Block cipher intelligent linear attack method and system based on quantum soil moisture preservation sampling

The training samples are generated through quantum moisture-retaining sampling and combined with deep learning networks, the problem of misjudgment caused by the training data form in packet cipher attacks by intelligent linear differentiators is solved, and the success rate and calculation speed of multi-bit key recovery attacks are improved.

CN120389854APending Publication Date: 2025-07-29Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510461619.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

The existing intelligent linear differentiator trains data form in packet cipher attacks, causing misjudgment, making it difficult to effectively learn linear features, and the multi-bit key recovery attack conditions are limited, so it cannot be applied to actual attacks.

Method used

The training samples are generated by quantum moisture conservation sampling method, the sampling sequence is generated through qubit operations, and the training sample set is constructed, the password is recovered using an intelligent linear differentiator, and the training is combined with a deep learning network for training.

Benefits of technology

The calculation speed and training accuracy are improved, the sampling sample distribution is closer to the real distribution, and the success rate of multi-bit key recovery attacks is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389854A_ABST
    Figure CN120389854A_ABST
Patent Text Reader

Abstract

The invention relates to a block cipher intelligent linear attack method and system based on quantum soil moisture preservation sampling, specifically, a master key is randomly generated, quantum bits with the length of K are generated, and the initialization state of the quantum bits is 0gt; a state; generating a sampling sequence with the length of N according to the master key and a quantum bit sampling quantum soil moisture conservation mode, and constructing a training sample set; wherein N is a positive integer; and training the intelligent linear discriminator by using the training sample set, and recovering the password by using the trained intelligent linear discriminator. Quantum soil moisture preservation sampling is utilized, so that sampling sample distribution is closer to real sample distribution, and the training accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and specifically to a method and system for intelligent linear attack of block cipher based on quantum moisture conservation sampling. Background Art

[0002] The intelligent differential distinguisher proposed by Gohr at the 2019 Crypto conference has greatly promoted the research of intelligent differential attack. However, as another important method for block cipher analysis, the research progress of combining linear attack with deep learning lags far behind that of differential attack. In 2020, Hou Baitao et al. first used an intelligent linear distinguisher to perform a linear attack on DES, but their single-bit key recovery attack did not achieve better results than traditional linear attacks, and the multi-bit key recovery attack experiment also had conditional limitations and could not be applied to actual attacks. Summary of the Invention

[0003] In view of the above problems, in the first aspect of the present invention, a method for intelligent linear attack of block cipher based on quantum moisture conservation sampling is provided, and the method includes:

[0004] Randomly generate a master key and generate quantum bits of length K, and the initial state of the quantum bits is all in the |0> state; where K is a positive integer.

[0005] According to the master key and the quantum bits, sample the quantum moisture conservation method to generate a sampling sequence of length N, and construct a training sample set; where N is a positive integer.

[0006] Use the training sample set to train the intelligent linear distinguisher, and use the trained intelligent linear distinguisher to recover the cipher.

[0007] Preferably, the step of generating a sampling sequence of length N according to the master key and the quantum bits by sampling the quantum moisture conservation method is specifically:

[0008] Obtain a linear relationship according to the master key.

[0009] Perform Hadamard transformation on the first K-1 quantum bits to obtain a superposition state.

[0010] Encode the plaintext bits in the linear relationship onto the Kth quantum bit using a CNOT gate.

[0011] Use the unitary transformation U SIMECK;(K;1) To obtain the ciphertext corresponding to the superposition state.

[0012] Encode the ciphertext bits in the linear relationship onto the Kth quantum bit using a CNOT gate.

[0013] Discard the first K-1 quantum bits, and measure the last quantum bit N times to obtain a sampling sequence of length N.

[0014] Preferably, the unitary transformation U SIMECK;(K;1) has a quantum circuit as follows:

[0015] The initial state |ψ0> is K qubits q K;1 , …, q0, which are used to store the K-bit state of the algorithm, where q K;1 , …, q K / 2 is used to store the high-order bit positions q K / 2;1 , …, q0 are used to store the low-order bit positions

[0016] For each round of encryption of SIMECK, perform the following operations:

[0017] Traverse all non-zero bit positions of K r , and apply the X gate to the corresponding bits of .

[0018] Use the CNOT gate, with the bits after circularly shifting a bits to the left as the control bits, to control the corresponding bits of .

[0019] Use the Toffoli gate, with and its corresponding bits after circularly shifting b bits to the left as the control bits, to act on the bits of

[0020] Use the Swap gate to swap the states of q K;1 , …, q K / 2 and q K / 2;1 , …, q0.

[0021] Among them, K is an even number, a is the first circular left shift bit number, and b is the second circular left shift bit number.

[0022] Preferably, the training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label.

[0023] Preferably, the intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2 where the activation function uses the Sigmoid function, the remaining layers all use the ReLU function.

[0024] In the second aspect of the present invention, there is provided an intelligent linear attack system for block ciphers based on quantum moisture-preserving sampling, and the system includes:

[0025] Initialization module, randomly generate a master key, and generate qubits of length K, and the initialization state of the qubits is all in the |0> state; where K is a positive integer.

[0026] Training sample construction module, which is used to generate a sampling sequence of length N according to the master key and the quantum bit sampling quantum moisture preservation method, and construct a training sample set; where N is a positive integer.

[0027] Training and attack module, which is used to train the intelligent linear discriminator using the training sample set, and recover the password using the trained intelligent linear discriminator.

[0028] Preferably, the generating a sampling sequence of length N according to the master key and the quantum bit sampling quantum moisture preservation method is specifically:

[0029] Obtain a linear relationship according to the master key.

[0030] Perform Hadamard transformation on the first K - 1 qubits to obtain a superposition state.

[0031] Encode the plaintext bits in the linear relationship onto the K-th qubit using the CNOT gate.

