Novel bit-oriented MILP impossible Boomerang attack method

Through the bit-oriented MILP impossible Boomerang attack method, bit-level modeling and contradiction determination are performed on the 4-bit S box packet cipher algorithm, and the impossible Boomerang differentiator search model and key recovery model are built, which solves the bit-level cipher algorithm problem that cannot be applied to the existing methods, and realizes efficient impossible Boomerang attack.

CN120074806APending Publication Date: 2025-05-30GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510232646.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing Impossible Boomerang differentiator construction method mainly targets nibble/byte-level cipher algorithms, and cannot effectively portray bit-level cipher algorithms, especially in cipher algorithms containing bit permutation operations.

Method used

A new method for bit-oriented MILP Impossible Boomerang attack is proposed. By performing bit-level modeling of linear and nonlinear components on the 4-bit S box packet cipher algorithm, using BCT to determine contradictions, building an impossible Boomerang differentiator search model, and key recovery is performed through the MILP model to optimize the overall time complexity.

Benefits of technology

The accurate portrayal of the impossible Boomerang differentiator search of the bit-level cryptographic algorithm is realized, and the high-round number impossible Boomerang differentiator for bit-design can be effectively built, and the time complexity is optimized through the key recovery model, which is suitable for the attack of the bit-level cryptographic algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074806A_ABST
    Figure CN120074806A_ABST
Patent Text Reader

Abstract

The invention discloses a novel bit-oriented method for impossible Boomerang attacks of an MILP (Multi-Independent Line Protection). For a block cipher algorithm of a 4-bit S box, a differential propagation constraint description with a bit-level probability of 1 is constructed for linear and nonlinear components of the block cipher algorithm, contradictions are constructed based on a BCT table, and an impossible Boomerang discriminator capable of searching a plurality of different contradiction points under the same round number can be searched; and expanding the front part and the back part of the discriminator, and constructing a key recovery model under a given impossible Boomerang discriminator. Time complexity calculation of each stage is incorporated into a model, a fixed difference of an S box is marked, filter bits when the S box relates to a subkey are counted and guessed, finally, constraints for balancing the complexity of each stage are set, and the minimum total time complexity can be obtained by solving the model. The method is suitable for a discriminator which is impossible to Boomerang attacks and search of key recovery attacks under related key or related adjustable conditions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and specifically to a new method for bit-oriented MILP impossible Boomerang attack. Background Art

[0002] The impossible Boomerang attack was first proposed by Lu et al. [1,2] and has a relatively low time complexity for attacking the AES cryptographic algorithm. This method is a variant of the Boomerang attack, which is a combination of the Boomerang attack, related keys, and impossible differential attack. Among them, the Boomerang attack constructs a high-probability and high-round differential characteristic from two high-probability and low-round differential characteristics for attack, and the related keys cleverly utilize the weakness of the key scheduling algorithm to custom-construct specific key differentials to construct a high-round distinguisher. The impossible differential attack uses an impossible differential characteristic to exclude incorrect candidate keys, gradually narrowing the key space to recover the correct key.

[0003] The impossible Boomerang attack combines the above three. Let the cryptographic algorithm be denoted as E. Assume that the algorithm E is divided into E 0 and E 1 two parts. Among them, for E 0 : α→β, α′→β′, the differential propagations of δ′→γ′ all propagate with probability 1, and when the 4 differential characteristics meet in the middle, they satisfy Then the above 4 differential characteristics constitute an impossible Boomerang distinguisher. The impossible Boomerang attack method is as Figure 2 shown.

[0004] The idea of searching for the impossible Boomerang distinguisher above is to construct a contradiction by using the differential XOR result of the middle misalignment, without using the theoretical tools of BCT to construct a contradiction.

[0005] In 2017, Cid et al. [3] proposed the theoretical tool of Boomerang Connectivity Table (BCT), including properties such as Ladder switch, Sbox switch, and upper and lower differential compatibility.

