Optimal impossible Boomerang attack search method based on MILP

Through the impossible Boomerang attack search method based on the MILP model, combined with the differentiator search and key recovery, the local optimal problem caused by the separation of differentiator search and key recovery in the prior art is solved, and a more efficient impossible Boomerang attack is achieved.

CN119945658APending Publication Date: 2025-05-06GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510104109.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

Existing impossible Boomerang differentiator search and key recovery attacks usually need to be performed separately, resulting in the searched optimal differentiator not necessarily the most suitable during the key recovery process, and there are too few rounds in the contradiction between the differentiator.

Method used

Using the optimal impossible Boomerang attack search method based on the MILP model, by constructing a complete impossible Boomerang attack model, including the expansion wheel of differentiator search and key recovery, the Gurobi solver is used to solve it to obtain the optimal attack under the specified number of attack rounds.

Benefits of technology

A unified model combining differentiator search and key recovery is implemented, reducing time complexity and ensuring the overall optimal result during attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945658A_ABST
    Figure CN119945658A_ABST
Patent Text Reader

Abstract

The invention discloses an optimal impossible Boomerang attack search method based on MILP, and the method aims at a block code algorithm of a 4-bit s box, builds a bit-level differential propagation constraint description for linear and nonlinear components of the block code algorithm, employs a contradiction point in a BCT table as a judgment method, can search an impossible Boomerang discriminator of a plurality of different contradiction points under the same round number, and achieves the optimal search of the optimal impossible Boomerang attack. A key recovery expansion round is further added into the model, plaintext difference and ciphertext difference are taken as objective functions, a complete MILP model impossible to Boomerang attack is constructed, and the minimum number of plaintext and ciphertext active bits can be obtained by solving the model, so that the overall time complexity is reduced, and the probability of the key recovery expansion round is reduced. The method is suitable for searching high-round impossible Boomerang attacks under the condition of related keys or related adjustability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The invention relates to the field of information security, and in particular to an optimal impossible Boomerang attack search method based on a MILP model. Background Art

[0002] The Impossible Boomerang Attack is a variant of the Boomerang Attack, first proposed by Lu et al. [1,2] The proposed method has a low time complexity for attacking the AES cryptographic algorithm. This method is inspired by the Boomerang attack and the impossible differential attack. The Boomerang attack is to construct two short differentials into a long differential to attack, while the impossible differential attack is to use a differential feature with a probability of 0 to eliminate the wrong key that meets this feature. The impossible Boomerang attack combines the two methods. The cryptographic algorithm is represented by E. Assume that the algorithm E consists of two sub-parts When searching for impossible Boomerang distinguishers, it is required that the two differential features satisfy the encryption direction E0 with a probability of 1. That is, the probability of the differential propagation E0: α→β and α′→β′ in the upper part is 1, and the probability of the differential propagation E0: α→β and α′→β′ in the lower part is 1. The probability of δ→γ and δ′→γ′ being true is also 1, and the result of XOR of the four differences that meet in the middle is not 0, that is, The above four differential features constitute an impossible Boomerang distinguisher, and an impossible Boomerang attack, such as Figure 2 shown.

[0003] The idea of ​​finding the impossible Boomerang discriminator above is to construct the contradiction by using the upper and lower differences. The contradiction is not constructed by using the BCT theoretical tools, but by finding the four differential XOR results.

[0004] Then in 2017, Cid et al. [3] The Boomerang Connectivity Table (BCT) is proposed, which makes the theoretical calculation of the intermediate round probability r of the Boomerang distinguisher more accurate.

[0005] 2023 Hadipour et al. [4] Constraint Programming (CP)-based modeling was used to unify the distinguisher search and key expansion recovery into one model, and 19 rounds of impossible differential analysis were successfully launched on SKINNY.

[0006] 2024 Bonnetain et al. [5]The search for impossible Boomerang discriminators is re-examined, and based on the CP model and with the intermediate contradiction as constraint, a new impossible Boomerang discriminator search method is constructed and applied to Skinnyee.

