Method and electronic device for simulating a cryptographic attack operation

By generating simulated cryptographic attack data and attack paths using a generator model, the problem of low accuracy in simulating cryptographic attack operations in existing technologies is solved, achieving more efficient and flexible simulation results.

CN120856355BActive Publication Date: 2026-01-27LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511343299.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-19
Publication Date
2026-01-27
Estimated Expiration
2045-09-19

AI Technical Summary

Technical Problem

Existing methods for simulating cryptographic attacks rely on fixed mathematical models or rules, which are difficult to adapt to the dynamic changes in cryptographic attack methods, resulting in low simulation accuracy.

Method used

By acquiring cryptographic attack data, a generator model is used to generate simulated cryptographic attack data. A cryptographic state parameter sequence is generated based on the initial cryptographic state parameter set, and a simulated attack path for cryptographic attack operations is generated based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set.

Benefits of technology

It improves the efficiency and flexibility of simulating cryptographic attacks, enabling dynamic simulation of the cryptographic attack process and enhancing simulation accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856355B_ABST
    Figure CN120856355B_ABST
Patent Text Reader

Abstract

The application discloses a password attack operation simulation method and electronic equipment, and relates to the technical field of cryptography, and comprises the following steps: inputting acquired password attack data into a generator model to obtain simulated password attack data, so that the generator model can be used to quickly simulate password attack operations, and the simulation efficiency of the password attack operations is improved; a password state parameter sequence is generated based on initial password state parameter groups in the simulated password attack data, and a simulated attack path of the password attack operation is generated according to the password state parameter sequence and a simulated password attack feature set in the simulated password attack data, so that the purpose of simulating the dynamic changes of the password attack process by using the password state parameter sequence is achieved, the flexibility of the password attack operation simulation process is improved, the simulation precision of the password attack operation is improved, and the problem that the simulation precision of the password attack operation is low due to the single content of the existing password attack operation simulation mode is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cryptography technology, and in particular to a method and electronic device for simulating cryptographic attack operations. Background Technology

[0002] With the rapid development of information technology, the scale of data storage, transmission, and processing has exploded. Enterprises often enhance data security by encrypting massive amounts of data and test the security of passwords by simulating various cryptographic attack methods on the encrypted data.

[0003] However, traditional methods for simulating cryptographic attacks typically rely on mathematical formulas for modeling to quantify and simulate attacks, or on pre-defined attack rules to simulate attack paths. However, these techniques, which rely on pre-set mathematical models or attack rules, struggle to adapt to evolving attack methods. In other words, the simulation methods used in these techniques rely on fixed attack strategies, failing to simulate dynamic changes in cryptographic attacks, thus resulting in low simulation accuracy. Summary of the Invention

[0004] This application provides a method and electronic device for simulating cryptographic attack operations, in order to at least solve the problem of low simulation accuracy of cryptographic attack operations in related technologies.

[0005] This application provides a method for simulating cryptographic attack operations, comprising: acquiring cryptographic attack data; inputting the cryptographic attack data into a generator model to obtain simulated cryptographic attack data, wherein the simulated cryptographic attack data includes an initial cryptographic state parameter set and a simulated cryptographic attack feature set; generating a cryptographic state parameter sequence based on the initial cryptographic state parameter set; and generating a simulated attack path for the cryptographic attack operation based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set.

[0006] This application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of a simulation method for any of the above-described cryptographic attack operations.

[0007] This application allows the acquisition of cryptographic attack data to be input into a generator model to obtain simulated cryptographic attack data. This enables the generator model to quickly simulate cryptographic attack operations, improving the simulation efficiency. Based on the initial cryptographic state parameter set in the simulated cryptographic attack data, a cryptographic state parameter sequence is generated. Then, based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set in the simulated cryptographic attack data, a simulated attack path for the cryptographic attack operation is generated. This achieves the goal of simulating the dynamic changes of the cryptographic attack process using the cryptographic state parameter sequence, improving the flexibility of the cryptographic attack operation simulation process and thus enhancing the simulation accuracy. This solves the problem of low simulation accuracy caused by the limited content of existing cryptographic attack operation simulation methods. Attached Figure Description

[0008] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0009] Figure 1 A hardware structure block diagram of a server device for simulating a cryptographic attack operation, provided in an embodiment of this application;

[0010] Figure 2 This is a flowchart of an optional method for simulating a cryptographic attack operation according to an embodiment of this application;

[0011] Figure 3 A flowchart illustrating another optional method for simulating a cryptographic attack operation according to an embodiment of this application;

[0012] Figure 4 This is a flowchart illustrating another optional method for simulating a cryptographic attack operation according to an embodiment of this application;

[0013] Figure 5 This is a schematic diagram of the structure of a simulation model of an optional cryptographic attack operation according to an embodiment of this application;

[0014] Figure 6 This is a schematic diagram of the structure of a simulation model of another optional cryptographic attack operation according to an embodiment of this application;

[0015] Figure 7 This is a flowchart illustrating another optional method for simulating a cryptographic attack operation according to an embodiment of this application;

[0016] Figure 8 This is a schematic diagram of an optional method for simulating a cryptographic attack operation according to an embodiment of this application;

[0017] Figure 9 This is a structural block diagram of a device for simulating a cryptographic attack operation according to an embodiment of this application;

[0018] Figure 10 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0020] It should be noted that, in the description of this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. The terms "first," "second," etc., in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0021] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0022] The methods and embodiments provided in this application can be executed on a server device or a similar computing device. Taking running on a server device as an example, Figure 1 This is a hardware structure block diagram of a computer device for simulating a cryptographic attack operation according to an embodiment of this application. Figure 1 As shown, the server device may include one or more ( Figure 1 Only one is shown in the image. A processor 102 (which may include, but is not limited to, a central processing unit (CPU), microprocessor (MCU), or programmable logic device (FPGA), etc.) and a memory 104 for storing data are also shown. The server device may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the server equipment described above. For example, the server equipment may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0023] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the cryptographic attack simulation method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the aforementioned cryptographic attack simulation method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to server devices via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0024] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the server device. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0025] This embodiment provides a method for simulating cryptographic attack operations, such as... Figure 2 As shown, the method includes:

[0026] S202, Obtain password attack data;

[0027] Optionally, in this embodiment, the aforementioned password attack data may be, but is not limited to, data generated or used during the execution of the password attack operation when the password data is attacked, such as a password list containing candidate passwords, encryption algorithms for the passwords to be cracked, candidate password arrangement rules, password cracking strategies, etc. Optionally, the aforementioned password attack data may be data generated or used before the simulation process of the password attack operation is executed.

