Lightweight block cipher binary linear matrix automatic design method and system

By using the automation tool STP solver and the g-XOR method, a binary linear matrix that meets specific cryptographic properties is designed, which solves the problem of difficulty in taking into account security and implementation costs in the prior art, and realizes efficient encryption in resource-constrained environments.

CN120180422APending Publication Date: 2025-06-20HANGZHOU DIANZI UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510328101.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

When designing bit-level binary linear matrix, it is difficult for the prior art to take into account both security and implementation costs in resource-constrained environments, resulting in poor results in practical applications.

Method used

The automation tool STP solver is used and combined with the g-XOR method to design a binary linear matrix that meets specific cryptographic properties, considering security and implementation costs, and converting it into CVC language for solution through mathematical model.

Benefits of technology

It is implemented to design a binary linear matrix with excellent security properties and low implementation costs at a given cryptographic cost, suitable for resource-constrained environments, and can contain all possible solutions for judging the limits of costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005319452220000041
    Figure BDA0005319452220000041
  • Figure BDA0005319452220000042
    Figure BDA0005319452220000042
  • Figure BDA0005319452220000071
    Figure BDA0005319452220000071
Patent Text Reader

Abstract

The invention discloses a lightweight block cipher binary linear matrix automatic design method and system. Meanwhile, the implementation cost and the safety property of constructing the binary linear matrix are considered, and from the perspective of circuit implementation, an automatic tool is used for constructing the binary linear matrix. From the perspective of circuit realization, the realization cost of two dimensions of area and time delay can be considered, and the cryptography cost is constrained while the security property of the binary linear matrix is considered. In addition, a g-XOR method is used for designing the matrix, and compared with a traditional method for iteratively designing according to the structure or constructing a binary linear matrix through mathematical derivation, the implementation cost is the lowest, all solutions for constructing the binary linear matrix can be included, and the method can be used for judging the cost limit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of block cipher design, and particularly relates to a method and system for automatically designing a lightweight block cipher binary linear matrix. Background Art

[0002] With the rapid development of the Internet of Things technology (IoT), the applications of microcomputing devices such as RFID chips and wireless sensor networks are becoming more and more extensive, bringing great convenience to people's lives. At the same time, these devices have strict resource limitations in terms of circuit area size, power consumption, and latency. Traditional cryptographic algorithms have high computational complexity and large storage requirements, and are not applicable to this environment. Lightweight block ciphers, due to their simple hardware implementation and low running power consumption, can efficiently provide information confidentiality and reliability guarantees in resource-constrained environments, and have become one of the research hotspots in the cryptographic community.

[0003] The design of lightweight block ciphers revolves around two main criteria, namely confusion and diffusion. Among them, the main role of the diffusion layer is to disperse the statistical structure of the plaintext into various parts of the ciphertext to prevent attackers from cracking the cipher by analyzing the statistical characteristics of the ciphertext. The security performance and implementation cost of the diffusion layer components determine whether the encryption algorithm can still have the required security strength in a resource-constrained environment. How to balance the relationship between the two is the focus of the current research on diffusion layer components. Among them, the bit-level binary matrix is one of the important components in the diffusion layer. It does not involve multiplication operations over finite fields, and only requires several exclusive-or operations for implementation, which can effectively improve the hardware implementation efficiency and security of cryptographic algorithms in resource-constrained environments.

[0004] At present, the main design methods of bit-level binary linear matrices are divided into two types: design relying on mathematical methods and design with special encryption structures. The former only considers whether the matrix can achieve the optimal security property, that is, the maximum branch number, but ignores the costs required for the hardware and software implementation of the linear matrix, resulting in the resulting matrix being unable to be well applied to actual algorithms; the latter constructs matrices with friendly hardware and software implementation characteristics and has optimal security properties, but is limited by the structure itself, and matrices in some dimensions cannot be designed or have poor effects, and cannot cover all possibilities. Summary of the Invention

[0005] In view of the deficiencies in the prior art, the present invention provides a lightweight block cipher binary linear matrix automated design method and system. By using the automated tool STP (Simple Theorem Prover) solver, it is possible to design a binary linear matrix that meets specific cryptographic properties under a given cryptographic cost, taking into account both the security properties of the components and the constraints on the required hardware cost, and at the same time being able to search for the boundaries between the security properties and implementation costs of the binary linear matrix.

[0006] The present invention simultaneously considers the security properties and implementation costs of the linear matrix, converts them into a mathematical model and characterizes them using the CVC language, and finally uses the STP solver to solve them.

[0007] The security properties include: the invertibility and branch number of the binary linear matrix;

[0008] The implementation costs include: the area of the hardware circuit implementation (the number of XOR gates) and the delay (the depth of the hardware implementation circuit).

