Dynamic encryption communication security assessment method based on SAT
By encoding the basic operations of the packet cipher algorithm into SAT problems, using SAT automated search technology to solve the impossible differential divider and dynamically adjust the encryption strategy, the problem of complex calculation of existing password analysis methods is solved, and the security and evaluation efficiency of packet ciphers are improved.
Patent Information
- Application Number
- CN202510182327.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-23
AI Technical Summary
Existing cryptographic analysis methods are complex and time-consuming to calculate, making it difficult to quickly and accurately evaluate the security of cryptographic systems, especially when traditional packet cryptographic algorithms are facing potential attack threats.
Using the SAT-based dynamic encryption communication security evaluation method, by encoding the basic operations of the packet cipher algorithm into SAT problems, SAT automated search technology is used to solve the impossible differential divider, and dynamically adjust the encryption strategy to ensure the security of the packet cipher.
The length of the impossible differential divider and the solution efficiency of the differentializer are improved, and more detailed state differential changes in the impossible differential trajectory are obtained, real-time security evaluation and dynamic adjustment of packet passwords are realized, and the security of the communication system is strengthened.
Smart Images

Figure CN120034380A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a SAT-based dynamic encryption communication security assessment method. Background Art
[0002] In industries such as finance, healthcare, and government, data security requirements are becoming increasingly high. The most common encryption protocols, such as SSL / TLS, are usually based on block ciphers (such as AES, PRESENT, SKINNY, etc.) to ensure the security of data during transmission. However, with the improvement of computing power, traditional block cipher algorithms may face potential attack threats. To solve this problem, network security experts usually rely on cryptanalysis technology to evaluate the strength of encryption algorithms.
[0003] However, existing cryptanalysis methods (such as differential cryptanalysis, linear cryptanalysis, etc.) are usually computationally complex and time-consuming, making it difficult to quickly and accurately evaluate the security of cryptographic systems. SAT has important applications in impossible differential searches for block ciphers. It can be used to construct impossible differential distinguishers, search for the minimum guess basis for keys, and combine key bridging technology to reduce the complexity of key recovery. However, selecting an optimal distinguisher requires traversing all input differential and output differential values, and the excessively large search space makes it computationally infeasible. Currently, there are divide-and-conquer algorithms, two-dimensional impossible differential modeling methods based on MILP, etc., but the efficiency of solving impossible differential distinguishers still has certain problems, and impossible differential distinguishers with longer rounds cannot be obtained, which affects subsequent key recovery work. Summary of the invention
[0004] The purpose of the present invention is to provide a dynamic encryption communication security assessment method based on SAT, which can evaluate and dynamically adjust the encryption algorithm and key length parameters of the system in real time during the encryption communication process to ensure the security of the block cipher used in the encryption transmission process.
[0005] To achieve the above object, the present invention provides a SAT-based dynamic encryption communication security assessment method, comprising the following steps:
[0006] Step 1: Data input and preprocessing;
[0007] Step 2: Encrypt the data using a block cipher algorithm;
[0008] Step 3: Two-dimensional binary variable setting;
[0009] Step: 4: SAT encode the basic operations of block cipher E;
[0010] Step 5: Characterize the contradictory position and solve the SAT model;
[0011] Step 6: Dynamically adjust encryption strategy;
[0012] Step 7: Transmit the encrypted data.
[0013] Optionally, the execution process of step 2 includes the selection of an encryption algorithm and the selection of a block cipher operation mode, including the following two steps:
[0014] Step 2.1: Select the corresponding block cipher algorithm of SP-Network structure according to the requirements;
[0015] Step 2.2: Select CBC mode for encryption.
[0016] Optionally, the two-dimensional binary variable includes a differential value type variable and an active mode type variable, the differential value type variable is denoted as θx[i], and the value is (0,0) θx ,(0,1) θx ,(1,0) θx ,(1,1) θx , respectively, indicating that the difference value is 0, Δ 1 ,Δ 2 ,Δ 3 , where Δ 1 ≠Δ 2 ≠Δ 3 ≠0;
[0017] The active mode type variable is denoted as ρx[i], and its value is (0,0) ρx ,(0,1) ρx ,(1,0) ρx ,(1,1) ρx They represent four different differential modes: inactive, active, unknown, and active known.
