Method and device for acquiring secret key, electronic equipment and storage medium
By using qubit superposition state and Grover iterative algorithms in quantum computing, the problem of high complexity in obtaining keys in the prior art is solved, and fast and efficient key acquisition is achieved.
Patent Information
- Application Number
- CN202510244042.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-30
AI Technical Summary
The method of obtaining keys in the prior art is complex, and it is difficult to effectively reduce the complexity of quantum attacks and the difficulty of obtaining keys.
By using n qubits to prepare the initial key superposition state, encrypting, phase flipping and decryption operations are performed, combined with the Grover iterative algorithm, the key search space is gradually reduced, and the key is finally obtained through measurement.
It effectively reduces the complexity of quantum attacks and the difficulty of obtaining keys, and realizes rapid calculation of obtaining keys corresponding to known ciphertext pairs.
Smart Images

Figure CN120074819A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of quantum computing technology, and in particular, to a method, apparatus, electronic device, and storage medium for obtaining a key. Background Art
[0002] In the process of data transmission, in order to ensure the security of data, corresponding encryption algorithms are usually used to encrypt the transmitted data (i.e., plaintext) to obtain ciphertext, and then the encrypted ciphertext is transmitted. There are many classical encryption algorithms, mainly including: symmetric encryption and asymmetric encryption. Among them, symmetric encryption algorithms such as the Advanced Encryption Standard (AES) have been widely applied in various technical fields to resist various known attack methods.
[0003] Most of the encryption algorithms in the prior art are based on mathematical problems to increase the complexity, the difficulty of breaking, and the time of the algorithm. Therefore, in the prior art, the method of exhaustive brute-force search (trying all possible key combinations) is usually used to crack to obtain the corresponding key. However, since the design pattern of the encryption algorithm can usually resist conventional attack schemes, the complexity of the method for obtaining the key is relatively high.
[0004] Since quantum computing was proposed in the 1980s, it has been widely studied and concerned. Due to the existence of quantum superposition and quantum entanglement, quantum computing has the advantage of parallelism. Using the quantum advantage for quantum algorithm design can accelerate the solution of some classical problems. Today, with the booming development of quantum computing technology, it is of great significance to determine the attack ability of quantum algorithms on classical symmetric encryption algorithms. However, the current attack schemes of quantum algorithms on classical symmetric encryption algorithms are relatively complex, and it is difficult to obtain the key. Summary of the Invention
[0005] In view of this, the present invention provides a method, apparatus, electronic device, and storage medium for obtaining a key, thereby effectively reducing the complexity of the attack and the difficulty of obtaining the key.
[0006] In a first aspect, an embodiment of the present invention provides a method for obtaining a key, the method including:
[0007] Preparing an initial key superposition state including all possible n-bit binary keys by using n quantum bits;
[0008] Performing an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state;
[0009] Performing a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state;
[0010] Perform a decryption operation on the current ciphertext superposition state and the initial key superposition state through an encrypted quantum circuit to obtain a marked key superposition state;
[0011] Perform a conditional phase flip operation on the marked key superposition state, use the key superposition state after the conditional phase flip operation as the current key superposition state, and increment the value of the iteration count by 1;
[0012] When the iteration count is less than a preset threshold, return to execute the step of performing an encryption operation on the current key superposition state and the known plaintext through an encrypted quantum circuit to obtain a ciphertext superposition state; otherwise, measure the current key superposition state to obtain a key corresponding to the known plaintext and ciphertext.
[0013] In a second aspect, an embodiment of the present invention provides an apparatus for obtaining a key. The apparatus for obtaining a key includes: a preparation unit, a calculation unit, and a measurement unit;
[0014] The preparation unit is configured to use n quantum bits to prepare an initial key superposition state including all possible n-bit binary keys, and output the initial key superposition state as the current key superposition state to the calculation unit;
[0015] The calculation unit is configured to perform an encryption operation on the current key superposition state and the known plaintext through an encrypted quantum circuit to obtain a ciphertext superposition state; perform a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state; perform a decryption operation on the current ciphertext superposition state and the initial key superposition state through an encrypted quantum circuit to obtain a marked key superposition state; perform a conditional phase flip operation on the marked key superposition state, use the key superposition state after the conditional phase flip operation as the current key superposition state, and increment the value of the iteration count by 1; when the iteration count is less than a preset threshold, return to execute the step of performing an encryption operation on the current key superposition state and the known plaintext through an encrypted quantum circuit to obtain a ciphertext superposition state; when the iteration count is equal to the preset threshold, output the current key superposition state to the measurement unit;
[0016] The measurement unit is configured to measure the current key superposition state to obtain a key corresponding to the known plaintext and ciphertext.
[0017] In a third aspect, an embodiment of the present invention further provides an electronic device, including a memory, a processor, a bus, and a computer program stored in the memory and executable on the processor. The processor, when executing the computer program, implements the steps of the method for obtaining a key as described in the first aspect.
[0018] Fourthly, an embodiment of the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the method for obtaining a key as described in the first aspect are implemented.