[0028] S204, Input the cryptographic attack data into the generator model to obtain simulated cryptographic attack data, wherein the simulated cryptographic attack data includes the initial cryptographic state parameter set and the simulated cryptographic attack feature set;

[0029] Optionally, in this embodiment, the generator model described above may be, but is not limited to, a pre-trained neural network model used to generate simulated cryptographic attack data based on real cryptographic attack data, wherein the simulated cryptographic attack data and the real cryptographic attack data have the same data distribution. The initial cryptographic state parameters in the initial cryptographic state parameter set may be, but are not limited to, parameters used to record the life state of candidate cryptographic keys for cracking, such as candidate cryptographic key length, candidate cryptographic key hit count, candidate cryptographic key entropy, candidate cryptographic key encryption method, etc. The simulated cryptographic attack feature set described above may include, but is not limited to, various types of simulated cryptographic attack features. These simulated cryptographic attack features may be, but are not limited to, data related to the simulated cryptographic attack operation during the simulation process, such as the attack step type, step priority, hit rate, and number of step attempts. Optionally, these simulated cryptographic attack features can be used to predict cryptographic attack efficiency or cryptographic attack hit rate, etc., to determine the simulation accuracy of the cryptographic attack operation.

[0030] S206, Generate a sequence of cryptographic state parameters based on the initial cryptographic state parameter group;

[0031] Optionally, in this embodiment, the aforementioned password state parameter sequence may include, but is not limited to, a set of timestamps and a corresponding set of password state parameters for each timestamp. The set of timestamps may, but is not limited to, multiple time points with the same time interval, and the password state parameters in the corresponding set of password state parameters for each timestamp may, but are not limited to, describe the password state of the candidate password at each timestamp. For example, the password state parameters may be the number of candidate passwords, the hit rate, the number of hits, and the matching degree. Here, the hit rate refers to the probability that a candidate password matches the password to be cracked; the number of hits refers to the number of times a candidate password matches the password to be cracked; and the matching degree refers to the degree of consistency between the candidate password and the password to be cracked.

[0032] S208. Based on the sequence of cryptographic state parameters and the set of simulated cryptographic attack features, generate a simulated attack path for the cryptographic attack operation.

[0033] Optionally, in this embodiment, the simulated attack path described above can be used, but is not limited to, to describe the process from obtaining a candidate password to successfully cracking the password to be cracked. The password state parameter sequence described above can be used, but is not limited to, to generate the simulation results of the execution state of the password attack operation at each timestamp in the simulated attack path. For example, the password state parameters in the password state parameter group corresponding to each timestamp in the above password state parameter sequence can be used to generate the usage status of the candidate password at each timestamp in the simulated attack path, such as the number of hits, matching degree, and the number of unused candidate passwords. The simulated password attack features in the simulated password attack feature set described above can be used, but is not limited to, to generate the execution status of the password attack steps at different attack stages in the simulated attack path, such as the number of attack steps, the execution time of the attack steps, and the execution order of the attack steps at different attack stages.

[0034] The embodiments provided in this application input the acquired cryptographic attack data into a generator model to obtain simulated cryptographic attack data. This allows for the rapid simulation of cryptographic attack operations using the generator model, improving the simulation efficiency of cryptographic attack operations. A cryptographic state parameter sequence is generated based on the initial cryptographic state parameter set in the simulated cryptographic attack data. Furthermore, a simulated attack path for the cryptographic attack operation is generated based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set in the simulated cryptographic attack data. This achieves the goal of simulating the dynamic changes in the cryptographic attack process using the cryptographic state parameter sequence, improving the flexibility of the cryptographic attack operation simulation process and ultimately enhancing the simulation accuracy of the cryptographic attack operation. This solves the problem of low simulation accuracy caused by the limited content of existing cryptographic attack operation simulation methods.

[0035] As an optional implementation, generating a sequence of cryptographic state parameters based on the initial cryptographic state parameter set includes:

[0036] Add the initial password state parameter group to the initial password state parameter sequence, and perform the following operations on the password state parameter group in the initial password state parameter sequence:

[0037] The i-th cryptographic state parameter group is determined from the initial cryptographic state parameter sequence, where i is a natural number greater than or equal to 1 and less than or equal to N, and N is the threshold number of cryptographic state parameter groups included in the initial cryptographic state parameter sequence.

[0038] Update the i-th password state parameter group to obtain the updated i-th password state parameter group;

[0039] The updated i-th password state parameter group is determined as the (i+1)-th password state parameter group, and the (i+1)-th password state parameter group is added to the initial password state parameter sequence;

[0040] If the number of cryptographic state parameter groups in the initial cryptographic state parameter sequence reaches a certain threshold, the initial cryptographic state parameter sequence is determined as the cryptographic state parameter sequence.

[0041] Optionally, in this embodiment, the password state parameter sequence may include, but is not limited to, multiple password state parameter groups. Each password state parameter group may include various types of password state parameters, and each password state parameter group may correspond to a timestamp. Different password state parameter groups may correspond to different timestamps. It is understood that in the password state parameter sequence, the timestamp corresponding to the i-th password state parameter group may be earlier than the timestamp corresponding to the (i+1)-th password state parameter group.

[0042] Optionally, in this embodiment, the updated i-th password state parameter set can be, but is not limited to, calculated based on the i-th password state parameter set in combination with password distribution patterns. Optionally, the password distribution patterns here can be, but are not limited to, the statistical patterns exhibited by password distribution characteristics such as character combinations, lengths, and character types when users set passwords.

[0043] Optionally, in this embodiment, the i-th cryptographic state parameter group may correspond to, but is not limited to, the i-th timestamp, and the (i+1)-th cryptographic state parameter group may correspond to, but is not limited to, the (i+1)-th timestamp. The time interval between two adjacent timestamps may remain unchanged. For example, the time interval between the i-th timestamp and the (i+1)-th timestamp may be the same as the time interval between the i-th timestamp and the (i-1)-th timestamp in the cryptographic state parameter sequence.

[0044] Optionally, in this embodiment, the aforementioned quantity threshold can be the maximum number of password state parameter groups that the password state parameter sequence can include, or it can be determined based on the password cracking time in the password attack data. For example, if the password attack data indicates that the average password cracking time is 200ms, then when the adjacent timestamps are 10ms, the aforementioned quantity threshold can be 20.

[0045] The embodiments provided in this application construct an initial cryptographic state parameter sequence using an initial cryptographic state parameter set, and calculate the cryptographic state parameter set for the next moment using the cryptographic state parameter set from the previous moment in the initial cryptographic state parameter sequence. This enables the calculation of the cryptographic state parameter sequence using the initial cryptographic state parameter set, thereby achieving iterative updates of the cryptographic state parameters. The dynamic changes in the execution state of a cryptographic attack operation are simulated through the cryptographic state parameter sequence, making the simulation results of the cryptographic attack operation closer to the actual cryptographic attack process and improving the simulation accuracy of the cryptographic attack operation.