[0018] Optionally, in step 4, the basic operations in the block cipher E are encoded using the CVC format specification in SAT, including the following operation items:
[0019] Linear permutation operation: Encoding is completed using the copy operation model in SAT;
[0020] S-box operation: SAT encoding is performed by state differential propagation according to the corresponding units;
[0021] Column confusion operation: First classify the column confusion operation and then perform SAT encoding according to the differential conversion table.
[0022] Optionally, in step 5, based on the Miss-In-Middle technique, a new variable μ_i is introduced to convert E A and E BEncoded as a complete R-round impossible difference distinguisher search model, it includes the following steps:
[0023] Step 5.1: SAT encoding of the contradictory positions;
[0024] Step 5.2: Solve the complete SAT discriminator;
[0025] Step 5.3: Traverse all conflicting positions;
[0026] Step 5.4: Eliminate redundant solutions.
[0027] Optionally, during the execution of step 5, the contradiction position is continuously changed to establish different SAT discriminator models, and the STP solver is used to solve the model. If the model has a solution, it is a valid impossible differential discriminator, and if there is no solution, it is not an impossible differential discriminator. Then, the repeated solutions in the solution obtained by the STP solver are removed, and the remaining solutions are all R-round impossible differential discriminators in the block cipher E.
[0028] Optionally, during the execution of step 6, security is evaluated based on the results of the impossible differential distinguisher search model analysis, and the encryption strategy is automatically adjusted, that is, the algorithm is switched and the key length is increased, and the encryption configuration is updated in real time.
[0029] The present invention provides a dynamic encryption communication security assessment method based on SAT, which uses the CVC format to characterize each operation of the block cipher algorithm, combines the algorithm of impossible differential two-dimensional modeling, improves the length of the impossible differential discriminator and the efficiency of the discriminator solution, and obtains a more detailed change of the state difference in the impossible differential trajectory. Specifically, through the SAT automated search technology, each operation component in the block cipher of the SP-Network structure is converted into a SAT problem, and the STP solver is used to solve and obtain a feasible solution, and then the encryption strategy is dynamically adjusted according to the feedback result of the security assessment module. It has been verified that the method of the present invention is universal for the SPN structure in the block cipher, and the discriminator round number obtained by the STP solver is longer and the discriminator solution efficiency is higher. The better impossible differential discriminator obtained by solving is applied to the security assessment module of the communication system, which enables the feedback and adjustment module of the system to dynamically adjust the cryptographic encryption algorithm according to the accurate security assessment result to achieve dynamic security assessment. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0031] Figure 1 It is a principle block diagram of a SAT-based dynamic encryption communication security assessment method of the present invention.
[0032] Figure 2 It is a schematic diagram of the block cipher CBC operation mode of the present invention.
[0033] Figure 3 It is an overall schematic diagram of the impossible differential discriminator search in the method of the present invention. DETAILED DESCRIPTION
[0034] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present invention, and should not be construed as limiting the present invention.
[0035] The following are definitions of the English abbreviations used in this invention:
[0036] SAT: Boolean Satisfiability Problem;
[0037] MILP: Mixed Integer Linear Programming;
[0038] STP: A solver for SAT problems.
[0039] CVC: Language specification under STP solver;
[0040] SP-Network: A block cipher structure that combines S-boxes and permutation operations;
[0041] Miss-In-Middle: missing in the middle;
[0042] CBC: Ciphertext block chaining working mode;
[0043] See also Figure 1 The present invention provides a SAT-based dynamic encryption communication security assessment method, comprising the following steps:
[0044] S1: Data input and preprocessing;
[0045] S2: Encrypt data using a block cipher algorithm;
[0046] S3: 2D binary variable setting;
[0047] S4: SAT encoding of the basic operations of block cipher E;
[0048] S5: Characterize the location of contradictions and solve the SAT model;
[0049] S6: Dynamically adjust encryption strategy;
[0050] S7: Transmit the encrypted data.
