A method, storage medium, and device for cracking RSA public keys based on CRAB quantum algorithm optimization
The RSA public key cracking method is optimized by using the CRAB quantum algorithm. By adjusting the constraint equations and time-varying Hamiltonian, and combining the Nelder-Mead algorithm for optimization, the problem of low efficiency in RSA public key cracking in traditional methods is solved, and fast and accurate factorization and private key determination are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2026-04-03
AI Technical Summary
Existing technologies struggle to effectively crack RSA public keys within polynomial time. Traditional quantum computing methods have high computational complexity, making them difficult to implement on quantum devices with moderate noise levels. Furthermore, parameter optimization is challenging, resulting in low efficiency in cracking RSA public keys.
The CRAB quantum algorithm is used to optimize the RSA public key cracking method. By constructing a binary multiplication table to generate a set of constraint equations, adjusting the time-varying Hamiltonian to maximize the first band gap, and using the Nelder-Mead algorithm to optimize the final state energy value of the Hamiltonian, factorization is achieved by combining qubit measurement.
It improves the accuracy and noise robustness of RSA public key cracking, achieves fast and reliable factorization, and reduces the requirement for qubits and computational complexity.
Smart Images

Figure CN120498666B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of quantum cryptography, specifically to an RSA public key cracking method, storage medium, and device based on the CRAB quantum algorithm. Background Technology
[0002] RSA encryption is an asymmetric encryption algorithm based on a simple mathematical fact: multiplying two prime numbers to obtain a large number is easy, but factoring a large number into the product of two prime numbers is extremely difficult. Factoring is one of the core problems in breaking RSA encryption, and it cannot be solved in polynomial time by classical algorithms. However, in 1994, Shor proposed a quantum algorithm, "Proceedings 35". th The annual symposium on foundations of computer science (Ieee, 1994) pp. 124–134 demonstrates an exponential reduction in time complexity compared to classical decomposition algorithms. Another approach to implementing decomposition algorithms is adiabatic quantum computation pioneered by Farhi et al. (Science 292, 472 (2001), which provides a promising alternative to the traditional quantum computing framework). Adiabatic quantum computation encodes the solution to the problem in the ground state of the problem Hamiltonian: the system starts from the easily prepared ground state of the initial Hamiltonian and gradually transforms the initial Hamiltonian into the problem Hamiltonian through adiabatic evolution. The adiabatic theorem (Journal of the Physical Society of Japan 5, 435 (1950)) guarantees that the system remains in the ground state, thus yielding the solution. Adiabatic quantum computation is fundamentally related to the preparation of ground states in quantum many-body systems and has achieved significant success in the field of quantum annealing.
[0003] In adiabatic quantum computation, evolution time is crucial, and much research has focused on accelerating this process through adiabatic techniques. For example, "Phys.Rev.A 104,L050403(2021)" adds a counter-diabatic (CD) term to the total Hamiltonian to suppress non-adiabatic transitions, thereby significantly increasing the probability of the system reaching the ground state; while "PRXQuantum" The paper 4,010312 (2023) proposes a local CD-driven protocol that approximates the antiadiabatic term. Compared to the traditional CD method, it does not require the computation of the full spectrum information of the Hamiltonian, thus providing a more practical alternative. For the CD method, the full spectrum information of the Hamiltonian is required, which leads to an exponential increase in computational complexity with the problem size. The classical computing resources required for the full spectrum computation of a 2048-bit RSA decomposition far exceed the capabilities of existing supercomputing. Although the local CD method does not require full spectrum information, the construction of higher-order CD terms requires complex many-body interactions, which is difficult to implement on quantum devices with medium noise levels, far exceeding the physical implementation capabilities of current superconducting quantum processors. Furthermore, regardless of whether it is the CD method or the local CD method, achieving rapid evolution may still require significant modifications to the Hamiltonian, such as large-amplitude control fields, which still faces challenges in current quantum hardware. Furthermore, quantum optimal control theory provides a non-adiabatic quantum control method, and recent research has attempted to combine quantum optimal control theory with factorization tasks. Traditional quantum optimal control algorithms, such as the gradient-ascending pulse engineering in "Journal of Magnetic Resonance 172, 296 (2005)" and the quantum approximation optimization algorithm in "arXiv: 1411.4028 (2014)", can also achieve adiabatic quantum computation by adjusting control pulse parameters through discrete-time optimization. However, these algorithms require pre-defined time segments and have high parameter dimensionality; for a 2048-bit RSA factorization task, the parameter dimensionality needs to be optimized to as high as 10. 6 The magnitude is too large to converge. Summary of the Invention
[0004] To address the problems existing in the prior art, this invention provides an RSA public key cracking method, storage medium, and device based on the CRAB quantum algorithm optimization. Through efficient evolution, it improves the accuracy of factorization and noise robustness, enabling rapid cracking of RSA public keys.
