Linear diffusion matrix construction method and system in block cipher design

By inversely constructing the linear diffusion matrix, using greedy algorithms and elementary matrix to construct a linear diffusion matrix pattern that meets specific scales and branches, and achieving cost through two-type elementary matrix optimization, the problem of high cost implementation of linear diffusion matrix in the prior art is solved, and a low-cost and high-efficiency linear diffusion matrix construction is achieved.

CN120165841APending Publication Date: 2025-06-17HANGZHOU DIANZI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510441520.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The existing packet cipher linear diffusion matrix is ​​too expensive to implement hardware in resource-constrained computing devices, and there is a lack of construction methods for low-branch diffusion matrix.

Method used

The linear diffusion matrix is ​​constructed inversely through the angle of matrix decomposition, and a linear diffusion matrix pattern that meets specific scales and branches is constructed using greedy algorithms and elementary matrixes, and the cost is achieved through the optimization of the second-type elementary matrix.

Benefits of technology

A linear diffusion matrix of various branches is realized under a specific scale, which reduces the cost of matrix implementation, takes into account the efficiency of software and hardware implementation, and improves the security and efficiency of packet passwords.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165841A_ABST
    Figure CN120165841A_ABST
Patent Text Reader

Abstract

The invention discloses a linear diffusion matrix construction method and system in block cipher design. According to the method, the linear diffusion matrix is reversely constructed from the angle of matrix decomposition, and a'mode + instance 'two-section search method is adopted, so that the search space and the calculation complexity are greatly reduced; during pattern search, symbolic operation is utilized to construct and then optimize, and a linear diffusion matrix of any number of branches under a specific scale can be constructed; in the instantiation stage, a low-cost binary matrix is introduced, so that the hardware implementation efficiency is considered on the premise of ensuring the safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of block cipher design, and particularly relates to a method and system for constructing a linear diffusion matrix in block cipher design. Background Art

[0002] With the rapid development of Internet technology, network security issues have become increasingly prominent, and the importance of information security and confidentiality technology has become more prominent. The modern cryptography system is mainly divided into two categories: symmetric cryptosystem and asymmetric cryptosystem. Among them, the symmetric cryptosystem includes three main branches: block cipher, stream cipher, and message authentication code. As the core cryptographic technology providing encryption services, block cipher is widely used in fields such as computer communication and information system security due to its advantages such as fast encryption speed, easy standardization, and convenient implementation in software and hardware.

[0003] The design of block cipher revolves around two main principles: confusion and diffusion. The diffusion principle is realized by a diffusion matrix, which can not only achieve the optimal diffusion effect but also significantly improve the execution efficiency of the algorithm. A matrix with optimal diffusion characteristics is called a maximum distance separable (MDS) matrix. The MDS matrix can provide the maximum branch number and more effectively resist differential and linear analysis, so it is widely used in the diffusion structure of block ciphers, such as in cryptographic algorithms like AES and LED.

[0004] However, in computing devices with extremely limited resources, the hardware implementation cost brought by using the MDS matrix is too high. In this case, designers usually use low-branch diffusion matrices such as approximate MDS matrices or linear matrices with a branch number of two as the linear layer of the block cipher.

[0005] Currently, most of the existing linear diffusion matrices for block ciphers focus on the construction of MDS matrices. For the construction of approximate MDS matrices, it is mainly constructed through an iterative structure. The cost of the matrix constructed in this way is restricted by the iterative structure and cannot further reduce the implementation cost of the matrix; for low-branch diffusion matrices, there is currently no related construction method. Summary of the Invention

[0006] Aiming at the deficiencies in the prior art, the present invention provides a method and system for constructing a linear diffusion matrix in block cipher design. By constructing the linear diffusion matrix reversely from the perspective of matrix decomposition, it is possible to construct linear diffusion matrices with various branch numbers under a specified scale, and at the same time, the construction process considers the matrix implementation cost and takes into account the implementation efficiency of software and hardware.

[0007] In the first aspect, the present invention provides a method for constructing a linear diffusion matrix in block cipher design, including the following steps:

[0008] Step 1: Based on the greedy algorithm, use type-III elementary matrices to construct a linear diffusion matrix pattern that meets a specific scale and a specific number of branches.