[0046] As an optional implementation, updating the i-th cryptographic state parameter group to obtain the updated i-th cryptographic state parameter group includes:

[0047] Determine the number of candidate passwords and the matching degree of the i-th password from the i-th password state parameter group;

[0048] The number of candidate passwords for the i-th password is verified to obtain the verification result;

[0049] If the verification result indicates that the number of candidate passwords of the i-th candidate password has passed the verification, the filtering ratio coefficient is calculated based on the i-th matching degree, and the first update candidate password number is determined by multiplying the filtering ratio coefficient and the number of candidate passwords of the i-th candidate password. There is a negative correlation between the filtering ratio coefficient and the i-th matching degree.

[0050] Based on the number of first updated candidate passwords and the number of i-th candidate passwords, the matching degree difference is calculated, and the matching degree difference and the i-th matching degree are used to determine the updated i-th matching degree.

[0051] If the updated matching degree of the i-th candidate password is less than the matching degree threshold, the number of candidate passwords for the first update is determined as the number of candidate passwords for the i-th candidate password after the update.

[0052] If the updated i-th matching degree is greater than or equal to the matching degree threshold, the number of the second update candidate password is calculated based on the correction ratio coefficient and the number of the first update candidate password, and the number of the second update candidate password is determined as the number of the updated i-th candidate password.

[0053] The updated matching degree and the updated number of candidate passwords are used to determine the updated password state parameter group for the i-th password.

[0054] Optionally, in this embodiment, the number of candidate passwords can refer to the total number of plaintext passwords used to attempt to crack the password to be cracked during the password attack process. The matching degree can refer to the similarity or degree of matching between the candidate password and the target password hash value, used to assess the closeness between the candidate password and the target password. In this embodiment, the matching degree is used to indicate the similarity between the candidate password and the password to be cracked.

[0055] Optionally, in this embodiment, the above verification may refer to, but is not limited to, the process of determining whether the number of candidate passwords meets the validity requirement, in order to determine whether the number of candidate passwords is normal. The validity judgment condition here may be, but is not limited to, determined based on the password distribution pattern; for example, the validity judgment condition may be that the number of candidate passwords is greater than 0. The above screening ratio coefficient may be, but is not limited to, the proportion of the number of candidate passwords after screening to the original number of candidate passwords. The above-mentioned first updated candidate password number may be, but is not limited to, the product of the screening ratio coefficient and the number of the i-th candidate password, used to indicate the number of candidate passwords after screening.

[0056] Optionally, in this embodiment, the matching degree difference may, but is not limited to, have a positive correlation with the ratio between the number of first updated candidate passwords and the number of i-th candidate passwords; that is, the larger the screening ratio coefficient, the larger the matching degree difference. For example, the formula for calculating the matching degree may be as shown in formula (1):

[0057] (1)

[0058] in, The difference in matching degree. Let be the number of candidate passwords for the i-th password. This represents the number of candidate passwords for the first update.

[0059] Optionally, the calculation process for the updated i-th matching degree can be as shown in formula (2):

[0060] (2)

[0061] in, For the updated i-th matching degree, For the i-th matching degree, This represents the difference in matching degree.

[0062] Optionally, in this embodiment, the aforementioned matching degree threshold can be used, but is not limited to, to indicate the cracking status of the password to be cracked, such as the password status being "to be cracked" or "close to being cracked". The aforementioned correction ratio coefficient can be used, but is not limited to, to reduce the number of candidate passwords when the updated matching degree is too high, so as to improve password cracking efficiency and reduce unnecessary resource consumption.

[0063] As an optional approach, the update process for the i-th cryptographic state parameter group can be as follows: Figure 3As shown in steps S302 to S316, after obtaining the number of candidate passwords and the matching degree of the i-th password, it is determined whether the number of candidate passwords is positive. If not, the update operation of the i-th password state parameter group is interrupted; if so, a filtering ratio coefficient is calculated based on the matching degree of the i-th password, and the product of the filtering ratio coefficient and the number of candidate passwords of the i-th password is determined as the first updated candidate password number. Subsequently, the matching degree difference is calculated based on the first updated candidate password number and the number of candidate passwords of the i-th password, and the updated i-th matching degree is calculated using the matching degree difference. Finally, the updated i-th matching degree is compared with the threshold to determine whether the updated i-th matching degree is too high. If the updated i-th matching degree is normal, the number of first updated candidate passwords is determined as the number of updated i-th candidate passwords to obtain the updated i-th password state parameter set. If the updated i-th matching degree is too high, the number of first updated candidate passwords is reduced using a correction ratio coefficient, and the reduced number of candidate passwords is used as the number of updated i-th candidate passwords to calculate the number of updated i-th candidate passwords based on the number of first updated candidate passwords.

[0064] The embodiments provided in this application determine the iterative update rules for the number of candidate passwords and the matching degree by combining the password distribution rules. The number of candidate passwords and the matching degree are verified by combining the validity verification conditions and the threshold verification conditions, so as to avoid the abnormal value of the password state parameter during the update process and improve the flexibility and accuracy of the password state parameter.

[0065] As an optional implementation method, such as Figure 4 As shown, before obtaining password attack data, the process also includes:

[0066] S402, Obtain the first sample password attack dataset;

[0067] S404, Construct the initial generator model, whereby the initial generator model is used to generate simulated sample cryptographic attack data based on the first sample cryptographic attack dataset;

[0068] S406, Construct an initial discriminator model, wherein the initial discriminator model is used to compare the sample cryptographic attack data in the first sample cryptographic attack dataset with the simulated sample cryptographic attack data to obtain the comparison result;

[0069] S408, based on the first sample cryptographic attack dataset, trains the initial generator model and the initial discriminator model until the generator model and discriminator model that meet the training convergence condition are obtained.

[0070] Optionally, in this embodiment, the aforementioned first sample cryptographic attack dataset may include, but is not limited to, various types of sample cryptographic attack data. The type can be a data format, such as numerical values ​​or vectors, or the object type described by the sample cryptographic attack data, such as attack steps, attack targets, or attack results. Optionally, the aforementioned sample cryptographic attack data may, but is not limited to, be used to provide a data learning basis for the generative adversarial network model, so that the network model can learn the data distribution of the sample cryptographic attack data and thereby generate simulated sample cryptographic attack data with the same data distribution as the sample cryptographic attack data.

