A quantum fault-tolerant implementation method of an S-box of zu chong zhi algorithm numbered 0
Patent Information
- Application Number
- CN202510269879.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2045-03-07
AI Technical Summary
相比之下,针对ZUC算法的S盒S0低T深度容错实现的构造,目前尚无可利用的高效方法
[0099]与现有技术相比,本发明的优点在于:本发明提供的一种祖冲之算法编号为0的S盒的量子容错实现方法,有效加快了祖冲之算法量子实现电路的实现效率,减少了相关量子电路实现的成本。
Smart Images

Figure CN120197722B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum optimization technology for the S-box S0 of the Zu Chongzhi algorithm subcomponent, and more specifically, to a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm. Background Technology
[0002] The development of quantum computers poses a serious threat to modern cryptography. For symmetric cryptography, quantum computers can reduce the complexity of brute-force attacks to the square root level using Grover's algorithm. This means that for a 128-bit key, a quantum computer would require approximately 2... 64 Two attempts, while a classic computer would require 2. 128 This is the first attempt.
[0003] Whether attacking specific cryptographic algorithms based on Shor's or Grover's algorithms, the quantum implementation circuit of these algorithms is a crucial component for launching quantum attacks. On one hand, in current quantum model machines, qubits are susceptible to decoherence due to environmental influences, diminishing the advantages of quantum computers over classical computers. Therefore, completing the quantum circuit's functionality before decoherence occurs places higher demands on its runtime. On the other hand, quantum circuits are essentially combinations of quantum logic gates. The Clifford+T gate set is a set of quantum fault-tolerant gates, widely used in quantum circuit design to meet the application requirements of quantum error correction. Circuit runtime is closely related to circuit depth, and in the Clifford+T gate set, the implementation cost of T gates is significantly higher than other gates in the set. Therefore, constructing quantum implementation circuits with lower T-depths for cryptographic algorithms based on the Clifford+T gate set to meet the application requirements of quantum error correction has attracted widespread attention.
[0004] The Zu Chongzhi algorithm is an important symmetric cryptography standard, a national standard in my country's cryptography industry, and an ISO / IEC international standard. It is widely used to protect the confidentiality and integrity of data. Researching quantum-optimized implementations of the Zu Chongzhi algorithm in the post-quantum era is of significant strategic importance. Confusion is one of the two fundamental principles of symmetric cryptography design, and S-boxes are commonly used as sub-components in symmetric cryptography to provide confusion. For the Zu Chongzhi algorithm, its S-boxes include S0 and S1, both of which are 8-bit S-boxes. However, there are currently no efficient methods or tools for designing optimized implementations of 8-bit S-boxes, whether for classical or quantum applications. Furthermore, the S-box S1 of the Zu Chongzhi algorithm is isomorphic to the S-box of the Advanced Encryption Standard (AES) algorithm, and its efficient implementation can refer to the implementation methods of the AES algorithm's S-box. In contrast, there are currently no efficient methods available for constructing a low-T-depth fault-tolerant implementation of the S-box S0 of the ZUC algorithm. Summary of the Invention
[0005] The purpose of this invention is to provide a quantum fault-tolerant implementation method for the S-box with the Zu Chongzhi algorithm number 0, so as to overcome the defects of the existing technology.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0007] A quantum fault-tolerant implementation method for the S-box numbered 0 in Zu Chongzhi's algorithm includes the following steps:
[0008] S1. Analyze the algebraic structure of the S-box S0 of Zu Chongzhi's algorithm and extract the information of the sub-components P1, P2 and P3 of the S-box S0 of Zu Chongzhi's algorithm.
[0009] S2, Design sub-component P1 for low-T depth implementation;
[0010] S3. Combining sub-components P2 and P3, design a low-T depth implementation of this combination;
[0011] The implementation of S4, combined with sub-components P1, P2 and P3, yields a low-T depth implementation of S0.
[0012] Furthermore, in step S1, the S-box S0 of Zu Chongzhi's algorithm is an 8-bit S-box, and it consists of three sub-components: P1, P2, and P3.
[0013] Furthermore, step S2 uses a quantum AND gate with a depth of T of 1 to construct a quantum realization circuit with a depth of low T, specifically including:
[0014] S21. Calculate the algebraic normal form information of sub-component P1;
[0015] S22. Based on the algebraic normal form information of subcomponent P1, design an implementation with optimal AND gate depth and number;
[0016] S23. Combine the quantum realization cost to convert the classical optimized implementation of sub-component P1 into its low-T-depth quantum optimized implementation.
[0017] Further, step S21 specifically includes:
[0018] Let the input of the S-box S0 in Zu Chongzhi's algorithm be X = (x0, x1, ..., x7), the input of the sub-component P1 be A = X2 = (x4, x5, x6, x7), and the output of P1 be B = (b0, b1, b2, b3). Then:
[0019] The expression for b0 is:
[0020] The expression for b1 is:
[0021] The expression for b2 is:
[0022] The expression for b3 is:
[0023] Further, step S22 specifically includes:
[0024] S221. Let N be the number of AND gates required to finally implement P1, n mark the number of AND gates required in the current implementation, and i be used to mark the output bit index of P1, i∈{0,1,2,3}. Initialize N=8, n=0, i=0;
[0025] S222, if b i The expression has been processed, i = i + 1 and proceed to step S223; if b i The expression was not processed, and the process proceeded directly to step S223;
[0026] S223, Statistics b i The expression contains monomials of degree 2, and the number of occurrences of each variable is used to determine the frequency of occurrence of b. i Common factorization is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. If the extracted variable itself is b... i The monomial in , i.e. b i If the expression contains an XOR operation with the variable b, use that variable as a common factor to perform the XOR operation, and repeat this step until b is reached. i There are no common factors that can be extracted from the remaining quadratic monomials. After statistical update, b i The number of AND gates in the expression is added to n, i = i + 1, and then proceed to step S224;
[0027] S224. If i = 4, then the expressions of b0, b1, b2 and b3 have been processed, and proceed to step S225; otherwise, if i ≤ 3, then the expressions of b0, b1, b2 and b3 have not been processed, and proceed to step S222.
