Method and system for searching password difference features by constructing SAT model based on weight

By assigning weights to Boolean variables and using the weight sequence encoding method, the problem of inefficiency of the SAT method when searching for differential characteristics of passwords is solved, and more efficient S-box probability information portrayal and differential feature search are achieved.

CN120342582APending Publication Date: 2025-07-18XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510561800.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

When searching for password differential features, the existing SAT method is particularly aimed at the large S-box algorithm, which is inefficient, mainly due to the introduction of a large number of Boolean variables, the S-box probability information is not efficient enough to construct the S-box component.

Method used

By assigning weights to the introduced Boolean variables and using the combination of weights and Boolean variables, the number of Boolean variables is reduced, and combined with the weight order coding method, the objective function is converted into a combination paradigm, a SAT model is generated, the number of clauses is reduced, and the search efficiency is improved.

Benefits of technology

It effectively reduces the number of use of Boolean variables, reduces the generation of clauses in the SAT model, and improves the efficiency of searching for password differential features.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342582A_ABST
    Figure CN120342582A_ABST
Patent Text Reader

Abstract

The invention provides a method and a system for searching a password difference feature based on a weight construction SAT model. The method and the system mainly solve the problems that more Boolean variables are introduced and the efficiency of searching the password difference feature is low when an S box probability is described in the prior art. According to the implementation scheme, the method comprises the steps that a linear component of a target cryptographic algorithm is converted into a linear differential propagation assembly; according to DDT of a target algorithm S box, Boolean variables are introduced, weights are given, impossible propagation clauses are generated and simplified, and an S box differential propagation component in the SAT model is obtained; establishing an objective function according to the difference feature probability expected to be searched, and converting the objective function into an objective function part component in a conjunctive normal form by using weight sequence coding; and forming an SAT model by the components, and solving the SAT model to find out the difference feature of the target password. The method can effectively reduce the number of Boolean variables introduced for describing the S-box difference probability information, improves the efficiency of searching the difference characteristics of the cryptographic algorithm, and can be used for the design and analysis of the cryptographic algorithm.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and particularly relates to a method and system for searching differential characteristics of passwords, which can be used for password design and analysis. Background Art

[0002] Block ciphers play an important role in the field of cryptography. In recent years, people have continuously proposed new password design schemes aimed at achieving more secure and efficient cryptographic algorithms. Currently, differential analysis technology is the mainstream analysis technology for analyzing the security of block ciphers. Therefore, being able to resist differential analysis has become a basic criterion for designing new cryptographic algorithms, and the premise of performing differential analysis is to find high-probability differential characteristics.

[0003] Automated search tools are increasingly widely used in the application of finding high-probability differential characteristics, especially the use of methods based on mixed integer linear programming (MILP) and Boolean satisfiability problem (SAT). After more than a decade of development, automatic search methods have been widely applied in aspects such as differential characteristics, linear characteristics, cube attacks, and meet-in-the-middle attacks. Compared with the MILP method, the SAT method has higher search efficiency, so the application of the SAT method is becoming more and more popular.

[0004] However, the current search efficiency of the SAT method is still not satisfactory, especially for some cryptographic algorithms with large S-box bits. In 2023, Wang Meiqin et al. disclosed a method for solving the problem of difficult simplification caused by a large number of clauses generated by large S-boxes in their paper "SoK: Modeling for Large S-boxes Oriented to Differential Probabilities and Linear Correlations". By introducing additional Boolean variables to represent different differential probabilities, the number of clauses generated by the S-box is reduced, and the probability information of the S-box is indirectly characterized through the additionally introduced Boolean variables, thus resulting in the introduction of more Boolean variables when constructing S-box components.

