RSA public key cracking method based on CRAB quantum algorithm optimization, storage medium and equipment

The RSA public key cracking method is optimized through the CRAB quantum algorithm, and the energy gap of the constrained equation system and time-varying Hamiltonian are maximized, combined with the optimization of the Nelder-Mead algorithm, the problem of RSA public key cracking in traditional methods is solved, and fast and accurate RSA public key cracking is achieved.

CN120498666AActive Publication Date: 2025-08-15NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510626056.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-15
Publication Date
2025-08-15
Estimated Expiration
2045-05-15

AI Technical Summary

Technical Problem

The prior art is difficult to effectively crack the RSA public key in polynomial time, and traditional quantum computing methods are difficult to implement on medium-noise quantum devices, and the parameter optimization dimension is high, making it difficult to converge.

Method used

The CRAB quantum algorithm is used to generate a system of constraint equations by constructing a binary multiplication table, and time-varying Hamiltonian is constructed to maximize the first energy gap. The Nelder-Mead algorithm is used to optimize the time-dependent scheduling function to realize the high-fidelity adiabatic evolution of qubits, reducing the redundant variable requirements and noise sensitivity.

Benefits of technology

It improves the accuracy and noise anti-noise robustness of RSA public key factorization, realizes rapid cracking of RSA public keys, and reduces the qubit requirement and evolution time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498666A_ABST
    Figure CN120498666A_ABST
Patent Text Reader

Abstract

The invention discloses an RSA public key cracking method based on CRAB quantum algorithm optimization, a storage medium and equipment, and the method comprises the steps: carrying out the factorization of a cracked RSA public key modulus, expanding a binary form, generating a constraint equation set through a binary multiplication table, constructing a cost function, generating a problem Hamiltonian, and constructing a time-varying Hamiltonian, the method comprises the following steps: taking maximization of a first energy gap of a time-varying Hamiltonian as a target to adjust a problem Hamiltonian, preparing a ground state of an initial Hamiltonian, obtaining a final state of the Hamiltonian according to the total evolution time of the maximized time-varying Hamiltonian, calculating a final state energy value of the Hamiltonian, and minimizing the final state energy value of the Hamiltonian by adopting a Nelder-Mead algorithm to obtain a final state of the Hamiltonian. And performing z-direction Fouli operator measurement on each quantum bit in the final state of the corresponding Hamiltonian, extracting a binary bit number of factor decomposition, obtaining a decomposed factor in combination with a binary multiplication table, determining a private key in combination with a cracked RSA public key index, and completing RSA public key cracking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of quantum cryptography, and in particular to an RSA public key cracking method, storage medium, and device based on CRAB quantum algorithm optimization. Background Art

[0002] The RSA encryption algorithm is an asymmetric encryption algorithm based on a very simple mathematical fact: it is easy to multiply two prime numbers to get a large number, but it is very difficult to factorize a large number into the product of two prime numbers. The factorization problem is one of the core problems in cracking RSA encryption, and it cannot be solved by classical algorithms in polynomial time. In 1994, Shor proposed a quantum algorithm "Proceedings 35 th annual symposium on foundations of computer science. (Ieee, 1994) pp. 124–134”, its time complexity is exponentially reduced compared to the classical decomposition algorithm; another approach to implementing the decomposition algorithm is adiabatic quantum computing pioneered by Farhi et al. “Science 292, 472 (2001)”, which provides a promising alternative to the traditional quantum computing framework. The adiabatic quantum computing method encodes the solution to the problem in the ground state of the problem Hamiltonian: the system starts from the ground state of an easily prepared initial Hamiltonian and gradually transforms the initial Hamiltonian into the problem Hamiltonian through adiabatic evolution. The adiabatic theorem “Journal of the Physical Society of Japan 5, 435 (1950)” ensures that the system always remains in the ground state, thereby obtaining the solution. Adiabatic quantum computing is essentially related to the preparation of the ground state of quantum many-body systems and has achieved remarkable success in the field of quantum annealing.