[0009] In one aspect, given the required cryptographic cost and cryptographic security properties by the user, a lightweight block cipher binary linear matrix automated design method includes the following steps:

[0010] Step (1): The linear matrix can be constructed from the identity matrix through XOR operations. Initially, an n×n identity matrix is given, and its row vectors or column vectors are subjected to a number of XOR operations to obtain the target linear matrix. Since the construction of the linear matrix only involves XOR operations, the area of its hardware circuit implementation can be directly measured by the number of XOR gates. Currently, the counting methods of XOR gates are divided into three types: d-XOR, s-XOR, and g-XOR, among which g-XOR is the mode with the lowest cost among the three and can cover the other two modes. The present invention implements the counting of XOR gates based on the g-XOR method, and the specific operations are as follows:

[0011] The definition of g-XOR is: Given a binary linear matrix M of m×n dimensions, each row of the matrix M corresponds to a linear expression of n-bit input, then the implementation of the matrix M can be written as XOR sequence, where 0≤j,k≤l, and i = n,n + 1,…,t - 1 and x0,x1,…,x n-1 is an n-bit input unit vector.

[0012] According to the definition of g-XOR, the construction of the binary linear matrix M can be split into several XOR sequences that satisfy The binary linear matrix M is regarded as a vector group with m n-bit vectors. Initially, the vector group contains n input unit vectors x0,x1,…,x n-1, each XOR operation selects two vectors from the vector group to perform XOR to obtain a result variable, and adds the new variable to the vector group. The specific implementation method is as follows: for each XOR operation, a flag bit is provided for each vector in the current vector group to mark whether the vector participates in the operation in this XOR operation. If the flag bit is 1, it means the vector participates in the operation; if the flag bit is 0, it does not participate in the operation. The new vector obtained by this XOR operation is equal to the new vector obtained by XORing all the current vectors with their flag bits, and is stored in the vector group.

[0013] The constraint on the area of the hardware circuit implementation of the binary linear matrix is equivalent to the constraint on the XOR operation. The process of counting the XOR gates implemented based on the g-XOR method is converted into a mathematical model of the cryptographic cost area part to characterize each XOR operation.

[0014] Step (2): In addition to the area cost of the hardware circuit implementation, the latency is also an important parameter to be considered. A smaller latency can bring a faster encryption speed. The latency is measured by the depth of the hardware circuit implementation, that is, the number of clock cycles required for the circuit implementation. Converting the hardware circuit implementation into a graph, the circuit depth is the number of nodes on the critical path.

[0015] The present invention adds a depth variable to each vector in the vector group in step (1) to record the depth value of the vector, and at the same time restricts the depth of each vector in the vector group to be no greater than a specified value to achieve the constraint on the latency of the overall hardware circuit implementation and complete the characterization of the depth. The above process of characterizing the depth is converted into a mathematical model of the cryptographic cost latency part.

[0016] Step (3): Characterize the cryptographic properties required for the linear matrix to ensure that the constructed binary linear matrix is invertible and has a certain branch number.

[0017] The invertibility of the linear matrix ensures that different plaintexts do not collide during the encryption process, and its inverse matrix can also be directly used in the decryption process. The present invention utilizes the equivalence between the invertibility of the linear matrix and the linear independence of its row and column vectors, and converts the linear independence of the row vectors of the matrix into a mathematical model of the invertible part of the cryptographic properties.

[0018] The branch number of the linear matrix measures the ability of the linear matrix to resist attacks, which is directly related to the minimum number of active elements in two consecutive S-boxes. The larger the branch number, the higher the security. The branch number is divided into the differential branch number and the linear branch number, and it is required that the differential branch number is equal to the linear branch number. The following gives the definitions of the two:

[0019] For the binary linear matrix M, the definition of its differential branch number is:

[0020]

[0021] The linear branch number is defined as:

[0022]

[0023] where M T is the transpose matrix of M, and w b (v) represents the number of non-zero elements in vector v, that is, the Hamming weight of the vector.

[0024] Convert the differential branch number and the linear branch number into the mathematical model of the cryptographic property branch number part at the same time.

[0025] Step (4): Convert the obtained mathematical models of the cryptographic costs (the number of XOR gates, depth) and cryptographic properties (reversibility, branch number) into the CVC language used by the STP solver and write them into the CVC file in order. Use the automated tool STP to solve the binary linear matrix that satisfies the corresponding cryptographic costs and properties. If there is a solution, obtain the specific content of all XOR operations and the values of the constructed binary linear matrix from the solution results; if there is no solution, it means that it is impossible to construct a binary linear matrix with the given cryptographic properties under the given cryptographic costs.

[0026] On the other hand, the present invention provides an automated design system for a lightweight block cipher binary linear matrix, including an XOR gate counting module, a depth characterization module, a cryptographic property characterization module, and a binary linear matrix solving module.