[0007] The impossible Boomerang attack is generally divided into two main stages: the distinguisher search stage and the key recovery attack stage. First, in the impossible Boomerang distinguisher search stage, the attacker needs to find an impossible Boomerang distinguisher of r2 rounds. The general method is to search for an impossible Boomerang distinguisher of r2 rounds through the CP model or the Satisfiability Problem (SAT) model. Based on the r2 round distinguisher, the attacker expands r1 and r3 rounds forward and backward respectively, and recovers the key on r1 and r3 rounds. The above two stages together constitute the impossible Boomerang attack of r=r1+r2+r3 rounds.

[0008] However, the impossible Boomerang discriminator search and key recovery attack are usually performed separately, which results in the searched optimal impossible Boomerang discriminator not necessarily being the most suitable in the key recovery process, that is, the local optimum is not necessarily the overall optimum. The second problem is that the discriminator involves too few rounds of inconsistencies.

[0009] [1]Lu J.Cryptanalysis of block ciphers[D].University of London,2008;

[0010] [2]Lu J.The(related-key)impossible boomerang attack and its application to the AES block cipher[J].Designs, Codes and Cryptography,2011,60:123-143;

[0011] [3]Cid C, Huang T, Peyrin T, et al. Boomerang connectivity table: a new cryptanalysis tool[C] / / Advances in Cryptology–EUROCRYPT 2018: 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29-May 3, 2018 Proceedings, Part II 37. Springer International Publishing, 2018: 683-714;

[0012] [4]Hadipour H, Sadeghi S, Eichlseder M. Finding the Impossible: Automated Search for Full Impossible-Differential, Zero-Correlation, and Integral Attacks[C] / / Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham: Springer Nature Switzerland, 2023: 128-157;

[0013] [5]Bonnetain X, Cordero M, Lallemand V, et al. On Impossible Boomerang Attacks[J]. IACR Transactions on Symmetric Cryptology, 2024, 2024(2): 222-253。 Summary of the Invention

[0014] In view of the problems existing in the background technology, the present invention proposes a search method for the optimal impossible Boomerang attack based on MILP. The method constructs a bit-level differential propagation constraint characterization for its linear and nonlinear components for a block cipher algorithm of a 4-bit S-box, and uses the contradiction points in the BCT table as the judgment method. It can search for impossible Boomerang discriminators with multiple different contradiction points under the same number of rounds, and further adds the key recovery expansion round to the model. The plaintext difference and ciphertext difference are used as the objective function to construct a MILP model of a complete impossible Boomerang attack. By solving the model, the minimum number of plaintext and ciphertext active bits can be obtained, thereby reducing the overall time complexity.

[0015] The technical solution for achieving the purpose of the present invention is:

[0016] The optimal impossible Boomerang attack search method based on MILP includes the following steps:

[0017] (1) Modeling the impossible Boomerang discriminator search based on the cryptographic algorithm:

[0018] According to the properties of the round function and the differential propagation law, linear components such as the XOR operation in the round function, nonlinear components such as the S-box, and BCT contradictions are modeled to form a complete impossible Boomerang discriminator search model;

[0019] (2) Modeling the extended part of the discriminator:

[0020] According to the expansion rule, the distinguisher is expanded forward and backward, and the active bits of the plaintext difference and the ciphertext difference are obtained through the active S-box position of the expansion round;

[0021] (3) Finally, the plaintext difference and the ciphertext difference are used as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the specified number of attack rounds.

[0022] The optimal impossible Boomerang attack search method based on MILP in the present invention characterizes the entire BCT table, taking into account the situations of all contradictory and non-contradictory points, without the need to manually set the contradictory points. When a contradiction is found somewhere, it can be further determined whether the upper difference extended backward for one round is contradictory to the lower difference. The model takes solvability as the judgment condition, and characterizes the search model of the new impossible Boomerang distinguisher through constrained inequalities.

[0023] The optimal impossible Boomerang attack search method based on MILP is added with the characterization of the discriminator expansion round on the basis of the discriminator search model. Thus, the discriminator search model is effectively combined with key recovery, and the optimal impossible Boomerang attack under the specified attack round number is obtained by solving the model. The search method is suitable for searching for impossible Boomerang attacks with a high number of rounds under related keys or related adjustable conditions. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 The figure is a flow chart of the optimal impossible Boomerang attack search method of the present invention.

[0025] Figure 2 Schematic diagram of the existing impossible Boomerang attack method. DETAILED DESCRIPTION

[0026] The present invention will be further described in detail below in conjunction with the embodiments and drawings, but the present invention is not limited thereto.

