Method, computer program and data processing system for determining pre-image elements of a cryptographic hash function
By using a quantum annealing device to accelerate computation through a method for determining the preimage element of a cryptographic hash function in a data processing system, the high computational complexity of existing technologies is solved, achieving efficient determination of the preimage element and improving system performance.
Patent Information
- Application Number
- CN202111370795.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-11-25
- Filing Date
- 2021-11-18
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2041-11-18
AI Technical Summary
Existing technologies struggle to efficiently and resource-efficiently determine the preimage elements of cryptographic hash functions, especially when performing calculations on quantum computers, where high computational complexity exists.
The method, executed in a data processing system, determines the preimage elements of a cryptographic hash function, including providing the output value of the cryptographic hash function, determining hash function relationships and optimization problems, and solving the optimization problems in a quantum processing device or a classical processing device, using a quantum annealing device to accelerate computation.
This technology enables the efficient determination of preimage elements of cryptographic hash functions on quantum computers, significantly reducing computation time and improving system performance, especially in blockchain systems where data integrity is crucial.
Smart Images

Figure CN114547638B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to techniques for determining preimage elements of cryptographic hash functions, particularly on quantum computers such as quantum annealing devices. Background Technology
[0002] Reversing cryptographic hash functions involves analyzing their respective cryptographic strength. For hash functions... ,in, It is a set of input values (input bit sequence, message), and It is a set of output values (hash value, fixed-length bit sequence). medium elements Size Usually more Much smaller. Therefore, the hash function is not bijective, and the equation...
[0003]
[0004] There are usually many solutions, i.e., sets. (with a certain hash value) The corresponding set of preimage or inverse image elements may contain many elements. Nevertheless, searching for any one of these elements is a computationally difficult problem for a "strong" hash function. In recent years, hash functions have been used as a core element of blockchain technology. The stage with the highest computational consumption can also be understood as solving the following inequality:
[0005]
[0006] in, It is a hash function The parameters, including unknown parts (The so-called random number is usually a 4-byte field) and a fixed remainder with a block header. And hash value Corresponding to a predefined threshold. The left and right sides of equation (2) are bit sequences, but can also be interpreted as binary representations of integers. Thus, according to equation (2), the hash value is... A predefined number of leading bits are all equal to zero. In, for example, hash functions... In the case of a 128-bit hash function, the hash value It can be written as a (finite) sequence ,in, It is a sequence The first (from left to right) non-zero bit in the matrix. Therefore, equation (2) is equivalent to
[0007]
[0008] Among them, hash function H of (m-1) Each leading bit is equal to zero. In this way, one of the preimage elements can be determined.
[0009] There are two main types of access to or modification of input processed by a cryptographic hash function: collision attacks and preimage attacks. In a collision attack, the goal is to find two distinct messages. Make This type of attack on the MD5 cryptographic hash function is known and requires approximately [a certain amount of time / effort]. MD5 compression is still better than exhaustive search (which requires...). The MD5 compression of the MD5 is much less. Therefore, this type of attack can be performed on a regular PC. On the other hand, preimage attacks are more complex, but also more powerful than collision attacks. During a preimage attack, for a given Sure , making For MD5, this attack is currently only theoretical; that is, although it requires less MD5 compression than exhaustive search (…). and However, known preimage attacks are still practically impossible to perform on available computers. Summary of the Invention
[0010] The purpose of this disclosure is to provide a method for determining, in an efficient and resource-saving manner, the preimage element corresponding to the hash value processed by the cryptographic hash function.
[0011] To solve this problem, a method for determining the preimage elements of a cryptographic hash function, executed in a data processing system, is provided. Furthermore, a computer program and a data processing system are provided respectively. Other embodiments are disclosed in this disclosure.
[0012] According to one aspect, a method is provided for determining preimage elements of a cryptographic hash function, performed in a data processing system. The method includes: providing an output value of a cryptographic hash function and hash function operations of the cryptographic hash function; for each of the hash function operations, determining at least one hash function relation, the hash function relation including equality and / or inequality; and determining an optimization problem. The optimization problem includes the output value, at least one constraint (optimization relation) assigned to iterations of the cryptographic hash function, and optimization variables, the optimization variables including internal state variables of the cryptographic hash function and at least one preimage variable. The at least one constraint is determined based on the at least one hash function relation and includes a previous internal state variable assigned to a previous iteration. The method further includes solving the optimization problem and determining the preimage elements of the cryptographic hash function based on the optimization values of the at least one preimage variable.
[0013] According to another aspect, a computer program and / or computer program product including instructions is provided, which, when executed in a data processing system, cause the data processing system to perform steps of a method for determining the preimage element of a cryptographic hash function.