[0005] In 2024, Sun Ling et al. disclosed a method for searching for the maximum differential probability of the SM4 algorithm in their paper "Exploring the Optimal Differential Characteristics of SM4(Full Version): Improving Automatic Search by Including Human Insights". This method observes the properties of the SM4 algorithm and adds additional clauses to narrow the search space. However, it still needs to introduce additional Boolean variables when constructing the S-box component to indirectly characterize the S-box component, and also introduces a large number of Boolean variables to describe the differential probability, resulting in a large number of auxiliary variables being introduced when constraining the objective function and reducing the search efficiency. Summary of the Invention

[0006] The object of the present invention is to propose a method and system for searching for cryptographic differential characteristics by constructing a SAT model based on weights in view of the above-mentioned deficiencies of the prior art, so as to reduce the number of Boolean variables introduced for characterizing the differential probability information of the S-box and improve the efficiency of searching for differential characteristics of the S-box cryptographic algorithm.

[0007] The technical idea for achieving the object of the present invention is: by assigning weights to the introduced Boolean variables, using the combination of weights and Boolean variables to replace the accumulation of the number of Boolean variables, thus characterizing the probability information of the S-box with fewer Boolean variables; on the basis of reducing the Boolean variables, when converting the objective function into conjunctive normal form by the weight order encoding method, the auxiliary variables to be introduced are correspondingly reduced, reducing the number of clauses in the generated SAT model, thereby improving the efficiency of searching for differential characteristics.

[0008] According to the above idea, the technical solution of the present invention includes the following:

[0009] 1. A method for searching for cryptographic differential characteristics by constructing a SAT model based on weights, characterized by comprising:

[0010] (1) Converting the linear components in the target cryptographic algorithm into linear differential propagation components in the SAT model;

[0011] (2) Generating a differential distribution table DDT from the non-linear component S-box in the target cryptographic algorithm. According to the types of different differential probabilities in the DDT, introduce Boolean variables and assign weights to characterize the probability information of the DDT, generate impossible propagation clauses, and simplify them to obtain the S-box differential propagation components in the SAT model;

[0012] (3) Establishing an objective function according to the differential characteristic probability to be searched, and using the weight order encoding method to convert the objective function into clauses in conjunctive normal form to generate the objective function partial components in the SAT model;

[0013] (4) The above-mentioned linear differential propagation component, S-box differential propagation component and partial components of the objective function are combined into a complete SAT model, which is solved by a SAT solver to obtain the cryptographic differential features that satisfy the objective function.

[0014] Furthermore, in step (2), according to the types of different differential probabilities in the DDT, Boolean variables are introduced and weighted, the probability information of the DDT is characterized, and an impossible propagation clause is generated, including:

[0015] (2a) Based on the DDT generated by the S-box, calculate the differential probability P(α, β) when the input difference is α and the output difference is β;

[0016] (2b) Calculate the differential probability weight W1(α, β) of the differential probability P(α, β);

[0017] (2c) Different differential probability weights W1(α,β) are used as elements of the S-box probability weight set Ω1, and Ω1 is used to record the probability information of DDT;

[0018] (2d) According to the type reflected by the number of elements in the S-box probability weight set Ω1, C Boolean variables x0, x1, …, x b ,…,x C-1 , and assign different Boolean variable weights W2(x b ), where 0≤b≤C-1;

[0019] (2e) Traverse the vector x=(x0,...,x C-1 ) of 2 C Species value, calculation As an element of the Boolean variable weight set Ω2, and the sets Ω1 and Ω2 satisfy use Represents all differential probability information in DDT;

[0020] (2f) Define the input difference α, output difference β and vector x=(x0, x1,…, x b ,…,x C-1 )’s Boolean function f(α||β||x);

[0021] (2g) Traverse all possible values of the vector (α||β||x) and convert the vector (α||β||x) with f(α||β||x)=0 into an impossible propagation clause.

[0022] Furthermore, in step (3), the objective function is established according to the differential feature probability of the desired search, and the objective function is converted into a clause in the conjunctive normal form using the weighted sequential coding method, and its implementation includes:

[0023] (3a) Set the target differential probability for searching the R-round differential characteristic as P R , and calculate its target differential probability weight k;

[0024] (3b) Establish an objective function in the form of Boolean cardinality constraints where W2(x i ) represents the Boolean variable weight of x i , x i represents the Boolean variable used to characterize the differential propagation probability information in the R-round;

[0025] (3c) Through the Boolean auxiliary variable s e,j ∈{0,1}, convert the objective function into a clause in the form of conjunctive normal form.

