And-rx structure zero correlation linear distinguisher search method based on miss-from-the-middle and milp
By combining miss-from-the-middle with MILP technology, a linear mask propagation and back-propagation model is constructed, which solves the problems of search space limitation and uncertainty of contradiction location in the And-RX structure block cipher algorithm, and realizes longer rounds and a larger number of zero-correlation linear discriminator searches.
Patent Information
- Application Number
- CN202411451382.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-10-17
AI Technical Summary
The existing zero-correlation linear discriminator search method in the And-RX structure block cipher algorithm has the problems of being unable to traverse the entire discriminator search space and unable to accurately determine the location where the contradiction occurs.
Combining miss-from-the-middle and MILP techniques, a linear mask propagation model is constructed. By merging the encountered linear masks and building a back-propagation model, the MILP model can be solved into decision conditions for search to determine an effective zero-correlation linear discriminator.
A longer number of rounds and a larger number of effective zero-correlation linear discriminator searches were achieved, accurately determining the location of indirect contradictions and avoiding misjudgments caused by the model having no solution.
Smart Images

Figure CN119249457B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of information security, and particularly relates to a zero correlation linear distinguisher search method for an And-RX structure block cipher algorithm, which combines miss-from-the-middle and MILP technology. BACKGROUND
[0002] Zero correlation linear analysis is an important method for block cipher analysis, and the basic principle is to use a linear approximation expression with a correlation of 0 to perform key recovery on a cipher algorithm. The primary key of this attack is how to find an effective and high-round zero correlation linear distinguisher [1]. The most common analysis means is to regard the search for the optimal distinguisher as a combinatorial optimization problem, and then automatically solve the model.
[0003] In 2014, Sun et al. [2] first proposed a MILP automatic search method for bit-oriented optimal differential / linear characteristics, and the optimal probability / correlation of differential / linear distinguishers of multiple lightweight block cipher algorithms was greatly improved.
[0004] In 2017, Sasaki et al. [3] applied the bit-oriented MILP modeling method to impossible differential distinguisher search, and proposed to search for impossible differential distinguishers with the condition that the model has no solution. Similarly, this method is applied to the search for zero correlation linear distinguishers of block ciphers based on S-boxes and ARX structures, and a method for finding the position of the contradiction based on the deletion of variable constraints is given [4].
[0005] Recently, Hadipour et al. [5] proposed a combination of miss-in-the-middle and CP byte-oriented latest modeling technology, and first realized the search for zero correlation linear distinguishers with the condition that the model has a solution. For block cipher algorithms with SPN structure and And-RX structure, based on the bit model description method and combined with miss-in-the-middle and miss-from-the-middle technology, the team further proposed to search for zero correlation linear distinguishers with the condition that the model has a solution, and can consider the direct contradiction and indirect contradiction at the same time to search for zero correlation linear distinguishers [6, 7].
[0006] There are mainly two types of basic methods for searching for zero correlation linear distinguishers of block cipher algorithms with And-RX structure:
[0007] The first type is to search for zero correlation linear distinguishers by taking the condition that the model has no solution. Under the condition of fixed input and output masks, the model is constructed according to the propagation property of the linear mask, and then the model is solved. If the model has no solution, it is considered that the fixed mask is an effective zero correlation linear distinguisher.
[0008] The second type is to search zero correlation linear distinguisher based on miss-in-the-middle technique. Under the condition of fixed input and output masks, the model of input and output masks is constructed to propagate in the encryption and decryption directions with a probability of 1. When the two models propagate to a certain round in the middle, the direct contradiction occurs as the determination condition. If the model has a solution, the distinguisher is an effective zero correlation linear distinguisher.
[0009] The search methods of the above two types of zero correlation linear distinguishers have some shortcomings. The first type of method does not need to consider the reason of contradiction, but has two disadvantages: one is that it cannot traverse all possible distinguishers; the second is that it is not accurate to judge whether a distinguisher is a zero correlation linear distinguisher only by the model without solution, because the specific position of the contradiction cannot be obtained.
[0010] The second type of method can directly obtain the position of the contradiction, but due to the particularity of the And-RX structure algorithm, the contradiction occurs in more than one case.
[0011] [1] Bogdanov A, Rijmen V. Linear hulls with correlation zero and linear cryptanalysis of block ciphers [J]. In: Designs, Codes and Cryptography, 2014, 70(3): 369-383.
