Non-interference bit and MILP-based impossible differential divider search method
By combining the non-interferenced bit differential propagation properties and the impossible differential divider search method of MILP technology, the existing models have solved the problem of reduced search accuracy and limited application scope in the bit operation cryptographic algorithm, and more efficient differential search and attack efficiency are achieved.
Patent Information
- Application Number
- CN202510232157.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
AI Technical Summary
The existing impossible differential divider search model has problems of reduced search accuracy and limited scope of application when processing cipher algorithms for bit operations, and it is difficult to traverse all possible input and output differences in a limited time.
The impossible differential divisor search method is adopted that combines the non-interferenced bit differential propagation properties and MILP technology. By portraying the bit-level differential propagation law in the MILP model, and introducing constraints for two types of contradiction points, we can solve the model and obtain an effective impossible differential divisor.
Improves the accuracy and efficiency of impossible differential divider searches, supports bit-level operation cipher algorithms, can find more differentiators in a limited time, and improves the efficiency of the entire attack.
Smart Images

Figure CN120074805A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and particularly to a method for searching impossible differential distinguishers by combining the properties of non-interfered bit propagation and MILP technology. Background Art
[0002] Impossible differential analysis is a classic variant of differential analysis, independently proposed by Knudsen [1] and Biham [2] respectively. The impossible differential analysis is defined as follows: Let the input difference be Δin and the output difference be Δout, and E k represents the encryption process of a block cipher under the key k. If for any k, the propagation probability from Δin to Δout is 0, then Δin and Δout are an impossible differential distinguisher, that is has no solution.
[0003] The impossible differential attack can be divided into two stages: The first stage is the distinguisher search stage. First, the input difference Δin is propagated backward with a probability of 1 for r 1 rounds to obtain α, and the output difference Δout is propagated forward with a probability of 1 for r 2 rounds to obtain β. If α≠β, then is an r 1 +r 2 round impossible differential distinguisher; The second stage is the key recovery stage. The input and output differences of the obtained distinguisher are extended to both ends by r 3 and r 4 rounds respectively, and all the round keys involved in r 3 and r 4 rounds are recovered, and then the master key of the cipher is recovered according to the key scheduling algorithm. According to the above steps, in order to make the attack round number r 1 +r 2 +r 3 +r 4 as large as possible, first, one or more impossible differential distinguishers as long as possible need to be found. Therefore, the search method of the distinguisher is very important.
[0004] In 2016, Cui et al. [3] used MILP tools to characterize the differential propagation law and considered the details of S-boxes when searching for impossible differential distinguishers.
[0005] In 2017, Sasaki et al. [4] applied MILP automation technology to the search for impossible differential distinguishers and obtained effective impossible differential distinguishers by fixing the input and output difference values.
[0006] In 2020, Sun et al. [5] combined the respective advantages of the truncated model and the bit model, and proposed a model that uses the middle-phase error technique to search for truncated impossible differentials, which simultaneously characterizes the differential value and the differential pattern.
[0007] Subsequently, in 2022, Cao et al. [6] used the MILP model to characterize the propagation law of non-disturbed bits in cryptographic operations, preset contradiction points, and obtained effective impossible differential distinguishers with the model having a solution.
[0008] However, the existing models in the above-mentioned literature have deficiencies. In the model in [5] that simultaneously characterizes the differential value and the differential pattern, since it can only search in units of bytes or half-bytes, it cannot be used for cryptographic algorithms with bit operations, which limits the scope of application of this model. In [4], by fixing the input and output differential values and obtaining impossible differential distinguishers according to the infeasibility of the model returned by the MILP solver, although it can search in bits, because the set composed of all possible Δin and Δout is very large, it is difficult to traverse all possible inputs and outputs, and only a relatively small subset can be traversed within the actual limited time, such as the subset where the Hamming weights of the input and output differentials are both 1. In addition, in order to reduce the complexity of the entire attack process, the distinguisher search and expansion, and key recovery can be combined. However, if the distinguisher is searched with the model having no solution, the combination will be difficult to achieve. Therefore, the search model with fixed input and output is difficult to further improve the attack efficiency. In the impossible differential distinguisher search model in [6] that characterizes non-disturbed bits, although it can be characterized in bits and does not require fixed input and output differentials, not all non-zero input differentials of the S-box have non-disturbed bits in the corresponding output differentials, and this model cannot handle this situation well. In addition, this model splits the forward and backward propagation processes of the differential value into two independent propagation models M 0 and M 1 , and manual fixing of contradiction points is required, so the model efficiency is limited and not all effective distinguishers can be obtained.
