Ciphertext decryption method and related equipment
By using the quantum computing module to solve the discrete logarithm problem in the RSA algorithm and using the quantum state to decrypt the ciphertext, the technical effect of recovering the plaintext when the private key is unknown is achieved.
Patent Information
- Application Number
- CN202111365914.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-18
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2041-11-18
AI Technical Summary
In the RSA algorithm, if the key is forgotten or unknown, it is difficult to decrypt and recover the plaintext.
By obtaining the large number in the ciphertext and public key, a number smaller than the large number is selected as the base of the discrete logarithm problem, and it is converted into an initial quantum state together with the result of the modular exponentiation operation. The discrete logarithm problem is then input into the quantum computing module to solve the problem, the solution result is extracted to calculate the private key, and finally the ciphertext is decrypted to obtain the plaintext.
When the private key is unknown, the powerful computing power of quantum computing can be used to recover the plaintext of the ciphertext, solving the decryption problem when the key is forgotten or unknown.
Smart Images

Figure CN116137565B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of quantum computing, and particularly relates to a ciphertext decryption method and related equipment. BACKGROUND
[0002] In order to ensure the security of information transmission, the information is sent to the receiving end after being encrypted by the key at the sending end. The encrypted information is chaotic data and cannot directly read useful information. The encryption process is mostly based on difficult mathematical problems such as large prime number decomposition problem and discrete logarithm problem. In the case that these mathematical problems are currently difficult to solve, the security of the encrypted information is ensured. Rivest-Shamir-Adleman algorithm (RSA algorithm) is named after the three inventors. It is an algorithm for establishing public key encryption, which is based on the large number decomposition problem, that is, it is difficult to decompose a larger composite number into the product of two prime numbers within an effective time. Only when the corresponding private key is known, the plaintext can be successfully decrypted.
[0003] In the related art, the ciphertext needs to be decrypted based on the public information without knowing the decryption key, for example, when the key is forgotten or lost, the corresponding plaintext is recovered. Based on this, a ciphertext decryption method and related equipment are proposed. SUMMARY
[0004] The purpose of the present application is to provide a ciphertext decryption method and related equipment, which aims to solve the technical problem that it is difficult to decrypt the ciphertext and recover the plaintext in the case that the key is unknown in the related art.
[0005] To achieve the above purpose, the first aspect of the embodiments of the present application provides a ciphertext decryption method applied to ciphertext encrypted according to RSA algorithm, the method comprising:
[0006] Obtaining a large number in the ciphertext and the public key of the ciphertext;
[0007] Selecting a number smaller than the large number as the base of the discrete logarithm problem, selecting 1 as the modulus power operation result corresponding to the base, and converting the base and the modulus power operation result into an initial quantum state;
[0008] Inputting the initial quantum state into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state storing a solution result of the discrete logarithm problem;
[0009] Extracting the solution result from the first target quantum state, and calculating the private key of the ciphertext based on the solution result;
[0010] Decrypting the ciphertext based on the private key to obtain the plaintext of the ciphertext.
[0011] Optionally, the calculating the private key of the ciphertext based on the solving result comprises:
[0012] decomposing the large number based on the solving result to obtain a first prime number and a second prime number;
[0013] calculating an Euler function of the large number according to the first prime number and the second prime number;
[0014] calculating a second modular inverse of the Euler function as the private key of the ciphertext by taking a first modular inverse in the public key of the ciphertext as the second modular inverse with respect to a modulus.
[0015] Optionally, the decomposing the large number based on the solving result to obtain a first prime number and a second prime number comprises:
[0016] when the solving result is an even number, calculating a power operation result of the base number with an index being a half of the solving result as an intermediate result, and performing a modulo operation on the intermediate result with the large number as a modulus to obtain a first operation result;
[0017] when the first operation result is not equal to -1, calculating a greatest common divisor of the intermediate result plus 1 and the large number as the first prime number, and calculating a greatest common divisor of the intermediate result minus 1 and the large number as the second prime number.
[0018] Optionally, the method further comprises:
[0019] when the first operation result is -1, reselecting a number smaller than the large number as the base number of the discrete logarithm problem, and returning to execute the step of converting the base number and the modular exponentiation result into the initial quantum state.
[0020] Optionally, the decrypting the ciphertext based on the private key to obtain the plaintext of the ciphertext comprises:
[0021] calculating a second operation result of a modular exponentiation of the ciphertext with the second modular inverse as an index with the large number as a modulus, and taking the second operation result as the plaintext of the ciphertext.
[0022] Optionally, the method further comprises:
[0023] when the solving result is an odd number, reselecting a number smaller than the large number as the base number of the discrete logarithm problem, and returning to execute the step of converting the base number and the modular exponentiation result into the initial quantum state.
[0024] Optionally, before the converting the base number and the modular exponentiation result into the initial quantum state, the method further comprises:
[0025] determining that the greatest common divisor of the base number and the large number is 1.
[0026] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0027] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0028] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0029] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0030] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0031] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0032] Optionally, the initial quantum state is prepared by an information quantum register including a first number of qubits, the quantum computing module includes a quantum Fourier transform module and a modular exponentiation module, and the inputting of the initial quantum state into the quantum computing module for solving the discrete logarithm problem obtains a first target quantum state in which a solution result of the discrete logarithm problem is stored, and the inputting includes:
[0033] Optionally, the first modular exponentiation module and the second modular exponentiation module each include a modular multiplication module.
[0034] Optionally, the quantum Fourier transform module includes a module for implementing forward quantum Fourier transform and / or a module for implementing inverse quantum Fourier transform.
[0035] Optionally, the extracting of the solution result from the first target quantum state includes:
[0036] measuring a parameter quantum register in the first target quantum state to obtain a measurement result;
[0037] constructing a matrix L based on the measurement result, the matrix L satisfying the following form:
[0038]
[0039] wherein A:=diag(u,…,u), u is the maximum eigenstate number of the first parameter quantum register, the vector elements in the vector are the measurement results corresponding to the first parameter quantum register;
[0040] obtaining a generating subspace of the matrix L based on the row vectors of the matrix L;
[0041] for any vector in the generating subspace, obtaining the last element of the vector as a to-be-verified to-be-solved logarithm;
[0042] determining that the to-be-verified to-be-solved logarithm satisfies a logarithm relationship of the discrete logarithm problem;
[0043] determining that the to-be-verified to-be-solved logarithm is the solving result.
[0044] Optionally, the measurement result is multiple, and the constructing a matrix L based on the measurement result comprises:
[0045] obtaining a preset number of measurement results from all the measurement results to construct a matrix L.
[0046] Optionally, before the obtaining the last element of the vector as a to-be-verified to-be-solved logarithm, the method further comprises:
[0047] calculating a target distance between each vector in the generating subspace and a reference vector, the last element of the reference vector being 0 and the other elements being -2 n the measurement result corresponding to the second quantum register, n being the difference between the number of quantum bits of the first quantum register and the number of quantum bits of the second quantum register;
[0048] determining that each target distance is less than a preset distance.
[0049] Optionally, the method further comprises:
[0050] determining that any target distance is greater than or equal to the preset distance;
[0051] obtaining a preset number of new measurement results from all the measurement results to construct a matrix L′;
[0052] The matrix L' is taken as the matrix L, and the step of obtaining the generating subspace of the matrix L based on the row vector of the matrix L is performed again.
[0053] Optionally, the preset distance is Wherein, s is the preset number.
[0054] A second aspect of the embodiment of the application provides a ciphertext decryption device, which is applied to a ciphertext encrypted according to an RSA algorithm, and the device comprises:
[0055] An acquisition module is configured to acquire a large number in a ciphertext and a public key of the ciphertext.
[0056] A selection and transformation module is configured to select a number smaller than the large number as a base number of a discrete logarithm problem, select 1 as a modulus power operation result corresponding to the base number, and transform the base number and the modulus power operation result into an initial quantum state.