[0028] S225. If N>n, then find an implementation scheme with less AND gate consumption, update N=n and go to step S226; otherwise, if no implementation scheme with less AND gate consumption is found, go directly to step S226.
[0029] S226. Let n = 0, i = 0, and go to step S222. After repeated steps, if a solution with less AND gate consumption is still not found, we get a solution with an AND gate depth of 1 and a better AND gate consumption.
[0030] Furthermore, step S23 specifically includes:
[0031] S231. Simulate the XOR and NOT operations in the modified expressions of b0, b1, b2, and b3 using CNOT gates and Pauli-X gates, as follows:
[0032]
[0033] S232. Regarding the AND operation in the modified expressions b0, b1, b2, and b3, i.e. The design employs a parallel implementation scheme using four QAND gates.
[0034] S233. Simulate the four AND operations in the modified expression of P1 by calling four QAND gates in parallel with a depth of T of 1:
[0035] QAND(t2,x4,t4,t8), QAND(t1,x7,t5,t9),
[0036] QAND(t3,x5,t6,t 10 QAND(t0,x6,t7,t) 11 ),
[0037] Among them, t8, t9, t 10 ,t 11 A value of 0 indicates a quantum auxiliary bit in the QAND gate, and its value remains unchanged before and after the QAND gate is invoked.
[0038] S234. Calculate the output of P1:
[0039]
[0040] Furthermore, step S3 specifically includes:
[0041] S31. Calculate the algebraic normal forms of sub-components P2 and P3.
[0042] S32. Calculate the algebraic normal form of subcomponent P2 combined with P3.
[0043] S33. Based on the algebraic normal forms of subcomponents P2 and P3, design the implementation of AND gate depth and number of AND gates in stages to achieve the best results.
[0044] Further, step S31 specifically includes:
[0045] Let the input of P2 be C = (c0, c1, c2, c3) and the output be D = (d0, d1, d2, d3), then:
[0046] The expression for d0 is:
[0047]
[0048] The expression for d1 is:
[0049]
[0050] The expression for d2 is:
[0051]
[0052] The expression for d3 is:
[0053]
[0054] Let the input of P3 be E = (e0, e1, e2, e3) and the output be F = (f0, f1, f2, f3), then:
[0055] The expression for f0 is as follows:
[0056]
[0057] The expression for f1 is as follows:
[0058]
[0059] The expression for f2 is as follows:
[0060]
[0061] The expression for f3 is as follows:
[0062]
[0063] Step S32 specifically includes:
[0064] Let P be the association between P2 and P3. Assume the input of S-box S0 is X = (x0, x1, ..., x7), and the output of P1 is (p0, p1, p2, p3). Then the input of P is... Let P be abbreviated as (q0, q1, ..., q7), and let the output of P be (y0, y1, ..., y7). Based on the expressions of P2 and P3, we can obtain the expressions of the 8 output variables of P.
[0065] The expression for y0 is:
[0066]
[0067] The expression for y1 is:
[0068]
[0069] The expression for y2 is:
[0070]
[0071]
[0072] The expression for y3 is:
[0073]
[0074] The expression for y4 is:
[0075]
[0076] The expression for y5 is:
[0077]
[0078] The expression for y6 is:
[0079]
[0080] The expression for y7 is:
[0081]
[0082] Furthermore, step S33 specifically includes:
[0083] The first stage of processing the algebraic normal form of the output variable of P includes:
[0084] Step 1: Let N1 be the number of AND gates required to implement P in the first stage, and n mark the number of AND gates required in the current implementation. Initialize N1 = 28, n = 28, and proceed to Step 2.
[0085] Step 2: Randomly select n operations from the 28 available in the first stage and substitute them into the 8 output expressions of P, then proceed to Step 3;
[0086] Step 3: If the algebraic count of the modified 8 expressions does not exceed 2 at the current value of n, proceed to Step 4; otherwise, if the algebraic count of the modified 8 expressions exceeds 2 at the current value of n, proceed to Step 2; if the algebraic count of the modified 8 expressions exceeds 2 for a long time at the current value of n, it means that the n AND operations are unlikely to reduce the algebraic count of P's expression to 2, proceed to Step 5.
[0087] Step 4: If N1 > n, it means that an implementation scheme for the AND gate has been found. Update the number of AND gates in the first stage N1 = n, set n = n-1, and go to step 2; otherwise, the number of AND gates has not been optimized at this time, and go to step 2.
[0088] Step 5: At this point, N1 is the number of AND gates that can reduce the algebraic degree of the output expression of P to 2. Save the N1 AND operations selected in step 2, and update the 8 output expressions of P to quadratic expressions accordingly.