[0051] The core of the present invention converts the operation process of the block cipher algorithm E (such as S-box, P permutation, column confusion, etc. in the encryption process) into SAT (satisfiability problem). The discriminator is searched through a two-dimensional modeling algorithm based on SAT impossible differentials, and the obtained discriminator is used to track the change of state differentials. The SAT problem after the above conversion is solved using the STP solver (Satisfiability ModuloTheories Solver). The STP solver can efficiently process complex SAT problems and give whether there are potential security vulnerabilities. If there are vulnerabilities, the system will feedback to the security assessment module and provide suggestions or automatically adjust the encryption scheme according to the type of vulnerability.
[0052] The following is a further explanation based on the specific implementation steps:
[0053] Step S1: Data input and preprocessing
[0054] Prepare the data to be encrypted and ensure that the data meets the specifications before encryption. The specific steps include input data and data preprocessing.
[0055] Specific steps:
[0056] 1. Input data: The user or system inputs the data to be encrypted into the encryption module. The data can be the user's sensitive information, files, communication content, etc.
[0057] 2. Data preprocessing: Data preprocessing is divided into block processing, padding, and generating random initialization vectors. Data block processing means that if the input data exceeds the block size of the block cipher, the data needs to be divided into multiple blocks for encryption one by one. Padding means that for data that is less than one block, a standard padding algorithm (such as PKCS7 padding) is used to pad the data to the specified block size. Generating an initialization vector means that for certain block cipher operation modes, a random initialization vector (IV) needs to be generated to ensure that the encryption results of the same plaintext are different each time, thereby increasing the security of encryption.
[0058] Step S2: Encrypt data using a block cipher algorithm
[0059] Use block cipher algorithms to encrypt data to ensure that data cannot be stolen during transmission. This includes the selection of encryption algorithms and the selection of block cipher operation modes.
[0060] Specific steps:
[0061] 1. Select encryption algorithm: The system selects the corresponding SP-Network structure block cipher algorithm E according to the requirements. During the initial setting, you can choose the lightweight block cipher algorithm SKINNY-64.
[0062] 2. Encryption operation mode selection: The encryption operation mode defines how to use the encryption key and IV (initialization vector) to encrypt the data block. The present invention adopts the CBC mode. Because for the CBC mode, each data block needs to be XORed with the previous ciphertext block, which enhances the security of encryption.
[0063] See also Figure 2 , it adopts a CBC (cipher block chaining mode) operation mode, and uses the lightweight block cipher SKINNY-64 for encryption and decryption operations. It encrypts one plaintext block at a time, and uses the same key for each encryption. The input of the encryption algorithm is the XOR of the current plaintext block and the previous ciphertext block. Therefore, the input of the encryption algorithm will not show a fixed relationship with the plaintext block this time, so repeated plaintext blocks will not expose this repetitive relationship in the ciphertext. When decrypting, each ciphertext block is decrypted and then XORed with the previous ciphertext block. Among them, IV stands for initial vector, which should be known to both the sender and the receiver. In order to improve security, IV needs to be protected like the key. P 1 ,P 2 ,…,P N Represents plain text, C 1 ,C 2 ,…,C N represents the ciphertext, and K represents the key used.
[0064] Step S3: Two-dimensional binary variable setting
[0065] Assume that the block size of block cipher E is n-bit, n = c·d. Where c is the size of each unit in the block, and d is the number of units in each block. When searching for impossible differential distinguishers, it is necessary to divide the state differential into two types of variables: differential value type variables and active mode type variables.
[0066] Variable type I (differential value type variable):
[0067] where Δ 1 ≠Δ2 ≠Δ 3 ≠0,i∈[0,d-1].
[0068] Variable type II (active model type variable):
[0069] where i∈[0,d-1].
[0070] (0,0) ρx ,(0,1) ρx ,(1,0) ρx ,(1,1) ρx The specific meaning is that the differential mode at the unit position i is inactive, active, unknown, and active known.