[0026] 2. Based on the same concept, the password differential characteristic search system of the present invention for constructing a SAT model based on weights includes:

[0027] A linear component conversion module, which is used to convert the linear components in the target cryptographic algorithm into linear differential propagation components in the SAT model;

[0028] An S-box component conversion module, which is used to introduce Boolean variables and assign weights to characterize the probability information of the DDT according to the types of different differential probabilities generated by the non-linear component S-box in the target cryptographic algorithm, generate impossible propagation clauses, and simplify the clauses to obtain the S-box differential propagation components in the SAT model;

[0029] An objective function conversion module, which is used to establish an objective function according to the differential characteristic probability to be searched, and convert the objective function into a clause in the form of conjunctive normal form by using weighted order encoding, and generate the objective function partial components in the SAT model;

[0030] A solving module, which is used to generate the SAT model and solve it to obtain the differential characteristics of the target password.

[0031] Compared with the prior art, the present invention has the following advantages:

[0032] First, since the present invention constructs the S-box differential propagation components by using the weight method, assigns weights to the Boolean variables introduced according to the types of different differential probabilities in the DDT, and replaces the accumulation of the number of Boolean variables with the combination of weights and Boolean variables, it realizes the characterization of the S-box probability information with fewer Boolean variables, generates fewer impossible propagation clauses, and is convenient for simplifying them;

[0033] Second, since the present invention uses fewer Boolean variables, the number of auxiliary variables introduced when converting the objective function into conjunctive normal form is reduced, the number of clauses in the generated SAT model is decreased, and the efficiency of searching for differential characteristics is improved. Description of the Drawings

[0034] Figure 1 It is a flowchart for implementing the method for searching for cryptographic differential characteristics of the SAT model constructed based on weights according to the present invention;

[0035] Figure 2 It is a sub-flowchart for solving the SAT model in the method of the present invention;

[0036] Figure 3 It is a block diagram of the system for searching for cryptographic differential characteristics of the SAT model constructed based on weights according to the present invention. Detailed Embodiments

[0037] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0038] It should be noted that the step numbers in the specification and claims of the present invention are only for clearly describing the implementation solutions of the present invention for easy understanding, and their sequence numbers are not limited.

[0039] Embodiment 1, a method for searching for cryptographic differential characteristics of the SAT model constructed based on weights;

[0040] Refer to Figure 1 , the implementation steps of this embodiment include the following:

[0041] Step 1, generate a linear differential propagation component.

[0042] The target cryptographic algorithm SM4 in this step is performed through different operations, that is, through the conversion of the branch operation and the exclusive OR operation in the target cryptographic algorithm. SM4 is a block cipher standard adopted in China and is currently widely used in fields such as the Internet and government affairs. In each round of the SM4 cryptographic algorithm, there are 3 branch operations of 32 bits, 7 exclusive OR operations of 32 bits, and 4 non-linear component S boxes.

[0043] (1.1) Convert the branch operation in the target cryptographic algorithm into a branch differential propagation component in the SAT model:

[0044] According to the three 32-bit branch operations in each round of the SM4 algorithm, let φ represent the input difference, and θ represent the two output differences respectively, and construct the branch difference propagation component conditions of φ, and θ as follows:

[0045]

[0046] where φ t represents the t-th bit in the 32-bit input difference φ, represents the t-th bit in the 32-bit output difference , and θ t represents the t-th bit in the 32-bit output difference θ, 0 ≤ t ≤ 31, ∨ represents disjunction, represents negation;

[0047] Convert the 32-bit branch operation in the SM4 algorithm into the branch difference propagation component in the SAT model using the above conditions;

[0048] (1.2) Convert the exclusive-or operation in the target cryptographic algorithm into the exclusive-or difference propagation component in the SAT model:

[0049] According to the seven 32-bit exclusive-or operations in each round of the SM4 cryptographic algorithm, let χ and δ represent the two input differences respectively, and η represent the output difference, and construct the exclusive-or difference propagation component conditions of χ, δ, and η as follows:

[0050]

[0051] where χ t represents the t-th bit in the 32-bit input difference χ, δ t represents the t-th bit in the 32-bit input difference δ, and η t represents the t-th bit in the 32-bit output difference η, 0 ≤ t ≤ 31;

[0052] Convert the 32-bit exclusive-or operation in the SM4 algorithm into the exclusive-or difference propagation component in the SAT model using the above conditions.