[0089] The second stage of processing the algebraic normal form of the output variable of P includes:
[0090] Step 1: Let N2 be the number of AND gates required to implement P in the second stage, n be the number of AND gates required in the current implementation, and i be the output bit index of P, i.e., i∈{0,1,…,7}. Initialize N2=100, n=0, i=0, and proceed to step 2;
[0091] Step 2: If y i The expression has been processed, i = i + 1 and proceed to step 3; if y i The expression was not processed, and the process proceeded directly to step three.
[0092] Step 3: Statistical analysis of y i The number of occurrences of each variable in the monomial of degree 2 in the expression, and using the variable with the highest frequency to analyze y. i Common factorization is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. If the extracted variable itself is y... i The monomial in , i.e. y i If the expression contains an XOR operation with that variable, then use that variable as a common factor to perform the XOR operation. Repeat this step until y... i There are no common factors that can be extracted from the remaining quadratic monomials. After statistical update, y i The number of AND gates in the expression is added to n, i = i + 1, then proceed to step four;
[0093] Step 4: If i = 8, then the expressions for y0, y1, ..., y7 have been processed, proceed to step 5; otherwise, if i ≤ 7, then the expressions for y0, y1, ..., y7 have not been processed, proceed to step 2.
[0094] Step 5: If N2 > n, it proves that a less resource-intensive implementation of the AND gate has been found. Update N2 = n and proceed to step 6. Otherwise, no less resource-intensive implementation of the AND gate has been found. Proceed directly to step 6.
[0095] Step 6: Let n = 0, i = 0, and go back to step 2. Repeat this process multiple times until a solution with fewer AND gates is found. This will give you a solution with a better number of AND gates in the second stage.
[0096] Further, step S4 specifically includes:
[0097] S41. Convert the low AND gate depth implementation of sub-components P2 and P3 into their low T depth quantum-optimized implementation, including using QAND gates to simulate the AND gate in the classical implementation, using CNOT gates to simulate the XOR operation in the classical implementation, and using Pauli-X gates to simulate the NOT operation in the classical implementation.
[0098] S42. Complete the substitution between variables. Assume that the input of P is (q0,q1,…,q7) and the output is (y0,y1,…,y7). Let the input variable of box S0 be X = (x0,x1,…,x7) and the output be S = (s0,s1,…,s7). Based on the output of sub-component P1, q4 = x4, q5 = x5, q6 = x6, q7 = x7, and there is only a circular shift operation between (y0, y1, ..., y7) and (s0, s1, ..., s7). (s0, s1, ..., s7) is obtained by circularly shifting (y0, y1, ..., y7) 5 bits to the left, that is, (s0, s1, ..., s7) = (y5, y6, y7, y0, y1, y2, y3, y4).
[0099] Compared with the prior art, the advantages of the present invention are as follows: The present invention provides a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm, which effectively accelerates the implementation efficiency of the quantum implementation circuit of the Zu Chongzhi algorithm and reduces the cost of implementing the related quantum circuit. Attached Figure Description
[0100] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0101] Figure 1 Here is a flowchart of Zu Chongzhi's algorithm;
[0102] Figure 2 The structure diagram of the S-box S0 of Zu Chongzhi's algorithm;
[0103] Figure 3 For quantum QAND gates;
[0104] Figure 4 For quantum Door;
[0105] Figure 5 This is a diagram illustrating the low-T depth fault-tolerant implementation framework of Zu Chongzhi's algorithm S-box S0 in this invention. Detailed Implementation
[0106] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.
[0107] See Figure 1 The diagram shown is a flowchart of Zu Chongzhi's algorithm. The quantum implementation circuit involved in this invention addresses the nonlinear transformation S-box of Zu Chongzhi's algorithm. Figure 1 (S layer in the S box), specifically involving the S0 part in the S box.
[0108] The method for obtaining the quantum-optimized implementation circuit of the present invention is as follows: Analyze the algebraic structure of the S-box S0 of the Zu Chongzhi algorithm, and extract information from the sub-components P1, P2, and P3 of S0; design a low-T-depth implementation of sub-component P1. To this end, calculate the algebraic normal form information of P1, design an implementation with optimal AND gate depth and number based on the algebraic normal form of P1, and convert the classical optimized implementation of P1 into a low-T-depth quantum-optimized implementation by considering the quantum implementation cost; combine P2 and P3 to design a low-T-depth implementation of this combination. To this end, calculate the algebraic normal forms of P2 and P3, calculate the algebraic normal form of P2 combined with P3, and design an implementation with optimal AND gate depth and number in stages based on the algebraic normal forms of P2 and P3; combine the implementations of P1, P2, and P3 to obtain the low-T-depth implementation of S0. This embodiment discloses a quantum fault-tolerant implementation method for the S-box numbered 0 of the Zu Chongzhi algorithm, including the following steps:
[0109] Step S1: Analyze the algebraic structure of the S-box S0 of Zu Chongzhi's algorithm and extract the information of the sub-components P1, P2 and P3 of the S-box S0 of Zu Chongzhi's algorithm.
[0110] The S-box S0 in Zu Chongzhi's algorithm is an 8-bit S-box, composed of three sub-components: P1, P2, and P3. The specific structure is as follows: Figure 2 As shown, where m = 5, and <<< m This indicates a cyclic left shift of m bits.
[0111] P1, P2, and P3 are all nonlinear transformations with 4-bit input and 4-bit output. Let x be the input, and the truth tables of P1, P2, and P3 are shown in Table 1.