[0014] According to another aspect, a data processing system is provided, configured to determine the preimage element of a cryptographic hash function by performing the following steps: providing the output value of the cryptographic hash function and hash function operations of the cryptographic hash function; for each of the hash function operations, determining at least one hash function relation, the hash function relation including equality and / or inequality; determining an optimization problem; and solving the optimization problem and determining the preimage element of the cryptographic hash function based on the optimization values of the at least one preimage variable. The optimization problem includes the output value, at least one constraint assigned to an iteration of the cryptographic hash function, and optimization variables, the optimization variables including internal state variables of the cryptographic hash function and at least one preimage variable. The at least one constraint is determined based on the at least one hash function relation and includes a previous internal state variable assigned to a previous iteration.
[0015] The at least one hash function relation may include assignment to a previous internal state variable of the immediately preceding iteration. The optimization problem may include multiple constraints. The cryptographic hash function may include multiple iterations, particularly 48, 64, 80, or 128 iterations. Preferably, each of the constraints may be assigned to one of the iterations. Further, at least one of the constraints may be assigned to each of the iterations. At least one of the constraints may be assigned to each of the iterations, and each constraint may include at least one internal state variable assigned to a previous internal state variable of the immediately preceding iteration. Constraints may include at least one of optimization equations, optimization inequalities, and objective functions. It is worth noting that when using equation (1) or equation (2) for the optimization problem, an explicit objective function may not be required (e.g., to minimize it). Therefore, the optimization problem may include a dummy zero constant objective function. Some of the multiple constraints may also be converted into elements of the objective function as penalty terms.
[0016] When determining the minimum and / or maximum value of an optimization problem, optimal values for at least one preimage variable can be assumed. The optimization problem may include multiple preimage variables, such as 16 preimage variables. Preimage elements can be determined by cascading the optimal values of the preimage variables. The minimum and / or maximum values can be global and / or local.
[0017] The output value of the cryptographic hash function can be a hash value (digest), preferably 128 or 160 bits in size.
[0018] Hash function operations can include at least one of the following: non-linear Boolean functions, left rotation, right rotation, and modulo addition, especially at least one of the following.
[0019]
[0020] At least one of the hash function operations, preferably each of the function operations, can be assigned to the iterations and / or rounds of the cryptographic hash function.
[0021] A left rotation may include rotating a bit one or more positions to the left. A right rotation may include rotating a bit one or more positions to the right. The number of rotation positions may depend on the iterations and / or rounds assigned to the left and / or right rotations.
[0022] The method may include: determining at least one elementary operation among the hash function operations; for each of the elementary operations, determining at least one elementary relation, the elementary relation including elementary expressions and / or elementary inequalities; and determining the at least one hash function relation based on the elementary relation of the at least one hash function operation. Preferably, the elementary operations may include at least one of NOT, AND, OR, and XOR.
[0023] In this embodiment, all hash function relations can be determined based on elementary relations. Alternatively, at least one or all of the hash function relations can be determined directly based on hash function operations.
[0024] At least one of the hash function relations and / or at least one of the elementary relations may include bilinear equations and / or linear equations, wherein the bilinear equations and / or linear equations preferably include at least one of continuous variables, binary variables, and integer variables.
[0025] The at least one of the hash function relations and / or the at least one of the elementary relations may have the form Among them, binary variables and / or integer variables include and And continuous variables include , and ,in, It is one of the hash function operations and / or one of the elementary operations.
[0026] At least one of the continuous variable and / or the binary variable can be determined by solving the initial optimization problem (auxiliary optimization problem), preferably a constrained quadratic problem.
[0027] Specifically, variables , and This can be determined by solving the initial optimization problem. The initial optimization problem may include... The objective function of the form, where, yes The first component. The form allows for normalization. The initial optimization problem may include auxiliary constraints, which include... and At least one of the following. Specifically, the initial optimization problem can be...
[0028]
[0029] here, Represents a set of feasible configurations, and This indicates the number of auxiliary variables in equation (4).
[0030] The at least one of the hash function relations and / or the at least one of the elementary relations (preferably determined by an initial optimization problem) may include a linear equation having continuous coefficients and binary variables, wherein the continuous coefficients are preferably integer coefficients.
[0031] For example, at least one of the elementary relations may include , , and At least one of them, wherein , , and It is a binary variable. Furthermore, at least one of the hash function relations may include... , , , and At least one of them, wherein , , , to ,as well as to It is a binary variable.
[0032] At least one of the elementary relations may also include at least one set of the following elementary inequalities: ; ;and ,in, and It is a binary variable, and It is a continuous variable. The inequalities of the hash function relation can be determined from at least one set in the set of elementary inequalities.