[0019] As can be seen from the above technical solutions, in the method, device, electronic device, and storage medium for obtaining a key in the present invention, since the current key superposition state and the known plaintext can be encrypted through an encrypted quantum circuit to obtain a ciphertext superposition state, then a phase flip operation is performed on the quantum state corresponding to the known ciphertext in the ciphertext superposition state, and the current ciphertext superposition state and the initial key superposition state are decrypted through an encrypted quantum circuit to obtain a marked key superposition state. Subsequently, a conditional phase flip operation is performed on the marked key superposition state, and the key superposition state after the conditional phase flip operation is used as the current key superposition state, thereby completing one Grover iteration operation. Therefore, after a preset number of Grover iteration operations, the current key superposition state can be measured, and thus the required key can be obtained. Therefore, the technical solution of the present application can use an encrypted quantum circuit to quickly calculate the key corresponding to a pair of known plaintext-ciphertext pairs based on a pair of known plaintext-ciphertext pairs, thereby effectively reducing the complexity of quantum attacks and the difficulty of obtaining keys. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1 It is a schematic flowchart of the method for obtaining a key in a specific embodiment of the present invention.
[0021] Figure 2 It is a schematic diagram of the principle of the method for obtaining a key in a specific embodiment of the present invention.
[0022] Figure 3 It is a schematic flowchart of step 102 in a specific embodiment of the present invention.
[0023] Figure 4 It is a schematic diagram of the encrypted quantum circuit in a specific embodiment of the present invention.
[0024] Figure 5 It is a schematic diagram of the sub-key quantum circuit in a specific embodiment of the present invention.
[0025] Figure 6 It is a schematic diagram of the third replacement quantum circuit SN in a specific embodiment of the present invention.
[0026] Figure 7 It is a schematic diagram of the second replacement quantum circuit SN” in a specific embodiment of the present invention.
[0027] Figure 8Schematic diagram of the first replacement quantum circuit SN' in a specific embodiment of the present invention.
[0028] Figure 9 Schematic diagram of the first inversion operation circuit IO1 in a specific embodiment of the present invention.
[0029] Figure 10 Schematic diagram of the second inversion operation circuit IO2 in a specific embodiment of the present invention.
[0030] Figure 11 Schematic diagram of the structure of the device for obtaining a key in a specific embodiment of the present invention.
[0031] Figure 12 Schematic diagram of the structure of an electronic device in a specific embodiment of the present invention. Detailed implementation manners
[0032] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.
[0033] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0034] Figure 1 Flow chart of the method for obtaining a key in an embodiment of the present invention. As Figure 1 shown, the method for obtaining a key in an embodiment of the present invention includes the following steps:
[0035] Step 101, preparing an initial key superposition state containing all possible n-bit binary keys using n qubits.
[0036] Assume that the required key is an n-bit binary key. Therefore, there are a total of N = 2 n possible n-bit binary keys. For example, if it is a 1-bit binary key, there are 2 (2 1 = 2) binary keys: 0 and 1; if it is a 2-bit binary key, there are 4 (2 2 = 4) binary keys: 00, 01, 10, and 11; and so on. Among them, n is a natural number.
[0037] Therefore, in the technical solution of this application, an initial key superposition state (the initial key superposition state is a uniform superposition state) containing the quantum states corresponding to all possible n-bit binary keys can be prepared by n qubits, and this initial key superposition state is used as the current key superposition state. In this initial key superposition state, each n-bit binary key corresponds to a quantum state of n qubits, and the probability amplitudes of the quantum states corresponding to each n-bit binary key are equal.
[0038] For example, assume n = 2, there are N = 2 2 = 4 binary keys: 00, 01, 10, and 11, which respectively correspond to 4 quantum states: |00>, |01>, |10>, |11>. Then the initial key superposition state that can be prepared using 2 qubits is: This initial key superposition state contains the 4 quantum states corresponding to all possible 2-bit binary keys. When n takes other values, it can be deduced by analogy, and will not be listed one by one here.
[0039] In addition, as an example, in a specific embodiment of this application, n qubits can be preset first, and the initial states of the n qubits are all in the ground state |0>; then, a Hadamard transformation is performed on the n qubits, and an initial key superposition state containing the quantum states corresponding to all possible n-bit binary keys can be obtained.
[0040] For example, as an example, in a specific embodiment of this application, a Hadamard gate can be used to implement the Hadamard transformation.
[0041] Step 102, encrypt the current key superposition state and the known plaintext through an encrypted quantum circuit to obtain a ciphertext superposition state.
[0042] In the technical solution of this application, if a key needs to be obtained, at least one pair of known plaintext-ciphertext pairs needs to be obtained first. The plaintext-ciphertext pair includes a known plaintext and a known ciphertext, and the known ciphertext is obtained by encrypting the known plaintext with the key to be obtained (i.e., the key corresponding to the known plaintext-ciphertext pair). Additionally, if the above-mentioned plaintext and ciphertext are not binary data, for the convenience of using quantum bits, the above-mentioned known plaintext and ciphertext can be converted into binary data and then the technical solution in this application can be used.
[0043] Additionally, in this step, through an encryption quantum circuit, the current key superposition state can be encrypted with the plaintext in the known plaintext-ciphertext pair to obtain a ciphertext superposition state. Since the current key superposition state contains the quantum states corresponding to all possible n-bit binary keys, according to the properties of quantum superposition states, after the above encryption operation, it is equivalent to encrypting the plaintext with each n-bit binary key respectively, so that the obtained ciphertext superposition state contains the quantum states corresponding to all possible ciphertexts.
[0044] Furthermore, in the technical solution of this application, according to the needs of the actual application scenario, an encryption quantum circuit corresponding to the encryption and decryption method can be preset to encrypt the current key superposition state with the plaintext in the known plaintext-ciphertext pair.
[0045] For example, as an example, in a specific embodiment of this application, the encryption quantum circuit can be an AES encryption quantum circuit, or a simplified advanced encryption standard (S-AES) encryption quantum circuit, or other suitable encryption quantum circuits for encryption.