[0005] To achieve the above technical objectives, the present invention adopts the following technical solution: an RSA public key cracking method based on CRAB quantum algorithm optimization, comprising the following steps:
[0006] Step S1: Factorize the modulus of the cracked RSA public key and expand it into binary form;
[0007] Step S2: Generate a set of constraint equations based on the binary multiplication table, construct a cost function using the set of constraint equations, and generate the problem Hamiltonian.
[0008] Step S3: Construct a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjust the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian to obtain the maximized time-varying Hamiltonian.
[0009] Step S4: Prepare the ground state of the initial Hamiltonian, and obtain the final state of the Hamiltonian based on the total evolution time of maximizing the time-varying Hamiltonian;
[0010] Step S5: Calculate the final state energy value of the Hamiltonian based on the adjusted Hamiltonian and the final state of the initial Hamiltonian. Use the Nelder-Mead algorithm to minimize the final state energy value of the Hamiltonian and determine the final state of the Hamiltonian corresponding to the minimum final state energy value.
[0011] Step S6: Perform a z-direction Pauli operator measurement on each qubit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, extract the number of binary bits of the factorization, and obtain the factorization factors by combining with the binary multiplication table.
[0012] Step S7: Combine the factorization with the cracked RSA public key exponent to determine the private key, thus completing the RSA public key cracking.
[0013] Furthermore, the RSA public key modulus ω = ab, where a and b represent the factors of the factorization, which can be expanded into binary form as follows:
[0014]
[0015] Where, n a This represents the number of qubits required to form factor a. This represents the largest even number less than or equal to ω. Represented in binary Minimum number of bits required; j represents n a index, a j This represents the value of the j-th qubit in the binary representation of factor a; n b This represents the number of qubits required to form factor b. Indicates less than or equal to The largest integer, Represented in binary Minimum number of bits required; h represents n b index, b h The value of the h-th qubit in the binary representation of factor b is given.
[0016] Furthermore, the construction process of the time-varying Hamiltonian is as follows:
[0017] H(t)=(1-s(t))H0+s(t)H p
[0018] Where H(t) represents the time-varying Hamiltonian; H0 represents the initial Hamiltonian. g represents the transverse field strength, n represents the number of unknowns in the constraint equations, and l represents the index of n. Let denote the Pauli x operator for the ol-th qubit; s(t) denotes the time-dependent scheduling function. s0(t) represents linear scheduling, s0(t) = t / T, T represents the total evolution time, t represents the evolution moment, and N c Let k represent the number of basis numbers in the expansion of s0(t), and let N represent the number of basis numbers. c index, ω k Indicates the expansion fundamental frequency. r k Let represent random numbers sampled from a uniform distribution in the range [-0.5, 0.5], and λ(t) represent the normalization factor. A k Let B represent the first coefficient of the k-th expansion basis. k h represents the second coefficient of the k-th expansion basis; p This represents the Hamiltonian of the problem.
[0019] Furthermore, the specific process of adjusting the problem Hamiltonian with the objective of maximizing the first bandgap of the time-varying Hamiltonian and obtaining the maximized time-varying Hamiltonian is as follows:
[0020] i. Discretize s(t) uniformly on [0,1], calculate the energy difference between the first excited state energy and the ground state energy of the time-varying Hamiltonian H(t) under different s(t), and find the smallest energy difference among all s(t) as the first energy gap;
[0021] ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian, update the time-varying Hamiltonian H(t), and calculate the first bandgap according to the method in step i;
[0022] iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first bandgap, adjust the problem Hamiltonian, update the time-varying Hamiltonian, and use the updated time-varying Hamiltonian as the maximized variable Hamiltonian.