[0003] In adiabatic quantum computing, the evolution time is crucial, and a large number of studies are devoted to accelerating this process through adiabatic technology. For example, "Phys. Rev. A 104, L050403 (2021)" adds a counter-diabatic (CD) term to the total Hamiltonian to suppress non-adiabatic transitions, thereby significantly increasing the probability of the system reaching the ground state; and "PRXQuantum 4,010312(2023)” proposes a local CD-driven protocol that approximates the anti-adiabatic term. Compared with the traditional CD method, it does not require the calculation of the full spectrum of the Hamiltonian, thus providing a more practical alternative. For the CD method, it requires the full spectrum of the Hamiltonian, resulting in exponential growth of computational complexity with the problem size. For the full spectrum calculation of the 2048-bit RSA decomposition, the classical computing resources required far exceed the current supercomputing capabilities. Although the local CD method does not require full spectrum information, the construction of high-order CD terms requires complex many-body interactions, which is difficult to implement on quantum devices with medium noise scale and far exceeds the physical realization capabilities of current superconducting quantum processors. Moreover, whether it is the CD method or the local CD method, achieving fast evolution may still require significant modifications to the Hamiltonian, such as large-amplitude control fields, which still faces challenges in current quantum hardware. In addition, quantum optimal control theory provides a non-adiabatic quantum control method. Recent studies have attempted to combine quantum optimal control theory with factorization tasks. Traditional quantum optimal control algorithms, such as the gradient ascent pulse engineering in "Journal of Magnetic Resonance 172,296 (2005)" and the quantum approximate optimization algorithm in "arXiv:1411.4028 (2014)", can also achieve adiabatic quantum computing by adjusting the control pulse parameters through discrete-time optimization. However, this requires preset time segments and high parameter dimensions. For the 2048-bit RSA factorization task, the parameter dimension to be optimized is as high as 10 6 Magnitude, difficult to converge. Summary of the Invention

[0004] In response to the problems existing in the prior art, the present invention provides an RSA public key cracking method, storage medium and device based on the CRAB quantum algorithm optimization. Through efficient evolution, the factorization accuracy and anti-noise robustness are improved, and the rapid cracking of RSA public keys is achieved.

[0005] To achieve the above technical objectives, the present invention adopts the following technical solution: an RSA public key cracking method based on CRAB quantum algorithm optimization, comprising the following steps:

[0006] Step S1: Factor the cracked RSA public key modulus and expand it into binary form;

[0007] Step S2: Generate a set of constraint equations according to the binary multiplication table, construct a cost function through the set of constraint equations, and generate the problem Hamiltonian;

[0008] Step S3: constructing a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjusting the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian, and obtaining a maximized time-varying Hamiltonian;

[0009] Step S4: preparing the ground state of the initial Hamiltonian and obtaining the final state of the Hamiltonian according to maximizing the total evolution time of the time-varying Hamiltonian;

[0010] Step S5: calculating the final state energy value of the Hamiltonian according to the adjusted problem Hamiltonian and the final state of the initial Hamiltonian, minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm, and determining the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian;

[0011] Step S6: Performing a z-direction Pauli operator measurement on each quantum bit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, extracting the binary digits of the factorization, and obtaining the factorization factors by combining the binary multiplication table;

[0012] Step S7: Combine the decomposed factors with the cracked RSA public key exponent to determine the private key, completing the RSA public key cracking.

[0013] Furthermore, the RSA public key modulus ω=ab, where a and b represent the decomposed factors respectively, which are expanded into binary form as follows:

[0014]

[0015] Among them, n a The number of qubits required to represent the factor a, represents the largest even number less than or equal to ω, Represented in binary The minimum number of bits required; j represents n a The index of a j The j-th qubit value in the binary representation of factor a; n b The number of qubits required to represent the factor b, Indicates less than or equal to The largest integer, Represented in binary The minimum number of bits required; h represents n b The index of b h Represent the factor b using the h-th qubit value in binary representation.

[0016] Furthermore, the construction process of the time-varying Hamiltonian is:

[0017] H(t)=(1-s(t))H0+s(t)H p

[0018] Where H(t) represents the time-varying Hamiltonian; H0 represents the initial Hamiltonian, g represents the transverse field strength, n represents the number of unknowns in the constraint equations, l represents the index of n, represents the Pauli x-operator of the ol-th quantum bit; s(t) represents the time-dependent scheduling function, s0(t) represents linear scheduling, s0(t) = t / T, T represents the total evolution time, t represents the evolution moment, N c represents the number of expansion bases of s0(t), and k represents N c The index of ω k represents the expansion base frequency, r k represents a random number sampled from a uniform distribution in [-0.5, 0.5], λ(t) represents the normalization factor, A k represents the first coefficient of the kth expansion basis, B k represents the second coefficient of the kth expansion basis; h p Denote the problem Hamiltonian.