[0046] Step 103: Perform a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state.
[0047] In the technical solution of this application, after obtaining the ciphertext superposition state, since the ciphertext superposition state contains the quantum state corresponding to the ciphertext in the known plaintext-ciphertext pair, a phase flip operation can be performed on the quantum state corresponding to the known ciphertext in the ciphertext superposition state in this step (equivalent to flipping the superposition state ciphertext according to the known ciphertext).
[0048] Since only the phase of this quantum state is flipped and the phases of other quantum states are not flipped, the quantum state corresponding to the known ciphertext can be distinguished from other quantum states in the ciphertext superposition state, which is equivalent to marking the quantum state corresponding to the known ciphertext.
[0049] Step 104: Perform a decryption operation on the current ciphertext superposition state and the initial key superposition state through an encryption quantum circuit to obtain a marked key superposition state.
[0050] In the technical solution of the present application, after the above-mentioned phase flipping operation is performed on the ciphertext superposition state, the current ciphertext superposition state (i.e., the ciphertext superposition state after the phase flipping operation) can be decrypted with the initial key superposition state through the above-mentioned encryption quantum circuit (i.e., the inverse operation of the encryption operation in step 102 above), to obtain the corresponding quantum superposition state. All possible quantum states corresponding to n-bit binary keys are still included in this quantum superposition state, but the quantum state corresponding to the key to be obtained has actually been marked (for example, compared with other quantum states, the quantum state corresponding to the key to be obtained has undergone a phase flip). Therefore, the quantum superposition state obtained after this step can be called the marked key superposition state.
[0051] It can be seen from this that the above steps 102 to 104 are equivalent to the marking (Oracle) operation or Oracle operator in Grover's algorithm (such as Figure 2 shown), so that the quantum state corresponding to the key to be obtained (i.e., the key corresponding to the known ciphertext-plaintext pair) can be distinguished from other quantum states in the marked key superposition state, which is equivalent to marking the quantum state corresponding to the key to be obtained.
[0052] Step 105, perform a conditional phase flipping operation on the marked key superposition state, use the key superposition state after the conditional phase flipping operation as the current key superposition state, and increment the value of the iteration count by 1.
[0053] In the technical solution of the present application, after obtaining the marked key superposition state, a conditional phase-shift operation needs to be performed on the marked key superposition state, and then, use the key superposition state after the conditional phase flipping operation as the current key superposition state; at the same time, the value of the iteration count also needs to be incremented by 1.
[0054] Through the above operations, the phase of the quantum state corresponding to the key to be obtained can be flipped, the amplitude of the quantum state corresponding to the key to be obtained can be increased, and the amplitudes of other quantum states can be decreased.
[0055] Therefore, the above steps 102 to 105 are equivalent to one Grover iteration operation or Grover iteration operator in Grover's algorithm (such as Figure 2 shown). So in step 105, the value of the iteration count also needs to be incremented by 1, indicating that one Grover iteration operation has been completed.
[0056] In addition, as an example, in a specific embodiment of the present application, the initial value of the iteration count can be set to 0, so that the value of the iteration count is equal to the number of completed Grover iteration operations.
[0057] Step 106, when the number of iterations is less than a preset threshold, return to execute Step 102; otherwise, execute Step 107.
[0058] In this step, it is necessary to judge the magnitude relationship between the number of iterations and the preset threshold. If the number of iterations is less than the preset threshold, it means that another round of iterative operation is required, so return to execute Step 102; if the number of iterations is equal to or greater than the preset threshold, it means that the necessary number of iterations has been completed, and thus the subsequent Step 107 will be executed.
[0059] In addition, as an example, in a specific embodiment of the present application, when the required key to be obtained is a 16-bit binary key, the preset threshold is 64π.
[0060] Step 107, measure the current key superposition state to obtain the key corresponding to the known plaintext and ciphertext.
[0061] In this step, the current key superposition state obtained after executing Step 105 can be measured. After the current key superposition state collapses, the corresponding measurement result can be obtained, and this measurement result can be used as the key corresponding to the known plaintext and ciphertext.
[0062] Therefore, through the above Steps 101 to 107, according to a pair of known plaintext-ciphertext pairs, the key corresponding to the known plaintext-ciphertext pair can be quickly calculated using the encryption quantum circuit.
[0063] In addition, in the technical solution of the present application, multiple specific implementation manners can be used to implement the above method for obtaining the key. The following will take one or more of the specific implementation manners as examples to introduce the technical solution of the present application in detail.
[0064] In the technical solution of the present application, the corresponding encryption quantum circuit can be set according to different encryption methods.
[0065] The following will take the encryption method S-AES as an example to introduce the corresponding encryption quantum circuit.
[0066] For example, as an example, as Figure 3 shown, in a specific embodiment of the present application, when the encryption method is S-AES, Step 102 may further include the following steps:
[0067] Step 21, set an encryption quantum circuit with 32 qubits and make the quantum states of the first 16 qubits be the initial key superposition state.
[0068] When using S - AES as the encryption method, since the key of S - AES is a 16 - bit binary key, in the technical solution of this application, an encryption quantum circuit with 32 qubits will be set up (for example, as Figure 4 shown, where |K 0 >, |K 1 >, |K 2 > and |K 3 > are the first 16 qubits, and 4 are the last 16 qubits), and then make the quantum state of the first 16 qubits the initial key superposition state.
