Method and device for constructing input ciphertext structure of neural network differential divider

By using a method based on random key decryption in the neural network differential divider to optimize the input ciphertext structure, the shortcomings of the differential analysis input ciphertext structure construction method in the prior art in terms of ciphertext distinction accuracy are solved, and high accuracy distinction and round expansion of lightweight symmetric cipher algorithms are achieved.

CN120165840APending Publication Date: 2025-06-17WUHAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510348790.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In the prior art, the differential analysis input ciphertext structure construction method of symmetric cryptography algorithms still has shortcomings in the accuracy of ciphertext distinction, especially in the environment where resource limitations are needed, it is difficult to achieve high accuracy distinction.

Method used

The input ciphertext structure of the neural network differential divider is optimized by a method based on random key decryption, and the preliminary ciphertext data set is generated through a simulated lightweight symmetric encryption algorithm, and the input ciphertext structure is optimized using random key decryption and key addition techniques to form the optimized input ciphertext structure.

Benefits of technology

The high accuracy distinction between lightweight symmetric cryptographic algorithms Speck and Simon ciphertext pairs was achieved, which greatly improved the distinction accuracy and expanded the discriminable rounds in a breakthrough manner, especially in the distinction between 9 rounds of Speck32/64 encrypted ciphertext groups, achieving the first success in all current research.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165840A_ABST
    Figure CN120165840A_ABST
Patent Text Reader

Abstract

The invention discloses a construction method and device for an input ciphertext structure of a neural network differential divider. The method comprises the following steps of simulating a Speck encryption algorithm, constructing a ciphertext data set and constructing a symmetric cryptographic differential analysis algorithm based on deep learning. And step 2, optimizing the input ciphertext structure of the neural network differential partition device by using methods of random key decryption, key addition and the like. And step 3, carrying out a ciphertext pair distinguishing experiment on the Speck and Simon encryption algorithms by using the new ciphertext structure. According to the method, the ciphertext data structure input into the neural network differential partition device is optimized through the schemes of random key decryption, key addition and the like, high accuracy and high-round ciphertext distinguishing of reduced-round Speck and Simon encryption algorithms are achieved, the distinguishing round is successfully expanded by one round, and the high-quality differential partition device is provided for key recovery attacks. According to the method, the analysis capability of the lightweight symmetric encryption algorithm is greatly improved, and a new improved method and optimization thought are provided for cryptography research.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of the combination of cryptography and artificial intelligence, and more specifically, to a method and device for constructing the ciphertext structure of the input of a neural network differential distinguisher. Background Art

[0002] With the wide application of big data, the Internet of Things, and various intelligent applications, cryptography is facing many new challenges while evolving rapidly. For example, the emergence of quantum computers has triggered in-depth research on quantum cryptography and post-quantum cryptography, prompting researchers to develop new cryptographic algorithms and protocols, such as lattice-based and code-based cryptography. In addition, in the context of the Internet of Everything, a large number of Internet of Things devices cannot directly use traditional cryptographic algorithms due to limited storage and computing capabilities. Therefore, it has become an urgent task to design a block cipher algorithm with a simple structure, high operation efficiency, and suitable for resource-constrained environments, and it has quickly become a hot topic in cryptography research.

[0003] For symmetric cipher algorithms, there are various cryptographic analysis methods, among which the most important ones include differential cryptanalysis, linear cryptanalysis, integral attack, and related attack variants. In the early 1990s, Eli Biham and Adi Shamir proposed the differential analysis method at the US Cryptography Conference. Differential cryptanalysis belongs to the chosen-plaintext attack method. It separates the block cipher from the random permutation through the probability propagation characteristics of specific plaintext difference values during the encryption process, and based on this, a key recovery attack is carried out. The analysis and attack on lightweight symmetric ciphers usually can be divided into two stages: distinguisher construction and key recovery. In the distinguisher construction stage, the attacker looks for non-random characteristics in the cryptographic algorithm, such as the linear correlation of the internal state, or the output difference that produces an abnormal distribution when a specific input difference is given. The key recovery stage aims at the round functions before and after the constructed distinguisher, and uses these non-random characteristics to (partially) recover the key bits. Therefore, it can be considered that a differential distinguisher with a high enough distinguishing accuracy is the most important part of the differential analysis work. Essentially, the attacker guesses the key information and checks whether there are non-random characteristics after encrypting or decrypting several round functions. If the probability distribution of the statistical data meets the expectation, it is considered that the guessed key may be correct.