[0019] Furthermore, the problem Hamiltonian is adjusted with the goal of maximizing the first energy gap of the time-varying Hamiltonian, and the specific process of obtaining the maximized time-varying Hamiltonian is as follows:

[0020] i. Uniformly discretize s(t) on [0,1], calculate the energy difference between the first excited state energy and the ground state energy of the time-varying Hamiltonian H(t) under different s(t), and find the smallest energy difference among all s(t) as the first energy gap;

[0021] ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian, update the time-varying Hamiltonian H(t), and calculate the first energy gap according to the method in step i;

[0022] iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first energy gap, adjust the problem Hamiltonian, and update the time-varying Hamiltonian, and use the updated time-varying Hamiltonian as the maximized variable Hamiltonian.

[0023] Furthermore, the final state of the Hamiltonian |ψ(T)> is obtained by:

[0024]

[0025] in, represents the maximized time-varying Hamiltonian, i represents the complex unit, |ψ0> represents the ground state of the initial Hamiltonian, |0> and |1> are both eigenstates of the Pauli z operator. The eigenvalue corresponding to |0> is -1, and the eigenvalue corresponding to |1> is 1. Represents direct product.

[0026] Furthermore, the calculation process of the final state energy value of the Hamiltonian is:

[0027] ε=<ψ(T)|H p |ψ(T)>.

[0028] Furthermore, the specific process of minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm is as follows:

[0029] A. Initialize the first and second coefficients of a set of expansion bases as the first vertex of the simplex; the other vertices in the simplex are generated by adding random perturbations to the first vertex;

[0030] B. Calculate the final-state energy value of the Hamiltonian for each vertex on the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final-state energy value of the Hamiltonian;

[0031] C. Reflect, expand, or shrink the sorted vertices according to the final energy value of the Hamiltonian, and update the vertices until the maximum relative difference of the final energy value of the Hamiltonian is less than 10 -3 , find the final state of the Hamiltonian corresponding to the vertex where the final state energy value of the Hamiltonian is the smallest.

[0032] Furthermore, the calculation process of the private key is:

[0033] ed-φ(a,b)n=1

[0034] Where e represents the cracked RSA public key exponent, d represents the private key, φ() represents the Euler function, and φ(a,b)=(a-1)(b-1).

[0035] Furthermore, the present invention also provides a computer-readable storage medium storing a computer program, wherein the computer program enables a computer to execute the RSA public key cracking method optimized based on the CRAB quantum algorithm.

[0036] Furthermore, the present invention also provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the RSA public key cracking method optimized based on the CRAB quantum algorithm is implemented.

[0037] Compared with the prior art, the present invention has the following beneficial effects:

[0038] (1) The RSA public key cracking method optimized based on the CRAB quantum algorithm of the present invention generates a set of constraint equations according to a binary multiplication table. Thus, when constructing a time-varying Hamiltonian, only the unknowns in the set of constraint equations are considered, which can eliminate redundant variables and reduce the demand for quantum bits.

[0039] (2) The RSA public key cracking method optimized based on the CRAB quantum algorithm of the present invention adjusts the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian, which can suppress the probability of ground state excitation, thereby improving the fidelity of adiabatic evolution to the ground state of the problem Hamiltonian and improving the accuracy of RSA public key cracking; at the same time, the coefficients of the expansion basis of the time-dependent scheduling function in the time-varying Hamiltonian are optimized by the Nelder-Mead algorithm, which can dynamically suppress non-adiabatic transitions, break through the limitations of adiabatic conditions, achieve high fidelity of the final state within a limited time, reduce sensitivity to instantaneous Hamiltonian parameters, and maintain high fidelity even in a noisy environment, thereby improving the decomposition reliability of the public key modulus factorization and improving the accuracy of RSA public key cracking. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 Schematic diagram of the RSA public key cracking method optimized based on the CRAB quantum algorithm of the present invention;

[0041] Figure 2 This is a comparison of the energy spectra of the unadjusted time-varying Hamiltonian and the adjusted time-varying Hamiltonian when decomposing the RSA public key modulus 2479;

[0042] Figure 3 Decompose the final state probability distribution of the RSA public key modulus 2479 for different total evolution times T, where Figure 3 (a) T = 0.75, Figure 3 (b) T=1, Figure 3 (c)T=2. DETAILED DESCRIPTION

[0043] The technical solution of the present invention will be further explained below with reference to the accompanying drawings.