[0027] The XOR gate counting module realizes the counting of XOR gates based on the g-XOR method. The specific operations are as follows:

[0028] The definition of g-XOR is: Given a binary linear matrix M of dimension m×n, each row of matrix M corresponds to a linear expression of n-bit input, then the implementation of matrix M can be written as the XOR sequence of, where 0 ≤ j, k ≤ l, and i = n, n + 1, …, t - 1 and x0, x1, …, x n-1 is the n-bit input unit vector.

[0029] According to the definition of g-XOR, the construction of the binary linear matrix M can be split into several XOR sequences that satisfy Regarding the binary linear matrix M as a vector group with m n-bit vectors, initially the vector group contains n input unit vectors x0, x1, …, x n-1, in each XOR operation, two vectors are selected from the vector group for XOR to obtain a result variable, and the new variable is added to the vector group. The specific implementation method is as follows: for each XOR operation, a flag bit is provided for each vector in the current vector group to mark whether the vector participates in the operation in this XOR operation. If the flag bit is 1, it means the vector participates in the operation; if the flag bit is 0, it does not participate in the operation. The new vector obtained from this XOR operation is equal to the new vector obtained by XORing all the current vectors with their flag bits, and is stored in the vector group.

[0030] The constraint on the area of the hardware circuit implementation of the binary linear matrix is equivalent to the constraint on the XOR operation. The process of counting the XOR gates implemented based on the g-XOR method is converted into a mathematical model of the cryptographic cost area part to characterize each XOR operation.

[0031] The described depth characterization module is specifically implemented as follows:

[0032] The latency is measured by the depth of the hardware circuit implementation, that is, the number of clock cycles required for the circuit implementation. The hardware circuit implementation is converted into a graph, and the circuit depth is the number of nodes on the critical path.

[0033] Regard the binary linear matrix M as a vector group with m n-bit vectors. Add a depth variable to each vector in the vector group to record the depth value of the vector, and at the same time limit the depth of each vector in the vector group to be no greater than the specified value. The above process of characterizing the depth is converted into a mathematical model of the cryptographic cost latency part.

[0034] The described cryptographic property characterization module characterizes the cryptographic properties required for the linear matrix to ensure that the constructed binary linear matrix is invertible and has a certain branch number. The specific implementation is as follows:

[0035] Utilize the equivalence between the invertibility of the linear matrix and the linear independence of its row and column vectors, and convert the linear independence of the row vectors of the matrix into a mathematical model of the invertible part of the cryptographic property.

[0036] The branch number of the linear matrix measures the ability of the linear matrix to resist attacks, which is directly related to the minimum number of active elements in two consecutive S-boxes. The larger the branch number, the higher the security. The branch number is divided into the differential branch number and the linear branch number, and it is required that the differential branch number is equal to the linear branch number. The definitions of the two are given as follows:

[0037] For the binary linear matrix M, the definition of its differential branch number is:

[0038]

[0039] And the linear branch number is defined as:

[0040]

[0041] where M T is the transpose matrix of M, and w b (v) represents the number of non-zero elements in vector v, that is, the Hamming weight of the vector.

[0042] Convert the differential branch number and the linear branch number into a mathematical model of the cryptographic property branch number part at the same time.

[0043] The described binary linear matrix solving module converts the obtained mathematical models of cryptographic costs (the number of XOR gates, depth) and cryptographic properties (reversibility, branch number) into the CVC language used by the STP solver and writes them into the CVC file in order, and uses the automated tool STP to solve the binary linear matrix that meets the corresponding cryptographic costs and properties. If there is a solution, obtain the specific content of all XOR operations and the constructed binary linear matrix value from the solution result; if there is no solution, it means that it is impossible to construct a binary linear matrix with given cryptographic properties under the given cryptographic costs.

[0044] The beneficial effects of the present invention are as follows:

[0045] The present invention simultaneously combines and considers the implementation cost and security properties of constructing a binary linear matrix. From the perspective of circuit implementation, an automated tool is used to construct the binary linear matrix. The traditional method of designing a binary linear matrix only considers security properties. The present invention, from the perspective of circuit implementation, can take into account the implementation costs in both the area and delay dimensions, and constraints the cryptographic costs while considering the security properties of the binary linear matrix. Moreover, the present invention uses the g-XOR method to design the matrix. Compared with the traditional method of iterative design according to the structure or constructing the binary linear matrix using mathematical derivation, the implementation cost is the lowest, and all solutions for constructing the binary linear matrix can be included, which can be used to judge the cost boundary. Specific embodiments

[0046] The technical solution of the present invention will be further described below in conjunction with embodiments.

[0047] The present invention takes the security parameters and implementation costs of the bit-level matrix as the design goals, including several parameters such as branch number, reversibility, the number of XOR gates, and circuit depth. It is required to use the STP solver to solve the reversible binary matrix that meets the branch number under the conditions of several XOR gates and depth.

