Attack Methods for DES and ADS

The attack on DES and AES through variable component quantum algorithms solves the problem of the degradation of attack capabilities of classical symmetric encryption algorithms in quantum computing environments, and realizes high-efficiency quantum attacks on DES and AES, which is feasible in medium-scale quantum computing hardware.

CN115333717BActive Publication Date: 2025-05-13BEIJING ACAD OF QUANTUM INFORMATION SCI +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210735475.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-27
Publication Date
2025-05-13
Estimated Expiration
2042-06-27

AI Technical Summary

Technical Problem

Existing classical symmetric encryption algorithms face the problem of degradation of attack capabilities in quantum computing environments, especially the security of the Data Encryption Standard (DES) and Advanced Data Encryption Standard (AES) is under threat.

Method used

The variable component quantum algorithm is used to encrypt plaintext by superimposing state keys, build Hamiltonian and define the loss function, and use the classic gradient descent algorithm to optimize parameters to obtain the minimum value of the loss function, and then measure the data space and key space to obtain the ciphertext and key.

Benefits of technology

It effectively accelerates the attack process of classic symmetric cryptography, improves the quantum attack capabilities against DES and AES, and the low depth of quantum lines makes it possible to implement it on medium-scale quantum computing hardware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115333717B_ABST
    Figure CN115333717B_ABST
Patent Text Reader

Abstract

The present application provides an attack method for the data encryption standard and the advanced data encryption standard, comprising: encrypting a known plaintext using a superposition state key to obtain a superposition state ciphertext; constructing a Hamiltonian using the quantum state corresponding to the known ciphertext as a base state, and defining the expectation of the Hamiltonian under the superposition state ciphertext as a loss function; obtaining the minimum value of the loss function; and when the minimum value of the loss function is less than a preset threshold, measuring a data space to obtain the known ciphertext, and measuring a key space to obtain a key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of quantum computing, and in particular to an attack method and electronic device for data encryption standards and advanced data encryption standards. Background Art

[0002] Quantum computing has been widely studied and paid attention to since it was proposed in the 1980s. Due to the existence of quantum superposition and quantum entanglement, quantum computing has the advantage of parallelism. Using quantum advantages to design quantum algorithms can accelerate the solution of some classical problems. For example, the Shor algorithm proposed in the mid-to-late 1990s can exponentially accelerate the solution of large number prime factorization, and the Grover algorithm can achieve polynomial acceleration in the search of disordered data space compared to traditional algorithms.

[0003] Classic encryption algorithms mainly include symmetric encryption and asymmetric encryption. Symmetric encryption algorithms such as the Data Encryption Standard (DES) and the Advanced Data Encryption Standard (AES) are widely used in life. With the booming development of quantum computing, it is extremely important to study the attack capabilities of quantum algorithms on classical symmetric encryption algorithms. Summary of the invention

[0004] The present application aims to provide an attack method and electronic device for data encryption standard and advanced data encryption standard, which can effectively accelerate the attack of classical symmetric encryption.

[0005] According to one aspect of the present application, an attack method for a data encryption standard and an advanced data encryption standard is proposed, comprising:

[0006] Use the superposition key to encrypt the known plaintext to obtain the superposition ciphertext;

[0007] The quantum state corresponding to the known ciphertext is used as the ground state to construct a Hamiltonian, and the expectation of the Hamiltonian under the superposition ciphertext is defined as a loss function;

[0008] Obtaining the minimum value of the loss function; and

[0009] When the minimum value of the loss function is less than a preset threshold, the data space is measured to obtain the known ciphertext, and the key space is measured to obtain the key.

[0010] According to some embodiments, the method comprises:

[0011] The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext includes:

[0012] The superposition state key is obtained by acting on the key space through parameterized quantum circuits.

[0013] According to some embodiments, the method comprises:

[0014] The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext also includes:

[0015] The known plaintext is encoded in the data space to obtain the quantum state plaintext.