[0112] Table 1 Truth Tables for P1, P2, and P3
[0113] <![CDATA[P1(x)]]> 9 f 0 e f f 2 a 0 4 0 c 7 5 3 9 <![CDATA[P2(x)]]> 8 d 6 5 7 0 c 4 b 1 e a f 3 9 2 <![CDATA[P3(x)]]> 2 6 a 6 0 d a f 3 3 d 5 0 9 c d
[0114] Step S2: Design the low-T depth implementation of sub-component P1.
[0115] The most common method for constructing quantum logic circuits with a depth of T is to use quantum AND gates with a depth of 1, i.e., QAND gates. A QAND gate is a 4-input logic gate, requiring two of its input bits to be in the state |0>. The circuit diagram of a QAND gate is shown below. Figure 3 As shown, its function can be described as follows:
[0116]
[0117] Where a,b∈{0,1}.
[0118] To conserve qubits, the conjugate of the QAND gate (i.e., ...) is often used. The qubits in the output of the QAND gate that are in the state of |a·b> are reset to |0>. The circuit diagram of the gate is as follows Figure 4 As shown, its function can be described as follows:
[0119]
[0120] Where a,b∈{0,1}.
[0121] Note that QAND gate and The basic logic components involved in gates include H-gates, S-gates, T-gates (and their conjugates). Quantum fault-tolerant gates (QAND gates, CNOT gates, etc.) are all examples of quantum fault-tolerant gates. Therefore, QAND gates and... Gates are also applicable to quantum error correction. In addition, the commonly used quantum Pauli-X gate is also a quantum fault-tolerant gate.
[0122] Step S21: Calculate the algebraic normal form information of sub-component P1.
[0123] When simulating a classical AND gate using QAND gates, two additional quantum auxiliary bits are required: one to store the output of the classical AND gate and the other as an auxiliary bit. Therefore, the number of qubits required to construct a quantum implementation by simulating the AND gate in a classical circuit using QAND gates is closely related to the number of AND gates required to implement the classical circuit. To design a low-T depth implementation of P1 and conserve qubits, we first study the algebraic normal form (i.e., expression) of P1 and focus on the number of AND gates involved.
[0124] Suppose the input of the S-box S0 in Zu Chongzhi's algorithm is denoted as X = (x0, x1, ..., x7), combined with... Figure 2 We know that the input to P1 is A = X2 = (x4, x5, x6, x7). Let the output of P1 be B = (b0, b1, b2, b3), then b0 can be calculated by the following expression:
[0125]
[0126] As can be seen from the above formula, the calculation of b0 consumes 2 AND gates, several XOR gates, and NOT gates, among which the AND gates calculate x4·x6 and x6·x7.
[0127] b1 can be calculated using the following expression:
[0128]
[0129] As can be seen from the above formula, the calculation of b1 consumes 2 AND gates and several XOR gates, where the AND gates calculate x5·x6 and x5·x7.
[0130] b2 can be calculated using the following expression:
[0131]
[0132] As can be seen from the above formula, the calculation of b2 consumes 2 AND gates and several XOR gates, where the AND gates calculate x4·x7 and x5·x7.
[0133] b3 can be calculated using the following expression:
[0134]
[0135] As can be seen from the above formula, the calculation of b3 consumes 2 AND gates, several XOR gates, and NOT gates, among which the AND gates calculate x4·x5 and x4·x6.
[0136] The AND gate can be simulated by the QAND gate, as described above. The XOR gate can be simulated by the quantum CNOT gate, and the NOT gate can be simulated by the quantum Pauli-X gate. Let a, b ∈ {0, 1}, the function of the CNOT gate is to transform the state (|a>, |b>) into... In other words, the state of one qubit is XORed into another qubit. The function of the Pauli-X gate is to transform the state (|a>) into... This involves inverting the state of a qubit. Specifically, the process of simulating an XOR gate using a quantum CNOT gate and an NOT gate using a quantum Pauli-X gate is as follows:
[0137] XOR operation The result can be obtained by directly using the qubits corresponding to a and b as inputs to the CNOT gate. or in or It corresponds to the output of a classic XOR gate.
[0138] For NOT gate The result can be obtained by directly using the qubit corresponding to 'a' as the input to the Pauli-X gate. This corresponds to the output of a classic NOT gate.
[0139] For simplicity, operations of the form QAND(a,b,c,d) are used to represent the computation of a·b using QAND gates, and operations of the form QAND_C(a,b,c) are used to represent the computation of a·b using QAND gates. The goalkeeper's value 'c' is reset to 0, using a form like The operation is represented by CNOT gates for computation. The value is stored in the qubit corresponding to a, using the form a The operation represents using the Pauli-X gate to invert the state of the qubit corresponding to a.
[0140] S22. Based on the algebraic normal form information of subcomponent P1, design an implementation with optimal AND gate depth and number.
[0141] From the output expression of P1, we know that the algebraic degree of b0, b1, b2, and b3 is all 2, so P1 can be implemented within one AND gate depth. Intuitively, the output of P1 can be calculated using 8 AND gates, several XOR gates, and NOT gates, where the 8 AND gates calculate x4·x6, x6·x7, x5·x6, x5·x7, x4·x7, x5·x7, x4·x5, and x4·x6, respectively.
[0142] Further processing of the expressions for b0, b1, b2, and b3 may reduce the number of AND gates required to compute the output of P1, thus saving qubits. The specific steps are as follows:
[0143] Step 1: Let N be the number of AND gates required to finally implement P1, n mark the number of AND gates required in the current implementation, and i be used to mark the output bit index of P1, i.e., i∈{0,1,2,3}. Initialize N=8, n=0, i=0, and proceed to Step 2.