[0048] Construct a binary linear matrix under the condition of r XOR gates, with a branch number of B and a depth not exceeding D. First, Table 1 shows the common functions of the CVC language used by STP:

[0049] Table 1: CVC language table

[0050]

[0051] The following describes how the design method and system convert the cryptographic cost and cryptographic properties (including g-XOR, depth, reversibility, branch number) of a binary linear matrix into a mathematical model and represent it using the CVC language:

[0052] First, the g-XOR method is used to characterize each XOR operation in the solution process. For a given m×n-dimensional binary matrix M, it is determined whether there exists a set of XOR sequences that can represent the matrix M, where 0 ≤ j, k ≤ l, and i = n, n + 1, …, t - 1 and x0, x1, …, x n-1 are n-bit input unit vectors.

[0053] Construct the target binary linear matrix. Starting from a vector group containing n initial vectors, these n initial vectors form an n×n identity matrix. For each XOR in r rounds of XOR operations, two vectors are selected from the vector group for XOR to obtain a new vector and add it to the vector group. To describe the operation of selecting two vectors, a flag bit a i,j is added to each vector in the vector group for each round of XOR, and it is determined whether it is equal to 1 to represent whether the vector x j participates in the operation in the i-th round of XOR. Since only two vectors are selected for XOR each time, the sum of the flag bits for each round of XOR is 2. Then, the description of the new vector obtained from the i-th round of XOR operation and the constraints of the flag bits can be converted into a mathematical model, and the specific formula is expressed as follows:

[0054]

[0055] To facilitate the use of the automated tool STP for solving, the mathematical model needs to be converted into the corresponding CVC input language. The following is the CVC language corresponding to the above mathematical model:

[0056] ASSERT(x i+n

[0057] = BVXOR(…(BVXOR(BVMULT(n, a0, x0), BVMULT(n, a1, x1)))…BVMULT(n, a n+i-1 , x1)));

[0058] ASSERT(BVPLUS(n, a i,0 , a i,1 , …, a i,n+i-1 ) = 0bin00…010);

[0059] For a given r - th XOR operation, it is all converted into CVC language.

[0060] Excluding the constraints on XOR, the present invention also adds a depth characterization. A depth variable d is added to each vector in the vector group i to record the depth of this variable. It is stipulated that the depth of all initial unit vectors is 0. Therefore, we have:

[0061]

[0062] For the depth of newly generated vectors subsequently, according to the definition, it is equal to the larger of the depth values of two precursor vectors plus 1. Since it is impossible to know which two vectors the new vector is obtained by XOR, consider using the flag bits of each round of XOR to assist in completing the depth characterization. The flag bits have the following characteristics: If the j - th vector x in the vector group j participates in the operation in the i - th round of XOR, then the corresponding flag bit a i,j = 1, otherwise it is equal to 0. Using this characteristic, a new parameter g_d i,j is defined for each vector in the vector group as g_d i,j = a j ·d i,j . If g_d i,k is greater than 0 and greater than or equal to all other g_d j (k≠j), it means that the vector x j participates in the operation in this round of XOR and its depth is greater than or equal to that of another vector participating in the operation. And d i,0 is the depth of the precursor node with a larger depth value in this XOR. Therefore, the mathematical model of the depth of the new node generated by the i - th XOR can be described as:

[0063]

[0064] For the i - th XOR, taking d0 as an example, the following explains how to convert the depth of if a i,j ·d0≥all a j ·d i+n to d0 + 1 into CVC language:

[0065] ASSERT(IF BVGE((BVMULT(a i,0 ,d0),BVMULT(a i,1 ,d1))AND

[0066] ……

[0067] AND BVGE((BVMULT(a i,0 ,d0),BVMULT(a i,i+n-1 ,d i+n-1 ))

[0068] THEN d i+n = BVPLUS(4, d0, 0bin0001) ENDIF);

[0069] For the depth d of the vector generated by the i-th XOR i+n It can be defined in CVC language as:

[0070] ASSERT(IF BVGE((BVMULT(a i,j , d j ), BVMULT(a i,0 , d0)) AND

[0071] ASSERT(IF BVGE((BVMULT(a i,j , d j , BVMULT(a i,1 , d1)) AND

[0072] ……

[0073] AND BVGE((BVMULT(a i,j , d j ), BVMULT(a i,i+n-1 , d i+n-1 ))

[0074] THEN d i+n = BVPLUS(4, d j , 0bin0001) ENDIF);

[0075] After characterizing the depths of all vectors, it is also necessary to constrain that all depth values are less than or equal to D, that is:

[0076]

[0077] Converted to CVC language as:

[0078] ASSERT(BVLE(d0, D));

[0079] …

[0080] ASSERT(BVLE(d n+r-1 , D));

[0081] Convert the constraints on the depth of each vector into CVC language.

