Elliptic curve point addition arithmetic unit, ciphertext decryption method and related device
By designing an elliptic curve point addition operator for quantum computing, the slope of points on the elliptic curve and the point addition operation is performed, the problem of low efficiency of elliptic curve point addition operation in the binary domain in the prior art is solved, and the acceleration of key cracking is achieved.
Patent Information
- Application Number
- CN202311552463.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-17
- Publication Date
- 2025-05-20
AI Technical Summary
The prior art is difficult to implement elliptical curve point addition operation on the binary domain through quantum computing, resulting in insufficiency of key cracking.
An elliptic curve point addition operator including a first operation module and a second operation module is designed, and the slope λ of two points to be added on the elliptic curve is calculated by quantum computing, and the point addition calculation result is calculated based on the slope.
The elliptic curve point addition operation on the binary domain is realized, which significantly accelerates the key cracking process and provides technical support.
Smart Images

Figure CN120020827A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of quantum computing, and particularly relates to an elliptic curve point addition operator, a ciphertext decryption method, and related devices. Background Art
[0002] Elliptic curves are a special type of algebraic curves. All rational points on them can form an additive group, and the addition operation has the characteristics of geometric addition. Take two points \(P\) and \(Q\) on the elliptic curve. If \(P\neq Q\) and \(P\), \(Q\) are not the infinite point \(O\), then connect \(P\) and \(Q\) to form a straight line. This straight line will intersect the elliptic curve at a third point \(G\). Then draw a straight line perpendicular to the \(x\)-axis through point \(G\), which will pass through another point \(R\) on the elliptic curve (usually a point symmetric about the \(x\)-axis). Point \(R\) is defined as the result of \(P + Q\), that is, \(P+Q = R\). This operation process is called the general point addition operation of the elliptic curve.
[0003] The general point addition operation based on elliptic curves is one of the core principles of the Elliptic curve cryptography (ECC). Its security is mainly based on the elliptic curve discrete logarithm problem: Given two points \(P\), \(Q\) on the elliptic curve and satisfying \([d]P = Q\), solve the discrete logarithm \(d\).
[0004] A quantum computer is a physical device that follows the laws of quantum mechanics to perform high-speed mathematical and logical operations, store, and process quantum information. When a device processes and calculates quantum information and runs quantum algorithms, it is a quantum computer. Because a quantum computer has a more efficient ability to process mathematical problems compared to ordinary computers. For example, it can accelerate the time to crack a key from hundreds of years to a few hours. Therefore, it has become a key technology under research. Thus, how to implement the elliptic curve point addition operation over the binary field through quantum computing is a key step in accelerating key cracking. Summary of the Invention
[0005] The object of the present invention is to provide an elliptic curve point addition operator, a ciphertext decryption method, and related devices, aiming to implement the elliptic curve point addition operation over the binary field through quantum computing and accelerate key cracking.
[0006] To achieve the above object, in the first aspect of the embodiments of the present invention, an elliptic curve point addition operator over the binary field is provided. The elliptic curve includes where \(\mathbb{F}_2\) represents the binary field, and the point addition operator includes: a first operation module and a second operation module;
[0007] wherein, the first operation module is used to calculate the slope \(\lambda\) of the line connecting the two points to be point-added on the elliptic curve;
[0008] The second operation module is used to calculate the point addition operation result of two points to be point-added on the elliptic curve according to the slope λ.
[0009] Optionally, the first operation module includes a first constant addition sub-module, a first modular inverse sub-module, and a first modular multiplication sub-module. The first operation module acts on a first register and a second register; the first register is used to obtain the abscissa x of one of the points to be point-added 1 corresponding quantum state |x 1 >, and the second register is used to load the ordinate y of the one of the points to be point-added 1 corresponding quantum state |y 1 >;
[0010] Among them, the first constant addition sub-module acts on the first register and the second register, so that the quantum state of the first register evolves from |x 1 > to |x 1 + x 2 >, and the quantum state of the second register evolves from |y 1 > to |y 1 + y 2 >, where (x 2 , y 1 ) is another point to be point-added on the elliptic curve point;
[0011] The first modular inverse sub-module acts on the first register and an auxiliary register, so that the quantum state of the auxiliary register evolves from |0> to |(x 1 + x 2 ) -1 mod m>, where m is an n-degree irreducible polynomial over the binary field ;
[0012] The first modular multiplication sub-module acts on the second register, the third register, and the auxiliary register, so that the quantum state of the third register evolves from |0> to |λ> = |(y 1 + y 2 ) * (x 1 + x 2 ) -1 mod m>.
[0013] Optionally, the second operation module acts on the first register, the second register, and the auxiliary register, and is used to evolve the quantum state of the first register from |x 1 + x 2 > to |x 3 > = |λ 2+λ + x1 + x2 + a, evolving the quantum state of the second register from y1 + y2 to y3 = x2 + x3*λ + x3 + y2, where (x 3 , y 3 ) is the result of bitwise addition.
[0014] Optionally, the second operation module includes a second modular multiplier module and a first modular squarer module. The second modular multiplier module acts on the first register, the second register, and the third register to perform a modular multiplication operation on the first register and the third register, and implement the operation between the quantum state |y 1 + y 2 > and the result of the modular multiplication operation, so that the quantum state of the second register evolves to |0.
[0015] The first modular squarer module acts on the third register to store the result of the modular square operation |λ 2 > into the second register, and evolve the quantum state of the second register from |0> to |λ 2 .
[0016] Optionally, the second operation module further includes a second constant sub - adder module. The second constant adder sub - module acts on the first register to evolve the quantum state |x 1 + x 1 > to |x 1 + a>.
[0017] Optionally, the second operation module further includes a first CNOT gate and a second CNOT gate. The control bit of the first CNOT gate is the third register, and the target bit is the first register, so that the quantum state of the first register evolves from |x 1 + a> to |x 1 + a + λ>;
[0018] The control bit of the second CNOT gate is the second register, and the target bit is the first register, so that the quantum state of the first register evolves from |x 1 + a + λ> to |x 1 + a + λ + λ 1 .
[0019] Optionally, the second operation module further includes a second modular squarer module. The second modular squarer module acts on the third register to perform a modular square operation, and implement the operation between the quantum state |λ 1 > and the result of the modular square operation, so that the quantum state of the second register evolves from |λ 2 > to |0>;
[0020] The second modular multiplication sub-module is further configured to perform modular multiplication operations on the first register and the third register, and store the modular multiplication operation result in the second register, so that the quantum state of the second register evolves from |0> to |(x 3 +x 2 )*λ>;
[0021] The second constant addition sub-module also acts on the first register, so that the quantum state of the first register evolves from |x 1 +a+λ+λ 2 > to |x 3 > = |λ 2 +λ+x 1 +x 2 +a>.