[0144] Step 2, if b i The expression has been processed, i = i + 1 and proceed to step 3; if b i The expression was not processed, and the process proceeded directly to step 3.
[0145] Step 3, Statistics b i The expression contains monomials of degree 2, and the number of occurrences of each variable is used to determine the frequency of occurrence of b. i Common factorization is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. Furthermore, if the extracted variable itself is b... i The monomial in , i.e. b i If the expression contains an XOR operation with this variable, then this variable is used as a common factor to perform the XOR operation. Repeat this step until b... i There are no common factors that can be extracted from the remaining quadratic monomials. After statistical update, b...i The number of AND gates in the expression is added to n. i = i + 1, then proceed to step 4.
[0146] Step 4: If i = 4, it means that the expressions for b0, b1, b2 and b3 have been processed, and proceed to step 5; otherwise, if i ≤ 3, it means that the expressions for b0, b1, b2 and b3 have not been processed, and proceed to step 2.
[0147] Step 5: If N>n, it proves that an implementation scheme with less AND gate consumption has been found. Update N=n and go to step 6. Otherwise, no implementation scheme with less AND gate consumption has been found. Go directly to step 6.
[0148] Step 6: Let n = 0, i = 0, and return to step 2. Repeat this process multiple times until a solution with lower AND gate consumption is found. A solution with an AND gate depth of 1 and relatively low AND gate consumption for P1 is obtained.
[0149] The process of step 3 is illustrated below using b0 as an example:
[0150] The expression for b0 is as follows:
[0151]
[0152] The monomials involved, with an algebraic degree of 2, are x4·x6 and x6·x7, and the variables involved are x4, x6, and x7, which appear 1, 2, and 1 time respectively. Therefore, x6, which appears most frequently, is selected as the common factor, and the expression for b0 is modified as follows:
[0153]
[0154] Note that the expression for b0 contains a direct XOR operation with x6, meaning x6 itself is already a monomial in the expression for b0. Therefore, when x6 is used as a common factor, the XOR operation is treated similarly to extract common factors as follows:
[0155]
[0156] At this point, the remaining unprocessed monomials in the expression for b0 are 1 and x4, with no quadratic terms and no common factors to extract. Based on the modified expression, implementing b0 consumes one AND gate, i.e.
[0157] After the above steps, the final implementation with 4 gates in P1 is as follows:
[0158]
[0159] S23. Combine the quantum realization cost to convert the classical optimized implementation of sub-component P1 into its low-T-depth quantum optimized implementation.
[0160] To convert the P1 implementation with 4 AND gates into a quantum implementation, QAND, CNOT, and Pauli-X gates are used to simulate the AND, XOR, and NOT gates in the classical implementation, respectively. Simultaneously, some auxiliary bits are reset to save on the number of qubits. The specific steps are as follows:
[0161] Step 1: Use CNOT gates and Pauli-X gates to simulate the XOR and NOT operations in the modified expressions b0, b1, b2, and b3, i.e.
[0162]
[0163] Step 2: Perform the AND operation on the modified expressions b0, b1, b2, and b3, i.e. The design employs a parallel implementation using four QAND gates. Note that x4, x5, x6, and x7 appear multiple times in the four AND operations. A qubit cannot be simultaneously input into two logic gates; on the other hand, using existing qubits to avoid introducing new ones helps conserve the qubits required for the circuit. A 2-input AND gate has two inputs (operands). The four AND gates have a total of eight inputs, or eight operands. x4, x5, x6, and x7 can themselves serve as operands for the AND gates. In addition, four auxiliary qubits (denoted as t0, t1, t2, and t3) are needed to store the other four operands for the four AND operations.
[0164]
[0165]
[0166] Step 3: Simulate the four AND operations in the modified expression of P1 by calling four QAND gates in parallel under the condition that the depth of T is 1:
[0167] QAND(t2,x4,t4,t8), QAND(t1,x7,t5,t9),
[0168] QAND(t3,x5,t6,t 10 QAND(t0,x6,t7,t) 11 ),
[0169] Where t8, t9, t 10 ,t 11 A value of 0 indicates a quantum auxiliary bit in a QAND gate, and its value remains unchanged before and after the QAND gate is invoked.
[0170] Step 4: Calculate the output of P1:
[0171]
[0172] Step S3: Combining sub-components P2 and P3, design a low-T depth implementation of this combination. Specifically, this includes:
[0173] Step S31: Calculate the algebraic normal form of sub-components P2 and P3.
[0174] After the above steps, the output of P1 in S-box S0 is now known. Combined with... Figure 2 Let the input of P2 be C = (c0, c1, c2, c3) and the output be D = (d0, d1, d2, d3), then:
[0175] The expression for d0 is:
[0176]
[0177] The expression for d1 is:
[0178]
[0179] The expression for d2 is:
[0180]
[0181] The expression for d3 is:
[0182]
[0183] Let the input of P3 be E = (e0, e1, e2, e3) and the output be F = (f0, f1, f2, f3), then:
[0184] The expression for f0 is as follows:
[0185]
[0186] The expression for f1 is as follows:
[0187]
[0188] The expression for f2 is as follows:
[0189]
[0190] The expression for f3 is as follows:
[0191]
[0192] Step S32: Calculate the algebraic normal form of sub-component P2 combined with P3.
[0193] Let P be the combination of P2 and P3. Figure 2 We know that, assuming the input of S-box S0 is X = (x0, x1, ..., x7) and the output of P1 is (p0, p1, p2, p3), then the input of P is... Let P be abbreviated as (q0, q1, ..., q7), and let the output of P be (y0, y1, ..., y7). Based on the expressions of P2 and P3, we can obtain the expressions of the 8 output variables of P.