[0009] [1]Knudsen, Lars. "DEAL - a 128 - bit block cipher." complexity 258.2(1998):216.
[0010] [2]Biham, Eli, Alex Biryukov, and Adi Shamir. "Cryptanalysis of Skipjack reduced to 31 rounds using impossible differentials." Advances in Cryptology - EUROCRYPT’99: International Conference on the Theory and Application of Cryptographic Techniques Prague, Czech Republic, May 2–6, 1999 Proceedings 18. Springer Berlin Heidelberg, 1999。
[0011] [3]Tingting Cui, Keting Jia, Kai Fu, Shiyao Chen, Meiqin Wang: New Automatic Search Tool for Impossible Differentials and Zero-Correlation Linear Approximations. IACR Cryptol. ePrint Arch. 2016:689(2016)。
[0012] [4]Sasaki, Yu, and Yosuke Todo. "New impossible differential search tool from design and cryptanalysis aspects: Revealing structural properties of several ciphers." Advances in Cryptology–EUROCRYPT 2017: 36th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Paris, France, April 30–May 4, 2017, Proceedings, Part III 36. Springer International Publishing, 2017。
[0013] [5]Ling Sun,David Gérault,Wei Wang,and Meiqin Wang.On the usage of deterministic(related-key)truncated differentials and multidimensional linear approximations for SPN ciphers.IACR Trans.Symmetric Cryptol.,2020(3):262-287,2020。
[0014] [6]Cao,Weiwei,Wentao Zhang,and Chunning Zhou."New Automatic Search Tool for Searching for Impossible Differentials Using Undisturbed Bits."International Conference on Information Security and Cryptology.Cham:Springer Nature Switzerland,2022。 Summary of the Invention
[0015] In view of the above problems, the impossible differential distinguisher search method proposed by the present invention improves the non-disturbed bit model in [6] as follows: The truncation model ignores the details of the S-box, resulting in a decrease in search accuracy, and it is impossible to search for distinguishers for ciphers with bitwise operations. To solve this deficiency, the MILP model of the present invention characterizes and searches for distinguishers bit by bit.
[0016] The object of the present invention is to propose an impossible differential distinguisher search method that combines the differential propagation properties of non-disturbed bits and MILP technology. This method is mainly aimed at lightweight block ciphers, transforms the relationship between differential values before and after linear and non-linear operations into linear constraint conditions, and adds these constraint conditions to the MILP model. And in order to detect possible contradictions in the middle rounds of the distinguisher, two types of contradiction points and corresponding constraint conditions are introduced. Finally, the model is solved to search for impossible differential distinguishers by the solvability of the model, and the input and output differential values are returned by the solver.
[0017] The technical solution for achieving the object of the present invention is as follows:
[0018] An impossible differential distinguisher search method based on non-disturbed bits and MILP includes the following steps:
[0019] (1) Model the components in the cryptographic algorithm:
[0020] For each bit involved in the impossible differential distinguisher, two binary variables are used in the MILP model. According to the differential propagation properties of the round function operations of the cryptographic algorithm, such as the S-box and XOR operations, a system of linear inequalities is used to characterize the differential propagation properties, and these inequality systems are added to the MILP model file;
[0021] (2) Set up contradiction positions and model the contradictions:
[0022] Let the input differential value of the impossible differential distinguisher be Δin. After r 1 rounds of encryption, the differential value is equal to α with probability 1. The output differential of the distinguisher is Δout. After r 2 rounds of decryption, the differential value is equal to β with probability 1. If α≠β, that is, there is a contradiction between the corresponding bits in α and β, then it constitutes an r 1 +r 2 -round impossible differential distinguisher;
[0023] To obtain an effective impossible differential distinguisher, constraints on the contradiction points need to be established in the middle rounds of the search model. The present invention proposes two types of contradiction points in the MILP model, and either one can be optionally added to the model;
[0024] (3) Use a solver to solve the model to obtain an effective impossible differential distinguisher:
[0025] According to the actual search requirements, it is possible to choose whether to add an objective function, and use the Gurobi solver to solve the lp model file generated in the above steps. If the model has a solution, the specific values of Δin and Δout in step (2) are returned. The obtained result is the input and output differential values of the r 1 +r 2 -round impossible differential distinguisher, and the solver returns the input and output differential values.