[0009] Any non-singular matrix can be decomposed into type-I elementary matrices (swapping two rows), type-II elementary matrices (multiplying a row by a coefficient λ), and type-III elementary matrices (multiplying a row by a coefficient λ and adding it to another row) through matrix decomposition. Type-I elementary matrices and type-II elementary matrices do not affect the number of branches. Therefore, type-III elementary matrices can be used to construct a linear diffusion matrix pattern. A linear diffusion matrix pattern refers to a diffusion matrix with a binary matrix L as the basis, where L is a non-singular binary matrix with a XOR cost not exceeding one. Initially, an n×n identity matrix is given according to requirements. Under the greedy algorithm, it is continuously left-multiplied by the corresponding n×n type-III elementary matrices, where the coefficients of the type-III elementary matrices are selected as λ = {…,L -2 ,L -1 ,1,L,L 2 ,…} to obtain a linear diffusion matrix pattern with the target number of branches.

[0010] The greedy algorithm selects type-III elementary matrices with the goal of reducing the number of singular submatrices the most after left-multiplying different type-III elementary matrices. Compared with traversing all possible type-III elementary matrices, the search space is greatly reduced. Since the linear diffusion matrix pattern is based on the binary matrix L, symbolic operations are used when calculating the number of singular submatrices. In addition, during the process of the greedy algorithm, when there are multiple type-III elementary matrices that result in the same reduction goal, the type-III elementary matrix that appears first is selected, and other type-III elementary matrices that result in the same reduction goal are retained for subsequent use.

[0011] Step 2: Under the principle of local optimality, use type-II elementary matrices to optimize the cost of the linear diffusion matrix pattern.

[0012] There are equivalent exchanges among type-I elementary matrices, type-II elementary matrices, and type-III elementary matrices. Therefore, the principle of equivalent exchange can be used to introduce type-II elementary matrices to any position of the linear diffusion matrix pattern with the target number of branches, and the cost of the linear diffusion matrix pattern can be optimized under the principle of local optimality.

[0013] The cost of the linear diffusion matrix pattern includes the XOR cost naturally existing in type-III elementary matrices and the XOR cost of the coefficients in type-II and type-III elementary matrices. Type-I elementary matrices have no cost. The principle of local optimality is that each introduced type-II elementary matrix is the one that eliminates the most coefficients λ in type-III elementary matrices. The number of eliminations refers to the number of matrices that reduce the absolute value of the degree of the coefficient λ in type-III elementary matrices after introducing this type-II elementary matrix. Continuously introduce type-II elementary matrices until the number of eliminations of the coefficient λ in type-III elementary matrices no longer decreases.

[0014] Step 3: Instantiate the linear diffusion matrix pattern and output a linear diffusion matrix that meets a specific scale and a specific number of branches.

[0015] Instantiate the optimized linear diffusion matrix pattern. By traversing the low-cost binary matrix L and substituting it into the linear diffusion matrix pattern, determine whether the branch number requirement is met. Output a linear diffusion matrix that meets the branch number requirement. For a linear diffusion matrix that does not meet the branch number requirement, return to Step 1 to select other type-III elementary matrices that result in the same descent objective and continue to construct the linear diffusion matrix pattern; if there are no other type-III elementary matrices that result in the same descent objective, expand the coefficient selection range of the type-III elementary matrix until a linear diffusion matrix pattern that meets the target branch number can be constructed.

[0016] On the other hand, the present invention provides a linear diffusion matrix construction system in block cipher design, including:

[0017] A linear diffusion matrix pattern construction module that constructs a linear diffusion matrix pattern that meets a specific scale and a specific number of branches based on the greedy algorithm using type-III elementary matrices.

[0018] A linear diffusion matrix pattern optimization module that optimizes the cost of the linear diffusion matrix pattern using type-II elementary matrices under the principle of local optimality.

[0019] A linear diffusion matrix pattern instantiation module for instantiating the linear diffusion matrix pattern and outputting a linear diffusion matrix that meets a specific scale and a specific number of branches.

[0020] On yet another aspect, the present invention proposes an electronic device, including: a memory and one or more processors connected to the memory, the memory storing a computer program, and the processors being configured to execute the computer program to implement a method for constructing a linear diffusion matrix in block cipher design.

[0021] On still another aspect, the present invention proposes a computer-readable storage medium storing computer-executable instructions for executing the above-mentioned method for constructing a linear diffusion matrix in block cipher design.