[0004] The general process of differential analysis is as follows. After constructing the differential distinguisher, if the plaintext input pair of the differential distinguisher is (x, x * ), then the difference value of x, x * is defined as Δ x = x ⊕ x * . After the first round of iteration, the intermediate ciphertext has a difference value of Δ x1 . After n rounds of iteration, a difference value sequence Ω = (Δx , Δ x1 ......Δ xn ), and this difference value sequence is called the n-round differential path of the block cipher. The differential characteristic characterizes the differential propagation characteristics during the encryption process. In this paper, the number of plaintext pairs that satisfy the input difference of Δ x and the last difference, i.e., the output difference of Δ xn , is defined as N D (Δ x , Δ xn ). The probability R x of transforming the input difference Δ xn to the output difference Δ P is defined as shown in formula (1):

[0005]

[0006] If the corresponding probabilities R P (Δ x , Δ xn ) of all differential paths can be calculated, the differential distribution table (DDT) of the corresponding encryption algorithm is obtained. Among them, the differential paths with probabilities much higher than 1 / 2 m are called high-probability differential paths. Finding the high-probability differential path with the highest probability is a prerequisite for differential analysis. The subsequent steps are as follows:

[0007] (1) Assume that the length of the sub-key in the r-th round to be recovered is L, and set a counter v i for each key to be guessed, which is used as the score for the candidate key;

[0008] (2) Uniformly select and generate random plaintexts p1, p2......p n , and let p i be XORed with the Δ x value in the high-probability differential path to obtain the plaintext pair (p i , p i ′ ). After encrypting r + 1 rounds, the ciphertext pair (c i , c i ′ ) is obtained;

[0009] (3) Use the differential distinguisher to filter all the ciphertext pairs, and then decrypt the ciphertext pair (c i , c i ′ ) with a random key. If the difference value of the decrypted ciphertext pair is Δ xn , the counter v i value is incremented by one, and the key with the largest resulting value is considered the correct key.

[0010] As a commonly used cryptographic attack technique, differential cryptanalysis is widely applied to the analysis of cryptographic algorithms due to its high efficiency, universality, and ability to reveal the internal characteristics of cryptographic algorithms. From the most basic DES encryption algorithm to Blowfish, Speck, LBlock, etc., differential analysis has now become one of the security indicators that must be considered in the design and analysis of symmetric ciphers.

[0011] In the prior art, Comparative Document 1 - CN119519940A, a design method for differential distinguishers of symmetric ciphers based on deep learning, discloses the construction of the input ciphertext structure, including collecting initial ciphertext pairs, splicing single ciphertext pairs into multi-ciphertext pairs, using random keys for the multi-ciphertext pairs, performing one-round encryption to generate encrypted ciphertext pairs, and using the difference value between the multi-ciphertext pairs and the encrypted ciphertext pairs as the difference value of the ciphertext data as the input data. However, this method still has low accuracy in ciphertext discrimination. Summary of the Invention

[0012] The present invention provides a construction scheme for the input ciphertext structure of a lightweight symmetric cipher differential analysis based on random key decryption, and uses this method to construct the input ciphertext structure of a neural network differential distinguisher for discriminating ciphertext pairs of reduced-round lightweight cryptographic algorithms. In the invention, the input ciphertext data structure of the neural network differential distinguisher is optimized based on schemes such as random key decryption and key addition, achieving high-accuracy discrimination of ciphertext pairs of lightweight symmetric cryptographic algorithms Speck and Simon, greatly improving the discrimination accuracy, and breaking through to expand the distinguishable round.