[0033] When solving an optimization problem, the initial internal state values and / or the final internal state values (preferably assigned to the last iteration) can be fixed. The optimization variables may not have internal state variables assigned to the last iteration.
[0034] The method may further include at least partially pre-solving the optimization problem before solving it. Pre-solving the optimization problem can reduce the number of constraints and / or optimization variables. Pre-solving may include determining the value of the optimization problem, preferably the optimal value. Pre-solving may also include determining at least one alternative constraint that replaces at least one other constraint among the constraints.
[0035] The optimization problem can be a mixed-integer linear programming (MILP), a mixed-integer nonlinear programming (MINLP), or a quadratic unconstrained bivariate optimization (QUBO) problem. The optimization problem can also be a constrained integer programming problem. The objective function of the QUBO problem can be determined based on the constraints defined for MILP and / or MINLP, preferably by squaring the constraints. The optimization problem can include a discrete search space.
[0036] The optimization problem can be (at least partially) solved in a quantum processing device of a data processing system, preferably a quantum annealing device.
[0037] For example, the quantum annealing device can be a D-Wave annealing device. The optimization problem can also be solved on a general-purpose quantum computer. Therefore, a quantum approximate optimization algorithm can be used to solve the optimization problem.
[0038] Alternatively, the optimization problem can be solved solely in a classical processing device (preferably, a classical processing device within a data processing system). A classical processing device may include a processor and memory. Determining elementary relations, determining hash function relations, determining the optimization problem, and / or determining the preimage element of the cryptographic hash function based on the optimization value of the at least one preimage variable can be performed in a classical data processing device, particularly by the processor of the classical processing device.
[0039] The data processing system may include quantum processing devices, particularly quantum annealing devices. Alternatively, the quantum processing devices may be separate from the data processing system.
[0040] At least one, preferably all, of the constraints can preferably be transferred from a classical processing device (particularly from the memory of a classical processing device) to a quantum processing device. Transferring the constraints may include transferring fixed values during optimization, such as the output value of a cryptographic hash function.
[0041] The optimization variable can be assigned to the superposition of quantum states and / or the optimizer can be the minimum value of the optimization problem, preferably the global minimum value.
[0042] Specifically, each possible value assignment of the optimization variable can correspond to one of the quantum states (preferably generated by a quantum processing device). At the initial moment, each quantum state in the superposition can have the same weight. The superposition can evolve over time by the quantum processing device according to a reduction determined from the constraints. The reduction can, for example, be represented by a Hamiltonian. The optimized value (assignment) of the at least one preimage variable can be determined based on the superposition at the final moment. At the final moment, the optimized quantum state (corresponding to the optimized value assignment) in the quantum state may have the largest weight among the superimposed quantum states. The optimized quantum state can, for example, correspond to the ground state of the Hamiltonian.
[0043] The optimized value of the at least one preimage variable can be determined by determining the optimized quantum state. The optimized value can be transmitted to a classical data processing device. In this way, the preimage element can be provided in the classical data processing device, particularly in the memory of the classical processing device.
[0044] Cryptographic hash functions can provide information security and are preferably used for authentication and / or data corruption detection. Furthermore, the cryptographic hash function can be one of MD4, MD5, SHA-1, and SHA-2.
[0045] The preimage elements may include messages and / or data files for digital signature and / or verification (preferably for data integrity and / or proof of work). Proof of work confirms transactions in the blockchain and / or allows the generation of new blocks in the blockchain.
[0046] The embodiments described above related to the method for determining the preimage element of a cryptographic hash function can be correspondingly provided to a data processing system configured to determine the preimage element of a cryptographic hash function. Attached Figure Description
[0047] In the following description, embodiments are illustrated by way of example and with reference to the accompanying drawings, in which:
[0048] Figure 1 A graphical representation of the MD5 hash function is shown.
[0049] Figure 2 A graphical representation of the SHA-1 hash function is shown.
[0050] Figure 3 A graphical representation of the method for determining the preimage elements of a cryptographic hash function is shown.
[0051] Figure 4 A graphical representation of the data processing system is shown. Detailed Implementation
[0052] Figure 1 The diagram shows a graphical representation of the MD5 hash function. The input data (e.g., a message) to the hash function is divided into message blocks (preimage data blocks) with a fixed block length (32 bits in the case of MD5). The message block corresponds to different iterations of the hash function. The hash function includes each iteration. The internal state, each internal state consists of four 32-bit blocks. composition.
[0053] From the initial internal state Initially, the hash function operation is applied to the initial internal state within the first iteration. This generates the first internal state. This, in turn, provides a starting point for the second iteration of hash function operations. Figure 1 The diagram shown illustrates the iteration. Application of hash function operations. In each iteration Inside, message block It is processed and used to modify the internal state. After reaching the maximum number of iterations (64 in the case of MD5), the 32-bit blocks of the last internal state are concatenated to produce the output value of the cryptographic hash function.