[0022] The beneficial effects of the present invention are as follows:

[0023] The method of the present invention constructs a linear diffusion matrix reversely from the perspective of matrix decomposition, adopts a two-stage search method of "pattern + instance", greatly reducing the search space and computational complexity; during pattern search, symbolic operations are used to construct and then optimize, and a linear diffusion matrix with any number of branches under a specific scale can be constructed; during the instantiation stage, by substituting a low-cost binary matrix, the hardware implementation efficiency is taken into account while ensuring security. The present invention has practical significance for the design of block cipher algorithms and has strong application prospects. Description of the Drawings

[0024] Figure 1 This is a flowchart of a method for constructing a linear diffusion matrix in a block cipher design according to an embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram of the principle of a method for constructing a linear diffusion matrix in a block cipher design provided by an embodiment of the present invention;

[0026] Figure 3 This is a schematic diagram of the system structure of a system for constructing a linear diffusion matrix in a block cipher design provided by an embodiment of the present invention.

[0027] Figure 4 This is a 6×6 scale linear diffusion matrix constructed in an embodiment of the present invention, with a block size of 4 and a branch number of 5. Detailed Embodiment

[0028] The technical solution of the present invention will be further described below in conjunction with the drawings and embodiments.

[0029] The present invention provides a method for constructing a linear diffusion matrix in a block cipher design. Refer to Figure 1 as shown, and specifically includes the following content:

[0030] (1) Construct a linear diffusion matrix pattern based on the greedy algorithm using type III elementary matrices; (2) Optimize the linear diffusion matrix pattern under the strategy of local optimality; (3) Instantiate the linear diffusion matrix pattern.

[0031] The security performance of the linear diffusion matrix is mainly measured by the branch number. The branch number can, to a certain extent, reflect the diffusion performance of the diffusion matrix. The smaller the branch number, the more vulnerable the block cipher is to attacks such as differential analysis, linear analysis, and some unknown analysis methods; conversely, the larger the branch number, the better the diffusion effect of the linear layer, the greater the attack difficulty, and the better the security.

[0032] First, construct a linear diffusion matrix pattern that meets the branch number requirements based on the greedy algorithm using type III elementary matrices. Specifically, there are three types of elementary matrices, namely, swapping two rows, multiplying a row by a coefficient λ, and adding a row multiplied by a coefficient λ to another row, where the coefficient λ = {..·,L -2 ,L -1 ,1,L,L 2 ,…}, which are respectively denoted as M I ,M II ,M III . Three elementary matrices are given as examples as follows:

[0033]

[0034] Any non - singular matrix can be decomposed into the product of a number of elementary matrices of type - 1, elementary matrices of type - 2, and elementary matrices of type - 3. For example:

[0035]

[0036] There is an exchange equivalence principle among the elementary matrices of type - 1, elementary matrices of type - 2, and elementary matrices of type - 3. Therefore, all elementary matrices of type - 1, elementary matrices of type - 2, and elementary matrices of type - 3 can be merged and processed together using the exchange equivalence. Since the elementary matrices of type - 1 and elementary matrices of type - 2 do not affect the branch number, first, use the elementary matrices of type - 3 to construct a linear diffusion matrix pattern that meets the branch - number requirements.

[0037] Construct a linear diffusion matrix pattern with a search range based on the binary matrix L. Therefore, calculate the polynomial representation form of each term after matrix multiplication through symbolic operations. Set the greedy - algorithm rule and the branch - number judgment criterion. Based on the identity matrix of a specific size, continuously screen and left - multiply by the elementary matrices of type - 3 according to the greedy algorithm until a linear diffusion matrix pattern that meets the branch - number requirements is found.