[0006] In 2023, Hadipour et al. [4] unified the impossible differential distinguisher and key recovery into a model using constraint programming (CP) modeling and successfully launched a 19-round impossible differential analysis on SKINNY.

[0007] In 2024, Bonnetain et al. [5] revisited the search for impossible Boomerang distinguishers and, based on the CP model, constructed a new search method for impossible Boomerang distinguishers with middle contradictions as constraints and applied it to Skinnyee. In the same year, Zhang et al. [6] also revisited the impossible Boomerang attack. Based on the Mixed-Integer Quadratically-Constrained Programming (MIQCP) modeling method, they constructed a new modeling method for the impossible Boomerang attack and launched attacks on Deoxys-BC, Joltik-BC, and SKINNY.

[0008] However, the construction methods of the impossible Boomerang distinguishers proposed above all study building models based on nibbles / bytes, which are limited to applicable block ciphers and cannot characterize block ciphers based on bits. When there are operations such as bit permutations in the block cipher, they are not applicable.

[0009] [1] Lu J. Cryptanalysis of block ciphers[D]. University of London, 2008.

[0010] [2] Lu J. The (related-key) impossible boomerang attack and its application to the AES block cipher[J]. Designs, Codes and Cryptography, 2011, 60: 123 - 143.

[0011] [3]Cid C, Huang T, Peyrin T, et al. Boomerang connectivity table: a new cryptanalysis tool[C] / / Advances in Cryptology–EUROCRYPT 2018: 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29-May 3, 2018 Proceedings, Part II 37. Springer International Publishing, 2018: 683-714。

[0012] [4]Hadipour H, Sadeghi S, Eichlseder M. Finding the Impossible: Automated Search for Full Impossible-Differential, Zero-Correlation, and Integral Attacks[C] / / Annual International Conference on the Theory and Applications of Cryptographic Techniques. Cham: Springer Nature Switzerland, 2023: 128-157。

[0013] [5]Bonnetain X, Cordero M, Lallemand V, et al. On Impossible Boomerang Attacks[J]. IACR Transactions on Symmetric Cryptology, 2024, 2024(2): 222-253。

[0014] [6]Zhang J,Wang H,Tang D.Impossible Boomerang Attacks Revisited:Applications to Deoxys-BC,Joltik-BC and SKINNY[J].IACR Transactions onSymmetric Cryptology,2024,2024(2):254-295。 Summary of the Invention

[0015] Aiming at the problems existing in the background technology, the present invention proposes a new method for bit-oriented MILP impossible Boomerang attack. This method is applicable to block cipher algorithms with 4-bit S-boxes. By modeling linear and non-linear components and determining contradictions based on BCT, it can be used to search for impossible Boomerang distinguishers with a high number of rounds for bit-oriented designed block cipher algorithms. Further, the found distinguisher is extended up and down to construct a key recovery model based on MILP. This model marks the differential fixed cases of S-boxes and counts the filtered bits when guessing sub-keys related to S-boxes, incorporates the calculation of time complexity into the model, and finally adds constraints for balancing complexity calculation. Solving this model with Gurobi can obtain the minimum overall time complexity.

[0016] The technical solution for achieving the purpose of the present invention is as follows:

[0017] A new method for bit-oriented MILP impossible Boomerang attack, comprising the following steps:

[0018] (1) Construct a bit-oriented impossible Boomerang distinguisher search model according to the block cipher algorithm;

[0019] According to the properties of the round function and the differential propagation law, perform bit-level modeling on the linear components, non-linear components such as S-boxes, and BCT contradiction points in the round function to form a complete impossible Boomerang distinguisher search model;

[0020] (2) Expand the distinguisher forward and backward, find the keys to be guessed corresponding to the positions of the active S-boxes, and construct a key recovery model based on MILP;

[0021] (3) Take the overall time complexity T as the objective function, add constraints for balancing the time complexity of each stage, and use Gurobi to solve the MILP model to return the result.