[0057] An input module is configured to input the initial quantum state into a quantum computing module configured to solve the discrete logarithm problem, to obtain a first target quantum state in which a solution result of the discrete logarithm problem is stored.
[0058] An extraction and calculation module is configured to extract the solution result from the first target quantum state, and calculate a private key of the ciphertext based on the solution result.
[0059] A decryption module is configured to decrypt the ciphertext based on the private key to obtain plaintext of the ciphertext.
[0060] Optionally, the extraction and calculation module is further configured to:
[0061] decompose the large number based on the solution result to obtain a first prime number and a second prime number;
[0062] calculate an Euler function of the large number according to the first prime number and the second prime number;
[0063] calculate a second modular inverse of a first modular inverse in the public key of the ciphertext with respect to a modulus as the Euler function to obtain the second modular inverse as the private key of the ciphertext.
[0064] Optionally, the extraction and calculation module is further configured to:
[0065] when the solution result is an even number, calculate a power operation result of the base number when an index is a half of the solution result as an intermediate result, and perform a modulus operation on the intermediate result with the large number as a modulus to obtain a first operation result;
[0066] When the first operation result is not equal to -1, a greatest common divisor of the sum of the intermediate result plus 1 and the large number is calculated as a first prime number, and a greatest common divisor of the difference of the intermediate result minus 1 and the large number is calculated as a second prime number.
[0067] Optionally, the apparatus further comprises:
[0068] The first reselection module is configured to, when the first operation result is -1, reselect a number smaller than the large number as a base of the discrete logarithm problem, and return to execute the step of converting the base and the modular exponentiation operation result into the initial quantum state.
[0069] Optionally, the decryption module is further configured to:
[0070] The second operation result of the modular exponentiation of the ciphertext when the exponent is the second modular multiplication inverse element is calculated with the large number as a modulus, and the second operation result is taken as the plaintext of the ciphertext.
[0071] Optionally, the apparatus further comprises:
[0072] The second reselection module is configured to, when the solving result is an odd number, reselect a number smaller than the large number as a base of the discrete logarithm problem, and return to execute the step of converting the base and the modular exponentiation operation result into the initial quantum state.
[0073] Optionally, the apparatus further comprises:
[0074] The first determination module is configured to, before the conversion module converts the base and the modular exponentiation operation result into the initial quantum state, determine that a greatest common divisor of the base and the large number is 1.
[0075] Optionally, the initial quantum state is prepared by an information quantum register comprising a first number of quantum bits, the quantum computing module comprises a quantum Fourier transform module and a modular exponentiation multiplication module, and the input module is further configured to:
[0076] Obtain a parameter quantum register comprising a second number of quantum bits, and prepare the parameter quantum register into a superposition state formed by quantum substates with equal amplitudes;
[0077] Input the initial quantum state and the superposition state into the modular exponentiation multiplication module to obtain a second target quantum state, when in the second target quantum state, a quantum state of the information quantum register and a quantum state of the parameter quantum register satisfy a preset entanglement relation corresponding to a modular exponentiation multiplication operation;
[0078] Input the quantum state of the parameter quantum register in the second target quantum state into the quantum Fourier transform module to obtain a first target quantum state.
[0079] Optionally, the modular exponentiation module comprises a first modular exponentiation module and a second modular exponentiation module connected in cascade, the information quantum register comprises a first information quantum register and a second information quantum register, the parameter quantum register comprises a first parameter quantum register and a second parameter quantum register, and the input module is further configured to:
[0080] input the quantum state of the first information quantum register in the initial quantum state and the quantum state of the first parameter quantum register in the superposition state into the first modular exponentiation module to obtain an intermediate quantum state;
[0081] input the quantum state of the second information quantum register in the initial quantum state, the quantum state of the second parameter quantum register in the superposition state, and the intermediate quantum state into the second modular exponentiation module to obtain a second target quantum state.
[0082] Optionally, the first modular exponentiation module and the second modular exponentiation module each comprise a modular multiplication module connected in cascade.
[0083] Optionally, the quantum Fourier transform module comprises a module for implementing forward quantum Fourier transform and / or a module for implementing inverse quantum Fourier transform.
[0084] Optionally, the extraction calculation module is further configured to:
[0085] measure the parameter quantum register in the first target quantum state to obtain a measurement result;
[0086] construct a matrix L based on the measurement result, the matrix L satisfying the following form:
[0087]
[0088] wherein A:=diag(u,…,u), u is the maximum eigenstate quantity of the first parameter quantum register, the vector is the measurement result corresponding to the first parameter quantum register;
[0089] obtain a generating subspace of the matrix L based on the row vectors of the matrix L;
[0090] for any vector in the generating subspace, obtain the last element of the vector as a to-be-verified to-be-solved logarithm;
[0091] determine that the to-be-verified to-be-solved logarithm satisfies the logarithm relationship of the discrete logarithm problem;
[0092] determine that the to-be-verified to-be-solved logarithm is the solving result.
[0093] Optionally, the measurement results are multiple, and the extraction calculation module is further configured to:
[0094] The matrix L is constructed by a preset number of measurement results from all the measurement results.
[0095] Optionally, the device further comprises:
[0096] The distance calculation module is configured to calculate a target distance between each vector in the generated subspace and a reference vector before the extraction calculation module obtains the last element of the vector as a to-be-verified to-be-solved logarithm, wherein the last element of the reference vector is 0, and the remaining elements are -2. n The product of the measurement results corresponding to the second quantum register, and n is the difference between the number of quantum bits of the first quantum register and the second quantum register.
[0097] The second determination module is configured to determine that each target distance is less than a preset distance.
[0098] Optionally, the device further comprises:
[0099] The third determination module is configured to determine that any target distance is greater than or equal to the preset distance.
[0100] The reconstruction module is configured to obtain a new matrix L' by a preset number of measurement results from all the measurement results.
[0101] The return execution module is configured to take the matrix L' as the matrix L, and return to execute the step of obtaining the generated subspace of the matrix L based on the row vector of the matrix L.
[0102] Optionally, the preset distance is Wherein, s is the preset number.
[0103] In a third aspect of the embodiments of the present application, a storage medium is provided, and the storage medium stores a computer program, wherein the computer program is configured to execute the steps of the method in any one of the first aspect when running.
[0104] In a fourth aspect of the embodiments of the present application, an electronic device is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the steps of the method in any one of the first aspect when running the computer program.
[0105] Based on the above technical scheme, a number smaller than the large number in the public key and 1 are selected as inputs for solving the discrete logarithm problem, the number and 1 are converted into initial quantum states, and then input into a quantum computing module for solving the discrete logarithm problem. By means of the powerful computing power of quantum computing, a first target quantum state containing a discrete logarithm solution is obtained, and then the solution is extracted from the first target quantum state to calculate the private key. Finally, the private key is used to decrypt the ciphertext to obtain the plaintext. Thus, in the case where the private key is unknown in advance, the corresponding private key can be restored only by using the public key which has been disclosed, and the plaintext can be recovered, thereby solving the technical problem that it is difficult to recover the plaintext when the private key is unknown, and filling the related technical gap. BRIEF DESCRIPTION OF DRAWINGS
[0106] Figure 1 FIG. 1 is a hardware structure block diagram of a computer terminal for a ciphertext decryption method according to an exemplary embodiment.
[0107] Figure 2 FIG. 2 is a flowchart of a ciphertext decryption method according to an exemplary embodiment.
[0108] Figure 3 FIG. 3 is a flowchart of step S23 included in a ciphertext decryption method according to an exemplary embodiment.
[0109] Figure 4 FIG. 4 is a schematic diagram of a quantum computing module according to an exemplary embodiment.
[0110] Figure 5 FIG. 5 is a flowchart of step S232 included in a ciphertext decryption method according to an exemplary embodiment.
[0111] Figure 6 FIG. 6 is a flowchart of step S24 included in a ciphertext decryption method according to an exemplary embodiment.