[0032] Use the unitary transformation U SIMECK;(K;1) To obtain the ciphertext corresponding to the superposition state.

[0033] Encode the ciphertext bits in the linear relationship onto the K-th qubit using the CNOT gate.

[0034] Discard the first K - 1 qubits, and measure the last qubit N times to obtain a sampling sequence of length N.

[0035] Preferably, the quantum circuit of the unitary transformation U SIMECK;(K;1) is:

[0036] The initial state |ψ0> is K qubits q K;1 ,…,q0, which are used to store the K-bit state of the algorithm, where q K;1 ,…,q K / 2 is used to store the high-order bit positions q K / 2;1 ,…,q0 are used to store the low-order bit positions

[0037] For each round of encryption of SIMECK, perform the following operations:

[0038] Traverse all non-zero bit positions of K r , and apply the X gate to the corresponding bits of .

[0039] Use the CNOT gate, with The bits after circularly shifting left by a bits are used as control bits to control the corresponding bits.

[0040] Using the Toffoli gate, and its corresponding bits after circularly shifting left by b bits are used as control bits and act on the bits.

[0041] Using the Swap gate to swap the states of q K;1 , …, q K / 2 and q K / 2;1 , …, q0.

[0042] Where K is an even number, a is the first circular left shift bit number, and b is the second circular left shift bit number.

[0043] Preferably, the training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label.

[0044] Preferably, the intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2, the activation function uses the Sigmoid function, and the rest of the layers use the ReLU function.

[0045] The new data sampling method proposed by the present invention - the quantum moisture conservation sampling method - is applied to the 5-round SIMECK-16 intelligent linear discriminator. Its advantages are as follows: First, it improves the calculation speed - using measurement and control technology, only one SIMECK encryption algorithm and N measurements are required to obtain the XOR values of the relevant bits of N plaintext-ciphertext pairs under the same key; Second, it improves the training accuracy from 0.53 to 0.65. Using quantum moisture conservation sampling makes the sampling sample distribution closer to the real sample distribution, thus improving the training accuracy. Description of the Drawings

[0046] Figure 1 is the quantum circuit diagram of the CNOT gate;

[0047] Figure 2 is the quantum circuit diagram of the Swap gate;

[0048] Figure 3 is the quantum circuit diagram of the Toffoli gate;

[0049] Figure 4 is the flowchart of Embodiment 1;

[0050] Figure 5 is the schematic diagram of the discriminator network structure;

[0051] Figure 6Schematic diagram of the discriminator accuracy varying with the epoch for different Ns;

[0052] Figure 7 Quantum circuit diagram for one-round encryption of SIMECK-16;

[0053] Figure 8 Quantum soil moisture conservation sampling algorithm circuit diagram. Specific implementation manners

[0054] In the embodiments of the present invention, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner for easy understanding.

[0055] It can be understood that the "embodiments" mentioned throughout the specification mean that specific features, structures, or characteristics related to the embodiments are included in at least one embodiment of the present application. Therefore, the various embodiments throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures, or characteristics can be combined in one or more embodiments in any suitable manner. It can be understood that in the various embodiments of the present application, the magnitude of the serial numbers of the various processes does not mean the order of execution, and the execution order of the various processes should be determined according to their functions and internal logics, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0056] In the present invention, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of the present invention, as well as in each implementation manner / implementation method / realization method in each embodiment, if there is no special specification and logical conflict, the terms and / or descriptions between different embodiments, as well as between each implementation manner / implementation method / realization method in each embodiment, are consistent and can be referred to each other, and the technical features in different embodiments, as well as in each implementation manner / implementation method / realization method in each embodiment, can be combined to form new embodiments, implementation manners, implementation methods, or realization methods according to their internal logical relationships. The implementation manners of the present application described below do not constitute a limitation to the protection scope of the present application. It should be noted that the implementation of the present invention needs to be within the scope permitted by laws and regulations.

[0057] Shannon's classical information theory is based on 0-1 bits. Similarly, in quantum information theory, the information stored is qubits. The state of a classical bit is either 0 or 1, while the state of a qubit is a vector in a complex space. The basic state of a single qubit is a two-dimensional complex space A set of orthonormal bases, usually denoted in Dirac notation as |0> and |1>:

[0058]

[0059] Due to the property of superposition states that qubits possess in the physical world, in addition to the above two computational basis states, a qubit can be in an infinite number of states |ψ> in a two-dimensional vector space. |ψ> is a superposition state of these two basis states, which can be expressed in mathematical terms as a linear combination: |ψ> = α|0> + β|1>, where are called amplitudes, and according to physical properties, they satisfy the normalization condition: |α| 2 + |β| 2 = 1.

[0060] The advantages of quantum computing are more prominent in multi-qubit systems. In a system composed of two qubits, there are four standard bases: |00>, |01>, |10>, |11>. Similarly, n qubits correspond to a 2 n dimensional complex space For two n-dimensional quantum states |x> = [x1, x2, …, x n T , |y> = [y1, y2, …, y n T , define addition: |x> + |y> = [x1 + y1, x2 + y2, …, x n + y n T , define the dot product: a|x> = [ax1, ax2, … ax n T , define the tensor product: where can be abbreviated as |x>|y> or |xy>.

[0061] Similar to the logic gates used in classical computers - AND, OR, NOT, quantum computing is also composed of quantum logic gates, which are used to manipulate the state changes of qubits. Described in mathematical terms, it can be represented as a reversible matrix U, and it satisfies UU H = I. Therefore, these quantum gates can also be called unitary transformations. The simplest quantum logic gates used in this article are the X gate, Hadamard gate, CNOT gate, and Toffoli gate.