[0071] Optionally, in this embodiment, the aforementioned generative adversarial network may include, but is not limited to, a generator model and a discriminator model. Through adversarial training between these two models, the generator model learns the distribution of real data, enabling it to generate samples that are difficult to distinguish from real data, thus simulating real samples. Specifically, the generator model may, but is not limited to, incorporate random noise vectors to learn the data distribution in the sample data, thereby outputting simulated data with a similar data distribution to the sample data, making it difficult for the discriminator model to distinguish between real and simulated data. The discriminator model may, but is not limited to, compare the simulated data output by the generator model with the real data and output a probability value indicating the similarity between the simulated and real data, accurately distinguishing between the simulated and real data generated by the generator model.

[0072] Optionally, in this embodiment, the model structure of the generator model described above can be as follows: Figure 5 As shown, the generator model can include an input layer, a hidden layer, and an output layer. The input layer receives sample data in 128-dimensional vector format. The hidden layer uses a linear activation function to map the 128-dimensional sample data received by the input layer to a 256-dimensional space, facilitating the learning of data distribution relationships between sample data. The output layer uses an activation function to map the 256-dimensional vector output by the hidden layer to the same 128-dimensional space as the input sample data, obtaining a 128-dimensional simulated sample cryptographic attack data vector. The activation function introduces a key nonlinear component to determine whether and with what data distribution the signal is passed to the next neuron. The activation function overcomes the limitations of linear models, allowing generative adversarial networks to learn and approximate complex nonlinear relationships, thereby improving the network model's expressive power and data fitting ability. For example, the activation function here could be the ReLU activation function, the Tanh activation function, etc.

[0073] Optionally, in this embodiment, the model structure of the discriminator model described above can be as follows: Figure 6As shown, the discriminator model can include an input layer, a hidden layer, and an output layer. The input layer receives a 128-dimensional sample cryptographic attack data vector and a 128-dimensional simulated sample cryptographic attack data vector generated by the generator. The hidden layer uses an activation function to map the data received by the input layer to a high-dimensional space, such as a 512-dimensional data space, to prevent gradient vanishing. The output layer maps the high-dimensional vector generated by the hidden layer to a low-dimensional space, such as a 1-dimensional space, to improve the similarity between the output sample cryptographic attack data vector and the simulated sample cryptographic attack data vector. This similarity is used to determine whether the input data is real sample cryptographic attack data or simulated sample cryptographic attack data. For example, when the similarity is close to 1, the input to the discriminator model can be determined to be real sample cryptographic attack data; when the similarity is close to 0, the input to the discriminator model can be determined to be simulated sample cryptographic attack data generated by the generator model. In other words, the more similar the simulated sample cryptographic attack data generated by the generator model is to the real sample cryptographic attack data, the more difficult it is for the discriminator model to distinguish between the real sample cryptographic attack data and the simulated sample cryptographic attack data generated by the generator model.

[0074] Optionally, in this embodiment, the comparison result may be, but is not limited to, the probability generated by the discriminator model used to indicate the similarity between the sample cryptographic attack data vector and the simulated sample cryptographic attack data vector. The training convergence condition may be, but is not limited to, that the similarity between the sample cryptographic attack data vector and the simulated sample cryptographic attack data vector is greater than a preset threshold. Here, the similarity can be the Euclidean distance, Hamming distance, cosine similarity, Pearson correlation coefficient, etc., between the sample cryptographic attack data vector and the simulated sample cryptographic attack data vector.

[0075] The embodiments provided in this application pre-construct generator and discriminator models before simulating cryptographic attack operations, and train the original generator and discriminator models using sample cryptographic attack data. This allows the generator model to accurately learn the data distribution of real sample cryptographic attack data, thereby generating more accurate simulated cryptographic attack data and improving the precision and accuracy of the simulated cryptographic attack data.

[0076] As an optional implementation, training the initial generator model and the initial discriminator model based on the first sample cryptographic attack dataset includes:

[0077] The first sample cryptographic attack dataset is denoised to obtain the second sample cryptographic attack dataset.

[0078] Feature extraction is performed on each sample cryptographic attack data in the second sample cryptographic attack dataset to obtain a sample cryptographic attack feature set. The sample cryptographic attack features in the sample cryptographic attack feature set are used to indicate the sample attack path of the sample cryptographic attack operation.

[0079] The format conversion process is performed on each sample cryptographic attack feature in the sample cryptographic attack feature set to obtain the sample cryptographic attack feature vector set;

[0080] The initial generator model and the initial discriminator model are trained using the sample cryptographic attack feature vector set until the generator model and the discriminator model that meet the training convergence condition are obtained.

[0081] Optionally, in this embodiment, the denoising process described above may refer to, but is not limited to, the process of extracting noise or outliers from the sample cryptographic attack data included in the first sample cryptographic attack dataset to improve the purity and quality of the data. For example, the denoising methods may include, but are not limited to, median filtering, average filtering, outlier detection, etc.

[0082] Optionally, in this embodiment, the aforementioned feature extraction process may refer to, but is not limited to, the process of extracting data related to the cryptographic attack process from the various sample cryptographic attack data included in the second sample cryptographic attack dataset. For example, the extracted sample cryptographic attack features may be data related to cryptographic attack steps, cryptographic attack targets, and cryptographic attack results. Specifically, data related to the cryptographic attack target may include encryption algorithm type, number of candidate passwords, matching degree, etc.; data related to the cryptographic attack steps may include attack step type, attack step time, attack step priority, etc.; and data related to the cryptographic attack result may include password cracking result, password cracking time, number of password verification attempts, etc.

[0083] Optionally, in this embodiment, the above-mentioned format conversion process may refer to, but is not limited to, the standardization process of sample cryptographic attack features in different formats to obtain a sample cryptographic attack feature vector containing cryptographic attack information from the sample cryptographic attack features. Standardization is a data preprocessing method used to adjust feature values ​​of different magnitudes or ranges to a uniform scale to avoid large data processing errors caused by different data magnitudes or formats. For example, in this embodiment, the standardization process may be zero-mean standardization, decimal scaling standardization, etc.

[0084] Optionally, in this embodiment, after obtaining the sample cryptographic attack feature vector set, the sample cryptographic attack feature vector set can be divided according to a ratio to obtain a training set and a validation set. The initial generator model is trained using the training set, and the initial generator model and initial discriminator model are validated using the validation set.

[0085] The embodiments provided in this application perform denoising and feature extraction on the first sample cryptographic attack data before training the initial generator model and the initial discriminator model. This avoids redundant information and outliers in the original sample data from interfering with the model training process and causing poor model performance. Furthermore, the sample data after feature extraction is format-converted to avoid the interference caused by different formats, dimensions, and magnitudes of the training data, thereby improving the stability and efficiency of model training.

[0086] As an optional implementation, a simulated attack path for a cryptographic attack operation is generated based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set, including:

[0087] Multiple simulated attack steps were identified from the set of simulated cryptographic attack features;

[0088] Construct an initial attack path using multiple simulated attack steps;

[0089] Based on the sequence of password state parameters, the initial attack path is adjusted to obtain a simulated attack path.