[0023] Furthermore, the process of obtaining the final state |ψ(T)> of the Hamiltonian is as follows:
[0024]
[0025] in, Let |ψ0> represent the time-varying Hamiltonian maximized, where i represents the complex unit, and |ψ0> represents the ground state of the initial Hamiltonian. Both |0> and |1> are eigenstates of the Pauli z operator, with |0> having an eigenvalue of -1 and |1> having an eigenvalue of 1. This represents the direct product.
[0026] Furthermore, the calculation process for the final state energy value of the Hamiltonian is as follows:
[0027] ε=<ψ(T)|H p |ψ(T)>.
[0028] Furthermore, the specific process of minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm is as follows:
[0029] A. Initialize the first and second coefficients of a set of expansion basis as the first vertex of the simplex; other vertices of the simplex are generated by adding random perturbations to the first vertex.
[0030] B. Calculate the final state energy value of the Hamiltonian of each vertex on the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final state energy value of the Hamiltonian.
[0031] C. Based on the final energy value of the Hamiltonian, perform reflection, expansion, or contraction operations on the sorted vertices, updating the vertices until the maximum relative difference of the calculated final energy values of the Hamiltonian is less than 10. -3 Find the final state of the Hamiltonian corresponding to the vertex with the smallest final state energy value.
[0032] Furthermore, the calculation process for the private key is as follows:
[0033] ed-φ(a,b)n=1
[0034] Where e represents the cracked RSA public key exponent, d represents the private key, φ() represents the Euler totient function, and φ(a,b)=(a-1)(b-1).
[0035] Furthermore, the present invention also provides a computer-readable storage medium storing a computer program that enables a computer to execute the described RSA public-key cracking method based on the CRAB quantum algorithm.
[0036] Furthermore, the present invention also provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the RSA public key cracking method based on the CRAB quantum algorithm optimization.
[0037] Compared with the prior art, the present invention has the following beneficial effects:
[0038] (1) The RSA public key cracking method based on the CRAB quantum algorithm of this invention generates a set of constraint equations according to the binary multiplication table. Thus, when constructing the time-varying Hamiltonian, only the unknowns in the set of constraint equations are considered, which can eliminate redundant variables and reduce the demand for qubits.
[0039] (2) The RSA public key cracking method based on the CRAB quantum algorithm of this invention adjusts the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian. This can suppress the ground state excitation probability, thereby improving the fidelity of adiabatic evolution to the ground state of the problem Hamiltonian and improving the accuracy of RSA public key cracking. At the same time, the coefficients of the expansion basis of the time-dependent scheduling function in the time-varying Hamiltonian are optimized by the Nelder-Mead algorithm, which can dynamically suppress non-adiabatic transitions, break through the adiabatic condition limitation, achieve high fidelity of the final state in a finite time, reduce the sensitivity to instantaneous Hamiltonian parameters, and maintain high fidelity even in noisy environments. This improves the reliability of the public key modulus factorization and the accuracy of RSA public key cracking. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the RSA public key cracking method optimized based on the CRAB quantum algorithm of this invention;
[0041] Figure 2 A comparison of the energy spectra of the unadjusted and adjusted time-varying Hamiltonians when decomposing the RSA public key modulus 2479.
[0042] Figure 3 Decompose the final state probability distribution of the RSA public key modulus 2479 for different total evolution times T, where, Figure 3 In (a)T=0.75, Figure 3 In (b)T=1, Figure 3 In the case of (c)T = 2. Detailed Implementation
[0043] The technical solution of the present invention will be further explained and described below with reference to the accompanying drawings.
[0044] like Figure 1 This is a schematic diagram of the RSA public key cracking method optimized by the CRAB quantum algorithm according to the present invention. The RSA public key cracking method includes the following steps:
[0045] Step S1: For the cracked RSA public key modulus, factorize it and expand it into binary form; specifically, the RSA public key modulus ω = ab, where a and b represent the factors, and the expanded binary form is:
[0046]
[0047] Where, n a This represents the number of qubits required to form factor a. This represents the largest even number less than or equal to ω. Represented in binary Minimum number of bits required; j represents n a index, a j This represents the value of the j-th qubit in the binary representation of factor a; n b This represents the number of qubits required to form factor b. Indicates less than or equal to The largest integer, Represented in binary Minimum number of bits required; h represents n b index, b h The value of the h-th qubit in the binary representation of factor b is given.