[0112] Figure 7 FIG. 7 is another flowchart of step S24 included in a ciphertext decryption method according to an exemplary embodiment.
[0113] Figure 8 FIG. 8 is another flowchart of step S24 included in a ciphertext decryption method according to an exemplary embodiment.
[0114] Figure 9 FIG. 9 is another flowchart of step S24 included in a ciphertext decryption method according to an exemplary embodiment.
[0115] Figure 10 FIG. 10 is a flowchart of step S2421 included in a ciphertext decryption method according to an exemplary embodiment.
[0116] Figure 11 is another flow chart of a ciphertext decryption method according to an example embodiment.
[0117] Figure 12 is another flow chart of a ciphertext decryption method according to an example embodiment.
[0118] Figure 13 is a schematic diagram of a modular multiplication operation module according to an example embodiment.
[0119] Figure 14 is a schematic diagram of a modular addition operation module according to an example embodiment.
[0120] Figure 15 is a block diagram of a ciphertext decryption apparatus according to an example embodiment. DETAILED DESCRIPTION
[0121] The embodiments described below are exemplary and are intended to explain the present application, but are not intended to limit the present application.
[0122] The embodiments of the present application first provide a ciphertext decryption method, which is applied to ciphertext encrypted according to RSA algorithm. The method can be applied to electronic devices, such as computer terminals, specifically, common computers, quantum computers, etc.
[0123] The following will be described in detail taking a computer terminal as an example. Figure 1 is a hardware structure block diagram of a computer terminal for a ciphertext decryption method according to an example embodiment. As shown in Figure 1 , the computer terminal can include one or more (only one is shown in Figure 1 ) processors 102 (the processor 102 can include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing a quantum circuit-based ciphertext decryption method. Optionally, the above computer terminal can also include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 the structure shown is only schematic, which does not limit the structure of the above computer terminal. For example, the computer terminal can also include more or less components than those shown in Figure 1 , or have a different configuration from Figure 1 .
[0124] The memory 104 can be used to store software programs of application software and modules, such as program instructions / modules corresponding to the ciphertext decryption method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the computer terminal through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0125] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network can include a wireless network provided by a communication provider of the computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet in a wireless manner.
[0126] It should be noted that a real quantum computer is a hybrid structure, which includes two parts: one part is a classical computer responsible for performing classical computation and control; the other part is a quantum device responsible for running a quantum program to implement quantum computation. The quantum program is a sequence of instructions written in a quantum language such as QRunes language that can run on a quantum computer, which supports quantum logic gate operations and finally realizes quantum computation. Specifically, the quantum program is a sequence of instructions for operating quantum logic gates in a certain time sequence.
[0127] In actual applications, due to the limitation of the development of quantum device hardware, quantum computation simulation is usually needed to verify quantum algorithms, quantum applications, and the like. Quantum computation simulation is a process of simulating the running of a quantum program corresponding to a specific problem by means of a virtual architecture (i.e., a quantum virtual machine) built by the resources of an ordinary computer. Generally, a quantum program corresponding to a specific problem needs to be constructed. The quantum program referred to in the embodiments of the present application is a program written in a classical language representing quantum bits and their evolution, in which quantum bits, quantum logic gates, and the like related to quantum computation are represented by corresponding classical codes.
[0128] As a kind of embodiment of quantum program, quantum circuit, also called quantum logic circuit, is the most commonly used general quantum computing model, which represents the circuit for operating quantum bits in abstract concept, and its composition includes quantum bits, circuit (time line) and various quantum logic gates, and finally the result is usually read out through quantum measurement operation.
[0129] Unlike traditional circuits connected by metal wires to transmit voltage signals or current signals, in quantum circuits, the circuit can be regarded as being connected by time, that is, the state of quantum bits evolves naturally with time, and in this process, it is always operated according to the instruction of Hamiltonian operator until it encounters a logic gate.
[0130] A quantum program corresponds to a total quantum circuit as a whole, and the quantum program in the present application refers to the total quantum circuit, wherein the total number of quantum bits in the total quantum circuit is the same as the total number of quantum bits of the quantum program. It can be understood that: a quantum program can be composed of a quantum circuit, a measurement operation for quantum bits in the quantum circuit, a register for storing measurement results and a control flow node (jump instruction), and a quantum circuit can contain tens, hundreds or even thousands of quantum logic gate operations. The execution process of the quantum program is the process of executing all quantum logic gates in a certain time sequence. It should be noted that the time sequence is the time sequence of the execution of individual quantum logic gates.
[0131] It should be noted that in classical computing, the most basic unit is a bit, and the most basic control mode is a logic gate, which can be combined to achieve the purpose of controlling the circuit. Similarly, the way to handle quantum bits is quantum logic gates. Using quantum logic gates can make quantum states evolve, and quantum logic gates are the basis of quantum circuits. Quantum logic gates include single-bit quantum logic gates such as Hadamard gate (H gate), Pauli-X gate (X gate), Pauli-Y gate (Y gate), Pauli-Z gate (Z gate), RX gate, RY gate, RZ gate, etc., and multi-bit quantum logic gates such as CNOT gate, CR gate, iSWAP gate, Toffoli gate, etc. Quantum logic gates are generally represented by unitary matrices, which are not only matrix forms, but also operations and transformations. The effect of a general quantum logic gate on a quantum state is calculated by multiplying the quantum state right vector by the unitary matrix on the left.
[0132] For the communication process based on RSA algorithm encryption, the receiving end sends the public key corresponding to the private key to the sending end, the sending end encrypts the plaintext using the public key to obtain the ciphertext, and sends it to the receiving end, and the receiving end decrypts the ciphertext using its own private key to obtain the plaintext. If you want to calculate the private key based on the public key, you need to factor the large number in the public key, which is difficult to achieve, so as to ensure the security of communication. The large number decomposition in RSA algorithm can be transformed into the problem of finding the prime factor of y=xr The problem of calculating r given p, y and x is also difficult, i.e. the discrete logarithm problem in RSA algorithm.
[0133] Figure 2 Fig. 1 is a flow chart of a ciphertext decryption method according to an exemplary embodiment, as shown in Fig. 1, the embodiment provides a ciphertext decryption method which can be applied to ciphertext encrypted according to RSA algorithm, and the method comprises the following steps: Figure 2
[0134] S21, obtaining a ciphertext and a large number in a public key of the ciphertext.
[0135] S22, selecting a number smaller than the large number as a base of a discrete logarithm problem, selecting 1 as a modulus power operation result corresponding to the base, and converting the base and the modulus power operation result into an initial quantum state.
[0136] S23, inputting the initial quantum state into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which a solution of the discrete logarithm problem is stored.
[0137] S24, extracting the solution from the first target quantum state, and calculating a private key of the ciphertext based on the solution.
[0138] S25, decrypting the ciphertext based on the private key to obtain plaintext of the ciphertext.
[0139] In step S21, the ciphertext and the public key are both disclosed through public channels, so these information can be obtained through these public channels. For the public key of RSA algorithm, it generally contains two parts, one of which is a large number. After obtaining the public key, the large number can be obtained from the public key.
[0140] After obtaining the ciphertext and the large number, step S22 is performed to select a number smaller than the large number as a base of a discrete logarithm problem, i.e. as the above x, and further an integer greater than 1 and smaller than the large number can be selected. In addition, 1 is selected as a modulus power operation result corresponding to the base x, i.e. the above y, and the base and the power operation result are converted into an initial quantum state for representing information of the two, for example, the base x can be converted into an initial quantum state |x>, and the power operation result y is converted into |y>, wherein y = 1.