[0013] To achieve the above object, the first aspect of the present invention provides a method for constructing the input ciphertext structure of a neural network differential distinguisher, including:

[0014] Simulating a lightweight symmetric encryption algorithm, generating a preliminary ciphertext data set for inputting into the neural network differential distinguisher through the simulated lightweight symmetric encryption algorithm, and dividing a training set from the preliminary ciphertext data set to train the neural network differential distinguisher;

[0015] Optimizing the input ciphertext structure of the neural network differential distinguisher using the method of random key decryption and key addition.

[0016] In one embodiment, simulating the lightweight symmetric encryption algorithm includes:

[0017] Simulating the Speck encryption algorithm and the Simon encryption algorithm using code.

[0018] In one embodiment, dividing a training set from the preliminary ciphertext data set to train the neural network differential distinguisher includes:

[0019] Divide a training set from the preliminary ciphertext dataset;

[0020] Determine hyperparameters and input the training set into a neural network differential distinguisher for training.

[0021] In one implementation, use the method of decrypting with a random secret key and adding a key to optimize the input ciphertext structure of the neural network differential distinguisher, including:

[0022] Use a multi-ciphertext splicing scheme to splice n individual ciphertexts into a combined ciphertext pair;

[0023] Based on the combined ciphertext pair, use a random single key to decrypt one round of the N-round ciphertext pair, and combine the ciphertext values, differential values of the N-round ciphertext, ciphertext values, differential values of the N - 1-round ciphertext, and the decryption key value into an optimized input ciphertext structure.

[0024] In one implementation, combining the ciphertext values of the N-round ciphertext, differential values, ciphertext values of the N - 1-round ciphertext, differential values, and the decryption key value into an optimized input ciphertext structure includes:

[0025] After splicing the ciphertext values of the N-round ciphertext and the ciphertext values of the N - 1-round ciphertext, then splice the differential values of the N-round ciphertext and the differential values of the N - 1-round ciphertext at the back, and finally add the decryption key value to combine into an optimized input ciphertext structure.

[0026] In one implementation, the method further includes:

[0027] Based on the combined ciphertext pair, use two random keys to decrypt the N-round ciphertext pair separately for two rounds, and combine the ciphertext values of the three rounds of ciphertext of the N-round, N - 1-round, and N - 2-round, the differential values of the three rounds of ciphertext of the N-round, N - 1-round, and N - 2-round, and the key differential value of the two random keys into an optimized input ciphertext structure.

[0028] In one implementation, combining the ciphertext values of the three rounds of ciphertext of the N-round, N - 1-round, and N - 2-round, the differential values of the three rounds of ciphertext of the N-round, N - 1-round, and N - 2-round, and the key differential value of the two random keys into an optimized input ciphertext structure includes:

[0029] After splicing the ciphertext values of the N-round ciphertext, the ciphertext values of the N - 1-round ciphertext, and the ciphertext values of the N - 2-round ciphertext, then splice the differential values of the N-round ciphertext, the differential values of the N - 1-round ciphertext, and the differential values of the N - 2-round ciphertext at the back, and finally add the key differential value of the decryption key to combine into an optimized input ciphertext structure.

[0030] In one implementation, the method further includes: performing ciphertext pair discrimination using the optimized input ciphertext structure.

[0031] Based on the same inventive concept, the second aspect of the present invention provides an apparatus for constructing the input ciphertext structure of a neural network differential distinguisher, including:

[0032] An algorithm simulation and ciphertext dataset construction module, configured to simulate a lightweight symmetric encryption algorithm, generate a preliminary ciphertext dataset for input to the neural network differential distinguisher through the simulated lightweight symmetric encryption algorithm, and divide a training set from the preliminary ciphertext dataset to train the neural network differential distinguisher;

[0033] An input ciphertext structure optimization module, configured to optimize the input ciphertext structure of the neural network differential distinguisher by using methods such as decrypting with a random secret key and adding a key

[0034] Based on the same inventive concept, the third aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method for constructing the input ciphertext structure of the neural network differential distinguisher described in the first aspect.