[0062] The X gate is equivalent to the NOT gate in classical gate circuits and acts on a single qubit: |0> → |1>, |1> → |0>:

[0063] ​​​​The Hadamard gate acts on a single qubit, but can transform the basis states: |0> or |1> into a superposition state: or In matrix form, it is represented as:

[0064] The CNOT gate is a two-qubit gate, equivalent to the XOR operation in classical gate circuits. If the first qubit is |0>, the second qubit remains unchanged; if the first qubit is |1>, the second qubit is inverted. It is represented in matrix form as follows: The quantum circuit of the CNOT gate is as Figure 1 shown.

[0065] The function of the Swap gate is to exchange the states of two qubits. For example, it changes |01> to |10>. In matrix form, it is represented as: The quantum circuit of the Swap gate is as Figure 2 shown.

[0066] The Toffoli gate is a three-qubit gate, equivalent to performing an AND operation on the first two qubits in classical logic gates. If the result is 0, the state of the third qubit remains unchanged; if the result is 1, the third qubit performs a NOT operation. That is, the first two qubits are control bits, and the third qubit is inverted if and only if the first two bits are both |1>: The quantum circuit of the Toffoli gate is as Figure 3 shown.

[0067] From the above definition of the Hadamard gate, the following proposition can be easily obtained: For a single qubit |x>, the state after being transformed by the Hadamard gate is:

[0068] Measuring the state of a quantum state |ψ> requires using another observation state |α>. The role of |α> is equivalent to a measuring ruler. Usually, the state |α> used for measurement is a set of computational bases in space. The result of the measurement has a certain probability of being the projection of |ψ> on |α>, and the rest of the probability is the projection of |ψ> on the orthogonal state. This probability is the projection length of |ψ> in that direction. For example: For a quantum superposition state |ψ> = α|0> + β|1>, when measuring this qubit with {|0>, |1>}, the result |0> will be measured with probability |α| 2 and the result |1> will be measured with probability |β| 2 After the measurement, this quantum superposition state will collapse to the measured state.

[0069] The existing intelligent differential distinguisher and intelligent linear distinguisher are both binary classifiers. The goal of the present invention is also to apply such a binary intelligent distinguisher to linear attacks. Naturally, the distributions in the two cases of γ·K = 0 and γ·K = 1 in the linear relationship are used as the targets of binary classification. At the same time, according to the supervised learning mode of deep learning, the training data is divided into two parts - the sample X and the corresponding label Y. The form of the training data suitable for the linear distinguisher is discussed below. The form of the training data of the existing intelligent linear distinguisher was proposed by Hou et al.: For the single-bit key recovery attack, the data preprocessing process is briefly described as follows: Assume that r-round linear relationship L is selected.

[0070] Extract the relevant bit positions P[i0], P[i1], …, P[i r and C[j0], C[j1], …, C[j m in a plaintext-ciphertext pair, and concatenate them into a sequence: n P[i0]∥P[i1]∥…∥P[i

[0071] ∥C[j0]∥C[j1]∥…∥C[j m n .

[0072] The training data is shown in Table 1.

[0073] Table 1 Form of the training data of the single-bit linear distinguisher

[0074]

[0075] For the multi-bit key recovery attack, assume that γ·K is known, and select the r-round linear approximation L′ r . Extract the relevant bits of the left half P L , the right half P R , the left half C L , the right half C R , F(P, K1) and F(C, K r ) of these six parts: P L [i0], P L [i1], …, P L [i m , P R [i′0], P R [i′1], …, P R [i′ u , C L [j0], C L [j1], …, C L [j n , C R [j0′], CR [j1′], …, C R [j v ′], F(P, K1)[k0], …, F(P, K1)[k s , and F(C, K r )[l0], …, F(C, K r )[l t For a sample data with label 1, these values need to be concatenated, and at the same time, the lengths of these six parts should be ensured to be the same. If there is a missing part, fill 0 at the end. In addition, for the sample with label 0, the first two parts are the same, but the last two parts are replaced with random data, and the sample lengths are the same, as shown in Table 2.

[0076] Table 2 Training data form of multi-bit linear distinguisher

[0077]

[0078]

[0079] The above two training data forms have the following characteristics: 1. One sample data only contains one plaintext-ciphertext pair information; 2. After extracting the relevant bit positions, they are directly concatenated. The directly concatenated training data form is similar to the training data of Gohr's intelligent differential distinguisher, and the training objectives are also similar - both are to determine whether the sample belongs to the target distribution. The target distribution of the intelligent differential distinguisher is an output differential distribution corresponding to an input differential, which is a multinomial distribution. From A and B in Gohr's experiment, it can be seen that the main basis for Gohr's distinguisher to make a judgment is the occurrence probability of the output differential (in the last round, the penultimate round, and the third-to-last round) in the entire space - The greater the output differential probability, the higher the score of the distinguisher, and the more likely it is to be judged as a true ciphertext pair; conversely, the probability of some output differentials is even 0.

[0080] However, the target distribution of the intelligent linear distinguisher is a binomial distribution. The reasons for the misjudgment of the distinguisher using such a data form are: 1. The distinguisher needs to learn the linear features of the sample data, that is, it needs to perform exclusive OR operations on the concatenated bit positions, and the features are relatively implicit, making it difficult to learn; 2. In the binomial distribution, there are only two cases, and the corresponding probabilities are p L and 1 - p L , and the difference is not significant. Moreover, the linear feature contained in one sample is only 1-bit value on F2; 3. Filling 0 for the missing part in Table 1.2 will become interference information for the distinguisher to learn. In addition, the prerequisite for adopting the training data form in Table 2 is that γ·K is known and fixed, which is also a condition difficult to achieve in actual attacks.

[0081] To verify the first reason for the misjudgment of the distinguisher, the present invention designs an experiment to verify whether the intelligent distinguisher can directly learn the linear relationship in the sample data in cascade form. Experiments a and b as shown in Table 3: The sample is a binary sequence of N bits in length, the lower bits are randomly generated, and the highest bit value is the exclusive OR value (or the inverse of the exclusive OR value) of the selected bit positions. If the intelligent distinguisher can distinguish, it indicates that the distinguisher can learn the exclusive OR operation between the bit positions of the training data.

