Hybrid differential bit-level discriminator searching method
By introducing mixed differential mode encoding variables and probability variables into lightweight packet ciphers, the Boolean satisfactory problem is established, and the bit-level mixed differential divider is automatically found, which solves the problem of lack of automated search methods in the prior art and improves the efficiency of security evaluation.
Patent Information
- Application Number
- CN202410884852.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-03
- Publication Date
- 2025-07-29
AI Technical Summary
The existing mixed-differential analysis methods mainly focus on packet ciphers with (half) bytes as basic operation elements, lack mixed-differential properties analysis for lightweight packet ciphers with bits as basic operation elements, and lack automated hybrid-differential divider search methods in the prior art.
A search method for mixed differential bit-level differentialist is proposed. By introducing mixed differential mode encoding variables and probability variables, the bit-level shift, XOR operation and AND operation are encoded, the Boolean satisfactory problem is established, and the solution is to obtain a high probability mixed differentialist.
It realizes a high probability hybrid differential divider that automatically finds bit-level lightweight packet passwords, reducing the workload and probability of manual search, and improving the efficiency of security evaluation.
Smart Images

Figure CN120389847A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for searching a hybrid differential bit-level distinguisher, belonging to the technical field of network information security cryptography design and analysis. Background Art
[0002] A symmetric cipher refers to a cipher algorithm that uses the same key for both encryption and decryption, and is mainly used for data encryption. Among them, block ciphers are a widely used type of symmetric cipher. The encryption of a block cipher means that under the control of a main key of length m bits, a plaintext of a fixed length (such as n bits) is transformed into a ciphertext of the same length (if the plaintext length is n, the ciphertext length is also n); decryption means restoring the plaintext under the control of the same key. n is the block length of the plaintext, m is the main key length, m is a positive integer, and n is a positive integer.
[0003] Block ciphers can not only be used for data encryption, but also be used to construct hash functions and message authentication codes (MACs), etc., which makes the application of block ciphers very extensive. How to design a secure and efficient block cipher is a crucial topic in the field of information security research.
[0004] The Feistel structure is one of the most commonly used structures in the design of block ciphers. The core of designing a Feistel structure block cipher lies in designing a suitable round function and iterating the round function multiple times to achieve sufficient security. A Feistel block cipher that iterates the round function R times is said to have R rounds, where R is a positive integer. The block length of the Feistel structure is 2N, and the plaintext and the intermediate state of each round are divided into two N-bit parts, the left and the right. Only half of them are encrypted in each round, and the other half is obtained by swapping the left and the right. Therefore, the encryption and decryption algorithm structures of the Feistel structure block cipher are the same. For an R-round Feistel block cipher with a block length of 2N, an N-bit subkey is required for each round, and the subkey used in each round is obtained from the main key of the block cipher through a deterministic key expansion algorithm.
[0005] The round function structure of a Feistel structure block cipher with a block length of 2N usually includes three operations. Taking the SIMON encryption algorithm as an example, as Figure 1 shown. These three operations are in sequence:
[0006] 1. Round function encryption operation. Perform linear operations such as shifting and XOR on the left N bits of the input half, and perform an AND non-linear operation, and output N bits.
[0007] As shown in the formula, it is the algebraic expression of the round function of SIMON, where x and y represent the left input and the right input before encryption of each round function respectively:
[0008]
[0009] 2. Block XOR operation. XOR the N bits encrypted by the round function with the other half of the right N bits to obtain N bits waiting for subsequent operations. Another N bits that have not undergone the encryption operation of the round function are directly used as the right N input bits of the next round.
[0010] 3. Round key XOR operation. XOR the N bits obtained from the first two operations with the N-bit round key of each round to obtain N bits as the left N input bits of the next round.
[0011] Figure 1 Among them, the round function includes cyclic left shift, XOR, and bit-level AND operations, including linear operations and non-linear operations.
[0012] In modern information society, the wide use of micro computing devices has made the demand for lightweight block ciphers more and more urgent. How to design a lightweight block cipher with small circuit area, low power consumption and high security after implementation has attracted wide interest in the cryptographic community and the industrial community. For example, SIMON (the name of a lightweight block cipher) is a lightweight block cipher with a new Feistel structure. One of its main design criteria is to effectively resist differential fault attacks, and it should also be able to cope with linear attacks, differential attacks, integral attacks, meet-in-the-middle attacks, zero-correlation attacks, etc.