[0141] After obtaining the initial quantum state, step S23 is performed to solve the discrete logarithm problem, i.e., to obtain the order r given the above x and y, which is the solution to the discrete logarithm problem. After the initial quantum state is prepared, the initial quantum state is input into a quantum computing module for solving the discrete logarithm problem, and a first target quantum state is output. At this time, the solution to the discrete logarithm problem is directly or indirectly stored in the first target quantum state. The solution can be present in the complex amplitudes of each quantum state of the first target quantum state, or can be present in the entanglement relationship of each quantum state of the first target quantum state. The solution itself can be present in the first target quantum state, or information related to the solution, such as information obtained by decomposing the solution, can be present in the first target quantum state, and the solution can be obtained by further calculating based on the information. It should be noted that the quantum states of a quantum state are basis states that superimpose to form the quantum state. For example, for a quantum state |0〉 and |1> are quantum states thereof.
[0142] Alternatively, referring to Figure 3 and Figure 4 , the initial quantum state is prepared by an information quantum register including a first number of quantum bits, and the quantum computing module includes a quantum Fourier transform module 420 and a modular exponentiation module 410. Alternatively, the initial quantum state is input into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which the solution to the discrete logarithm problem is stored, including:
[0143] S231, obtaining a parameter quantum register including a second number of quantum bits, and preparing the parameter quantum register to a superposition state formed by quantum states with equal amplitudes.
[0144] S232, inputting the initial quantum state and the superposition state into the modular exponentiation module to obtain a second target quantum state. When in the second target quantum state, the quantum state of the information quantum register and the quantum state of the parameter quantum register satisfy a predetermined entanglement relationship corresponding to the modular exponentiation operation.
[0145] S233, inputting the quantum state of the parameter quantum register in the second target quantum state into the quantum Fourier transform module to obtain a first target quantum state.
[0146] Both the information quantum register and the parameter quantum register are quantum registers containing a certain number of qubits. In step S231, to facilitate the quantum computing module's solution to the discrete logarithm problem, a parameter quantum register is introduced to construct parameters related to the initial quantum state within the following entanglement relationship. Obtaining a parameter quantum register containing a second number of qubits can be a call to an existing quantum register. The superposition state described above can be prepared by applying an H-gate to each qubit in the parameter quantum register. In one possible embodiment, the parameter quantum register may include a first parameter quantum register and a second parameter quantum register.
[0147] Continuing with the above example, we can select a first parameter quantum register containing l+n qubits, see Figure 4 The quantum register on the fourth circuit from top to bottom, where That is, the minimum number of quantum bits that can represent the solution r to be solved can be estimated through relevant information. If there is no relevant information, the number of elements of the group corresponding to the above discrete logarithm problem can be regarded as r. s is a preset number. At the same time, a second parameter quantum register containing l quantum bits is selected, that is, Figure 4 In the quantum register of the last circuit from top to bottom, each qubit of the first parameter quantum register and the second parameter quantum register is prepared to the quantum state |0>, and then the H gate is applied to each qubit with the quantum state |0> to obtain the superposition state formed by the quantum substates of equal amplitude as follows:
[0148]
[0149] Where u = 2 l+n , v = 2 l , a, b correspond to the quantum states of the first parameter quantum register and the second parameter quantum register respectively.
[0150] In step S232, modular exponentiation multiplication module 410 is used to implement the aforementioned entanglement relationship. After the initial quantum state and superposition state are input into modular exponentiation multiplication module 410, they continuously evolve under the action of quantum logic gates within modular exponentiation multiplication module 410, ultimately obtaining a second target quantum state. This causes the qubits of the information quantum register and the qubits of the parameter quantum register to become entangled according to a preset entanglement relationship. The entanglement relationship corresponding to the modular exponentiation operation refers to the entanglement relationship corresponding to the modular operation of the product of the exponentiation operation.
[0151] Alternatively, see Figure 4 The modular exponentiation multiplication module 410 includes a cascaded first modular exponentiation operation module 411 and a second modular exponentiation operation module 412, and the information quantum register includes a first information quantum register and a second information quantum register.
[0152] Optionally, referring to Figure 5 inputting the initial quantum state and the superposition state into the modular exponentiation module to obtain a second target quantum state, comprising:
[0153] S2321, inputting the quantum state of the first information quantum register in the initial quantum state and the quantum state of the first parameter quantum register in the superposition state into the first modular exponentiation module to obtain an intermediate quantum state.
[0154] S2322, inputting the quantum state of the second information quantum register in the initial quantum state, the quantum state of the second parameter quantum register in the superposition state, and the intermediate quantum state into the second modular exponentiation module to obtain a second target quantum state.
[0155] The first modular exponentiation module 411 and the second modular exponentiation module 412 are both modules for implementing modular exponentiation. In step S2321, for example, the initial quantum state of the first information quantum register can be |x> described above, and the quantum state of the first parameter quantum register in the superposition state is |a>, and |x> and |a> are input into the first modular exponentiation module 411 to obtain an intermediate quantum state.
[0156] After obtaining the intermediate quantum state, step S2322 is performed, and using the above example, the initial quantum state of the second information quantum register can be |y> described above, and the quantum state of the second parameter quantum register in the superposition state is |b>, and then |y>, |b>, and the intermediate quantum state are input into the second modular exponentiation module 412 to obtain a second target quantum state where N is a large number in the public key described above. It should be noted that since modular exponentiation is actually implemented by multiple modular multiplication operations, in step S2321, multiple modular multiplications of x can be regarded as obtaining the entanglement relationship x a (mod N), and in step S2322, multiple modular multiplications of x a and multiple y can be regarded as obtaining the entanglement relationship x a *y b (mod N). Figure 4 From top to bottom, the quantum bits of the first three lines of the circuit belong to the information quantum register, and the quantum bits of the first information quantum register and the second information quantum register are all from the information quantum register. As for how to divide them, the present application does not make specific limitations.
[0157] In step S233, referring to Figure 4, the second target quantum state of the parameter quantum register is evolved into the first target quantum state described above under the action of the quantum Fourier transform module 420. The quantum Fourier transform module 420 is a module composed of quantum circuits for implementing Fourier transform. Optionally, the quantum Fourier transform module 420 includes a module for implementing forward quantum Fourier transform and / or a module for implementing inverse quantum Fourier transform. Continuing with the example described above, the second target quantum state output by the modular exponentiation module 410 is input into the quantum Fourier transform module 420 along with the quantum state of the first parameter quantum register and the second parameter quantum register in the
[0158]
[0159] , where c and d respectively represent the quantum states of the first parameter quantum register and the second parameter quantum register after the action of the quantum Fourier transform module 420 described above, i is an imaginary number, r is the order of the base x in the discrete logarithm problem described above, and the remaining parameters can be referred to the description above.
[0160] After obtaining the first target quantum state, step S24 is performed to extract the solution result from the first target quantum state, and related operations are performed based on the solution result to obtain the private key of the ciphertext. Specifically, the measurement result related to the solution result can be obtained by measuring the first target quantum state, and then the measurement result is transformed to extract the solution result.
[0161] Optionally, referring to Figure 6 , the solution result is extracted from the first target quantum state, including:
[0162] S2411, measuring the parameter quantum register in the first target quantum state to obtain a measurement result.
[0163] S2412, constructing a matrix L based on the measurement result, the matrix L satisfying the following form:
[0164]
[0165] , where A = diag(u, …, u), u is the maximum eigenstate number of the first parameter quantum register, and the vector The elements in the vector are the measurement results corresponding to the first parameter quantum register.
[0166] S2413, obtaining the generating subspace of the matrix L based on the row vectors of the matrix L.
[0167] S2414, for any vector in the generating subspace, obtaining the last element of the vector as the logarithm to be verified and solved.
[0168] S2415, determining whether the to-be-verified to-be-solved logarithm satisfies the logarithm relationship of the discrete logarithm problem.
[0169] S2416, determining that the to-be-verified to-be-solved logarithm is the solving result.
[0170] In step S2411, the first parameter quantum register and the second parameter quantum register in the first target quantum state are measured according to the above example, and the first target quantum state collapses to the quantum state |c, d, x (a+br) (mod N), and the amplitude is:
[0171]
[0172] Wherein, each parameter can refer to the description above. The measurement of the first target quantum state can be performed by means such as projection measurement. In order to make the measurement result as accurate as possible, multiple measurements can be performed, and the measurement results obtained can include different quantum states and the number of times of collapsing to the corresponding quantum state.