[0016] According to some embodiments, the method comprises:

[0017] The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext also includes:

[0018] The superposition state key is used to encrypt the quantum state plaintext according to the quantization method of the corresponding symmetric cipher to obtain the superposition state ciphertext.

[0019] According to some embodiments, the method comprises:

[0020] The parameterized quantum circuit includes N layers of anatomy, wherein N is a natural number greater than or equal to 1, and the anatomy includes a layer of Hadamard gate, a layer of rotation gate around the y-axis and a layer of cyclic control gate, wherein the y-axis refers to the y-axis in the rectangular coordinate system where the Bloch sphere is located.

[0021] According to some embodiments, the method comprises:

[0022] The classical gradient descent algorithm is used to update the parameters in the proposed hypothesis to obtain the minimum value of the loss function.

[0023] According to some embodiments, the method comprises:

[0024] The method of constructing a Hamiltonian by taking the quantum state corresponding to the known ciphertext as the base state, and defining the expectation of the Hamiltonian under the superposition ciphertext as a loss function, comprises:

[0025] The loss function is constructed by selecting a Hamiltonian with the largest ratio of the energy level difference between the ground state and the first excited state to the first energy level width, where the first energy level width is the difference between the highest energy level and the ground state.

[0026] According to some embodiments, the method comprises:

[0027] Repeating the steps of obtaining the minimum value of the loss function and measuring the superposition state ciphertext in the data space,

[0028] Furthermore, the method further comprises:

[0029] Comparing the minimum value of the loss function with the first excited state energy of the Hamiltonian;

[0030] If the minimum value of the loss function is less than the first excited state energy of the Hamiltonian, the repeated execution is stopped, the data space is measured according to the current parameters to obtain the known ciphertext, and the key space is measured to obtain the key.

[0031] According to another aspect of the present application, there is provided an electronic device, including:

[0032] Processor; and

[0033] A memory stores a computer program, and when the computer program is executed by the processor, the processor is enabled to perform any one of the above methods.

[0034] According to another aspect of the present application, a non-transitory computer-readable storage medium is provided, on which computer-readable instructions are stored. When the instructions are executed by a processor, the processor executes any one of the above methods.

[0035] According to the exemplary embodiments of the present application, the progress of quantum attacks on the Data Encryption Standard and the Advanced Data Encryption Standard is advanced through the advantages of quantum circuit depth and the loss function and the proposed design, as well as the selection of the gradient descent optimization algorithm.

[0036] It should be understood that the foregoing general description and the following detailed description are exemplary only and are not restrictive of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for describing the embodiments are briefly introduced below.

[0038] Figure 1 A flow chart of an attack method for the Data Encryption Standard and the Advanced Data Encryption Standard according to an exemplary embodiment of the present application is shown.

[0039] Figure 2 A schematic diagram showing a parameterized quantum circuit according to an exemplary embodiment of the present application.

[0040] Figure 3 A flow chart of a variational quantum algorithm according to an exemplary embodiment of the present application is shown.

[0041] Figure 4 A schematic diagram of a variational quantum algorithm according to an exemplary embodiment of the present application is shown.

[0042] Figure 5 The encryption flow chart of DES according to an exemplary embodiment of the present application is shown.

[0043] Figure 6 The following is a flowchart showing the encryption of AES-128 according to an exemplary embodiment of the present application.

[0044] Figure 7 A block diagram of an electronic device according to an exemplary embodiment is shown. DETAILED DESCRIPTION

[0045] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be comprehensive and complete and will fully convey the concepts of the example embodiments to those skilled in the art. The same reference numerals in the figures represent the same or similar parts, and thus their repeated description will be omitted.

[0046] In addition, described feature, structure or characteristic can be combined in one or more embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the embodiments of the present application. However, those skilled in the art will appreciate that the technical scheme of the present application can be put into practice without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, known methods, devices, realizations or operations are not shown or described in detail to avoid blurring the various aspects of the application.

[0047] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.

[0048] The flowcharts shown in the accompanying drawings are only exemplary and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps can be decomposed, and some operations / steps can be combined or partially combined, so the actual execution order may change according to actual conditions.