[0013] Differential attack is an important method among all known attacks. It obtains some key bits by analyzing the influence of the difference of a specific plaintext pair on the difference of the ciphertext pair. Differential attacks can be used to attack and analyze any cryptographic system constructed by iterating a fixed round function, including Feistel structure block ciphers, including DES (Data Encryption Standard), AES (Advanced Encryption Standard), as well as SIMECK (a lightweight bit-level block cipher) and SIMON (a lightweight bit-level block cipher). Among them, the SIMON algorithm is a lightweight bit-level cryptographic algorithm with a new Feistel structure, which can effectively resist differential fault attacks. It performs bit-level non-linear layer AND operations, linear shift operations, and XOR operations with bits as single elements. The specific bit-level non-linear operations and linear operations are as Figure 1As shown. The linear operations in each round are divided into bit shifts and bit-level XOR operations. The bit shift generates a new N-bit element by circularly shifting the left N-bit element of the input in each round. The bit-level XOR operation performs an exclusive OR on the N-bit element and the right N-bit element for diffusion. The non-linear operation in each round is a bit-level AND operation, which performs a bit-by-bit AND operation on the N-bit element after bit shift. Differential attacks involve selecting plaintext pairs with a certain special differential pattern, making the probability of ciphertext pairs with a certain special differential pattern higher. Differential attacks use these characteristics to calculate possible keys. Differential attacks largely depend on the probability of the selected differential path.
[0014] Therefore, in order to resist the classical but efficient differential attacks, all newly designed lightweight block ciphers must prove their security against differential attacks. For example, in 2013, the National Security Agency (NSA) of the United States launched a new family of encryption algorithms, SIMON and SPECK. Both SIMON and SPECK are based on the Feistel structure. As bit-level lightweight block ciphers, their designs use bit shifts and bit XOR operations as their linear operations, and this design can prove that SIMON can resist traditional differential attacks.
[0015] The effectiveness of differential attacks depends on the probability of the selected differential characteristics. The higher the probability, the more effective the attack. Hybrid differential analysis is a variant of differential attacks. The core idea of hybrid differential cryptanalysis is to study the properties of four plaintext states and their corresponding four ciphertexts, which are closely related. This property was first proposed by Grassi et al. in Eurocrypt 2017. They first discovered a key recovery distinguisher for 5-round AES. It was formally defined as the hybrid differential property at FSE / ToSC 2019. Specifically, it is that the four ciphertexts corresponding to four specially constructed plaintexts are located in a specific subspace with probability 1, which is different from random permutations. The purpose of hybrid differential analysis is to obtain a hybrid differential distinguisher for the corresponding algorithm. The hybrid differential distinguisher consists of a pair of differentials (input differential and output differential), and the probability of this pair of differentials. In order to distinguish from random permutations, the probability of the hybrid differential distinguisher is greater than the probability of obtaining this pair of differentials in the case of random permutations.
[0016] Currently, the properties of hybrid differentials have been studied from different perspectives and have been extended to more block ciphers, that is, experiments on the hybrid differential properties of various different block ciphers have been carried out, and distinguishers with more rounds have been set.
[0017] However, the existing hybrid differential properties and the construction of hybrid differential paths are all aimed at block ciphers with (semi-)bytes as the basic operation elements, lacking the analysis of the hybrid differential properties of lightweight block ciphers with bits as the basic operation elements. Moreover, the search for hybrid differentiators in most cryptanalyses relies on the dependency relationships between larger text sets for differentiation, so as to discover more non-random properties to construct an effective plaintext structure, which requires a large amount of work. Therefore, it is very necessary to have a search method for automated hybrid differential differentiators for bit-level lightweight block ciphers. Summary of the Invention
[0018] The purpose of the present invention is to address the problems and deficiencies existing in the prior art. In order to solve the problem of searching for automated hybrid differential differentiators for bit-level lightweight block ciphers in this field, a method for searching for hybrid differential bit-level differentiators is creatively proposed.
[0019] This method can automatically obtain the hybrid differential differentiators of lightweight block ciphers that use bit-level shift operations and XOR operations as basic linear operations, and bit-level AND operations as non-linear operations. This method is also applicable to other cases of bit-level lightweight block ciphers.
[0020] The present invention is implemented by the following technical solutions.
[0021] A method for searching for hybrid differential bit-level differentiators includes the following steps:
[0022] Step 1: For the left and right input bits of each round in a block cipher that uses bit shift and bit XOR as basic linear operations, introduce hybrid differential mode coding variables, and introduce probability variables for the non-linear AND operation (i.e., sum operation) in each round. At the same time, introduce new hybrid differential mode coding variables for the bits after the non-linear operation.
[0023] Among them, all variables are binary variables, that is, the values are 0 or 1.