[0044] like Figure 1 This is a schematic diagram of the RSA public key cracking method optimized based on the CRAB quantum algorithm of the present invention. The RSA public key cracking method includes the following steps:

[0045] Step S1: Factor the cracked RSA public key modulus and expand it into binary form. Specifically, the RSA public key modulus ω = ab, where a and b represent the decomposed factors, which are expanded into binary form as follows:

[0046]

[0047] Among them, n a The number of qubits required to represent the factor a, represents the largest even number less than or equal to ω, Represented in binary The minimum number of bits required; j represents n a The index of a j The j-th qubit value in the binary representation of factor a; n b The number of qubits required to represent the factor b, Indicates less than or equal to The largest integer, Represented in binary The minimum number of bits required; h represents n b The index of b h Represent the factor b using the h-th qubit value in binary representation.

[0048] Step S2: Generate a set of constraint equations based on the binary multiplication table, construct a cost function through the constraint equations, and generate the problem Hamiltonian. The quantum bits required for the problem Hamiltonian are determined by the unknowns in the constraint equations, which makes it convenient to only consider the unknowns in the constraint equations when constructing the time-varying Hamiltonian. This can eliminate redundant variables and reduce the demand for quantum bits.

[0049] Step S3: constructing a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjusting the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian, so as to suppress the ground state excitation probability and obtain a maximized time-varying Hamiltonian;

[0050] The construction process of the time-varying Hamiltonian in the present invention is:

[0051] H(t)=(1-s(t))H0+s(t)H p

[0052] Where H(t) represents the time-varying Hamiltonian; H0 represents the initial Hamiltonian, g represents the transverse field strength, n represents the number of unknowns in the constraint equations, l represents the index of n, represents the Pauli x operator of the lth quantum bit; s(t) represents the time-dependent scheduling function, s0(t) represents linear scheduling, s0(t) = t / T, T represents the total evolution time, t represents the evolution moment, N c represents the number of expansion bases of s0(t), and k represents N c The index of ωk represents the expansion base frequency, r k represents a random number sampled from a uniform distribution in [-0.5, 0.5], λ(t) represents the normalization factor, A k represents the first coefficient of the kth expansion basis, B k represents the second coefficient of the kth expansion basis; H p Denote the problem Hamiltonian.

[0053] The specific process of adjusting the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian and obtaining the maximized time-varying Hamiltonian is as follows:

[0054] i. Uniformly discretize s(t) on [0,1], calculate the energy difference between the first excited state energy and the ground state energy of the time-varying Hamiltonian H(t) under different s(t), and find the smallest energy difference among all s(t) as the first energy gap;

[0055] ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian, update the time-varying Hamiltonian H(t), and calculate the first energy gap according to the method in step i;

[0056] iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first energy gap, adjust the problem Hamiltonian, and update the time-varying Hamiltonian, and use the updated time-varying Hamiltonian as the maximized variable Hamiltonian.

[0057] Step S4: Prepare the ground state of the initial Hamiltonian and obtain the final state of the Hamiltonian by maximizing the total evolution time of the time-varying Hamiltonian in, represents the maximized time-varying Hamiltonian, i represents the complex unit, |ψ0> represents the ground state of the initial Hamiltonian, |0> and |1> are both eigenstates of the Pauli z operator. The eigenvalue corresponding to |0> is -1, and the eigenvalue corresponding to |1> is 1. Represents direct product.

[0058] Step S5: Calculate the final state energy value of the Hamiltonian according to the adjusted problem Hamiltonian and the final state of the initial Hamiltonian ε=<ψ(T)|H p |ψ(T)>, the Nelder-Mead algorithm is used to minimize the final state energy value of the Hamiltonian, and the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian is determined; specifically,

[0059] A. Initialize the first and second coefficients of a set of expansion bases as the first vertex coeffi of the simplex initial =[A1,…A Nc ,B1,…B Nc], where the array elements initialized here are all 0; the other vertices in the simplex are generated by adding random perturbations to the first vertex, and the other vertices in the simplex coeffi i =coeff initial +0.05*random(2N c ), random(2N c ) is of dimension 2N c A one-dimensional array of , where the array elements are random numbers from a Gaussian distribution with a sampling mean of 0 and a variance of 1;

[0060] B. Calculate the final energy value of the Hamiltonian for each vertex on the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final energy value of the Hamiltonian to obtain an ordered list of the final energy values of the Hamiltonian. and the corresponding vertices

[0061] C. Reflect, expand, or shrink the sorted vertices according to the final energy value of the Hamiltonian, and update the vertices until the maximum relative difference of the final energy value of the Hamiltonian is less than 10 -3 , find the final state of the Hamiltonian corresponding to the vertex where the final state energy value of the Hamiltonian is the smallest.

