Mobile payment system encryption strength evaluation method based on automatic differential analysis

By adopting automated differential analysis methods in mobile payment systems, dynamically update the optimal differential characteristics, and using Matsui algorithm and optimization algorithm to improve search efficiency, solving the problem of low efficiency in packet password encryption strength evaluation in the existing technology, and significantly improving the system's differential attack resistance ability.

CN119963188AInactive Publication Date: 2025-05-09GUILIN UNIV OF ELECTRONIC TECH
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510028383.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-08
Publication Date
2025-05-09
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The prior art is not very effective when evaluating the strength of packet password encryption in mobile payment systems. Especially when the number of iteration rounds is high, it is difficult to quickly and accurately find differential characteristics, resulting in insufficient defense capabilities in the system when facing differential attacks.

Method used

Using an automated differential analysis method, the optimal differential feature is dynamically updated by setting the upper bound, the search space is divided into three subsets, the Matsui algorithm is used to calculate the subset lower bound, the inequality group is optimized using greedy algorithm and the minimum norm algorithm, the appropriate search order is selected for searching, and the optimal differential feature is integrated for security analysis and optimization of the encryption algorithm.

Benefits of technology

It significantly improves the search speed and efficiency of differential characteristics of packet passwords under high rounds, enhances the differential attack resistance of the mobile payment system, and ensures the accuracy and speed of the system's encryption strength evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119963188A_ABST
    Figure CN119963188A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of differential analysis, in particular to a mobile payment system encryption strength evaluation method based on automatic differential analysis, and the method comprises the steps: setting an upper bound in a mobile payment system, taking a generated effective differential feature as an optimal differential feature, and carrying out the dynamic updating of the optimal differential feature in a search process; dividing the whole search space into three subsets, and calculating the lower bound of the subsets; deleting redundant inequalities in the inequation group, and reducing norms of the inequation group; selecting a proper search sequence to search the subsets, starting from the middle, performing up-and-down oscillation search, if the lower bound is greater than or equal to the upper bound, stopping the search, integrating the optimal difference characteristics in all the subsets, performing security analysis on the encryption algorithm of the payment system, and adjusting and optimizing the encryption strategy. According to the method, the automatic modeling technology is utilized, the divide-and-conquer algorithm, the Matsui algorithm and the inequality norm optimization algorithm are combined, and the efficiency of solving the differential features under the condition that the number of rounds of grouping is high is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of differential analysis, and in particular to an encryption strength assessment method for a mobile payment system based on automated differential analysis. Background Art

[0002] With the rapid development of mobile payment technology, more and more consumers rely on smartphones and other mobile devices for daily payments and financial transactions. This increase in convenience has brought strict requirements on the security of payment systems, especially in the face of an increasingly complex network threat environment. Differential cryptanalysis is one of the main means of evaluating the security of block ciphers. Attackers may use statistical deviations of cryptographic algorithms to recover keys or decrypt information, and the core of differential cryptanalysis lies in how to efficiently and quickly find the differential trajectory of the corresponding block cipher under high rounds. Therefore, in order to ensure the security of the mobile payment system, there is a need for a fast and accurate calculation method for obtaining the differential trajectory of the block cipher, so that the encryption strength of the mobile system can be efficiently verified, and an improvement strategy is proposed to ensure the ability of the mobile payment system to resist differential attacks and improve the security of the system.

[0003] Mixed integer linear programming (MILP) has been widely used in differential cryptanalysis research, mainly to solve the problems of searching for the minimum number of active S-boxes and searching for the best differential features. However, with the increase of the number of iterations, the efficiency of the model is not satisfactory for many symmetric key primitives. At present, the solutions to solve the efficiency include simple division of the number of rounds, divide-and-conquer algorithms, and branch-and-bound search algorithms, but there are still some problems in solving the efficiency of the existing MILP model. Summary of the invention

[0004] The purpose of the present invention is to provide a mobile payment system encryption strength assessment method based on automated differential analysis, which is used to quickly and accurately assess the encryption strength of block ciphers in the mobile payment system, and optimize the security of the system according to the analysis results to meet the needs of the modern payment environment.