[0069] For example, as an example, in a specific embodiment of this application, making the quantum state of the first 16 qubits the initial key superposition state can be: inputting the 16 - bit initial key superposition state generated in step 101 to the first 16 qubits of the encryption quantum circuit; or, it can also be directly using the first 16 qubits to prepare the initial key superposition state containing all possible 16 - bit binary keys (equivalent to performing step 101 above on the first 16 qubits of this encryption quantum circuit).
[0070] In addition, as an example, in a specific embodiment of this application, the initial quantum state of the 32 qubits of the encryption quantum circuit can be preset to the ground state (for example, the |0> state).
[0071] Step 22, encode the known plaintext onto the first 16 qubits.
[0072] Since in the S - AES encryption method, the known plaintext is 16 - bit binary data, in this step, the plaintext in the known plaintext - ciphertext pair can be directly encoded onto the first 16 qubits, thus equivalent to performing the first round key addition (AddRoundKey) operation using the initial key superposition state on the first 16 qubits as the key.
[0073] For example, as an example, in a specific embodiment of this application, the known plaintext can be XOR - operated bit - by - bit with the initial key superposition state on the first 16 qubits, so that the known plaintext can be encoded onto the first 16 qubits.
[0074] For example, as an example, as Figure 4 shown, in a specific embodiment of this application, the above step 22 can be implemented through Figure 4 the first encoding circuit P from the left in
[0075] Step 23, perform a byte substitution operation on the quantum states of the first 16 qubits through the first replacement quantum circuit, and store the operation result on the last 16 qubits according to the row displacement rule.
[0076] In the technical solution of this application, multiple first replacement quantum circuits can be used to perform the first round of byte substitution (SubBytes) operation on the quantum states of the first 16 qubits; then, the operation result after the first round of byte substitution operation is stored in a staggered manner on the last 16 qubits. When performing the above storage operation, the storage operation will be performed according to the row displacement (ShiftRows) rule, so it is equivalent to performing a row displacement operation.
[0077] For example, as an example, as Figure 4 shown, in a specific embodiment of this application, the above step 23 can be implemented by the 4 first replacement quantum circuits SN' in Figure 4
[0078] Step 24, perform a column mixing operation on the quantum states of the last 16 qubits through the column mixing quantum circuit.
[0079] In the technical solution of this application, a column mixing quantum circuit can be used to perform a column mixing (MixColumns) operation on the quantum states of the last 16 qubits.
[0080] For example, as an example, as Figure 4 shown, in a specific embodiment of this application, the above step 24 can be implemented by the 2 column mixing quantum circuits MC in Figure 4
[0081] Step 25, perform an exclusive OR operation on the known plaintext bit by bit with the quantum states of the first 16 qubits.
[0082] In this step, the known plaintext will be again exclusive ORed bit by bit with the quantum states of the first 16 qubits. Through two exclusive OR operations, the quantum states of the first 16 qubits can be restored to the initial key superposition state.
[0083] For example, as an example, as Figure 4 shown, in a specific embodiment of this application, the above step 25 can be implemented by the second encoding circuit P from the left in Figure 4
[0084] Step 26, perform a sub-key generation operation on the quantum states of the first 16 qubits through the sub-key quantum circuit.
[0085] In the technical solution of the present application, a sub-key quantum circuit can be used to perform a sub-key generation operation on the quantum states of the first 16 qubits, so as to generate a first sub-key state on the first 16 qubits.
[0086] For example, as an example, as Figure 4 shown, in a specific embodiment of the present application, the above step 26 can be implemented by the sub-key quantum circuit in the first virtual box from the left in Figure 4
[0087] Step 27, perform an exclusive OR operation on the first 16 qubits and the last 16 qubits, and store the operation result on the last 16 qubits.
[0088] In the technical solution of the present application, the first 16 qubits and the last 16 qubits can be subjected to an exclusive OR operation, and then the operation result is stored on the last 16 qubits, so as to equivalently perform a second round key addition operation on the quantum states of the last 16 qubits using the first sub-key state on the first 16 qubits.
[0089] For example, as an example, as Figure 4 shown, in a specific embodiment of the present application, the above step 27 can be implemented by the 4 exclusive OR operation circuits after the first virtual box from the left in Figure 4
[0090] Step 28, perform a sub-key generation operation on the quantum states of the first 16 qubits through a sub-key quantum circuit.
[0091] In the technical solution of the present application, a sub-key quantum circuit can be used to perform a sub-key generation operation on the quantum states of the first 16 qubits again, so as to generate a second sub-key state on the first 16 qubits.
[0092] For example, as an example, as Figure 4 shown, in a specific embodiment of the present application, the above step 28 can be implemented by the sub-key quantum circuit in the second virtual box from the left in Figure 4
[0093] Step 29, perform a byte substitution operation on the quantum states of the last 16 qubits through a second substitution quantum circuit, perform an exclusive OR operation on the operation result and the second sub-key state on the first 16 qubits, and store the final operation result on the first 16 qubits according to the row shift rule.
[0094] In the technical solution of the present application, a second replacement quantum circuit can be used to perform a second-round byte replacement operation on the quantum states of the last 16 qubits; then, the operation result after the second-round byte replacement operation is XORed with the second sub-key state on the first 16 qubits, and the final operation result is stored on the first 16 qubits in a misaligned manner according to the row shift rule.
[0095] Therefore, in step 29 above, it is equivalent to performing a second-round byte replacement operation, a row shift operation, and a third-round key addition operation.
[0096] After performing the above operations, it is equivalent to completing an S-AES encryption process, and the quantum state on the first 16 qubits will become a ciphertext superposition state.