[0082] Table 3 Two data forms of Experiments a and b

[0083]

[0084] The accuracy rate given in Table 3 is the average value of multiple experiments. In fact, multiple experiments have been carried out by changing variables such as the length N of the sample and the selected bit positions. The accuracy rate of the distinguisher has not exceeded 0.6, indicating that it is indeed very difficult for the distinguisher to learn the linear relationship inside the samples in cascade form.

[0085] Figure 4 The flowchart of the first embodiment of the present invention is shown, as Figure 4 shown, a group cipher intelligent linear attack method based on quantum entropy-preserving sampling, the method comprising:

[0086] S1, randomly generate a master key and generate quantum bits of length K, and the initial states of the quantum bits are all in the |0> state; where K is a positive integer.

[0087] Use a classical random number generator (RNG) or a cryptographically secure pseudorandom number generator (CSPRNG) or a true random number generator (TRNG) to generate the master key, and then generate quantum bits of length K, that is, generate K quantum bits, and the initial state of each quantum bit is |0〉.

[0088] S2, generate a sampling sequence of length N according to the master key and the quantum bits by sampling the quantum entropy-preserving method, and construct a training sample set; where N is a positive integer.

[0089] Use the information of the master key to control a series of quantum gate operations on the K quantum bits, and the operations include but are not limited to single-bit gates such as Hadamard gates, Pauli gates, rotation gates, and multi-bit gates such as CNOT gates. In one embodiment, the generating a sampling sequence of length N according to the master key and the quantum bits by sampling the quantum entropy-preserving method specifically is:

[0090] Obtain a linear relationship formula according to the master key.

[0091] Perform Hadamard transformation on the first K-1 quantum bits to obtain a superposition state.

[0092] Encode the plaintext bits in the linear relation to the \(K\) -th qubit using CNOT gates.

[0093] Use the unitary transformation \(U\) SIMECK;(K;1) Obtain the ciphertext corresponding to the superposition state.

[0094] Encode the ciphertext bits in the linear relation to the \(K\) -th qubit using CNOT gates.

[0095] Discard the first \(K - 1\) qubits, and measure the last qubit \(N\) times to obtain a sampling sequence of length \(N\).

[0096] Derive a linear relation from the master key. In one embodiment, the linear relation is \(\alpha\cdot P\oplus\beta\cdot C=\gamma\cdot K\), where \(\alpha\) and \(\beta\) are masks for the plaintext \(P\) and ciphertext \(C\), and \(\gamma\cdot K\) is a linear combination of the key \(K\). Initialize \(K\) qubits, with the first \(K - 1\) bits storing partial information of the plaintext \(P\). Apply Hadamard gates to the first \(K - 1\) bits to put them in a uniform superposition state:

[0097] Use the plaintext in the linear relation as the control bit and the \(K\) -th qubit as the target bit, and apply a CNOT gate. Apply the quantum circuit \(U\) of the SIMECK encryption algorithm to the first \(K - 1\) qubits SIMECK;(K;1) , generate the corresponding ciphertext superposition state. Then, use the ciphertext in the linear relation as the control bit and update the \(K\) -th bit with a CNOT gate again. Discard or ignore the first \(K - 1\) bits, and only keep the state of the \(K\) -th bit. Repeat the measurement \(N\) times to obtain a binary sequence \(s_1,s_2,\cdots,s\) N .

[0098] In one embodiment, the quantum circuit of the unitary transformation \(U\) SIMECK;(K;1) is as follows:

[0099] The initial state \(|\psi_0\rangle\) is \(K\) qubits \(q\) K;1 ,\(\cdots,q_0\), which are used to store the \(K\) -bit state of the algorithm, where \(q\) K;1 ,\(\cdots,q\) K / 2 are used to store the high - order bit positions \(q\) K / 2;1 ,\(\cdots,q_0\) are used to store the low - order bit positions

[0100] For each round of encryption of SIMECK, perform the following operations:

[0101] Traverse all non - zero bit positions of \(K\) r and apply an \(X\) gate to the corresponding bits of ; the initial state is Traverse the non - zero bit positions of \(K\) r : for Apply the X gate to the corresponding qubit, e.g., K r = 0010…1, if the 0th and 2nd bits are 1, then apply the X gate to q0 and q2.

[0102] Use the CNOT gate to take the bits after circularly shifting a bits to the left as the control bits to control the corresponding bits; use the CNOT gate with the shifted q j as the control bit and the corresponding bit as the target bit.

[0103] Use the Toffoli gate to take and its corresponding bits after circularly shifting b bits to the left as the control bits and act on the bits.

[0104] Use the Swap gate to swap the states of q K;1 ,…,q K / 2 and q K / 2;1 ,…,q0; use the Swap gate to swap all the qubits of the high bits and the low bits.

[0105] Among them, K is an even number, a is the first circular left shift bit number, and b is the second circular left shift bit number. In one embodiment, both a and b are less than K / 2. Preferably, K = 8, 16, 32 or 64.

[0106] After obtaining the sampling sequence of length N, further construct a training sample set. The training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label. In one embodiment, the sample label is 1 if the sampling sequence is generated in the above manner, otherwise it is 0. In another embodiment, the label is obtained according to γ·K of the linear relationship formula.

[0107] S3. Use the training sample set to train the intelligent linear discriminator, and use the trained intelligent linear discriminator to recover the password.

[0108] Use the generated training sample set to train the intelligent linear discriminator. When recovering the password or the key, input the plaintext-ciphertext pair into the intelligent linear discriminator to obtain the score of γ·K, and use the score to recover the key.

[0109] In one embodiment, the intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2 where the activation function uses the Sigmoid function, the other layers all use the ReLU function.