[0054] The MD5 hash function (and most widely used cryptographic hash functions, such as MD4, SHA-1, and SHA-2) includes the following hash function operations:
[0055] - Nonlinear Boolean functions based on bitwise logic operations ,
[0056] - 16-bit and 32-bit integer modulo or addition, and
[0057] - Shift a bit sequence by multiple bits.
[0058] The MD5 hash function's 64 iterations are divided into four rounds, with 16 operations per round. A different Boolean function is used for each round. . It consists of 32-bit constants, and for each iteration They are all different. (Symbols) Indicates left rotation There are 100 locations, among which... It is different for each iteration. (Symbol) Modulus Addition.
[0059] For iteration From the internal state Beginning, according to Figure 1 The value of the internal state is processed as follows:
[0060]
[0061] function Defined as
[0062]
[0063] Depends on iteration nonlinear Boolean functions Defined as
[0064]
[0065] The first 16 iterations The first round consists of 16 iterations, the second round consists of 16 iterations, the third round consists of 16 iterations, and the final fourth round consists of 16 iterations. (Symbol) and These represent the logical operations OR, AND, XOR, and NOT, respectively. (Variable) , and It is a 32-bit word.
[0066] All It can be considered a 32-bit unsigned integer. It is a 32-bit block of the final hash value. ( The input message to be determined is used as the optimization variable (preimage variable). The variables appearing in equations (1) and (2) are... It is an internal state / data block The union of .
[0067] Therefore, determining a given hash value preimage elements Corresponding to a given preimage variable .
[0068] Figure 2 This is a graphical representation of the SHA-1 hash function, illustrating the iteration... Application of hash function operations. The internal state of each iteration consists of five 32-bit data blocks. composition. Iteration The message block, and Each iteration Different constants.
[0069] Non-linear Boolean functions to be used in MD5 and SHA-1 Defined as:
[0070]
[0071] Although only two of the aforementioned Boolean functions are used in MD5 and SHA-1, all Boolean functions are for binary variables. and The following combinations of elementary Boolean operations: as well as .
[0072] At the bit level, the NOT operation is simply equivalent to toggling between 0 and 1, that is, and The other three elementary operations are defined as follows (note that...). (Corresponding to modulo 2 addition):
[0073]
[0074] Left-hand rotation and modulo addition can be represented by the following formulas. N Number of digits Performed Left shift rotation at each position Defined as
[0075] ,
[0076] Here, the symbol " / / " indicates floor division, and the symbols "<<" and ">>" represent left shift and right shift, respectively. Right shift rotation is defined as:
[0077]
[0078] mold The meaning of addition is addition, followed by calculation and division. The remainder after that.
[0079] a. Methods for determining preimage elements
[0080] If equation (2) If the left and right sides of are represented in binary notation, then if and only if Number of leading bits (Depend on (The value is predefined) equal to When, equation (2) holds true. The larger the value, the more difficult it is to determine the preimage element that satisfies equation (2). .use To represent (binary) finite sequences The first in k The position, equation (2) can be expressed as the following system of equations:
[0081]
[0082] Equation (1) Equation (9) can be further restated as a mixed integer programming problem with binary variables, particularly a mixed integer linear programming problem (MILP) with constraints, which include linear equations and / or linear inequalities as constraints.
[0083] Equations (1) and (9) can also be formulated as a quadratic unconstrained bivariate optimization problem (QUBO) with bilinear functions and no additional constraints on feasible values of the binary variables. Both MILP and QUBO can be solved using available classical solvers (e.g., CPLEX, Gurobi, XPRESS, or SCIP), but can also be solved in quantum processing devices. Specifically, quantum annealing devices such as D-Wave can be used to solve QUBO. Since QUBO can include a discrete search space (containing all possible value assignments of the optimization variables), the assignment of possible values can be processed in parallel (quantum parallelism), which can significantly accelerate the determination of preimage elements.
[0084] Any significant speedup in solving systems of equations (such as equations (1) and (9)) would greatly improve the performance of systems that rely on data integrity or proof-of-work, such as blockchain systems. Currently, the time limit for random number search is ten minutes. In particular, quantum annealing devices can help reduce the required computation time to a few seconds.
[0085] Figure 3 A graphical representation of a method for determining the preimage elements of a cryptographic hash function, performed in a data processing system, is shown.
[0086] In the first step 10, the hash function operation of the cryptographic hash function (such as MD5 or SHA-1) as defined in equation (8) is provided. For hash function operations For each of the following, determine one or more corresponding hash function relations (step 11). Each hash function relation can be an equality. Alternatively, the multiple corresponding hash functions can be a set of inequalities. These equality equations can be determined by solving a preferred lower-dimensional auxiliary (initial) optimization problem.