[0038] Specifically, according to the determination theorem of the MDS matrix, a matrix is an MDS matrix if and only if all its sub - square matrices are non - singular. When setting the greedy - algorithm rule, take the number of singular sub - square matrices as the greedy - algorithm goal, that is, each time select the elementary matrix of type - 3 that causes the largest decrease in the number of singular sub - matrices after left - multiplying by different elementary matrices of type - 3. During the process of the greedy algorithm, there may be multiple elementary matrices of type - 3 that lead to the same decrease target. In this case, select the elementary matrix of type - 3 that appears first, and at the same time retain other elementary matrices of type - 3 that lead to the same decrease target for subsequent use. After each selection of an elementary matrix of type - 3 for left - multiplication, supplement it with the branch - number judgment criterion. Specifically, according to the definitions of the differential branch number and the linear branch number, let A be a matrix in the general linear group That is, A is an n×n invertible matrix defined over the finite field (binary field). Then the differential branch number β d (A) of A is defined as the minimum value of the number of non - zero components in the input vector x and the output vector Ax. Considering all non - zero input vectors x, that is where w(x) represents the number of non - zero components in the vector x; similarly, the linear branch number A T represents the transpose matrix of matrix A. Traverse all non - zero inputs, calculate the output of the left - multiplied matrix and the output of the left - multiplied transpose matrix, and judge whether the minimum value of the sum of non - zero components in the input and output is the same as the branch number. Until a linear diffusion matrix pattern that meets the branch - number requirements is formed.

[0039] With the rapid development of the Internet of Things, the computing power of resource-first devices is limited. Just meeting security requirements is not enough; the implementation efficiency of software and hardware should also be fully considered. The cost of the linear diffusion matrix mode includes the XOR cost naturally present in the three types of elementary matrices and the XOR cost of the coefficients in the second and third types of elementary matrices. The first type of elementary matrix has no cost. Therefore, the second type of elementary matrix can be used to optimize the linear diffusion matrix mode and reduce the implementation cost.

[0040] Since the first type of elementary matrix, the second type of elementary matrix, and the third type of elementary matrix can be equivalently exchanged, the second type of elementary matrix can be introduced from one end to any position in the form of the product of the M matrix through equivalent exchange, that is:

[0041]

[0042] By introducing the second type of elementary matrix multiple coefficients λ in the third type of elementary matrix can be eliminated simultaneously. Based on the local optimal principle, each time the second type of elementary matrix is introduced, it is to eliminate the one with the largest number of coefficients λ in the third type of elementary matrix. The elimination quantity refers to the number of matrices that reduce the absolute value of the degree of the coefficient λ in the third type of elementary matrix after introducing this second type of elementary matrix. Continuously introduce the second type of elementary matrix until the elimination quantity of the coefficient λ in the third type of elementary matrix no longer decreases.

[0043] After obtaining the linear diffusion matrix mode through the above steps, it needs to be instantiated. By traversing the low-cost binary matrix L and substituting it into the linear diffusion matrix mode M, it is judged whether the instance of the M matrix meets the required branch number. Output the linear diffusion matrix that meets the branch number requirement. For the linear diffusion matrix that does not meet the branch number requirement, reconstruct the linear diffusion matrix mode. During the construction process, select other third type of elementary matrices that lead to the same descent target; if there are no other third type of elementary matrices that lead to the same descent target, expand the coefficient selection range of the third type of elementary matrix until a linear diffusion matrix mode that meets the target branch number can be constructed.

[0044] Embodiment

[0045] According to the above description, an embodiment of the present invention gives a construction of a low-branch number linear diffusion matrix with a scale of 6×6, a block size of 4, and a branch number of 5. Initially, a 6×6 identity matrix is given Set the coefficient selection range of the third type of elementary matrix as λ = {L -1 , 1, L}, and denote the third type of elementary matrix as It means adding λ times of the j-th row to the i-th row. The total number of type-III elementary matrices is 6×5×3 = 90. The number of singular submatrices of the initial identity matrix is 860. After the first greedy algorithm, there are 90 type-III elementary matrices that, when left-multiplying the identity matrix I, result in the largest decrease in the number of singular submatrices. The number of singular submatrices decreases to 844, and the matrix is judged not to meet the branch number requirement. On this basis, the greedy algorithm is continued until the branch number of the linear diffusion matrix pattern is 5. After 12 selections by the greedy algorithm, the constructed linear diffusion pattern is

[0046] At this time, the branch number of the linear diffusion matrix pattern is 5.