[0022] The beneficial effects of the present invention are:

[0023] (1) Compared with the method of depicting half - byte / byte, the method of the present invention can accurately depict the search for impossible Boomerang distinguishers of bit - level cryptographic algorithms. By representing all cases of the difference of each 1 bit with 2 auxiliary variables, depicting each component of the cryptographic algorithm, depicting the entire BCT table, and considering all cases of contradictions and non - contradictions, this model takes solvability as the judgment condition. By depicting new constraint inequalities, a new search model for impossible Boomerang distinguishers is depicted.

[0024] (2) Based on the distinguisher search model, a key - recovery model based on the distinguisher is proposed. This model marks whether the input difference or output difference of the state unit (S - box) is fixed, depicts the sub - keys involved in guessing the S - box, counts the filtering bits of the S - box, and substitutes the complexity calculation into the model according to the selected key - recovery algorithm. The overall minimum time complexity can be obtained by solving the model. This search method is applicable to cryptographic algorithms designed for bits. Brief Description of the Drawings

[0025] Figure 1 is the search flow chart of the impossible Boomerang attack for bits of the present invention;

[0026] Figure 2 is a schematic diagram of the existing impossible Boomerang attack method. Detailed Embodiment

[0027] The following further describes the content of the present invention in conjunction with embodiments and drawings, but it is not a limitation of the present invention.

[0028] Embodiment

[0029] A new method for bit - oriented MILP impossible Boomerang attack, referring to Figure 1 , includes the following steps:

[0030] (1) Construct a bit - oriented impossible Boomerang distinguisher search model according to the block cipher algorithm;

[0031] According to the properties of the round function and the differential propagation law, perform bit - level modeling on the linear components, non - linear components such as S - boxes, and BCT contradiction points in the round function to form a complete impossible Boomerang distinguisher search model;

[0032] (2) Expand the distinguisher before and after, find the keys that need to be guessed corresponding to the positions of the active S - boxes, and construct a key - recovery model based on MILP;

[0033] (4) Take the overall time complexity T as the objective function, add the constraint of balancing the time complexity of each stage, and use Gurobi to solve the MILP model and return the result.

[0034] Furthermore, for the block cipher algorithm described in step (1), assume that each round of iteration of the block cipher passes through m S-boxes, and the size of each S-box is 4 bits, then the total length is n = 4m bits. The contradiction position of the impossible Boomerang distinguisher is at the pd round. If the distinguisher has a total of r 2 rounds, xi,j (0 ≤ i ≤ r 2 -1, 0 ≤ j ≤ n - 1) represents the difference value of the j-th bit in the i-th round of the distinguisher;

[0035] For bit-level modeling, since there are only 3 cases for the specific bit difference, namely the difference value is 0, the difference value is 1, and any value, only 2-bit auxiliary variables z i,j and k i,j can represent the 3 difference states of 1 bit;

[0036] z i,j = 1 indicates that the bit difference is 0, and k i,j = 1 indicates that the bit difference is known. Therefore,

[0037] when z i,j = 1 and k i,j = 1, the bit difference is 0;

[0038] when z i,j = 0 and k i,j = 1, the bit difference is 1;

[0039] when z i,j = 0 and k i,j = 0, the bit difference takes any value.

[0040] Referring to Figure 1 , the specific steps for constructing the search model of the impossible Boomerang distinguisher for bits described in step (1) are as follows:

[0041] (1.1) Construct the constraint description between the difference and the auxiliary variables for bits:

[0042] For each 1-bit difference in the round function of the block cipher algorithm, 2-bit auxiliary variables z i,j and k i,j are used to describe the difference propagation. For example, linear operations or non-linear operations in S-boxes, P permutations, row shifts, column confusions, and key scheduling are all described in this way;

[0043] The bit difference x i,j (0 ≤ i ≤ r 2-1, 0 ≤ j ≤ n - 1) and the auxiliary variable z i,j , k i,j The corresponding relationship and specific values with the auxiliary variable z and k are shown in Formula 1 as follows:

[0044]

[0045] (1.2) Characterizing the differential propagation of the S-box in terms of bits:

[0046] When differential propagation passes through the S-box, the characteristics of differential propagation are as follows: when the input difference is 0, the output difference is always 0; when the input difference is not 0, the output difference is not 0; when the input difference is non-zero and not fixed, the output difference is also non-zero and not fixed; when the input difference is any value, the output difference is also any value;

[0047] Let and represent the 4-bit input and output bits corresponding to the l-th S-box in the i-th round;

[0048] Suppose the propagation point set of the 4-bit S-box is:

[0049]

[0050] Since the S-box design methods and S-box values of different cryptographic algorithms are different, the S-boxes of different algorithms need to be analyzed specifically;

[0051] Represent all possible propagation cases of the 4-bit S-box with the above point set and input it into SageMath, then the coefficient matrix M of the S-box can be obtained i,j (i is the number of inequalities, the dimension of j is 16 points in the above point set, j = 16) and the constant column vector C 1 (C 1 has a dimension of 16 points in the above point set, rows(C 1 ) = 16), then the corresponding MILP constraints are shown in Formula 2:

[0052]

[0053] When the S-box is bijective, the way of characterizing propagation is the same as (1.2). When it is necessary to characterize the propagation of the S-box for the differential, from propagating to the constraints are the same as Formula 2, and only the column vectors need to be swapped;

[0054] (1.3) Characterizing the differential propagation of the XOR operation in terms of bits:

[0055] When two differentials perform an XOR operation, when two input differentials of 0 are XORed, the output differential must be 0;

[0056] When two non-zero input differences are XORed differentially, the output difference is 0 when they are equal, and non-zero when they are not equal;

[0057] When the two input differences are both specific difference values, the output difference correspondingly is also a specific value;

[0058] According to the fact that 1-bit difference is represented by 2-bit auxiliary variables in (1.1), so use and to represent the input difference of the j-th bit in the i-th round, represents the output difference of its XOR operation, then the MILP constraint is characterized as shown in Formula 3:

[0059]

[0060] (1.4) Construct the constraints of the pull-wire type linear permutation layer:

[0061] When the difference passes through the linear permutation layer of the cryptographic algorithm, the difference states and difference values of the difference before input and the difference after output are exactly the same, and only a simple permutation operation is performed;

[0062] Let x i,j (0 ≤ i ≤ r 2 -1, 0 ≤ j ≤ n - 1) represent the difference value of the j-th bit in the i-th round of the distinguisher. After linear permutation, it is y i,j , and each bit difference is represented by the auxiliary variable z i,j , k i,j in Formula 1. Therefore, the MILP constraint for constructing the linear permutation layer is characterized as shown in Formula 4:

[0063]

[0064] (1.5) Construct the constraints of the bit-level contradiction points:

[0065] Suppose the contradiction position is in the l-th (0 ≤ l ≤ m - 1) S-box in the pd-th round. The contradiction condition of this S-box needs to pass through the contradiction of the BCT lookup table item;

[0066] Let the 4-bit input difference of the l-th S-box in the pd-th round of the upper difference be represented by the auxiliary variable in Formula 1 as and the output difference of the l-th S-box in the pd-th round of the lower difference( The superscripts U x and D y represent the upper difference and the lower difference respectively) form a contradiction. Considering all the contradictory situations in the BCT table, only when the 4-bit differences in both the upper and lower difference paths are non-zero and known, it is possible to form a contradiction at this time, corresponding to z i,j = 0, k i,j = 1 in Formula 1;

[0067] When all 4-bit differential states are non-zero and known, that is and can only be 1. According to formula 1, k i,j = 1 indicates that the difference of this bit has a known difference. When the values of the upper and lower 4-bit differences in the corresponding entry in the BCT in the table are 0, it means that the upper and lower differences form a contradiction here;