[0026] The present invention is an improved search model for impossible differential distinguishers based on non-disturbed bits. The core lies in characterizing the forward and backward propagation of the input and output differentials by tracing the propagation law of non-disturbed bits in cryptographic operations, and adding a new contradiction characterization model. When there is a contradiction between the corresponding bits after the input and output differentials are propagated through several rounds, that is, α≠β, these contradiction points can be detected through the contradiction indicator variable to ensure the correctness of the obtained distinguisher. Finally, when using the solver to solve, it is possible to choose to obtain the distinguisher with the minimum Hamming weight or all effective distinguishers to meet various requirements.
[0027] The beneficial effects of the present invention are:
[0028] (1) The search method of the present invention supports a password for bit-level operations, further subdivides the case where the bit difference is unknown, studies the relationship between multiple unknown bits, and uses special values to distinguish these bits. In this way, more possible propagation cases can be excluded than the traditional method, and a distinguisher that cannot be found by the existing model can be found;
[0029] (2) The search method of the present invention introduces two types of contradiction points. According to the respective properties of the two contradictions, corresponding indicator variables and auxiliary variables, and the inequality group between them are introduced. Using these two types of variables, the forward and backward propagation processes of the input-output difference can be integrated into a unified model, and there is no need to manually set the contradiction points, and the automation program is higher than the existing non-disturbed bit model;
[0030] (3) The search method of the present invention searches for impossible differentials with a solution in the MILP model. The traditional method of searching for a distinguisher with no solution in the model is not convenient to combine with the distinguisher extension and key recovery process. This model can improve the efficiency of the entire attack. Description of the Drawings
[0031] Figure 1 It is a flow chart for establishing an impossible differential search model and searching for a distinguisher for the present invention. Detailed Embodiments
[0032] The following further describes the content of the present invention in conjunction with embodiments and drawings, but it is not a limitation of the present invention.
[0033] Embodiment
[0034] An impossible differential distinguisher search method based on non-disturbed bits and MILP, referring to Figure 1 , includes the following steps:
[0035] (1) Model the components in the cryptographic algorithm:
[0036] For each bit involved in the impossible differential distinguisher, two binary variables are used to represent it in the MILP model. According to the differential propagation properties of the round function operations of the cryptographic algorithm, such as the S-box and XOR, a linear inequality group is used to describe the differential propagation properties, and these inequality groups are added to the MILP model file;
[0037] (2) Set the contradiction positions and model the contradictions:
[0038] Let the input difference value of the impossible differential distinguisher be Δin, and after r 1 rounds of encryption, the difference value is equal to α with a probability of 1, and the output difference of the distinguisher is Δout. After r 2The differential value after round decryption is equal to β with probability 1. If α≠β, that is, there is a contradiction between the corresponding bits in α and β, then constitutes an r 1 +r 2 -round impossible differential distinguisher;
[0039] To obtain an effective impossible differential distinguisher, constraints on the contradiction points need to be established in the middle rounds of the search model. The present invention proposes two types of contradiction points in the MILP model, and either one can be selected and added to the model;
[0040] (3) Use a solver to solve the model to obtain an effective impossible differential distinguisher:
[0041] According to the actual search requirements, it is possible to choose whether to add an objective function and use the Gurobi solver to solve the lp model file generated in the above steps. If the model has a solution, return the specific values of Δin and Δout in step (2). The obtained result is the input and output differential values of an r 1 +r 2 -round impossible differential distinguisher, and the solver returns the input and output differential values.