[0024] Step 2: For the bit shift operation in the encryption process, there is no need to generate new coding variables (because the basic shift operation at the bit level does not change the overall hybrid differential mode of the bits). By changing the subscript of the hybrid differential mode coding variables, the shift operation can be achieved.
[0025] For the bit-level XOR operation in the basic linear operation, the change of the hybrid differential mode on the bits after the XOR operation is as Figure 2As shown, with the goal of minimizing the sum of probability variables of non - linear AND operations on all bits in all rounds of a block cipher, the above - mentioned restrictions are imposed on all input - bit mixed - difference coding variables, output - bit mixed - difference coding variables, bit - mixed - difference pattern variables after AND operations and XOR operations, and probability variables in each round, and a Boolean satisfiability problem is established;
[0026] Step 3: Obtain a mixed - difference distinguisher by solving the Boolean satisfiability problem.
[0027] Furthermore, the block length of the bit - level block cipher is 2N bits; the block cipher has a total of R rounds, and in each round, the block is divided into a left - hand input of N bits and a right - hand input of N bits; the linear operation in each round of the block cipher consists of three bit - level shift operations and two bit XOR operations, and the non - linear operation is a bit - level AND operation.
[0028] Furthermore, in the block cipher, the mixed - difference pattern coding variable introduced at any bit position of the left - hand input of N bits in the r - th round is expressed as L represents the left - hand input of the bit - level block cipher, and the mixed - difference pattern coding variable introduced at any bit position of the right - hand input of N bits is expressed as where c is the abbreviation of code, i ∈ [1, N], r ∈ [0, R - 1], and both N and R are positive integers.
[0029] For the case where the output bit after a linear XOR operation is used as an intermediate state, a mixed - difference pattern coding variable on the intermediate state is introduced i ∈ [1, N], r ∈ [0, R - 1], and aftXOR represents the output bit after the XOR operation.
[0030] For the case where the output bit after a non - linear AND operation is used as an intermediate state, a mixed - difference pattern coding variable on the intermediate state is introduced i ∈ [1, N], r ∈ [0, R - 1]. aftAND represents the output bit after the AND operation. The specific settings are as follows:
[0031] If or Then it means that the mixed - difference legend represented by this input bit is The mixed - difference pattern is "aaaa";
[0032] If or Then it means that the mixed - difference pattern represented by this input bit is The mixed - difference pattern is "bbba";
[0033] …
[0034] If it indicates that the mixed difference example represented by the intermediate state bit after XOR operation is the mixed difference pattern is "aaaa";
[0035] If it indicates that the mixed difference example represented by the intermediate state bit after XOR operation is the mixed difference pattern is "bbba";
[0036] …
[0037] If it indicates that the mixed difference example represented by the intermediate state bit after AND operation is the mixed difference pattern is "aaaa";
[0038] If it indicates that the mixed difference pattern example represented by the intermediate state bit after AND operation is the mixed difference pattern is "bbba";
[0039] …
[0040] The correspondence between the complete ternary code and the example, and the mixed difference pattern is as Figure 3 shown.
[0041] Among them, the value range of i is an integer from 1 to N, and the value range of r is an integer from 0 to R - 1. The mixed difference pattern of each bit in the encryption process is represented by a ternary code.
[0042] Furthermore, in the block cipher, the probability variable introduced by the possible change of the mixed difference pattern caused by any non - linear AND operation is represented as i ∈ [1, N], p represents the probability variable of the bit after the non - linear operation, where p h represents the high - order bit of the probability variable, p l represents the low - order bit of the probability variable, N is a positive integer representing the number of input bits on one side of the block, r ∈ [0, R - 1]. That is, the probability of the pattern change caused by a single bit through the AND operation is Wherein:
[0043] If it indicates that the probability of obtaining the output mixed difference pattern after the AND operation on the input mixed difference pattern is 1;
[0044] If it indicates that the probability of obtaining the output mixed difference pattern after the AND operation on the input mixed difference pattern is 2 -1 ;
[0045] If It means that the probability that the output mixed difference pattern is obtained after the AND operation on the input mixed difference pattern is 2 -2 ;
[0046] If It means that the probability that the output mixed difference pattern is obtained after the AND operation on the input mixed difference pattern is 2 -3 ;
[0047] Among them, the value range of i is an integer from 1 to N, and the value range of r is an integer from 0 to R - 1.