[0110] Embodiment 2

[0111] For the intelligent linear attack, the present invention places the relevant bitwise XOR operation in the data preprocessing stage: The XOR values of multiple plaintext-ciphertext pairs are concatenated into one piece of data, which increases the amount of information contained in one piece of data. The following is the data preprocessing algorithm given by the present invention:

[0112]

[0113] After the above data preprocessing, the form of the training data obtained is as follows: an N-bit sequence serves as one sample, plus the corresponding 1-bit label, as shown in Table 4. The biggest difference from all previous training data is that one sample contains the information of N plaintext-ciphertext pairs and is a sampling distribution of a binomial distribution. Therefore, it is called distribution data. The training data is all obtained through Algorithm 1 and used to train the distinguisher for key recovery attack.

[0114] Table 4 Distribution Data

[0115]

[0116] Both the intelligent linear distinguisher and the intelligent differential distinguisher adopt the residual network. The main structure of the network used in the present invention remains unchanged. As Figure 5 shown, the residual block is set to loop 10 layers, and the input layer is adjusted according to the training data structure. And the Reshape layer is modified from a 4×16 matrix to an 8-column matrix. Each of the last two Dense layers contains 32 neurons, and the output layer has 1 neuron. The input N-length sequence becomes an (N / 8)×8 matrix through the Reshape layer and finally outputs 1 bit. Except for using the Sigmoid function as the activation function after the last layer Dense2, the ReLU function is used for the rest of the layers.

[0117] Training data is generated according to the linear relations L3, L4, L5, and L6 of 3 rounds, 4 rounds, 5 rounds, and 6 rounds of the DES encryption algorithm. The probabilities of the relations are: P r (L3)=0.7, P r (L4)=0.439, P r (L5)=0.519, P r (L6)=0.4962.

[0118]

[0119]

[0120] The training data is divided into two sets: the training data set and the test data set, and the sizes of the sets are shown in Table 5. Through experiments, it is found that when the number of training epochs is 50 and the batch size is 500, the training convergence speed is the most appropriate. Table 5 compares the accuracies of the discriminators trained in this section and those trained by Hou Bitao on these 4 linear relationships. The accuracy of the discriminator of the present invention is the range of the accuracy values on the test set obtained from 2000 experiments. In addition, taking L3 and L4 as examples, Figure 6 represents the change in accuracy when the sequence length N is different. In Table 5, N is the length of the input sample.

[0121] Table 5 Accuracies of Two Intelligent Linear Discriminators

[0122]

[0123] By adopting the new data preprocessing algorithm, compared with the work of Hou et al., the present invention uses less training data volume, successfully improves the accuracies of the intelligent linear discriminator on the 3-round, 4-round, and 5-round linear relationships, and increases the distinguishable number of rounds by one to 6 rounds. In addition, the accuracy of the discriminator decreases as the probability p L of the relationship decreases. Using the same relationship, the longer the sequence length N, the better the discrimination effect of the discriminator.

[0124] The input length of the trained discriminator is N, so at least N pairs of plaintext-ciphertext pairs are required to perform key recovery. Similar to the data preprocessing process, the XOR value of the relevant bits on the left side of the equation is calculated according to the linear relationship to obtain an N-bit sequence, which is fed into the discriminator to obtain a score Z (0 ≤ Z ≤ 1).

[0125]

[0126] If the number of known plaintext-ciphertext pairs is more than N pairs, Algorithm 2 can be slightly modified: in Step 1, N pairs of plaintext-ciphertext pairs are taken as a group to obtain multiple groups of plaintext-ciphertext pairs and generate multiple sequences S. In Step 2, the multiple sequences obtained in the previous step are fed into the discriminator, and the average value of the obtained scores is taken as the final score Z.

[0127] In the key recovery experiment, plaintext and keys are randomly generated and encrypted to obtain ciphertext. Table 6 shows the comparison of the number of plaintext-ciphertext pairs used and the success rate in single-bit key recovery between the intelligent linear discriminator in the traditional method and the discriminator trained by the present invention. The success rate of the traditional method in the table is the theoretical value, which can be calculated according to the formula. The average success rate given in Table 6 is for 200 experiments. The number of plaintext-ciphertext pairs is represented in the form of "N" × "number of groups".

[0128] Table 6 Single-Bit Key Recovery Attacks on 3-Round, 4-Round, 5-Round, and 6-Round DES

[0129]

[0130]

[0131] In the case of knowing N plaintext-ciphertext pairs (i.e., the number of groups is 1), the success rate of key recovery is slightly smaller than the accuracy rate of the distinguisher trained in the present invention, with a difference of at most no more than 0.02. When the number of known plaintext-ciphertext pairs increases, the success rate of key recovery also rises. Therefore, in the experiments of recovering 5-round and 6-round keys, the present invention does not need to train a new distinguisher, but increases the number of plaintext-ciphertext pairs to improve the success rate of key recovery. In the linear attack on the selected 4 groups of linear relations, the new intelligent linear distinguisher proposed in the present invention not only has a better accuracy rate than the existing distinguishers, but also surpasses them in the success rate of key recovery. In addition, it also surpasses the traditional linear attack method in the 5-round attack.

[0132] Still use the trained distinguisher to perform multi-bit key recovery. Derive the 4-round and 5-round linear approximations L′4 and L′5 from the linear relations L3 and L4, and keep the probability unchanged, that is, Pr(L′4) = Pr(L3), Pr(L′5) = Pr(L4). Their non-linear parts are all F(P R , K1)

[15] , and 6 bit positions of the first-round sub-key K1 are related to it: K1

[42] , K1

[43] , K1

[44] , K1

[45] , K1

[46] , K1

[47] :

[0133]

[0134] From the results of single-bit key recovery, the distinguisher can relatively accurately distinguish two binomial distributions: B(N, p L ) and B(N, 1 - p L ). And the multi-bit linear approximation is obtained by adding one round (or several rounds) on the basis of the single-bit relation, and the probability distribution remains unchanged. Therefore, when performing multi-bit key recovery, the binary classification target of the distinguisher also remains unchanged, so there is no need to redesign a new distinguisher. Moreover, the intelligent linear distinguisher of the present invention learns the binomial distribution.