[0048] Step S2: Generate a set of constraint equations based on the binary multiplication table, construct a cost function through the set of constraint equations, and generate the problem Hamiltonian. The number of qubits required for the problem Hamiltonian is determined by the unknowns in the set of constraint equations. This makes it easier to consider only the unknowns in the set of constraint equations when constructing the time-varying Hamiltonian, thereby eliminating redundant variables and reducing the number of qubits required.
[0049] Step S3: Construct a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjust the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian. This can suppress the ground state excitation probability and obtain the maximized time-varying Hamiltonian.
[0050] The construction process of the time-varying Hamiltonian in this invention is as follows:
[0051] H(t)=(1-s(t))H0+s(t)H p
[0052] Where H(t) represents the time-varying Hamiltonian; H0 represents the initial Hamiltonian. g represents the transverse field strength, n represents the number of unknowns in the constraint equations, and l represents the index of n. Let denote the Pauli x operator for the l-th qubit; s(t) denote the time-dependent scheduling function. s0(t) represents linear scheduling, s0(t) = t / T, T represents the total evolution time, t represents the evolution moment, and N c Let k represent the number of basis numbers in the expansion of s0(t), and let N represent the number of basis numbers. c index, ωk Indicates the expansion fundamental frequency. r k Let represent random numbers sampled from a uniform distribution in the range [-0.5, 0.5], and λ(t) represent the normalization factor. A k Let B represent the first coefficient of the k-th expansion basis. k H represents the second coefficient of the k-th expansion basis; p This represents the Hamiltonian of the problem.
[0053] The specific process of adjusting the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian and obtaining the maximized time-varying Hamiltonian is as follows:
[0054] i. Discretize s(t) uniformly on [0,1], calculate the energy difference between the first excited state energy and the ground state energy of the time-varying Hamiltonian H(t) under different s(t), and find the smallest energy difference among all s(t) as the first energy gap;
[0055] ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian, update the time-varying Hamiltonian H(t), and calculate the first bandgap according to the method in step i;
[0056] iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first bandgap, adjust the problem Hamiltonian, update the time-varying Hamiltonian, and use the updated time-varying Hamiltonian as the maximized variable Hamiltonian.
[0057] Step S4: Prepare the ground state of the initial Hamiltonian, and obtain the final state of the Hamiltonian based on the total evolution time of maximizing the time-varying Hamiltonian. in, Let |ψ0> represent the time-varying Hamiltonian maximized, where i represents the complex unit, and |ψ0> represents the ground state of the initial Hamiltonian. Both |0> and |1> are eigenstates of the Pauli z operator, with |0> having an eigenvalue of -1 and |1> having an eigenvalue of 1. This represents the direct product.
[0058] Step S5: Calculate the final state energy value ε = <ψ(T)|H based on the adjusted Hamiltonian and the final state of the initial Hamiltonian. p |ψ(T)>, the Nelder-Mead algorithm is used to minimize the final state energy value of the Hamiltonian, and the final state of the Hamiltonian corresponding to the minimum final state energy value is determined; specifically,
[0059] A. Initialize the first and second coefficients of a set of expansion basis equations, which will be used as the first vertex of the simplex, coeffi. initial =[A1,…A Nc ,B1,…B NcHere, all array elements are initialized to 0; other vertices in the simplex are generated by adding random perturbations to the first vertex, and the coeffi of the other vertices in the simplex... i =coeff initial +0.05*random(2N c ), random(2N) c (a) is a 2N dimension c A one-dimensional array, where the array elements are random numbers from a Gaussian distribution with a sample mean of 0 and a variance of 1;
[0060] B. Calculate the final state energy value of the Hamiltonian at each vertex of the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final state energy values of the Hamiltonian to obtain an ordered list of the final state energy values of the Hamiltonian. and corresponding vertices
[0061] C. Based on the final energy value of the Hamiltonian, perform reflection, expansion, or contraction operations on the sorted vertices, updating the vertices until the maximum relative difference of the calculated final energy values of the Hamiltonian is less than 10. -3 Find the final state of the Hamiltonian corresponding to the vertex with the smallest final state energy value.