[0062] The reflection operation is as follows: Calculation Among them, centroid is the first 2N c The mean of the vertices, if And ε r ≥ε0, then use coeffr r replace

[0063] The expansion operation is as follows: If ε r <ε0, calculate the expansion point coeff e =2*coeff r -centroid, if ε e <ε r , replaced by coeffe e Otherwise keep coeffr r ;

[0064] The contraction operation is as follows: If Execute contraction: (i) External contraction: If Calculate coeffc c =0.5*coeff r +0.5*centroid. (ii) Internal contraction: If calculate like Replaced by coeffcc Otherwise, the simplex reduction operation is performed. The simplex reduction operation is as follows: the best vertex coeff00 is retained, and the remaining vertices shrink to coeff00: coeffi i =0.5*coeffi i +0.5*coeff00.

[0065] Optimizing the coefficients of the expansion basis of the time-dependent scheduling function through the Nelder-Mead algorithm can dynamically suppress non-adiabatic transitions, break through the limitations of adiabatic conditions, achieve high fidelity of the final state within a limited time, reduce sensitivity to the instantaneous Hamiltonian parameters, and maintain high fidelity even in noisy environments, thereby improving the decomposition reliability of the public key modulus factorization and improving the accuracy of RSA public key cracking.

[0066] Step S6: Performing a z-direction Pauli operator measurement on each quantum bit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, extracting the binary digits of the factorization, and obtaining the factorization factors by combining the binary multiplication table;

[0067] Step S7: Combine the decomposed factors with the cracked RSA public key exponent to determine the private key and complete the RSA public key cracking. The calculation process of the private key d is:

[0068] ed-φ(a,b)n=1

[0069] Wherein, e represents the cracked RSA public key exponent, φ() represents the Euler function, and φ(a,b)=(a-1)(b-1).

[0070] The present invention improves the factorization accuracy and the anti-noise robustness, and realizes the rapid cracking of the RSA public key.

[0071] Example

[0072] Using the RSA public key cracking method optimized by the CRAB quantum algorithm of the present invention, taking the cracking of the RSA public key (ω=2479, e=5) as an example, it is necessary to decompose the RSA public key modulus 2479 and expand the factors a and b of 2479 into the following binary form:

[0073] a=2 0 a0+2 1 a1+2 2 a2+2 3 a3+2 4 a4+2 5 a5+2 6 a6

[0074] b=2 0 b0+2 1 b1+22 b2+2 3 b3+2 4 b4+2 5 b5

[0075] Construct a multiplication table based on the binary form of a and b, as shown in Table 1, where c i,j Indicates the carry from the i-th bit to the j-th bit.

[0076] Table 1. Binary multiplication table of 2479

[0077]

[0078] According to the binary representation of 2479 in Table 1, the following constraint equations are generated by column summation:

[0079] a3b1-b1=0

[0080] a3b2-b1=0

[0081] a3+b2+c 7,8 -1=0

[0082] b1-b2-2c 7,8 +1=0

[0083] a3-2b1b2-b1+b2-1=0

[0084] According to the constraint equations, the number of quantum bits n required for decomposition is 4, and it is necessary to solve a3, b1, b3, c 7,8 , therefore, the cost function is constructed as:

[0085] f(a3,b1,b2,c 7,8 )=(a3b1-b1) 2 +(a3b2-b1) 2 +(a3+b2+c 7,8 -1) 2 +(b1-b2-2c 7,8 +1) 2 +(a3-2b1b2-b1+b2-1) 2

[0086] The Hamiltonian of the problem is:

[0087]

[0088] in, is the identity matrix, are the Pauli z operators for the 1st, 2nd, 3rd, and 4th qubits respectively.