[0194] The expression for y0 is:
[0195]
[0196] The expression for y1 is:
[0197]
[0198]
[0199] The expression for y2 is:
[0200]
[0201] The expression for y3 is:
[0202]
[0203] The expression for y4 is:
[0204]
[0205] The expression for y5 is:
[0206]
[0207] The expression for y6 is:
[0208]
[0209] The expression for y7 is:
[0210]
[0211] Step S33: Based on the algebraic normal forms of sub-components P2 and P3, design the optimal implementation of their AND gate depth and number in stages.
[0212] Based on the expressions for y0, y1, ..., y7, we know that the algebraic degree of the expressions for the eight output variables of P does not exceed 4. Therefore, it can be implemented within two AND gate depths. Taking the monomial q1·q2·q3·q6 in y0 as an example, the first layer of AND gate depth implements: t0 = q1·q2, t1 = q3·q6; the second layer of AND gate depth calculates t0·t1 to obtain q1·q2·q3·q6. Expressions with an algebraic degree of 4 can all be implemented within two AND gate depths in the same way.
[0213] Therefore, the implementation of the combination of P2 and P3 (i.e. P) is divided into two stages: the first stage reduces the algebraic degree of the output variable to 2; the second stage designs an implementation with less overhead for the expression AND gate, which has an algebraic degree of 2.
[0214] Step S331, the first stage of processing the algebraic normal form of the output variable of P, includes:
[0215] The first phase reduces the algebraic degree of the expression for the output variable of P to 2. The output of the AND operation in the first phase is of the form q. i ·q j Where i,j = 0,1,…,7, and i≠j. Therefore, the first stage can utilize a maximum of 28 possible AND operation outputs, i.e.
[0216] q0·q1,q0·q2,…,q0·q7,
[0217] q1·q2,q1·q3,…,q1·q7,
[0218] q2·q3,q2·q4,…,q2·q7,
[0219] q3·q4,q3·q5,…,q3·q7,
[0220] q4·q5,q4·q6,q4·q7,
[0221] q5·q6, q5·q7,
[0222] q6·q7.
[0223] Step 1: Let N1 be the number of AND gates required to implement P in the first stage, and n mark the number of AND gates required in the current implementation. Initialize N1 = 28, n = 28, and proceed to Step 2.
[0224] Step 2: Randomly select n operations from the 28 available in the first stage and substitute them into the 8 output expressions of P, then proceed to Step 3;
[0225] Step 3: If the algebraic count of the modified 8 expressions does not exceed 2 at the current value of n, proceed to Step 4; otherwise, if the algebraic count of the modified 8 expressions exceeds 2 at the current value of n, proceed to Step 2; if the algebraic count of the modified 8 expressions exceeds 2 for a long time at the current value of n, it means that the n AND operations are unlikely to reduce the algebraic count of P's expression to 2, proceed to Step 5.
[0226] Step 4: If N1 > n, it means that an implementation scheme for the AND gate has been found. Update the number of AND gates in the first stage N1 = n, set n = n-1, and go to step 2; otherwise, the number of AND gates has not been optimized at this time, and go to step 2.
[0227] Step 5: At this point, N1 is the number of AND gates that can reduce the algebraic degree of the output expression of P to 2. Save the N1 AND operations selected in step 2, and update the 8 output expressions of P to quadratic expressions accordingly.
[0228] Step S332: The second stage of processing the algebraic normal form of the output variable of P.
[0229] At the beginning of the second stage, after the first stage, the algebraic degree of the expression for the output variable of P is at most 2. Note that the algebraic degree of the expression for the output variable of P1 is also 2. Therefore, the process of processing the expression for P in the second stage is the same as the process of processing the expression for P1, only the number of output bits differs: P has 8 outputs, while P1 has 4 output bits. The specific steps for processing the expression for P are as follows:
[0230] Step 1: Let N2 be the number of AND gates required to implement P in the second stage, n be the number of AND gates required in the current implementation, and i be the output bit index of P, i.e., i∈{0,1,…,7}. Initialize N2=100, n=0, i=0, and proceed to step 2;
[0231] Step 2: If y i The expression has been processed, i = i + 1 and proceed to step 3; if y i The expression was not processed, and the process proceeded directly to step three.
[0232] Step 3: Statistical analysis of y i The number of occurrences of each variable in the monomial of degree 2 in the expression, and using the variable with the highest frequency to analyze y. i Common factorization is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. If the extracted variable itself is y... i The monomial in , i.e. y i If the expression contains an XOR operation with that variable, then use that variable as a common factor to perform the XOR operation. Repeat this step until y... iThere are no common factors that can be extracted from the remaining quadratic monomials. After statistical update, y i The number of AND gates in the expression is added to n, i = i + 1, then proceed to step four;
[0233] Step 4: If i = 8, then the expressions for y0, y1, ..., y7 have been processed, proceed to step 5; otherwise, if i ≤ 7, then the expressions for y0, y1, ..., y7 have not been processed, proceed to step 2.
[0234] Step 5: If N2 > n, it proves that a solution with less AND gate overhead has been found. Update N2 = n and proceed to step 6. Otherwise, no solution with less AND gate overhead has been found. Proceed directly to step 6.
[0235] Step 6: Let n = 0, i = 0, and go back to step 2. Repeat this process multiple times until a solution with fewer AND gates is found. This will give you a solution with a better number of AND gates in the second stage.