[0048] Furthermore, the restrictions include: for the non - linear AND operation corresponding to the mixed difference pattern variable and the mixed difference probability variable, without loss of generality, the two input mixed difference pattern variables for the non - linear AND operation are respectively denoted as and where i - k is the mod N operation, k is the number of shifts for bit shifting, the output mixed difference pattern variable is denoted as The probability variable is denoted as Among them, represents the mixed difference pattern encoding of the input bits on both sides of the AND operation respectively, represents the mixed difference pattern encoding of the bit output after the AND operation. Enumerate the feasible propagation patterns and corresponding probabilities of the AND operation on the mixed difference pattern to generate a mixed difference pattern propagation table under the non - linear AND operation. The specific rules are as follows:
[0049] "000" ^ "000" → "000" with probability 1, and the variable value is (000 000 000 00);
[0050] "000" ^ "111" → "111" with probability 2 -1 , and the variable value is (000 111 111 01);
[0051] "110" ^ "011" → "100" with probability 2 -2 , and the variable value is (110 011 100 10);
[0052] "110" ^ "101" → "111" with probability 2 -2 , and the variable value is (110 101 111 10);
[0053] Select a part of the 64 combination cases in the text and all are given in the form of drawings, as Figure 4 shown.
[0054] Further, for the above-mentioned mixed difference propagation mode of the AND operation, corresponding CNF (Conjunctive Normal Form) constraints are added to ensure that the propagation of the mixed difference mode on the bits proceeds according to the specified rules. The constraints include:
[0055] Use CNF constraints to restrict the propagation of the mixed difference mode on the input and output bits of the AND operation. Each disjunctive clause in the CNF constraints can add corresponding constraints to the SAT solver by adding constraint clauses (for the sake of simplicity of constraint representation, where c2′ represents the negation of c2, and the rest are similar; e is used to simply replace aftAND). The specific CNF constraints are as follows:
[0057]
[0058] Furthermore, for the mixed differential propagation mode of the above XOR operation, corresponding CNF constraints also need to be added to ensure that the propagation of the mixed differential mode on the bits after the linear XOR operation proceeds according to the specified rules. The constraints include:
[0059] (c0′ + d0′ + e0′)(c0 + d0 + e0′)(c1′ + d1′ + e1′)(c1 + d1 + e1′)(c2′ + d2′
[0060] + e2′)(c2 + d2 + e2′)(c0 + d0′ + e0)(c1 + d1′ + e1)(c2 + d2′
[0061] + e2)(c0′ + d0 + e0)(c1′ + d1 + e1)(c2′ + d2 + e2)
[0062] To distinguish the mixed differential distinguisher from the random permutation, the sum of the probability variables of the output mode obtained under the random permutation needs to be used as the upper bound of the sum of the probability variables of the mixed differential distinguisher of the block cipher:
[0063] For the output mixed differential mode of the random permutation, there are 8 propagation cases for each bit, represented in the ternary code mode, namely: 000, 111, 100, 010, 001, 011, 101, 110. It is restricted that the sum of the probability variables corresponding to the input mixed difference to the output mixed difference of the block cipher is less than the sum of the probability variables under the random permutation: ∑(2ph + pl) < 6N′. N′ is the input length of one side of the block cipher.
[0064] As can be seen from the above solution, the method of the present invention describes the mixed differential propagation property of a block cipher system with bits as the basic elements of linear and non - linear operations as a Boolean satisfiability problem, solves this Boolean satisfiability problem, obtains a high - probability mixed differential distinguisher that can be distinguished from the random permutation, and thus greatly reduces the workload and error probability of manually searching for the mixed differential distinguisher.
[0065] Beneficial Effects
[0066] Compared with the prior art, the method of the present invention realizes the automatic search for a high - probability mixed differential distinguisher for lightweight block ciphers that use bit - level linear and non - linear operations as basic operations. In the prior art, there is no method that can automatically search for a high - probability mixed differential distinguisher in block ciphers that use bit - level shift and XOR operations as linear operations and bit - level AND operation as non - linear operation. At the same time, the present invention can also be extended to other lightweight block ciphers that use bits as basic operation elements. Description of the Drawings
[0067] Figure 1 Structure diagram of the round function of the SIMON (Feistel structure) block cipher;
[0068] Figure 2 Schematic diagram of the propagation of the mixed differential pattern for bit-level XOR operations;
[0069] Figure 3 Legend and symbolic representation diagram of the mixed differential pattern variables;
[0070] Figure 4 Example diagram of the propagation of the mixed differential pattern for bit-level AND operations;
[0071] Figure 5 Flowchart of the method for obtaining a high-probability mixed differential distinguisher for a block cipher with bits as basic operation elements according to the present invention;
[0072] Figure 6 Propagation diagram of one round of the mixed differential pattern in the 6-round mixed differential distinguisher of SIMON64. Detailed implementation manners
[0073] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the following takes examples with reference to the accompanying drawings and further elaborates on the present invention in detail.