[0053] Step 2, generate the S-box difference propagation component.

[0054] According to the four non-linear components S-boxes in each round of the SM4 cryptographic algorithm, generate the differential distribution table DDT of each S-box. According to the types of different differential probabilities in the DDT, introduce Boolean variables and assign weights to characterize the probability information of the DDT, generate impossible propagation clauses, simplify the clauses, and obtain each S-box difference propagation component in the SAT model. The specific implementation steps are as follows:

[0055] (2.1) According to the S-box of the target cryptographic algorithm, traverse all possible 8-bit input differences α and output differences β, count the frequencies of the difference pairs (α, β) that appear, and generate a differential distribution table DDT, as shown in Table 1.

[0056] Table 1 DDT of SM4

[0057]

[0058] (2.2) Generate the DDT according to the S-box of the SM4 algorithm, and calculate the differential probability with the input difference being α and the output difference being β The obtained differential probabilities are shown in Table 2:

[0059] Table 2 Differential Probabilities of SM4 DDT

[0060]

[0061] (2.3) Calculate the differential probability weight W1(α, β) = -log2(P(α, β)) of the differential probability P(α, β), where P(α, β) ≠ 0. The obtained differential weights are shown in Table 3:

[0062] Table 3 Differential Weights of SM4 DDT

[0063]

[0064] (2.4) According to the different differential probability weights W1(α, β) calculated in step (2.3), construct the S-box probability weight set Ω1. In this example, according to the different differential weights of 0, 6, and 7 in the SM4 DDT in Table 3, the corresponding

[0065] Ω1 = {0, 6, 7};

[0066] (2.5) According to the types reflected by the number of elements in the S-box probability weight set Ω1, introduce 2 Boolean variables x0 and x1, and let the Boolean variable weights W2(x0) = 1 and W2(x1) = 6;

[0067] (2.6) Let the vector x = (x0, x1) be composed of 2 Boolean variables, traverse all its possible 2 2 values, calculate the Boolean variable weight set Ω2, satisfying The elements of Ω2 are

[0068] When x0 = 0 and x1 = 0,

[0069] When x0 = 0 and x1 = 1,

[0070] When x0 = 1 and x1 = 0,

[0071] When \(x0 = 1\) and \(x1 = 1\),

[0072] So, \(\Omega2=\{0,1,6,7\}\);

[0073] (2.7) Define the Boolean function \(f(\alpha||\beta||x)\) for the input difference \(\alpha\), output difference \(\beta\) of the S - box and the vector \(x=(x0,x1)\), and its values are as follows:

[0074] When That is, when the vector \((\alpha||\beta||x)\) can perform differential propagation: \(f(\alpha||\beta||x)=1\), otherwise: \(f(\alpha||\beta||x)=0\), where, "||" represents the concatenation operation;

[0075] (2.8) Traverse all possible values of the vector \((\alpha||\beta||x)\), and convert the vector \((\alpha||\beta||x)\) with \(f(\alpha||\beta||x)=0\) into impossible propagation clauses. Some impossible propagation clauses are shown in Table 4;

[0076] Table 4 Some impossible propagation clauses

[0077]

[0078] (2.9) Simplify the impossible propagation clauses, as shown in Table 5:

[0079] Table 5 Simplified some impossible propagation clauses

[0080]

[0081] In Table 5, the symbol "-" means omitting the variable at that position;

[0082] Take the simplified impossible propagation clauses in Table 5 as each S - box differential propagation component in the SAT model.

[0083] Step 3, generate partial components of the objective function.