[0005] To achieve the above object, the present invention provides a method for evaluating the encryption strength of a mobile payment system based on automated differential analysis, comprising the following steps:

[0006] An upper bound is set in the mobile payment system, and a generated effective differential feature is used as the current best differential feature, which is dynamically updated during the search process;

[0007] Divide the entire search space into three subsets, and use the Matsui algorithm to calculate the lower bound of the subsets;

[0008] Use the greedy algorithm to delete the redundant inequalities in the inequality group, and use the minimum norm algorithm to reduce the norm of the inequality group;

[0009] Select a suitable search order to search the subsets, starting from the middle and oscillating up and down. If the lower bound is greater than or equal to the upper bound, stop searching the current subset, integrate the best differential features in all subsets, perform security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy.

[0010] The specific method of setting an upper bound in the mobile payment system, taking a generated valid differential feature as the current best differential feature, and dynamically updating it during the search process is as follows:

[0011] Bit-level XOR modeling;

[0012] For S-box modeling;

[0013] The solution is obtained using the Gurobi solver.

[0014] The specific method of dividing the entire search space into three subsets and using the Matsui algorithm to calculate the lower bound of the subsets is as follows:

[0015] Set partitioning, establishing subset MILP constraints;

[0016] Use Matsui branch bound depth first algorithm to find the lower bound of the current subset;

[0017] Write the subset partitioning constraints into the Matsui condition.

[0018] The specific method of using the greedy algorithm to delete redundant inequalities in the inequality group and using the minimum norm algorithm to reduce the norm of the inequality group is:

[0019] Take out the inequalities in the inequality group after removing redundancy using the greedy algorithm;

[0020] Find the solution space of the inequality and add the solution set to the set;

[0021] Define the variables low and high for the binary search, initialize them, solve them, and return the inequality after norm reduction.

[0022] Among them, the method of selecting a suitable search order to search the subsets, starting from the middle, and searching up and down, if the lower bound is greater than or equal to the upper bound, then stop searching the current subset, continue to turn to other subsets, integrate the best differential features in all subsets, conduct security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy:

[0023] Select a suitable search order to search the subset, starting from the middle and searching up and down. If the lower bound is greater than or equal to the upper bound, stop searching.

[0024] The best differential features in all subsets are integrated to obtain the best differential features in the entire set.

[0025] The encryption strength assessment method of a mobile payment system based on automated differential analysis of the present invention sets an upper bound in the mobile payment system, takes a generated effective differential feature as the current optimal differential feature, and dynamically updates it during the search process; divides the entire search space into three subsets, and uses the Matsui algorithm to calculate the lower bound of the subset; uses a greedy algorithm to delete redundant inequalities in the inequality group, and uses a minimum norm algorithm to reduce the norm of the inequality group; selects a suitable search order to search the subsets, starts from the middle, and searches up and down, stops searching if the lower bound is greater than or equal to the upper bound, integrates the best differential features in all subsets, performs security analysis on the encryption algorithm of the payment system, and adjusts and optimizes the encryption strategy; the method uses automated modeling technology, combines the divide-and-conquer algorithm, the Matsui algorithm, and the inequality norm optimization algorithm, improves the efficiency of solving differential features in the case of a high number of rounds, and reduces a relatively large number of iteration rounds. R Decompose it and combine it with Matsui's branch and bound depth first search algorithm to accelerate it. For the inequality group (FLIIC) modeled by the MILP method, the norm and cardinality of the constructed FLIIC are reduced, so that when the number of differential feature search rounds is high, the search will not fail due to excessive complexity, and significantly improve the search speed and efficiency of differential features in the same round, laying a good foundation for subsequent key recovery work. It can handle Feistel and SP-network structures in block ciphers, mainly applied to SP-network structures, and divide all possible differential feature sets into smaller subsets for separate searches through a divide-and-conquer algorithm. For the search lower bound, Matsui's branch and bound depth first search algorithm is used to accelerate it. Among them, a series of linear inequality groups obtained by the MILP tool are optimized using a norm reduction algorithm to improve the solution speed of the Gurobi solver, and a more efficient search for differential features of block ciphers under high rounds is achieved, and it can be used to evaluate the security of block ciphers against differential attacks. This method can improve the efficiency of solving the minimum number of active S-boxes and the best differential characteristics of symmetric key primitives when the number of rounds is high, and plays a certain role in cryptographic security assessment, with important practical application value. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0027] Figure 1 It is a flow chart of the encryption strength assessment method of the mobile payment system based on automated differential analysis provided by the present invention.

[0028] Figure 2 It is a flowchart of the minimum norm reduction algorithm used in the present invention.

[0029] Figure 3 It is a flowchart of a specific method of setting an upper bound, taking a generated effective differential feature as the current best differential feature, and dynamically updating it during the search process.