[0236] Step S4: Combine the implementations of sub-components P1, P2, and P3 to obtain the low-T depth implementation of S0.
[0237] Step S41: Convert the low AND gate depth implementation of sub-components P2 and P3 into their low T depth quantum-optimized implementation. This process is similar to the process of converting the low AND gate depth implementation of P1 into its low T depth quantum-optimized implementation, that is: use QAND gates to simulate the AND gate in the classical implementation, use CNOT gates to simulate the XOR operation in the classical implementation, and use Pauli-X gates to simulate the NOT operation in the classical implementation.
[0238] Step S42: Complete the substitution between variables. For example, when processing the combination of P2 and P3 (i.e., P), for simplicity, this invention assumes that the input of P is (q0, q1, ..., q7) and the output is (y0, y1, ..., y7). Figure 2 It can be seen that neither (q0,q1,…,q7) nor (y0,y1,…,y7) are the inputs or outputs of the S-box S0. Let the input variables of the S-box S0 be X = (x0,x1,…,x7), and the output be S = (s0,s1,…,s7). Combining... Figure 2 And the output of P1, it is easy to see, q4 = x4, q5 = x5, q6 = x6, q7 = x7, and there is only a circular shift operation between (y0, y1, ..., y7) and (s0, s1, ..., s7). That is, (s0, s1, ..., s7) can be obtained by circularly shifting (y0, y1, ..., y7) 5 bits to the left, i.e., (s0, s1, ..., s7) = (y5, y6, y7, y0, y1, y2, y3, y4).
[0239] This embodiment utilizes the above steps to implement the fault-tolerant circuit for the Zu Chongzhi algorithm's S-box S0 within a depth of 3T. Since the Zu Chongzhi algorithm's S-box S0 is an 8-bit S-box, the maximum algebraic order of its output bits is 7. Therefore, the minimum gate depth for calculating the output bits of S0 using a 2-input classical AND gate is... That is, 3. This embodiment constructs a classical implementation with an AND gate depth of 3, and then uses this classical implementation and QAND gates to simulate the AND gates to construct a fault-tolerant circuit for S0. Therefore, the classical implementation constructed in this invention achieves the theoretically optimal AND gate depth, which also optimizes the depth T of the quantum implementation constructed in this invention.
[0240] Currently, the quantum implementation T-depth of the sub-component S-box S0 in the Zu Chongzhi algorithm is 7, while the quantum implementation scheme for S0 designed in this invention has a T-depth of only 3. Therefore, from the perspective of circuit depth, the quantum implementation circuit designed in this invention saves the implementation cost of the sub-component S-box S0 in the nonlinear layer of the Zu Chongzhi algorithm. Furthermore, using the implementation scheme designed in this invention, the quantum implementation cost of the Zu Chongzhi algorithm can be effectively reduced.
[0241] Although embodiments of the present invention have been described in conjunction with the accompanying drawings, the patent owner may make various modifications or alterations within the scope of the appended claims, as long as they do not exceed the protection scope described in the claims of the present invention, they shall be within the protection scope of the present invention.
Claims
1. A quantum fault-tolerant implementation method for the S-box numbered 0 in Zu Chongzhi's algorithm, characterized in that, Includes the following steps: S1. Analyzing Zu Chongzhi's algorithm using the S-box. Algebraic structure, extracting the S-box from Zu Chongzhi's algorithm sub-components , and Information; S2, Design Sub-components Low T-depth implementation; S3, Connecting Sub-component Harmony components Design a low-T depth implementation for this combination; S4, Combined Sub-component , and The realization of, to obtain Low T-depth implementation; The S-box of Zu Chongzhi's algorithm in step S1 It is an 8-bit S-box, and is composed of , and It consists of three sub-components; Step S2 uses a quantum AND gate with a depth of 1 (T) to construct a low-T-depth quantum realization circuit, specifically including: S21. Calculate the sub-component Information related to algebraic normal forms; S22, According to sub-components Design an implementation with optimal AND gate depth and number of AND gates for information related to algebraic normal types; S23, Combining the cost of quantum realization will The classical optimization implementation is converted into its low-T-depth quantum optimization implementation; Step S3 specifically includes: S31, Calculate the sub-component and algebraic normal form S32, Calculate the sub-component Combination algebraic normal form S33, According to sub-components and The algebraic normal form is designed in stages to achieve a better implementation of AND gate depth and number; Step S33 specifically includes: deal with The first stage of the algebraic normal form of the output variable includes: Step 1, record For the first phase of implementation The required number of AND gates Mark the number of AND gates required in the current implementation, and initialize. Proceed to step two; Step 2: Randomly select from the 28 options available in the first stage. Substitute into From the eight output expressions, proceed to step three; Step 3, if the current If the algebraic exponent of all eight modified expressions does not exceed 2, proceed to step four; otherwise, if the current... If the algebraic exponents of all eight modified expressions exceed 2, proceed to step two. When the value is modified, the algebraic exponent of the 8 expressions exceeds 2 for an extended period, indicating that... The AND operation is highly unlikely to make... The algebraic degree of the expression decreases to 2, proceed to step five; Step 4, if This indicates that an implementation scheme for the AND gate has been found, and the number of AND gates in the first stage has been updated. ,set up Proceed to step two; otherwise, the number of AND gates has not been optimized at this point, so proceed to step two. Step 5, at this time It can make The algebraic degree of the output expression is reduced to the number of AND gates of 2, and the selection in step 2 is saved. The terms and operations are defined, and updates are made accordingly. The eight output expressions are quadratic expressions; deal with The second stage of the algebraic normal form of the output variable includes: Step 1: Remember For the second phase to be realized The required number of AND gates Mark the number of AND gates required in the current implementation. For marking The output bit index, i.e. ;initialization Proceed to the second step; Step 2: If The expression has been processed. Then proceed to step 3; if The expression was not processed, and the process proceeded directly to step three. Step 3: Statistics The number of occurrences of each variable in a monomial of degree 2 in the expression, using the variable with the highest frequency to... Common factor extraction is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. If the extracted variable itself is... The monomial in , i.e. If the expression contains an XOR operation with that variable, then use that variable as a common factor to perform the XOR operation as well, repeating this step until... There are no common factors that can be extracted from the remaining quadratic monomials. After statistical update... The number of AND gates in the expression and added to middle, Proceed to step four; Step 4, if ,but The expression has been processed; proceed to step five. Otherwise, ,but The expression has not been fully processed, proceed to the second step; Step 5, if This proves that a less resource-intensive implementation of AND gates has been found, and the update... Then proceed to step six; otherwise, if no less resource-efficient implementation of the AND gate is found, proceed directly to step six. Step 6, Order The process proceeds to the second step, and after repeated attempts, if a solution with lower AND gate overhead is still not found, the second stage is reached. An implementation scheme with lower AND gate consumption.