[0062] The reflection operation is as follows: Calculate Where centroid is the first 2N c The mean of the vertices, if And ε r If ≥ε0, then use coeffr r replace
[0063] The expansion operation is as follows: if ε r If ε < 0, calculate the expansion point coeff. e =2*coeff r -centroid, if ε e <ε r Replace with coeffe e Otherwise, retain coeffr r ;
[0064] The contraction operation is as follows: If Perform contraction: (i) External contraction: if Calculate coeffc c =0.5*coeff r +0.5*centroid. (ii) Internal contraction: If calculate like Replace with coeffcc Otherwise, perform a simplex shrinking operation, which is as follows: retain the optimal vertex coeff00, and shrink the remaining vertices towards coeff00: coeff00 i =0.5*coeffi i +0.5*coeff00.
[0065] Optimizing the coefficients of the expanded basis of the time-dependent scheduling function using the Nelder-Mead algorithm can dynamically suppress non-adiabatic transitions, overcome the limitations of adiabatic conditions, achieve high fidelity of the final state within a finite time, reduce sensitivity to instantaneous Hamiltonian parameters, and maintain high fidelity even in noisy environments. This improves the reliability of public key modulus factorization and enhances the accuracy of RSA public key cracking.
[0066] Step S6: Perform a z-direction Pauli operator measurement on each qubit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, extract the number of binary bits of the factorization, and obtain the factorization factors by combining with the binary multiplication table.
[0067] Step S7: Combine the factorization factors with the cracked RSA public key exponent to determine the private key, completing the RSA public key cracking. The calculation process for the private key d is as follows:
[0068] ed-φ(a,b)n=1
[0069] Where e represents the cracked RSA public key exponent, φ() represents the Euler totient function, and φ(a,b)=(a-1)(b-1).
[0070] This invention improves the accuracy of factorization and noise robustness, enabling rapid cracking of RSA public keys.
[0071] Example
[0072] Using the RSA public key cracking method optimized by the CRAB quantum algorithm of this invention, taking the cracking of the RSA public key (ω=2479, e=5) as an example, it is necessary to decompose the modulus of the RSA public key 2479. The factors to be decomposed, a and b, of 2479 are expanded into the following binary form:
[0073] a = 2 0 a0+2 1 a1+2 2 a2+2 3 a3+2 4 a4+2 5 a5+2 6 a6
[0074] b=2 0 b0+2 1 b1+22 b2+2 3 b3+2 4 b4+2 5 b5
[0075] A multiplication table is constructed based on the binary forms of a and b, as shown in Table 1, where c i,j This indicates the carry from the i-th position to the j-th position.
[0076] Table 1.2479 Binary Multiplication Table
[0077]
[0078] Based on the binary representation of 2479 in Table 1, the following set of constraint equations is generated by summing the columns:
[0079] a3b1-b1=0
[0080] a3b2-b1=0
[0081] a³ + b² + c 7,8 -1 = 0
[0082] b1-b2-2c 7,8 +1 = 0
[0083] a3-2b1b2-b1+b2-1=0
[0084] According to the constraint equations, the number of qubits n required for decomposition is 4, and we need to solve for a3, b1, b3, c. 7,8 Therefore, the cost function is constructed as follows:
[0085] f(a3,b1,b2,c 7,8 )=(a3b1-b1) 2 +(a3b2-b1) 2 +(a³+b²+c 7,8 -1) 2 +(b1-b2-2c 7,8 +1) 2 +(a3-2b1b2-b1+b2-1) 2
[0086] The Hamiltonian of the problem is:
[0087]
[0088] in, It is the identity matrix. These are the Pauli z operators for the 1st, 2nd, 3rd, and 4th qubits, respectively.
[0089] Construct a time-varying Hamiltonian H(t) = (1-s(t))H0 + s(t)H based on the initial Hamiltonian and the problem Hamiltonian. p Among them, the initial Hami quantity The transverse field strength g = 10. To widen the first energy gap, the Hamiltonian of the problem can be transformed into:
[0090]
[0091] Unfolding will yield:
[0092]
[0093] The change in bandgap before and after the time-varying Hamiltonian adjustment is as follows: Figure 2 As shown, the band gap of the unadjusted time-varying Hamiltonian is represented by the gray line, and the band gap of the adjusted time-varying Hamiltonian is represented by the blue line. By adjusting the coefficient of the problem Hamiltonian, the energy difference between the first excited state energy and the ground state energy is significantly increased, thereby accelerating the adiabatic evolution process.