[0090] Optionally, in this embodiment, the simulated attack steps may refer to, but are not limited to, multiple operations or methods used to simulate password attack operations and crack the password to be cracked during the simulation of password attack operations. The attack path may refer to, but is not limited to, a sequence of actions to achieve the purpose of password cracking by executing the above-mentioned multiple simulated attack steps. In this sequence of actions, each simulated attack step is arranged according to a certain step execution priority and the number of times it is executed. Further, the adjustment process of the initial attack path may refer to, but is not limited to, the process of adjusting the execution strategy of each simulated attack step in the initial attack path according to the password state parameter sequence. For example, the execution priority and number of times each simulated attack step in the initial attack path can be adjusted according to the password state parameter group corresponding to each timestamp in the password state parameter sequence. For example, when the matching degree in the password state parameter group is high, the number of times the simulated attack steps are executed can be reduced to reduce the operational complexity of the password attack process and improve the password cracking efficiency. The simulated attack path may include, but is not limited to, the step type, execution time, and operation parameters of each simulated attack step.

[0091] The embodiments provided in this application construct an initial attack path using multiple simulated attack steps identified from a set of simulated cryptographic attack features. The initial attack path is then adjusted based on a sequence of cryptographic state parameters to obtain a simulated attack path. This allows for dynamic adjustment of the simulated attack path in conjunction with the changes in cryptographic state reflected in the sequence of cryptographic state parameters. Consequently, the adjusted simulated attack path effectively simulates changes in cryptographic state during a cryptographic attack, meeting the actual requirements for simulating cryptographic attack operations and improving the simulation accuracy of cryptographic attack operations.

[0092] As an optional implementation, an initial attack path is constructed using multiple simulated attack steps, including:

[0093] Based on the attack stage to which each simulated attack step belongs, multiple simulated attack steps are divided into multiple simulated attack step sets, where different simulated attack step sets are matched with different attack stages.

[0094] According to the priority of each simulated attack step, the simulated attack steps in each simulated attack step set are sorted to obtain the adjusted simulated attack step sets.

[0095] Based on the adjusted set of simulated attack steps, an initial attack path is constructed.

[0096] Optionally, in this embodiment, the attack phase can be a phase used to perform different cryptographic attack tasks during the simulation of a cryptographic attack operation. For example, the attack phase can be a cryptographic space initialization phase, a cryptographic matching phase, a cryptographic verification phase, a result verification phase, etc. The cryptographic space initialization phase refers to determining the set of all possible values ​​of the cryptography during the cryptographic analysis or cryptographic cracking process. This set is called the cryptographic space, and the size of the cryptographic space directly determines the difficulty of cracking the cryptography. The size of the cryptographic space can be defined based on the characteristics of the encryption algorithm (such as cryptographic length, cryptographic character set, etc.). In the cryptographic matching phase, candidate cryptography can be matched with the cryptography to be cracked to determine the candidate cryptography that matches the cryptography to be cracked, thus completing the cracking of the cryptography to be cracked. The matching method can be direct cracking, dictionary attack, plaintext attack, etc. The cryptographic verification phase is used to further verify the determined candidate cryptography. The result verification phase is used to perform a secondary check or verification of the cracking result of the cryptography to be cracked after the candidate cryptography has passed verification, to ensure the accuracy and completeness of the cryptographic attack or analysis.

[0097] Optionally, in this embodiment, step priority refers to sorting each simulated attack step in a series of simulated attack steps according to cryptographic attack criteria (such as attack efficiency, resource consumption, etc.) to determine which simulated attack steps or tasks to execute first. It is understood that multiple simulated attack steps in the set of simulated attack steps matched for each attack stage can be arranged according to the execution order indicated by the step priority, with higher-priority simulated attack steps executed first and lower-priority simulated attack steps executed later.

[0098] Optionally, in this embodiment, the initial attack path may be, but is not limited to, a sequence of steps obtained by arranging the simulated attack steps in the adjusted set of simulated attack steps matched by each attack stage in the order of each attack stage.

[0099] The embodiments provided in this application divide the simulated attack steps into sets according to each attack stage, and sort the simulated attack steps in each set according to the priority of the steps, so as to construct an initial attack path using the adjusted set of simulated attack steps. By dividing the simulated attack steps according to the attack stage, the construction efficiency of the initial attack path is improved, and by sorting the simulated attack steps according to a certain priority, the more core simulated attack steps can be executed first, saving the resources required for the password cracking process.

[0100] As an optional implementation, the initial attack path is adjusted according to the sequence of cryptographic state parameters, including:

[0101] Based on the simulated attack time of each attack phase, determine the cryptographic state parameter group corresponding to the simulated attack time from the cryptographic state parameter sequence;

[0102] If the password state parameters in the password state parameter group meet the first adjustment condition, adjust the step execution strategy of each simulated attack step in the simulated attack step set matched by each attack stage.

[0103] Optionally, in this embodiment, the simulated attack time may refer to, but is not limited to, the time required to execute all simulated attack steps in the simulated attack step set corresponding to each attack stage, or the time point at which each simulated attack step in the simulated attack step set corresponding to each attack stage is executed. The aforementioned cryptographic state parameter set may refer to, but is not limited to, the cryptographic state parameter set corresponding to the time point of the simulated attack time in the cryptographic state parameter sequence.

[0104] Optionally, in this embodiment, the first adjustment condition may be, but is not limited to, the condition that the password state parameter in the password state parameter group is greater than a preset threshold. The step execution strategy refers to the rules and methods that determine the operation order, resource allocation, and execution method of the simulated attack steps. For example, the step execution strategy may be a sequential execution strategy for simulated attack steps, a resource allocation strategy, an execution condition configuration strategy, etc.

[0105] As an alternative approach, the adjustment conditions can differ for different attack phases. For example, during the cryptographic space initialization phase, the matching degree in the cryptographic state parameter group can be compared with a matching degree threshold. If the matching degree is greater than the matching degree threshold, it is determined that the adjustment condition has been met, and the execution count of each simulated attack step in the simulated attack step set corresponding to cryptographic space initialization is reduced. If the matching degree is less than or equal to the matching degree threshold, it is determined that the adjustment condition has not been met, and the execution count of each simulated attack step in the simulated attack step set corresponding to cryptographic space initialization is increased.

[0106] For example, during the password verification phase, the number of candidate passwords in the password state parameter group can be compared with the candidate password number threshold. If the number of candidate passwords is greater than the candidate password number threshold, it is determined that the adjustment condition has been met, and the execution count of each simulated attack step in the simulated attack step set corresponding to the password verification phase is increased. If the number of candidate passwords is less than or equal to the candidate password number threshold, it is determined that the adjustment condition has not been met, and the execution count of each simulated attack step in the simulated attack step set corresponding to the password verification phase is reduced.