[0042] Furthermore, the specific steps of modeling the components in the cryptographic algorithm in step (1) are as follows:
[0043] (1.1) The MILP search model mainly tracks the differential propagation situation through non-disturbed bits and uses a special value f to represent the relationship between bits;
[0044] For a bit, there are only two possible values, 0 or 1. In addition to the fixed differential value, the possible value of this bit is unknown, denoted as?. When the value of a bit is unknown, it means that the differential value of this bit may be 1 or 0. In addition, there is a special unknown situation, that is, there are several bits denoted as?, and the value of each of these bits is unknown when viewed alone, but their sum is not 0. If there is an n-bit S-box, its input differential is non-zero and there are no non-disturbed bits in the corresponding output differential, then the differential values of all output bits are unknown, but the sum of these bits is not 0. For this situation, the special value f is used to represent the differential values of these output bits;
[0045] For example, assume there is a 4-bit S-box transformation, denoted as S. When the 4-bit input differential α≠0 and there are no non-disturbed bits in the 4-bit output differential of S(α), then it is denoted as S(Δα)=ffff;
[0046] (1.2) Since each bit difference has 4 possible values: fixed to 0, fixed to 1, unknown, and a special flag value f, 2 BINARY type variables are needed to represent it in the MILP model, denoted as X[2];
[0047] For convenience, assume the flag value takes f = 11, and the bit difference ΔX and the corresponding X[2] values are as follows:
[0048]
[0049] (1.3) The MILP search model uses a logical modeling method to characterize the propagation of non-disturbed bits in the S-box;
[0050] If there is a bit difference in the output difference of the S-box whose value is uniquely determined by the input difference, this bit is called a non-disturbed bit. Take the first S-box S of the LBlock algorithm as an example 0 For example, when the input difference is 0001, the output difference values include: 0001, 0011, 0111, 1001, 1011, 1111. Thus, a propagation pattern of non-disturbed bits 0001 →???1 can be obtained, and this pattern is represented as the point (0,0,0,0,0,0,0,1,1,0,1,0,1,0,0,1);
[0051] When the input difference is 0100, the output difference values include: 0011, 0100, 0101, 0110, 1011, 1101. It can be seen that there are no non-disturbed bits under this input. And since the S-box input difference is non-zero, the output difference must also be non-zero. Therefore, it is represented as the point (0,0,0,1,0,0,0,0,1,1,1,1 1,1,1,1);
[0052] In addition, when S 0 The input difference is 1011, the output difference may be 0001, 1000, 1010, 1011, obtaining a propagation pattern of non-disturbed bits 1011 →?0??. Although this propagation pattern contains non-disturbed bits, the only non-disturbed bit is 0. According to the properties of S-box difference propagation, the unknown bits are non-zero. Therefore, this propagation pattern should be represented as the point (0,1,0,0,0,1,0,1,1,1,0,0,1,1,1,1);
[0053] Using [α 3 , α 2 , α 1 , α 0 and [β 3 , β 2 , β 1 , β 0represents the input-output difference of a 4-bit S-box. As described above, the propagation law of non-disturbed bits through this S-box is expressed as:
[0054]
[0055] Referring to Figure 1 , all possible propagation patterns and impossible propagation patterns of the S-box are respectively represented as point sets P and P * , using the mathematical tool Logic Friday to convert the propagation law of non-disturbed bits of the S-box into a system of inequalities. Let the coefficient matrix of the obtained system of inequalities be L, and the vectors x and y be the sets of input-output variables of the S-box. Then the following constraint conditions are added to the search model:
[0056] Lx = y (Equation 3);
[0057] (1.4) Characterizes the XOR operation, and the operation method is as follows:
[0058] For the XOR operation a 0 、a 1 The value relationship with b is shown in Table 1:
[0059] Table 1 XOR operation The value-taking situation of the operands in:
[0060]
[0061] According to the above table, each possible propagation law is converted into a point [a 0 ,a 1 ,b]. Table 1 is converted into a point set containing 16 points, and using the mathematical tool SageMath to convert it into the following system of inequalities, where a 0 [1] and a 0 [0] respectively represent the two binary variables of a 0 , and so on:
[0062]
[0063] Furthermore, in order to ensure that contradictions occur after the input difference Δin and the output difference Δout propagate forward and backward through several rounds, it is necessary to introduce constraint conditions regarding the contradiction points in the model.