[0082] After completing the above constraints on the XOR cryptographic cost of r rounds, n + r vectors can be obtained. Select the last n vectors x in order r , x r+1 , …, x n+r-1Construct a binary linear matrix \(M = \{y_0, y_1, \ldots, y\}\) n-1} T , and further add the characterization of the invertibility and branch number of the binary linear matrix \(M\). Expressed in CVC language as:

[0083] ASSERT(y0 == x r );

[0084] ASSERT(y1 == x r+1 );

[0085] …

[0086] ASSERT(y n-1 == x n+r-1 );

[0087] For the invertibility of the constructed matrix, using the characteristic that the linear independence of the row vectors of the matrix is equivalent to the invertibility of the matrix, the invertibility is characterized by characterizing the linear independence of the row vectors of the matrix. The definition of vector linear independence is:

[0088] For a set of vectors \(\{x_0, x_1, \ldots, x\}\), if the equation: n-1}, if the equation:

[0089] k0·x0 + k1·x1 + … + k n-1 ·x n-1 == 0

[0090] holds if and only if all k i are equal to 0, then the vectors x0, x1, …, x n-1 can be said to be linearly independent. For binary vectors, this condition can be described as that for any i - element combination (1 ≤ i ≤ n) of x0, x1, …, x in the vector group, its XOR result is not equal to the 0 vector. Then for the binary linear matrix \(M = \{y_0, y_1, \ldots, y\}\) n-1}, it can be described as: n-1} T , it can be described as:

[0091]

[0092] Converted to CVC language as:

[0093] ASSERT(y0 == 0bin0);

[0094] …

[0095] ASSERT(BVXOR(y n-2 , y n-1 ) == 0bin0);

[0096] ASSERT(BVXOR(BVXOR(y0,y1),y2) == 0bin0);

[0097] …

[0098] ASSERT(BVXOR…(BVXOR(y0,y1),y2)…y n-1 ) == 0bin0)

[0099] Convert the characterization of the invertibility of the binary linear matrix M = {y0, y1, …, y n-1} T into CVC language.

[0100] Finally, for the characterization of the branch number, since it is required that the differential branch number of the matrix is equal to the linear branch number; for the differential branch number, from its definition, it can be seen that if the branch number of the matrix is to reach B, then for all non - zero vectors v, w b (v)+w b (M(v)) has a minimum value greater than or equal to B. The result of the product M·v of the matrix M and the vector v is equal to the sum of the exclusive - or operations of several corresponding column vectors in the matrix M, where the subscripts of the column vectors participating in the operation correspond to the subscripts of the elements with value 1 in the vector v. Using this rule, w b (M(v)) is equal to the Hamming weight of the exclusive - or result of the corresponding column vectors, and it is required that for all vectors with non - zero Hamming weight, w b (M(v))≥B - w b (v), then:

[0101]

[0102] The characterization of the differential branch number can be completed. Similarly for the linear branch number, that is:

[0103]

[0104] Convert the above differential branch number into CVC language, specifically as follows:

[0105] ASSERT(BVGE(w b (y0), B - 1));

[0106] …

[0107] ASSERT(BVGE(w b (BVXOR(y n-2 , y n-1 ))), B - 2));

[0108] ASSERT(BVGE(w b(BVXOR(BVXOR(y0,y1),y2)),B-3));

[0109] …

[0110] ASSERT(BVGE(w b (BVXOR…(BVXOR(y n-s+1 ,y n-s+2 ),…y n-1 ))),1));

[0111] Similarly, convert the linear branch number to CVC language as follows:

[0112]

[0113] Similarly, convert the characterization of the above branch numbers (including differential branch numbers and linear branch numbers) into the corresponding CVC language.

[0114] After writing the CVC language obtained by converting the characterizations of XOR operations, depth, reversibility, and branch numbers into the same CVC file in order, use the STP solver to solve the CVC file. If there is no solution, it means that a binary linear matrix satisfying the given cryptographic properties cannot be constructed under the given cryptographic cost; if there is a solution, the relevant parameters of each XOR operation and the value of the finally constructed binary linear matrix will be returned in the result.

[0115] The results of the binary linear matrix constructed using the present invention are shown in Table 2 and compared with the current optimal results, including the results of "Constructing lightweight optimal diffusion primitives with Feistel structure" [1], the results of designing a binary linear matrix using the iterative Feistel structure proposed by Guo et al. at the SAC conference in 2015, and "Constructing binary matrices with good implementation properties for low-latency block ciphers based on Lai-Massey structure" [2], the results of designing a binary linear matrix using the iterative Lai-Massey structure by Li et al. in the Comput. J. journal in 2023. The results show that, on the premise of ensuring the same cryptographic properties, the depth of the binary linear matrix constructed by the present invention is less than or equal to the existing optimal results, and the number of XOR gates is mostly less than the existing optimal results.

[0116] Table 2: Result comparison table

[0117]

[0118] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.