[0074] See Figure 5 As shown, a method for searching a mixed differential bit-level distinguisher proposed by the present invention includes the following steps.
[0075] Step 1: Introduce mixed differential pattern variables for the left input bits and right input bits of each round in a block cipher that uses bit-level shift and bit-level XOR operations as linear operations and bit-level AND operation as a non-linear operation, as well as the output bits after XOR operation and AND operation, and introduce probability variables for each of the AND operations.
[0076] Step 2: For each of the non-linear AND operations, analyze the restrictions on the propagation from the input mixed differential pattern to the output mixed differential pattern, and assign the restrictions to the mixed differential variables of each input bit and each output bit of each AND operation and the probability variable of each AND operation with the goal of minimizing the sum of the probability variables of all AND operations in the block cipher. At the same time, add the restrictions distinguishable from a random permutation to establish a Boolean satisfiability problem.
[0077] Step 3: Solve the Boolean satisfiability problem to obtain a mixed differential distinguisher for a lightweight block cipher.
[0078] The following combinesFigure 1 , Figure 5 , Figure 6 , the present method will be further described.
[0079] Step 1: Introduce mixed differential mode variables to the left N-bit input and right N-bit input of each round in a block cipher that uses bit-level shift operations and XOR operations as basic linear operations, introduce mixed differential mode variables to the output bits that go through XOR operations and AND operations, and introduce probability variables to each of the AND operations.
[0080] Among them, the block length of the lightweight block cipher under discussion is 2N bits, adopts the Feistel structure, is divided into a left N-bit input and a right N-bit input in each round, and the block cipher has a total of R rounds, with multiple linear operations in each round; among them, both N and R are positive integers.
[0081] As Figure 1 shown, it is a schematic diagram of the block cipher round function that uses bit-level shift and XOR operations as linear operations and AND operations as basic non-linear operations provided by Step 1. Figure 1 In the block cipher shown, N can take various values such as 16, 32, 64, etc. Here, the case of N = 32 is taken, that is Figure 1 shown is a block cipher with a block length of 64 (2N) bits that uses bit-level shift and XOR operations as linear operations and AND operations as basic non-linear operations. The following will, in combination with Figure 1 , Figure 5 and Figure 6 shown embodiments, describe each step of the present invention in detail.
[0082] Figure 6 In the block cipher of the example shown, R = 6, that is, there are a total of 6 rounds, and each round has three steps of operations. Refer to Figure 1 and the introduction in the background art, that is:
[0083] (1) Basic linear shift and XOR operations;
[0084] (2) Non-linear bit AND operation;
[0085] (3) Round key XOR and Feistel left-right swap.
[0086] In each round, N = 32, that is, the left input bits and the right input bits in each round are both 32 bits. For the left 32-bit input.
[0087] After the operation (3) of each round, it enters the operation (1) of the next round, that is, the plaintext bits on the left and right sides of the Feistel structure pass through Figure 1Encrypt using the block cipher shown. After the operation (3) in the first round, enter the operation (1) in the second round. After the operation (3) in the second round, enter the operation (1) in the third round. After the operation (3) in the third round, enter the operation (1) in the fourth round, and so on for multiple rounds of encryption. Consider the propagation and probability of the mixed differential pattern formed by special plaintexts among them.
[0088] As Figure 1 shown, the basic linear operations in each round include bit shift operations on the left - hand input bits, i.e., S 1 , S 2 , S 8 and bit XOR operations. The bit shift is a cyclic left shift of the N bits of the left - hand input, and the superscript represents the number of shift bits. In each round, the bit XOR operation mainly includes the XOR operation with the N bits of the right - hand input, the XOR operation with the cyclic left shift S 2 of the N bits of the left - hand input, and the round key XOR.
[0089] See Figure 1 , Figure 6 shown. In the block cipher, to search for a 6 - round mixed differential distinguisher, perform the following steps. Figure 6 Specifically shows the propagation of the mixed differential pattern of each bit in one round:
[0090] Step 1: Define the mixed differential pattern variables on the bits in each round as follows:
[0091] Input pattern:
[0092]
[0093] Output pattern of the first round:
[0094]
[0095] Output pattern of the second round:
[0096]
[0097] Output pattern of the sixth round:
[0098]
[0099] Define the mixed differential pattern variables of the intermediate state after the non - linear AND operation in each round as follows: Intermediate pattern of the first round:
[0100]
[0101] Intermediate pattern of the second round:
[0102]
[0103] The intermediate mode of the 3rd round:
[0104]
[0105] The intermediate mode of the 6th round:
[0106]
[0107] Define the mixed differential mode variables of the intermediate state after the XOR operation in each round as follows:
[0108] The intermediate mode of the 1st round:
[0109]
[0110] The intermediate mode of the 2nd round:
[0111]
[0112] The intermediate mode of the 3rd round:
[0113]
[0114] The intermediate mode of the 6th round:
[0115]
[0116] Define the probability variables of each non - linear AND operation in each round as follows, where corresponding probability variables are introduced for each bit:
[0117] The 1st round:
[0118] The 2nd round:
[0119] The 3rd round:
[0120] …
[0121] The 6th round: Among them, represents the probability variable in the propagation of the mixed differential mode in the AND operation on the i - th bit in the r - th round.