[0030] Figure 4 It is a flowchart of a specific method of dividing the entire search space into three subsets in a mobile payment system and using the Matsui algorithm to calculate the lower bound of the subsets.

[0031] Figure 5 It is a flowchart of a specific method of using a greedy algorithm to delete redundant inequalities in an inequality group and using a minimum norm algorithm to reduce the norm of the inequality group.

[0032] Figure 6 It is to select the appropriate search order to search the subsets, starting from the middle, and oscillating up and down to search. If the lower bound is greater than or equal to the upper bound, stop searching the current subset and turn to searching other subsets, integrate the best differential features in all subsets, conduct security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy. Flowchart of the specific method. DETAILED DESCRIPTION

[0033] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.

[0034] See also Figures 1 to 6 The present invention provides a method for evaluating the encryption strength of a mobile payment system based on automated differential analysis, comprising the following steps:

[0035] S1 sets an upper bound in the mobile payment system, takes a generated valid differential feature as the current best differential feature, and dynamically updates it during the search process;

[0036] In the embodiment of the present invention, in the mobile payment system, the correct algorithm selection can help ensure that the system complies with international security standards and regulatory requirements, thereby maintaining user trust and promoting the sustainable development of the business. Data collection is the key to determining which block cipher algorithm to use. Specifically, determine the encryption requirements: analyze the specific requirements of the mobile payment system, including the confidentiality, integrity, authentication requirements of the data and the ability to resist potential attacks. Collect candidate algorithms: First, lightweight block ciphers can be used, including encryption algorithms such as Craft-64. For example, the design of Craft pays special attention to preventing differential fault attacks, and its high efficiency in software implementation makes it suitable for resource-constrained devices, which is more suitable for the initial setting of the candidate algorithm of this system, and then adjusts it according to the results obtained by the differential optimization model algorithm. Preliminary evaluation: The goal of the preliminary evaluation is to evaluate the basic security of each collected encryption algorithm to determine its adaptability to the system, and to conduct compliance verification to verify whether the algorithm meets the relevant security standards and regulatory requirements, so as to pave the way for differential analysis of the selected cipher based on MILP modeling in the subsequent steps. At the beginning of the search, a valid differential feature needs to be generated and used as the best differential feature. Its number of active S-boxes is the minimum active S-boxes, and then the current best differential feature is dynamically updated during the search process.

[0037] Specific method:

[0038] S11 bit-level XOR modeling;

[0039] In an embodiment of the present invention, bit-level XOR modeling is performed:

[0040]

[0041] Among them, x in1 , x in2 is the input bit difference, y out The output bit differences are all binary variables.

[0042] S12 for S-box modeling;

[0043] In the embodiment of the present invention, the S-box is modeled (assuming that the input and output difference of the S-box is 4-bit):

[0044]

[0045] Among them, A r,i represents the active state of the i-th S-box in round r, x r,4·i ,xr,4·i+1 ,x r,4·i+2 ,x r,4·i+3 The input bit difference is binary variable. According to DDT (Differential Distribution Table), all possible differential patterns and their probabilities are used to model the inequality group using the mathematical tool SageMath. According to the impossible differential pattern, the redundant inequalities are simplified using the greedy algorithm.

[0046] S13 is solved using the Gurobi solver.

[0047] In an embodiment of the present invention, the established inequality group is solved using a Gurobi solver. If the status is feasible, the inequality group has a solution, and one of the solutions is selected. This solution is a valid differential feature and is dynamically updated as the current best differential feature.

[0048] S2 divides the entire search space into three subsets and uses the Matsui algorithm to calculate the lower bound of the subsets;

[0049] In an embodiment of the present invention, during the subset search process, the weight of the best differential feature used to introduce the upper bound is used as the threshold. If the lower bound of the searched subset is greater than or equal to the upper bound, then there is no feature with a weight less than the current best differential feature. It is necessary to terminate the search for this subset in advance and search the next subset to reduce the number of inequalities in the MILP model.