[0084] (3.1) When searching for the differential characteristic of the SM4 cipher algorithm, establish the objective function according to the differential characteristic probability expected to be searched:

[0085] Set the target differential probability \(P\) for searching the differential characteristic of \(R\) rounds R = 1;

[0086] Calculate the target differential probability weight \(k\) according to the target differential probability:

[0087]

[0088] Among them, Denote ceiling function;

[0089] According to the Boolean variable x i , the Boolean variable weight W2(x i ), and the target differential probability weight k, establish an objective function in the form of a Boolean cardinality constraint:

[0090]

[0091] where x i represents the Boolean variable used to characterize the differential propagation probability information of the S-box in the R-th round, and n = R * 2 * 4 represents the total number of the Boolean variable x i ;

[0092] (3.2) Use the weighted order encoding to convert the objective function into clauses in the form of conjunctive normal form, and generate the component of the objective function in the SAT model:

[0093] In this step, by introducing the Boolean auxiliary variable s e,j ∈{0, 1}, convert the objective function into the following clauses in the form of conjunctive normal form:

[0094]

[0095] where, 0 ≤ e ≤ n - 2, 0 ≤ j ≤ k - 1, 0 ≤ l < W2(x0), W2(x0) ≤ d < k, 1 ≤ h < k - W2(x i ), 1 ≤ i ≤ n - 2, denotes negation;

[0096] Take these clauses in the form of conjunctive normal form as the component of the objective function in the SAT model.

[0097] Step 4, generate the SAT model and solve it.

[0098] (4.1) Combine the linear differential propagation component of the SM4 cipher algorithm generated in Step 1, the S-box differential propagation component generated in Step 2, and the component of the objective function generated in Step 3 into a complete SAT model;

[0099] (4.2) Use the SAT solver to solve the SAT model and obtain the cipher differential characteristic that satisfies the objective function:

[0100] As Figure 2 shown, the implementation of this step includes:

[0101] (4.2.1) Solve the SAT model with the objective function and determine whether its solution exists:

[0102] If the solution exists, execute step (4.2.2);

[0103] Otherwise, execute step (4.2.4);

[0104] (4.2.2) Let k = k - 1, update the objective function component using step (3), and regenerate the SAT model;

[0105] (4.2.3) Solve the SAT model regenerated in step (4.2.2) and determine whether a solution exists:

[0106] If a solution exists, return to step (4.2.2);

[0107] Otherwise, let k = k + 1 be the differential weight of the maximum differential characteristic probability, and execute step (4.2.6);

[0108] (4.2.4) Let k = k + 1, update the objective function component using step (3), and regenerate the SAT model;

[0109] (4.2.5) Solve the SAT model regenerated in (4.2.4) and determine whether a solution exists:

[0110] If a solution exists, let k be the differential weight of the maximum differential characteristic probability, and execute step (4.2.6);

[0111] Otherwise, return to step (4.2.4);

[0112] (4.2.6) Output the target cipher differential characteristic according to the solution model result.

[0113] In this example, a 19-round differential characteristic search is performed on SM4, and its differential characteristics are shown in Table 6:

[0114] Table 6 19-round differential characteristics of SM4

[0115]

[0116] As can be seen from Table 6, the maximum differential probability of the 19-round differential characteristic of SM4 is 2 -123 .

[0117] Example 2, a system for searching cipher differential characteristics by constructing a SAT model based on weights;

[0118] Refer to Figure 3, this example includes: a linear component conversion module 1, an S-box component conversion module 2, an objective function conversion module 3, and a solving module 4, where: The S-box component conversion module 2 includes a DDT generation sub-module 21, an S-box probability weight set generation sub-module 22, a Boolean variable weight set generation sub-module 23, and an impossible propagation clause generation sub-module 24; The objective function conversion module 3 includes an objective function generation sub-module 31 and an objective function conversion sub-module 32, which are used to generate the component of the objective function in the SAT model. The working principle of the entire system is as follows:

[0119] The linear component conversion module 1 is used to generate the linear differential propagation component in the SAT model according to the linear component in the target cryptographic algorithm and transmit it to the solving module 4;