[0071] Step S4: SAT encoding of the basic operations of block cipher E
[0072] For the block cipher E, before constructing the impossible differential distinguisher, it is necessary to encode the basic operations in E using the CVC format specification in SAT. This includes encoding the differential propagation rules for linear permutation, S-box, column confusion and other operations. Since the method of the present invention is modeled based on two-dimensional binary variables, it is also necessary to construct the corresponding state differential conversion table for some operations, and complete the SAT encoding of each operation according to the content of the conversion table. For linear permutation, SAT can be used for direct modeling, and for S-box and column confusion operations, it is necessary to combine the differential conversion table to assist in modeling.
[0073] Specific steps:
[0074] Linear permutation operation:
[0075] Linear permutation operations such as P permutation and circular shift are essentially simple position transformations. They can be encoded using the copy operation model in SAT without building a state differential conversion table to model. Let's assume that the values of the input differential and the output differential are and Where j∈{θx,ρx},i∈[0,d-1]. For example, given a P permutation, assuming that its corresponding permutation rule is P=[0,1,2,3,5,6,7,4,10,11,8,9,15,12,13,14], it can be encoded using the CVC format specification in SAT as:
[0076]
[0077] S-box operation:
[0078] Since the method of the present invention seeks the truncated trajectory, it is only necessary to perform state differential propagation and SAT encoding according to the corresponding unit for the S-box, and there is no need to establish a DDT (differential distribution table). The two-dimensional differential propagation mode corresponding to the operation of the S-box is divided into two cases, and it is necessary to combine the differential mode conversion table of the S-box to model it.
[0079] Case 1: Indicates the conversion from a differential value type variable to an active mode type variable. Its differential conversion table is represented by a two-dimensional array, Transition = [[0,0,0,0], [0,1,0,1], [1,0,0,1], [1,1,0,1]]. The specific explanation is that there are 4 differential propagation situations in this table, and the four points in each element are the values of the input differential and the output differential. According to the conversion table, use SAT to encode:
[0080]
[0081] Case 2: Indicates from active mode type variable to active mode type variable. Its differential transition table is represented by a two-dimensional array, Transition = [[0,0,0,0], [0,1,0,1], [1,0,1,0], [1,1,0,1]]. Similarly, SAT is used to encode the transition table:
[0082]
[0083] MC (column confusion operation):
[0084] For block cipher E, assuming that the matrix to be encoded is non-MDS, the input difference of the column confusion operation is (u 0 ,u 1 ,u 2 ,u 3 ), the output difference is (v 0 ,v 1 ,v 2 ,v 3 ), and both satisfy the following conditions: where i∈[0,3], is the coefficient of the corresponding confusion matrix. The value of , the MC operation in the present invention can be divided into 6 cases, and each case can be SAT encoded according to the differential conversion table.
[0085] Case 1: When When it represents the propagation from a differential value type variable to a differential value type variable, and its differential conversion table is represented in the form of a two-dimensional array, then Transition = [[0,0,0,0],[0,1,0,1],[1,0,1,0],[1,1,1,1]]. The SAT encoding is as follows:
[0086]
[0087] Case 2: When it represents the propagation from an active mode variable to an active mode variable, its differential conversion table is also represented in a two-dimensional array, Transition = [[0,0,0,0],[0,1,1,1],[1,0,1,1],[1,1,1,1]]. The SAT encoding is as follows:
[0088]
[0089]
[0090] Case 3: When it represents that the input difference is two differential value type variables and the output difference type is one active mode type variable, the two-dimensional array corresponding to the differential conversion table is Transition = [[0,0,0,0,0,0],[0,1,0,1,0,0],[1,0,1,0,0,0],[1,1,1,1,0,0],[0,0,0,1,1,1],[0,1,0,0,1,1],[0,0,1,0,1,1],[1,0,0,0,1,1],[0,0,1,1,1,1],[1,1,0,0,1,1],[0,1,1,0,0,1],[1,0,0,1,0,1],[0,1,1,1,0,1],[1,1,0,1,0,1],[1,0,1,1,0,1],[1,1,1,0,0,1]]. Since there are many propagation cases in the array, only the first four are written, and the remaining 12 cases are the same by analogy. The SAT encoding cases are as follows:
[0091]
[0092] Case 4: It means that the input difference is two active mode type variables, the output difference is also an active mode type variable, and the two-dimensional array corresponding to the differential transition table is Transition = [[0,0,0,0,0,0],[0,0,0,1,0,1],[0,1,0,0,0,1],[0,0,1,1,1,1],[1,1,0,0,1,1],[0,0,1,0,1,0]] ,[1,0,0,0,1,0],[1,0,1,0,1,0],[1,0,0,1,1,0],[0,1,1,0,1,0],[1,0,1,1,1,0],[1,1,1,0,1,0],[1,1,0,1,0],[0,1,1,1,1,0],[0,1,0,1,1,0],[1,1,1,1,1,0]]. Since there are many propagation situations in the array, only the first four are written out, and the remaining 12 are similar. The SAT encoding is as follows:
[0093]
[0094] Case 5: It means that the input difference is divided into three difference value type variables, the output is the active mode type variable, and the two-dimensional array corresponding to the difference transition table is Transition = [[0,0,0,0,0,0,0,0],[0,0,0,1,0,1,0,0],[0,1,0,0,0,1,0,0],[0,1,0,1,0,0,0,0],[0,0,1,0,1,0,0,0],[1,0,0,0,1,0,0,0],[1,0,1,0,0,0,0,0],[0,0,1,1,1,1,0,0], [1,1,0,0,1,1,0,0],[1,1,1,1,0,0,0,0],[0,0,0,0,0,1,1,1],[0,0,0,1,0,0,1,1],[0,1,0,0,0,0,1,1],[1,0,0,0,0,0,1,1],[0,0,0,0,1,0,1,1],[0,0,1,0,0,0,1,1],[0,0,1,0,0,0,1,1],[0,0,0,0,1,1,1],[1,1,0,0,0,0,1,1],
[0095] [0,1,1,0,1,1,1,0],[0,1,1,1,1,0,1,0],[1,0,0,1,1,1,1,0],
[0096] [1,0,1,1,0,1,1,0],[1,1,0,1,1,0,1,0],[1,1,1,0,0,1,1,0],
[0097] [0,1,0,1,0,1,1,1],[0,1,0,1,1,0,1,1],[0,1,0,1,1,1,1,1],
[0098] [0,1,1,0,0,1,1,1],[0,1,1,0,1,0,1,1],[0,1,1,1,0,1,1,1],
[0099] [0,1,1,1,1,1,1,1],[1,0,0,1,0,1,1,1],[1,0,0,1,1,0,1,1],
[0100] [1,0,1,0,0,1,1,1],[1,0,1,0,1,0,1,1],[1,0,1,0,1,1,1,1],
[0101] [1,0,1,1,1,0,1,1],[1,0,1,1,1,1,1,1],[1,1,0,1,0,1,1,1],
[0102] [1,1,0,1,1,1,1,1],[1,1,1,0,1,0,1,1],[1,1,1,0,1,1,1,1],
[0103] [1,1,1,1,0,1,1,1],[1,1,1,1,1,0,1,1],[1,1,1,1,1,1,1,1],
[0104] [0,0,0,1,1,0,0,1],[0,0,0,1,1,1,0,1],[0,0,1,0,0,1,0,1],
[0105] [0,0,1,0,1,1,0,1],[0,0,1,1,0,1,0,1],[0,0,1,1,1,0,0,1],
[0106] [0,1,0,0,1,0,0,1],[0,1,0,0,1,1,0,1],[0,1,1,0,0,0,0,1],
[0107] [0,1,1,1,0,0,0,1],[1,0,0,0,0,1,0,1],[1,0,0,0,1,1,0,1],
[0108] [1,0,0,1,0,0,0,1],[1,0,1,1,0,0,0,1],[1,1,0,0,0,1,0,1],
[0109] [1,1,0,0,1,0,0,1],[1,1,0,1,0,0,0,1],[1,1,1,0,0,0,0,1]]
[0110] Since there are many propagation situations in the array, only the first 4 are written out, and the remaining 60 are similar. The SAT encoding is as follows:
[0111]
[0112] Case 6: It means that the input difference is divided into three active mode type variables, and the output is also an active mode type variable. The specific SAT encoding method is the same as case 5.