[0012] [2] Sun S, Hu L, Wang M, et al. Towards finding the best characteristics of some bit-oriented block ciphers and automatic enumeration of (related-key) differential and linear characteristics with predefined properties [J]. Cryptology ePrint Archive, 2014.
[0013] [3] Sasaki Y, Todo Y. New impossible differential search tool from design and cryptanalysis aspects: Revealing structural properties of several ciphers [C] / / Advances in Cryptology - EUROCRYPT 2017: 36th Annual International Conference on the Theory and Applications of Cryptographic Techniques. Springer International Publishing, 2017: 185-215.
[0014] [4] Cui T, Chen S, Fu K, et al. New automatic tool for finding impossible differentials and zero-correlation linear approximations [J]. Science China Information Sciences, 2021, 64: 1-3.
[0015] [5] Hadipour H, Sadeghi S, Eichlseder M. Finding the Impossible: Automated search for full impossible-differential, zero-correlation, and integral attacks [C] / / Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham: Springer Nature Switzerland, 2023: 128-157.
[0016] [6] Hadipour H, Gerhalter S, Sadeghi S, et al. Improved search for integral, impossible differential and zero-correlation Attacks [J].
[0017] [7]Chakraborty D, Hadipour H, Nguyen P H, et al. Finding complete impossible differential attacks on AndRX ciphers and efficient distinguishers for ARX designs[J]. IACR Transactions on Symmetric Cryptology, 2024, 2024(3). SUMMARY
[0018] The present application is directed to the problems of the two methods in the background art, and proposes a miss-from-the-middle and MILP technology combined zero correlation linear distinguisher search method for searching zero correlation linear distinguishers of block cipher algorithms with And-RX structure. The method first combines miss-from-the-middle and MILP technology to construct a perfect zero correlation linear distinguisher search method, which can solve the limitations of not being able to traverse all distinguisher search spaces and not being able to determine the specific position of the contradiction, and also considers the causes of indirect contradictions.
[0019] The technical solution for achieving the object of the present application is:
[0020] An And-RX structure zero correlation linear distinguisher search method based on miss-from-the-middle and MILP, comprising the following steps:
[0021] (1) Establish a linear mask propagation model according to the structure of the block cipher algorithm:
[0022] Based on the structure of the algorithm round function and the linear mask propagation property, the non-linear components And operation, linear component branch operation, etc. are constrained and described in bits, and the input mask output mask The r-round MILP model is propagated in the encryption direction and the decryption direction with a probability of 1, and the contradiction point determination constraint is given;
[0023] (2) Merge the mth round meeting linear mask:
[0024] When the input mask output mask in step (1) is propagated to the middle mth round meeting, 0≤m≤r, without contradiction, the two linear masks Merging into a new linear mask according to the given mask merging rule
[0025] (3) Merging linear masks based on the merging rule Constructing a back propagation model:
[0026] Merging the linear masks in step (2) Respectively propagating in the encryption and decryption directions with a probability of 1, at a certain bit position of a mask in a round, compared with the propagation path of the mask , it is determined whether a contradiction of mask values of 0 and 1 with a probability of 1 will be generated;
[0027] (4) Solving the constructed model:
[0028] Connecting the back propagation model and the mask propagation model based on the contradiction point to form a unified model, and then solving, selecting and determining the value of the initial parameter m (0≤m≤r), setting the initial constraint to ensure that the searched discriminator is effective, and setting the objective function.
[0029] The present application proposes a discriminator search method combining miss-from-the-middle and MILP technology, which is used for searching the zero correlation linear discriminator of the And-RX structure algorithm. Two problems that may occur when searching the zero correlation linear discriminator with the model without solution as the determination condition are avoided, the causes of indirect contradictions are also considered, and the MILP model can be solved as the determination condition to extend the discriminator, which lays a foundation for attacking the search and key recovery of the zero correlation linear discriminator as a whole problem.
[0030] The method of the present application applies the MILP modeling to the miss-from-the-middle technology, and constructs a zero correlation linear discriminator search method with the model solvable as the determination condition for the And-RX structure group cipher algorithm. The limitation that the model without solution as the determination condition cannot traverse all search spaces is solved, and the zero correlation linear discriminator caused by indirect contradictions is also considered, so that more effective zero correlation linear discriminators with longer rounds can be searched under the new model. BRIEF DESCRIPTION OF DRAWINGS
[0031] Figure 1 The model construction principle diagram in the And-RX structure zero correlation linear discriminator search method of the present application. DETAILED DESCRIPTION
[0032] The content of the present application will be further described in detail below in combination with embodiments and drawings, but is not limited to the present application.