[0097] For example, as an example, as Figure 4 shown, in a specific embodiment of the present application, the above step 29 can be implemented by Figure 4 the 4 second replacement quantum circuits SN” in
[0098] Therefore, through the above steps 21 to 29, the current key superposition state and the known plaintext can be encrypted through an encryption quantum circuit to obtain a ciphertext superposition state.
[0099] In addition, in the technical solution of the present application, a variety of specific implementation methods can be used to implement the above encryption quantum circuit. One or more of the following specific implementation methods will be used as examples to introduce the technical solution of the present application in detail.
[0100] For example, as an example, as Figure 5 shown, in a specific embodiment of the present application, the sub-key quantum circuit may include: two third replacement quantum circuits SN, a first XOR circuit RC1, and a second XOR circuit;
[0101] Among them, one third replacement quantum circuit SN is used to perform a byte replacement operation on the 5th to 12th qubits; the other third replacement quantum circuit SN is used to perform a byte replacement operation on the 1st to 4th, 13th to 16th qubits;
[0102] The first XOR circuit RC1 is used to perform an XOR operation on the 1st to 8th qubits;
[0103] The second XOR circuit is used to perform an XOR operation on the 1st to 4th, 9th to 12th qubits, and perform an XOR operation on the 5th to 8th, 13th to 16th qubits.
[0104] In addition, in the technical solution of the present application, a variety of specific implementation methods can be used to implement the above third replacement quantum circuit SN.
[0105] For example, as an illustration, such as Figure 6 shown, in a specific embodiment of the present application, the third replacement quantum circuit SN may include: a first mapping circuit PN, a second mapping circuit PN -1 , a first inverse operation circuit IO, a first combination circuit NPA, and a second combination circuit NPA -1* ;
[0106] The output end of the first mapping circuit PN is connected to the first input end of the first inverse operation circuit IO;
[0107] The second combination circuit NPA -1* 's output end is connected to the second input end of the first inverse operation circuit IO1;
[0108] The first output end of the first inverse operation circuit IO1 is connected to the input end of the second mapping circuit PN -1 ;
[0109] The second output end of the first inverse operation circuit IO1 is connected to the input end of the first NPA circuit;
[0110] The first mapping circuit PN is a mapping circuit from the polynomial basis to the standard basis;
[0111] The second mapping circuit PN -1 is a mapping circuit from the standard basis to the polynomial basis;
[0112] The first inverse operation circuit IO1 is used to perform an inversion operation in a finite field;
[0113] The first combination circuit NPA is a combined circuit of a mapping from the standard basis to the polynomial basis and an affine transformation;
[0114] The second combination circuit NPA -1* is a combined circuit of a mapping from the polynomial basis to the standard basis and an affine transformation.
[0115] In addition, in the technical solution of the present application, the second mapping circuit PN -1 is equivalent to the inverse operation of the first mapping circuit PN; the second combination circuit NPA -1* is equivalent to the inverse operation of the first combination circuit NPA, and the second combination circuit NPA -1* does not include two X gates.
[0116] In addition, in the technical solution of the present application, multiple specific implementation manners can be used to implement the above-mentioned second replacement quantum circuit SN.
[0117] For example, as an illustration, such asFigure 7 As shown, in a specific embodiment of the present application, the second replacement quantum circuit SN” may include: a first mapping circuit PN, a first inverse operation circuit IO1, a first combination circuit NPA, and a second combination circuit NPA -1* ;
[0118] The output end of the first mapping circuit PN is connected to the first input end of the first inverse operation circuit IO1;
[0119] The second combination circuit NPA -1* The output end of is connected to the second input end of the first inverse operation circuit IO1;
[0120] The second output end of the first inverse operation circuit IO1 is connected to the input end of the first combination circuit NPA.
[0121] In the technical solution of the present application, since the quantum state on the last 16 qubits will not be used in the subsequent process after operating with the second replacement quantum circuit SN”, there is no need to worry about whether the quantum state on the last 16 qubits will be changed when using the second replacement quantum circuit SN”. Therefore, compared with the third replacement quantum circuit SN in the previous specific embodiment, the second replacement quantum circuit SN” in this specific embodiment does not set the second mapping circuit PN -1 , thereby effectively saving the used quantum gates and reducing the circuit cost.
[0122] In addition, in the technical solution of the present application, multiple specific implementation manners can be used to implement the above-mentioned first inverse operation circuit IO1.
[0123] When using the third replacement quantum circuit SN or the second replacement quantum circuit SN”, the initial quantum state on the output qubit is arbitrary, so the circuit design is relatively complex.
[0124] For example, as an example, in a specific embodiment of the present application, the mathematical expression corresponding to the first inverse operation circuit IO1 can be expressed as follows:
[0125] x 2 =x 2 +x 1 ×x 4 y 2 =y 2 +x 2 ×x 3 y 4 =y 4 +x 2
[0126] y 3 =y 3+x 2 y 1 =y 1 +x 2 x 2 =x 2 +x 1 ×x 4
[0127] x 4 =x 4 +x 1 ×x 3 y 4 =y 4 +x 2 ×x 4 y 4 =y 4 +x 4
[0128] y 1 =y 1 +x 4 y 2 =y 2 +x 4 x 4 =x 4 +x 1 ×x 3
[0129] x 1 =x 1 +x 2 ×x 3 y 1 =y 1 +x 1 ×x 4 y 1 =y 1 +x 1
[0130] x 1 =x 1 +x 2 ×x 3 x 3 =x 3 +x 2 ×x 4 y 3 =y 3 +x 1 ×x 3
[0131] y 2 =y 2 +x 3 x 3 =x 3 +x 2 ×x4 y 1 = y 1 + x 1
[0132] y 1 = y 1 + x 2 y 1 = y 1 + x 3 y 2 = y 2 + x 3
[0133] y 3 = y 3 + x 1 y 4 = y 4 + x 4 ;
[0134] One-to-one correspondence is carried out for the second-order terms and third-order terms in the above mathematical expressions as follows, with one set of correspondences implemented each time:
[0135] x 1 x 4→ x 1 x 3 x 4
[0136] x 1 x 3→ x 1 x 2 x 3
[0137] x 2 x 3→ x 2 x 3 x 4
[0138] x 2 x 4→ x 1 x 2 x 4 。
[0139] For another example, as an illustration, in a specific embodiment of the present application, the specific quantum circuit diagram of the first inverse operation circuit IO1 can be as Figure 9 shown.