[0068] At this time, it is represented by w i (0 ≤ i ≤ m - 1), where w i = 1 indicates a contradiction, and w i = 0 indicates no contradiction;

[0069] The set of points at the contradiction is:

[0070]

[0071] Input all the cases in the BCT table, such as the sets of points for contradiction and non-contradiction cases, into SageMath, and the coefficient matrix N i,j (i is the number of inequalities, the dimension of j is 17 points in the above contradiction point set, j = 17) and the constant column vector C 2 (C 2 has a dimension of 17 points in the above contradiction point set, rows(C 2 ) = 17). Therefore, the MILP constraint description of the contradiction points to construct contradiction points is as shown in formula 5:

[0072]

[0073] Furthermore, in step (2), the distinguisher is extended before and after to find the keys that need to be guessed corresponding to the positions of the active S-boxes, and a key recovery model based on MILP is constructed. The specific steps are as follows:

[0074] (2.1) Determine the number of rounds r 1 and r 3 for extending the distinguisher before and after, and mark whether the input and output differences of the S-boxes are fixed;

[0075] First, according to the extension rules, extend the distinguisher by r 1 and r 3 rounds. Through the positions of the active S-boxes in the extended rounds, when the internal state passes through the S-boxes, one input may correspond to multiple outputs. At this time, the output bits cannot be represented by "0" or "1", and are represented by "*" at this time;

[0076] Use fix_x i,j [k](0 ≤ i ≤ r 3, 0 ≤ j ≤ m - 1, 0 ≤ k ≤ 3) indicates whether the k-th input bit of the j-th S-box in the i-th round of the up and down expansion rounds is fixed. If this bit is "*", then fix_x i,j [k] = 0 indicates that the bit difference is not fixed; if this bit is "0" or "1", then fix_x i,j [k] = 1 indicates that the bit difference is fixed;

[0077] (2.2) Construct a key recovery model for the expansion rounds. When guessing the sub-keys involved in the S-boxes, the output differences of the S-boxes can be determined, and the filtering bits of different S-boxes can be counted;

[0078] Use the binary variable know_x i,j [k](0 ≤ i ≤ r 3 , 0 ≤ j ≤ m - 1, 0 ≤ k ≤ 3) indicates whether the k-th input bit of the j-th S-box in the i-th round of the up and down expansion rounds is known. If this bit is guessed, then know_x i,j [k] = 1 indicates that this plaintext bit is known;

[0079] Use filter_x i,j (0 ≤ i ≤ r 3 , 0 ≤ j ≤ m - 1) to represent the filtering situation of the j-th S-box in the i-th round of the up and down expansion rounds. filter_x i,j represents the number of filtering bits of this S-box;

[0080] Assume a 4-bit S-box and guess 2-bit sub-key gk i [k](0 ≤ i ≤ r 3 , 0 ≤ k ≤ 1), the output know_y of the S-box can be obtained i,j [k](0 ≤ i ≤ r 3 , 0 ≤ j ≤ m - 1, 0 ≤ k ≤ 3). From this, it can be seen that only when the 4-bit input and the 2-bit sub-key are both guessed, the 4-bit output of the S-box is known. Input all possible point sets into SageMath, and 10 constraints characterizing the guess propagation of the S-box can be obtained, as shown in Equation 6. The last 3 constraints indicate that if know_y i,j [0] is known, then the situations of know_y i,j [1, 2, 3] are also known;

[0081]

[0082] i,j Assume that after expanding a 4-bit S-box from bottom to top, the input is y: "000*" → x: "****". Then use filter_x

[0083] the filtering bits of this S-box can be obtained:

[0084] That is, it means that the S-box can filter 3 bits;

[0085] The filtered bits of the S-box obtained in the i-th round can be obtained by adding the following formula, where the variable c is a constant representing the c-th S-box (0 ≤ c ≤ m - 1) as shown in Formula 7:

[0086] m.addConstr(filter_x i,j == know_y i,j ×(fix_y i,j .sum(c, '*') - fix_x i,j .sum(c, '*'))

[0087] (Formula 7).