[0135] Compared with single-bit key recovery, multi-bit key recovery not only needs to recover the rightmost one bit γ·K, but also needs to recover 6 related key bits of the left non-linear part. Therefore, the key recovery algorithm is also divided into two parts.

[0136] When recovering the multi-bit key on the left side of the equation, the distinguisher can accurately binary-classify the distribution corresponding to the correct key, but it cannot well judge the distribution when the key is wrong. Therefore, the greater the deviation between the score of the distinguisher and 0.5, the more likely it is the correct key.

[0137] When recovering γ·K, according to the setting method of the binary classification label, the more the discriminator score biases towards 0, the greater the probability that γ·K is 0; conversely, the more it biases towards 1, the more likely γ·K is also 1.

[0138]

[0139]

[0140]

[0141] In the multi-bit key recovery attack experiment, the number of groups n has a negligible impact on the recovery success rate, which is different from the single-bit key recovery attack. The experiment was repeated 200 times, and the average value of the real key sorting was 30 - slightly higher than random search. Algorithms A and B are used to recover γ·K in different situations. If the relevant bits on the left have been recovered, then Algorithm A is used; Algorithm B can recover γ·K when the relevant bits on the left are unknown, and at the same time, Algorithm 3 is required to give the key sorting.

[0142] Table 7 Multi-bit key recovery attack on 4-round and 5-round DES

[0143]

[0144] The advantages of the intelligent linear discriminator of the present invention in the multi-bit key recovery attack are reflected in the following three aspects: First, the present invention increases the number of distinguishable rounds by one round compared with the method of Hou et al. Second, there is no need to redesign and train a new discriminator, and only one discriminator is used to perform single-bit key recovery and multi-bit key recovery attacks simultaneously. Therefore, the method of the present invention simplifies the attack process and saves space and pre-computation time. Finally, all key sortings and γ·K are obtained successively through Algorithm 3 and Algorithm B, which is a practical attack without any assumptions. Algorithm A helps to prove that the discriminator has the ability to judge γ·K based on the real distribution data. Since the method of Hou et al. has the limitation that γ·K is known, this is the first known practical multi-bit key recovery attack using deep learning.

[0145] After the intelligent linear discriminator is successfully applied to DES, it is continued to be extended and applied to the block cipher SIMECK32 / 64 with the Feistel structure. The selected high-probability linear relations are as follows: P r (L5) = 0.5625, P r (L7) = 0.5039, P r (L8) = 0.5020.

[0146]

[0147] Through experiments, it is found that the number of training epochs required for the neural network of SIMECK32 / 64 to converge is less than that of DES, set to 50, and the batch size is 5000. However, the training data volume is larger: the size of the training dataset is 600,000, and the validation dataset is 10,000.

[0148] Table 8 Training effect of the distinguisher for SIMECK32 / 64

[0149]

[0150] For the 8-round linear relation L8, the accuracy of the trained distinguisher on the training set can reach 0.9, but the accuracy on the test set is only 0.58, which is in an overfitting state. When N is increased to 1024, the test set accuracy increases to 0.63 at the 5th epoch, but it is still in an overfitting state. Generally speaking, the overfitting state is caused by insufficient or unrepresentative training data.

[0151] Generally speaking, applying the intelligent linear distinguisher of DES to SIMECK32 / 64, the experimental phenomena are similar to those of DES, but it reaches overfitting faster. The accuracy of the distinguisher drops directly from 0.97 in 7 rounds to 0.58 in 8 rounds, and it converges faster, reaching convergence after 10 training epochs. This has a great relationship with the fact that the probability of the low-round linear relation (L8) of P r (L8) is lower than that of the low-round linear relation used in the present invention - when the deviation of the linear relation is very small, the training effect of the distinguisher is also very poor.

[0152] When training the intelligent linear distinguisher, for the same linear relation, the longer the length N of the training data, the better the effect of the distinguisher. However, for a trained distinguisher with a fixed length, the number of known plaintext-ciphertext pairs has little effect on the success rate. According to the law of large numbers, the more randomly sampled data, the closer the 0-1 distribution of the sequence is to the true distribution of the linear relation, which is also one of the important factors affecting the data complexity of traditional statistical analysis algorithms. Therefore, the closer the training data is to the true distribution reflected by the linear relation, the better the training effect.

[0153] In order to maintain the advantage of using fewer plaintext-ciphertext pairs for the intelligent distinguisher, it is hoped that without increasing the length of the training data, the sampled sample distribution is closer to the true distribution. Quantum entropy-preserving sampling is used instead of random sampling to train the intelligent linear distinguisher, which is applied to the simplified algorithm SIMECK-16, improving the training accuracy of the distinguisher.

[0154] To improve the intelligent linear distinguisher for SIMECK32 / 64, the quantum soil moisture sampling algorithm is used on SIMECK. In this chapter, the SIMECK-16 quantum circuit is designed on the quantum simulator. Limited by the data width of qubits, the parameter n of the SIMECK encryption algorithm is set to 8, that is, the block length is 16 bits and the key length is 32 bits. This is a simplified SIMECK algorithm, which is called SIMECK-16 here. Therefore, except that the block length of SIMECK-16 is half of that of SIMECK32 / 64, other operations: left circular shift, modulo 2 addition, bitwise AND operation, etc. are the same.

[0155] The specific quantum circuit design is as follows: The initial state |ψ0> is 16 qubits q 15 ,q 14 ,…,q0 for storing the 16-bit state of the algorithm, where q 15 ,…,q8 for storing the high-order (left half) bit positions q7,…,q0 for storing the low-order (right half) bit positions

[0156] In the r-th round of SIMECK encryption, first execute Find the K r non-zero bit positions, and apply an X gate operation to the corresponding bits to obtain the state |ψ1>.