[0120] The S-box component conversion module 2 is used to generate the differential propagation component of the S-box in the SAT model, where: The DDT generation sub-module 21 first traverses all possible input differences α and output differences β according to the S-box of the target cryptographic algorithm, counts the frequency of the differential pair (α, β) to generate a DDT, and transmits it to the S-box probability weight set generation sub-module 22. This sub-module 22 is used to calculate the differential probability weight W1(α, β) with the input difference α and the output difference β according to the DDT of the S-box, and use it as an element of the S-box probability weight set Ω1, and transmit it to the Boolean variable weight set generation sub-module 23; This sub-module 23 introduces multiple Boolean variables and assigns different weights according to the number of elements in the S-box probability weight set Ω1, and uses the weighted result of the multiple Boolean variables as an element of the Boolean variable weight set Ω2, and the sets Ω1 and Ω2 satisfy The impossible propagation clause generation sub-module 24 determines the impossible propagation vector according to the differential probability weight W1(α, β), converts it into an impossible propagation clause, and simplifies the impossible propagation clause into the differential propagation component of the S-box and transmits it to the solving module 4;

[0121] The objective function conversion module 3 is used to generate the component of the objective function in the SAT model, where: The objective function generation sub-module 31 calculates the target differential probability weight k according to the set search differential characteristic probability P R , generates an objective function in the form of a Boolean cardinality constraint and transmits it to the objective function conversion sub-module 32; This sub-module 32 uses the weight order encoding method to convert the generated objective function into a conjunctive normal form clause, and uses the generated conjunctive normal form clause as the component of the objective function part and transmits it to the solving module 4;

[0122] The solving module 4 is used to combine the linear differential propagation components generated by the linear component conversion module 1, the S-box differential propagation components generated by the S-box component conversion module 2, and the objective function partial components generated by the objective function conversion module 3 into a complete SAT model, and use a SAT solver to solve it to obtain a cryptographic differential characteristic that satisfies the objective function.

[0123] The technical effects of the present invention will be further described below in combination with the experimental results:

[0124] 1. Experimental conditions:

[0125] The hardware platform for the experiment: The CPU is the 13th generation i5-13400F, the main frequency is 2.5GHz * 10, and the memory is 32GB;

[0126] The software platform: The operating system is Windows11, and the SAT solver is the Cadical solver;

[0127] The target cryptographic algorithm: The block cipher algorithm SM4.

[0128] 2. Experimental content and result analysis:

[0129] Using the method proposed by the present invention and the method proposed by Sun Ling et al. in the public paper "Exploring the Optimal Differential Characteristics of SM4 (Full Version): Improving Automatic Search by Including Human Insights", the 20-round differential characteristic search is respectively carried out on the block cipher algorithm SM4. During the search process, the number of Boolean variables introduced by the two methods is shown in Table 7, and the search time is shown in Table 8:

[0130] Table 7 Comparison of Boolean variables depicting S-box probability information in the 20-round differential characteristics of SM4

[0131] Method type Number of Boolean variables Existing method 560 Method proposed by the present invention 160

[0132] Table 8 Comparison of search times for the 20-round differential characteristics of SM4

[0133] Method type Search time Existing method 28.1 days Method proposed by the present invention 12.9 days

[0134] As can be seen from Table 7, when the present invention and the prior art search for the 20-round differential characteristics of SM4, the number of Boolean variables introduced by the prior method to depict the S-box probability information is 560, and the number of Boolean variables introduced by the method of the present invention is only 160. Compared with the prior art, the number of Boolean variables introduced by the present invention is reduced by 400.

[0135] As can be seen from Table 8, when searching for the 20-round differential characteristic of SM4 by the present invention and the prior art, the search time of the prior art is 28.1 days, while the search time of the method of the present invention is only 12.9 days. Compared with the prior art, the search time of the present invention is reduced by 15.2 days, improving the search efficiency.

[0136] The above experimental results show that the present invention can significantly reduce the number of Boolean variables introduced by characterizing the probability information of the S-box, effectively improving the search efficiency.