[0089] According to the initial Hamiltonian and the problem Hamiltonian, the time-varying Hamiltonian H(t) = (1-s(t))H0 + s(t)H is constructed. p , where the initial Hami quantity The transverse field strength g = 10. To expand the first energy gap, the Hamiltonian of the problem can be changed to:

[0090]

[0091] After expansion, you can get:

[0092]

[0093] The energy gap changes before and after the time-varying Hamiltonian is adjusted as follows Figure 2 As shown, the energy gap of the unadjusted time-varying Hamiltonian is represented by the gray line, and the energy gap of the adjusted time-varying Hamiltonian is represented by the blue line. By adjusting the coefficients of the problem Hamiltonian, the energy difference between the first excited state energy and the ground state energy is significantly increased, thereby accelerating the adiabatic evolution process.

[0094] Construct the initial guess linear schedule s0(t) = t / T, where T = 2.0 is the total evolution time, and perform random basis expansion on the linear schedule s0(t) Among them, N c =4 is the number of expansion bases, is the expansion base frequency, r k is a random number sampled from a uniform distribution in [-0.5, 0.5]. is the expansion basis coefficient.

[0095] Prepare the ground state of the initial Hamiltonian H0 According to the Schrödinger equation Calculate the final state of |ψ0> obtained after the time-varying Hamiltonian evolves H(t) at time T Calculate the final energy value of the time-varying Hamiltonian ε=<ψ(T)|H p |ψ(T)>.

[0096] The Nelder-Mead algorithm is used to minimize the final state energy value of the Hamiltonian, and the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian is determined to be |ψ(T)>=|0010>, indicating that the four quantum bits are in the |0>, |0>, |1>, and |0> states respectively.

[0097] Perform the Pauli operator measurement in the x direction on each qubit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, and obtain Get a3=0, b1=0, b2=1, c 7,8 = 0. According to the binary multiplication table, we can calculate:

[0098] (a5,a4,a3,a2,a1)=(0,0,0,0,1)

[0099] (b4,b3,b2,b1)=(0,0,1,0)

[0100] Then we have:

[0101]

[0102] Thus, the factorization result of 2479 is obtained: 2479=67×37.

[0103] Calculate the Euler function φ(a,b)=(a-1)(b-1)=2376. Based on the RSA public key exponent e=5, use the extended Euclidean algorithm to solve the equation: 5d-2376×4=1, and obtain the private key d=1901, completing the cracking.

[0104] Figure 3 The comparison of the final state probability distributions of CRAB optimization and non-optimization for different total evolution times T when decomposing the RSA public key modulus 2479 intuitively demonstrates the effectiveness of CRAB optimization in improving the efficiency of adiabatic evolution. Figure 3 (a) corresponds to the probability distribution when T = 0.75. At this time, CRAB optimization has shown obvious advantages, but the probability concentration still has room for improvement; Figure 3 (b) corresponds to the probability distribution when T = 1. After optimization, the dominance of |0010> is further enhanced; Figure 3 (c) in the figure corresponds to the probability distribution when T=2. The CRAB optimization probability is almost completely concentrated in |0010>, which verifies the promoting effect of time extension on the optimization effect.

[0105] In one technical solution of the present invention, a computer-readable storage medium is further provided, storing a computer program, wherein the computer program enables a computer to execute the RSA public key cracking method optimized based on the CRAB quantum algorithm.

[0106] In one technical solution of the present invention, an electronic device is also provided, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the RSA public key cracking method optimized based on the CRAB quantum algorithm is implemented.

[0107] In the embodiments disclosed herein, computer storage media can be tangible media that can contain or store programs for use by or in conjunction with an instruction execution system, device, or apparatus. Computer storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any suitable combination of the foregoing. More specific examples of computer storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0108] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0109] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions based on the principles of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A RSA public key cracking method based on CRAB quantum algorithm optimization, characterized in that: The steps include: Step S1: Factor the cracked RSA public key modulus and expand it into binary form; Step S2: Generate a set of constraint equations according to the binary multiplication table, construct a cost function through the set of constraint equations, and generate the problem Hamiltonian; Step S3: constructing a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjusting the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian, and obtaining a maximized time-varying Hamiltonian; Step S4: preparing the ground state of the initial Hamiltonian and obtaining the final state of the Hamiltonian according to maximizing the total evolution time of the time-varying Hamiltonian; Step S5: calculating the final state energy value of the Hamiltonian according to the adjusted problem Hamiltonian and the final state of the initial Hamiltonian, minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm, and determining the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian; Step S6: Performing a z-direction Pauli operator measurement on each quantum bit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, extracting the binary digits of the factorization, and obtaining the factorization factors by combining the binary multiplication table; Step S7: Combine the decomposed factors with the cracked RSA public key exponent to determine the private key, completing the RSA public key cracking.

2. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 1 is characterized in that: The RSA public key modulus ω=ab, where a and b represent the decomposed factors respectively, which are expanded into binary form as follows: Among them, n a The number of qubits required to represent the factor a, represents the largest even number less than or equal to ω, Represented in binary The minimum number of bits required; j represents n a The index of a j The j-th qubit value in the binary representation of factor a; n b The number of qubits required to represent the factor b, Indicates less than or equal to The largest integer, Represented in binary The minimum number of bits required; h represents n b The index of b h Represent the factor b using the h-th qubit value in binary representation.

3. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 2 is characterized in that: The construction process of the time-varying Hamiltonian is: H(t)=(1-s(t))H0+s(t)H p Where H(t) represents the time-varying Hamiltonian; H0 represents the initial Hamiltonian, g represents the transverse field strength, n represents the number of unknowns in the constraint equations, l represents the index of n, represents the Pauli x operator of the lth quantum bit; s(t) represents the time-dependent scheduling function, s0(t) represents linear scheduling, s0(t) = t / T, T represents the total evolution time, t represents the evolution moment, N c represents the number of expansion bases of s0(t), and k represents N c The index of ω k represents the expansion base frequency, r k represents a random number sampled from a uniform distribution in [-0.5, 0.5], λ(t) represents the normalization factor, A k represents the first coefficient of the kth expansion basis, B k represents the second coefficient of the kth expansion basis; H p Denote the problem Hamiltonian.

4. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 3 is characterized in that: The specific process of adjusting the problem Hamiltonian with the goal of maximizing the first energy gap of the time-varying Hamiltonian and obtaining the maximized time-varying Hamiltonian is as follows: i. Uniformly discretize s(t) on [0,1], calculate the energy difference between the first excited state energy and the ground state energy of the time-varying Hamiltonian H(t) under different s(t), and find the smallest energy difference among all s(t) as the first energy gap; ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian, update the time-varying Hamiltonian H(t), and calculate the first energy gap according to the method in step i; iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first energy gap, adjust the problem Hamiltonian, and update the time-varying Hamiltonian, and use the updated time-varying Hamiltonian as the maximized variable Hamiltonian.

5. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 4 is characterized in that: The process of obtaining the final state of the Hamiltonian |ψ(T)> is as follows: in, represents the maximized time-varying Hamiltonian, i represents the complex unit, |ψ0> represents the ground state of the initial Hamiltonian, |0> and |1> are both eigenstates of the Pauli z operator. The eigenvalue corresponding to |0> is -1, and the eigenvalue corresponding to |1> is 1. Represents direct product.

6. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 5 is characterized in that: The calculation process of the final state energy value of the Hamiltonian is: ε=<ψ(T)|H p |ψ(T)>。 7. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 6 is characterized in that: The specific process of minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm is as follows: A. Initialize the first and second coefficients of a set of expansion bases as the first vertex of the simplex; the other vertices in the simplex are generated by adding random perturbations to the first vertex; B. Calculate the final-state energy value of the Hamiltonian for each vertex on the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final-state energy value of the Hamiltonian; C. Reflect, expand, or shrink the sorted vertices according to the final energy value of the Hamiltonian, and update the vertices until the maximum relative difference of the final energy value of the Hamiltonian is less than 10 -3 , find the final state of the Hamiltonian corresponding to the vertex where the final state energy value of the Hamiltonian is the smallest.

8. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 7 is characterized in that: The calculation process of the private key is: ed-φ(a,b)n=1 Where e represents the cracked RSA public key exponent, d represents the private key, φ() represents the Euler function, and φ(a,b)=(a-1)(b-1).

9. A computer-readable storage medium storing a computer program, characterized in that: The computer program enables a computer to execute the RSA public key cracking method based on CRAB quantum algorithm optimization as described in any one of claims 1 to 8.

10. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the RSA public key cracking method based on the CRAB quantum algorithm optimization as described in any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Large integer decomposition problem mapping method and system based on Isin model

    CN115514488A

  • Integer decomposition method based on quantum approximate optimization algorithm

    CN119743261A

  • Tensor network-enhanced prime factorization

    EP4531331A1

  • Systems and methods for solving computational problems

    US20130144925A1

  • Variationally and adiabatically navigated quantum eigensolvers

    US20210166148A1