[0107] The embodiments provided in this application utilize cryptographic state parameters to dynamically adjust the execution strategy of the simulated attack steps matched in each attack stage. This allows for adjustments to the execution of each simulated attack step based on the real-time changes in the cryptographic state during the execution of the simulated attack steps, thereby improving the accuracy and flexibility of the simulated attack path.

[0108] As an optional implementation, after generating the simulated attack path for the cryptographic attack operation based on the cryptographic state parameter sequence and the simulated cryptographic attack characteristics, the method further includes:

[0109] If the simulated attack path meets the second adjustment condition, the adjustment strategy is determined based on the simulated attack path, and the model parameters of the generator model are adjusted according to the adjustment strategy.

[0110] Optionally, in this embodiment, the second adjustment condition may refer to, but is not limited to, the execution status of the simulated attack steps corresponding to each attack stage in the simulated attack path meeting the preset adjustment conditions. The adjustment conditions may be used to indicate that there is an abnormal execution status of the simulated attack steps in the simulated attack path. For example, the adjustment conditions here may be that the number of times the simulated attack steps corresponding to each attack stage are executed is higher than a preset threshold, or that the execution time of the simulated attack steps corresponding to each attack stage is greater than a preset threshold.

[0111] Optionally, in this embodiment, the model parameters of the generator model may include, but are not limited to: convolution kernel size, bias weights of each layer, number of neural network layers, activation function, number of neurons in each layer, and random noise vector used by the generator model.

[0112] Optionally, in this embodiment, the adjustment strategy can be determined by combining cryptographic attack states such as cryptographic encryption algorithms and attack environment factors. Furthermore, the adjustment process of the generator model parameters can be implemented by repeatedly adjusting the generator model parameters according to a preset adjustment ratio and step size, to avoid excessively large single model parameter adjustments leading to a surge in resource consumption and consequently a decrease in cryptographic attack efficiency. Optionally, the adjustment ratio and step size can be dynamically adjusted based on the real-time simulated attack path. For example, if the matching degree of candidate passwords changes after the previous parameter adjustment in the simulated attack path, the next parameter adjustment continues; otherwise, the parameter adjustment process is interrupted or the adjustment ratio is appropriately increased.

[0113] Through the embodiments provided in this application, when the simulated attack path meets the second adjustment condition, the adjustment strategy is determined in a timely manner according to the simulated attack path, and the model parameters of the generator model are adjusted according to the adjustment strategy. This enables timely correction of the model parameters of the generator model in the event of an abnormal simulated attack path, avoiding more unnecessary resource consumption, and improving the simulation accuracy of cryptographic attack operations through the simulated attack path repair mechanism.

[0114] Specific combination Figure 7 To illustrate the implementation process of the simulation method for the above-mentioned cryptographic attack operation:

[0115] S702, obtain sample password attack data;

[0116] S704, preprocess the sample cryptographic attack data to obtain processed sample cryptographic attack data; the preprocessing process includes: denoising the sample cryptographic attack data to remove null values, noise, outliers, etc., and extracting features from the denoised sample cryptographic attack data to obtain sample cryptographic attack features; standardizing the sample cryptographic attack features to obtain a sample cryptographic attack feature set, wherein the sample cryptographic attack feature set includes multiple sample cryptographic attack feature vectors.

[0117] S706, Construct the initial generator model and the initial discriminator model. The initial generator model includes an input layer, a hidden layer, and an output layer. The input layer receives the cryptographic attack feature vectors of each sample, the hidden layer learns the data distribution information of the sample cryptographic attack feature vectors, and the output layer converts the simulated cryptographic attack data generated by the hidden layer into the same data space as the input sample cryptographic attack feature vectors. The initial discriminator model includes an input layer, an output layer, and a hidden layer. The input layer receives the simulated cryptographic attack data output by the initial generator model, the hidden layer compares the simulated cryptographic attack data with the sample cryptographic attack feature vectors, and the output layer converts the comparison result of the hidden layer into a similarity score with a value greater than or equal to 0 and less than or equal to 1.

[0118] S708, the initial generator model and the initial discriminator model are trained using the processed sample cryptographic attack data to obtain the generator model and the discriminator model; the training convergence condition of the initial generator model and the initial discriminator model is determined by the cosine similarity between the simulated cryptographic attack data and the sample cryptographic attack feature vectors. When the cosine similarity is greater than or equal to 0.9, the training convergence condition is determined to be met.

[0119] S710, Obtain password attack data; the password attack data is data with the same data distribution as the sample password attack data.

[0120] S712, input the cryptographic attack data into the generator model to obtain simulated cryptographic attack data. The simulated cryptographic attack data includes an initial cryptographic state parameter set and a simulated cryptographic attack feature set. The cryptographic state parameters in the initial cryptographic state parameter set are parameters used to describe the initial state of candidate cryptographics, including the number of candidate cryptographics, matching degree, etc. The simulated cryptographic attack feature set includes feature data related to cryptographic attack steps, such as attack step type and attack step priority.

[0121] S714, Generate a password state parameter sequence using the initial password state parameter set; Use the initial password state parameters as the password state parameter set corresponding to the initial time point, and calculate the password state parameter set for the next time point using the initial password state parameter set; Calculate the password state parameter set corresponding to the next time point using the password state parameter set corresponding to the previous time point, until the number of password state parameter sets reaches a preset threshold; Add the calculated password state parameter sets corresponding to all time points to the password state parameter sequence.

[0122] S716. Based on the sequence of cryptographic state parameters and the set of simulated cryptographic attack features, generate a simulated attack path for the cryptographic attack operation; divide each simulated attack step in the set of simulated cryptographic attack features into a set of simulated attack steps corresponding to each attack stage, and sort them according to the priority of each simulated attack step; construct an initial attack path using the sorted simulated attack steps, and adjust the initial attack path according to the set of cryptographic state parameters corresponding to the execution time of each simulated attack path to obtain the simulated attack path.

[0123] Optionally, the simulation method for the above-mentioned cryptographic attack operations can be, but is not limited to, through methods such as... Figure 8 The cryptographic attack simulation system shown is used to implement this, and includes: a data preprocessing module 802, a model building module 804, an attack state simulation module 806, and an attack path simulation module 808. Before simulating the cryptographic attack, during the training of the generator model, the data preprocessing module may, but is not limited to, acquire sample cryptographic attack data and preprocess it to obtain processed sample cryptographic attack data. The model building module may, but is not limited to, construct an initial generator model and an initial discriminator model, and train the initial generator model and initial discriminator model using the processed sample cryptographic attack data to obtain the generator model and discriminator model. During the simulation of the cryptographic attack, the data preprocessing module may, but is not limited to, acquire cryptographic attack data. The model building module may, but is not limited to, input the cryptographic attack data into the generator model to obtain simulated cryptographic attack data. The attack state simulation module may, but is not limited to, generate a sequence of cryptographic state parameters using the initial cryptographic state parameter set. The attack path simulation module can, but is not limited to, generate simulated attack paths for cryptographic attack operations based on a sequence of cryptographic state parameters and a set of simulated cryptographic attack features.