Claims

1. A method for searching for a password differential characteristic by constructing a SAT model based on weights, characterized in that, Including: (1) Convert the linear components in the target cryptographic algorithm into linear differential propagation components in the SAT model; (2) Generate a differential distribution table (DDT) from the non-linear component S-box in the target cryptographic algorithm. According to the types of different differential probabilities in the DDT, introduce Boolean variables and assign weights to characterize the probability information of the DDT, generate impossible propagation clauses, and simplify them to obtain the S-box differential propagation components in the SAT model; (3) Establish an objective function based on the differential characteristic probability to be searched. Use the weighted order encoding method to convert the objective function into clauses in conjunctive normal form to generate the objective function partial components in the SAT model; (4) Combine the above linear differential propagation components, S-box differential propagation components, and objective function partial components into a complete SAT model, and use a SAT solver to solve it to obtain the cryptographic differential characteristics that satisfy the objective function.

2. The method according to claim 1, characterized in that In step (1), the conversion of the linear components in the target cryptographic algorithm into linear differential propagation components in the SAT model includes: (1a) Convert the branch operations in the target cryptographic algorithm into branch differential propagation components in the SAT model: Let φ denote the input difference, and θ denote the two output differences respectively. Construct the branch difference propagation component conditions for φ, and θ as follows: where φ t represents the t-th bit in the m-bit input difference φ, represents the m-bit output difference the t-th bit in, θ t represents the t-th bit in the m-bit output difference θ, 0 ≤ t ≤ m - 1, ∨ represents disjunction, represents negation; Convert the m-bit branch operation that satisfies the above conditions into a branch differential propagation component in the SAT model; (1b) Convert the exclusive OR operations in the target cryptographic algorithm into exclusive OR differential propagation components in the SAT model: Let χ and δ represent two input differentials respectively, and η represent the output differential. The conditions for constructing the exclusive OR differential propagation components of χ, δ, and η are as follows: where χ t represents the t-th bit in the m-bit input difference χ, δ t represents the t-th bit in the m-bit input difference δ, η t represents the t-th bit in the m-bit output difference η, 0 ≤ t ≤ m - 1; Convert the m-bit exclusive OR operation that satisfies the above conditions into an exclusive OR differential propagation component in the SAT model.

3. The method according to claim 1, characterized in that In step (2), according to the types of different differential probabilities in the DDT, introduce Boolean variables and assign weights to characterize the probability information of the DDT, including: (2a) According to the DDT generated by the S-box, calculate the differential probability P(α, β) with the input differential being α and the output differential being β; (2b) Calculate the differential probability weight W1(α, β) of the differential probability P(α, β): W1(α, β) = -log2(P(α, β)) where: P(α, β) ≠ 0; (2c) Take the different differential probability weights W1(α, β) as elements of the S-box probability weight set Ω1, and use Ω1 to record the probability information of the DDT; (2d) According to the types reflected by the number of elements in the S-box probability weight set Ω1, introduce C Boolean variables x0, x1, …, x b , …, x C-1 , and assign different Boolean variable weights W2(x b ) to each Boolean variable, where 0 ≤ b ≤ C - 1; (2e) Traverse all \(2^C\) possible values of the vector \(x=(x_0,\ldots,x_{C - 1})\) composed of \(C\) boolean variables, and calculate \(\cdots\) as an element of the set \(\Omega_2\) of boolean variable weights, where the sets \(\Omega_1\) and \(\Omega_2\) satisfy \(\cdots\). C-1 ) of \(2^C\) C possible values, and calculate \(\cdots\) as an element of the set \(\Omega_2\) of boolean variable weights, and the sets \(\Omega_1\) and \(\Omega_2\) satisfy \(\cdots\) Use \(\cdots\) to represent all the differential probability information in the DDT.

4. The method according to claim 1, wherein In step (2), the generation of impossible propagation clauses includes: (2f) Define the Boolean function f(α||β||x) for the input difference α, output difference β of the S-box, and the vector x = (x0, x1, …, x b , …, x C-1 ), whose values are as follows: When That is, when the vector (α||β||x) can perform differential propagation: f(α||β||x) = 1 Otherwise: f(α||β||x) = 0 where: "||" represents the concatenation operation; (2g) Traverse all possible values of the vector (α||β||x), and convert the vector (α||β||x) with f(α||β||x) = 0 into an impossible propagation clause.