[0088] In the key recovery model, according to the selected impossible Boomerang key recovery algorithm, the time for partial encryption and decryption of T 1 , and the time required for constructing differential pairs of T 2 , and the generation and filtering of quadruples of T 3 , as well as the calculation of the time for exhaustive search of T 4 are all put into the model.

[0089] Furthermore, in step (3), the overall time complexity T is set as the objective function, and the optimal impossible Boomerang attack under the given impossible Boomerang distinguisher is solved using the Gurobi solver. The specific steps are as follows;

[0090] (3.1) Set the overall time complexity T as the objective function and let T balance the complexity of each stage during the attack;

[0091] According to the expansion rules described in step (2), and using the distinguisher searched in step (1), expand r 1 and r 3 rounds forward and backward respectively, and calculate the time complexity T 1 , T 2 , T 3 , T 4 of each stage in the model. To balance the time complexity of each stage and prevent the time complexity of a certain step from being too high, Formula 8 is needed for balancing.

[0092]

[0093] And take the overall time complexity as the objective function, as shown in Formula 9:

[0094] Minimize T (Formula 9);

[0095] (3.2) Solving the MILP model with Gurobi:

[0096] The solution of the model can be obtained by solving it with the Gurobi solver, and the impossible Boomerang attack with the optimal attack parameters can be obtained under the given impossible Boomerang distinguisher.

[0097] If the MILP model is successfully solved, the Gurobi solver will return the result, that is, the minimum overall time complexity after balancing the time complexity of each stage.

[0098] The present invention proposes a new method for bit-oriented MILP impossible Boomerang attack. This method aims at the block cipher algorithm based on 4-bit S-box, constructs bit-level differential propagation constraints for its linear and non-linear components, constructs contradictions with the BCT table, and can search for multiple impossible Boomerang distinguishers with different contradiction points in the same round. After searching for the impossible Boomerang distinguisher of the bit-oriented designed cipher algorithm, it is extended forward and backward, and a key recovery model is further constructed. With the overall time complexity as the objective function and adding relevant constraints to balance the complexity of each stage, the minimum overall attack time complexity of the model can be solved.

Claims

1. A new bit-oriented MILP impossible Boomerang attack method, characterized by: The steps include: (1) Based on the block cipher algorithm, a bit-oriented impossible Boomerang discriminator search model is constructed; according to the properties of the round function and the differential propagation law, the linear components in the round function, the nonlinear components of the S-box, and the BCT contradiction points are modeled at the bit level to form a complete impossible Boomerang discriminator search model; (2) Expand the discriminator forward and backward to find the key that needs to be guessed corresponding to the active S-box position, and build a key recovery model based on MILP; (3) Take the overall time complexity T as the objective function, add constraints to balance the time complexity of each stage, and use Gurobi to solve the MILP model and return the result.