[0035] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0036] The present invention uses optimization ideas such as decrypting with a random key to propose an optimization scheme for the input ciphertext structure of neural network differential analysis, achieving high-accuracy discrimination of ciphertext pairs of lightweight symmetric cryptography algorithms Speck and Simon, greatly improving the discrimination accuracy, and breakthroughly expanding the distinguishable rounds. Among them, the discrimination of the 9-round Speck32 / 64 encrypted ciphertext group is the first implementation in all current studies. Therefore, the work of this invention is pioneering.

[0037] Furthermore, the present invention has obtained two currently optimal input ciphertext structures, and based on the two optimal input ciphertext structures, ciphertext discrimination is performed for Speck and Simon encryption, obtaining the highest discrimination accuracy in all current studies, and successfully expanding the distinguishable rounds of Speck encryption by one round, greatly enhancing the discrimination ability of the neural network differential distinguisher and providing a basis for subsequent key recovery attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0039] Figure 1It is a flowchart of the construction method of the input ciphertext structure of the neural network differential distinguisher in the embodiment of the present invention;

[0040] Figure 2 It is a detailed flowchart of the construction of the input ciphertext structure and key distinction of the neural network differential distinguisher in the embodiment of the present invention;

[0041] Figure 3 It is a structural diagram of the Speck encryption algorithm simulated by code in the embodiment of the present invention;

[0042] Figure 4 It is a structural diagram of the Simon encryption algorithm simulated by code in the embodiment of the present invention;

[0043] Figure 5 It is a structural diagram of the neural network differential distinguisher in the embodiment of the present invention;

[0044] Figure 6 It is an optimized input ciphertext structure diagram in the embodiment of the present invention;

[0045] Figure 7 It is another optimized input ciphertext structure diagram in the embodiment of the present invention. Detailed implementation manners

[0046] The present invention discloses a method for constructing an input ciphertext structure by using a random key decryption and key addition scheme, etc., to realize high-accuracy ciphertext distinction for a lightweight symmetric encryption algorithm (such as Speck32 / 64 encryption) after reducing the number of rounds by using an existing neural network differential distinguisher. Among them, the distinction of the 9-round Speck32 / 64 encrypted ciphertext group is the first realization in all current researches. Therefore, the work of this invention is pioneering. It includes the following steps: Step 1, simulate the Speck encryption algorithm, and construct a ciphertext data set and a symmetric cipher differential analysis algorithm based on deep learning. Step 2, optimize the input ciphertext structure of the neural network differential distinguisher by using methods such as random secret key decryption and key addition. Step 3, conduct ciphertext pair distinction experiments on the Speck and Simon encryption algorithms using the new ciphertext structure.

[0047] The present invention optimizes the ciphertext data structure of the input neural network differential distinguisher through schemes such as random key decryption and key addition, achieving high-accuracy and high-round ciphertext differentiation for the reduced-round Speck and Simon encryption algorithms. It successfully extends the differentiation round by one round, providing a high-quality differential distinguisher for key recovery attacks. This achievement greatly enhances the analysis ability of lightweight symmetric encryption algorithms and provides new improvement methods and optimization ideas for cryptography research. In the field of information security, this technology can be used to evaluate and improve the security of encryption algorithms, especially in resource-constrained environments such as smart device communication and wireless networks, where it has important application value. Through in-depth analysis of lightweight symmetric encryption algorithms, the present invention provides a powerful tool for cryptography research and practice, promoting technological progress in related fields.