[0049] It should be understood that although the terms first, second, third, etc. may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another component. Therefore, the first component discussed below can be referred to as the second component without departing from the teachings of the concepts of the present application. As used herein, the term "and / or" includes any one of the associated listed items and all combinations of one or more.

[0050] Those skilled in the art will appreciate that the drawings are merely schematic diagrams of example embodiments, and the modules or processes in the drawings are not necessarily necessary for implementing the present application, and therefore cannot be used to limit the scope of protection of the present application.

[0051] The attack scheme designed in this application for the Data Encryption Standard (DES) and the Advanced Data Encryption Standard (AES) is based on a variational quantum algorithm and can effectively accelerate the attack on classical symmetric encryption.

[0052] The variational quantum algorithm (VQA) is a quantum-classical hybrid algorithm that can be implemented on noisy intermediate-scale quantum (NISQ) devices. VQA is expected to enable recent quantum computers to show potential advantages over classical computers in solving certain specific problems. The core of the algorithm lies in the three major processes of loss function design, ansatz construction, and parameter adjustment.

[0053] The advantages of attack schemes based on variational quantum algorithms are fundamentally derived from the powerful computing power of quantum algorithms. More specifically, quantum variational algorithms have lower time complexity and shallower quantum circuit depth. These advantages are directly related to the design of loss functions, the design of ansatz, the selection of gradient descent optimization algorithms, and the setting of parameters.

[0054] The attack scheme for the Data Encryption Standard (DES) and the Advanced Data Encryption Standard (AES) based on the quantum variational algorithm includes: a pair of known plaintext and ciphertext pairs; initialization of the key space and the data space; preparation of the superposition key and encoding the known plaintext in the data space; using the superposition key to encrypt the known plaintext according to the quantized implementation of DES or AES to obtain the superposition ciphertext; constructing a loss function; using the classical gradient descent algorithm to find the minimum value of the loss function; when measuring the data space to obtain the known ciphertext, measuring the key space to obtain the required key.

[0055] The attack scheme of the present application has a low quantum circuit depth and is very likely to be implemented on noisy medium-scale quantum computing hardware, thus greatly advancing the progress of quantum attacks on DES and AES.

[0056] The exemplary embodiments of the present application are described below with reference to the accompanying drawings.

[0057] Figure 1 A flow chart of an attack method for the Data Encryption Standard and the Advanced Data Encryption Standard according to an exemplary embodiment of the present application is shown.

[0058] See also Figure 1 In S101, the known plaintext is encrypted using the superposition state key to obtain the superposition state ciphertext.

[0059] The superposition key can be obtained by acting on the key space through parameterized quantum circuits, and the known plaintext can be encoded in the data space to obtain the quantum plaintext. The superposition key is then used to encrypt the quantum plaintext according to the quantization method of the corresponding symmetric encryption to obtain the superposition ciphertext.

[0060] According to some embodiments, the key space and the data space are initialized to State and states, where n is the key length and m is the number of qubits required for the encryption process. The key space refers to the Hilbert space where the key is located, and its size is represented by the dimension of the corresponding Hilbert space. The longer the key, the larger its key space. For example: when the key length is r, the dimension of the Hilbert space corresponding to the key space is 2 to the power of r.

[0061] According to some embodiments, a parameterized quantum circuit is designed, such as an ansatz, and is applied to a key space to obtain a superposition state key, while encoding a known plaintext in a data space.

[0062] The parameterized quantum circuit may include N layers of ansatz, where N is a natural number greater than or equal to 1, and the ansatz may include a layer of Hadamard gate, a layer of rotating gate around the y-axis, and a layer of cyclic control gate, where the y-axis refers to the y-axis in the rectangular coordinate system where the Bloch sphere is located. For a schematic diagram of a specific parameterized quantum circuit, see Figure 2 shown.

[0063] According to some embodiments, after obtaining the superposition state key and encoding the known plaintext, the superposition state key is used to encrypt the known plaintext according to the quantization implementation scheme of DES or AES to obtain the superposition state ciphertext. For specific implementation schemes, see Figure 5 and Figure 6 shown.

