Figure 1 As shown, the initial convolution layer performs feature mapping, the iterative layer introduces nonlinear characteristics, and the prediction layer performs classification tasks. The dataset contains multiple rounds of differential information, and the dataset size is not less than 10 7 , the specific construction steps are as follows:

[0046] (1.1) Initial convolutional layer construction:

[0047] The initial convolutional layer is designed with multiple parallel branches. After repeated experiments and debugging, the convolution kernel sizes of each branch are finally set to 1×1, 3×3, and 5×5, respectively. After convolution, the batch normalization layer (BN) normalizes the convolution output to accelerate network training and prevent gradient vanishing. The activation function (ReLU) then introduces nonlinearity to enhance the network's ability to learn complex relationships. The maximum pooling branch performs dimensionality reduction sampling to reduce the amount of computation and parameters, thereby enhancing robustness. Finally, the outputs of each branch are spliced ​​and merged to achieve multi-scale feature fusion and enrich the feature representation.

[0048] (1.2) Iterative layer construction:

[0049] The iterative layer consists of multiple residual blocks combined with SE modules. Each residual block contains two Conv2D layers. The SE module compresses the spatial dimension through global average pooling to capture channel dependencies. After full connection and activation operations, the Sigmoid output channel weights implement the channel attention mechanism, which improves the model's selectivity for feature channels at a low computational cost and enhances the effectiveness of feature representation. Four initial convolutional layers with different convolution kernel sizes extract multi-scale features from the input data and output feature information containing different spatial scales. The SE module performs a secondary screening of multi-scale features and adaptively adjusts the channel weights so that subsequent residual blocks can use these features more efficiently. The two form a "comprehensive extraction first, then key enhancement" processing chain, which enhances the neural network's ability to extract feature information and the efficiency of analysis.

[0050] (1.3) Prediction layer structure:

[0051] The prediction layer first passes through a Flatten layer to perform one-dimensional flattening on the data output by the convolution layer, so that the data can be smoothly converted to the fully connected layer. The fully connected layer consists of a Dense layer and a Relu function. The number of neurons in the Dense layer is the same as the length of the password block. Finally, a single neuron is used as the output unit to express the final prediction result. Each neuron in the fully connected layer is connected to all neurons in the previous layer. Through weighted summation and Sigmoid activation function, the features are mapped to the final classification results 0 and 1. The fully connected layer outputs the final classification result by integrating all extracted features.

[0052] Furthermore, the construction of the data set S based on the password structure in step (2) is specifically carried out as follows:

[0053] (2.1) Initial data generation:

[0054] The dataset used for the discrimination task consists of ciphertext data and random data, which are generated as follows:

[0055] Randomly generate n pairs of plaintext ,Label and the corresponding key , plain text ,in is the input differential, Encrypt the plaintext pairs to r rounds to obtain the corresponding n pairs of ciphertext pairs , each pair of ciphertext is regarded as a sample, and a corresponding label is attached to each sample ;

[0056] When the value of label Y is 0, the corresponding ciphertext pair is replaced with random data, as shown in Formula 1;

[0057] (Formula 1)

[0058] The ciphertext pairs and random data together form a data set, and all samples in the data set are converted into binary data , so as to input the neural network for training and verification;

[0059] (2.2) Dataset format based on password structure:

[0060] For the cryptographic algorithm with SPN structure, each round performs nonlinear operations on the complete input state, and the data set format only needs to contain the ciphertext pair and difference of the current r rounds;

[0061] The dataset format is designed as , which includes the intrinsic characteristics of a single ciphertext and the differential relationship between ciphertexts , the SPN structure dataset format is as follows Figure 2 As shown;

[0062] For the Feistel structure cryptographic algorithm, since each iteration of the Feistel structure only performs nonlinear operations on part of the input state, in order to facilitate the propagation process of the neural network learning difference, the data set format is designed as ,This dataset format not only captures the characteristics of r-round ciphertext pairs and ciphertext differences, but also incorporates the information from the previous round of differential propagation, specifically Figure 3 As shown, Represents the difference between the left and right branches of the current round r. At the same time, the left branch difference and the left branch ciphertext pair of the algorithm r-1 round also need to be part of the sample data, that is, ;

[0063] Similarly, the cryptographic algorithm of the ARX structure uses modular addition and AND operations as nonlinear operations and only exists in the left branch, and can use a similar data set format .