Claims

1. A method for automatically designing binary linear matrices for lightweight block ciphers, characterized in that: The steps include: Step (1): Implement the counting of XOR gates based on the g-XOR method and convert it into a mathematical model of the cryptographic cost area part; Step (2): In addition to the area cost of the hardware circuit implementation, latency is also an important parameter that needs to be considered. Smaller latency can lead to faster encryption speed. Latency is measured by the depth of the hardware circuit implementation, that is, the number of clock cycles required for the circuit implementation. Convert the hardware circuit implementation into a graph, where the circuit depth is the number of nodes on the critical path; The binary linear matrix M is regarded as a vector group with m n-bit vectors, and a depth variable is added to each vector in the vector group to record the depth value of the vector. At the same time, the depth of each vector in the vector group is restricted to be no greater than the specified value, thus completing the characterization of the depth; the above characterization process of the depth is converted into a mathematical model of the cryptographic cost delay part; Step (3): characterize the cryptographic properties required by the linear matrix, ensure that the constructed binary linear matrix is ​​reversible and has a certain number of branches; obtain a mathematical model of the cryptographic properties; Step (4): Convert the obtained cryptographic cost and the mathematical model of the cryptographic property into the CVC language used by the STP solver and write them into the CVC file in sequence, and use the automated tool STP to solve the binary linear matrix that satisfies the corresponding cryptographic cost and property; if there is a solution, obtain the specific content of all XOR operations and the constructed binary linear matrix value from the solution result; If there is no solution, it means that there is no solution to construct a binary linear matrix with given cryptographic properties at a given cryptographic cost.

2. A method for automatically designing a binary linear matrix for a lightweight block cipher according to claim 1, characterized in that: The counting of XOR gates is realized based on the g-XOR method. The specific operations are as follows: The definition of g-XOR is: given a binary linear matrix M of m×n dimensions, each row of the matrix M corresponds to a linear expression of n-bit input, then the implementation of the matrix M can be written as XOR sequence, where 0≤j, k≤l, and i=n,n+1,…,t-1 and x0,x1,…,x n-1 is the n-bit input unit vector; According to the definition of g-XOR, the construction of the binary linear matrix M can be split into several XOR sequence; the binary linear matrix M is regarded as a vector group with m n-bit vectors. Initially, the vector group contains n input unit vectors x0, x1, …, x n-1 , each XOR operation selects two vectors from the vector group to XOR the result variable, and adds the new variable to the vector group; the specific implementation method is: for each XOR operation, a flag is provided for each vector in the current vector group to mark whether the vector participates in the operation in this XOR operation. If the flag is 1, it means that the vector participates in the operation, and if the flag is 0, it does not participate in the operation; the new vector obtained by this XOR operation is equal to the new vector obtained by XORing the product of all current vectors and their flags, and is stored in the vector group; The constraint on the area of ​​the binary linear matrix hardware circuit is equivalent to the constraint on the XOR operation. The process of counting XOR gates based on the g-XOR method is converted into a mathematical model of the cryptographic cost area part to characterize each XOR operation.

3. A method for automatically designing a binary linear matrix for a lightweight block cipher according to claim 1, characterized in that: By using the equivalence between the reversibility of a linear matrix and the linear independence of its row and column vectors, the linear independence of the row vectors of the matrix is ​​transformed into a mathematical model of the reversibility part of the cryptographic property. The number of branches of a linear matrix measures the ability of the linear matrix to resist attacks. It is directly related to the minimum number of active S-boxes in two consecutive rounds. The larger the number of branches, the higher the security. The number of branches is divided into the number of differential branches and the number of linear branches. The number of differential branches is required to be equal to the number of linear branches. The definitions of the two are given below: For a binary linear matrix M, the number of differential branches is defined as: The linear branching number is defined as: Among them, M T is the transposed matrix of M, w b (v) represents the number of non-zero elements in vector v, that is, the Hamming weight of the vector; A mathematical model for simultaneously converting differential branching numbers and linear branching numbers into the cryptographic property branching number part.

4. A method for automatically designing a binary linear matrix for a lightweight block cipher according to claim 1 or 2, characterized in that: Step (1) is specifically implemented as follows: First, the g-XOR method is used to characterize each XOR operation in the solution process; for a given m×n dimensional binary matrix M, g-XOR determines whether there is a set of The XOR sequence can represent the matrix M, where 0≤j, k≤l, and i=n,n+1,…,t-1 and x0,x1,…,x n-1 is the n-bit input unit vector; Construct the target binary linear matrix, starting from a vector group containing n initial vectors, which form an n×n unit matrix; for each XOR operation in r rounds, two vectors are selected from the vector group for XOR to obtain a new vector and add it to the vector group; in order to describe the operation of selecting two vectors, a flag bit a is added to each vector in the vector group in each round of XOR i,j , and represents the vector x by judging whether it is equal to 1 j Whether to participate in the operation in the i-th round of XOR; since only two vectors are selected for XOR each time, the sum of the flag bits of each round of XOR is 2; the description of the new vector obtained by the i-th round of XOR operation and the constraint of the flag bit can be converted into a mathematical model, and the specific formula is as follows: In order to facilitate the use of the automated tool STP for solving, the mathematical model needs to be converted into the corresponding CVC input language; the following is the CVC language corresponding to the above mathematical model: ASSERT(x i+n =BVXOR(…(BVXOR(BVMULT(n,a0,x0),BVMULT(n,a1,x1)))…BVMULT(n,a n+i-1 ,x1))); ASSERT(BVPLUS(n,a i,0 ,a i,1 ,…,a i,n+i-1 )=0bin00…010); For a given r XOR operations, they are converted into CVC language.