[0087] The hash function relation is determined directly from the hash function operation or via an optional intermediate step 11a. In step 11a, the hash function operation is determined. The elementary operations (including NOT, AND, OR and / or XOR) are constructed, and for each elementary operation, the corresponding elementary equation and / or a set of elementary inequalities are determined.
[0088] After determining the hash function relationships, the optimization problem (e.g., MILP and QUBO) is defined (step 12). For each iteration of the hash function established based on the hash function relationships, the optimization problem includes a set of optimization equations or optimization inequalities (constraints). The optimization problem further includes the internal state of the hash function (in the case of MD5, it is...). And in the case of SHA-1, it is ( ), and the preimage variable as an optimization variable. Initial internal state ( The final internal state (corresponding to the obtained hash value) is known and remains fixed during optimization. The constraints assigned to a given iteration include the internal state variables assigned to previous iterations.
[0089] In optional step 12a, the number of constraints and / or optimization variables can be reduced. This can be achieved by pre-solving the constraints and / or optimization variables.
[0090] After determining the optimization problem, solve the optimization problem and determine the preimage elements of the hash function based on the optimization set (optimizer) of the optimization variables of the optimization problem (step 13).
[0091] Figure 4 A graphical representation of the data processing system 20 is shown. The data processing system 20 includes a classical processing device 21. Additionally, the data processing system 20 may include a quantum processing device 22, such as a quantum annealing device. Data can be exchanged between the classical processing device 21 and the quantum processing device 22. Specifically, in the case of using a D-Wave quantum annealing device, data exchange can be performed using the D-Wave Python API. Steps 10 to 12 are preferably performed in the classical processing device 21. Step 13 can also be performed in the classical processing device 21. However, when solving the optimization problem in the quantum processing device 22, step 13 is significantly accelerated.
[0092] b. Determine the elementary relations of elementary operations
[0093] According to step 11a, the elementary relations are included in elementary operations. Each of the equations establishes an elementary equation or a set of inequalities.
[0094] Consider reducing equations with basic Boolean functions to MILP constraints.
[0095] For binary variables The NOT operation corresponds to an equation that includes subtraction, thus yielding the following equivalence:
[0096]
[0097] More generally, in order to determine a corresponding system of linear equations among other elementary operations (which are Boolean functions), the corresponding initial optimization problem is solved. In the following sections, Defined as elementary operations Input variable set and output joint vector Furthermore, This represents a set of feasible configurations. The equation to be determined has the following form.
[0098]
[0099] in, It is a binary coefficient auxiliary vector. These are continuous coefficients. It is a continuous coefficient vector, and It is a binary variable vector. The transpose of the vector is... It is worth noting that equation (11) It is linear.
[0100] A linear system must satisfy:
[0101]
[0102] The coefficients sought, to be determined by the initial optimization problem, are continuous variables. , ,and The initial optimization problem can be formulated as MILP, and is determined according to equation (12) as follows. First, the auxiliary quantities in equation (12) are selected. quantity The number of variables in the original problem is expressed as follows: MILP consists of a set of auxiliary constraints and an objective function. Each vector from a feasible configuration produces variables with continuous variables. , ,and as well as A new binary variable One of the auxiliary constraints:
[0103]
[0104] For each vector from the infeasible configuration ,Add to A new auxiliary constraint:
[0105]
[0106] The number of auxiliary constraints grows exponentially, but most popular hash functions are functions with only a small number of input and output variables. These include MD-hash functions and SHA-hash functions. We do not consider summation because we have created a corresponding linear equation for it.
[0107] Therefore, establish with Auxiliary constraints ( and (These represent the number of feasible and infeasible configurations, respectively) and A MILP with multiple variables. This isomorphic MILP has many solutions (multiplying all coefficients by the same number also yields a solution). Therefore, First coefficient Setting it to 1 will generate additional auxiliary constraints or corresponding penalty terms. .
[0108] Then, the initial optimization problem is written as:
[0109]
[0110] in, Including real-valued variables, and This includes binary variables. As an example, the following describes how to determine elementary operations. The elementary equations. The feasible and infeasible configurations of the operation are as follows:
[0111]
[0112] Equation (13) simplifies to And the coefficients need to be determined. So that:
[0113]
[0114] Then, the initial optimization problem is written as:
[0115]
[0116] The initial optimization problem described above can be directly assigned to a state-of-the-art solver (such as CPLEX), or it can be converted into a classic MINLP (without inequality constraints) or MILP.