[0064] Furthermore, the initial neural network differential distinguisher in step (3) The specific steps of training and verification are as follows: using a deep residual network with strong classification ability to classify data belonging to ciphertext distribution and random distribution, the expected goal of the neural network model is:

[0065]

[0066] in, represents the ciphertext distribution, represents a random distribution, represents a data sample, Represents the overall operation of the neural network;

[0067] use Represents the data sample, and the preliminary results will be , use the classification result judgment formula 2 for processing:

[0068] (Formula 2)

[0069] The training effect of the model is demonstrated by verifying the accuracy formula 3:

[0070] (Formula 3)

[0071] in, represents the verification accuracy, and m is the number of verification samples;

[0072] The training set generated in the data generation phase is put into the model for training. Here, hyperparameters need to be set. Selecting appropriate hyperparameters ensures high accuracy and low complexity of the model.

[0073] Determine the epoch size, batch size, and dataset size to be retained during the training phase and then validated during the validation phase;

[0074] In the process of determining the hyperparameters, the default parameter settings of Adam in Keras are generally used. The arrangement is expressed by Formula 4 in the i-th epoch:

[0075] (Formula 4)

[0076] in, ;

[0077] The networks obtained after each epoch are stored and the best network with validation loss is evaluated on a test set that was not used for training or validation.

[0078] Furthermore, the construction of the adaptive evolutionary optimizer and the search of the candidate difference set in step (4) are as follows: the evolutionary optimizer difference search is a machine learning algorithm with no gradient optimization, the core principle of which is to search for the optimal neural network difference distinguisher input difference in the complex solution space through population iteration and genetic operation. The algorithm starts with an initial population starting_population consisting of n random differences, and uses information entropy To measure the diversity of differential populations and dynamically adjust the mutation probability at different stages , the adaptive mutation probability can ensure that the differential search can differentiate the deviations in the population When the distribution is relatively concentrated, the global search capability of the algorithm is guaranteed, and the convergence capability and search capability of the algorithm are guaranteed in the later stage of iteration. The population finally returned by the algorithm after continuous iteration is regarded as the optimal candidate differential set candidates. The specific steps are as follows:

[0079] (4.1) Initial population generation:

[0080] Generate n input differences through a random number generator , where the superscript is the iteration round and the subscript is the current round index, forming the initial seed starting_population, and calculating the deviation score of each difference , sort in descending order and retain the first x differences as the current population current_population;

[0081] (4.2) i-round iterative optimization process:

[0082] Initialize the candidate difference set candidates;

[0083] Population diversity assessment: Calculate the gene bit information entropy of the input difference m bits in the current population current_population respectively , where the number of individuals with the value of 0 and 1 at the j-th gene position is recorded as and , the probabilities are and and ;

[0084] Calculate the mean information entropy of all gene positions as the population information entropy to evaluate population diversity;

[0085] The formula for calculating population information entropy is as follows:

[0086] (Formula 5)

[0087] Adaptive crossover operation: When When all the differences in the current population current_population Perform uniform crossover between the two and generate randomly A mask of the same length as the difference, for the parent and Uniform crossover , the value of each bit is determined by the corresponding random mask The value of the bit is determined (x is the number of differences in the current population);

[0088] like ,like ;

[0089] when When all the differences in the current population current_population Perform normal crossover operations between two pairs, that is, traverse all differences in the population , the differences are XORed to generate new individuals current_population i ⊕current_population j ;

[0090] Adaptive mutation operation: Assume the maximum mutation probability is , minimum mutation probability , the maximum value of information entropy is , the minimum value is ;

[0091] when hour, , that is, when the population diversity is the highest, the minimum mutation probability is adopted, and vice versa;

[0092] The cross operation obtained Differences, generate corresponding mutation labels ;

[0093] when When , the random bits corresponding to the difference are flipped, and the dynamic mutation probability calculation formula is as follows:

[0094] (Formula 6)

[0095] The next generation of population is generated, and the candidate differentials are sorted according to the deviation scores. Sort in descending order and keep the first x as the current population of the new generation;

[0096] (4.3) Output:

[0097] After the current population converges and stabilizes, the candidate population candidates are returned as the final differential search result set.

[0098] Furthermore, the output of step (5) is the final neural network differential distinguisher , as follows:

[0099] The difference in the differential search result set obtained in step (4) , according to the data set construction method based on the password structure in step (2), multiple data sets are obtained , by different differences The generated dataset , which will be used as the training model in step (3) The model with the highest input and output distinction accuracy As the final neural network differential discriminator .

[0100] The present invention proposes a method for searching for an optimal neural network differential discriminator based on a cryptographic structure. The existing method is improved mainly from three aspects: the design of an ISRN neural network, the optimization of a data set format based on a cryptographic structure, and the construction of an adaptive evolutionary optimizer and the search for candidate differential sets. In the ISRN neural network design part, the combination of initial convolution layers with different convolution kernel sizes and adaptive screening of SE modules improves the utilization rate of feature information by the neural network; in the data set format optimization part based on a cryptographic structure, the input format of the data set for the cryptographic structure can provide more features in the differential propagation process; in the construction of an adaptive evolutionary optimizer and the search for candidate differential sets, the evaluation of information entropy is introduced to dynamically adjust the crossover operation and mutation probability at different stages. This ensures the global search and convergence capabilities of the evolutionary optimizer, improves the search efficiency and convergence speed of the algorithm, and avoids falling into a local optimal solution.