[0113] Step S5: Characterize the contradiction and solve the SAT model
[0114] We can see that in the last step of the cost model, based on the Miss-In-Middle technique, E is transformed into A and E B Encoded as a full R-round impossible differential discriminator search model.
[0115] See also Figure 3 , Figure 3 is the overall structure of the impossible differential distinguisher. The entire block cipher is divided into E, E A ,E B In these three parts, we first solve an impossible difference distinguisher through the SAT model. Then we expand the impossible difference distinguisher by and E B Backward expansion R A Round and forward extension R B Rounds, and finally the R rounds of the entire block cipher cannot be differentiated.
[0116] The specific steps include:
[0117] 1. Perform SAT encoding on the contradictory positions:
[0118] Before performing the conflict encoding, it is necessary to fix the conflict rounds. Assume that the total number of units in E is d = 16. t and r t+1 There is a contradiction between The output difference is Use a two-dimensional array to represent the contradiction table, conPos = [[0,0,0,1,1],[0,0,1,1,1],[0,1,0,0,1],[1,1,0,0,1],[0,0,0,0,0],[0,0,1,0,0],[0,1,0,1,0],[0,1,1,0,0],[0,1,1,1,0],[1,0,0,0,0],[1,0,0,1,0],[1,0,1,0,0],[1,0,1,0,0],[1,0,1,1,0],[1,1,0,1,0],[1,1,1,0,0],[1,1,1,1,0]], and then perform SAT encoding on the contradiction table. Only one case is taken as an example, and the rest of the encoding cases are the same:
[0119]
[0120] It is also necessary to limit the contradiction to occur in at least one unit position, and the corresponding SAT encoding is:
[0121] "ASSERT(μ_0=1ORμ_1=1OR...μ_15=1)";
[0122] 2. Solve the complete SAT discriminator:
[0123] Combined with the previous E A and E B Model, according to the contradictory SAT encoding, we can get the R-round complete SAT impossible difference model of E, and use the STP solver to solve it to get an effective impossible difference distinguisher.
[0124] 3. Traverse all conflicting positions:
[0125] Constantly change the position of the contradiction to establish different SAT discriminator models, and use the STP solver to solve them. If the model has a solution, it is an effective impossible differential discriminator. If it has no solution, it is not an impossible differential discriminator.
[0126] 4. Eliminate redundant solutions:
[0127] Remove the duplicate solutions from the solutions obtained by the STP solver, and the remaining solutions are the distinguishers of all R rounds in E that cannot be differentiated.
[0128] Step S6: Dynamically adjust encryption strategy
[0129] According to the security assessment results of the SAT-based impossible differential model, the encryption strategy is dynamically adjusted to ensure security during transmission.
[0130] Specific steps:
[0131] 1. Feedback on evaluation results: The security evaluation module will provide feedback to the system on the security of the current algorithm based on the results of the SAT impossible differential model analysis. If the algorithm is secure, the current encryption settings will be maintained. If potential vulnerabilities are found, it will be recommended to change the encryption algorithm or adjust the current configuration.
[0132] 2. Automatically adjust encryption strategy: The present invention mainly uses algorithm switching and increasing key length. Algorithm switching means that the system initially uses a lightweight cipher SKINNY-64, which can be replaced with AES-64 for encryption. Increasing the key length can set the original SKINNY-64 to SKINNY-128, and can also take the form of a related key.
[0133] 3. Update encryption configuration in real time: The adjusted encryption configuration will be applied to subsequent encryption operations in real time to ensure that the subsequent encryption process is always in the optimal security state.
[0134] Step S7: Data transmission
[0135] Transmit the encrypted data to ensure that the data will not be stolen, tampered with or leaked on the network.