[0140] In addition, in the technical solution of the present application, multiple specific implementation manners can be used to implement the above-mentioned first replacement quantum circuit SN'.
[0141] For example, as an illustration, as Figure 8As shown, in a specific embodiment of the present application, the first replacement quantum circuit SN' may include: a first mapping circuit PN, a second mapping circuit PN -1 , a second inversion operation circuit IO2, and a first combination circuit NPA;
[0142] The output end of the first mapping circuit PN is connected to the first input end of the second inversion operation circuit IO2;
[0143] The first output end of the second inversion operation circuit IO2 is connected to the input end of the second mapping circuit PN -1 ;
[0144] The second output end of the second inversion operation circuit IO2 is connected to the input end of the first NPA circuit;
[0145] The second inversion operation circuit IO2 is used to perform an inversion operation (InversionOperation) in a finite field.
[0146] In the technical solution of the present application, since when the first replacement quantum circuit SN' is used for operation, the quantum state on the output qubit is the initial |0> state and there is no need to perform mapping and affine transformation from the polynomial basis to the standard basis. Therefore, compared with the third replacement quantum circuit SN in the above specific embodiment, the second combination circuit NPA is not provided in the first replacement quantum circuit SN' in this specific embodiment -1* , thereby effectively saving the used quantum gates and reducing the circuit cost.
[0147] In addition, compared with the first inversion operation circuit IO1 in the third replacement quantum circuit SN in the above specific embodiment, the second inversion operation circuit IO2 in the first replacement quantum circuit SN' in this specific embodiment can also be simplified, thereby also saving the used quantum gates and reducing the circuit cost.
[0148] In addition, in the technical solution of the present application, multiple specific implementation manners can be used to implement the above-mentioned second inversion operation circuit IO2.
[0149] When the first replacement quantum circuit SN' is used, the initial quantum state on the output qubit is state, so the circuit design can be relatively simple.
[0150] For example, as an example, in a specific embodiment of the present application, the mathematical expression corresponding to the second inversion operation circuit IO2 can be expressed as follows:
[0151] x 2 =x 1 +x 2 y 3 =x1 ×x 3 x 4 =y 4 +x 4
[0152] y 4 =x 2 ×x 4 x 2 =x 1 +x 2 x 4 =y 3 +x 4
[0153] y 4 =x 2 +y 4 x 3 =x 3 +x 4 x 2 =y 3 +x 2
[0154] y 2 =x 2 ×x 3 x 2 =y 3 +x 2 y 2 =x 2 ×x 3
[0155] x 2 =y 3 +x 2 y 2 =y 2 +x 4 x 3 =x 4 +x 3
[0156] x 3 =x 3 +y 2 y 2 =y 2 +y 3 +x 4 y 1 =x 4 ×y 2
[0157] x 4 =y 3 +x 4 y 2 =y 2 +x 4y 1 = x 4 + y 1
[0158] y 3 = x 4 + y 3 y 3 = y 3 + y 1 × y 4 y 3 = y 3 + x 1 + x 2
[0159] y 1 = y 1 + x 4 y 1 = y 1 + x 3 x 3 = x 3 + y 2
[0160] x 4 = x 4 + x 1 × x 3 y 3 = y 3 + x 4 。
[0161] For another example, as an illustration, in a specific embodiment of the present application, the specific quantum circuit diagram of the second inverse operation circuit IO2 can be as shown in Figure 10 shown.
[0162] In the technical solution of the present application, since the current key superposition state and the known plaintext can be encrypted through an encryption quantum circuit to obtain a ciphertext superposition state, then a phase flip operation is performed on the quantum state corresponding to the known ciphertext in the ciphertext superposition state, and the current ciphertext superposition state and the initial key superposition state are decrypted through an encryption quantum circuit to obtain a marked key superposition state. Subsequently, a conditional phase flip operation is performed on the marked key superposition state, and the key superposition state after the conditional phase flip operation is used as the current key superposition state, thereby completing one Grover iteration operation. Therefore, after a preset number of Grover iteration operations, the current key superposition state can be measured, and thus the required key can be obtained. Therefore, the technical solution of the present application can quickly calculate the key corresponding to a pair of known plaintext-ciphertext pairs using an encryption quantum circuit, thereby effectively reducing the complexity of quantum attacks and the difficulty of obtaining the key.