5. The method for automatically designing a binary linear matrix for a lightweight block cipher according to claim 4, characterized in that: In addition to the constraints on XOR, a depth characterization is added. For each vector in the vector group, a depth variable d is added. i Used to record the depth of the variable; it is stipulated that the depth of all initial unit vectors is 0; therefore: The depth of the newly generated vector is defined as the larger of the two predecessor vector depths plus 1. The depth characterization is completed using the flag bit of each round of XOR. The flag bit has the following characteristics: if the jth vector x in the vector group j In the i-th round of XOR operation, the corresponding flag bit a i,j =1, otherwise it is equal to 0; using this feature, a new parameter g_d is defined for each vector in the vector group i,j =a i,j ·d j ; if g_d i,j Greater than 0, and greater than or equal to all other g_d i,k , k≠j, represents the vector x j It participates in the operation in this round of XOR, and its depth is greater than or equal to another vector participating in the operation; and d j That is, the depth of the predecessor node with a larger depth value in this XOR; therefore, the mathematical model of the depth of the new node generated by the i-th XOR can be described as: For the i-th XOR, taking d0 as an example, the following explains how to convert a i,0 ·d0≥all a i,j ·d j , then d i+n The depth of d0+1 is converted into CVC language: ASSERT(IF BVGE((BVMULT(a i,0 ,d0),BVMULT(a i,1 ,d1))AND …… AND BVGE((BVMULT(a i,0 ,d0),BVMULT(a i,i+n-1 ,d i+n-1 )) THEN d i+n =BVPLUS(4,d0,0bin0001)ENDIF); For the depth d of the vector generated by XOR for the i-th time i+n The CVC language can be defined as: ASSERT(IF BVGE((BVMULT(a i,j ,d j ),BVMULT(a i,0 ,d0))AND ASSERT(IF BVGE((BVMULT(a i,j ,d j ),BVMULT(a i,1 ,d1))AND …… AND BVGE(BVMULT(a i,j ,d j ),BVMULT(a i,i+n-1 ,d i+n-1 )) THEN d i+n =BVPLUS4,d j ,0bin0001)ENDIF); After characterizing the depth of all vectors, it is also necessary to constrain all depth values ​​to be less than or equal to D, that is: Converted to CVC language: ASSERT(BVLE(d0,D)); … ASSERT(BVLE(d n+r-1 ,D)); The constraints on each vector depth are converted into CVC language.

6. A method for automatically designing binary linear matrices for lightweight block ciphers according to claim 5, characterized in that: After completing the constraints of the cost of XOR cryptography for r rounds, we get n+r vectors, and select the last n vectors x in order. r ,x r+1 ,…,x n+r-1 The binary linear matrix M = {y0,y1,…,y n-1 } T , and further add the characterization of the reversibility and number of branches of the binary linear matrix M; expressed in CVC language as: ASSERT(y0=x r ); ASSERT(y1=x r+1 ); … ASSERT(y n-1 =x n+r-1 ); For the reversibility of the constructed matrix, we use the characteristics that the linear independence of matrix row vectors is equivalent to the reversibility of the matrix, and characterize the reversibility by characterizing the linear independence of matrix row vectors; for the vector group x0,x1,…,x n-1 For any i-th combination 1≤i≤n, the XOR result is not equal to the zero vector. Then for the binary linear matrix M={y0,y1,…,y n-1 } T , is described as: Converted to CVC language: ASSERT(y0=0bin0); … ASSERT(BVXOR(and n-2 ,and n-1 )=0bin0); ASSERT(BVXOR(BVXOR(y0,y1),y2)=0bin0); … ASSERT(BVXOR…(BVXOR(y0,y1),y2)…y n-1 )=0bin0) For a binary linear matrix M = {y0, y1, ..., y n-1 } T The characterization of reversibility is converted into CVC language.