[0124] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method.

[0125] Based on this understanding, the technical solution of this application, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of this application.

[0126] This embodiment also provides a device for simulating cryptographic attacks, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0127] Figure 9 This is a structural block diagram of a device for simulating a cryptographic attack operation according to an embodiment of this application; as shown... Figure 9 As shown, the device includes:

[0128] The first acquisition unit 902 is used to acquire password attack data;

[0129] The input unit 904 is used to input cryptographic attack data into the generator model to obtain simulated cryptographic attack data, wherein the simulated cryptographic attack data includes an initial cryptographic state parameter set and a simulated cryptographic attack feature set.

[0130] The first generation unit 906 is used to generate a sequence of cryptographic state parameters based on the initial cryptographic state parameter group;

[0131] The second generation unit 908 is used to generate a simulated attack path for a cryptographic attack operation based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set.

[0132] As an optional solution, the first generating unit 906 mentioned above includes:

[0133] The first processing module is used to add the initial password state parameter group to the initial password state parameter sequence, and perform the following operations on the password state parameter groups in the initial password state parameter sequence: determine the i-th password state parameter group from the initial password state parameter sequence, where i is a natural number greater than or equal to 1 and less than or equal to N, and N is the threshold number of password state parameter groups included in the initial password state parameter sequence; update the i-th password state parameter group to obtain the updated i-th password state parameter group; determine the updated i-th password state parameter group as the (i+1)-th password state parameter group, and add the (i+1)-th password state parameter group to the initial password state parameter sequence; if the number of password state parameter groups in the initial password state parameter sequence reaches the threshold number, determine the initial password state parameter sequence as the password state parameter sequence.

[0134] As an optional solution, the above processing module includes: a first determining submodule, used to determine the number of the i-th candidate passwords and the i-th matching degree from the i-th password state parameter group; a verification submodule, used to verify the number of the i-th candidate passwords to obtain a verification result; a first processing submodule, used to calculate a screening ratio coefficient based on the i-th matching degree when the verification result indicates that the number of the i-th candidate passwords has passed the verification, and to determine the number of the first updated candidate passwords by multiplying the screening ratio coefficient by the number of the i-th candidate passwords, wherein there is a negative correlation between the screening ratio coefficient and the i-th matching degree; and a second processing submodule, used to calculate a matching degree based on the number of the first updated candidate passwords and the number of the i-th candidate passwords. The first submodule is used to determine the updated i-th matching degree by taking the matching degree difference and using the matching degree difference with the i-th matching degree; the second determining submodule is used to determine the number of first updated candidate passwords as the number of updated i-th candidate passwords when the updated i-th matching degree is less than the matching degree threshold; the third processing submodule is used to calculate the number of second updated candidate passwords based on the correction ratio coefficient and the number of first updated candidate passwords when the updated i-th matching degree is greater than or equal to the matching degree threshold, and determine the number of second updated candidate passwords as the number of updated i-th candidate passwords; the third determining submodule is used to determine the updated i-th matching degree and the updated number of i-th candidate passwords as the updated i-th password state parameter group.

[0135] As an optional solution, the above-mentioned apparatus further includes: a second acquisition unit for acquiring a first sample cryptographic attack dataset; a first construction unit for constructing an initial generator model, wherein the initial generator model is used to generate simulated sample cryptographic attack data based on the first sample cryptographic attack dataset; a second construction unit for constructing an initial discriminator model, wherein the initial discriminator model is used to compare the sample cryptographic attack data in the first sample cryptographic attack dataset with the simulated sample cryptographic attack data to obtain a comparison result; and a training unit for training the initial generator model and the initial discriminator model based on the first sample cryptographic attack dataset until a generator model and a discriminator model that satisfy the training convergence condition are obtained.

[0136] As an optional approach, the training unit includes: a denoising module for denoising the first sample cryptographic attack dataset to obtain a second sample cryptographic attack dataset; an extraction module for extracting features from each sample cryptographic attack data in the second sample cryptographic attack dataset to obtain a sample cryptographic attack feature set, wherein the sample cryptographic attack features in the sample cryptographic attack feature set are used to indicate the sample attack path of the sample cryptographic attack operation; a second processing module for performing format conversion processing on each sample cryptographic attack feature in the sample cryptographic attack feature set to obtain a sample cryptographic attack feature vector set; and a training module for training the initial generator model and the initial discriminator model using the sample cryptographic attack feature vector set until a generator model and a discriminator model that meet the training convergence condition are obtained.

[0137] As an optional solution, the second generation unit 908 includes: a determining module for determining multiple simulated attack steps from a set of simulated cryptographic attack features; a constructing module for constructing an initial attack path using the multiple simulated attack steps; and an adjusting module for adjusting the initial attack path according to a sequence of cryptographic state parameters to obtain a simulated attack path.

[0138] As an optional approach, the aforementioned construction module includes: a partitioning submodule, used to divide multiple simulated attack steps into multiple simulated attack step sets according to the attack stage to which each simulated attack step belongs, wherein different simulated attack step sets are matched with different attack stages; a sorting submodule, used to sort the simulated attack steps in each simulated attack step set according to the step priority corresponding to each simulated attack step, to obtain adjusted simulated attack step sets; and a construction submodule, used to construct an initial attack path based on the adjusted simulated attack step sets.

[0139] As an optional solution, the above adjustment module includes: a fourth determining submodule, used to determine the password state parameter group corresponding to the simulated attack time from the password state parameter sequence based on the simulated attack time of each attack stage; and an adjustment submodule, used to adjust the step execution strategy of each simulated attack step in the simulated attack step set matched by each attack stage when the password state parameters in the password state parameter group meet the first adjustment condition.

[0140] As an optional solution, the above-mentioned device further includes: an adjustment unit, used to determine an adjustment strategy based on the simulated attack path when the simulated attack path meets the second adjustment condition, and to adjust the model parameters of the generator model according to the adjustment strategy.

[0141] For a description of the features in the embodiment corresponding to the simulating device for cryptographic attack operations, please refer to the relevant description in the embodiment corresponding to the simulating method for cryptographic attack operations, which will not be repeated here.

[0142] Embodiments of this application also provide an electronic device, such as... Figure 10 As shown, it includes a memory and a processor, the memory storing a computer program, and the processor being configured to run the computer program to perform the steps in the simulation method embodiment of any of the above-described cryptographic attack operations.