2. The new bit-oriented MILP impossible Boomerang attack method according to claim 1, characterized in that: The step (1) of constructing a bit-oriented impossible Boomerang distinguisher search model includes the following specific steps: (1.1) Bit-oriented construction of differences and constraint characterization between auxiliary variables: Each 1-bit difference in the round function of the block cipher algorithm uses a 2-bit auxiliary variable z i,j , k i,j To characterize differential propagation, such as S-box, P permutation, row shift, column confusion, linear operations or nonlinear operations in key scheduling are all characterized in this way; Bit Difference x i,j , 0≤i≤r2-1,0≤j≤n-1, and auxiliary variable z i,j , k i,j The corresponding relationship and specific value of are shown in Formula 1: (1.2) Characterization of differential propagation for bit-oriented S-box construction: When differential propagation passes through the S-box, the characteristics of differential propagation are that when the input differential is 0, the output differential is always equal to 0; when the input differential is not 0, the output differential is not 0; when the input differential is non-zero and not fixed, the output differential is also non-zero and not fixed; when the input differential is an arbitrary value, the output differential is also an arbitrary value; use and Represents the 4-bit input bits and output bits of the corresponding S-box of the l-th S-box in the i-th round, where 0≤i≤r2-1,0≤l≤m-1; Assume that the propagation point set of the 4-bit S-box is: Since the S-box design methods and S-box values ​​of different cryptographic algorithms are different, the S-boxes of different algorithms need to be analyzed specifically; Represent all possible propagation situations of the 4-bit S-box with the above point set and input it into SageMath to obtain the coefficient matrix M of the S-box i,j , i is the number of inequalities, j has a dimension of 16 points in the above point set, j = 16, and a constant column vector C1, C1 has a dimension of 16 points in the above point set, rows(C1) = 16, then the corresponding MILP constraints are shown in Formula 2: When the S-box is bijective, the propagation is described in the same way as (1.2). When the differential S-box propagation needs to be described, we can start from Spread to The constraints are the same as in formula 2, except that the column vectors are swapped front to back; (1.3) Characterization of differential propagation for bit-oriented XOR operation: When two differentials are XORed, when two zero input differentials are XORed, the output differential must be 0; when two non-zero input differentials are XORed, the output differential is 0 when the two are equal, and non-zero when the two are not equal; When both input differences are specific differential values, the output difference is also a specific value; According to (1.1), the 1-bit difference is represented by a 2-bit auxiliary variable, so and represents the input difference of the jth bit in the i-th round, where 0≤i≤r2-1,0≤j≤n-1, represents the output difference of its XOR operation, then the MILP constraint characterization is shown in Formula 3: (1.4) Constraints for constructing a pull-type linear permutation layer: When the difference passes through the linear permutation layer of the cryptographic algorithm, the difference state and difference value before input and after output are exactly the same, and only a simple permutation operation is performed; Let x i,j Represents the difference value of the jth bit in the i-th round of the distinguisher, where 0≤i≤r2-1,0≤j≤n-1, and after linear permutation is y i,j Each bit difference uses the auxiliary variable z in formula 1 i,j ,k i,j Therefore, the MILP constraint characterization of the linear permutation layer is shown in Formula 4: (1.5) Constructing bit-level conflict constraints: Assume that the contradictory position is in the lth S-box of the pd round, 0≤l≤m-1, and the contradictory condition of the S-box needs to be checked through the BCT table item contradiction; Assume that the 4-bit input difference of the lth S-box in the upper differential pd round is expressed by the auxiliary variable in formula 1 as The output difference with the lth S box of the lower differential pd wheel Constitute a contradiction, where the superscript U x and D y Respectively represent the upper difference and the lower difference, and consider all the contradictions in the BCT table. Only when the 4-bit differences in the upper and lower differential paths are all known to be non-zero, a contradiction may be formed at this time, corresponding to z in formula 1 i,j =0,k i,j =1; When the 4-bit differential states are all non-zero, that is, and can only be 1, where 0≤i≤3; according to formula 1, k i,j =1 indicates that the difference of this bit has a known difference. When the entry in the BCT table of the upper and lower difference 4 bits is 0, it indicates that the upper and lower differences are contradictory. At this time, use w i It means, 0≤i≤m-1, where w i =1 indicates a contradiction, w i =0 means no contradiction; The point set used for the contradiction is: Input all BCT table items, such as the contradictory and non-contradictory point sets, into SageMath to obtain the coefficient matrix N of the linear inequality. i,j And the constant column vector C2, where i is the number of inequalities, the dimension of j is the 17 points in the above contradiction point set, j=17, the dimension of C2 is the 17 points in the above contradiction point set, rows(C2)=17, so the MILP constraint characterization of the contradiction point is constructed as shown in Formula 5:

3. The new bit-oriented MILP impossible Boomerang attack method according to claim 1, characterized in that: Step (2) expands the distinguisher forward and backward to find the key that needs to be guessed corresponding to the active S-box position, and constructs a key recovery model based on MILP. The specific steps are as follows: (2.1) Determine the forward and backward expansion of the discriminator by r1 and r3 rounds, and mark whether the input difference and output difference of the S-box are fixed; first, according to the expansion rule, the discriminator is expanded by r1 and r3 rounds, and the active S-box position of the expansion round is passed. When the internal state passes through the S-box, one input may correspond to multiple outputs. At this time, the output bit cannot be represented by "0" or "1", and is represented by "*"; Use fix_x i,j [k], 0≤i≤r3, 0≤j≤m-1, 0≤k≤3, indicates whether the k-th input bit of the j-th S-box in the i-th round in the upper and lower expansion rounds is fixed. If the bit is "*", then fix_x i,j [k] = 0 means that the bit difference is not fixed; if the bit is "0" or "1", then fix_x i,j [k] = 1 means that the bit difference is fixed; (2.2) Construct a key recovery model for the expansion round. When guessing the subkey involved in the S-box, the output difference of the S-box can be determined and the filtered bits of different S-boxes can be counted; Using the binary variable know_x i,j [k], 0≤i≤r3, 0≤j≤m-1, 0≤k≤3, indicates whether the k-th input bit of the j-th S-box in the i-th round of the upper and lower expansion rounds is known. If the bit is guessed, then know_x i,j [k] = 1 means that the plaintext bit is known; Use filter_x i,j , 0≤i≤r3,0≤j≤m-1, represents the filtering of the jth S-box in the i-th round in the upper and lower expansion rounds, filter_x i,j Indicates the number of bits filtered by the S-box; Assume a 4-bit S-box and guess the 2-bit subkey gk i [k], 0≤i≤r3, 0≤k≤1, we can get the output of S-box know_y i,j [k], 0≤i≤r3,0≤j≤m-1,0≤k≤3. It can be seen that the 4-bit S-box output is known only when the 4-bit input and the 2-bit subkey are guessed. By inputting all possible point sets into SageMath, we can get 10 constraints that characterize the propagation of S-box guesses, as shown in Formula 6. The last three constraints represent know_y i,j [0] is known, then know_y i,j [1,2,3] The situation is also known; Assume that a 4-bit S-box is expanded from bottom to top to input y:"000*"→x:"****", then use filter_x i,j The filter bits of the S-box can be obtained: This means that the S-box can filter 3 bits; The following formula can be added to obtain the S-box filtering bits obtained in the i-th round, where the variable c is a constant, representing the c-th S-box, 0≤c≤m-1, as shown in Formula 7: m.addConstr(filter_x i,j ==know_y i,j ×(fix_y i,j .sum(c,'*')-fix_x i,j .sum(c,'*')) (Formula 7).

4. The new bit-oriented MILP impossible Boomerang attack method according to claim 1, characterized in that: Furthermore, in step (3), the overall time complexity T is set as the objective function, and the Gurobi solver is used to solve the optimal impossible Boomerang attack under the given impossible Boomerang discriminator. The specific steps are as follows; (3.1) Set the overall time complexity T as the objective function and let T balance the complexity of each stage during the attack; According to the expansion rules described in step (2), the distinguisher searched in step (1) is used to expand forward and backward by r1 and r3 rounds respectively, and the time complexity T1, T2, T3, and T4 of each stage are calculated in the model. In order to balance the time complexity of each stage and prevent the time complexity of a certain step from being too high, formula 8 is needed to balance. And the overall time complexity is used as the objective function, as shown in Formula 9: Minimize T(Formula 9); (3.2) Gurobi solves the MILP model: The solution of the model can be obtained by using the Gurobi solver, and the impossible Boomerang attack with the optimal attack parameters under a given impossible Boomerang discriminator can be obtained; If the MILP model is solved successfully, the Gurobi solver will return the result, which is the minimum overall time complexity after balancing the time complexity of each stage.