[0064] In S103, the quantum state corresponding to the known ciphertext is used as the ground state to construct the Hamiltonian, and the expectation of the Hamiltonian under the superposition ciphertext is defined as the loss function.

[0065] The loss function can be constructed by selecting a Hamiltonian with the largest ratio of the energy level difference between the ground state and the first excited state to the first energy level width, where the first energy level width is the difference between the highest energy level and the ground state.

[0066] According to some embodiments, the design of the loss function may include the following steps.

[0067] Encode the known ciphertext (the quantum state corresponding to the known ciphertext) as the ground state of the Hamiltonian, and convert the Hamiltonian into the quantum state ciphertext (with The expected value under (represented) is defined as the loss function. The known n-bit binary ciphertext is mapped to n nodes to construct a regular graph, and then the Hamiltonian is generated.

[0068] The value of each node in the regular graph is the value of the bit at the corresponding position (0 or 1). For a network with n nodes, an r-regular graph (r = 1, 2, ..., n-1) can be constructed. Let V(i) represent the value of the i-th node. If the i-th and j-th nodes are connected in the regular graph, the two-bit item w ij Z i Z j is added to the Hamiltonian, where Z is the Pauli-Z gate. The coefficient w ij Determined by V(i) and V(j). The specific form is as follows:

[0069]

[0070] At the same time, the single-bit item is also added to the Hamiltonian, where t i is defined as follows:

[0071]

[0072] Therefore, the Hamiltonian H can be expressed as

[0073]

[0074] Correspondingly, the loss function is defined as

[0075]

[0076] According to the above definition, for a network with n grid points, n-1 regular graphs can be generated, that is, there will be n-1 Hamiltonians to choose from. The energy level of each Hamiltonian is analyzed, and the Hamiltonian with the largest ratio of the energy level difference between the ground state and the first excited state to the entire energy level width is selected to construct the loss function. Such Hamiltonians are more easily optimized to the ground state.

[0077] Numerical analysis of the energy levels of the above Hamiltonian shows that when the connectivity When , the ratio Ratio can reach its maximum value. Therefore, when n is an even number, take When n is an odd number, take

[0078] According to some embodiments, the parameters in the parameterized quantum circuit may be updated using a classical gradient descent algorithm to obtain the minimum value of the loss function.

[0079] The classical gradient descent method may include: adding a cutoff condition and a restart condition on the basis of the classical optimization algorithm.

[0080] The cutoff condition is: when the loss function value is less than the first excited state, stop searching. Use the current parameter value to perform quantum evolution, measure the superposition ciphertext, and after obtaining the known ciphertext result, measure the key space again to obtain the required key.

[0081] The restart condition is: when the gradient value of the loss function is less than 0.08n (n is the key length), a set of parameters is randomly selected again to start optimization. This can prevent the optimization from falling into the local minimum and failing to find the global minimum.

[0082] In S105, a minimum value of the loss function is obtained. When the minimum value of the loss function is less than a preset threshold, the data space is measured to obtain a known ciphertext, and the key space is measured to obtain a key.

[0083] According to some embodiments, the parameters in ansatz are updated using a classical gradient descent algorithm to find the minimum value of the loss function. When the expected value of the Hamiltonian is less than the first excited state energy, there is a high probability that the known ciphertext is obtained by measuring the data space. When the known ciphertext is obtained, the key space is measured to obtain the required key.

[0084] According to the loss function defined in step S103, the steps of obtaining the minimum value of the loss function and measuring the superposition state ciphertext of the data space are repeated, and the minimum value of the loss function is compared with the first excited state energy of the Hamiltonian; if the minimum value of the loss function is less than the first excited state energy of the Hamiltonian, the repeated execution is stopped and the data space is measured according to the current parameters.

[0085] Figure 2 A schematic diagram showing a parameterized quantum circuit according to an exemplary embodiment of the present application.