[0163] For example, as an illustration, in a specific embodiment of the present application, taking the encryption algorithm as S-AES, the quantum resources consumed by the method for obtaining a key in the present application can be as shown in Table 1 below:
[0164] Table 1
[0165] Qubit Pauli-X Gate Hadamard Gate CNOT Gate Toffoli Gate Depth 32 ≤40 12 392 120 42
[0166] Through the simulation and analysis of quantum attacks on the S-AES encryption algorithm, it can be seen that the time complexity of the method for obtaining a key in the present application is superior to the classical brute-force search method in the prior art. Moreover, the quantum circuit depth of the method for obtaining a key in the present application is low, and it is very likely to be implemented on noisy medium-scale quantum computing hardware, thus greatly advancing the process of quantum attacks on the S-AES algorithm.
[0167] In addition, in the technical solution of the present application, a device for obtaining a key is also proposed.
[0168] Figure 11 is a schematic structural diagram of the device for obtaining a key in a specific embodiment of the present invention. As Figure 11 shown, the device for obtaining a key in the embodiment of the present invention may include: a preparation unit 1101, a calculation unit 1102, and a measurement unit 1103;
[0169] The preparation unit 1101 is configured to prepare an initial key superposition state including all possible n-bit binary keys using n quantum bits, and output the initial key superposition state as the current key superposition state to the calculation unit 1102;
[0170] The calculation unit 1102 is configured to perform an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state; perform a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state; perform a decryption operation on the current ciphertext superposition state and the initial key superposition state through an encryption quantum circuit to obtain a marked key superposition state; perform a conditional phase flip operation on the marked key superposition state, use the key superposition state after the conditional phase flip operation as the current key superposition state, and increment the value of the iteration count by 1; when the iteration count is less than a preset threshold, return to execute the step of performing an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state; when the iteration count is equal to or greater than the preset threshold, output the current key superposition state to the measurement unit 1103;
[0171] The measurement unit 1103 is configured to measure the current key superposition state to obtain a key corresponding to the known plaintext and ciphertext.
[0172] In addition, in the exemplary embodiments of the present application, any of the foregoing method embodiments can be applied to the apparatus embodiments, and details thereof will not be described herein one by one.
[0173] In addition, in the technical solution of the present application, an electronic device is further proposed.
[0174] Figure 12 The schematic structural diagram of an electronic device provided by an embodiment of the present invention is shown, as Figure 12 shown, the electronic device may include a memory 1202, a processor 1201, a bus 1203, and a computer program stored on the memory 1202 and executable on the processor 1201. Among them, the processor 1201 and the memory 1202 complete mutual communication through the bus 1203. When the processor 1201 executes the computer program, the steps of the method in any of the foregoing embodiments are implemented.
[0175] In addition, in an embodiment of the present invention, a non-transitory computer-readable storage medium is further provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the method in any of the foregoing embodiments are implemented.
[0176] The foregoing apparatus embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0177] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0178] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A method for obtaining a key, characterized in that: The method includes: An initial key superposition state containing all possible n-bit binary keys is prepared using n quantum bits; The current key superposition state and the known plaintext are encrypted through an encryption quantum circuit to obtain a ciphertext superposition state; Performing a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state; The current ciphertext superposition state and the initial key superposition state are decrypted through an encrypted quantum circuit to obtain a marked key superposition state; Performing a conditional phase flip operation on the marked key superposition state, taking the key superposition state after the conditional phase flip operation as the current key superposition state, and adding 1 to the value of the number of iterations; When the number of iterations is less than a preset threshold, the method returns to the step of performing an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state; otherwise, the current key superposition state is measured to obtain a key corresponding to the known plaintext and ciphertext.
2. The method according to claim 1, characterized in that When the encryption method is a simplified advanced encryption standard, the encryption operation of the current key superposition state and the known plaintext through the encryption quantum circuit to obtain the ciphertext superposition state includes: Set up an encryption quantum circuit with 32 quantum bits, and make the quantum state of the first 16 quantum bits an initial key superposition state; Encode the known plaintext onto the first 16 qubits; Perform a byte replacement operation on the quantum state of the first 16 quantum bits through the first replacement quantum circuit, and store the operation result on the last 16 quantum bits according to the row shift rule; The column confusion operation is performed on the quantum states of the last 16 quantum bits through the column confusion quantum circuit; Perform XOR operation on the known plaintext bit by bit with the quantum state of the first 16 qubits; Perform subkey generation operations on the quantum states of the first 16 qubits through the subkey quantum circuit; Perform an XOR operation on the first 16 qubits and the last 16 qubits, and store the result of the operation on the last 16 qubits; Perform subkey generation operations on the quantum states of the first 16 qubits through the subkey quantum circuit; The quantum state on the last 16 quantum bits is byte-replaced through the second replacement quantum circuit, the operation result is XORed with the second subkey state on the first 16 quantum bits, and the final operation result is stored on the first 16 quantum bits according to the row shift rule.
3. The method according to claim 2, characterized in that The subkey quantum circuit comprises: two third replacement quantum circuits, a first XOR circuit and a second XOR circuit; A third replacement quantum circuit is used to perform a byte replacement operation on the 5th to 12th quantum bits; another third replacement quantum circuit is used to perform a byte replacement operation on the 1st to 4th and 13th to 16th quantum bits; The first XOR circuit is used to perform an XOR operation on the 1st to 8th quantum bits; The second XOR circuit is used to perform XOR operations on the 1st to 4th and 9th to 12th quantum bits, and to perform XOR operations on the 5th to 8th and 13th to 16th quantum bits.