[0094] Construct an initial conjecture linear schedule s0(t) = t / T, where T = 2.0 is the total evolution time, and perform a stochastic basis expansion on the linear schedule s0(t). Where, N c =4 represents the number of expansion bases. For the expansion of the fundamental frequency, r k These are random numbers sampled from a uniformly distributed range [-0.5, 0.5]. These are the expansion basis coefficients.
[0095] Preparation of the ground state of the initial Hamiltonian H0 According to the Schrödinger equation Calculate the final state obtained by |ψ0> at time T after the evolution of the time-varying Hamiltonian H(t). Calculate the final state energy value ε=<ψ(T)|H of the time-varying Hamiltonian p |ψ(T)>.
[0096] The Nelder-Mead algorithm is used to minimize the final energy value of the Hamiltonian. The final state of the Hamiltonian corresponding to the minimum final energy value is determined as |ψ(T)>=|0010>, which means that the four qubits are in the states of |0>, |0>, |1>, and |0> respectively.
[0097] Perform a Pauli operator measurement in the x-direction for each qubit in the final state of the Hamiltonian corresponding to the minimum final state energy value of the Hamiltonian, and obtain... We obtain a3=0, b1=0, b2=1, c 7,8 = 0. This can be calculated using the binary multiplication table:
[0098] (a5,a4,a3,a2,a1)=(0,0,0,0,1)
[0099] (b4,b3,b2,b1)=(0,0,1,0)
[0100] Then we have:
[0101]
[0102] Therefore, the factorization result of 2479 is: 2479 = 67 × 37.
[0103] Calculate the Euler totient function φ(a,b)=(a-1)(b-1)=2376. Based on the RSA public key exponent e=5, solve the equation using the extended Euclidean algorithm: 5d-2376×4=1, and obtain the private key d=1901, thus completing the cracking.
[0104] Figure 3 The comparison of the final state probability distributions using CRAB optimization and non-optimization for different total evolution times T when decomposing the RSA public key modulus 2479 visually demonstrates the effectiveness of CRAB optimization in improving adiabatic evolution efficiency. Specifically, Figure 3 (a) in the diagram corresponds to the probability distribution when T = 0.75. At this point, CRAB optimization has shown a clear advantage, but there is still room for improvement in probability concentration. Figure 3 (b) in the equation corresponds to the probability distribution when T = 1. After optimization, the dominance of |0010> is further enhanced. Figure 3 (c) in the equation corresponds to the probability distribution when T=2. The CRAB optimization probability is almost entirely concentrated in |0010>, which verifies the promoting effect of time extension on optimization.
[0105] In one embodiment of the present invention, a computer-readable storage medium is also provided, storing a computer program that enables a computer to execute the RSA public key cracking method optimized based on the CRAB quantum algorithm.
[0106] In one technical solution of the present invention, an electronic device is also provided, including: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the RSA public key cracking method based on the CRAB quantum algorithm.
[0107] In the embodiments disclosed in this application, a computer storage medium may be a tangible medium that may contain or store programs for use by or in conjunction with an instruction execution system, apparatus, or device. The computer storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of computer storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0108] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0109] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should be considered within the scope of protection of the present invention.