[0086] According to some embodiments, parameterized quantum circuits are constructed in accordance with the idea of ​​using as few parameters as possible to speed up optimization, such as Figure 2 The quantum circuit shown.

[0087] Quantum circuits, which are circuits for operating quantum bits, are composed of quantum logic gates. Unlike traditional circuits, which are connected by metal wires to transmit voltage or current signals, in quantum circuits, the circuits are connected by time, that is, the state of the quantum bit evolves naturally over time, following the instructions of the Hamiltonian operator until it encounters a logic gate and is operated.

[0088] The parameterized quantum circuit may include N layers of ansatz, wherein N is a natural number greater than or equal to 1, and the ansatz includes a layer of Hadamard gate, a layer of rotation gate around the y-axis, and a layer of cyclic control gate, and the y-axis refers to the y-axis in the rectangular coordinate system where the Bloch sphere is located.

[0089] See also Figure 2 The dotted box represents an ansatz layer, which includes a Hadamard gate H and a rotating gate R around the y axis. y (β) and a layer of recurrent control gates CZ, where Z is a Pauli-Z gate. The number of parameters of a layer of ansatz is n. n is the number of key qubits, i.e., the length of the password.

[0090] The expressive power of parameterized quantum circuits can be improved by increasing the number of ansatz layers. The shallower the circuit, the lower the requirements for quantum hardware. Figure 2 The quantum circuit depth shown is exponentially reduced relative to the Grover attack (the circuit depth of the Grover attack is exponential). Due to its low quantum circuit depth, it is very likely to be implemented on noisy medium-scale quantum computing hardware, thus greatly advancing the progress of quantum attacks on DES and AES.

[0091] Figure 3 A flow chart of a variational quantum algorithm according to an exemplary embodiment of the present application is shown.

[0092] See also Figure 3 ,The variational quantum algorithm includes the following steps.

[0093] Initialize the quantum state key, and initialize the key space and data space to State and states, where n is the key length and m is the number of qubits required for the encryption process.

[0094] Initialize the quantum state data, encode the known plaintext in the data space, and obtain the quantum state corresponding to the known plaintext.

[0095] Design ansatz and apply it to the key space to obtain the superposition key. Use the superposition key to encrypt the quantum state of the known plaintext according to the quantization implementation method of DES or AES to obtain the superposition ciphertext.

[0096] The quantum state corresponding to the known ciphertext is used as the ground state to construct the Hamiltonian, and the expectation of the Hamiltonian under the superposition ciphertext is defined as the loss function. The parameters in ansatz are updated using the classical gradient descent algorithm To find the minimum value of the loss function, the update parameter here is It is calculated based on the gradient value. When the expected value of the Hamiltonian is less than the energy of the first excited state, there is a high probability that the known ciphertext will be obtained by measuring the data space. When the known ciphertext is obtained, the required key can be obtained by measuring the key space.

[0097] Figure 3The "encryption" shown in the figure means that the encryption operation is performed using the quantized implementation scheme of DES or AES; the "condition" in "measurement when the condition is met" means that the measurement result of the data space is a known ciphertext.

[0098] Figure 4 A schematic diagram of a variational quantum algorithm according to an exemplary embodiment of the present application is shown.

[0099] See also Figure 4 , the module "Ansatz" is a module containing the parameters The parameterized quantum circuit can prepare the key into a linear superposition quantum state.

[0100] Module "P" represents encoding of known plaintext into data space.

[0101] The module "DES / AES" encrypts the plaintext quantum state with the superposition state key according to the quantization implementation scheme of the corresponding symmetric cipher.

[0102] The final quantum state ciphertext of the data space Measure the loss function value and transfer it to the classical computer for optimization to obtain new parameters During the whole process, if the value of the loss function is less than the set threshold (the energy of the first excited state of the Hamiltonian), the iteration is stopped, and there is a high probability that the known ciphertext will be obtained by measuring the data space according to the current parameters. Once the known ciphertext is obtained, the corresponding key space will also collapse to the required key state, and the key can be obtained by measuring it.