[0027] Example

[0028] The optimal impossible Boomerang attack search method based on MILP, refer to Figure 1 , including the following steps:

[0029] (1) Modeling the impossible Boomerang discriminator search based on the cryptographic algorithm:

[0030] According to the properties of the round function and the differential propagation law, linear components such as the XOR operation in the round function, nonlinear components such as the S-box, and BCT contradictions are modeled to form a complete impossible Boomerang discriminator search model;

[0031] (2) Modeling the extended part of the discriminator:

[0032] According to the expansion rule, the distinguisher is expanded forward and backward, and the active bits of the plaintext difference and the ciphertext difference are obtained through the active S-box position of the expansion round;

[0033] (4) Finally, the plaintext difference and the ciphertext difference bits are used as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the specified number of attack rounds.

[0034] Reference Figure 1 In step (1), the search for an impossible Boomerang distinguisher is modeled according to the cryptographic algorithm. Assuming that each round of block cipher iteration passes through m S-boxes, each S-box is 4 bits in size, then the total length is n = 4m Bit, it is impossible that the contradiction of the Boomerang distinguisher is in the pd round, and the contradiction is extended to pd+1 round;

[0035] If the distinguisher has a total of r2 rounds, A i,j and B i,j represents the differential state and differential value of the jth S-box in the i-th round in the distinguisher, where 0≤i≤r2-1,0≤j≤m-1;

[0036] Since the differential state has only four cases: the difference is 0, the difference is not 0 and fixed, any non-zero value, and any value, only 2 bits A are used. i,j [0], A i,j [1] can represent 4 differential states;

[0037] Since the difference value of the 4-bit S-box is in {0,1,2...15}, 4 bits can be used to represent the difference, and another bit is required to indicate whether the difference value is an arbitrary value, so a 5-bit B i,j [0...5] indicates the specific difference value;

[0038] When A i,j When [0] = 0, it means that the differential state of the state unit is inactive, indicating that the differential value is fixed. At this time, the differential value is {0, 1, 2...15};

[0039] When A i,j When [0] = 1, it indicates that the differential state of the state unit is active. At this time, there are two states: any non-zero value and any value. The differential values ​​are represented by 10001 and 10010 respectively.

[0040] Taking a 4-bit S-box as an example, the differential state A of the S-box i,j and the difference value B i,j The corresponding relationship and specific value are shown in formulas 1 and 2, where 0≤i≤r2-1,0≤j≤m-1:

[0041]

[0042] The specific steps for modeling the impossible Boomerang discriminator search are as follows:

[0043] (1.1) Construct the constraint characterization between the differential state and the corresponding specific differential value:

[0044] Each state unit of the round function of the cryptographic algorithm uses the correspondence between the differential state and the differential value to characterize differential propagation, such as S-box, row shift, column confusion, linear operation or nonlinear operation in key arrangement.

[0045] According to formula 1 and formula 2, the differential state A of each state unit of the distinguisher is obtainedi,j and the difference value B i,j The MILP constraint inequality is shown in Equation 3, where 0≤i≤r2-1,0≤j≤m-1:

[0046]

[0047] (1.2) Construct the differential propagation characterization of the S-box:

[0048] When differential propagation passes through the S-box, the characteristic of differential propagation is that when the input differential is 0, the output differential must be 0, and when the input differential is non-0, the output differential is non-0;

[0049] When the input differential is non-zero and not fixed, the output differential is also non-zero and not fixed;

[0050] When the input differential is an arbitrary value, the output differential is also an arbitrary value;

[0051] Therefore, use and represents the input and output of the j-th S-box in the i-th round, where 0≤i≤r2-1,0≤j≤m-1, and the corresponding MILP constraints are shown in Formula 4:

[0052]

[0053] When the S-box is a bijection, it also has the above properties. It is necessary to characterize the difference and Spread to When propagating the S-box, the constraints are as shown in Formula 5:

[0054]

[0055] (1.3) Construct the differential propagation characterization of the XOR operation:

[0056] When two differentials are XORed, the characteristic of differential propagation is that when two input differentials of 0 are XORed, the output differential must be 0;

[0057] When two non-zero inputs are XORed, the output difference is 0 when they are equal, and non-zero when they are not equal.