[0157] The second step is to execute Exclusive OR with Using the CNOT gate, q 14 ,…,q8,q 15 as the control bits to correspondingly control q7,…,q0 to obtain the state |ψ2>.

[0158] The third step is to exclusive OR with Using the Toffoli gate, take q 15 ,…,q8 and the q 10 corresponding to q after circular left shift by 5 bits, q9, q8,…,q 11 as the control bits to control q7,…,q0 to obtain the state |ψ3>.

[0159] Finally, swap left and right: Use the Swap gate to swap the state positions of q 15 ,…,q8 and the corresponding q7,…,q0 positions, and the final state is |ψ4>.

[0160] Taking the round key K r =(01101010) as an example, the quantum circuit diagram for the r-th round of encryption of SIMECK-16 is as Figure 7 shown.

[0161] The design of implementing the quantum moisture-preserving sampling algorithm on a quantum simulator requires 17 qubits. The first 16 qubits are used for SIMECK-16 encryption operations, and the last 1 qubit is used for measurement. Prepare the initial state of these 17 qubits as |0>. First, apply the Hadamard transformation to each of the first 16 qubits to obtain a quantum superposition state. Then, through the SIMECK-16 quantum circuit, this quantum circuit is denoted as a unitary transformation U SIMECK;16 .

[0162]

[0163] The above quantum moisture-preserving sampling algorithm uses a quantum circuit as Figure 8 shown.

[0164] In actual execution, for the last step of multiple measurements, measurement and control technology can be used to repeat the measurement multiple times without destroying the quantum state. In this way, the quantum circuit does not need to run multiple times.

[0165] In the encryption function of the SIEMCK algorithm, the non-linear part only has the bitwise AND calculation ⊙. For two single qubits x i and x j , the probability that the equation x i ⊙x j = 0 holds is 3 / 4. Based on this, find the linear approximation relationships for 3 rounds, 4 rounds, and 5 rounds in SIMECK-16, where

[0166]

[0167] Before using the quantum moisture-preserving sampling algorithm, use random sampling to generate data to train the distinguisher.

[0168] Table 9 Training of the SIMECK-16 distinguisher and single-key recovery

[0169]

[0170] The training accuracy of the distinguisher trained according to the same linear relationship will increase as the length N of the training data increases.

[0171] For a 4-round linear relationship with a multi-bias distribution Traverse all keys (at this time, the 4-round round keys are the master keys), and there are exactly two biases for the linear relationship, 0.011719 and 0.003906.

[0172] The plaintext full space of SIMECK-16 is 2 16= 65536, fix the sampling length N as 256, and compare the average deviation of the classical sampling distribution and the quantum entropy-preserving sampling distribution from the distribution on the full space of 65536 under 10000 randomly generated keys, as shown in Table 10:

[0173] Table 10 Comparison of Two Sampling Methods

[0174]

[0175]

[0176] The average deviation shown in Table 10 refers to the average deviation of the proportion of 0s in the sampled data from the proportion of 0s in the true distribution during 10000 samplings. It can be seen that when the amount of sampled data is 256, the sample data of quantum entropy-preserving sampling is closer to the true data distribution than random sampling. When training an intelligent discriminator with the training data generated by the two sampling methods, the accuracy of training with the quantum entropy-preserving sampling method is increased by about 10 percentage points compared to the random sampling method.

[0177] Example 3 provides an intelligent linear attack system for block ciphers based on quantum entropy-preserving sampling. The system includes:

[0178] An initialization module that randomly generates a master key and generates quantum bits of length K, and the initial state of the quantum bits is all in the |0> state; where K is a positive integer.

[0179] A training sample construction module for generating a sampling sequence of length N according to the master key and the quantum bit sampling quantum entropy-preserving method, and constructing a training sample set; where N is a positive integer.

[0180] A training and attack module for training an intelligent linear discriminator using the training sample set and recovering the cipher using the trained intelligent linear discriminator.

[0181] Preferably, generating the sampling sequence of length N according to the master key and the quantum bit sampling quantum entropy-preserving method specifically includes:

[0182] Obtaining a linear relation according to the master key.

[0183] Performing a Hadamard transform on the first K - 1 quantum bits to obtain a superposition state.

[0184] Encoding the plaintext bits in the linear relation onto the Kth quantum bit using a CNOT gate.

[0185] Using the unitary transformation U SIMECK;(K;1) To obtain the ciphertext corresponding to the superposition state.

[0186] Encode the ciphertext bits in the linear relation to the K-th qubit using CNOT gates.

[0187] Discard the first K - 1 qubits, and measure the last qubit N times to obtain a sampling sequence of length N.

[0188] Preferably, the unitary transformation U SIMECK;(K;1) has a quantum circuit as follows:

[0189] The initial state |ψ0> is K qubits q K;1 ,…,q0, which are used to store the K-bit state of the algorithm, where q K;1 ,…,q K / 2 is used to store the high-order bit positions q K / 2;1 ,…,q0 is used to store the low-order bit positions

[0190] For each round of encryption of SIMECK, perform the following operations:

[0191] Traverse all non-zero bit positions of K r , and apply the X gate to the corresponding bits of .

[0192] Use the CNOT gate, with the bits after circularly shifting a bits to the left as the control bits, to control the corresponding bits of .

[0193] Use the Toffoli gate, with and its corresponding bits after circularly shifting b bits to the left as the control bits, to act on the bits of

[0194] Use the Swap gate to swap the states of q K;1 ,…,q K / 2 and q K / 2;1 ,…,q0.

[0195] Where K is an even number, a is the first circular left shift bit number, and b is the second circular left shift bit number.

[0196] Preferably, the training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label.