[0103] The above scheme is applied to DES and AES and the quantum resource consumption is estimated. The quantum circuit of the entire attack scheme mainly includes two parts: one is the preparation of superposition state key (that is, the implementation of ansatz); the other is the quantization implementation of the corresponding symmetric encryption.

[0104] The resources consumed by the superposition key preparation are related to the key length n, requiring n Hadamard gates and n rotations R around the y axis. y door and n rotation controlled CZ doors.

[0105] The actual key length of DES encryption is 56. There are three main types of AES, namely AES-128, AES-196 and AES-256, and the corresponding key lengths are 128, 196 and 256 respectively. Figure 5 and Figure 6The encryption flow charts of DES and AES-128 are given respectively. The quantum implementation of DES requires 120 qubits; the quantum implementation of AES-128 requires 400 qubits; the quantum implementation of AES-196 requires 528 qubits; and the quantum implementation of AES-256 requires 656 qubits.

[0106] Figure 5 The encryption flow chart of DES according to an exemplary embodiment of the present application is shown.

[0107] See also Figure 5 IP in the above code indicates the replacement of the initial plaintext. -1 It is the reverse process of IP. Both processes do not require additional quantum operations. L0 and R0 represent the left and right parts of the data after being equally divided. K1 represents the subkey of the first round of encryption. f is a complex function, including data permutation and replacement operations, XOR operations with subkeys, and S-box transformations.

[0108] This part contains 16 rounds. The XOR operation with the key requires 56 CNOT gates per round. The S-box transformation can be expressed in the form of a Boolean function. According to statistics, each round requires 19 Pauli-X gates, 117 CNOT gates, 212 Toffoli gates, 268 three-bit control flip gates, 209 four-bit control flip gates, and 66 five-bit control flip gates.

[0109] After decomposing the multi-bit controlled flip gate into Toffoli gates, the required quantum resources are 19 Pauli-X gates, 117 CNOT gates and 3746 Toffoli gates.

[0110] In addition, the first, third, fifth, seventh and eighth S-boxes can be realized at the same time, and the second, fourth, sixth and eighth S-boxes can also be realized at the same time, and the corresponding Toffoli gate depths are 170 and 148 respectively. Subkey generation is just a position change and does not require additional quantum operations. The specific quantum resource consumption is shown in Table 1.

[0111] Table 1: Resource consumption of variational quantum attack on DES

[0112] Quantum Bits Hadamard Gate Pauli-X Gate <![CDATA[R y Door]]> CNOT Door CZ Door Toffoli Door depth 120 56 304 56 2384 56 59968 5088

[0113] Figure 6 The following is a flowchart showing the encryption of AES-128 according to an exemplary embodiment of the present application.

[0114] See also Figure 6, the key lengths of AES-128, AES-196 and AES-256 are 128, 196 and 256 respectively. The corresponding number of encryption rounds are 10, 12 and 14 respectively. Apart from that, their encryption operations are exactly the same, including round key addition (ARK), bit substitution (SB), row shift (SR) and column confusion (MC).

[0115] The round key addition means to perform an XOR operation on the data and the subkey of the corresponding round number, and the bit replacement contains the finite field GF(2 8 ) to find the multiplicative inverse and an affine transformation. Row shift transforms the position of the data, and column confusion is an affine transformation.

[0116] The generation of subkeys includes position swapping, bit replacement, and XOR operation with a known binary string. Overall, round key addition and column confusion only require CNOT gates, which require 128 and 277 CNOT gates respectively each time; row shift does not require additional quantum gate operations; bit replacement is the most complex, requiring single-bit gates, CNOT gates, and Toffoli gates.

[0117] In order to save the use of quantum bits, after some operations are executed, it is necessary to restore the state of the quantum bits by performing inverse operations for use in subsequent encryption coding. The specific statistics of quantum resource consumption are shown in Tables 2, 3, and 4. The CZ gate represents the above-mentioned controlled Pauli-Z gate, and the depth represents the Toffoli gate depth.