[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0049] Embodiment 1

[0050] This embodiment discloses a method for constructing the input ciphertext structure of a neural network differential distinguisher. Please refer to Figure 1 , including:

[0051] S1: Simulate lightweight symmetric encryption algorithms, generate a preliminary ciphertext data set for the input neural network differential distinguisher through the simulated lightweight symmetric encryption algorithms, and divide a training set from the preliminary ciphertext data set to train the neural network differential distinguisher;

[0052] S2: Optimize the input ciphertext structure of the neural network differential distinguisher using the methods of random key decryption and key addition.

[0053] In one implementation, S1 includes:

[0054] Step S1.1, simulate the Speck and Simon encryption algorithms with code.

[0055] Step S1.2, construct a neural network architecture to form a neural network differential distinguisher.

[0056] Step S1.3, generate a preliminary ciphertext data set for the input neural network differential distinguisher through the simulated Speck and Simon encryption algorithms, including a training set and a test set.

[0057] Step S1.4: Determine hyperparameters such as the number of epochs and the learning rate, and train the neural network differential distinguisher.

[0058] In the specific implementation process, in step S1.1, the Speck and Simon encryption algorithms are simulated using code. The structures of the two cryptographic algorithms are as Figure 3 and Figure 4 shown.

[0059] In step S1.2, a neural network architecture is constructed to form a neural network differential distinguisher. The specific structure of the network is as Figure 5 visible. The neural network differential distinguisher consists of an input module (Module1), an initial convolutional module (Module2), a residual module (Module3), and a prediction module (Module4). The input module is used to receive data input from ciphertext pairs. In the initial convolutional layer, a single-layer convolutional operation with a convolutional kernel size of 1 is used to extract the features of the ciphertext matrix in the input layer. The purpose of this step is to mimic the XOR operation in cryptographic operations. Since the XOR operation cannot be performed in a neural network, this convolutional layer performs convolutional learning on the four bits that are XORed with each other in the cryptographic operation to extract the features therein. After the convolutional layer, a BN layer and a Gelu activation function are added. Next, the residual module is used to improve the feature extraction ability of the model. In this module, 5 residual towers composed of 5 convolutional neural network layers are used to extract deeper features, that is, each residual tower contains 5 convolutional layers, and the convolutional layer sizes increase by 2 layer by layer. The initial sizes of the convolutional kernels between each residual tower also increase by 2. A BN layer and a Gelu activation function are also added after each convolutional layer. At the same time, the features learned by each convolutional layer are connected to the subsequent convolutional layer using a residual structure as part of the input to increase the neural network's feature extraction ability for ciphertext data. Finally, 2 fully connected layers with 64 neurons each are added as the prediction module. This module maps the input features to output labels, predicts real pairs and random pairs, and outputs the final result to obtain the accuracy rate.

[0060] In step S1.3, a preliminary ciphertext dataset for inputting into the neural network differential distinguisher is generated through a cryptographic algorithm, including a training set and a test set. The training set contains 1 million ciphertext pairs, with half being real ciphertext pairs with a fixed difference and half being random ciphertext pairs with a random difference. The test set contains 100,000 new ciphertext pairs that are not used in the training set, and the proportion remains unchanged.

[0061] Step S1.4: Determine hyperparameters such as the number of epochs and the learning rate. The network is trained for 200 epochs in total. The batch size is set to 5000. The Adam algorithm with default parameters in Keras is used to optimize the cross-entropy loss function and a small penalty for L2 weight regularization (regularization parameter). The learning rate adopts a cyclic learning rate, as shown in Equation 1, where. The network obtained at the end of each epoch is stored, and the best network obtained is evaluated according to the test set, which is not used for training.

[0062]

[0063] l i is the current learning rate, and a differential distinguisher is obtained after the training ends.

[0064] In one embodiment, S2 includes:

[0065] Use the multi-ciphertext splicing scheme to splice n individual ciphertexts into a combined ciphertext pair;

[0066] Based on the combined ciphertext pair, use a random single key to decrypt one round of the N-round ciphertext pair, and combine the ciphertext values, difference values of the N-round ciphertext, ciphertext values, difference values of the N-1-round ciphertext, and the decryption key value into an optimized input ciphertext structure.