[0050] Specific method:

[0051] S21 set partitioning, establishing subset MILP constraints;

[0052] In the embodiment of the present invention, set partitioning: for a block cipher of R rounds, all possible differential features are divided into three subsets: Subset-1: the divided differential features have at least one active S-box in each round, and at least one round has exactly one active S-box. Subset-2: the divided differential features have at least two active S-boxes in each round, and at least one round has exactly two active S-boxes. Subset-3: the divided differential features have at least three active S-boxes in each round. Set variable C r,NA,i,Δ , indicating that there are a total of R rounds, and except for the i-th round, each round has at least N A active S-boxes, the input difference value in the i-th round is Δ and the number of active S-boxes corresponding to this difference value is N A In summary, all possible differential features of a block cipher can be divided into:

[0053] Where N A ∈{1,2},i∈{1,2,…,R}

[0054] Establish subset MILP constraints: For the subset There are two constraints that need to be met.

[0055] Condition 1: Except for the i-th round, each round has at least N A Active S-boxes. Where j∈{1,2,…,R}, j≠R.

[0056] Condition 2: The input difference value of the i-th round is required to be Δ. i,j =Δ j , where j∈{0,1,…,n-1}, x i,j Represents the j-bit difference value of the i-th round.

[0057] S22 uses the Matsui branch-bound depth-first algorithm to find the lower bound:

[0058] In the embodiment of the present invention, Matsui algorithm is used to calculate the Best (i), where i∈{1,2,…,R-1}. Use a depth-first approach to explore the search space of all possible differential features and output the optimal R-round differential features. Perform a conditional test on the specified boundary. If this condition is violated, the current branch needs to be abandoned and another branch needs to be tried. Where P Rd (i) represents α i-1 →α i The probability, P Estim Represents the probability of a known feature. Set the variable obj as P in the test condition Estim , and set the objective function to obj, objective function: Among them A i,j Expressed as a probability weight variable, the contribution weight of the i-th round is Matsui's boundary condition constraints are M 1 and M 2 . M 1 Means: From round 1 to round R-1, R-1 additional constraints are generated according to Matsui's bounding conditions. 2 Representation: Use minimize obj as the objective function and add all 2R-2 additional constraints.

[0059]

[0060] Among them, P Best (1),P Best (2),…,P Best(R-1) The probability is known.

[0061]

[0062] Among them, P Best (1),P Best (2),…,P Best (R-1) The probability is known.

[0063] S23 writes the subset partitioning restriction condition into the Matsui condition.

[0064] In the embodiment of the present invention, the subset partitioning restriction condition is written into the Matsui condition to construct M 3 ;

[0065]

[0066] Among them, P Best (1),P Best (2),…,P Best (R-1) The probability is known.

[0067] S3 uses a greedy algorithm to delete redundant inequalities in the inequality group and uses a minimum norm algorithm to reduce the norm of the inequality group;

[0068] In an embodiment of the present invention, the obtained inequality group is set to Under the premise of keeping the solution space of the inequality group unchanged, the coefficients of the inequality group are simplified by using the bisection method, and the Gurobi solver is used to solve it until the output state is infeasible, so as to find the inequality group with the minimum norm equivalent to the original inequality group. The specific process of the minimum norm algorithm is as follows: Figure 2 shown.

[0069] Specific method:

[0070] S31 extracts the inequalities in the inequality group after removing redundancy using the greedy algorithm;

[0071] In the embodiment of the present invention, the inequality 1 is taken out from the inequality group after redundancy removal using the greedy algorithm: a0x0+a1x1+…+a n-1 x n-1 ≥b.

[0072] S32 finds the solution space of the inequality and adds the solution set to the set;

[0073] In the embodiment of the present invention, the solution space and its complement are obtained, and they are added to two different sets respectively to obtain the solution space of inequality l, and the solution set is added to set S, and the complement of the solution set is added to Go in.

[0074] S33 defines the variables low and high for the dichotomy, initializes them, solves them, and returns the inequality after norm reduction.

[0075] In the embodiment of the present invention, the variables low and high of the binary method are defined and initialized, low = 0, high = max{abs(a i ),abs(b),i=0,1,…,n-1}.

[0076] Under the premise of low ≤ high, Using Gurobi solver to solve MILP model When solving, when the solver state is feasible, high = mid-1, when the solver state is infeasible, low = mid+1.

[0077] When low>high, the binary search algorithm ends and the inequality L after norm reduction is returned.

[0078] S4 selects a suitable search order to search the subsets, starting from the middle and oscillating up and down to search. If the lower bound is greater than or equal to the upper bound, stop searching the current subset and continue to search other subsets, integrating the best differential features in all subsets, performing security analysis on the encryption algorithm of the payment system, and adjusting and optimizing the encryption strategy.