Claims

1. The optimal neural network differential discriminator search method based on the password structure is characterized by: The method comprises the following steps: (1) Construction of ISRN neural network: The ISRN neural network structure is an improved variant of the ResNet structure, consisting of an initial convolutional layer, an iterative layer, and a prediction layer. The initial convolution uses four convolutional layers with different convolution kernel sizes to process the input data in parallel. At the same time, the SE module is introduced between the residual blocks of the iterative layer. This module can adaptively adjust the weight of each channel through squeezing and excitation operations, enhancing the focus on important feature channels. (2) Construction of the data set S based on the password structure: Different dataset formats are given according to the characteristics of the cryptographic structure, and the differential propagation characteristics between some intermediate states and ciphertext pairs are converted into information that can be learned by the neural network. The generated ciphertext pairs with differential information are recombined into dataset S according to the dataset formats corresponding to different cryptographic structures. (3) Initial neural network differential discriminator Training and validation: Use the neural network ISRN built in step (1) to learn and train the differential information in the data set S generated in step (2). The trained initial neural network differential discriminator Ability to classify data belonging to ciphertext distribution and random distribution respectively; (4) Construction of adaptive evolutionary optimizer and search for candidate difference sets: The random number generator generates an initial population starting_population consisting of n random differences, using the deviation score Evaluate the quality of candidate differential individuals and construct an evolutionary optimizer in combination with machine learning algorithms to perform differential search. At the same time, during the search process, information entropy is introduced. Evaluate the diversity of differential populations to dynamically adjust crossover operations and mutation probabilities , after the iteration converges, x differences are returned The candidate differential set candidates is used as the differential search result; (5) Output optimal neural network differential discriminator : The difference found in step (4) is used to construct the dataset based on the password structure in step (2) to obtain the dataset , and use it as the initial neural network differential discriminator obtained in step (3) The input has the highest accuracy As the final neural network differential discriminator .

2. The method for searching for an optimal neural network differential discriminator based on a cryptographic structure according to claim 1, wherein: In step (1), the ISRN neural network is constructed. The initial convolution layer performs feature mapping, the iteration layer introduces nonlinear characteristics, and the prediction layer performs classification tasks. The data set contains multiple rounds of differential information, and the data set size is not less than 10 7 , the specific construction steps are as follows: (1.1) Initial convolutional layer construction: The initial convolutional layer is designed with multiple parallel branches, and the convolution kernel sizes of each branch are set to 1×1, 3×3, and 5×5 respectively. After convolution, the batch normalization layer (BN) normalizes the convolution output. The activation function (ReLU) then introduces nonlinearity to enhance the network's ability to learn complex relationships. The maximum pooling branch performs dimensionality reduction sampling to reduce computational effort and parameters, thereby enhancing robustness. Finally, the outputs of each branch are spliced ​​and merged to achieve multi-scale feature fusion and enrich feature representation. (1.2) Iterative layer construction: The iterative layer consists of multiple residual blocks combined with SE modules. Each residual block contains two Conv2D layers. The SE module compresses the spatial dimension through global average pooling to capture channel dependencies. After full connection and activation operations, sigmoid output channel weights implement the channel attention mechanism. Four initial convolutional layers with different convolution kernel sizes extract multi-scale features from the input data and output feature information containing different spatial scales. The SE module performs secondary screening of multi-scale features and adaptively adjusts channel weights. (1.3) Prediction layer structure: The prediction layer first passes through a Flatten layer to perform one-dimensional flattening on the data output by the convolution layer, so that the data can be smoothly converted to the fully connected layer. The fully connected layer consists of a Dense layer and a Relu function. The number of neurons in the Dense layer is the same as the length of the password block. Finally, a single neuron is used as the output unit to express the final prediction result. Each neuron in the fully connected layer is connected to all neurons in the previous layer. Through weighted summation and Sigmoid activation function, the features are mapped to the final classification results 0 and 1. The fully connected layer outputs the final classification result by integrating all extracted features.