[0022] Optionally, the second operation module further includes a third CNOT gate, where the control bit of the third CNOT gate is the first register, and the target bit is the second register, so that the quantum state of the second register evolves from |(x 3 +x 2 )*λ> to |(x 3 +x 2 )*λ+x 3 >;
[0023] The second constant addition sub-module also acts on the second register, so that the quantum state of the second register evolves from |(x 3 +x 2 )*λ+x 3 to |y 3 > = |(x 3 +x 2 )*λ+x 3 +y 2 >.
[0024] In a second aspect, an embodiment of the present invention provides a ciphertext decryption method, and the method includes:
[0025] Obtain the public key and the base point of the ciphertext to be decrypted;
[0026] Based on the control bit and 2n + 2 cascaded elliptic curve point adder as described in any one of the first aspects, construct a quantum decryption circuit, where the control bit is used to control the first n + 1 elliptic curve point adders to perform n + 1 point addition operations on the base point, and control the last n + 1 elliptic curve point adders to perform n + 1 point addition operations on the public key;
[0027] Run the quantum decryption circuit. For each elliptic curve point addition operator, after the control bit controls the current elliptic curve point addition operator to perform point addition operation, measure the quantum state of the control bit, and set the quantum state of the control bit to the zero state to control the next elliptic curve point addition operator to perform point addition operation, so as to obtain a measurement result sequence;
[0028] Solve the private key of the ciphertext to be decrypted according to the measurement result sequence, and decrypt the ciphertext to be decrypted.
[0029] In a third aspect, an embodiment of the present invention provides a ciphertext decryption device, and the device includes:
[0030] An acquisition module, configured to acquire the public key and the base point of the ciphertext to be decrypted;
[0031] A construction module, configured to construct a quantum decryption circuit based on a control bit and 2n + 2 cascaded elliptic curve point addition operators as described in any one of the first aspects, where the control bit is used to control the first n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the base point, and control the latter n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the public key;
[0032] A running module, configured to run the quantum decryption circuit. For each elliptic curve point addition operator, after the control bit controls the current elliptic curve point addition operator to perform point addition operation, measure the quantum state of the control bit, and set the quantum state of the control bit to the zero state to control the next elliptic curve point addition operator to perform point addition operation, so as to obtain a measurement result sequence;
[0033] In a fourth aspect of the embodiments of the present invention, a storage medium is provided, and a computer program is stored in the storage medium, where the computer program is configured to execute the steps of the method described in the second aspect when running.
[0034] In a fifth aspect of the embodiments of the present invention, an electronic device is provided, including a memory and a processor, a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps of the method described in the second aspect.
[0035] Based on the above technical solutions, by providing an elliptic curve point addition operator, the elliptic curve includes Denote the binary field. The point addition calculator includes: a first operation module and a second operation module. Among them, the first operation module is used to calculate the slope λ of the line connecting two points to be added on the elliptic curve. The second operation module is used to calculate the point addition operation result of two points to be added on the elliptic curve according to the slope λ. The point addition operation of the elliptic curve over the binary field is realized through quantum computing, providing technical support for accelerating key cracking. Description of the Drawings
[0036] Figure 1 It is a network block diagram of a ciphertext decryption system shown according to an exemplary embodiment.
[0037] Figure 2 It is a schematic diagram of an elliptic curve point addition operation shown according to an exemplary embodiment.
[0038] Figure 3 It is a schematic diagram of an elliptic curve point addition calculator shown according to an exemplary embodiment.
[0039] Figure 4 It is a flowchart of a ciphertext decryption method shown according to an exemplary embodiment.
[0040] Figure 5 It is a schematic diagram of a quantum decryption circuit shown according to an exemplary embodiment.
[0041] Figure 6 It is a block diagram of a ciphertext decryption device shown according to an exemplary embodiment.
[0042] Figure 7 It is a block diagram of a computer device shown according to an exemplary embodiment. Detailed Embodiments
[0043] The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0044] Figure 1 It is a network block diagram of the ciphertext decryption system provided by the embodiment of the present invention. The ciphertext decryption system may include a network 110, a server 120, a wireless device 130, a client 140, a storage 150, a classical computing unit 160, a quantum computing unit 170, and may also include additional memories, classical processors, quantum processors, and other devices not shown.
[0045] The network 110 is a medium for providing a communication link between various devices and computers connected together within the ciphertext decryption system, including but not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof. The connection method may adopt wired, wireless communication links, or fiber optic cables, etc.
[0046] The server 120, the wireless device 130, and the client 140 are conventional data processing systems, which may contain data and have application programs or software tools for performing conventional computing processes. The client 140 may be a personal computer or a network computer, and thus the data may also be provided by the server 120. The wireless device 130 may be a smart phone, a tablet, a laptop computer, a smart wearable device, etc. The storage unit 150 may include a database 151, which may be configured to store data such as qubit parameters, quantum logic gate parameters, quantum circuits, quantum programs, etc.
[0047] The classical computing unit 160 (quantum computing unit 170) may include a classical processor 161 (quantum processor 171) for processing classical data (quantum data) and a memory 162 (memory 172) for storing classical data (quantum data). The classical data (quantum data) may be a boot file, an operating system image, and an application program 163 (application program 173). The application program 163 (application program 173) may be used to implement a quantum algorithm compiled according to the ciphertext decryption method provided in the embodiments of the present invention.
[0048] Any data or information stored or generated in the classical computing unit 160 (quantum computing unit 170) may also be configured to be stored or generated in another classical (quantum) processing system in a similar manner. Similarly, any application program executed by it may be configured to be executed in another classical (quantum) processing system in a similar manner.
[0049] It should be noted that a real quantum computer has a hybrid structure, which at least includes Figure 1 two major parts: a classical computing unit 160, responsible for performing classical computing and control; a quantum computing unit 170, responsible for running quantum programs to implement quantum computing.
[0050] The above-mentioned classical computing unit 160 and quantum computing unit 170 may be integrated in one device, or may be distributed in two different devices. For example, the first device including the classical computing unit 160 runs a classical computer operating system, on which quantum application development tools and services are provided, and storage and network services required for quantum applications are also provided. The user develops a quantum program through the quantum application development tools and services thereon, and sends the quantum program to the second device including the quantum computing unit 170 through the network service thereon. The second device runs a quantum computer operating system, and parses and compiles the code of the quantum program into instructions that can be recognized and executed by the quantum processor 170. The quantum processor 170 implements the quantum algorithm corresponding to the quantum program according to the instructions.
[0051] The computing unit of the classical processor 161 in the classical computing unit 160 is based on CMOS transistors on a silicon chip. This computing unit is not restricted by time and coherence, that is, this computing unit is not restricted by the usage duration and is available at any time. In addition, in a silicon chip, the number of such computing units is also sufficient. Currently, the number of computing units in a classical processor 161 is in the thousands. The sufficiency of the number of computing units and the fixed computing logic that can be selected by CMOS transistors, such as AND logic. When performing operations with CMOS transistors, a large number of CMOS transistors are combined with limited logic functions to achieve the operation effect.