[0079] In the embodiment of the present invention, for the last step of this model, it is necessary to select a suitable search order for the subset C r,NA,i,Δ There are two principles for searching: 1. Prioritize the subsets that are more likely to provide better differential features. 2. Prioritize the subsets that can be solved faster by the corresponding MILP model. Since the input differential of the i-th round is fixed to Δ, the complexity of searching the subset depends on the sum of the complexity of the first (i-1) round and the last (r-i+1) round. Therefore, we can start the search from the middle of R, and then oscillate the search from the middle up and down. When the number of search rounds R is an even number, the search order is: When the number of search rounds R is an odd number, the search order is:

[0080] Integrate the best differential features determined in all subsets, and finally obtain the best differential features in the entire set, the differential trajectory of the high rounds of the adopted block cipher, conduct security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy to improve the anti-differential attack capability of the encryption algorithm in the system. This includes the expansion of the distinguisher and the improvement of the encryption strategy. Specifically, the differential distinguisher is extended forward by r1 rounds and backward by r2 rounds to perform (r1+R+r2) rounds of key recovery attack; in the key recovery part, the key bridging technology is used to find the relationship between keys of different rounds to reduce the complexity of the recovery attack; the encryption strength of the cryptographic algorithm used in this mobile payment system is calculated; the encryption parameters are adjusted, such as adjusting the key length and replacing a more powerful S-box design to enhance the encryption strength. For fundamental security flaws, consider replacing a more secure encryption algorithm, such as upgrading Craft-64 to AES-128.

[0081] What is disclosed above is only a preferred embodiment of the encryption strength assessment method for a mobile payment system based on automated differential analysis of the present invention. Of course, this cannot be used to limit the scope of rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of the above embodiments are implemented, and equivalent changes made according to the claims of the present invention still fall within the scope of the invention.

Claims

1. A method for evaluating the encryption strength of a mobile payment system based on automated differential analysis, characterized in that: The following steps are involved: An upper bound is set in the mobile payment system, and a generated effective differential feature is used as the current best differential feature, which is dynamically updated during the search process; Divide the entire search space into three subsets, and use the Matsui algorithm to calculate the lower bound of the subsets; Use the greedy algorithm to delete the redundant inequalities in the inequality group, and use the minimum norm algorithm to reduce the norm of the inequality group; Select a suitable search order to search the subsets, starting from the middle and oscillating up and down. If the lower bound is greater than or equal to the upper bound, stop searching the current subset and continue to search other subsets. Integrate the best differential features in all subsets, perform security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy.

2. The method for evaluating the encryption strength of a mobile payment system based on automated differential analysis as claimed in claim 1, It is characterized by: The specific method of setting an upper bound in the mobile payment system, taking a generated effective differential feature as the current best differential feature, and dynamically updating it during the search process is as follows: Bit-level XOR modeling; For S-box modeling; The solution is obtained using the Gurobi solver.

3. The method for evaluating the encryption strength of a mobile payment system based on automated differential analysis as claimed in claim 1, It is characterized by: The specific method of dividing the entire search space into three subsets and using the Matsui algorithm to calculate the lower bound of the subsets is: Set partitioning, establishing subset MILP constraints; Use Matsui branch bounding depth first algorithm to find the lower bound of the current subset: Write the subset partitioning constraints into the Matsui condition.

4. The method for evaluating the encryption strength of a mobile payment system based on automated differential analysis as claimed in claim 1, It is characterized by: The specific method of using the greedy algorithm to delete redundant inequalities in the inequality group and using the minimum norm algorithm to reduce the norm of the inequality group is: Take out the inequalities in the inequality group after removing redundancy using the greedy algorithm; Find the solution space of the inequality and add the solution set to the set; Define the variables low and high for the binary search, initialize them, solve them, and return the inequality after norm reduction.

5. The method for evaluating the encryption strength of a mobile payment system based on automated differential analysis as claimed in claim 1, characterized in that ; The specific method of selecting a suitable search order to search the subsets, starting from the middle, oscillating up and down to search, if the lower bound is greater than or equal to the upper bound, stop searching, integrate the best differential features in all subsets, perform security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy is as follows: Select a suitable search order to search the subset, start from the middle, and search up and down. If the lower bound is greater than or equal to the upper bound, stop searching. Integrate the best differential features from all subsets, conduct security analysis on the encryption algorithm of the payment system, and adjust and optimize the encryption strategy.

Citation Information

Patent Citations

  • Tweeakable GOST2 differential route searching method based on MILP

    CN112953703A