[0067] Specifically, use the multi-ciphertext splicing scheme to splice n individual ciphertexts into a combined ciphertext pair, which serves as the basis for the following two optimal ciphertext data structures. The optimized input ciphertext structure is abbreviated as the DRMSPADK (double rounds multiple splicing ciphertext pairs add differences and keys) ciphertext structure.

[0068] The splicing order of the ciphertext value, difference value, and decryption key is not limited. The ciphertext value can be in the front, or the difference value can be in the front.

[0069] In one embodiment, combining the ciphertext values, difference values of the N-round ciphertext, ciphertext values, difference values of the N-1-round ciphertext, and the decryption key value into an optimized input ciphertext structure includes:

[0070] After splicing the ciphertext values of the N-round ciphertext and the ciphertext values of the N-1-round ciphertext, then splice the difference values of the N-round ciphertext and the difference values of the N-1-round ciphertext at the back, and finally add the decryption key value to combine into an optimized input ciphertext structure.

[0071] Specifically, the N-round ciphertext value represents the numerical value of the initial input ciphertext pair. The N-1 round ciphertext value represents the ciphertext value obtained by decrypting the N-round ciphertext value with a randomly selected key for one round. The difference value represents the numerical value obtained by performing an exclusive OR operation on the N-round and N-1 round ciphertext pairs themselves. The decryption key is the key for decrypting with the random key, specifically as Figure 6 shown.

[0072] By obtaining the ciphertext structure in the way of giving priority to ciphertext pairs and then concatenating the difference values of all ciphertext pairs at the back and finally adding the key, a relatively high discrimination accuracy can be obtained. Moreover, the distinguishable rounds of the Speck encryption are successfully extended by one round, greatly enhancing the discrimination ability of the neural network differential distinguisher and providing a basis for subsequent key recovery attacks.

[0073] In one implementation, the method further includes:

[0074] On the basis of the combined ciphertext pairs, randomly select two keys to decrypt the N-round ciphertext pairs for two rounds respectively, and combine the ciphertext values of the N-round, N-1 round, and N-2 round ciphertexts, the difference values of the N-round, N-1 round, and N-2 round ciphertexts, and the key difference values of the two random keys into an optimized input ciphertext structure.

[0075] Specifically, the optimized input ciphertext structure is abbreviated as the TRMSPADKD (triple rounds multiple splicing ciphertext pairs add differences) ciphertext structure.

[0076] There is no limitation on the concatenation order of the ciphertext value, the difference value, and the decryption key difference value. The ciphertext value can be in the front, or the difference value can be in the front.

[0077] In one implementation, combining the ciphertext values of the N-round, N-1 round, and N-2 round ciphertexts, the difference values of the N-round, N-1 round, and N-2 round ciphertexts, and the key difference values of the two random keys into an optimized input ciphertext structure includes:

[0078] After concatenating the ciphertext values of the N-round ciphertext, the N-1 round ciphertext, and the N-2 round ciphertext, then concatenate the difference values of the N-round ciphertext, the N-1 round ciphertext, and the N-2 round ciphertext at the back, and finally add the key difference value of the decryption key to combine into the optimized input ciphertext structure.

[0079] Specifically, different from the previous one, in this implementation, two randomly selected keys are used to decrypt for two rounds, and an exclusive OR operation can also be performed between the two keys, so there is a key difference value. The obtained optimized input ciphertext structure is as Figure 7 shown.

[0080] The ciphertext structure obtained by prioritizing ciphertext pairs, then concatenating the difference values of all ciphertext pairs at the back, and finally adding the key difference can achieve a relatively high discrimination accuracy. Moreover, the distinguishable rounds of the Speck encryption are successfully extended by one round, greatly enhancing the discrimination ability of the neural network differential distinguisher, providing a basis for subsequent key recovery attacks.