Claims
1. A method for cracking RSA public keys based on the CRAB quantum algorithm, characterized in that, Includes the following steps: Step S1: For the cracked RSA public key modulus, perform factorization and expand it into binary form; the RSA public key modulus ,in, and The factors are represented as follows: in, Factors The number of qubits required Indicates less than or equal to The largest even number, Represented in binary Minimum number of bits required; j express index, Factors Representing the first in binary The value of a quantum bit; Factors b The number of qubits required , Indicates less than or equal to The largest integer, Represented in binary Minimum number of bits required; express index, Factors Representing the first in binary The value of a quantum bit; Step S2: Generate a set of constraint equations based on the binary multiplication table, construct a cost function using the set of constraint equations, and generate the problem Hamiltonian. Step S3: Construct a time-varying Hamiltonian based on the initial Hamiltonian and the problem Hamiltonian, and adjust the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian to obtain the maximized time-varying Hamiltonian. The construction process of the time-varying Hamiltonian is as follows: in, Represents a time-varying Hamiltonian; This represents the initial Hamiltonian. , Indicates transverse field strength. This indicates the number of unknowns in the system of constraint equations. l express n index, Indicates the first Pauli Operators; Represents a time-dependent scheduling function. , Indicates linear scheduling. , Indicates the total evolution time. Indicates the moment of evolution. express The number of expansion bases, express index, Indicates the expansion fundamental frequency. , Indicates sampling at Uniformly distributed random numbers, Represents the normalization factor. , Indicates the first k The first coefficient of the expansion basis, Indicates the first k The second coefficient of the expansion basis; Represents the problem Hamiltonian; The specific process of adjusting the problem Hamiltonian with the goal of maximizing the first bandgap of the time-varying Hamiltonian and obtaining the maximized time-varying Hamiltonian is as follows: i. in Uniform discretization Calculate different Time-varying Hamiltonian The energy difference between the first excited state energy and the ground state energy is used to find all... The smallest energy difference is taken as the first energy gap; ii. Under feasible conditions, adjust the coefficients of the problem Hamiltonian and update the time-varying Hamiltonian. Calculate the first bandgap according to the method in step i; iii. Find the coefficient of the problem Hamiltonian corresponding to the maximum value of the first bandgap, adjust the problem Hamiltonian, update the time-varying Hamiltonian, and take the updated time-varying Hamiltonian as the maximized time-varying Hamiltonian. Step S4: Prepare the ground state of the initial Hamiltonian, and obtain the final state of the Hamiltonian based on the total evolution time of maximizing the time-varying Hamiltonian; The final state of the Hamiltonian The acquisition process is as follows: in, This represents the time-varying Hamiltonian that is maximized. To represent a complex unit, This represents the ground state of the initial Hamiltonian. , and All are Pauli The eigenstates of the operator, The corresponding eigenvalue is -1. The corresponding eigenvalue is 1. Represents a direct product; Step S5: Calculate the final state energy value of the Hamiltonian based on the adjusted Hamiltonian and the final state of the initial Hamiltonian. Use the Nelder-Mead algorithm to minimize the final state energy value of the Hamiltonian and determine the final state of the Hamiltonian corresponding to the minimum final state energy value. The specific process of minimizing the final state energy value of the Hamiltonian using the Nelder-Mead algorithm is as follows: A. Initialize the first and second coefficients of a set of expansion basis as the first vertex of the simplex; other vertices of the simplex are generated by adding random perturbations to the first vertex. B. Calculate the final state energy value of the Hamiltonian of each vertex on the simplex according to steps S4-S5, and arrange the vertices in ascending order of the final state energy value of the Hamiltonian. C. Based on the final energy value of the Hamiltonian, perform reflection, expansion, or contraction operations on the sorted vertices, updating the vertices until the maximum relative difference of the calculated final energy values of the Hamiltonian is less than [the maximum relative difference between the calculated final energy values of the Hamiltonian]. Find the final state of the Hamiltonian corresponding to the vertex with the minimum final state energy value; Step S6: Perform the following steps on each qubit in the final state of the Hamiltonian corresponding to the minimum final state energy value: Directional Pauli operator measurement extracts the number of binary bits for factorization, and combines this with a binary multiplication table to obtain the factors. Step S7: Combine the factorization with the cracked RSA public key exponent to determine the private key, thus completing the RSA public key cracking.
2. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 1, characterized in that, The calculation process for the final energy value of the Hamiltonian is as follows: 。 3. The RSA public key cracking method based on CRAB quantum algorithm optimization according to claim 1, characterized in that, The calculation process for the private key is as follows: in, This represents the index of the cracked RSA public key. This represents the private key. Represents Euler's totient function. .
4. A computer-readable storage medium storing a computer program, characterized in that, The computer program causes the computer to execute the RSA public key cracking method based on the CRAB quantum algorithm optimization as described in any one of claims 1-3.
5. An electronic device, characterized in that, include: The memory, the processor, and the computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the RSA public key cracking method based on the CRAB quantum algorithm as described in any one of claims 1-3.
Citation Information
Patent Citations
Large integer decomposition problem mapping method and system based on Isin model
CN115514488A
Integer decomposition method based on quantum approximate optimization algorithm
CN119743261A