[0058] When both input differentials are fixed differential values, the output differential is also fixed accordingly;

[0059] Therefore, use and represents the two specific input differences of the XOR operation of the jth state unit in the i-th round, represents the output difference of its XOR operation, where 0≤i≤r2-1,0≤j≤m-1, then the MILP constraint characterization is shown in Formula 6:

[0060]

[0061] (1.4) Constructing the constraints of contradictions:

[0062] Assume that the contradictory position is in the jth state unit of the pd round, 0≤j≤m-1, that is, the differential state of the jth state unit of the upper differential pd round and difference value and the differential state of the jth state unit of the next differential pd wheel and difference value Constitute a contradiction. Consider all the contradictory situations in the BCT table. When the differential states are all non-zero, that is, and must be 01. According to formula 1, A i,j =01 means that the differential state is not 0 and is known. and The values ​​in the table When the value of 0 in the byte is 0, it means that the difference of the half byte is inconsistent. In this case, z i It means, 0≤i≤m-1, where z i =1 indicates contradiction, z i =0 means no contradiction;

[0063] If a half-byte state difference contradiction has been found at this time, the upper difference is further expanded with probability 1, and an attempt is made to expand the upper difference set of multiple contradictions after one round. There are n differences in total, and the output difference of the lower difference By comparing with the BCT table, if all entries are 0, the number of intermediate contradiction rounds is extended by one more round, the number of distinguisher rounds is further extended by one round, and the number of overall attack rounds is also extended by one round;

[0064] Point set for contradictions Indicates that all BCT table items, such as contradictory and non-contradictory point sets, are input into SageMath, and the coefficient matrix M of the linear inequality is obtained. i,j and constant column vector C, matrix M i,j Where i is the number of inequalities, the dimension of j is 15 points in the above contradiction point set, j=15, and the dimension of the constant column vector C is 15 points in the above contradiction point set, rows(C)=15, so the MILP constraint characterization of the contradiction point is constructed, as shown in Formula 7:

[0065]

[0066] (1.5) Constrain the input and output and their conflicting states:

[0067] (a) Restrictions for single key case:

[0068] In the case of a single key, no key differential is introduced, so it is only necessary to set the input differential of the upper differential to be non-zero, the output differential of the lower differential to be non-zero, and the number of contradictions to be at least one. The restriction conditions in the case of a single key are shown in Formula 8:

[0069]

[0070] (b) Restrictions in case of related keys:

[0071] In the correlated key mode, the key differential is introduced and XORed with the input differential to obtain the output differential. Therefore, the sum of the input differential and the key differential is non-zero, which ensures that the overall input differential of the cryptographic algorithm is non-zero.

[0072] Assume that the key difference of the first round is k 0,0 ,k 0,1 ,...,k 0,m-1 , the key difference of the last round is m is the number of S-boxes, so the restriction condition in the case of related keys is as shown in Formula 9:

[0073]

[0074] Reference Figure 1 , the extended part of the distinguisher is modeled in step (2), and the method is similar to step (1), but the modeling direction needs to be changed. The modeling adopts the upward expansion direction and the downward expansion direction. Assume that the input difference of the impossible Boomerang distinguisher is α, the length is the block length n of the cryptographic algorithm, the plaintext difference obtained by forward expansion is α′, the output difference is δ, and the ciphertext difference obtained by backward expansion is δ′. The specific steps of modeling are as follows:

[0075] (2.1) Extend the r1 round forward:

[0076] When expanding the r1 round forward, it is necessary to note that the key arrangement rules should be propagated in reverse order, and the differential propagation of the round function structure should also be carried out in the opposite direction with probability 1, as shown in Formula 5. The differential propagation of the S box should be carried out in the opposite direction, that is, from Spread to At this time, the active bits will also be added to the plaintext input difference. For the reverse column confusion operation, the column confusion matrix needs to be inverted and then multiplied with the state matrix to obtain the state matrix expanded in the reverse direction. The plaintext difference obtained by forward expansion is α′;

[0077] (2.2) Expand backwards to round r3:

[0078] When expanding backward, the output difference is δ, and the propagation direction can be the forward propagation of the round function structure of the cryptographic algorithm. When expanding backward, according to Formula 1, Formula 2, and Formula 3, it is necessary to characterize the relationship between the differential state and the differential value for the expanded state unit. Since backward expansion is forward propagation, the differential propagation characterization of the S box can be used using Formula 4, and the ciphertext difference obtained by backward expansion is δ′.