[0117] For elementary operations The optimization problem generates the following variables with auxiliary variables. Elementary equations:
[0118]
[0119] Equation (18) is equivalent to the following in the sense that : if and only if there exists a binary value When equation (18) holds, the triplet of the binary variable satisfies This can be seen from the table below (bold zeros indicate...). (feasible triples)
[0120]
[0121] Instead of using equations to express Elementary operations can also be represented by a set of inequalities:
[0122]
[0123] Importantly, if It is binary and if If equation (19) is satisfied, then Only different values can be taken and Without explicit requirements It is binary. This reduces the complexity of the MILP representation of the preimage problem.
[0124] Accordingly, further elementary operations OR
[0125]
[0126] The following elementary equations are generated:
[0127]
[0128] This can be verified using the following table:
[0129]
[0130] For a set of elementary inequalities, the elementary operation OR is represented as follows:
[0131]
[0132] if Also binary, and if If equation (22) is satisfied, then Only different values can be taken and Without explicit requirements It is binary.
[0133] XOR in the following elementary relation
[0134]
[0135] In this case, the corresponding elementary equation is written as
[0136]
[0137] This can be verified using the following table:
[0138]
[0139] The XOR operation can also be represented by a set of inequalities.
[0140]
[0141] As mentioned above, if continuous variables Satisfy binary and According to equation (25), the continuous variable can still only be assumed to have a value. and .
[0142] c. Determine the relationship between hash functions
[0143] Similar to elementary relations, the hash function relations determined in step 11 can be either equations or inequalities. In the case of equations, the equations can be determined by solving an initial optimization problem of the form shown in equation (15). Alternatively, the set of inequalities can be determined based on a set of inequalities corresponding to the elementary operations that constitute the respective hash function operations.
[0144] In the following hash function operation (See equation (8.1))
[0145]
[0146] and Corresponding to 32-bit words , and In the case of shared bits, determine the binary variable. 'and binary auxiliary variables , and The following equations:
[0147]
[0148] In order to determine the set of inequalities for hash function operations based on elementary inequalities, equation (26) is reformulated with continuous auxiliary variables. and The following equation
[0149]
[0150] However, the equation will only take binary values. Then, the hash function will be applied. The system of inequalities is determined to have binary variables. The following system of inequalities:
[0151]
[0152] Equations (27) and (29) can be used to determine constraints in optimization problems (preferably MILP), respectively.
[0153] In the following hash function operation
[0154]
[0155] and Corresponding to 32-bit words , and In the case of shared bits, determine the binary variable. and binary auxiliary variables , and The following equations:
[0156]
[0157] In order to determine the set of inequalities for hash function operations based on elementary inequalities, equation (30) is reformulated with continuous auxiliary variables. and The following equation
[0158]
[0159] Therefore, the equation takes a binary value. Then, the hash function is operated on. The system of inequalities is determined to have binary variables. The following system of inequalities:
[0160]
[0161] In the following hash function operation (See equation (8.3))
[0162]
[0163] and Corresponding to 32-bit words , and In the case of shared bits, determine the binary variable. and binary auxiliary variables The following equations:
[0164]
[0165] In order to determine the set of inequalities for hash function operations based on elementary inequalities, equation (34) is reformulated with continuous auxiliary variables. The following equation
[0166]
[0167] Therefore, the equation takes a binary value. Then, the hash function is operated on. The system of inequalities is determined to have binary variables. The following system of inequalities:
[0168]
[0169] In the following hash function operation
[0170]
[0171] and Corresponding to 32-bit words , and In the case of shared bits, determine the binary variable. and binary auxiliary variables and The following equations:
[0172]
[0173] To determine the hash function operation based on elementary inequalities The system of inequalities allows equation (38) to be restated with continuous auxiliary variables. The following equation
[0174]
[0175] Therefore, the equation takes a binary value. Then, the hash function is operated on. The system of inequalities is determined to have binary variables. The following system of inequalities:
[0176]
[0177] In the following hash function operation
[0178]
[0179] and Corresponding to 32-bit words , and In the case of shared bits, determine the binary variable. and binary auxiliary variables The following equations:
[0180]
[0181] To determine the hash function operation based on elementary inequalities The system of inequalities, restate equation (42) with continuous auxiliary variables. and The following equation
[0182]
[0183] Therefore, the equation takes a binary value. Then, the hash function is operated on. The system of inequalities is determined to have binary variables. The following system of inequalities:
[0184]
[0185] Equations (43) and (45) can be used to determine constraints in optimization problems (preferably MILP).
[0186] Hash function operations are applied to systems of linear equations. (in, It is a vector of variables, and In the case of a shift operation involving a vector with fixed parameters (which remains constant during optimization), only the corresponding variable is renamed. To represent the shifted vector Then rotate to the right ( In the case of ), And on the left rotation ( In the case of ), Therefore, the linear equation system after applying the shift operation is simply another linear equation system that has been reindexed. .