[0033] EMBODIMENT
[0034] An And-RX structure zero correlation linear distinguisher search method based on miss-from-the-middle and MILP, with reference to Figure 1 , comprising the following steps:
[0035] (1) Establish a linear mask propagation model according to the structure of the block cipher algorithm:
[0036] Based on the algorithm round function structure and the linear mask propagation property, the non-linear components And operation, linear component branch operation, etc. are constrained and described in bits, and the input mask output mask The r-round MILP model is propagated in the encryption direction and the decryption direction respectively with a probability of 1, and the determination constraints of the contradiction points are given;
[0037] (2) Merge the mth round meeting linear mask:
[0038] When the input mask output mask in the first step (1) propagates to the middle mth round meeting, 0≤m≤r, under the premise that no contradiction occurs, the two linear masks are merged into a new linear mask
[0039] (3) Based on the merged linear mask , construct a reverse propagation model:
[0040] The linear mask after merging in the second step (2) is propagated in the encryption direction and the decryption direction respectively with a probability of 1, and compared with the propagation path of the mask , it is determined whether the mask values of 0 and 1 will be generated with a probability of 1;
[0041] (4) Solve the constructed model:
[0042] Connect the reverse propagation model and the mask propagation model based on the contradiction points to form a unified model, and then solve it, select and determine the value of the initial parameter m (0≤m≤r), set the initial constraints to ensure that the searched distinguisher is effective, and set the objective function.
[0043] Furthermore, in step (1), based on the algorithm round function structure and the linear mask propagation properties, a MILP model of linear mask propagation with probability 1 along the encryption and decryption directions and a constraint characterization of contradiction point determination are constructed respectively. It is assumed that the cryptographic algorithm block length is 2n bits, and a two-dimensional variable (x1, x2) is used to represent the value state of a 1-bit mask, where (0,0) represents the mask value of 0, (0,1) represents the mask value of 1, (1,1) represents the mask value is unknown, and "*" represents an unknown state. The constraint characterization of the linear mask through each algorithm component and the constraint characterization of contradiction point determination are as follows:
[0044] (1.1) Branch operation linear mask propagation constraints:
[0045] The linear mask is propagated with a probability of 1 through the branch operation. When the values of the two output masks are determined, the value of the input mask is the XOR value of the two output masks; when the value of any output mask is unknown, the value of the input mask is also unknown.
[0046] Since each bit mask has three value states and the value of a 1-bit mask is represented by a two-dimensional variable, there are a total of 9 possible values, including (0,0,0,0,0,0), (0,0,0,1,0,1), (0,0,1,1,1,1), (0,1,0,0,0,1), (0,1,0,1,0,0), (0,1,1,1,1,1), (1,1,0,0,1,1), (1,1,0,1,1,1), (1,1,0,1,1,1), and (1,1,1,1,1,1,1);
[0047] Therefore, let Indicates the input mask of the i-th round of branch operation The value state of the j-th bit, and Respectively represent the output mask of the i-th round of branch operation The value state of the j-th bit, 0≤i≤r-1, 0≤j≤n-1;
[0048] Then the linear mask propagation constraint of the branch operation can be expressed as Equation 1:
[0049]
[0050] (1.2) “AND” operation linear mask propagation constraint:
[0051] Think of the AND operation as a 2×1 S-box: when the output mask value is 0, the values of the two input masks must also be 0; when the output mask value is 1, the values of the two input masks can be any value;
[0052] Similar to step (1.1), there are three possible cases for the input and output masks of the AND operation, including (0, 0, 0, 0, 0, 0), (1, 1, 1, 1, 0, 1) and (1, 1, 1, 1, 1, 1);
[0053] Therefore, let and denote the value state of the i-th round input mask of the j-th bit of the AND operation, respectively, denote the value state of the i-th round output mask of the j-th bit of the AND operation, 0≤i≤r-1, 0≤j≤n-1;
[0054] The linear mask propagation constraint of the AND operation can be represented by equation 2:
[0055]
[0056] (1.3) The determination constraint of the contradiction point:
[0057] When the input and output masks propagate along the encryption and decryption directions, respectively, the masks meet at a certain round in the middle. Only when the contradiction values of 0 and 1 are generated with a probability of 1 is the contradiction considered to occur. An additional bit of the flag variable d is used to represent whether the contradiction occurs at each bit position. d = 0 represents that the contradiction does not occur, and d = 1 represents that the contradiction occurs. There are a total of 8 possible cases, including (0, 0, 0, 0, 0), (0, 0, 0, 1, 1), (0, 1, 0, 0, 1), (0, 0, 1, 1, 0), (1, 1, 0, 0, 0), (0, 1, 1, 1, 0), (1, 1, 0, 1, 0) and (1, 1, 1, 1, 0);
[0058] Therefore, let and denote the value state of the i-th round input mask and of the j-th bit of the AND operation, respectively, d i,j is the flag variable representing whether the contradiction occurs at the position;
[0059] In order to depict the generation of the indirect contradiction, the determination function of the contradiction point is defined as The specific constraint is represented by equation 3:
[0060]
[0061] Further, step (2) described that the two linear masks that meet are merged into a new linear mask according to the given mask merging rule:
[0062] When input, output mask When and only when the masks meeting at the same bit position, without contradiction, are merged according to the rules in Table 1 along the encryption and decryption directions with probability 1, respectively.
[0063] Therefore, the masks meeting at the intermediate round m Without contradiction, that is, the value of each bit flag of the contradictory variable is 0, the constraint condition of formula 4 needs to be met, and then the masks are merged by formula 7 to obtain the new mask
[0064] Table 1 Mask merging rule
[0065]
[0066] (2.1) The premise condition constraint description of mask merging:
[0067] and respectively represent the value state of the jth bit of the meeting mask and The value state of the jth bit of the meeting mask The value state of the jth bit of the meeting mask The value state of the jth bit of the meeting mask
[0068] When the meeting mask is merged, it is necessary to ensure that and The contradiction between them cannot occur, that is, the contradiction flag variable d m,j (0≤j≤n-1) all take value 0, and and The value state cannot all be unknown, which ensures that the merged mask The contradiction can occur when the merged mask propagates along the encryption and decryption directions with probability 1, and the constraint conditions are formula 4, formula 5 and formula 6:
[0069]
[0070]
[0071] (2.2) Constraint description of mask merging:
[0072] As can be seen from Table 1, there are 7 possible cases of mask merging, including (0, 0, 0, 0, 0, 0), (0, 1, 0, 1, 0, 1), (0, 1, 1, 1, 0, 1), (0, 0, 1, 1, 0, 0), (1, 1, 0, 0, 0, 0), (1, 1, 0, 1, 0, 1) and (1, 1, 1, 1, 1, 1).
[0073] The merging constraint of the mask can be represented by formula 7:
[0074]
[0075] Further, step (3) is based on the mask obtained after merging in step (2) Respectively, along the encryption, decryption direction to build a propagation model, the establishment of the model in step (1), set up the indirect contradiction of the determination of the constraints:
[0076] Based on the contradiction point d connection mask Γ U And the propagation path of (Γ W ,Γ V ) is shown in equation 8:
[0077]
[0078] And to ensure the merger of the mask In the reverse propagation path, there is at least one bit position appears contradiction, its constraints as shown in equation 9:
[0079]
[0080] Further, step (4) is described to solve the constructed propagation model, first set the initial parameters and initial conditions constraints, to ensure the solvability and effectiveness of the model, and to search for as many zero correlation linear distinguishers as the objective function, the solving process is as follows:
[0081] (4.1) initial condition constraints:
[0082] The initial constraint is to limit the input, output mask The value can not be all zero, its condition constraints as shown in equation 10:
[0083]
[0084]
[0085] (4.2) objective function:
[0086] In order to meet all the conditions of the constraints, search to as many zero correlation linear distinguishers as possible, that is, to contain as many unknown "*" bits in the input, output mask, therefore, each bit (x1,x2) in the input, output mask needs to use an additional variable t i (0≤i≤2n-1) to represent the value of the unknown state, and the variable t i The relationship between the mask can be represented by equation 11, and the objective function is set to equation 12:
[0087]
[0088] Finally, the model is solved by Gurobi solver, and the maximum number of zero-correlation linear distinguishers and the corresponding indirect contradiction positions are obtained.