2. The quantum fault-tolerant implementation method of the S-box numbered 0 in Zu Chongzhi's algorithm according to claim 1, characterized in that, Step S21 specifically includes: Let Zu Chongzhi's algorithm use S-boxes. The input is denoted as Sub-components The input is ,remember The output is ,but: The expression is: The expression is: The expression is: The expression is : .
3. The quantum fault-tolerant implementation method of the S-box numbered 0 in Zu Chongzhi's algorithm according to claim 1, characterized in that, Step S22 specifically includes: S221, Note To ultimately achieve The required number of AND gates Mark the number of AND gates required in the current implementation. For marking The output bit index, ,initialization ; S222, if The expression has been processed. And proceed to step S223; if The expression was not processed, and the process proceeded directly to step S223; S223, Statistics The number of occurrences of each variable in a monomial of degree 2 in the expression, using the variable with the highest frequency to... Common factor extraction is performed on the expression. If multiple variables have the highest frequency, one is randomly selected. If the extracted variable itself is... The monomial in , i.e. If the expression contains an XOR operation with the variable, use that variable as a common factor to perform the XOR operation, and repeat this step until... The remaining quadratic monomials have no extractable common factors, and after statistical update... The number of AND gates in the expression and added to middle, Proceed to step S224; S224, if ,but , , and The expression has been processed; proceed to step S225; otherwise, ,but , , and The expression has not been fully processed, proceed to step S222; S225, if Then, find an implementation scheme with lower AND gate overhead and update... Then proceed to step S226; otherwise, if no implementation scheme with less AND gate consumption is found, proceed directly to step S226. S226, Order Proceed to step S222, and repeat this process multiple times until a solution with lower AND gate overhead is still not found, resulting in... An implementation scheme with an AND gate depth of 1 and a relatively low AND gate consumption.
4. The quantum fault-tolerant implementation method of the S-box numbered 0 in Zu Chongzhi's algorithm according to claim 1, characterized in that, Step S23 specifically includes: S231, After simulation using CNOT gates and Pauli-X gates, the modification was completed. , , and The XOR and NOT operations in the expression are as follows: , , , , S232, Regarding the revised , , and The AND operation in the expression, i.e. , , , A parallel implementation scheme using 4 QAND gates is designed; S233, Parallel calls to four QAND gates, simulating modifications under a depth of T of 1. The four AND operations in the expression: , , , , in, A value of 0 indicates a quantum auxiliary bit in the QAND gate, and its value remains unchanged before and after the QAND gate is invoked. S234, calculated Output: , , , 。 5. The quantum fault-tolerant implementation method of the S-box numbered 0 in Zu Chongzhi's algorithm according to claim 1, characterized in that, Step S31 specifically includes: set up The input is The output is ,but: The expression is: ; The expression is: ; The expression is: ; The expression is: set up The input is The output is ,but: The expression is as follows: The expression is as follows: The expression is as follows: The expression is as follows: Step S32 specifically includes: remember and The combination of Assuming S-box The input is , The output is ,but The input is abbreviated as ,remember The output is ,according to and The expression is obtained The expressions for the 8 output variables; The expression is: ; The expression is: ; The expression is: ; The expression is: ; The expression is: ; The expression is: ; The expression is: ; The expression is: 。 6. The quantum fault-tolerant implementation method of the S-box numbered 0 in Zu Chongzhi's algorithm according to claim 1, characterized in that, Step S4 specifically includes: S41, will and The low-DAND gate depth implementation is converted into its low-T-depth quantum-optimized implementation, including using QAND gates to simulate the AND gate in the classical implementation, using CNOT gates to simulate the XOR operation in the classical implementation, and using Pauli-X gates to simulate the NOT operation in the classical implementation. S42. Complete the substitution between variables, assuming... The input is The output is , record S box The input variables are The output is According to sub-components The output, ,and and There are only cyclic shift operations between them, resulting in By Shifting left by 5 bits yields the result, i.e. .
Citation Information
Patent Citations
Power consumption attack efficient screening method based on genetic algorithm
CN113128133A
Implementation method of ZUC password security algorithm
CN114785482A