[0052] The basic computing unit of the quantum processor 171 in the quantum computing unit 170 is a qubit. The input of a qubit is restricted by coherence and also by the coherence time, that is, a qubit is restricted by the usage duration and is not available at any time. Making full use of qubits within their available usage duration is a key problem in quantum computing. In addition, the number of qubits in a quantum computer is one of the representative indicators of the performance of a quantum computer. Each qubit realizes its computing function through logic functions configured as needed. Given the limited number of qubits, while the logic functions in the field of quantum computing are diverse, such as Hadamard gate (H gate), Pauli-X gate (X gate), Pauli-Y gate (Y gate), Pauli-Z gate (Z gate), X gate, RY gate, RZ gate, CNOT gate, CR gate, iSWAP gate, Toffoli gate, etc. When performing quantum computing, it is necessary to combine a limited number of qubits with diverse combinations of logic functions to achieve the operation effect.
[0053] Based on these differences, the design of classical logic functions acting on CMOS transistors and the design of quantum logic functions acting on qubits are significantly and essentially different; the design of classical logic functions acting on CMOS transistors does not need to consider the individuality of CMOS transistors, such as the individual identification of which CMOS transistor it is in the silicon chip, its position, and the available usage duration of each CMOS transistor. Therefore, the classical algorithms composed of classical logic functions only express the operation relationship of the algorithm and do not express the dependence of the algorithm on the individual CMOS transistors.
[0054] However, the quantum logic functions acting on qubits need to consider the individuality of qubits, such as the individual identification of which qubit it is in the quantum chip, its position, the relationship with surrounding qubits, and the available usage duration of each qubit. Therefore, the quantum algorithms composed of quantum logic functions not only express the operation relationship of the algorithm but also express the dependence of the algorithm on the individual qubits.
[0055] Exemplary:
[0056] Quantum algorithm one: H1, H2, CNOT(1,3), H3, CNOT(2,3);
[0057] Quantum algorithm two: H1, H2, CNOT(1,2), H3, CNOT(2,3);
[0058] Quantum algorithm one and quantum algorithm two use the method of adding Arabic numerals to quantum logic gates to represent the qubits on which the quantum logic gates act. The Arabic numerals 1, 2, and 3 among them can represent three sequentially connected qubits Q1, Q2, Q3 or interconnected qubits Q1, Q2, Q3;
[0059] An exemplary explanation of the influence of quantum algorithms on the coherence time of qubits is as follows:
[0060] Define the execution duration of a single-qubit logic gate as t, and the execution time of 1 two-qubit logic gate acting on adjacent qubits as 2t; then:
[0061] When Q1, Q2, and Q3 are interconnected with each other, the calculation of quantum algorithm one requires 6t and is carried out in 4 time periods. The duration required for each time period is t, 2t, t, 2t respectively. The operations executed within each time period are: H1, H2; CNOT(1,3); H3; CNOT(2,3);
[0062] The calculation of quantum algorithm one requires 5t and is carried out in 3 time periods. The duration required for each time period is t, 2t, 2t respectively. The operations executed within each time period are: H1, H2, H3; CNOT(1,2); CNOT(2,3);
[0063] When Q1, Q2, and Q3 are sequentially connected, quantum algorithm one needs to be equivalent to: H1, H2; swap(1,2), CNOT(2,3), swap(1,2); H3; CNOT(2,3); The calculation of the equivalent quantum algorithm one requires 10t and is divided into 4 time periods. The duration required for each time period is t, 6t, t, 2t respectively. The operations executed within each time period are: H1, H2; swap(1,2), CNOT(2,3), swap(1,2); H3; CNOT(2,3).
[0064] Therefore, the quantum logic function acting on the design of qubits (including the design of whether to use qubits and the design of the usage efficiency of each qubit) is the key to improving the computing performance of quantum computers and requires special design. This is also the uniqueness of quantum algorithms based on quantum logic functions, which is essentially and significantly different from classical algorithms based on classical logic functions. The above-mentioned design for qubits is a technical problem that ordinary computing devices do not need to consider and do not need to face. The present invention proposes an elliptic curve point addition operator, a ciphertext decryption method and related devices to implement the elliptic curve point addition operation on the binary field.
[0065] An embodiment of the present invention provides an elliptic curve point addition operator on the binary field, and the elliptic curve includes denotes the binary field, and the point addition operator includes: a first operation module and a second operation module;
[0066] Among them, the first operation module is used to calculate the slope λ of the line connecting two points to be added on the elliptic curve;
[0067] The second operation module is used to calculate the point addition operation result of two points to be added on the elliptic curve according to the slope λ.
[0068] In the embodiment of the present invention, the elliptic curve on the binary field may include:
[0069]
[0070] Optionally, the elliptic curve on the binary may further include:
[0071]
[0072] Among them, denotes the binary field.
[0073] Finite fields are an important basic work in cryptography. For example, the Diffie-Hellman cryptographic algorithm over finite fields, the elliptic curve cryptosystem over finite fields, and the application of the tower of binary fields in block ciphers, etc. Finite fields are generally divided into prime fields F p (where p is a very large prime number) and binary extensions The following briefly introduces a representation method of binary extensions:
[0074] Let F 2 [x] be the polynomial ring defined over F 2 , and its elements are polynomials f(x) = a n x n + a n-1 x n-1 + … + a 1x + a 0 。Furthermore, the binary extension field F 2n = F 2 [x] / <m(x)>, where m(x) is an irreducible polynomial over F 2 [x], and the degree of m(x) is n (i.e., deg(m(x)) = n). Generally, the binary extension field is represented as:
[0075]
[0076] where a i = 0 or 1, i ∈ {0, 1, …, n - 1}.
[0077] Here, can be regarded as an n-dimensional vector space defined over F 2 . Select {1, x, x 2 , …, x n-1} as a basis for . This basis is also called the polynomial basis. Thus, an element g(x) in can be represented by a vector, i.e.:
[0078] The polynomial g(x) = a n-1 x n-1 + a n-2 x n-2 + … + a 1 x + a 0 can be represented by the vector , where a i = 0 or 1, i = 0, 1, …, n - 1.
[0079] It should be noted that there are two ways to express the binary field: or These two expressions are equivalent.
[0080] Elliptic curves are a very special type of algebraic curve. The addition on an elliptic curve is not the ordinary numerical addition but a special geometric operation. In elliptic curve cryptography, the points on an elliptic curve are combined, and this combination follows specific rules, called "point addition operation on an elliptic curve".
[0081] Specifically, the rules of the point addition operation on an elliptic curve are as follows:
[0082] Rule 1: Calculate the point addition operation of two points A and B on the elliptic curve. If A and B are not the same point and neither A nor B is the infinite point O, then connect points A and B to form a straight line. This straight line will intersect the elliptic curve at a third point G. Then draw a straight line perpendicular to the x-axis through point G, which will intersect the elliptic curve at another point R (generally, points G and R are symmetric about the x-axis). Point R is defined as the result of A + B, that is, A + B = R. This operation process is called the general point addition operation of the elliptic curve.