[0064] Referring to Figure 1 , after completing the characterization of each component in the cryptographic algorithm in step (1), it is necessary to establish contradiction point constraints in the model. The contradiction positions set in step (2) are specifically, using Δin and Δout to represent the input and output differences of the impossible differential distinguisher, and then propagating Δin and Δout forward and backward by r 1Wheel and r 2 After the wheel, the output values are respectively represented as α and β, where α[i] and β[i] represent the i-th bit in α and β. To accurately obtain all possible contradiction points, the contradiction points are divided into two categories:
[0065] The first type of contradiction point is: there exists a certain bit difference that is 0 and 1, or 1 and 0 in α and β respectively, which is expressed as Satisfy α[i]=1, β[i]=0 or α[i]=0, β[i]=1, where blocksize represents the block size of the cipher;
[0066] To ensure that the corresponding bits in α and β have a 0-1 contradiction, introduce a contradiction indicator variable c, and use γ and δ to characterize the corresponding bits where the first type of contradiction occurs. γ and δ are binary variables of length 2. If there is a 0-1 contradiction between the corresponding bits, then c = 1, otherwise c = 0. Then the relationship between γ, δ and c can be expressed by an inequality group as:
[0067]
[0068] Use c i To represent the contradiction situation of the i-th corresponding bit between the output difference of the r 1 -1 round and the input difference of the r 1 round. Then as long as there is a 0-1 contradiction in one of the blocksize corresponding bits, Δin and Δout are a pair of impossible differences. The constraint to ensure the occurrence of the first type of contradiction point is:
[0069]
[0070] The second type of contradiction is different from the first type of contradiction which only requires one 0-1 contradiction point. The second type of contradiction is the occurrence of an all-0 - non-all-0 contradiction between several corresponding bits; for a specific explanation, use Δin and Δout to represent the input and output differences of the impossible difference distinguisher. After propagating Δin and Δout forward and backward by r 1 Wheel and r 2 rounds respectively, the output values are α and β respectively. The value situation of β is unknown, but the set of bit numbers corresponding to non-0 is denoted as index, and for Satisfy α[i]=00, β[i]=11, that is, there is a set of bits in α that are all 0, and its corresponding bits in β are not all 0. Such a contradiction is called the second type of contradiction;
[0071] To characterize the second type of contradiction point, introduce an indicator variable d i , when α[i]=11, the corresponding d i =1, otherwise d i =0, d iThe relationship between and α[i] can be expressed by a system of inequalities as follows:
[0072]
[0073] To indicate the all-0 vs. non-all-0 contradiction in the corresponding bit sets of α and β, an indicator variable c is introduced. If the corresponding bits are 00 and 11 respectively, then c = 0; otherwise, c = 1. Then d i The relationship among d, β[i], and c can be expressed by a system of inequalities as follows:
[0074]
[0075] Contrary to the first type of contradiction points, according to the definition, for the second type of contradiction to occur, all α[i] = 11 must correspond to β[i] = 00. Therefore, any c = 1 is not allowed. The constraints to ensure the occurrence of the second type of contradiction points are:
[0076]
[0077] Refer to Figure 1 , after establishing all the differential propagation and contradiction characterization constraints, the distinguisher is solved according to the actual requirements. In step (3), the distinguisher is solved according to the actual search requirements, and the input and output differentials are propagated forward and backward by r 1 and r 2 rounds, and after adding all the relevant differential propagation constraint conditions, contradiction point constraint conditions, and variable declarations involved to the search model, if you hope to obtain as many distinguishers as possible, then the objective function does not need to be set. On the contrary, if you only hope to obtain a distinguisher with the smallest possible Hamming weight of the input-output differential, then add the objective function:
[0078]
[0079] where in i [0] and in i [1] are two binary variables representing the value of the i-th bit of the input differential, and out i [0] and out i [1] are two binary variables representing the value of the i-th bit of the output differential;
[0080] If you hope to obtain all the distinguishers, then no objective function is required;
[0081] Finally, use the Gurobi solver to solve the model to obtain the input and output differentials of the impossible differential distinguisher for r 1 + r 2 rounds.
[0082] The search method of the present invention searches for impossible differential distinguishers with the condition that the model has a solution, which is convenient for integrating the search and extension of distinguishers and the key recovery process, and improving the overall attack efficiency. When the input difference of the S-box is non-zero and there are no non-disturbed bits or all non-disturbed bits are 0 in the output difference, the existing non-disturbed bit models cannot accurately describe this situation. To solve this problem, a flag value f is introduced, and the process of propagating non-disturbed bits forward and backward is integrated into a single unified model to improve the solution efficiency. Searching for impossible differential distinguishers with the condition that the model has a solution cannot obtain the contradiction points of the distinguishers. The existing non-disturbed bit models need to manually set the contradiction points. To automatically obtain the contradiction points, two new types of contradictions are introduced in this model. The first type of contradiction is the 0-1 contradiction at the bit level, and the second type of contradiction is the all-0 - non-all-0 contradiction. By adding the respective constraint conditions of the two types of contradictions to the model, the contradiction points can appear and the positions of the contradiction points can be obtained. And the MILP model has a long development time and relatively mature technology. There are various cross-platform solvers. The model has the advantages of being easy to write and fast in solving speed. Therefore, the present invention uses the MILP model to implement the search for impossible differential distinguishers.