[0122] Step 2: Perform the linear XOR operation and the non - linear AND operation on the i - th bit in the r - th round.
[0123] Introduce the following inequality constraints:
[0124] For each of the non - linear AND operations, analyze the limitations of the propagation from the input mixed - differential pattern to the output mixed - differential pattern, and add CNF constraints to the mixed - differential variables and probability variables of each AND operation with the goal of minimizing the sum of the probability variables of all AND operations in the block cipher. Also, add constraint limitations that are distinguishable from random permutations. For each of the XOR operations, introduce corresponding CNF constraints, and finally establish a Boolean satisfiability problem.
[0125] A. For non - linear AND operations
[0126] Take the CNF constraints on the AND operation of all bits in the r - th round as an example:
[0127] In the r - th round, for the i - th bit (using the aforementioned CNF constraints for AND operations):
[0128] Let After determining the specified input - output operation variables of a single - bit - level AND operation, introduce the CNF constraints corresponding to the AND operation (as shown below), and use the corresponding CNF constraints.
[0130] (c2 + c1 + c0 + d2 + d1 + d0 + pl′)(c2 + d2 + e2′)(c1 + d1 + e1′)(c0 + d0 + e0′)(c 2′ + c1 + c0′ + e2 + e1′ + e0′)(c2′ + c1′ + c0 + e2 + e1′ + e0′)(d′2 + de1 + d′0 + e2 + e1′ + e0′)……(c2 + c0 + d2 + d0 + ph′)(c2 + c1 + d2 + d1 + ph′)
[0131] Among them, the range of r is [0, R - 1]. For all cases and their distributions of the mixed - differential pattern of bits after AND operation, see Figure 4 .
[0132] For the probability variables of obtaining this mixed - differential output pattern in the AND operation and under random permutation, let the sum of the probability variables be less than a set specified boundary value, that is, satisfying the sum of multiple Boolean variables less than a constant. The cardinality constraint can be transformed into the CNF form of specified Boolean variables through a coding method based on a sequential counter. By adding the generated CNF constraints to the model, it can be ensured that the sum of probabilities satisfies the objective function (where p h and p l are probability variables, and W is the specified probability boundary):
[0133] ∑(2p h + p l ) < w
[0134] B. Regarding other linear shift operations and XOR operations
[0135] For the linear basic operation of bit shift, it does not affect the mixed differential pattern on the overall N bits, only changes the arrangement of the mixed differential patterns on different bits, and does not introduce new probability variables. Therefore, for the pattern propagation and probability distribution of the mixed differential pattern, the bit-level shift operation does not affect the probability calculation. For the remaining linear operations such as the XOR operation, which includes the XOR on the intermediate state, a definite output bit mixed differential pattern is generated with a probability of 1 during propagation. By adding constraints on the propagation of the mixed differential pattern for the XOR operation on a single bit, the specified pattern propagation can be achieved. Without loss of generality, c i and d i represent the input encoding variables, and e i represents the output encoding variable. The specific constraints are as follows:
[0136] (c0′ + d0′ + e0′)(c0 + d0 + e0′)(c1′ + d1′ + e1′)(c1 + d1 + e1′)(c2′ + d2′ + e2′)(c2 + d2 + e2′)(c0 + d0′ + e0)(c1 + d1′ + e1)(c2 + d2′ + e2)(c0′ + d0 + e0)(c1′ + d1 + e1)(c2′ + d2 + e2)
[0137] So far, aiming to minimize the sum of the probability variables introduced by the AND operation of all bits in the block cipher, the input mixed differential pattern encoding variables, output mixed differential pattern encoding variables, and the introduced probability variables of each operation in each round are given the above CNF constraint restrictions, and a Boolean satisfiability problem is established.
[0138] Step 3: Solve the Boolean satisfiability problem obtained in Step 2 to obtain the values of all variables, obtain the mixed differential distinguisher, and its corresponding probability.