[0083] Rule 2: If A and B are the same point, then determine the tangent line of the elliptic curve at point A. This tangent line will intersect the elliptic curve at point G. Then draw a straight line perpendicular to the x-axis through point G, which will intersect the elliptic curve at another point R (generally, it is a point symmetric about the x-axis). Point R is defined as the result of doubling point A, that is, 2A = R. This operation process is called the double point operation of the elliptic curve.
[0084] Rule 3: If A and B are on the same vertical line, then the result of the point addition operation of A and B is defined as the "infinite point" denoted as O. The infinite point does not exist on the elliptic curve, but it plays a special role in elliptic curve cryptography. For any point D on the elliptic curve, there is D + O = D.
[0085] As Figure 2 shown, Figure 2 is a schematic diagram of the point addition operation of the elliptic curve. For the two points to be added on the elliptic curve shown in Figure 2 are P 1 and P 2 . Connecting the values of these two points intersects the elliptic curve at another point P' 3 . Then the point P' 3 's symmetric point P 3 about the X-axis is the result of the point addition operation.
[0086] Suppose on the elliptic curve shown in Figure 2 , the coordinates of P 1 are (x 1 , y 1 ), the coordinates of P 2 are (x 2 , y 2 ). The result of the point addition operation of P 1 and P 2 is P 3 . The coordinates of P 3 are (x 3 , y 3 ). Then the coordinates of the point addition operation result P 3 can be determined according to the following formula:
[0087] When x 1 ≠ x 2 , x3 = λ 2 + λ + x 1 + x 2 + a, y 3 = (x 2 + x 3 ) * λ + x 3 + y 2 , where λ = (y 1 + y 2 ) / (x 1 + x 2 );
[0088] When x 1 = x 2 , x 3 = λ 2 + λ + x 1 + x 2 + a, where λ = x 1 + y 1 / x 1 .
[0089] It can be seen that when calculating the point addition result P 1 and point P 2 on the elliptic curve, the coordinates (x 3 , y 3 ) of P 3 depend on the slope λ of the line connecting P 1 and P 2 . Therefore, the embodiment of the present invention constructs an elliptic curve point addition calculator including a first operation module and a second operation module. Among them, the first operation module is used to calculate the slope λ of the two points to be added on the elliptic curve, and the second operation module is used to calculate the point addition result based on the slope λ. The elliptic curve point addition calculator provided by the embodiment of the present invention realizes the point addition operation of the elliptic curve over the binary field through quantum computing, providing technical support for accelerating key cracking.
[0090] In another embodiment of the present invention, the above-mentioned first operation module includes a first constant addition sub-module, a first modular inverse sub-module, and a first modular multiplication sub-module. The first operation module acts on a first register and a second register; the first register is used to obtain the quantum state |x 1 > corresponding to the abscissa x 1 of one of the points to be added, and the second register is used to obtain the quantum state |y 1 > corresponding to the ordinate y 1 of the one of the points to be added;
[0091] Among them, the first constant addition sub-module acts on the first register and the second register, so that the quantum state of the first register changes from |x1 evolves into |x 1 +x 2 >, the quantum state of the second register evolves from |y 1 > to |y 1 +y 2 >, where (x 2 , y 2 ) is another point to be added on the elliptic curve;
[0092] The first modular inverse sub-module acts on the first register and the auxiliary register, so that the quantum state of the auxiliary register evolves from |0> to |(x 1 +x 2 ) -1 mod m>, where m is an n-th degree irreducible polynomial over the binary field .
[0093] The first modular multiplier sub-module acts on the second register, the third register and the auxiliary register, so that the quantum state of the third register evolves from |0> to |λ> = |(y 1 +y 2 ) * (x 1 +x 2 ) -1 mod m>.
[0094] According to the definition of the binary field in the above embodiments, each element in the binary field is a binary array of {0, 1}. Therefore, the abscissa and ordinate of the points on the elliptic curve in the embodiments of the present invention can form a two-dimensional array, and both the abscissa and ordinate are binary arrays of {0, 1}. In the first register and the second register, one can encode the abscissa x 1 of one of the points to be added to the quantum bits in the first register and the ordinate y 1 to the quantum bits in the second register in the order from the high bit to the low bit of the array. The encoding method can be basis encoding, angle encoding, amplitude encoding, etc., and the embodiments of the present invention do not make specific limitations.
[0095] In the binary field, the definitions of addition and subtraction are as follows:
[0096] Addition: For any two elements a and b, perform a bitwise exclusive OR operation on their binary representations, and the result obtained is their sum. That is
[0097] Subtraction: For any two elements a and b, perform a bitwise exclusive OR operation on their binary representations, and the result obtained is their difference. That is
[0098] That is to say, in the binary field, the results of addition and subtraction are the same because the XOR operation is reversible.
[0099] Therefore, in the embodiment of the present invention, the first constant addition sub-module acts on the first register and the second register, evolving the quantum state of the first register from |x 1 > to |x 1 +x 2 >, and evolving the quantum state of the second register |y 1 > to |y 1 +y 2 >. This is equivalent to obtaining the calculation results of x 1 -x 2 , y 1 -y 2 .
[0100] Furthermore, by the action of the first modular inverse sub-module on the first register and the auxiliary register, the quantum state of the auxiliary register evolves from |0> to |(x 1 +x 2 ) -1 mod m>;
[0101] The first modular multiplication sub-module acts on the second register, the third register, and the auxiliary register, causing the quantum state of the third register to evolve from |0> to |λ> = |(y 1 +y 2 )*(x 1 +x 2 ) -1 mod m>. Thus, the slope λ of the line connecting the two points to be added on the elliptic curve can be obtained.
[0102] λ = (y 1 +y 2 )*(x 1 +x 2 ) -1 mod m = (y 1 -y 2 )*(x 1 -x 2 ) -1 mod m.
[0103] In another embodiment of the present invention, after the above first operation module calculates the slope λ, the above second operation module acts on the first register, the second register, and the auxiliary register to evolve the quantum state of the first register from |x 1 +x 2 > to |x 3 > = |λ 2 +λ+x 1 +x 2+a>, evolve the quantum state of the second register from |y 1 +y 2 > to |y 3 > = |(x 2 +x 3 ) * λ + x 3 +y 2 >, where (x 3 , y 3 ) is the result of the dot addition operation.
[0104] Optionally, the second operation module includes a second modular multiplier module and a first modular squarer module. The second modular multiplier module acts on the first register, the second register, and the third register to perform a modular multiplication operation on the first register and the third register, and implement the operation between the quantum state |y 1 +y 2 > of the second register and the modular multiplication result, so that the quantum state of the second register evolves to |0>.
[0105] Specifically, the quantum state of the first register is |x 1 +x 2 >, the quantum state of the second register is |y 1 +y 2 >, and the quantum state of the third register is |λ> = |(y 1 +y 2 ) * (x 1 +x 2 ) -1 mod m>.