[0047] In the above linear diffusion matrix pattern, the sum of the absolute values of the coefficients of the type-III elementary matrices is 6. The sum of the absolute values of its coefficients can be reduced by introducing type-II elementary matrices. Select the type-II elementary matrix which means multiplying the 5th row by L times and introducing it into M to get

[0048] Without changing the scale and branch number of the linear diffusion matrix pattern, the sum of the absolute values of the coefficients of the type-III elementary matrices is reduced to 5, and the matrix implementation cost is further reduced. The linear diffusion matrix pattern is expressed as

[0049]

[0050] Traverse the low-cost binary matrices and select Substitute it into the linear diffusion matrix pattern to obtain the final 6×6 scale, branch number 5, and block size 4-bit linear diffusion matrix as Figure 4 shown.

[0051] The above content is a further detailed description of the present invention in combination with specific / preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, they can also make several substitutions or variations to these described embodiments, and these substitution or variation methods should all be regarded as belonging to the protection scope of the present invention.

[0052] The parts not detailed in the present invention belong to the well-known technologies in the art.

Claims

1. A method for constructing a linear diffusion matrix in a block cipher design, characterized in that: The steps include: Step 1: Based on the greedy algorithm, a linear diffusion matrix model satisfying a specific scale and a specific number of branches is constructed using three-type elementary matrices; Step 2, using type II elementary matrix to optimize the linear diffusion matrix model realization cost under the principle of local optimality; Step three, instantiate the linear diffusion matrix model and output a linear diffusion matrix that meets a specific scale and a specific number of branches.

2. The method for constructing a linear diffusion matrix in a block cipher design according to claim 1, characterized in that: Step 1 is as follows: Any non-singular matrix can be decomposed into type-I elementary matrix, type-II elementary matrix and type-III elementary matrix by matrix decomposition method; type-I elementary matrix and type-II elementary matrix do not affect the number of branches, so type-III elementary matrix is ​​used to construct linear diffusion matrix mode; linear diffusion matrix mode refers to a diffusion matrix based on binary matrix L, where L is a non-singular binary matrix with no more than one XOR cost; initially, an n×n unit matrix is ​​given according to the requirements, and the corresponding type-III elementary matrix of n×n size is obtained by continuously left-multiplying it under the greedy algorithm, where the coefficient of type-III elementary matrix is ​​selected as λ={…,L -2 ,L -1 ,1,L,L 2 ,···}get the linear diffusion matrix pattern of the target branch number; The greedy algorithm selects the three-type elementary matrices with the goal of reducing the number of singular submatrices the most after left-multiplying different three-type elementary matrices; The linear diffusion matrix model is based on the binary matrix L, so symbolic operations are used when calculating the number of singular submatrices; in addition, in the process of the greedy algorithm, when there are multiple three-type elementary matrices that lead to the same descent target, the first three-type elementary matrix is ​​selected, and other three-type elementary matrices that lead to the same descent target are retained for subsequent use.

3. The method for constructing a linear diffusion matrix in a block cipher design according to claim 2, characterized in that: Step 2 is as follows: There is an equivalent exchange between type-I elementary matrices, type-II elementary matrices and type-III elementary matrices. Therefore, the type-II elementary matrices are introduced into any position of the linear diffusion matrix pattern with the target number of branches by using the principle of equivalent exchange, and the cost of the linear diffusion matrix pattern is optimized under the principle of local optimality. The cost of the linear diffusion matrix model includes the XOR cost naturally existing in the type-three elementary matrix and the XOR cost of the coefficients in the type-two and type-three elementary matrices. There is no cost for the type-one elementary matrix. The local optimal principle is: the type-two elementary matrix introduced each time is the one that eliminates the most coefficients λ of the type-three elementary matrix. The number of eliminations refers to the number of matrices that reduce the absolute value of the times of the coefficients λ in the type-three elementary matrix after the introduction of the type-two elementary matrix. The type-two elementary matrix is ​​continuously introduced until the number of eliminations of the coefficients λ of the type-three elementary matrix no longer decreases.

4. The method for constructing a linear diffusion matrix in a block cipher design according to claim 3, characterized in that: Step 3 is as follows: The optimized linear diffusion matrix pattern is instantiated, and the low-cost binary matrix L is traversed and brought into the linear diffusion matrix pattern to determine whether the branch number requirement is met; the linear diffusion matrix that meets the branch number requirement is output; for the linear diffusion matrix that does not meet the branch number requirement, return to step 1 to select other three-type elementary matrices that lead to the same descent target to continue constructing the linear diffusion matrix pattern; if there are no other three-type elementary matrices that lead to the same phase descent target, the coefficient selection range of the three-type elementary matrix is ​​expanded until a linear diffusion matrix pattern that meets the target branch number can be constructed.