Claims
1. An impossible differential distinguisher search method based on non-interfered bits and MILP, characterized in that: The steps include: (1) Modeling the components of the cryptographic algorithm: For each bit involved in the impossible differential distinguisher, two binary variables are used in the MILP model to represent it. According to the differential propagation properties of the round function operation, S-box and XOR operation of the cryptographic algorithm, a linear inequality group is used to characterize the properties of differential propagation, and these inequality groups are added to the MILP model file. (2) Establish the conflict position and model the conflict: Suppose the input differential value of the impossible differential distinguisher is Δin. After r1 rounds of encryption, the differential value is equal to α with probability 1. The output differential of the distinguisher is Δout. After r2 rounds of decryption, the differential value is equal to β with probability 1. If α≠β, that is, there is a contradiction between the corresponding bits in α and β, then Construct an r1+r2 round impossible differential distinguisher; In order to obtain an effective impossible difference distinguisher, constraints on the contradiction points are established in the middle round of the search model. The present invention proposes two types of contradiction points in the MILP model, and one of them can be added to the model at will; (3) Use the solver to solve the model and obtain an effective impossible difference distinguisher: According to the actual search requirements, you can choose whether to add an objective function and use the Gurobi solver to solve the lp model file generated in the above steps. If the model has a solution, the specific values of Δin and Δout in step (2) are returned. The result is the input-output difference value of the r1+r2 round impossible differential distinguisher, and the input-output difference value is returned by the solver.
2. The impossible differential distinguisher search method based on non-interfered bits and MILP according to claim 1, characterized in that: Step (1) of modeling the components in the cryptographic algorithm is as follows: (1.1) The MILP search model mainly tracks the differential propagation through non-interfered bits and uses a special value f to represent the relationship between bits; For a bit, there are only two possible values, 0 or 1. In addition to the fixed differential value, the bit may also have an unknown value, that is, ?. When the value of a bit is unknown, it means that the differential value of the bit may be 1 or 0. In addition, there is a special unknown case, that is, there are several bits with the value of ?. The values of these bits are unknown when viewed individually, but their sum is not 0. If there is an n-bit S-box whose input differential is non-zero and the corresponding output differential does not contain non-interfered bits, then the output bit differential values are all unknown, but the sum of these bits is not 0. For this case, a special value f is used to represent these output bit differentials; For example, suppose there is a 4-bit S-box transformation, denoted by S, when the 4-bit input difference α≠0, and there is no non-interfered bit in the 4-bit output difference of S(α), then it is denoted by S(Δα)=ffff; (1.2) Since each bit difference has four possible values: fixed to 0, fixed to 1, unknown, and a special flag value f, two BINARY type variables need to be used in the MILP model, denoted as X[2]; For convenience, the characterization flag value is f=11, and the bit difference ΔX and the corresponding X[2] values are: (1.3) The MILP search model uses a logical modeling approach to characterize the propagation of non-interfered bits for the S-box; If there is a bit difference in the output difference of the S-box, and its value is uniquely determined by the input difference, the bit is called an unaffected bit. Taking the first S-box S0 of the LBlock algorithm as an example, when the input difference is 0001, the output difference can take the following values: 0001, 0011, 0111, 1001, 1011, 1111. Thus, a propagation pattern containing unaffected bits 0001→? ? ? 1 can be obtained. The pattern is represented by the point (0,0,0,0,0,0,0,0,1,1,0,1,0,1,0,0,1); When the input differential is 0100, the output differential values include: 0011, 0100, 0101, 0110, 1011, 1101. It can be seen that there is no non-interfered bit under this input, and because the S-box input differential is not 0, the output differential must be non-0, so it is represented as the point (0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 11, 1, 1, 1); In addition, when the S0 input differential is 1011, the output differential may be 0001, 1000, 1010, 1011, and the propagation pattern containing non-interfered bits is 1011→? 