[0081] In one implementation, the method further includes: performing ciphertext pair discrimination using the optimized input ciphertext structure.

[0082] Please refer to Figure 2 , the detailed flowchart of the construction of the input ciphertext structure of the neural network differential distinguisher and key discrimination in the embodiments of the present invention.

[0083] In the specific implementation process, the ciphertext pair discrimination is realized through the following steps:

[0084] Step S3.1, simulate the Speck symmetric cipher algorithm to generate the data sets for training and verification. The training set is 1 million ciphertext data, with real pairs and random pairs each accounting for half, and the test set is 100,000 ciphertext data.

[0085] Step S3.2, use the two optimal ciphertext data structures in step S2 to perform ciphertext discrimination on the Speck encryption reduced to rounds 7 - 9. Use the 32-ciphertext pair mode to discriminate the ciphertext pairs of the Speck encryption in rounds 7 - 8, and use the 128-ciphertext pair mode to discriminate the ciphertext pairs of the Speck encryption in round 9. The discrimination results are shown in Table 1.

[0086] Step S3.3, use the two optimal ciphertext data structures in step S2 to perform ciphertext discrimination on the Simon encryption reduced to rounds 9 - 11. Use the 32-ciphertext pair mode to discriminate the ciphertext pairs of the Simon encryption in rounds 9 - 11. The discrimination results are shown in Table 2.

[0087]

[0088] Table 1

[0089]

[0090] Table 2

[0091] The present invention proposes a construction scheme for the input ciphertext structure of a lightweight symmetric cipher differential analysis based on random key decryption, and realizes the construction of two optimal ciphertext structures, DRMSPADK and TRMSPADKD. On this basis, a high-probability distinction for the 7-9 round Speck encryption algorithm and the 9-11 round Simon encryption algorithm is realized, and the distinguishable rounds of Speck encryption are extended by one round to achieve the purpose of optimizing the differential distinguisher. The research results significantly enhance the detection ability for low-complexity symmetric cipher systems, and inject innovative methodologies and improved paradigms into the modern cryptography theory system. In the field of data security protection, this technical system can systematically improve the security performance evaluation and optimization mechanism of cryptographic protocols, and show breakthrough engineering adaptation value and practical guiding significance for application scenarios with significant computing power constraints such as intelligent terminal devices and wireless sensor networks.

[0092] Embodiment 2

[0093] Based on the same inventive concept, this embodiment discloses a device for constructing the input ciphertext structure of a neural network differential distinguisher, including:

[0094] An algorithm simulation and ciphertext dataset construction module, which is used to simulate a lightweight symmetric encryption algorithm, generate a preliminary ciphertext dataset for inputting into the neural network differential distinguisher through the simulated lightweight symmetric encryption algorithm, and divide a training set from the preliminary ciphertext dataset to train the neural network differential distinguisher;

[0095] An input ciphertext structure optimization module, which is used to optimize the input ciphertext structure of the neural network differential distinguisher by using the method of random key decryption and key addition.

[0096] Since the system introduced in Embodiment 2 of the present invention is the system adopted for implementing the method for constructing the input ciphertext structure of the neural network differential distinguisher in Embodiment 1 of the present invention, based on the method introduced in Embodiment 1 of the present invention, those skilled in the art can understand the specific structure and variations of the system, so it will not be elaborated here. Any system adopted by the method in Embodiment 1 of the present invention belongs to the scope protected by the present invention.

[0097] Embodiment 3

[0098] The present invention also provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method described in Embodiment 1.

[0099] Since the computer device introduced in Embodiment 3 of the present invention is the computer device adopted for constructing the ciphertext structure of the neural network differential differentiator in Embodiment 1 of the present invention, based on the method introduced in Embodiment 1 of the present invention, those skilled in the art can understand the specific structure and variations of this computer device, so it will not be elaborated here. Any computer device adopted by the method of Embodiment 1 of the present invention falls within the scope of protection of the present invention.