[0187] Its role in hash function operations In the case of addition modulo operation, that is,
[0188]
[0189] Among them, the addend We need to consider the position of each bit in equation (46). and ,in, They are and The If the position is given, then equation (46) is equivalent to:
[0190]
[0191] in, yes and The The number of carry-over bits.
[0192] From operations on hash functions and Starting with the hash function equation determined by the MILP constraints, the corresponding QUBO penalty term can be determined, i.e.
[0193]
[0194] The QUBO penalty in equation (48) does not necessarily produce a more efficient optimization than that obtained directly by squaring the corresponding deterministic hash function equation of MILP form. For example, the QUBO penalty mentioned above could include more binary auxiliary variables.
[0195] Generally, additional binary variables should be avoided because the more discrete variables there are, the larger the potential search tree size of the branch and bound algorithm will be. On the other hand, state-of-the-art MILP solvers can accommodate thousands of continuous variables without significantly degrading performance.
[0196] Furthermore, when a hash function operation is performed using a set of inequalities instead of an equality, there are different alternative methods to create a feasible set of inequalities.
[0197] d. Determine the optimization problem
[0198] After determining the hash function relationships, the optimization problem is defined according to step 12. Therefore, when calculating the hash value, the hash function relationships within each iteration of the cryptographic hash function are combined in their (temporal) order, such as... Figure 1 or Figure 2 As shown.
[0199] For MD5, and when using an equality as the hash function relation, the data blocks (internal state variables) from the initial internal state. and First, define the first constraint of the optimization problem.
[0200]
[0201] The method is to and auxiliary variable vector Insert the variables in equation (27) respectively. and (First round) hash function operator In the equation. Then, according to Figure 1 ,implement With preimage variables and constant Modulo addition. , and Insert the corresponding hash function relation into equation (47) and arrange all terms on the left side of the equation to determine the terms with auxiliary variables. constraints
[0202]
[0203] After that, the obtained items Perform the shift and combine with Adding them together produces a result with auxiliary variables. constraints
[0204]
[0205] The terms obtained by the modular addition method correspond to the internal state variables assigned to the next iteration. Determine other constraints to represent the internal state variables. and Assignment to the corresponding internal state variables and (They are assigned to the next iteration).
[0206] In summary, the following constraints are determined for assignment to the first iteration:
[0207]
[0208] The constraints for assignment to subsequent iterations are determined in a similar manner, resulting in the following set of constraints (which are the optimization equations):
[0209]
[0210] Equation (53) leads to the constraint satisfaction problem (CSP), where feasible solutions must be determined that satisfy all constraints in equation (53). It is worth noting that... A 64 、B 64 、C 64 、D 64 It is a hash value y Part of, and M k ( k = 1,…,16 ) is part of the parameters (preimage elements) of the hash function.
[0211] Typically, variables These are known and are fixed during optimization. The remaining variables constitute the optimization variables.
[0212] Under optimized equations, all M k All of this was unknown beforehand, and A 64 、B 64 、C 64 、D 64 It is fixed.
[0213] In the case of optimizing the inequalities (see equation (9)), some M k (For example k = 3,…,16) are fixed, and only the rest (e.g., M 1 、M 2) is an unknown variable. Furthermore, when... A 64 、B 64 、C 64 、D 64 When each of them is considered as a finite sequence, for example A 64 It is fixed as a zero-bit sequence and the other variables can take any value.
[0214] Then, the optimization problem (MILP with constraints (equation (53)) is solved to produce the optimal values of the optimization variables. Message Block The optimal value constitutes one of the preimage elements of the MD5 cryptographic hash function. Constraints can be determined similarly for SHA-1 and other cryptographic hash functions.
[0215] In the optional pre-solution step 12a, the number of constraints and / or optimization variables can be reduced. By analyzing the constraints, the values of some optimization variables can be determined before the overall solution of the optimization problem. This can begin with constraints that include, for example, the following:
[0216]
[0217] Relationship can be determined And thus, the relationship is determined. and Subsequently, a set of modified constraints with fewer optimization variables / constraints is determined:
[0218]
[0219] Alternatively, pre-solving can be performed using a pre-solver library (such as PaPILO within SCIP).
[0220] Instead of defining and solving the optimization problem as a MILP, it can also be defined and solved as a QUBO problem. Specifically, the MILP (equations (53) and (54)) can be converted to a QUBO problem. To do this, the constraints (equation (53)) are squared and summed to obtain the QUBO objective function to be minimized. :
[0221]
[0222] Optimization problems can also be solved using available solvers. Classical solutions for MILP and MINLP can be found using, for example, CPLEX, Gurobi, FicoXPRESS, ParaSCIP, FiberSCIP, and / or open-source SCIP. Classical solutions for QUBO problems can be found using general annealing solvers (e.g., digital annealing and / or simulated bifurcation machines).