0? ?. Although this propagation pattern contains non-interfered bits, the only non-interfered bit is 0. According to the properties of S-box differential propagation, the unknown bit sum is not 0, so this propagation pattern should be represented as the point (0,1,0,0,0,1,0,1,1,1,0,0,1,1,1,1); Using [α3, α2, α1, α0] and [β3, β2, β1, β0] to represent the input and output differences of a 4-bit S-box, the propagation law of the non-interfered bits through the S-box is expressed as: All possible propagation modes and impossible propagation modes of the S-box are expressed as point sets P and P respectively. * , use the mathematical tool Logic Friday to convert the S-box's uninterrupted bit propagation law into an inequality group. Let the coefficient matrix of the obtained inequality group be L, and vectors x and y be the set of S-box input and output variables. Then add the following constraints to the search model: Lx=y (Formula 3); (1.4) Describe the XOR operation, which is as follows: XOR operation The relationship between a0, a1 and b values is shown in Table 1: Table 1 XOR operation The value of the operand in According to the above table, each possible propagation law is converted into a point [a0, a1, b], and Table 1 is converted into a point set containing 16 points. The mathematical tool SageMath is used to convert it into the following inequality group, where a0[1] and a0[0] represent two binary variables of a0, and so on:
3. The impossible differential distinguisher search method based on non-interfered bits and MILP according to claim 1, characterized in that: In step (2), the contradictory position is established by using Δin and Δout to represent the input and output differences of the impossible differential distinguisher, and then propagating Δin and Δout forward and backward for r1 rounds and r2 rounds respectively, and the output values are represented as α and β respectively, where α[i] and β[i] represent the i-th bit in α and β. In order to accurately obtain all possible contradictory points, the contradictory points are divided into two categories: The first type of contradiction is: there is a bit difference in which α and β are 0 and 1, or 1 and 0, respectively, which can be expressed as Satisfies α[i]=1,β[i]=0 or α[i]=0,β[i]=1, where blocksize represents the block size of the cipher; In order to ensure that there is no 0-1 contradiction between the corresponding bits in α and β, a contradiction indicator variable c is introduced, and γ and δ are used to characterize the corresponding bits where the first type of contradiction occurs. γ and δ are binary variables with a length of 2. If there is a 0-1 contradiction between the corresponding bits, c = 1, otherwise c = 0. Then the relationship between γ, δ and c can be expressed by the inequality group as follows: Use c i Indicates the contradiction between the i-th corresponding bit of the output difference of the r1-1th round and the input difference of the r1th round. Then, as long as a 0-1 contradiction appears in the blocksize corresponding bits, Δin and Δout are a pair of impossible differences. The constraint to ensure the occurrence of the first type of contradiction is: The second type of contradiction is different from the first type of contradiction. It only needs a 0-1 contradiction point. The second type of contradiction is the contradiction between all 0 and non-all 0 between several corresponding bits. For the sake of specific explanation, Δin and Δout are used to represent the input and output differences of the impossible differential distinguisher. After propagating Δin and Δout forward and backward for r1 rounds and r2 rounds respectively, the output values are α and β respectively. The set of bit numbers in β whose values are unknown but non-zero is recorded as index, and the Satisfies α[i]=00,β[i]=11, that is, there is a set of bits that are all 0 in α, but its corresponding bits in β are not all 0. This contradiction is called the second kind of contradiction; In order to characterize the second type of contradiction, the indicator variable d is introduced. i , when α[i]=11, corresponding to d i =1, otherwise d i =0,d i The relationship between and α[i] can be expressed by a set of inequalities: In order to indicate the contradiction between all 0 and non-all 0 in the corresponding bit sets of α and β, an indicator variable c is introduced. If the corresponding bits are 00 and 11 respectively, then c = 0, otherwise c = 1, then d i The relationship between , β[i] and c can be expressed by the following inequality group: In contrast to the first type of contradiction, according to the definition, the second type of contradiction must occur when all α[i]=11 correspond to β[i]=00, so no c=1 can appear. The constraints that ensure the occurrence of the second type of contradiction are:
4. The impossible differential distinguisher search method based on non-interfered bits and MILP according to claim 1, characterized in that: In step (3), the discriminator is obtained according to the actual search requirements, and the input and output differences are propagated forward and backward for r1 and r2 rounds respectively. After all the relevant differential propagation constraints, the constraints of the conflict points and the variable declarations involved are added to the search model, if you want to get as many discriminators as possible, you do not need to set the objective function. On the contrary, if you only want to get a discriminator with the smallest input and output differential Hamming weight as possible, then add the objective function: where i [0] and in i [1] Two binary variables representing the value of the i-th bit of the input difference, out i [0] and out i [1] Two binary variables representing the value of the i-th bit of the output difference; If you want to get all the discriminators, no objective function is needed.