[0100] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0101] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0102] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present invention. Obviously, those skilled in the art can make various changes and variations to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and variations.

Claims

1. A method for constructing a ciphertext structure of a neural network differential distinguisher input, characterized in that: include: Simulate a lightweight symmetric encryption algorithm, generate a preliminary ciphertext data set for inputting a neural network differential distinguisher through the lightweight symmetric encryption algorithm obtained by simulation, and divide a training set from the preliminary ciphertext data set to train the neural network differential distinguisher; The input ciphertext structure of the neural network differential distinguisher is optimized using random key decryption and key addition methods.

2. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 1, characterized in that: Emulates lightweight symmetric encryption algorithms, including: Use code to simulate the Speck encryption algorithm and the Simon encryption algorithm.

3. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 1, characterized in that: A training set is divided from the preliminary ciphertext data set to train the neural network differential distinguisher, including: Divide the training set from the preliminary ciphertext data set; Determine the hyperparameters and input the training set into the neural network differential discriminator for training.

4. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 1, characterized in that: The input ciphertext structure of the neural network differential distinguisher is optimized using random key decryption and key addition methods, including: Use a multi-ciphertext concatenation scheme to concatenate n individual ciphertexts into a combined ciphertext pair; On the basis of combining the ciphertext pairs, a random single key is used to decrypt the N-round ciphertext pairs for one round, and the ciphertext value, differential value of the N-round ciphertext, the ciphertext value, differential value of the N-1-round ciphertext and the decryption key value are combined into an optimized input ciphertext structure.

5. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 1, characterized in that: The ciphertext value, differential value of the N-round ciphertext, the ciphertext value, differential value of the N-1-round ciphertext, and the decryption key value are combined into an optimized input ciphertext structure, including: After concatenating the ciphertext values ​​of the N-round ciphertext and the N-1-round ciphertext, the differential values ​​of the N-round ciphertext and the N-1-round ciphertext are concatenated, and finally the decryption key value is added to form the optimized input ciphertext structure.

6. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 4, characterized in that: The method further comprises: On the basis of combining ciphertext pairs, two random keys are used to perform two rounds of decryption on N rounds of ciphertext pairs respectively, and the ciphertext values ​​of N rounds, N-1 rounds, and N-2 rounds of ciphertexts, the differential values ​​of N rounds, N-1 rounds, and N-2 rounds of ciphertexts, and the key differential values ​​of the two random keys are combined into an optimized input ciphertext structure.

7. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 6, characterized in that: The ciphertext values ​​of the three rounds of ciphertexts of N rounds, N-1 rounds, and N-2 rounds, the difference values ​​of the three rounds of ciphertexts of N rounds, N-1 rounds, and N-2 rounds, and the key difference values ​​of two random keys are combined into an optimized input ciphertext structure, including: The ciphertext values ​​of the N-round ciphertext, the N-1-round ciphertext, and the N-2-round ciphertext are concatenated, and then the differential values ​​of the N-round ciphertext, the N-1-round ciphertext, and the N-2-round ciphertext are concatenated, and finally the key differential value of the decryption key is added to form an optimized input ciphertext structure.

8. The method for constructing a neural network differential distinguisher input ciphertext structure as claimed in claim 1, characterized in that: The method further includes: using the optimized input ciphertext structure to distinguish ciphertext pairs.

9. A device for constructing a ciphertext structure for a neural network differential distinguisher input, characterized in that: include: The algorithm simulation and ciphertext data set construction module is used to simulate the lightweight symmetric encryption algorithm, generate a preliminary ciphertext data set for inputting the neural network differential distinguisher through the lightweight symmetric encryption algorithm obtained by simulation, and divide the training set from the preliminary ciphertext data set to train the neural network differential distinguisher; The input ciphertext structure optimization module is used to optimize the input ciphertext structure of the neural network differential distinguisher using random key decryption and key addition methods.

10. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the method for constructing the input ciphertext structure of the neural network differential distinguisher as described in any one of claims 1 to 8.