[0106] Therefore, the modular multiplication operation of the first register and the third register is |y 1 +y 2 . Performing an operation on this modular multiplication result and the quantum state |y 1 +y 2 > of the second register can evolve the quantum state of the second register to |0>.
[0107] The first modular squarer module acts on the third register to implement storing the modular square operation result |λ 2 > into the second register, and evolving the quantum state of the second register from |0> to |λ 2 .
[0108] Specifically, the quantum state of the third register is |λ> = |(y 1 +y 2 ) * (x 1 +x 2 ) -1mod m>, the quantum state of the second register is |0>, the modular square sub-module acts on the third register, and the modular square operation result is |λ 2 >, store the modular square operation result in the second register, and the quantum state of the second register is |λ 2 >.
[0109] Optionally, the second operation module may further include a second constant sub-addition module, and the second constant addition sub-module acts on the first register to change the quantum state |x 1 +x 2 > of the first register into |x 1 +a>.
[0110] According to the introduction of addition and subtraction in the binary field in the above embodiments, it can be known that the second constant addition sub-module adds x 2 and a to the first register to obtain |x 1 +a>.
[0111] Optionally, the second operation module may further include a first CNOT gate and a second CNOT gate. The control bit of the first CNOT gate is the third register, and the target bit is the first register, so that the quantum state of the first register changes from |x 1 +a> to |x 1 +a+λ>;
[0112] The control bit of the second CNOT gate is the second register, and the target bit is the first register, so that the quantum state of the first register changes from |x 1 +a+λ> to |x 1 +a+λ+λ 2 >.
[0113] Specifically, the control bit of the first CNOT gate is the third register, the quantum state of the third register is |λ> = |(y 1 +y 2 )*(x 1 +x 2 ) -1 mod m, the quantum state of the first register is |x 1 +a>, after the action of the first CNOT gate, the quantum state of the first register evolves into |x 1 +a+λ>.
[0114] The control bit of the second CNOT gate is the second register, the quantum state of the second register is |λ 2 】>, after the action of the second CNOT gate, the quantum state of the target bit first register can change from |x 1 +a+λ> to |x 1+a+λ+λ 2 >。
[0115] Optionally, the second operation module may further include a second modular squaring sub-module, which acts on the third register to perform modular squaring operation and implement the operation between the quantum state |λ 2 > of the second register and the result of the modular squaring operation, so that the quantum state of the second register evolves from |λ 2 > to |0>;
[0116] The second modular multiplier module is further configured to perform a modular multiplication operation on the first register and the third register, and store the result of the modular multiplication operation in the second register, so that the quantum state of the second register evolves from |0> to |(x 3 +x 2 )*λ>;
[0117] Specifically, the quantum state of the first register is |x 1 +a+λ+λ 2 >, according to the elliptic curve point addition operation calculation formula in the above embodiment: x 3 =λ 2 +λ+x 1 +x 2 +a and the definitions of addition and subtraction in the binary field, it can be known that: |x 3 +x 2 > = |x 1 +a+λ+λ 2 .
[0118] The quantum state of the third register is |λ>. After the modular multiplication operation is performed by the second modular multiplier module, the result of the modular multiplication operation is stored in the second register with the quantum state of |0>. The quantum state of the second register is |(x 3 +x 2 )*λ>.
[0119] The second constant addition sub-module also acts on the first register, so that the quantum state of the first register evolves from |x 1 +a+λ+λ 2 > to |x 3 > = |λ 2 +λ+x 1 +x 2 +a>.
[0120] Specifically, according to the binary field addition and subtraction introduced in the above embodiment, the second constant addition sub-module can add x 2 to the first register, so that the quantum state of the first register evolves from |x 1 +a+λ+λ2 to x3 = λ2+λ+x1+x2+a.
[0121] Optionally, the second operation module may further include a third CNOT gate, where the control bit of the third CNOT gate is the first register and the target bit is the second register, such that the quantum state of the second register evolves from |(x 3 +x 2 )*λ> to |(x 3 +x 2 )*λ+x 3 >;
[0122] The second constant addition sub-module also acts on the second register, such that the quantum state of the second register evolves from |(x 3 +x 2 )*λ+x 3 > to |y 3 > = |(x 3 +x 2 )*λ+x 3 +y 2 >.
[0123] For the specific implementation manners of the first modular square sub-module and the second modular square sub-module in the embodiments of the present invention, reference may be made to the Chinese patent documents with the application numbers 202311277423.3 or 202311435305.0.
[0124] The first modular multiplier module and the second modular multiplier module are both implemented based on the Karatsuba algorithm, which is a fast multiplication algorithm. For the specific implementation manners of the first modular multiplier module and the second modular multiplier module, reference may be made to the Chinese patent document with the application number 202311489922.9.
[0125] The first modular inverse sub-module and the second modular inverse sub-module are both implemented based on Fermat's little theorem. For the specific implementation manner, reference may be made to the Chinese patent document with the application number 202311377525.2. In the embodiments of the present invention, the auxiliary register is used to store multiple intermediate operation results during the modular inverse operation of the first modular inverse sub-module and the second modular inverse sub-module. The auxiliary register is composed of s auxiliary sub-registers, and s = max{k 1 +t-1,k 1 +1}, where k 1 is obtained through the following calculation method:
[0126] Expand n-1 in binary to obtain [k 1 ,k 2 ,…,k t , where that is, k t is the result of rounding down log 2 (n-1), and n is the number of terms of the polynomial in the binary field .
[0127] In addition, in the embodiments of the present invention, the abscissa of the finally obtained point addition operation result P 3 is stored in the first register, and the ordinate is stored in the second register. In order to make the auxiliary register and the third register reusable, it is also necessary to reset the quantum states of the auxiliary register and the third register to |0>.
[0128] Specifically, as can be seen from the above embodiments, if the quantum state of the auxiliary register is |(x 1 +x 2 ) -1 mod m>, then in the above embodiments, when the quantum state of the first register is |x 1 +x 2 >, the modular inverse operation result can be stored in the auxiliary register by the action of the second modular inverse sub-module on the first register, so that the quantum state of the auxiliary register is reset to |0>.
[0129] Similarly, if the quantum state of the third register is |λ>, when the quantum state of the first register is |x 3 +x 2 >, and the quantum state of the second register is |(x 3 +x 2 )*λ>, the quantum state of the third register can be evolved to |λ+(x 3 +x 2 )*λ / (x 3 +x 2 )> = |0> through the modular addition and modular division operations.
[0130] As Figure 3 shown, Figure 3 FIG. is a schematic diagram of an elliptic curve point addition calculator provided by an embodiment of the present invention, Figure 3 showing a first register for obtaining the quantum state |x 1 corresponding to the abscissa x 1 of the point P to be point-added, a second register for obtaining the quantum state |y 1 corresponding to the ordinate y 2 of the point P to be point-added, a third register for loading the slope λ of the line connecting the two points to be point-added, and the auxiliary register is composed of s auxiliary sub-registers |aux> 1 to |aux> 1 . 1 to |aux> s .