[0089] The method has high accuracy, can search for zero-correlation linear distinguishers and give accurate indirect contradiction positions, eliminates the misjudgment caused by no solution of the model, and avoids the cumbersome process of manually deriving the indirect contradiction positions based on zero-correlation linear distinguishers.
Claims
1. A zero-correlation linear discriminator search method based on miss-from-the-middle and MILP and And-RX structure, characterized by: The following steps are involved: (1) Establish a linear mask propagation model based on the block cipher algorithm structure: Based on the algorithm round function structure and linear mask propagation properties, the nonlinear component And operation and linear component branch operation are constrained and characterized in bits to construct the input mask. , output mask , with probability 1, propagating along the encryption and decryption directions respectively Round MILP model, and give the judgment constraints of the contradiction points; (2) For Merge by using linear masks: When the input mask in step (1) , output mask Spread to the middle When the wheels meet, , under the premise that there is no contradiction, the two linear masks ( ) is merged into a new linear mask according to the given mask merging rule ; (3) Based on merged linear mask Build the backpropagation model: The linear mask after merging in step (2) Back propagation is performed along the encryption and decryption directions with a probability of 1. At a certain bit position of the mask in a certain round, the bit position of the mask , Compare with the propagation path to determine whether there will be a contradiction with the mask values 0 and 1 respectively with a probability of 1; (4) Solve the constructed model: Connect the back propagation model and the mask propagation model based on the contradiction points to form a unified model, then solve it, select and determine the initial parameters The value of , set the initial constraints to ensure that the searched discriminator is valid, and set the objective function.
2. The And-RX structure zero-correlation linear discriminator search method according to claim 1, characterized in that: In step (1), based on the algorithm round function structure and the linear mask propagation property, the MILP model of linear mask propagation with probability 1 along the encryption and decryption directions and the constraint characterization of the conflict point judgment are constructed respectively. It is assumed that the block length of the cryptographic algorithm is 2n bits and the two-dimensional variable is used. Indicates the value state of a 1-bit mask, where (0, 0) indicates that the mask value is 0, (0, 1) indicates that the mask value is 1, (1, 1) indicates that the mask value is unknown, and "*" indicates an unknown state. The linear mask is characterized by the constraints of each algorithm component and the constraint characterization of the contradiction point judgment as follows: (1.1) Linear mask propagation constraints for branch operations: The linear mask is propagated with a probability of 1 through the branch operation. When the values of the two output masks are determined, the value of the input mask is the XOR value of the two output masks; when the value of any output mask is unknown, the value of the input mask is also unknown. Since each bit mask has three value states and the value of a 1-bit mask is represented by a two-dimensional variable, there are a total of 9 possible values, including (0, 0, 0, 0, 0, 0), (0, 0, 0, 1, 0, 1), (0, 0, 1,1, 1, 1), (0, 1, 0, 0, 0, 1), (0, 1, 0, 1, 0, 0), (0, 1, 1, 1, 1, 1), (1, 1, 0,0, 1, 1), (1, 1, 0, 1, 1, 1), and (1, 1, 1, 1, 1, 1); Therefore, let ( , Indicates branch operation Wheel Input Mask No. The value status of the bit, , and , Respectively represent the branch operation Round output mask ( No. Bit value status ; Then the linear mask propagation constraint of the branch operation can be expressed as Equation 1: (Formula 1); (1.2) "AND" operation linear mask propagation constraint: Think of the AND operation as a 2×1 S-box: when the output mask value is 0, the values of the two input masks must also be 0; when the output mask value is 1, the values of the two input masks can be any value; Similar to step (1.1), there are three possible input and output masks for the AND operation, including (0, 0, 0, 0, 0, 0), (1, 1, 1, 1, 0, 1), and (1, 1, 1, 1, 1, 1); Therefore, let , , Respectively represent the "and" operation Wheel Input Mask , No. The value status of the bit, , Indicates the AND operation Round output mask No. The value status of the bit, ; Then the linear mask propagation constraint of the "AND" operation can be expressed by Equation 2: (Formula 2); (1.3) Decision constraints of contradiction points: When the input and output masks propagate along the encryption and decryption directions respectively, if the masks meet in a certain round, a contradiction is considered to occur only when the mask value is 0 and 1 with a probability of 1. An additional bit flag variable is required for each bit position. Indicates whether a conflict occurs. It means that no conflict has occurred. Represents the occurrence of a contradiction. There are 8 possible situations, including (0, 0, 0, 0, 0), (0, 0, 0, 1, 1), (0, 1, 0, 0, 1), (0, 0, 1,1, 0), (1, 1, 0, 0, 0), (0, 1, 1, 1, 0), (1, 1, 0, 1, 0), and (1, 1, 1, 1, 0); Therefore, let ( , , Represents two masks respectively and In the Round The value state of the bit position encounter, , As a flag variable, it indicates whether a contradiction occurs at this position; In order to characterize the generation of indirect contradictions, the judgment function of the contradiction point is defined as contradiction( , , ), its specific constraints are expressed as formula 3: (Formula 3).