[0173] In step S2412, the above matrix L is constructed according to the measurement result, in which A is a diagonal matrix, the diagonal elements are u, and the vector The elements in the vector can be the number of times of occurrence of the corresponding collapsed quantum state. Then in step S2413, the row vectors of the matrix L are linearly combined to obtain the generating subspace of the matrix L. Then step S2414 is performed, and a vector is randomly taken from the generating subspace, and the last element of the vector is taken as the to-be-verified to-be-solved logarithm, so as to verify in step S2415 whether it satisfies the logarithm relationship of the discrete logarithm problem, such as the above operation relationship y=x r (mod N), and the to-be-solved logarithm obtained is substituted into the formula to verify whether the formula is correct, and if it is correct, it is determined that the logarithm relationship is correct. Then in step S2416, the to-be-solved logarithm satisfying the logarithm relationship is taken as the solving result for subsequent private key calculation.
[0174] Optionally, the measurement result is multiple, and in step S2412, the matrix L is constructed based on the measurement result, including:
[0175] The matrix L is constructed from a preset number of measurement results among all the measurement results.
[0176] For the quantum state |c, d, x (a+br) (mod N), and b is converted around the center point The amplitude after the localization conversion can be expressed as:
[0177]
[0178] Wherein, {rc+2n d} u representing The remaining elements can be seen from the above description. When |c, d> satisfies {rc+2 n d} u ≤2 n-2 , |c, d> is defined as a good state, which corresponds to a more concentrated amplitude, facilitating the determination of the to-be-solved logarithm. Since the number of good states is at least 2 l+n-1 , the probability of observing a specified good state is at least 2 -n-l-2 . Therefore, the probability of observing any good state in a single run is 2 -3 . Therefore, after running 8s times, we can obtain s good state measurement results with a probability of about 50%. Further, in step S2412, a predetermined number of measurement results are obtained from all measurement results, and there is a certain probability of obtaining a good state, for example, when the measurement result is 8s times, the predetermined number is s, and s measurement results are obtained. If they are all good states, the efficiency of obtaining the correct to-be-solved logarithm in subsequent operations can be improved.
[0179] Optionally, referring to Figure 7 , extracting the solving result from the first target quantum state as a private key for decrypting the ciphertext, comprising:
[0180] S241a, measuring the parameter quantum register in the first target quantum state to obtain a measurement result.
[0181] S241b, constructing a matrix L based on the measurement result, the matrix L satisfies the following form:
[0182]
[0183] Wherein, A = diag(u,…,u), u is the maximum eigenstate number of the first parameter quantum register, and the elements in the vector are the measurement results corresponding to the first parameter quantum register.
[0184] S241 c, obtaining the generating subspace of the matrix L based on the row vectors of the matrix L.
[0185] S241 d, calculating the target distance between each vector in the generating subspace and a reference vector, the last element of the reference vector is 0, and the rest of the elements are the product of -2 n and the measurement result corresponding to the second quantum register, n is the difference between the number of quantum bits of the first quantum register and the second quantum register.
[0186] S241 e, determining that each target distance is less than a predetermined distance.
[0187] S241 f, for any vector in the generated subspace, obtaining the last element of the vector as a to-be-verified to-be-solved logarithm.
[0188] S241 g, determining that the to-be-verified to-be-solved logarithm satisfies the logarithm relationship of the discrete logarithm problem.
[0189] S241 h, determining that the to-be-verified to-be-solved logarithm is the solving result.
[0190] For steps S241 a to S241 c, refer to steps S2411 to S2413 described above.
[0191] In step S241 d, using the above example, the reference vector is constructed as follows:
[0192]
[0193] Wherein, d1,…,d s The number of times of occurrence of the above-mentioned second parameter quantum register corresponding to different collapsed quantum states, and the remaining parameters can be referred to the above description. Further, lattice-based techniques are applied to each vector of the above-mentioned generated subspace Calculate the target distance of the two
[0194] After calculating the target distance, step S241 e is executed to determine whether the target distance is less than the preset distance. If it is less than the preset distance, it means that |c, d> are both good states, and then step S241 f is executed. Alternatively, the preset distance is Wherein, s is the preset number. Steps S241 f to S241 h can refer to the description of steps S2414 to S2416 described above.
[0195] Alternatively, referring to Figure 8 Extracting the solving result from the first target quantum state as a private key for decrypting the ciphertext, comprising:
[0196] S241A, measuring the parameter quantum register in the first target quantum state to obtain a measurement result.
[0197] S241 B, constructing a matrix L based on the measurement result, the matrix L satisfies the following form:
[0198]
[0199] Wherein, A = diag(u,…,u), u is the maximum eigenstate number of the first parameter quantum register, and the vector the elements in the matrix L are the measurement results corresponding to the first parameter quantum register.
[0200] S241 C, obtaining a generating subspace of the matrix L based on the row vectors of the matrix L.
[0201] S241 D, calculating a target distance of each vector in the generating subspace to a reference vector, the last element of the reference vector is 0 and the rest elements are -2 n the product of the measurement results corresponding to the second quantum register, n is the difference between the number of quantum bits of the first quantum register and the second quantum register.
[0202] S241 E, determining that each of the target distances is less than a preset distance.
[0203] S241 F, for any vector in the generating subspace, obtaining the last element of the vector as a to-be-verified to-be-solved logarithm.
[0204] S241 G, determining that the to-be-verified to-be-solved logarithm satisfies the logarithm relationship of the discrete logarithm problem.
[0205] S241 H, determining that the to-be-verified to-be-solved logarithm is the solving result.
[0206] S241 I, determining that any of the target distances is greater than or equal to the preset distance.
[0207] S241 J, obtaining a preset number of new measurement results from all the measurement results to construct a matrix L'.
[0208] S241 K, taking the matrix L' as the matrix L, and returning to execute the step of obtaining a generating subspace of the matrix L based on the row vectors of the matrix L.
[0209] For the above steps S241A to S241H, refer to the description of the above steps S241a to S241h.
[0210] In step S241I, if it is judged that the target distance is greater than or equal to the preset distance, it indicates that |c, d> is not in good condition, and then step S241F is not executed, and step S241J is executed. The matrix L' is constructed in the same way as the matrix L, and the difference is only in the element value. Then in step S241K, the matrix L' is taken as the matrix L, and the steps S241C and the subsequent steps are executed until the target distance corresponding to the matrix L is less than the preset distance, so as to obtain the correct solving result.
[0211] Alternatively, see Figure 9 , calculating the private key of the ciphertext based on the solution result, including:
[0212] S2421, decompose the large number based on the solution result to obtain a first prime number and a second prime number.
[0213] S2422: Calculate the Euler function of the large number according to the first prime number and the second prime number.
[0214] S2423, calculating the second modular inverse element of the first modular inverse element in the public key of the ciphertext with respect to the modulus of the Euler function, and obtaining the second modular inverse element as the private key of the ciphertext.
[0215] In step S2421, when the above solution result is known, the large number can be decomposed according to a relevant algorithm to obtain the first prime number and the second prime number.
[0216] Alternatively, see Figure 10 , decomposing the large number based on the solution result to obtain a first prime number and a second prime number, including:
[0217] SI, when the solution result is an even number, the power operation result of the base when the calculated exponent is half of the solution result is used as an intermediate result, and the intermediate result is modulo operated with the large number as the modulus to obtain the first operation result.
[0218] SII, when the first operation result is not equal to -1, calculate the greatest common divisor of the sum of the intermediate result plus 1 and the large number as the first prime number, and calculate the difference between the intermediate result minus 1 and the greatest common divisor of the large number as the second prime number.