[0131] Figure 3The elliptic curve point addition calculator shown includes multiple sub-modules and CNOT gates. The operation sequence of each sub-module is from left to right in turn. Next, in combination with Figure 3 the process of performing point addition operation on the elliptic curve point addition calculator will be described.
[0132] Figure 3 The point addition calculator shown includes a first operation module and a second operation module. Among them, +x 2 and +y 2 mean that the first constant addition sub-module acts on the first register and the second register, evolving the quantum state of the first register from |x 1 > to |x 1 +x 2 >, evolving the quantum state of the second register from |y 1 > to |y 1 +y 2 . FLT-Inv represents the first modular inverse sub-module. The first modular inverse sub-module FLT-Inv acts on the first register and s auxiliary sub-registers (|aux> 1 to |aux> s ) to perform a modular inverse operation. The modular inverse operation result |(x 1 +x 2 ) -1 mod m> is stored in the auxiliary sub-register |aux> s .
[0133] Mul represents the first modular multiplication sub-module. The first modular multiplication sub-module Mul acts on the second register and the auxiliary sub-register |aux> s , performs a modular multiplication operation. The modular multiplication operation result |λ> = |(y 1 +y 2 )*(x 1 +x2-1 mod m is stored in the third register. So far Figure 3 the first operation module in calculates the slope λ of the line connecting the two points to be added.
[0134] In the second operation module, Mul represents the second modular multiplication sub-module, FLT-Inv represents the second modular inverse sub-module, +x 2 +a, +x 2 and +y 2 are the second constant addition sub-module, and Div is the modular addition and modular division sub-module.
[0135] The second modular multiplication sub-module Mul acts on the first register, the second register and the third register to perform an operation on the first register |x 1 +x 2 > and the third register |(y 1 +y 2)*(x 1 +x 2 ) -1 perform a modular multiplication operation modulo m and implement the quantum state |y 1 +y 2 > of the second register with the result of the modular multiplication operation, such that the quantum state of the second register evolves to |0>.
[0136] sqr represents the first modular squaring sub-module and the second modular squaring sub-module. The first modular squaring sub-module acts on the third register to implement storing the result of the modular squaring operation |λ 2 > in the second register and evolving the quantum state of the second register from |0> to |λ 2 >.
[0137] The second modular inverse sub-module FLT-Inv acts on s auxiliary sub-registers (|aux> 1 to |aux> s ) to perform a modular inverse operation, and stores the result of the modular inverse operation |(x 1 +x 2 ) -1 mod m> in the auxiliary sub-register |aux> s such that the quantum state of the auxiliary register is reset to |0>.
[0138] The second constant addition sub-module +x 2 +a acts on the first register, evolving the quantum state |x 1 +x 2 > of the first register to |x 1 +a>.
[0139] The control qubit of the first CNOT gate is the third register, and the target qubit is the first register, such that the quantum state of the first register evolves from |x 1 +a> to |x 1 +a+λ>;
[0140] The control qubit of the second CNOT gate is the second register, and the target qubit is the first register, such that the quantum state of the first register evolves from |x 1 +a+λ> to |x 1 +a+λ+λ 2 >.
[0141] The second modular squaring sub-module Sqr acts on the third register to perform a modular squaring operation and implement the operation of the quantum state |λ 2 > of the second register with the result of the modular squaring operation, such that the quantum state of the second register evolves from |λ 2 > to |0>.
[0142] The second modular multiplication sub-module Mul is also used to perform a modular multiplication operation on the first register and the third register, and store the modular multiplication operation result in the second register, so that the quantum state of the second register evolves from |0> to |(x 3 +x 2 )*λ>.
[0143] The modular addition and modular division sub-module Div acts on the first register, the second register, the third register and the auxiliary register, and evolves the quantum state of the third register to |λ+(x 3 +x 2 )*λ / (x 3 +x 2 )> = |0, and then through the action of the second modular inverse sub-module on the first register and the auxiliary register, the modular division result stored in the auxiliary register by the modular addition and modular division sub-module is calculated, so that the quantum state of the auxiliary sub-register |aux> s is reset to |0>.
[0144] The second constant addition sub-module +x 2 also acts on the first register, so that the quantum state of the first register evolves from |x 1 +a+λ+λ 2 > to |x 3 > = |λ 2 +λ+x 1 +x 2 +a.
[0145] The control bit of the third CNOT gate is the first register, and the target bit is the second register, so that the quantum state of the second register evolves from |(x 3 +x 2 )*λ> to |(x 3 +x 2 )*λ+x 3 >.
[0146] The second constant addition sub-module also acts on the second register, so that the quantum state of the second register evolves from |(x 3 +x 2 )*λ+x 3 > to |y 3 > = |(x 3 +x 2 )*λ+x 3 +y2>.
[0147] An embodiment of the present invention also provides a ciphertext decryption method, as Figure 4 shown, the method includes:
[0148] S401. Obtain the public key and the base point of the ciphertext to be decrypted.
[0149] Among them, the ciphertext to be decrypted is an Elliptic Curve Cryptography (ECC) ciphertext, and the security of the ECC ciphertext is mainly based on the Elliptic Curve Discrete Logarithm Problem (ECDLP).
[0150] The ECDLP is defined as follows: Given a prime number p and an elliptic curve E, for Q = kP, find the positive integer k less than p when P and Q are known. It can be proved that it is relatively easy to calculate Q from k and P, while it is relatively difficult to calculate k from Q and P.
[0151] In a specific encryption scenario, P is usually called the base point, Q is called the public key, and k is called the private key, which is also called the discrete logarithm.
[0152] S402. Construct a quantum decryption circuit based on a control bit and 2n + 2 cascaded elliptic curve point addition operators. The control bit is used to control the first n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the base point, and control the last n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the public key.
[0153] Regarding the elliptic curve point addition operator over a binary field, reference can be made to the relevant descriptions in the above embodiments, which will not be elaborated here.
[0154] S403. Run the quantum decryption circuit. For each elliptic curve point addition operator, after the control bit controls the current elliptic curve point addition operator to perform a point addition operation, measure the quantum state of the control bit, and set the quantum state of the control bit to the zero state to control the next elliptic curve point addition operator to perform a point addition operation, obtaining a measurement result sequence.
[0155] In the embodiments of the present invention, after measuring the quantum state of the control bit, the measurement result is 1 or 0. After each time the control bit controls the elliptic curve point addition operator to perform a point addition operation, measure the quantum state of the control bit to obtain a measurement result sequence, and this measurement result sequence is a series of binary numbers composed of 0 or 1.
[0156] Among them, the measurement result sequence includes a first result sequence and a second result sequence. The first result sequence is the quantum state measurement result sequence after the control bit controls n + 1 elliptic curve point addition operators to perform point addition operations on the base point, and the second result sequence is the quantum state measurement result sequence after the control bit controls n + 1 elliptic curve point addition operators to perform point addition operations on the public key.