[0197] Preferably, the intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2 where the activation function uses the Sigmoid function, the other layers all use the ReLU function.

[0198] Embodiment 4 provides a computer terminal, which includes a computer-readable storage medium. A computer program is stored on the storage medium, and when the computer program is executed by a processor, the method described in Embodiment 1 or Embodiment 2 is implemented.

[0199] The above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium accessible by a computer or a data storage device such as a server or data center integrating one or more available media. The available medium may be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

[0200] The steps of the methods or algorithms described in the embodiments of the present application may be directly embedded in hardware, a software unit executed by a processor, or a combination of the two. The software unit may be stored in a RAM memory, a flash memory, a ROM memory, an EPROM memory, an EEPROM memory, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium may be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium may also be integrated into the processor. The processor and the storage medium may be disposed in an ASIC.

[0201] These computer program instructions may also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process or multiple processes and / or one block or multiple blocks. Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0202] Although the present application has been described in connection with specific features and their embodiments, it will be apparent that various modifications and combinations can be made without departing from the spirit and scope of the present application. Accordingly, the present specification and the drawings are merely exemplary illustrations of the present application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A method for intelligent linear attack of block cipher based on quantum moisture-preserving sampling, characterized in that, The method includes: Randomly generate a master key and generate qubits of length K, where the initial state of each qubit is the |0> state; where K is a positive integer; Generate a sampling sequence of length N according to the master key and the qubits by sampling the quantum entropy conservation method, and construct a training sample set; where N is a positive integer; Use the training sample set to train an intelligent linear discriminator, and use the trained intelligent linear discriminator to recover the password.

2. The method according to claim 1, wherein The specific method of generating a sampling sequence of length N according to the master key and the qubits by sampling the quantum entropy conservation method is: Obtain a linear relationship according to the master key; Perform Hadamard transformation on the first K-1 qubits to obtain a superposition state; Encode the plaintext bits in the linear relationship onto the Kth qubit using the CNOT gate; Using the unitary transformation U SIMECK;(K;1) to obtain the ciphertext corresponding to the superposition state; Encode the ciphertext bits in the linear relationship onto the Kth qubit using the CNOT gate; Discard the first K-1 qubits, and measure the last qubit N times to obtain a sampling sequence of length N.

3. The method according to claim 2, wherein The unitary transformation U SIMECK;(K;1) has a quantum circuit as follows: The initial state |ψ0> is K qubits q K;1 , …, q0, which are used to store the K-bit state of the algorithm, where q K;1 , …, q K / 2 is used to store the high-order bit q K / 2;1 , …, q0 are used to store the low-order bit For each round of encryption of SIMECK, perform the following operations: Traverse all non-zero bits of K r , and apply the X gate to the corresponding bits of . Using a CNOT gate, with the bits after circularly shifting left by a bits as the control bits to control the corresponding bits; Using the Toffoli gate, take and the corresponding bits after circularly shifting it left by b bits as the control bits, and apply them to 's bits; Swap the states of q K;1 , …, q K / 2 and q K / 2;1 , …, q0; Where K is an even number, a is the first cyclic left shift bit number, and b is the second cyclic left shift bit number.

4. The method according to claim 1, wherein The training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label.

5. The method according to claim 1, characterized in that, The intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2 where the activation function uses the Sigmoid function, the other layers all use the ReLU function.

6. A block cipher intelligent linear attack system based on quantum moisture-preserving sampling, characterized in that, The system includes: An initialization module that randomly generates a master key and generates qubits of length K, where the initial state of each qubit is the |0> state; where K is a positive integer; A training sample construction module for generating a sampling sequence of length N according to the master key and the qubits by sampling the quantum entropy conservation method, and constructing a training sample set; where N is a positive integer; A training and attack module for using the training sample set to train an intelligent linear discriminator and using the trained intelligent linear discriminator to recover the password.

7. The system according to claim 6, characterized in that, The specific method of generating a sampling sequence of length N according to the master key and the qubits by sampling the quantum entropy conservation method is: Obtain a linear relationship according to the master key; Perform Hadamard transformation on the first K-1 qubits to obtain a superposition state; Encode the plaintext bits in the linear relationship onto the Kth qubit using the CNOT gate; Using the unitary transformation U SIMECK;(K;1) to obtain the ciphertext corresponding to the superposition state; Encode the ciphertext bits in the linear relationship onto the Kth qubit using the CNOT gate; Discard the first K-1 qubits, and measure the last qubit N times to obtain a sampling sequence of length N.

8. The system according to claim 7, wherein The unitary transformation U SIMECK;(K;1) has a quantum circuit as follows: The initial state |ψ0> is K qubits q K;1 ,…, q0, which are used to store the K-bit state of the algorithm, where q K;1 ,…, q K / 2 is used to store the high-order bit q K / 2;1 ,…, q0 are used to store the low-order bit For each round of encryption of SIMECK, perform the following operations: Traverse all non-zero bits of K r , and apply an X gate to the corresponding bits of ; Using a CNOT gate, with the bits after circularly shifting a bits to the left as the control bits to control the corresponding bits; Using a Toffoli gate, take and its corresponding bits after circularly shifting left by b bits as control bits and apply them to 's bits; Swap the states of q K;1 ,…,q K / 2 and q K / 2;1 ,…,q0; Where K is an even number, a is the first cyclic left shift bit number, and b is the second cyclic left shift bit number.

9. The system according to claim 6, wherein The training sample set includes multiple samples, and each sample includes a sampling sequence of length N and a sample label.

10. The system according to claim 6, wherein, The intelligent linear discriminator includes a Reshape layer, a convolutional layer, 10 sequentially connected residual blocks, and 2 sequentially connected Dense layers. The Dense layer contains 32 neurons. Except for the last layer Dense2 where the activation function uses the Sigmoid function, the ReLU function is used in the remaining layers.