[0223] When solving QUBO problems using quantum processing devices, quantum annealing devices (e.g., D-Wave annealers) can be employed. For this purpose, the QUBO objective function... The data is transmitted to a quantum annealing apparatus. Then, a QUBO algorithm is solved within the quantum annealing apparatus to generate optimal value assignments for the optimization variables, especially the preimage variables. The optimal value can be found. Therefore, the preimage element of the cryptographic hash function can be determined.
[0224] The features disclosed in this specification, drawings and / or claims may be materials used to implement various embodiments individually or in various combinations thereof.
Claims
1. A method for determining the preimage element of a cryptographic hash function, the method being performed in a data processing system (20), and the method comprising: - Provides the output value of the cryptographic hash function and the hash function operation of the cryptographic hash function; - For each of the hash function operations, at least one hash function relation is determined, the hash function relation including equality and / or inequality; - Define the optimization problem, which includes - The output value, - At least one constraint assigned to the iteration of the cryptographic hash function, and - Optimization variables, which include the internal state variables of the cryptographic hash function and at least one preimage variable. Wherein, the at least one constraint is determined based on the at least one hash function relation, and the at least one constraint includes assignments to previous internal state variables from previous iterations; and - Solve the optimization problem and determine the preimage element of the cryptographic hash function based on the optimization value of the at least one preimage variable, wherein the preimage element includes at least one of the message and data file to be digitally signed or verified.
2. The method according to claim 1, wherein, The hash function operation includes at least one of the following: nonlinear Boolean function, left rotation, right rotation, and modulo addition, or includes at least one of the following: 。 3. The method according to claim 1 or 2, further comprising: - Determine the elementary operations of at least one of the hash function operations; - For each of the elementary operations, determine at least one elementary relation, which includes elementary equations and / or elementary inequalities; as well as - Determine the at least one hash function relation based on the elementary relation of the at least one hash function operation.
4. The method according to claim 3, wherein, At least one of the hash function relations and / or at least one of the elementary relations includes bilinear equations and / or linear equations.
5. The method according to claim 4, wherein: - The bilinear equation and / or the linear equation includes at least one of continuous variables, binary variables, and integer variables; and - At least one of the continuous variables and / or the binary variables is determined by solving the initial optimization problem.
6. The method according to claim 3, wherein, The at least one of the hash function relations and / or the at least one of the elementary relations includes a linear equation having continuous coefficients and binary variables.
7. The method according to claim 1 or 2, wherein, When solving the optimization problem, the initial internal state values and / or the final internal state values are fixed.
8. The method according to claim 1 or 2, further comprising: Before solving the optimization problem, the optimization problem is at least partially pre-solved.
9. The method according to claim 1 or 2, wherein, The optimization problem is a mixed-integer linear programming problem, a mixed-integer nonlinear programming problem, or a quadratic unconstrained binary optimization problem.
10. The method according to claim 1 or 2, wherein, The optimization problem is solved at least in part in the quantum processing device (22) of the data processing system (20).
11. The method according to claim 10, wherein, The optimization variables are assigned to the superposition of quantum states and / or the optimizer is the minimum of the optimization problem.
12. The method according to claim 1 or 2, wherein, The cryptographic hash function provides information security.
13. A computer program product comprising a computer program including instructions that, when executed in a data processing system (20), cause the data processing system (20) to perform the steps of the method according to any one of the preceding claims.
14. A data processing system (20) configured to determine the preimage element of a cryptographic hash function by performing the following steps: - Provides the output value of the cryptographic hash function and the hash function operation of the cryptographic hash function; - For each of the hash function operations, at least one hash function relation is determined, the hash function relation including equality and / or inequality; - Define the optimization problem, which includes - The output value, - At least one constraint assigned to the iteration of the cryptographic hash function, and - Optimization variables, which include the internal state variables of the cryptographic hash function and at least one preimage variable. Wherein, the at least one constraint is determined based on the at least one hash function relation, and the at least one constraint includes assignments to previous internal state variables from previous iterations; and - Solve the optimization problem and determine the preimage element of the cryptographic hash function based on the optimization value of the at least one preimage variable, wherein the preimage element includes at least one of the message and data file to be digitally signed or verified.
Citation Information
Patent Citations
Solving digital logic constraint problems via adiabatic quantum computation
US20150262074A1
System and method of solving optimization problems using prestored advanced bases
US7424451B1