5. The method according to claim 1, characterized in that In step (3), establishing the objective function based on the differential characteristic probability to be searched includes: (3a) Set the target differential probability for searching the R-round differential characteristic as P R , and calculate its target differential probability weight k: Among them, represents rounding up; (3b) Establish an objective function in the form of a Boolean cardinality constraint: Among them, x i represents the Boolean variable used to characterize the differential propagation probability information of the S-box in the R-th round, and W2(x i ) represents the Boolean variable weight of x i . n = R * C * M represents the total number of Boolean variables x i , and M represents the number of S-boxes in one round of the target cryptographic algorithm.

6. The method according to claim 1, wherein In step (3), the weighted ordered encoding method is used to transform the objective function into clauses in conjunctive normal form by introducing a Boolean auxiliary variable s e,j ∈ {0, 1}, and the objective function is transformed into the following clauses in conjunctive normal form: where: 0 ≤ e ≤ n - 2, 0 ≤ j ≤ k - 1, 0 ≤ l < W2(x0), W2(x0) ≤ d < k, 1 ≤ h < k - W2(x i ), 1 ≤ i ≤ n - 2, represents negation.

7. The method according to claim 1, characterized in that In step (4), using a SAT solver to solve the generated SAT model includes: (4a) Solve the SAT model with the objective function and determine whether a solution exists: If a solution exists, execute step (4b); Otherwise, execute step (4d); (4b) Let k = k - 1, update the objective function components using step (3), and regenerate the SAT model; (4c) Solve the SAT model and determine whether a solution exists: If a solution exists, return to step (4b); Otherwise, let k = k + 1 be the differential weight of the maximum differential characteristic probability, and execute step (4f); (4d) Let k = k + 1, update the objective function component using step (3), and regenerate the SAT model; (4e) Solve the SAT model and determine whether a solution exists: If a solution exists, let k be the differential weight of the maximum differential characteristic probability, and execute step (4f); Otherwise, return to step (4d); (4f) Output the target cipher differential characteristic according to the result of the solved model.

8. A system for searching for cryptographic differential characteristics based on weight construction of a SAT model, characterized in that, Including: A linear component conversion module, which is used to convert the linear components in the target cipher algorithm into linear differential propagation components in the SAT model; An S-box component conversion module, which is used to introduce Boolean variables and assign weights to characterize the probability information of the DDT according to the types of different differential probabilities in the DDT generated by the non-linear component S-box in the target cipher algorithm, generate impossible propagation clauses, and simplify the clauses to obtain the S-box differential propagation components in the SAT model; An objective function conversion module, which is used to establish an objective function according to the differential characteristic probability to be searched, and convert the objective function into clauses in conjunctive normal form by using weight order encoding to generate the objective function partial components in the SAT model; A solving module, which is used to generate the SAT model and solve it to obtain the differential characteristic of the target cipher.

9. The system according to claim 8, wherein The S-box component conversion module includes: An S-box probability weight set generation sub-module, which is used to calculate the differential probability weight W1(α,β) of the input difference being α and the output difference being β according to the DDT of the S-box, and use it as an element of the S-box probability weight set Ω1; A Boolean variable weight set generation sub-module, which is used to introduce multiple Boolean variables, assign different weights according to the number of elements in the S-box probability weight set Ω1, weight the multiple Boolean variables, and use the weighted result as an element of the Boolean variable weight set Ω2, and the sets Ω1 and Ω2 satisfy An impossible propagation clause generation sub-module, which is used to determine the impossible propagation vector according to the differential probability weight W1(α,β) and convert it into an impossible propagation clause.

10. The system according to claim 8, wherein The objective function module includes: An objective function generation sub-module, which is used to calculate an objective differential probability weight k according to a differential feature probability P to be searched as expected, and generate an objective function in the form of a boolean cardinality constraint; R ​ An objective function conversion sub-module, which is used to convert the objective function in the form of Boolean cardinality constraint into clauses in conjunctive normal form by using the weight order encoding method.