[0219] In step S1, using the above example, when the solution r is determined to be an even number, the exponent of the base x is calculated as The result of the power operation As an intermediate result, the modulus operation is then performed on it As the first operation result. Then execute step SII, and when it is determined that the first operation result is not -1, calculate As the first prime number, calculate As the second prime number, gcd represents the greatest common divisor, and N is the above large number.
[0220] After calculating the first prime number and the second prime number, step S2422 is executed to calculate the Euler function of the large number based on the two prime numbers. Specifically, the Euler function φ(N)=(p-1)(q-1) can be calculated, where p and q are the first prime number and the second prime number, respectively.
[0221] Then step S2423 is performed, and in the above example, since ed≡1mod φ(N), where e is the non-large number part in the public key, d is the non-large number part in the private key, e and d are mutually modular multiplicative inverses with respect to the Euler function φ(N), e is the first modular multiplicative inverse, and d is the second modular multiplicative inverse. In the case where the first modular multiplicative inverse e and the Euler function φ(N) are known, the second modular multiplicative inverse d can be calculated, and specifically, the second modular multiplicative inverse d can be calculated by using the Extended Euclidean Algorithm and taken as the private key for decrypting the ciphertext.
[0222] After the private key is calculated, step S24 is performed, the ciphertext is decrypted by using the private key to obtain the original plaintext, and the ciphertext can be decrypted by using a decryption method in the RSA encryption system.
[0223] Optionally, the ciphertext is decrypted based on the private key to obtain plaintext of the ciphertext, and the method comprises the following steps.
[0224] Taking the large number as a modulus, a second operation result of modular exponentiation of the ciphertext when an index is the second modular multiplicative inverse is calculated, and the second operation result is taken as the plaintext of the ciphertext.
[0225] In the above example, since the sender calculates the ciphertext c = m e mod N, c is the ciphertext, and the remaining parameters can be referred to the description above, and then after the private key is calculated, m = c d mod N is calculated to obtain the plaintext m.
[0226] Based on the technical solution, a number smaller than the large number in the public key and 1 are selected as inputs for solving the discrete logarithm problem, the number and 1 are converted into initial quantum states, then the initial quantum states are input into a quantum computing module for solving the discrete logarithm problem, a first target quantum state containing a discrete logarithm solution result is obtained by using the powerful computing power of quantum computing, then the solution result is extracted from the first target quantum state to calculate the private key, and finally the ciphertext is decrypted based on the obtained private key to obtain the plaintext. In the case where the private key is unknown in advance, the corresponding private key can be restored only by using the public key which has been disclosed, and the plaintext can be recovered, thereby solving the technical problem that the plaintext is difficult to recover when the private key is unknown, and filling the related technical blank.
[0227] Figure 11 Another flowchart of a ciphertext decryption method is shown according to an example embodiment, as shown in FIG. 11, the method comprises the following steps. Figure 11
[0228] S1101, obtaining a ciphertext and a large number in a public key of the ciphertext.
[0229] S1102, select a number smaller than the large number as a base of the discrete logarithm problem, select 1 as a modulus power operation result corresponding to the base, and convert the base and the modulus power operation result into an initial quantum state.
[0230] S1103, input the initial quantum state into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which a solving result of the discrete logarithm problem is stored.
[0231] S1104, extract the solving result from the first target quantum state.
[0232] S1105, when the solving result is an even number, calculate a power operation result of the base when the exponent is one half of the solving result as an intermediate result, and perform a modulus operation on the intermediate result with the large number as a modulus to obtain a first operation result.
[0233] S1106, when the first operation result is not equal to -1, calculate a greatest common divisor of the sum of the intermediate result and 1 and the large number as a first prime number, and calculate a greatest common divisor of the difference of the intermediate result and 1 and the large number as a second prime number.
[0234] S1107, calculate the Euler function of the large number according to the first prime number and the second prime number.
[0235] S1108, calculate a second modular inverse of the Euler function as a private key of the ciphertext by taking a first modular inverse in the public key of the ciphertext as the modulus.
[0236] S1109, decrypt the ciphertext based on the private key to obtain a plaintext of the ciphertext.
[0237] S1110, when the solving result is an odd number, reselect a number smaller than the large number as a base of the discrete logarithm problem, and return to perform the step of converting the base and the modulus power operation result into the initial quantum state.
[0238] S1111, when the first operation result is -1, reselect a number smaller than the large number as a base of the discrete logarithm problem, and return to perform the step of converting the base and the modulus power operation result into the initial quantum state.
[0239] Specifically, steps S1101 to S1104 can refer to steps S21 to S24 described above, steps S1105 and S1106 can refer to steps SI and SII described above, steps S1107 to S1108 can refer to steps S2422 to S2423 described above, and step S1109 can refer to step S25 described above.
[0240] If the result is determined to be an odd number in step S1110, the first prime number and the second prime number cannot be calculated subsequently, and the step S1102 is executed again to select a new base number, and the subsequent calculation is continued until the selected base number can calculate the first prime number and the second prime number.
[0241] If the first operation result is -1 in step S1111, the first prime number and the second prime number cannot be calculated subsequently, and the step S1102 is executed again to select a new base number, and the subsequent calculation is continued until the selected base number can calculate the first prime number and the second prime number.
[0242] Figure 12 Another flowchart of a ciphertext decryption method according to an example embodiment is shown in FIG. 12. As shown in FIG. 12, the method comprises: Figure 12
[0243] S121, obtaining a ciphertext and a large number in a public key of the ciphertext.
[0244] S122, selecting a number smaller than the large number as a base number of a discrete logarithm problem, and selecting 1 as a modulus power operation result corresponding to the base number.
[0245] S123, determining that the greatest common divisor of the base number and the large number is 1.
[0246] S124, converting the base number and the modulus power operation result into an initial quantum state.
[0247] S125, inputting the initial quantum state into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which a solution result of the discrete logarithm problem is stored.
[0248] S126, extracting the solution result from the first target quantum state, and calculating a private key of the ciphertext based on the solution result.
[0249] S127, decrypting the ciphertext based on the private key to obtain a plaintext of the ciphertext.
[0250] Specifically, steps S121 to S122 can refer to steps S21 to S22 described above.
[0251] After selecting the base, step S123 is executed to determine whether the greatest common divisor of the base and the large number is 1. If it is 1, the two are mutually prime, and the subsequent steps may be able to solve the private key, and then step S124 is executed. If it is not 1, the process returns to step S122 and is executed until the greatest common divisor of the selected base and the large number is 1, thereby avoiding the waste of computing resources by executing the subsequent steps when the greatest common divisor is not 1. The step of selecting 1 as the result of the modular exponentiation operation corresponding to the base in step S122 can be executed in step S122 or in step 124, and the present invention does not make any specific restrictions on this.
[0252] For steps S124 to S127 , reference may be made to the description of steps S22 to S25 above.
[0253] Optionally, the first modular exponentiation operation module 411 and the second modular exponentiation operation module 412 both include cascaded modular multiplication operation modules. Figure 13 , which for the input information x k (mod N) and x are transformed into corresponding quantum states, and modular multiplication is performed to obtain the corresponding x k+1 (mod N) quantum state. The modular multiplication operation module can include cascaded modular addition operation modules, see Figure 14 , which converts the input information kx(mod N) and x into corresponding quantum states, and performs modular addition operations to obtain the corresponding quantum state of (k+1)x(mod N). The modules for implementing modular exponentiation, modular multiplication, and modular addition operations can all adopt existing technologies, and this application does not elaborate on this.
[0254] Figure 15 is a block diagram of a ciphertext decryption device according to an exemplary embodiment, which is applied to ciphertext encrypted according to the RSA algorithm, such as Figure 15 As shown, the device 150 includes:
[0255] An acquisition module 151 is used to obtain a large number in a ciphertext and a public key of the ciphertext;
[0256] A conversion module 152 is selected to select a number smaller than the large number as a base of the discrete logarithm problem, select 1 as a modular exponentiation result corresponding to the base, and convert the base and the modular exponentiation result into an initial quantum state;
[0257] An input module 153 is configured to input the initial quantum state into a quantum computing module for solving a discrete logarithm problem, to obtain a first target quantum state storing a solution to the discrete logarithm problem;
[0258] The extraction and calculation module 154 is configured to extract the solution result from the first target quantum state, and calculate the private key of the ciphertext based on the solution result.