[0079] Reference Figure 1 In step (3), the plaintext difference and the ciphertext difference bits are used as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the specified number of attack rounds. The specific steps are as follows:

[0080] (3.1) The plaintext difference and the ciphertext difference are used as the objective function:

[0081] According to the expansion rules, the distinguisher searched in step (1) is used to expand forward and backward by r1 and r3 rounds respectively to obtain the plaintext difference plaintext 0,j Difference with ciphertext Will Set as the objective function, where 0≤j≤m-1, as shown in Formula 10:

[0082]

[0083] (3.2) Gurobi solves the MILP model:

[0084] The solution of the model is obtained by using the Gurobi solver, and a distinguisher for impossible Boomerang attacks and an optimal impossible Boomerang attack based on the distinguisher can be obtained;

[0085] If the MILP model is solved successfully, the Gurobi solver will return the result, which is the minimum value of the sum of the plaintext difference and the ciphertext difference of the objective function;

[0086] (3.3) Gurobi sets the multi-solution mode:

[0087] After the model solves the optimal value, the solution pool mode of the MILP model is set to the multi-solution mode. By setting the solution pool mode to 2, multiple solutions can be implemented, as shown in Formula 11:

[0088] model.setParam(GRB.Param.PoolSearchMode,2)(Formula 11);

[0089] And initialize the solution pool size to a self-set initial value λ, as shown in Formula 12:

[0090] model.setParam(GRB.Param.PoolSolutions,λ)(Formula 12);

[0091] If the initial solution pool is set to λ, the first λ solutions will all be solved. If the number of solutions is less than λ, all solutions that are less than λ will be solved.

[0092] The search method of the present invention can be solved as a judgment condition based on the MILP model to search for impossible Boomerang discriminators, so that the discriminator search and key recovery process can be further characterized as a unified model; by analyzing the propagation law of differentials in cryptographic algorithms, the differential propagation characteristics of each component of the cryptographic algorithm and all situations of upper and lower differentials at contradictory positions in the BCT table are characterized as new linear inequality constraints; then according to the forward and backward expansion of the discriminator, the active bits of the plaintext differential and the active bits of the ciphertext differential when expanding forward and backward in all contradictory situations can be obtained.

[0093] By characterizing all situations when the BCT table is contradictory, we can obtain multiple impossible Boomerang distinguishers with the same number of rounds and different contradictions, but not every distinguisher among the multiple distinguishers makes the attack optimal. Therefore, the key recovery forward and backward expansion rounds are added to the model, and the first and last active bits are minimized. Therefore, when the distinguisher can obtain the plaintext difference and ciphertext difference active bits with the least first and last contradictions, the optimal impossible Boomerang attack is obtained. This method integrates the distinguisher search and key recovery attack to avoid local optimality and obtain the overall optimality during the attack.

Claims

1. The optimal impossible Boomerang attack search method based on MILP is characterized by: The steps include: (1) Modeling the impossible Boomerang discriminator search based on the cryptographic algorithm: According to the properties of the round function and the differential propagation law, the linear components of the XOR operation in the round function, the nonlinear components of the S-box and the BCT contradiction points are modeled to form a complete impossible Boomerang discriminator search model; (2) Modeling the extended part of the discriminator: According to the expansion rule, the distinguisher is expanded forward and backward, and the active bits of the plaintext difference and the ciphertext difference are obtained through the active S-box position of the expansion round; (3) Finally, the plaintext difference and the ciphertext difference are used as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the specified number of attack rounds.