[0157] In the embodiments of the present invention, the single measurement result of the quantum state of the control bit is 0 or 1, so the measurement result sequence can be expressed as {ml} 0≤l≤2n+1 , m l = 0 or 1, that is, the measurement result sequence is a binary number composed of 0 and 1. Then the first result sequence composed of the first n + 1 measurement results can be expressed as {m l} 0≤l≤n , and the second result sequence composed of the last n + 1 measurement results can be expressed as {m l} n+1≤l≤2n+1 .
[0158] As Figure 5 shown, Figure 5 FIG. is a schematic structural diagram of a quantum decryption circuit provided by an embodiment of the present invention. Figure 5 In the quantum decryption circuit shown, it includes a control qubit with an initial quantum state of the zero state. The first H gate, the phase rotation logic gate, and the second H gate act on the control qubit in sequence. However, when the control qubit controls the first elliptic curve point addition operator, only the first H gate and the second H gate act on the control qubit. The control qubit controls 2n + 2 cascaded elliptic curve point addition operators to perform point addition operations. Among them, the parameters of the first n + 1 elliptic curve point addition operators are P, 2P, 2 2 P... 2 n P, and the parameters of the last n + 1 elliptic curve point addition operators are Q, 2Q, 2 2 Q... 2 n Q, where P is the base point of the ciphertext to be decrypted, and Q is the public key of the ciphertext to be decrypted.
[0159] In Figure 5 , except that the control qubit controls the first elliptic curve point addition operator, after the first H gate acts on the control qubit, the control qubit controls the elliptic curve point addition operator to perform point addition operations, then the phase rotation logic gate and the second H gate act on the control qubit, and subsequently the quantum state of the control qubit is measured to obtain a measurement result, where the measurement result is 0 or 1. The control operation of the control qubit on the elliptic curve point addition operator will affect the measurement result, that is, the measurement operation after quantum entanglement is a disentanglement process. Therefore, the measurement result μ i is 0 or 1.
[0160] In the above embodiment, the parameter of the phase rotation logic gate R i acting on the controlled qubit currently is determined according to the measurement result of the quantum state of the control qubit last time.
[0161] Specifically, the matrix form of the phase rotation logic gate R K is:[[]]
[0162]
[0163] The parameter θ kCalculated according to the following formula:
[0164]
[0165] where k represents the k-th action of the phase rotation logic gate on the control bit, and m j represents the measurement result obtained by measuring the control bit for the j-th time.
[0166] S404. Solve the private key of the ciphertext to be decrypted according to the measurement result sequence, and decrypt the ciphertext to be decrypted.
[0167] Specifically, it can be implemented as follows:
[0168] Step 1. Convert the first result sequence and the second result sequence into decimal numbers respectively.
[0169] Specifically, convert the first result sequence {m l} 0≤l≤n into a decimal number M 0 , and convert the second result sequence into a decimal number M 1 .
[0170] Step 2. Perform continued fraction expansion on the quotient of the decimal number corresponding to the first result sequence and 2 n+1 , and perform continued fraction expansion on the quotient of the decimal number corresponding to the second result sequence and 2 n+1 .
[0171] Step 3. Divide the obtained expansion results to obtain the private key of the ciphertext to be decrypted, and decrypt the ciphertext to be decrypted according to the private key.
[0172] Perform and to perform continued fraction expansion, and perform integer division on the obtained expansion results to obtain the discrete logarithm d. The discrete logarithm d is the private key of the ciphertext to be decrypted.
[0173] Adopting the above technical solution, a quantum decryption circuit is constructed based on multiple cascaded elliptic curve point adder and control bits. Running this quantum decryption circuit can perform point addition operations on the base point and public key of the ciphertext to be decrypted. Furthermore, by measuring the quantum state of the control bit, a measurement result sequence is obtained, and the ciphertext to be decrypted is decrypted based on the measurement result sequence, realizing the decryption of the ciphertext without a private key.
[0174] Based on the same inventive concept, an embodiment of the present invention also provides a ciphertext decryption device, as Figure 6 shown. This device includes:
[0175] An acquisition module 601, configured to acquire the public key and base point of the ciphertext to be decrypted;
[0176] A building block 602, configured to build a quantum decryption circuit based on a control bit and 2n + 2 cascaded elliptic curve point addition operators as described in the above embodiments, where the control bit is used to control the first n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the base point, and control the last n + 1 elliptic curve point addition operators to perform n + 1 point addition operations on the public key;
[0177] An operation module 603, configured to run the quantum decryption circuit. For each elliptic curve point addition operator, after the control bit controls the current elliptic curve point addition operator to perform a point addition operation, measure the quantum state of the control bit, and set the quantum state of the control bit to the zero state for controlling the next elliptic curve point addition operator to perform a point addition operation, so as to obtain a measurement result sequence;
[0178] A decryption module 604, configured to solve the private key of the ciphertext to be decrypted according to the measurement result sequence and decrypt the ciphertext to be decrypted.
[0179] Regarding the specific functions and effects achieved by the ciphertext decryption device, reference may be made to other embodiments of this specification for comparison and explanation, which will not be elaborated here. Each module in the ciphertext decryption device can be implemented in whole or in part by software, hardware, and their combination. The various modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above various modules.
[0180] Please refer to Figure 7 ... This embodiment of the specification also provides a computer device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the ciphertext decryption method in any of the above embodiments. Please refer to Figure 7 ... The computer device can be a classical computer. The computer device can also be a quantum computer.
[0181] This embodiment of the specification also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by the computer, the computer executes the ciphertext decryption method in any of the above embodiments.
[0182] This embodiment of the specification also provides a computer program product including instructions. When the instructions are executed by the computer, the computer executes the ciphertext decryption method in any of the above embodiments.
[0183] It can be understood that the specific examples in this specification are only for helping those skilled in the art better understand the embodiments of this specification, rather than limiting the scope of the present invention.
[0184] It should be understood that in the various embodiments described in this specification, the magnitudes of the serial numbers of the various processes do not imply the order of execution, and the order of execution of the various processes should be determined by their functions and internal logics, and should not constitute any limitation to the implementation processes of the embodiments of this specification.
[0185] It should be understood that the various embodiments described in this specification can be implemented alone or in combination, and the embodiments of this specification do not limit this.
[0186] Unless otherwise specified, all technical and scientific terms used in the embodiments of this specification have the same meanings as those commonly understood by those skilled in the technical field of this specification. The terms used in this specification are only for the purpose of describing specific embodiments, and are not intended to limit the scope of this specification. The term "and / or" used in this specification includes any and all combinations of one or more of the related listed items. The singular forms of "a", "above-mentioned", and "the" used in the embodiments of this specification and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0187] It should be understood that the processor in the embodiments of this specification can be an integrated circuit chip with the ability to process signals. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit in the hardware of the processor or the instructions in the form of software. The above-mentioned processor can be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of this specification. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of this specification can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0188] It can be understood that the memory in the embodiments of this specification can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0189] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or by a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this specification.