7. A method for automatically designing binary linear matrices for lightweight block ciphers according to claim 6, characterized in that: Finally, the characterization of the number of branches is as follows. Since the number of differential branches of the matrix is ​​required to be equal to the number of linear branches, the definition of the number of differential branches shows that if the number of matrix branches is to reach B, then for all non-zero vectors v, w is satisfied. b (v)+w b The minimum value of (M(v)) is greater than or equal to B; the product of matrix M and vector v, M·v, is equal to the sum of the XOR operations of the corresponding column vectors in matrix M, where the subscripts of the column vectors involved in the operation correspond to the subscripts of the elements with a value of 1 in vector v; using this rule, w b (M(v)) is equal to the Hamming weight of the corresponding column vector XOR result, and it is required that for all vectors with non-zero Hamming weight, there is w b (M(v))≥Bw b (v) then: The number of differential branches can be described, and the number of linear branches is the same, that is: The above differential branch number is converted into CVC language as follows: ASSERT(BVGE(w b (y0),B-1)); … ASSERT(BVGE(w b (BVXOR(y n-2 ,y n-1 )),B-2)); ASSERT(BVGE(w b (BVXOR(BVXOR(y0,y1),y2)),B-3)); … ASSERT(BVGE(w b (BVXOR…(BVXOR(y n-s+1 ,y n-s+2 ),…y n-1 )),1)); Similarly, the linear branch number is converted into CVC language as follows: … … Similarly, the above description of the number of branches is converted into the corresponding CVC language.

8. A lightweight block cipher binary linear matrix automatic design system, including an XOR gate counting module, a depth characterization module, a cryptographic property characterization module and a binary linear matrix solving module; The XOR gate counting module implements XOR gate counting based on the g-XOR method, and the specific operations are as follows: The definition of g-XOR is: given a binary linear matrix M of m×n dimensions, each row of the matrix M corresponds to a linear expression of n-bit input, then the implementation of the matrix M can be written as XOR sequence, where 0≤j, k≤l, and i=n,n+1,…,t-1 and x0,x1,…,x n-1 is the n-bit input unit vector; According to the definition of g-XOR, the construction of the binary linear matrix M can be split into several XOR sequence; the binary linear matrix M is regarded as a vector group with m n-bit vectors. Initially, the vector group contains n input unit vectors x0, x1, …, x n-1 , each XOR operation selects two vectors from the vector group to XOR the result variable, and adds the new variable to the vector group; the specific implementation method is: for each XOR operation, a flag is provided for each vector in the current vector group to mark whether the vector participates in the operation in this XOR operation. If the flag is 1, it means that the vector participates in the operation, and if the flag is 0, it does not participate in the operation; the new vector obtained by this XOR operation is equal to the new vector obtained by XORing the product of all current vectors and their flags, and is stored in the vector group; The constraint on the area of ​​binary linear matrix hardware circuit implementation is equivalent to the constraint on XOR operation. The process of counting XOR gates based on the g-XOR method is converted into a mathematical model of the cryptographic cost area part to characterize each XOR operation. The depth characterization module is specifically implemented as follows: The delay is measured by the depth of the hardware circuit implementation, that is, the number of clock cycles required for the circuit implementation; the hardware circuit implementation is converted into a graph, and the circuit depth is the number of nodes on the critical path; The binary linear matrix M is regarded as a vector group with m n-bit vectors, and a depth variable is added to each vector in the vector group to record the depth value of the vector. At the same time, the depth of each vector in the vector group is restricted to be no greater than the specified value, thus completing the characterization of the depth; the above characterization process of the depth is converted into a mathematical model of the cryptographic cost delay part; The cryptographic property characterization module characterizes the cryptographic properties required by the linear matrix to ensure that the constructed binary linear matrix is ​​reversible and has a certain number of branches; the specific implementation is as follows: By using the equivalence between the reversibility of a linear matrix and the linear independence of its row and column vectors, the linear independence of the row vectors of the matrix is ​​transformed into a mathematical model of the reversibility part of the cryptographic property. The number of branches of a linear matrix measures the ability of the linear matrix to resist attacks. It is directly related to the minimum number of active S-boxes in two consecutive rounds. The larger the number of branches, the higher the security. The number of branches is divided into the number of differential branches and the number of linear branches. The number of differential branches is required to be equal to the number of linear branches. The definitions of the two are given below: For a binary linear matrix M, the number of differential branches is defined as: The linear branching number is defined as: Among them, M T is the transposed matrix of M, w b (v) represents the number of non-zero elements in vector v, that is, the Hamming weight of the vector; A mathematical model for converting differential branching numbers and linear branching numbers into cryptographic branching numbers at the same time; The binary linear matrix solving module converts the obtained cryptographic cost and the mathematical model of cryptographic properties into the CVC language used by the STP solver and writes them into the CVC file in sequence, and uses the automated tool STP to solve the binary linear matrix that satisfies the corresponding cryptographic cost and properties; if there is a solution, the specific contents of all XOR operations and the constructed binary linear matrix values ​​are obtained from the solution results; If there is no solution, it means that there is no solution to construct a binary linear matrix with given cryptographic properties at a given cryptographic cost.

Citation Information

Cited By

  • STP solver-based minimum time delay S-box circuit searching method

    CN121683684A

  • A minimum time delay s-box circuit search method based on an STP solver

    CN121683684B