4. The method according to claim 3, characterized in that The third replacement quantum circuit comprises: a first mapping circuit, a second mapping circuit, a first inversion operation circuit, a first combination circuit and a second combination circuit; The output terminal of the first mapping circuit is connected to the first input terminal of the first inversion operation circuit; The output terminal of the second combination circuit is connected to the second input terminal of the first inversion operation circuit; A first output terminal of the first inversion operation circuit is connected to an input terminal of the second mapping circuit; The second output terminal of the first inversion operation circuit is connected to the input terminal of the first circuit; The first mapping circuit is a mapping circuit from a polynomial basis to a standard basis; The second mapping circuit is a mapping circuit from a standard basis to a polynomial basis; The first inversion operation circuit is used to perform an inversion operation on a finite field; The first combination circuit is a combination circuit of mapping from a standard basis to a polynomial basis and an affine transformation; The second combination circuit is a combination circuit of mapping from a polynomial basis to a standard basis and an affine transformation.
5. The method according to claim 2, characterized in that: The second replacement quantum circuit comprises: a first mapping circuit, a first inversion operation circuit, a first combination circuit and a second combination circuit; The output terminal of the first mapping circuit is connected to the first input terminal of the first inversion operation circuit; The output terminal of the second combination circuit is connected to the second input terminal of the first inversion operation circuit; The second output terminal of the first inversion operation circuit is connected to the input terminal of the first combination circuit; The first mapping circuit is a mapping circuit from a polynomial basis to a standard basis; The first inversion operation circuit is used to perform an inversion operation on a finite field; The first combination circuit is a combination circuit of mapping from a standard basis to a polynomial basis and an affine transformation; The second combination circuit is a combination circuit of mapping from a polynomial basis to a standard basis and an affine transformation.
6. The method according to claim 4 or 5, characterized in that: The mathematical expression corresponding to the first inversion operation circuit is: x2=x2+x1×x4 y2=y2+x2×x3 y4=y4+x2 y3=y3+x2 y1=y1+x2 x2=x2+x1×x4 x4=x4+x1×x3 y4=y4+x2×x4 y4=y4+x4 y1=y1+x4 y2=y2+x4 x4=x4+x1×x3 x1=x1+x2×x3 y1=y1+x1×x4 y1=y1+x1 x1=x1+x2×x3 x3=x3+x2×x4 y3=y3+x1×x3 y2=y2+x3 x3=x3+x2×x4 y1=y1+x1 y1=y1+x2 y1=y1+x3 y2=y2+x3 y3=y3+x1 y4=y4+x4; The second-order terms and third-order terms in the mathematical expression are matched one by one, and one set of matches is achieved each time: x1x 4→ x1x3x4 x1x 3→ x1x2x3 x2x 3→ x2x3x4 x2x 4→ x1x2x4。 7. The method according to claim 2, characterized in that The first replacement quantum circuit comprises: a first mapping circuit, a second mapping circuit, a second inversion operation circuit and a first combination circuit; The output terminal of the first mapping circuit is connected to the first input terminal of the second inversion operation circuit; The first output terminal of the second inversion operation circuit is connected to the input terminal of the second mapping circuit; The second output terminal of the second inversion operation circuit is connected to the input terminal of the first circuit; The first mapping circuit is a mapping circuit from a polynomial basis to a standard basis; The second mapping circuit is a mapping circuit from a standard basis to a polynomial basis; The second inversion operation circuit is used to perform an inversion operation on a finite field; The first combination circuit is a combination circuit of mapping from a standard basis to a polynomial basis and an affine transformation.
8. The method according to claim 7, characterized in that The mathematical expression corresponding to the second inversion operation circuit is: x2=x1+x2 y3=x1×x3 x4=y4+x4 y4=x2×x4 x2=x1+x2 x4=y3+x4 y4=x2+y4 x3=x3+x4 x2=y3+x2 y2=x2×x3 x2=y3+x2 y2=x2×x3 x2=y3+x2 y2=y2+x4 x3=x4+x3 x3=x3+y2 y2=y2+y3+x4 y1=x4×y2 x4=y3+x4 y2=y2+x4 y1=x4+y1 y3=x4+y3 y3=y3+y1×y4 y3=y3+x1+x2 y1=y1+x4 y1=y1+x3 x3=x3+y2 x4=x4+x1×x3 y3=y3+x4.
9. A device for obtaining a key, characterized in that: The device for obtaining the key includes: a preparation unit, a calculation unit and a measurement unit; The preparation unit is used to use n quantum bits to prepare an initial key superposition state containing all possible n-bit binary keys, and output the initial key superposition state as the current key superposition state to the calculation unit; The computing unit is used to perform an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state; perform a phase flip operation on the quantum state corresponding to the known ciphertext in the ciphertext superposition state; perform a decryption operation on the current ciphertext superposition state and the initial key superposition state through an encryption quantum circuit to obtain a marked key superposition state; perform a conditional phase flip operation on the marked key superposition state, use the key superposition state after the conditional phase flip operation as the current key superposition state, and add 1 to the value of the number of iterations; when the number of iterations is less than a preset threshold, return to perform the step of performing an encryption operation on the current key superposition state and the known plaintext through an encryption quantum circuit to obtain a ciphertext superposition state; when the number of iterations is equal to the preset threshold, output the current key superposition state to the measuring unit; The measuring unit is used to measure the current key superposition state to obtain the key corresponding to the known plaintext and ciphertext.
10. An electronic device comprising a memory, a processor, a bus, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method for preventing data leakage according to any one of claims 1 to 8 are implemented.
11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method for preventing data leakage as claimed in any one of claims 1 to 8 are implemented.
Citation Information
Cited By
Hybrid quantum and classical symmetric encryption key security analysis method
CN121690578A