[0190] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0191] In the several embodiments provided in this specification, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0192] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0193] In addition, in each embodiment of this specification, each functional unit may be integrated into one processing unit, may exist physically alone for each unit, or two or more units may be integrated into one unit.
[0194] If the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this specification, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this specification. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0195] As described above, the above are only specific embodiments of this specification, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed in this specification can easily think of changes or substitutions, which should all be covered by the protection scope of this specification. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. An elliptic curve point addition operator over a binary field, the elliptic curve comprising represents a binary domain, characterized in that The point addition operator comprises: a first operation module and a second operation module; The first operation module is used to calculate the slope λ of the line connecting two points to be added on the elliptic curve; The second operation module is used to calculate the point addition operation result of two points to be added on the elliptic curve according to the slope λ.
2. The elliptic curve point addition operator according to claim 1, characterized in that: The first operation module includes a first constant addition submodule, a first module inversion submodule and a first module multiplication module, and the first operation module acts on a first register and a second register; the first register is used to obtain the quantum state |x1> corresponding to the horizontal coordinate x1 of one of the points to be added, and the second register is used to obtain the quantum state |y1> corresponding to the vertical coordinate y1 of one of the points to be added; The first constant addition submodule acts on the first register and the second register, so that the quantum state of the first register evolves from |x1> to |x1+x2>, and the quantum state of the second register evolves from |y1> to |y1+y2>, wherein (x2, y2) is another point to be added on the elliptic curve point; The first modulus inverse module acts on the first register and the auxiliary register, so that the quantum state of the auxiliary register evolves from |0> to |(x1+x2) -1 mod m>, m is a binary domain n-order irreducible polynomials on ; The first modular multiplier module acts on the second register, the third register and the auxiliary register, so that the quantum state of the third register evolves from |0> to |λ>=|(y1+y2)*(x1+x2) -1 mod m>.
3. The elliptic curve point addition operator according to claim 2, characterized in that: The second operation module acts on the first register, the second register and the auxiliary register, and is used to evolve the quantum state of the first register from |x1+x2> to |x3>=|λ 2 +λ+x1+x2+a>, the quantum state of the second register evolves from |y1+y2> to |y3>=|(x2+x3)*λ+x3+y2>, where (x3, y3) is the result of the point addition operation.
4. The elliptic curve point addition operator according to claim 3, characterized in that: The second operation module includes a second modular multiplier module and a first modular square submodule, the second modular multiplier module acts on the first register, the second register and the third register to perform modular multiplication operation on the first register and the third register, and realizes the operation of the quantum state |y1+y2> of the second register and the modular multiplication operation result, so that the quantum state of the second register evolves to |0>; The first modular square submodule acts on the third register to realize the modular square operation result |λ 2 >stored to the second register, and the quantum state of the second register is evolved from |0> to |λ 2 >.
5. The elliptic curve point addition operator according to claim 4, characterized in that: The second operation module also includes a second constant sub-addition module, which acts on the first register to evolve the quantum state |x1+x2> of the first register into |x1+a>.
6. The elliptic curve point addition operator according to claim 5, characterized in that: The second operation module further includes a first CNOT gate and a second CNOT gate, the control bit of the first CNOT gate is the third register, and the target bit is the first register, so that the quantum state of the first register evolves from |x1+a> to |x1+a+λ>; The control bit of the second CNOT gate is the second register, and the target bit is the first register, so that the quantum state of the first register evolves from |x1+a+λ> to |x1+a+λ+λ 2 >.
7. The elliptic curve point addition operator according to claim 6, characterized in that: The second operation module further includes a second modular square submodule, which acts on the third register to perform modular square operation and realize the quantum state |λ of the second register. 2 > and the result of the modular square operation, so that the quantum state of the second register is |λ 2 >evolves into |0>; The second modular multiplier module is further used to perform a modular multiplication operation on the first register and the third register, and store the modular multiplication result in the second register, so that the quantum state of the second register evolves from |0> to |(x3+x2)*λ>; The second constant addition submodule also acts on the first register, so that the quantum state of the first register is |x1+a+λ+λ 2 >evolves into |x3>=|λ 2 +λ+x1+x2+a>.
8. The elliptic curve point addition operator according to claim 7, characterized in that: The second operation module further includes a third CNOT gate, the control bit of the third CNOT gate is the first register, and the target bit is the second register, so that the quantum state of the second register evolves from |(x3+x2)*λ> to |(x3+x2)*λ+x3>; The second constant addition submodule also acts on the second register, so that the quantum state of the second register evolves from |(x3+x2)*λ+x3> to |y3>=|(x3+x2)*λ+x3+y2>.
9. A ciphertext decryption method, characterized in that: The method comprises: Get the public key and base point of the ciphertext to be decrypted; A quantum decryption circuit is constructed based on a control bit and 2n+2 cascaded elliptic curve point adders as described in any one of claims 1 to 8, wherein the control bit is used to control the first n+1 elliptic curve point adders to perform n+1 point addition operations on the base point, and control the last n+1 elliptic curve point adders to perform n+1 point addition operations on the public key; Running the quantum decryption circuit, for each elliptic curve point adder operator, after the control bit controls the current elliptic curve point adder operator to perform point addition operation, measuring the quantum state of the control bit, and setting the quantum state of the control bit to a zero state for controlling the next elliptic curve point adder operator to perform point addition operation, to obtain a measurement result sequence; A private key of the ciphertext to be decrypted is solved according to the measurement result sequence, and the ciphertext to be decrypted is decrypted.
10. A ciphertext decryption device, characterized in that: The device comprises: An acquisition module, used to obtain the public key and base point of the ciphertext to be decrypted; A construction module, for constructing a quantum decryption circuit based on a control bit and 2n+2 cascaded elliptic curve point adders as described in any one of claims 1 to 8, wherein the control bit is used to control the first n+1 elliptic curve point adders to perform n+1 point addition operations on the base point, and control the last n+1 elliptic curve point adders to perform n+1 point addition operations on the public key; An operation module is used to operate the quantum decryption circuit, for each elliptic curve point addition operator, after the control bit controls the current elliptic curve point addition operator to perform point addition operation, measure the quantum state of the control bit, and set the quantum state of the control bit to a zero state for controlling the next elliptic curve point addition operator to perform point addition operation, to obtain a measurement result sequence; The decryption module is used to solve the private key of the ciphertext to be decrypted according to the measurement result sequence, and decrypt the ciphertext to be decrypted.
11. A storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method according to claim 9 when executed.
12. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method of claim 9.
Citation Information
Patent Citations
Polynomial modular square arithmetic unit, arithmetic method and related device
CN117196053A
Polynomial modular inverse operator, polynomial modular inverse operation method and related device
CN117455001A
Polynomial modular square arithmetic unit, arithmetic method and related device
CN117521833A