[0259] The decryption module 155 is configured to decrypt the ciphertext based on the private key to obtain the plaintext of the ciphertext.
[0260] Optionally, the extraction and calculation module 154 is further configured to:
[0261] decompose the large number based on the solution result to obtain a first prime number and a second prime number;
[0262] calculate the Euler function of the large number according to the first prime number and the second prime number;
[0263] calculate the second modular inverse of the first modular inverse in the public key of the ciphertext with respect to the modulus as the Euler function, and obtain the second modular inverse as the private key of the ciphertext.
[0264] Optionally, the extraction and calculation module 154 is further configured to:
[0265] when the solution result is an even number, calculate the power operation result of the base number with an index being half of the solution result as an intermediate result, and perform a modulo operation on the intermediate result with the large number as the modulus to obtain a first operation result;
[0266] when the first operation result is not equal to -1, calculate the greatest common divisor of the sum of the intermediate result plus 1 and the large number as a first prime number, and calculate the greatest common divisor of the difference of the intermediate result minus 1 and the large number as a second prime number.
[0267] Optionally, the device 150 further comprises:
[0268] The first reselection module is configured to, when the first operation result is -1, reselect a number smaller than the large number as the base number of the discrete logarithm problem, and return to perform the step of converting the base number and the modular exponent operation result into the initial quantum state.
[0269] Optionally, the decryption module 155 is further configured to:
[0270] calculate a second operation result of the modular exponent operation of the ciphertext with an index being the second modular inverse with the large number as the modulus, and take the second operation result as the plaintext of the ciphertext.
[0271] Optionally, the device 150 further comprises:
[0272] The second reselection module is configured to, when the solution result is an odd number, reselect a number smaller than the large number as a base of the discrete logarithm problem, and return to perform the step of converting the base and the modulus exponentiation result into the initial quantum state.
[0273] Optionally, the apparatus 150 further comprises:
[0274] The first determination module is configured to determine that the greatest common divisor of the base and the large number is 1 before the conversion module converts the base and the modulus exponentiation result into the initial quantum state.
[0275] Optionally, the initial quantum state is prepared by an information quantum register comprising a first number of quantum bits, the quantum computing module comprises a quantum Fourier transform module 420 and a modulus exponentiation multiplication module 410, and the input module 153 is further configured to:
[0276] acquire a parameter quantum register comprising a second number of quantum bits, and prepare the parameter quantum register into a superposition state formed by quantum substates with equal amplitudes;
[0277] input the initial quantum state and the superposition state into the modulus exponentiation multiplication module to obtain a second target quantum state, wherein when in the second target quantum state, the quantum state of the information quantum register and the quantum state of the parameter quantum register satisfy a preset entanglement relationship corresponding to the modulus exponentiation multiplication operation;
[0278] input the quantum state of the parameter quantum register in the second target quantum state into the quantum Fourier transform module to obtain a first target quantum state.
[0279] Optionally, the modulus exponentiation multiplication module 410 comprises a first modulus exponentiation operation module 411 and a second modulus exponentiation operation module 412 connected in cascade, the information quantum register comprises a first information quantum register and a second information quantum register, the parameter quantum register comprises a first parameter quantum register and a second parameter quantum register, and the input module 153 is further configured to:
[0280] input the quantum state of the first information quantum register in the initial quantum state and the quantum state of the first parameter quantum register in the superposition state into the first modulus exponentiation operation module to obtain an intermediate quantum state;
[0281] input the quantum state of the second information quantum register in the initial quantum state, the quantum state of the second parameter quantum register in the superposition state, and the intermediate quantum state into the second modulus exponentiation operation module to obtain a second target quantum state.
[0282] Optionally, the first modulus exponentiation operation module 411 and the second modulus exponentiation operation module 412 each comprise a modulus multiplication operation module connected in cascade.
[0283] Optionally, the quantum Fourier transform module 420 comprises a module for implementing a forward quantum Fourier transform and / or a module for implementing an inverse quantum Fourier transform.
[0284] Optionally, the measurement results are multiple, and the extraction and calculation module 154 is further configured to:
[0285] measure a parameter quantum register in the first target quantum state to obtain a measurement result;
[0286] construct a matrix L based on the measurement result, the matrix L satisfying the following form:
[0287]
[0288] wherein A:=diag(u,…,u), u is the maximum eigenstate number of the first parameter quantum register, and the elements in vector are the measurement results corresponding to the first parameter quantum register;
[0289] obtain a generating subspace of the matrix L based on the row vectors of the matrix L;
[0290] for any vector in the generating subspace, obtain the last element of the vector as a to-be-verified to-be-solved logarithm;
[0291] determine that the to-be-verified to-be-solved logarithm satisfies the logarithm relationship of the discrete logarithm problem;
[0292] determine that the to-be-verified to-be-solved logarithm is the solving result.
[0293] Optionally, the extraction and calculation module 154 is further configured to:
[0294] obtain a matrix L constructed by a preset number of measurement results from all the measurement results.
[0295] Optionally, the apparatus 150 further comprises:
[0296] a distance calculation module configured to calculate a target distance between each vector in the generating subspace and a reference vector before the extraction and calculation module obtains the last element of the vector as a to-be-verified to-be-solved logarithm, wherein the last element of the reference vector is 0 and the other elements are -2 n the product of the measurement results corresponding to the second quantum register, and n is the difference between the number of quantum bits of the first quantum register and the number of quantum bits of the second quantum register;
[0297] a second determination module configured to determine that each target distance is less than a preset distance.
[0298] Optionally, the apparatus 150 further comprises:
[0299] a third determining module configured to determine whether any of the target distances is greater than or equal to the preset distance;
[0300] a reconstructing module configured to obtain a preset number of new measurement results from all the measurement results to construct a matrix L';
[0301] a returning executing module configured to return the matrix L' as the matrix L and return to execute the step of obtaining the generating subspace of the matrix L based on the row vector of the matrix L.
[0302] Optionally, the preset distance is wherein s is the preset number.
[0303] As to the apparatus in the above embodiments, the specific manners in which the respective modules perform operations have been described in detail in the embodiments of the method, and thus will not be described in detail here.
[0304] Still another embodiment of the present application further provides a storage medium having a computer program stored therein, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.
[0305] Specifically, in the present embodiment, the above storage medium can include but is not limited to a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various storage media that can store computer programs.
[0306] Still another embodiment of the present application further provides an electronic apparatus comprising a memory and a processor, wherein the memory has a computer program stored therein, and the processor is configured to run the computer program to execute the steps in any of the above method embodiments.
[0307] Specifically, the above electronic apparatus can further comprise a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0308] Specifically, in the present embodiment, the processor can be configured to execute the following steps through the computer program:
[0309] A large number in the ciphertext and a public key of the ciphertext is obtained; a number smaller than the large number is selected as a base of a discrete logarithm problem, 1 is selected as a modulus power operation result corresponding to the base, and the base and the modulus power operation result are converted into an initial quantum state; the initial quantum state is input into a quantum computing module for solving the discrete logarithm problem to obtain a first target quantum state in which a solution of the discrete logarithm problem is stored; the solution is extracted from the first target quantum state, and a private key of the ciphertext is calculated based on the solution; and the ciphertext is decrypted based on the private key to obtain plaintext of the ciphertext.
[0310] The above detailed the structure, features and effects of the present application according to the embodiments shown in the drawings. The above is only the preferred embodiments of the present application, but the present application is not limited to the embodiments shown in the drawings. Any changes or modifications made in accordance with the concept of the present application, or equivalent embodiments with equivalent changes, are still within the scope of the present application.