5. The method for constructing a linear diffusion matrix in a block cipher design according to claim 2, characterized in that: Step 1: Firstly, the linear diffusion matrix pattern that meets the branch number requirement is constructed based on the greedy algorithm using three types of elementary matrices; specifically, the elementary matrices include three types, namely, swapping two rows, multiplying one row by the coefficient λ, and multiplying one row by the coefficient λ and adding it to another row, where the coefficient λ={..·,L -2 ,L -1 ,1,L,L 2 ,…}, respectively denoted as M I ,M II ,M III ; Any non-singular matrix can be decomposed into the product of several type 1 elementary matrices, type 2 elementary matrices, and type 3 elementary matrices, such as: Construct a linear diffusion matrix pattern with a search range based on the binary matrix L, so the polynomial representation of each term after matrix multiplication is calculated through symbolic operations; set the greedy algorithm rules and branch number judgment criteria, and continuously screen and left-multiply the three-type elementary matrix based on the unit matrix of a specific scale according to the greedy algorithm until a linear diffusion matrix pattern that meets the branch number requirements is found; Specifically, according to the determination theorem of MDS matrix, a matrix is ​​an MDS matrix if and only if all its submatrices are non-singular; when setting the greedy algorithm rules, the number of singular submatrices is used as the greedy algorithm target, that is, the type-three elementary matrix with the largest decrease in the number of singular submatrices after each left multiplication by a different type-three elementary matrix is ​​selected; in the process of the greedy algorithm, multiple type-three elementary matrices may appear, leading to the same descent target; in this case, the type-three elementary matrix that appears first is selected, and other type-three elementary matrices that lead to the same descent target are retained for subsequent use; after each selection of a type-three elementary matrix for left multiplication, the branch number judgment criterion is used. Specifically, according to the definitions of the differential branch number and the linear branch number, let A be a general linear group A is a matrix on a finite field, that is, A is defined on a finite field (binary field) is an n×n reversible matrix, then the number of differential branches of A is β d (A) is defined as the minimum value of the non-zero components of the input vector x and the output vector Ax, considering all non-zero input vectors x, that is, where w(x) represents the number of non-zero components in vector x; similarly, the number of linear branches A T Represents the transposed matrix of matrix A; traverses all non-zero inputs, calculates the output of the left multiplication matrix and the output of the left multiplication matrix transpose, and determines whether the minimum sum of the non-zero components in the input and output is the same as the number of branches; until a linear diffusion matrix pattern that meets the branch number requirements is formed.

6. The method for constructing a linear diffusion matrix in a block cipher design according to claim 5, characterized in that: The specific method of step 2 is as follows: The type II elementary matrix By equivalent exchange, any position of the M matrix product form is introduced from one end, that is: By introducing the type II elementary matrix Simultaneously eliminate three types of elementary matrices Based on the local optimal principle, each time a type-two elementary matrix is ​​introduced, the one that eliminates the largest number of type-three elementary matrix coefficients λ is eliminated. The number of eliminations refers to the number of matrices whose absolute values ​​of the degrees of coefficients λ in the type-three elementary matrix are reduced after the type-two elementary matrix is ​​introduced. The type-two elementary matrix is ​​continuously introduced until the number of type-three elementary matrix coefficients λ that are eliminated no longer decreases.

7. A linear diffusion matrix construction system in block cipher design, characterized in that: The method for constructing a linear diffusion matrix according to claim 1-6 comprises: Linear diffusion matrix pattern construction module, based on the greedy algorithm, uses three types of elementary matrices to construct linear diffusion matrix patterns that meet specific scales and specific branch numbers; The linear diffusion matrix model optimization module uses the type-two elementary matrix to optimize the linear diffusion matrix model realization cost under the principle of local optimality; The linear diffusion matrix model instantiation module is used to instantiate the linear diffusion matrix model and output a linear diffusion matrix that meets a specific scale and a specific number of branches.

8. An electronic device comprising: A memory and one or more processors connected to the memory, the memory storing a computer program, and the processor being configured to execute the computer program to implement the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium storing computer-executable instructions for executing the steps of the method according to any one of claims 1 to 6.