[0118] Table 2: Resource consumption of variational quantum attack on AES-128

[0119] Quantum Bits Hadamard Gate Pauli-X Gate <![CDATA[R y Door]]> CNOT Door CZ Door Toffoli Door depth 400 128 4528 128 118980 128 19064 2016

[0120] Table 3: Resource consumption of variational quantum attack on AES-196

[0121] Quantum Bits Hadamard Gate Pauli-X Gate <![CDATA[R y Door]]> CNOT Door CZ Door Toffoli Door depth 528 196 5128 196 152378 196 19580 2022

[0122] Table 4: Resource consumption of variational quantum attack on AES-256

[0123] Quantum Bits Hadamard Gate Pauli-X Gate <![CDATA[R y Door]]> CNOT Door CZ Door Toffoli Door depth 656 256 6103 256 177645 256 26774 2292

[0124] Through the simulation analysis of the variational quantum attack on the simplified version of DES (S-DES), it can be seen that its time complexity / instruction complexity / gate complexity is comparable to that of the Grover attack, and sometimes even better than the Grover attack scheme. At the same time, its quantum circuit depth is exponentially reduced compared to the Grover attack (the circuit depth of the Grover attack is exponential).

[0125] Due to the limitations of existing computing power, it is impossible to simulate DES and AES on a larger scale, but variational quantum attacks are still effective against DES and AES and maintain a complexity comparable to that of Grover's attack, with the advantage of exponentially reduced depth of quantum circuits.

[0126] The attack scheme of the present application has a low quantum circuit depth and is very likely to be implemented on noisy medium-scale quantum computing hardware, thus greatly advancing the progress of quantum attacks on DES and AES.

[0127] It should be clearly understood that the present application describes how to form and use specific examples, but the present application is not limited to any details of these examples. On the contrary, based on the teaching of the content disclosed in the present application, these principles can be applied to many other embodiments.

[0128] Those skilled in the art will appreciate that all or part of the steps to implement the above embodiments are implemented as a computer program executed by a CPU. When the computer program is executed by the CPU, the program for executing the above functions defined by the above method provided in the present application may be stored in a computer-readable storage medium, which may be a read-only memory, a disk or an optical disk, etc.

[0129] In addition, it should be noted that the above figures are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, and are not intended to be limiting. It is easy to understand that the processes shown in the above figures do not indicate or limit the time sequence of these processes. In addition, it is also easy to understand that these processes can be performed synchronously or asynchronously, for example, in multiple modules.

[0130] Through the description of the example embodiments, it is easy for those skilled in the art to understand that the attack method for the data encryption standard and the advanced data encryption standard according to the embodiments of the present application has at least one or more of the following advantages.

[0131] According to the exemplary embodiments, the progress of quantum attacks on DES and AES is advanced through the advantages of quantum circuit depth and loss function and proposed design, as well as the selection of gradient descent optimization algorithm.

[0132] Figure 7 A block diagram of an electronic device according to an exemplary embodiment is shown.

[0133] Refer to the following Figure 7 The electronic device 200 according to this embodiment of the present application is described. Figure 7 The electronic device 200 shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0134] like Figure 7As shown, the electronic device 200 is in the form of a general computing device. The components of the electronic device 200 may include, but are not limited to: at least one processing unit 210, at least one storage unit 220, a bus 230 connecting different system components (including the storage unit 220 and the processing unit 210), a display unit 240, etc.

[0135] The storage unit stores program codes, and the program codes can be executed by the processing unit 210, so that the processing unit 210 executes the methods described in this specification according to various exemplary embodiments of the present application.

[0136] The storage unit 220 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 2201 and / or a cache memory unit 2202 , and may further include a read-only memory unit (ROM) 2203 .

[0137] The storage unit 220 may also include a program / utility 2204 having a set (at least one) of program modules 2205, such program modules 2205 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.