2. The optimal impossible Boomerang attack search method based on MILP according to claim 1, characterized in that: Step (1) models the search for impossible Boomerang distinguishers according to the cryptographic algorithm. Assuming that each round of block cipher iteration passes through m S-boxes, each S-box is 4 bits in size, then the total length is Bit, it is impossible that the contradiction of the Boomerang distinguisher is in the pd round, and the contradiction is extended to pd+1 round; If the distinguisher has a total of r2 rounds, A i,j and B i,j represents the differential state and differential value of the jth S-box of the i-th round in the distinguisher, where 0≤i≤r2-1,0≤j≤m-1; Since the differential state has only four cases: the difference is 0, the difference is not 0 and fixed, any non-zero value, and any value, a 2-bit A is used. i,j [0], A i,j [1] indicates 4 differential states; Since the difference value of the 4-bit S-box is in {0,1,2...15}, 4 bits are used to represent the difference, and another bit is required to indicate whether the difference value is an arbitrary value, so a 5-bit B i,j [0...5] indicates the specific difference value; when A i,j When [0] = 0, it means that the differential state of the state unit is inactive, indicating that the differential value is fixed. At this time, the differential value is {0, 1, 2...15}; When A i,j When [0] = 1, it indicates that the differential state of the state unit is active. At this time, there are two states: any non-zero value and any value. The differential values ​​are represented by 10001 and 10010 respectively. Taking a 4-bit S-box as an example, the differential state A of the S-box i,j and the difference value B i,j The corresponding relationship and specific values ​​are shown in formulas 1 and 2, where 0≤i≤r2-1, 0≤j≤m-1: The specific steps for modeling the impossible Boomerang discriminator search are as follows: (1.1) Construct the constraint characterization between the differential state and the corresponding specific differential value: Each state unit of the round function of the cryptographic algorithm uses the correspondence between the differential state and the differential value to characterize differential propagation, such as S-box, row shift, column confusion, linear operation or nonlinear operation in key arrangement. According to formula 1 and formula 2, the differential state A of each state unit of the distinguisher is obtained i,j and the difference value B i,j The MILP constraint inequality is shown in Equation 3. The differential state A i,j and the difference value B i,j where 0≤i≤r2-1,0≤j≤m-1; (1.2) Construct the differential propagation characterization of the S-box: When differential propagation passes through the S-box, the characteristic of differential propagation is that when the input differential is 0, the output differential must be 0, and when the input differential is non-0, the output differential is non-0; When the input differential is non-zero and not fixed, the output differential is also non-zero and not fixed; When the input differential is an arbitrary value, the output differential is also an arbitrary value; Therefore, use and represents the input and output of the j-th S-box in the i-th round, where 0≤i≤r2-1,0≤j≤m-1, and the corresponding MILP constraints are shown in Formula 4: When the S-box is a bijection, it also has the above properties. It is necessary to characterize the difference and Spread to When propagating the S-box, the constraints are as shown in Formula 5: (1.3) Construct the differential propagation characterization of the XOR operation: When two differentials are XORed, the characteristic of differential propagation is that when two input differentials of 0 are XORed, the output differential must be 0; When two non-zero inputs are XORed, the output difference is 0 when they are equal, and non-zero when they are not equal. When both input differentials are fixed differential values, the output differential is also fixed accordingly; Therefore, use and represents the two specific input differences of the XOR operation of the jth state unit in the i-th round, represents the output difference of its XOR operation, where 0≤i≤r2-1,0≤j≤m-1, then the MILP constraint characterization is shown in Formula 6: (1.4) Construct the constraint of the contradiction point: Assume that the contradiction position is in the j-th state unit of the pd round, 0≤j≤m-1, that is, the differential state of the j-th state unit of the upper differential pd round and difference value and the differential state of the jth state unit of the next differential pd wheel and difference value Constitute a contradiction. Consider all the contradictory situations in the BCT table. When the differential states are all non-zero, that is, and must be 01. According to formula 1, A i,j =01 means that the differential state is not 0 and is known. and The values ​​in the table When the value of 0 in the byte is 0, it means that the difference of the half byte is inconsistent. In this case, z i It means, 0≤i≤m-1, where z i =1 indicates contradiction, z i =0 means no contradiction; If a half-byte state difference contradiction has been found at this time, the upper difference is further expanded with probability 1, and an attempt is made to expand the upper difference set of multiple contradictions after one round. There are n differences in total, and the output difference of the lower difference By comparing with the BCT table, if all entries are 0, the number of intermediate contradiction rounds is extended by one more round, the number of distinguisher rounds is further extended by one round, and the number of overall attack rounds is also extended by one round; Point set for contradictions Indicates that all BCT table items, such as contradictory and non-contradictory point sets, are input into SageMath, and the coefficient matrix M of the linear inequality is obtained. i,j and constant column vector C, matrix M i,j Where i is the number of inequalities, the dimension of j is 15 points in the above contradiction point set, j=15, and the dimension of the constant column vector C is 15 points in the above contradiction point set, rows(C)=15, so the MILP constraint characterization of the contradiction point is constructed, as shown in Formula 7: (1.5) Constrain the input and output and their conflicting states: (a) Restrictions for single key case: In the case of a single key, no key differential is introduced, so it is only necessary to set the input differential of the upper differential to be non-zero, the output differential of the lower differential to be non-zero, and the number of contradictions to be at least one. The restriction conditions in the case of a single key are shown in Formula 8: (b) Restrictions in case of related keys: In the correlated key mode, the key difference is introduced and XORed with the input difference to obtain the output difference. Therefore, the sum of the input difference and the key difference is non-zero, which can ensure that the overall input difference of the cryptographic algorithm is non-zero. Suppose the first round key difference is k 0,0 ,k 0,1 ,..k. 0,,m-1 , the key difference of the last round is m is the number of S-boxes, so the restriction condition in the case of related keys is as shown in Formula 9:

3. The optimal impossible Boomerang attack search method based on MILP according to claim 1, characterized in that: Step (2) is to model the extended part of the distinguisher in a similar way to step (1), but the modeling direction needs to be changed. The modeling adopts the upward expansion direction and the downward expansion direction. Assume that the input difference of the impossible Boomerang distinguisher is α, the length is the block length n of the cryptographic algorithm, the plaintext difference obtained by forward expansion is α′, the output difference is δ, and the ciphertext difference obtained by backward expansion is δ′. The specific steps of modeling are as follows: (2.1) Extend the r1 round forward: When expanding the r1 round forward, it is necessary to note that the key arrangement rules should be propagated in reverse order, and the differential propagation of the round function structure should also be carried out in the opposite direction with probability 1, as shown in Formula 5. The differential propagation of the S box should be carried out in the opposite direction, that is, from Spread to At this time, the active bits will also be added to the plaintext input difference. For the reverse column confusion operation, the column confusion matrix needs to be inverted and then multiplied with the state matrix to obtain the state matrix expanded in the reverse direction. The plaintext difference obtained by forward expansion is α′; (2.2) Expand the r3 round backwards: When expanding backward, the output difference is δ, and the propagation direction can be the forward propagation of the round function structure of the cryptographic algorithm. When expanding backward, according to Formula 1, Formula 2, and Formula 3, it is necessary to characterize the relationship between the differential state and the differential value for the expanded state unit. Since backward expansion is forward propagation, the differential propagation characterization of the S box can be used using Formula 4, and the ciphertext difference obtained by backward expansion is δ′.

4. The optimal impossible Boomerang attack search method based on MILP according to claim 1, characterized in that: In step (3), the plaintext difference and the ciphertext difference bits are used as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the specified number of attack rounds. The specific steps are as follows: (3.1) The plaintext difference and the ciphertext difference are used as the objective function: According to the expansion rules, the distinguisher searched in step (1) is used to expand forward and backward by r1 and r3 rounds respectively to obtain the plaintext difference plaintext 0,j Difference with ciphertext Will Set as the objective function, where 0≤j≤m-1, as shown in Formula 10: (3.2) Gurobi solves the MILP model: The solution of the model is obtained by using the Gurobi solver, and a distinguisher for impossible Boomerang attacks and an optimal impossible Boomerang attack based on the distinguisher can be obtained; If the MILP model is solved successfully, the Gurobi solver will return the result, which is the minimum value of the sum of the plaintext difference and the ciphertext difference of the objective function; (3.3) Gurobi sets the multi-solution mode: After the model solves the optimal value, the solution pool mode of the MILP model is set to the multi-solution mode. By setting the solution pool mode to 2, multiple solutions can be implemented, as shown in Formula 11: model.setParam(GRB.Param.PoolSearchMode,2)(Formula 11); and initialize the solution pool size to a self-set initial value of λ, as shown in Formula 12: model.setParam(GRB.Param.PoolSolutions,λ)(Formula 12); If the initial solution pool is set to λ, then the first λ solutions will all be solved. If the number of solutions is less than λ, then all the solutions that are less than λ will be solved.