[0136] Specific steps:
[0137] 1. Sending encrypted data: The encrypted data is sent to the receiver through a secure data transmission channel (such as SSL / TLS). After receiving the encrypted data, the receiver uses the corresponding decryption algorithm to decrypt it.
[0138] 2. Decryption process: The receiver uses the same key and decryption algorithm as the sender to decrypt the data and restore the original plaintext data.
[0139] 3. Integrity check: During the decryption process, the system will also verify the data integrity to ensure that the data has not been tampered with during transmission. If data tampering is found, the system will alarm and terminate data reception.
[0140] What is disclosed above is only one or more preferred embodiments of the present invention, which certainly cannot be used to limit the scope of rights of the present invention. Ordinary technicians in this field can understand that all or part of the processes of implementing the above embodiments and making equivalent changes according to the claims of the present invention still fall within the scope of the invention.
Claims
1. A dynamic encryption communication security assessment method based on SAT, characterized in that: The following steps are involved: Step 1: Data input and preprocessing; Step 2: Encrypt the data using a block cipher algorithm; Step 3: Two-dimensional binary variable setting; Step: 4: SAT encode the basic operations of block cipher E; Step 5: Characterize the contradictory position and solve the SAT model; Step 6: Dynamically adjust encryption strategy; Step 7: Transmit the encrypted data.
2. The SAT-based dynamic encryption communication security assessment method according to claim 1, characterized in that: The execution process of step 2 includes the selection of encryption algorithm and the selection of block cipher operation mode, which includes the following two steps: Step 2.1: Select the corresponding block cipher algorithm of SP-Network structure according to the requirements; Step 2.2: Select CBC mode for encryption.
3. The SAT-based dynamic encryption communication security assessment method according to claim 2, characterized in that: The two-dimensional binary variable includes a differential value type variable and an active mode type variable. The differential value type variable is denoted as θx[i] and has a value of (0,0). θx ,(0,1) θx ,(1,0) θx ,(1,1) θx , respectively represent the difference values are 0, Δ1, Δ2, Δ3, where Δ1≠Δ2≠Δ3≠0; The active mode type variable is denoted as ρx[i], and its value is (0,0) ρx ,(0,1) ρx ,(1,0) ρx ,(1,1) ρx They represent four different differential modes: inactive, active, unknown, and active known.
4. The SAT-based dynamic encryption communication security assessment method according to claim 3, characterized in that: In step 4, the basic operations in the block cipher E are encoded using the CVC format specification in SAT, including the following operation items: Linear permutation operation: Encoding is completed using the copy operation model in SAT; S-box operation: SAT encoding is performed by state differential propagation according to the corresponding units; Column confusion operation: First classify the column confusion operation and then perform SAT encoding according to the differential conversion table.
5. The SAT-based dynamic encryption communication security assessment method according to claim 4, characterized in that: In step 5, based on the Miss-In-Middle technique, a new variable μ_i is introduced to convert E A and E B Encoded as a complete R-round impossible difference distinguisher search model, it includes the following steps: Step 5.1: SAT encoding of the contradictory positions; Step 5.2: Solve the complete SAT discriminator; Step 5.3: Traverse all contradictory positions; Step 5.4: Eliminate redundant solutions.
6. The SAT-based dynamic encryption communication security assessment method according to claim 5, characterized in that: During the execution of step 5, the contradiction position is continuously changed to establish different SAT discriminator models, and the STP solver is used to solve the model. If the model has a solution, it is an effective impossible differential discriminator. If there is no solution, it is not an impossible differential discriminator. Then, the repeated solutions obtained by the STP solver are removed, and the remaining solutions are all R-round impossible differential discriminators in the block cipher E.
7. The SAT-based dynamic encryption communication security assessment method according to claim 6, characterized in that: During the execution of step 6, the security is evaluated based on the results of the impossible differential distinguisher search model analysis, and the encryption strategy is automatically adjusted, that is, the algorithm is switched and the key length is increased, and the encryption configuration is updated in real time.