[0139] In this example, taking a certain round in a 6-round distinguisher searched as an example, as Figure 6 shown, the results are as follows:
[0140] The mixed differential pattern of the left N-bit input is: the pattern is "010" on the 20th bit
[0141] The mixed differential pattern of the right N-bit input is: the pattern is "010" on the 18th bit
[0142] The intermediate state is: the left N-bit input passes through S 1 , S 2 , S 8; Obtain the mixed differential patterns on each bit after shifting, where for the two parts of bits shifted left by one bit and eight bits, a non-linear AND operation will result in a change in probability. For example, Figure 6 For the AND operation of the red-highlighted and blue-highlighted bits, the probability that the pattern "010" and the pattern "000" result in the pattern "000" after the AND operation is 2 -1 .
[0143] Therefore, in this round, the probability is 2 -2 , and the analysis method for other rounds is similar.
[0144] Step 3: Solve the above Boolean satisfiability problem to obtain a high-probability mixed differential distinguisher that is different from a random permutation.
[0145] Regarding the Boolean satisfiability problem, that is, to determine whether a propositional formula is satisfiable under the premise of satisfying all given CNF constraints, that is, whether the variables of the formula can be set to 1 (True, true) or 0 (False, false) to determine whether the propositional formula has a satisfiable assignment (SAT, 1) or no satisfiable assignment (UNSAT, 0). Common tools for solving this problem include cryptominisat, etc.
[0146] It should be noted that solving the Boolean satisfiability problem is a prior art in this field.
[0147] The method of the present invention introduces mixed differential pattern variables for each bit in a block cipher that uses bit-level shifting and XOR operations as basic linear operations, and introduces probability variables for non-linear bit-level AND operations; for each of the AND operations, analyze the restrictions on the propagation of the input bit mixed differential pattern to the output bit mixed differential pattern, and assign the restrictions to the mixed differential variables and probability variables of each input bit and each output bit of the non-linear AND operation on each bit with the goal of minimizing the sum of the probability variables of all non-linear AND operations in the block cipher. For the XOR operation, add the corresponding restrictions on the propagation of the mixed differential pattern, and at the same time add the restrictions distinguishable from a random permutation to establish a Boolean satisfiability problem; solve the Boolean satisfiability problem to obtain the mixed differential distinguisher pattern. The present invention provides an automated method for obtaining a mixed differential distinguisher, which can perform security evaluation of bit-level lightweight block ciphers against mixed differential analysis, filling the gap in the automated security evaluation of bit-level block ciphers against mixed differential analysis.
[0148] The above are only the preferred examples of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A hybrid differential bit-level discriminator search method, characterized in that, Comprising the following steps: Step 1: For the left and right input bits in each round of a block cipher that uses bit shift and bit XOR as basic linear operations, introduce mixed differential mode coding variables, introduce probability variables for the non-linear AND operation in each round, and at the same time introduce new mixed differential mode coding variables for the bits after the non-linear operation; Among them, all variables are binary variables, that is, the values are 0 or 1; Step 2: For the bit shift operation in the encryption process, there is no need to generate new coding variables. Change the subscript of the mixed differential mode coding variables to implement the shift operation; For the bit-level XOR operation in the basic linear operation, aiming at minimizing the sum of the probability variables of the non-linear AND operation on all bits in all rounds of the block cipher, impose restrictions on the mixed differential coding variables of all input bits, output bit mixed differential coding variables, bit mixed differential mode variables after AND and XOR operations, and probability variables in each round, and establish a Boolean satisfiability problem; Step 3: Obtain a mixed differential distinguisher by solving the Boolean satisfiability problem; The block length of the bit-level block cipher is 2N bits; the block cipher has a total of R rounds, and each round of the block is divided into a left input of N bits and a right input of N bits; the linear operation in each round of the block cipher consists of three bit-level shift operations and two bit XOR operations, and the non-linear operation is a bit-level AND operation; In a block cipher, the mixed differential pattern encoding variable introduced at any bit position of the left input of N bits in the r-th round is denoted as L represents the left input of the bit-level block cipher, and the mixed differential pattern encoding variable introduced at any bit position of the right input of N bits is denoted as where c is the abbreviation of code, i ∈ [1, N], r ∈ [0, R - 1], and both N and R are positive integers; For the case where the output bits after the linear XOR operation are used as intermediate states, a mixed differential mode coding variable on the intermediate states is introduced. For \(i\in[1,N]\) and \(r\in[0,R - 1]\), aftXOR represents the output bits after the XOR operation. For the case where the output bit after the non-linear AND operation is used as an intermediate state, a hybrid differential mode coding variable on the intermediate state