Claims
1. A ciphertext decryption method, characterized in that: Applied to ciphertext encrypted according to the RSA algorithm, the method comprises: Obtaining a large number from a ciphertext and a public key of the ciphertext; Selecting a number smaller than the large number as the base of the discrete logarithm problem, selecting 1 as the modular exponentiation result corresponding to the base, and converting the base and the modular exponentiation result into an initial quantum state; Inputting the initial quantum state into a quantum computing module for executing a discrete logarithm problem solution to obtain a first target quantum state storing a solution to the discrete logarithm problem; Extracting the solution result from the first target quantum state, and calculating the private key of the ciphertext based on the solution result, comprising: When the solution result is an even number, decomposing the large number to obtain a first prime number and a second prime number; Calculate the Euler function of the large number according to the first prime number and the second prime number; Calculating a second modular multiplication inverse element of a first modular multiplication inverse element in a public key of the ciphertext with respect to a modulus of the Euler function, and obtaining the second modular multiplication inverse element as a private key of the ciphertext; The ciphertext is decrypted based on the private key to obtain a plaintext of the ciphertext.
2. The method according to claim 1, wherein When the solution result is an even number, decomposing the large number to obtain a first prime number and a second prime number includes: Calculating a power operation result of the base when the exponent is half of the solution result as an intermediate result, and performing a modulo operation on the intermediate result with the large number as the modulus to obtain a first operation result; When the first operation result is not equal to -1, the greatest common divisor of the sum of the intermediate result plus 1 and the large number is calculated as the first prime number, and the difference between the intermediate result and 1 and the greatest common divisor of the large number is calculated as the second prime number.
3. The method according to claim 2, wherein The method further comprises: When the first operation result is -1, a number smaller than the large number is reselected as the base of the discrete logarithm problem, and the process returns to execute the step of converting the base and the modular exponentiation operation result into an initial quantum state.
4. The method according to claim 1, wherein Decrypting the ciphertext based on the private key to obtain the plaintext of the ciphertext includes: Using the large number as a modulus, calculating a second operation result of the modular exponentiation operation of the ciphertext when the exponent is the second module multiplied by the inverse element, and using the second operation result as the plaintext of the ciphertext.
5. The method according to claim 1, wherein The method further comprises: When the solution result is an odd number, a number smaller than the large number is reselected as the base of the discrete logarithm problem, and the process returns to execute the step of converting the base and the modular exponentiation result into an initial quantum state.
6. The method according to claim 1, wherein Before converting the base and the modular exponentiation result into an initial quantum state, the method further includes: Determine that the greatest common divisor of the base number and the large number is 1.
7. The method according to claim 1, wherein The initial quantum state is prepared by an information quantum register including a first number of quantum bits, the quantum computing module includes a quantum Fourier transform module and a modular power multiplication module, and the initial quantum state is input into the quantum computing module for performing a discrete logarithm problem solution to obtain a first target quantum state storing a solution result of the discrete logarithm problem, including: Obtaining a parameter quantum register comprising a second number of quantum bits, and preparing the parameter quantum register to a superposition state formed by quantum states of equal amplitude; Inputting the initial quantum state and the superposition state into the modular exponentiation multiplication module to obtain a second target quantum state, wherein when in the second target quantum state, the quantum state of the information quantum register and the quantum state of the parameter quantum register satisfy an entanglement relationship corresponding to a preset modular exponentiation multiplication operation; The quantum state of the parameter quantum register in the second target quantum state is input into the quantum Fourier transform module to obtain a first target quantum state.
8. The method according to claim 7, wherein The modular exponentiation multiplication module includes a cascaded first modular exponentiation operation module and a second modular exponentiation operation module, the information quantum register includes a first information quantum register and a second information quantum register, and the parameter quantum register includes a first parameter quantum register and a second parameter quantum register. Inputting the initial quantum state and the superposition state into the modular exponentiation multiplication module to obtain a second target quantum state includes: Inputting the quantum state of the first information quantum register in the initial quantum state and the quantum state of the first parameter quantum register in the superposition state into the first modular exponentiation operation module to obtain an intermediate quantum state; The quantum state of the second information quantum register in the initial quantum state, the quantum state of the second parameter quantum register in the superposition state, and the intermediate quantum state are input into the second modular exponentiation operation module to obtain a second target quantum state.
9. The method according to claim 8, wherein The first modular exponentiation operation module and the second modular exponentiation operation module both include cascaded modular multiplication operation modules.
10. The method according to claim 7, wherein: The quantum Fourier transform module includes a module for implementing a forward quantum Fourier transform and / or a module for implementing an inverse quantum Fourier transform.
11. The method according to claim 8, wherein The extracting the solution result from the first target quantum state includes: measuring a parameter quantum register in the first target quantum state to obtain a measurement result; Construct a matrix based on the measurement results , the matrix Satisfy the following form: in, , is the maximum number of eigenstates of the first parameter quantum register, the vector The elements in are the measurement results corresponding to the first parameter quantum register; Based on the matrix The row vector of the matrix is obtained The generated subspace of ; For any vector in the generated subspace, obtaining the last element of the vector as the logarithm to be solved to be verified; Determining that the logarithm to be solved to be verified satisfies the logarithmic relationship of the discrete logarithm problem; The to-be-solved logarithm to be verified is determined to be the solution result.
12. The method according to claim 11, wherein There are multiple measurement results, and the matrix is constructed based on the measurement results. ,include: Obtain a preset number of measurement results from all of the measurement results to construct a matrix .
13. The method according to claim 12, wherein: Before obtaining the last element of any vector in the generated subspace as the logarithm to be verified, the method further includes: Calculate the target distance between each vector in the generated subspace and the reference vector, where the last element of the reference vector is 0 and the remaining elements are the product of the measurement results corresponding to the second parameter quantum register, where n is the difference in the number of qubits between the first parameter quantum register and the second parameter quantum register; It is determined that each target distance is less than a preset distance.
14. The method according to claim 13, wherein The method further comprises: Determining that any target distance is greater than or equal to the preset distance; Obtain a preset number of new measurement results from all the measurement results to construct a matrix ; The matrix As the matrix , and returns the execution based on the matrix The row vector of the matrix is obtained The steps of generating subspace.
15. The method according to claim 13, wherein The preset distance is ,in, is the preset number.
16. A ciphertext decryption device, characterized in that: Applicable to ciphertext encrypted according to the RSA algorithm, the device comprises: An acquisition module, configured to obtain a large number from a ciphertext and a public key of the ciphertext; Selecting a conversion module, configured to select a number smaller than the large number as a base of a discrete logarithm problem, select 1 as a modular exponentiation result corresponding to the base, and convert the base and the modular exponentiation result into an initial quantum state; An input module, configured to input the initial quantum state into a quantum computing module for executing a discrete logarithm problem solution, to obtain a first target quantum state storing a solution to the discrete logarithm problem; An extraction calculation module, configured to extract the solution result from the first target quantum state and calculate the private key of the ciphertext based on the solution result, comprising: When the solution result is an even number, decomposing the large number to obtain a first prime number and a second prime number; Calculate the Euler function of the large number according to the first prime number and the second prime number; Calculating a second modular multiplication inverse element of a first modular multiplication inverse element in a public key of the ciphertext with respect to a modulus of the Euler function, and obtaining the second modular multiplication inverse element as a private key of the ciphertext; The decryption module decrypts the ciphertext based on the private key to obtain a plaintext of the ciphertext.
17. A storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method according to any one of claims 1 to 15 when executed.
18. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 15.
Citation Information
Patent Citations
An encryption and decryption hardware system and method based on RSA cryptographic algorithm
CN109039640A
Paillier decryption system, chip and method
CN112988237A
Cited By
Quantum computing based ciphertext decryption method and related apparatus
CN119030695B
Quantum circuit construction method, ciphertext decryption method and related devices
CN119129758A
Ciphertext decryption method and related apparatus
CN119129758B
Ciphertext decryption method and related apparatus
CN119135360B