3. The method for searching for an optimal neural network differential discriminator based on a cryptographic structure according to claim 1, wherein: The construction of the data set S based on the password structure in step (2) is as follows: (2.1) Initial data generation: The dataset used for the discrimination task consists of ciphertext data and random data, which are generated as follows: Randomly generate n pairs of plaintext ,Label and the corresponding key , plain text ,in is the input differential, Encrypt the plaintext pairs to r rounds to obtain the corresponding n pairs of ciphertext pairs , each pair of ciphertext is regarded as a sample, and a corresponding label is attached to each sample ; When the value of label Y is 0, the corresponding ciphertext pair is replaced with random data, as shown in Formula 1; (Formula 1) The ciphertext pairs and random data together form a data set, and all samples in the data set are converted into binary data , so as to input the neural network for training and verification; (2.2) Dataset format based on password structure: For the cryptographic algorithm with SPN structure, each round performs nonlinear operations on the complete input state, and the data set format only needs to contain the ciphertext pair and difference of the current r rounds; The dataset format is designed as , which includes the intrinsic characteristics of a single ciphertext and the differential relationship between ciphertexts ; For the Feistel structure cryptographic algorithm, the dataset format is designed as , this dataset format not only captures the characteristics of r-round ciphertext pairs and ciphertext differences, but also incorporates the information from the previous round of differential propagation, where Represents the difference between the left and right branches of the current round r. At the same time, the left branch difference and the left branch ciphertext pair of the algorithm r-1 round also need to be part of the sample data, that is, ; Similarly, the ARX structure cryptographic algorithm uses modular addition and AND operations as nonlinear operations and only exists in the left branch, using a similar data set format. .

4. The optimal neural network differential distinguisher search method based on a cryptographic structure according to claim 1, characterized in that: Step (3) The initial neural network differential discriminator The specific steps of training and verification are as follows: using a deep residual network with strong classification ability to classify data belonging to ciphertext distribution and random distribution, the expected goal of the neural network model is:

5. Among them, represents the ciphertext distribution, represents a random distribution, Represents the data sample, and f represents the overall operation of the neural network; use Represents the data sample, and the preliminary results will be , use the classification result judgment formula 2 for processing: (Formula 2) The training effect of the model is demonstrated by verifying the accuracy formula 3: (Formula 3) in, represents the verification accuracy, and m is the number of verification samples; Determine the epoch size, batch size, and dataset size to be retained during the training phase and then validated during the validation phase; Put the training set generated in the data generation phase into the model for training. It is necessary to set hyperparameters. In the process of determining hyperparameters, the default parameter settings of Adam in Keras are generally used. For the learning rate The arrangement is expressed by Formula 4 in the i-th epoch: (Formula 4) in, ; The networks obtained after each epoch are stored and the best network with validation loss is evaluated on a test set that was not used for training or validation.

6. The optimal neural network differential discriminator search method based on a cryptographic structure according to claim 1, characterized in that: The construction of the adaptive evolutionary optimizer and the search for candidate difference sets in step (4) are specifically as follows: (4.1) Initial population generation: Generate n input differences through a random number generator , where the superscript is the iteration round and the subscript is the current round index, forming the initial seed starting_population, and calculating the deviation score of each difference , sort in descending order and retain the first x differences as the current population current_population; (4.2) i-round iterative optimization process: Initialize the candidate difference set candidates; Population diversity assessment: Calculate the gene bit information entropy of the input difference m bits in the current population current_population respectively , where the number of individuals with the value of 0 and 1 at the j-th gene position is recorded as and , the probabilities are and and ; Calculate the mean information entropy of all gene positions as the population information entropy to evaluate population diversity; The formula for calculating population information entropy is as follows: (Formula 5) Adaptive crossover operation: When When all the differences in the current population current_population Perform uniform crossover operations between the two and randomly generate A mask of the same length as the difference, for the parent and Uniform crossover , the value of each bit is determined by the corresponding random mask The value of the bit determines,x,is the number of differences in the current population; like , like ; when When all the differences in the current population current_population Perform normal crossover operations between two pairs, that is, traverse all differences in the population , the differences are XORed to generate new individuals current_population i ⊕current_population j ; Adaptive mutation operation: Assume the maximum mutation probability is , minimum mutation probability , the maximum value of information entropy is , the minimum value is ; when hour, , that is, when the population diversity is the highest, the minimum mutation probability is adopted, and vice versa; The cross operation obtained Differences, generate corresponding mutation labels ; when When , the random bits corresponding to the difference are flipped, and the dynamic mutation probability calculation formula is as follows: (Formula 6) The next generation of population is generated, and the candidate differentials are sorted according to the deviation scores. Sort in descending order and keep the first x as the current population of the new generation; (4.3) Output: After the current population converges and stabilizes, the candidate population candidates are returned as the final differential search result set.

7. The optimal neural network differential distinguisher search method based on a cryptographic structure according to claim 1, characterized in that: Step (5) outputs the final neural network differential discriminator , as follows: The difference in the differential search result set obtained in step (4) , according to the data set construction method based on the password structure in step (2), multiple data sets are obtained , by different differences The generated dataset , which will be used as the training model in step (3) The model with the highest input and output distinction accuracy As the final neural network differential discriminator .

Citation Information

Cited By

  • Discrete space global optimization method based on neighborhood mapping and multi-path parallel search

    CN121940123A