is introduced. i ∈ [1, N], r ∈ [0, R - 1]; aftAND represents the output bit after the AND operation. In a block cipher, the probability variable introduced by any non-linear AND operation that may cause a change in the mixed differential pattern is represented as i ∈ [1, N], where p represents the probability variable of the bit after the non-linear operation, and p h represents the high-order bit of the probability variable, and p l represents the low-order bit of the probability variable. N is a positive integer representing the number of input bits on one side of the block, and r ∈ [0, R - 1]; The limitations include: for the non-linear AND operation corresponding to the mixed differential mode variable and the mixed differential probability variable, without loss of generality, the two input mixed differential mode variables for the non-linear AND operation are respectively denoted as and where i-k is a mod N operation, k is the number of shift bits for bit shift, and the output mixed differential mode variable is denoted as The probability variable is denoted as where, respectively represent the mixed differential mode encodings of the input bits on both sides of the AND operation, represents the mixed differential mode encoding of the bit output after the AND operation; For the mixed differential propagation mode of the AND operation, add the corresponding CNF conjunctive normal form constraints to ensure that the propagation of the mixed differential mode on the bits proceeds according to the specified rules, specifically including: Restrict the propagation of the mixed differential pattern on the input and output bits of the AND operation using CNF constraints; each disjunctive clause in the CNF constraint can add the corresponding constraint to the SAT solver by adding a constraint clause, where c′2 represents the negation of c2, and the rest is similar; e is used to simply replace aftAND; For the mixed differential propagation mode of the XOR operation, corresponding CNF constraints also need to be added to ensure that the propagation of the mixed differential mode on the bits after the linear XOR operation proceeds according to the specified rules; To distinguish the mixed differential distinguisher from a random permutation, take the sum of the probability variables of the output mode obtained under the random permutation as the upper bound of the sum of the mixed differential distinguisher probability variables of the block cipher: For the output mixed differential mode of the random permutation, there are 8 propagation cases for each bit, represented in a ternary code pattern: 000, 111, 100, 010, 001, 011, 101, 110; restrict the sum of the probability variables corresponding to the input mixed difference to the output mixed difference of the block cipher to be less than the sum of the probability variables under the random permutation: ∑(2ph + pl) < 6N′, where N′ is the length of one side of the input of the block cipher.
2. The hybrid differential bit-level discriminator search method according to claim 1, characterized in that In Step 3, set as follows: If or it indicates that the hybrid differential legend represented by the input bit is and the hybrid differential mode is "aaaa"; If or it indicates that the hybrid differential mode represented by the input bit is The hybrid differential mode is "bbba"; If it indicates that the mixed difference example represented by the intermediate state bits after the XOR operation is the mixed difference pattern is "aaaa"; If it means that the mixed difference legend represented by the intermediate state bits after the XOR operation is the mixed difference pattern is "bbba"; If it means that the mixed difference legend represented by the intermediate state bits after the AND operation is the mixed difference pattern is "aaaa"; If it indicates that the legend of the mixed difference pattern represented by the intermediate state bits after the AND operation is the mixed difference pattern is "bbba"; Among them, the value range of i is an integer from 1 to N, and the value range of r is an integer from 0 to R - 1. Use ternary code to represent the mixed differential mode of each bit in the encryption process.
3. The method for searching a hybrid differential bit-level differentiator according to claim 1, characterized in that In step 3, the probability of pattern change caused by the AND operation on a single bit is where: If it means that the probability that the input mixed differential mode obtains the output mixed differential mode after the AND operation is 1; If it means that the probability that the input mixed difference pattern obtains the output mixed difference pattern after the AND operation is 2 -1 ; If it means that the probability that the input mixed difference pattern obtains the output mixed difference pattern after the AND operation is 2 -2 ; If it means that the probability that the input mixed difference mode obtains the output mixed difference mode after the AND operation is 2 -3 ; Among them, the value range of i is an integer from 1 to N, and the value range of r is an integer from 0 to R - 1.
4. A hybrid differential bit-level discriminator search method according to claim 1, characterized in that In Step 3, enumerate the feasible propagation modes and corresponding probabilities of the AND operation of the mixed differential mode to generate a mixed differential mode propagation table under the non-linear AND operation. The rules are as follows: The probability that "000”^"000” → "000” is 1, and the variable value is (000 000 000 00); The probability of "000”^"111”→"111” is 2 -1 , and the variable values are (000 111 111 01); The probability of "110”^"011”→"100” is 2 -2 , and the variable values are (110 011 100 10); The probability that "110”^"101”→"111” is 2 -2 , and the variable values are (110 101 111 10).