[0138] Bus 230 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0139] The electronic device 200 may also communicate with one or more external devices 300 (e.g., keyboards, pointing devices, Bluetooth devices, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 200, and / or communicate with any device that enables the electronic device 200 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 250. Furthermore, the electronic device 200 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 260. The network adapter 260 may communicate with other modules of the electronic device 200 via the bus 230. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 200, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0140] Through the description of the above implementation methods, it is easy for those skilled in the art to understand that the example implementation methods described here can be implemented by software or by combining software with necessary hardware. The technical solution according to the implementation method of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the implementation method of the present application.

[0141] The software product may use any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, a system, device or device of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0142] Computer readable storage media may include data signals propagated in baseband or as part of a carrier wave, wherein readable program codes are carried. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program codes contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination thereof.

[0143] Program code for performing the operations of the present application may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, C++, etc., and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, as a separate software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0144] Those skilled in the art will appreciate that the above modules can be distributed in the device according to the description of the embodiment, or can be changed accordingly and only used in one or more devices different from the embodiment. The modules of the above embodiments can be combined into one module, or further divided into multiple sub-modules.

[0145] The exemplary embodiments of the present application are specifically shown and described above. It should be understood that the present application is not limited to the detailed structures, configurations or implementations described herein; on the contrary, the present application is intended to cover various modifications and equivalent configurations included in the spirit and scope of the appended claims.

Claims

1. An attack method for Data Encryption Standard and Advanced Data Encryption Standard, characterized in that: include: Use the superposition key to encrypt the known plaintext to obtain the superposition ciphertext; The method comprises: constructing a Hamiltonian using a quantum state corresponding to a known ciphertext as a ground state, and defining an expectation of the Hamiltonian under the superposition ciphertext as a loss function, including: selecting a Hamiltonian having a maximum ratio of an energy level difference between a ground state and a first excited state to a first energy level width to construct the loss function, wherein the first energy level width is a difference between a highest energy level and a ground state; Obtaining the minimum value of the loss function; as well as When the minimum value of the loss function is less than a preset threshold, the data space is measured to obtain the known ciphertext, and the key space is measured to obtain the key.

2. The method according to claim 1, characterized in that The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext includes: The superposition state key is obtained by acting on the key space through parameterized quantum circuits.

3. The method according to claim 2, characterized in that The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext also includes: The known plaintext is encoded in the data space to obtain the quantum state plaintext.

4. The method according to claim 3, characterized in that The method of using the superposition state key to encrypt the known plaintext to obtain the superposition state ciphertext also includes: The superposition state key is used to encrypt the quantum state plaintext according to the quantization method of the corresponding symmetric cipher to obtain the superposition state ciphertext.

5. The method according to claim 4, characterized in that The parameterized quantum circuit includes N layers of anatomy, wherein N is a natural number greater than or equal to 1, and the anatomy includes a layer of Hadamard gate, a layer of rotation gate around the y-axis and a layer of cyclic control gate, wherein the y-axis refers to the y-axis in the rectangular coordinate system where the Bloch sphere is located.

6. The method according to claim 5, characterized in that The parameters in the parameterized quantum circuit are updated using a classical gradient descent algorithm to obtain the minimum value of the loss function.

7. The method according to claim 1, characterized in that Repeating the steps of obtaining the minimum value of the loss function and measuring the superposition state ciphertext in the data space, Furthermore, the method further comprises: Comparing the minimum value of the loss function with the first excited state energy of the Hamiltonian; If the minimum value of the loss function is less than the first excited state energy of the Hamiltonian, the repeated execution is stopped, the data space is measured according to the current parameters to obtain the known ciphertext, and the key space is measured to obtain the key.

8. An electronic device, characterized in that: include: processor; as well as A memory storing a computer program, which, when executed by the processor, enables the processor to perform the method according to any one of claims 1 to 7.

9. A non-transitory computer-readable storage medium having computer-readable instructions stored thereon, which, when executed by a processor, causes the processor to execute the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Full-quantum molecular simulation method based on quantum computer

    CN111599414A

  • A method of constructing a semi-public key system in qap-based homomorphic encryption

    GB202118125D0