3. The And-RX structure zero-correlation linear discriminator search method according to claim 1, characterized in that: In step (2), the two linear masks that meet are merged into a new linear mask according to the given mask merging rule. , the merging rules are: When input and output masks With probability 1, it propagates to the middle When the two rounds meet, the masks that meet at the same bit position are merged according to the rules of Table 1 if and only if there is no contradiction. Therefore, the masks that meet in the middle ( ) cannot be contradictory, that is, the value of each bit flag variable that is contradictory is 0, and the constraint condition of formula 4 needs to be satisfied. Then, the mask is merged by formula 7 to obtain a new mask. ; Table 1 Mask merging rules (2.1) Characterization of the precondition constraints of mask merging: and Represents encounter mask and No. The value status of the bit, Indicates the Merge mask at round No. The value status of bits, ; When merging by encountering mask, make sure and There can be no contradiction between the Contradictory sign variable of wheel All values are 0. ,and and The value status cannot all be unknown, ensuring the merge mask When propagating along the encryption and decryption directions with probability 1, a direct contradiction can occur. The constraints are as follows: Formula 4 ; Formula 5 ; Formula 6 ; (2.2) Constraint characterization of mask merging: As shown in Table 1, there are 7 possible cases of mask merging, including (0, 0, 0, 0, 0, 0), (0, 1, 0,1, 0, 1), (0, 1, 1, 1, 0, 1), (0, 0, 1, 1, 0, 0), (1, 1, 0, 0, 0, 0), (1, 1, 0,1, 0, 1), and (1, 1, 1, 1, 1, 1); Then the mask merging constraint can be expressed by Equation 7: (Formula 7).
4. The And-RX structure zero-correlation linear discriminator search method according to claim 3, characterized in that: Step (3) is based on the mask merging in step (2) , and then construct the propagation model along the encryption and decryption directions respectively. The establishment of the model is the same as step (1), and the judgment constraints of indirect contradictions are set: Based on the contradiction Connection Mask and The propagation path of is constrained as shown in Equation 8: (Formula 8); Where, Represents the merge mask of the i-th round 、 The jth bit of As a flag variable, it indicates whether a contradiction occurs at this position; And make sure to merge the mask There is at least one bit position in the back propagation path where a contradiction occurs, and its constraint is shown in Equation 9: (Formula 9).
5. The And-RX structure zero-correlation linear discriminator search method according to claim 1, characterized in that: In step (4), the constructed propagation model is solved by first setting the initial parameters and initial condition constraints to ensure the solvability and effectiveness of the model, and the objective function is to search for as many zero-correlation linear discriminators as possible. The solution process is as follows: (4.1) Initial condition constraints: The initial constraints are to restrict input and output masks The value of cannot be all zero, and its conditional constraints are shown in formula 10: Formula (10); (4.2) Objective function: In order to search for as many zero-correlation linear discriminators as possible while satisfying all the constraints, that is, to include as many unknown "*" bits as possible in the input and output masks, each bit in the input and output masks is An additional variable is required To indicate whether the value is unknown, The variable The relationship between and mask can be expressed by Equation 11, and the objective function is set to Equation 12: (Formula 11); (Formula 12); Finally, the model is solved using the Gurobi solver to obtain as many zero-correlation linear discriminators as possible and the corresponding specific locations of indirect contradictions.
Citation Information
Patent Citations
Zero-correlation linear cipher analysis method and system, medium and electronic equipment
CN112398638A
Optimal impossible differential analysis method with MILP model solvability as judgment condition
CN117857020A