[0143] Embodiments of this application also provide a computer-readable storage medium storing a computer program configured to execute the steps in the simulation method embodiments of any of the above-described cryptographic attack operations when run.

[0144] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0145] Embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in the simulation method embodiment of any of the above-described cryptographic attack operations.

[0146] Embodiments of this application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps in the simulation method embodiment of any of the above-described cryptographic attack operations.

[0147] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0148] The above provides a detailed description of a method for simulating cryptographic attacks provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only intended to help understand the method and core ideas of this application. It should be noted that those skilled in the art can make various improvements and modifications to this application without departing from its principles, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A method for simulating cryptographic attack operations to test the security of cryptography, characterized in that, include: Obtain password attack data; The cryptographic attack data is input into the generator model to obtain simulated cryptographic attack data. The simulated cryptographic attack data includes an initial cryptographic state parameter set and a simulated cryptographic attack feature set. The initial cryptographic state parameters included in the initial cryptographic state parameter set are used to indicate the life state of candidate cryptographics. The simulated cryptographic attack features included in the simulated cryptographic attack feature set are data related to the simulated cryptographic attack operation during the simulation process. Add the initial password state parameter group to the initial password state parameter sequence; Based on the i-th cryptographic state parameter group in the initial cryptographic state parameter sequence, the (i+1)-th cryptographic state parameter group is calculated and added to the initial cryptographic state parameter sequence, where i is a natural number greater than or equal to 1 and less than or equal to N, and N is the threshold number of cryptographic state parameter groups included in the initial cryptographic state parameter sequence. If the number of the cryptographic state parameter groups in the initial cryptographic state parameter sequence reaches the number threshold, the initial cryptographic state parameter sequence is determined as a cryptographic state parameter sequence. Based on the sequence of cryptographic state parameters and the set of simulated cryptographic attack features, a simulated attack path for the cryptographic attack operation is generated.

2. The method according to claim 1, characterized in that, The calculation of the (i+1)th cryptographic state parameter group based on the i-th cryptographic state parameter group in the initial cryptographic state parameter sequence includes: The i-th cryptographic state parameter group is determined from the initial cryptographic state parameter sequence, where i is a natural number greater than or equal to 1 and less than or equal to N, and N is the threshold number of cryptographic state parameter groups included in the initial cryptographic state parameter sequence. The i-th password state parameter group is updated to obtain the updated i-th password state parameter group; The updated i-th password state parameter group is determined as the (i+1)-th password state parameter group, and the (i+1)-th password state parameter group is added to the initial password state parameter sequence.

3. The method according to claim 2, characterized in that, The step of updating the i-th password state parameter group to obtain the updated i-th password state parameter group includes: The number of candidate passwords and the matching degree of the i-th password are determined from the i-th password state parameter group; The number of the i-th candidate password is verified to obtain the verification result; If the verification result indicates that the number of the i-th candidate passwords has passed the verification, a screening ratio coefficient is calculated based on the i-th matching degree, and the first update candidate password number is determined by multiplying the screening ratio coefficient and the number of the i-th candidate passwords. There is a negative correlation between the screening ratio coefficient and the i-th matching degree. Based on the number of the first updated candidate passwords and the number of the i-th candidate passwords, the matching degree difference is calculated, and the updated i-th matching degree is determined by using the matching degree difference and the i-th matching degree. If the updated i-th matching degree is less than the matching degree threshold, the number of the first updated candidate passwords is determined as the number of the updated i-th candidate passwords. If the updated i-th matching degree is greater than or equal to the matching degree threshold, the second update candidate password number is calculated based on the correction ratio coefficient and the first update candidate password number, and the second update candidate password number is determined as the updated i-th candidate password number. The updated i-th matching degree and the updated i-th candidate password number are determined as the updated i-th password state parameter group.

4. The method according to claim 1, characterized in that, Before obtaining the password attack data, the following is also included: Obtain the first sample of the password attack dataset; Construct an initial generator model, wherein the initial generator model is used to generate simulated sample cryptographic attack data based on the first sample cryptographic attack dataset; An initial discriminator model is constructed, wherein the initial discriminator model is used to compare the sample cryptographic attack data in the first sample cryptographic attack dataset with the simulated sample cryptographic attack data to obtain the comparison result; Based on the first sample cryptographic attack dataset, the initial generator model and the initial discriminator model are trained until the generator model and the discriminator model that satisfy the training convergence condition are obtained.

5. The method according to claim 4, characterized in that, The training of the initial generator model and the initial discriminator model based on the first sample cryptographic attack dataset includes: The first sample cryptographic attack dataset is denoised to obtain the second sample cryptographic attack dataset. Feature extraction is performed on each sample cryptographic attack data in the second sample cryptographic attack dataset to obtain a sample cryptographic attack feature set, wherein the sample cryptographic attack features in the sample cryptographic attack feature set are used to indicate the sample attack path of the sample cryptographic attack operation. The format conversion process is performed on each sample cryptographic attack feature in the sample cryptographic attack feature set to obtain the sample cryptographic attack feature vector set; The initial generator model and the initial discriminator model are trained using the sample cryptographic attack feature vector set until the generator model and the discriminator model that satisfy the training convergence condition are obtained.

6. The method according to claim 1, characterized in that, The step of generating a simulated attack path for the cryptographic attack operation based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set includes: Multiple simulated attack steps were identified from the set of simulated cryptographic attack features; The initial attack path is constructed using the aforementioned multiple simulated attack steps; The initial attack path is adjusted according to the sequence of password state parameters to obtain the simulated attack path.

7. The method according to claim 6, characterized in that, The construction of the initial attack path using multiple simulated attack steps includes: Based on the attack stage to which each of the simulated attack steps belongs, the plurality of simulated attack steps are divided into a plurality of simulated attack step sets, wherein different simulated attack step sets are matched with different attack stages; According to the step priority corresponding to each of the simulated attack steps, the simulated attack steps in each set of simulated attack steps are sorted to obtain the adjusted sets of simulated attack steps. The initial attack path is constructed based on the adjusted set of each simulated attack step.

8. The method according to claim 7, characterized in that, The step of adjusting the initial attack path according to the password state parameter sequence includes: Based on the simulated attack time of each attack phase, determine the cryptographic state parameter group corresponding to the simulated attack time from the cryptographic state parameter sequence; If the password state parameters in the password state parameter group meet the first adjustment condition, the step execution strategy of each simulated attack step in the simulated attack step set matched by each attack stage is adjusted.

9. The method according to claim 1, characterized in that, After generating the simulated attack path of the cryptographic attack operation based on the cryptographic state parameter sequence and the simulated cryptographic attack feature set, the method further includes: If the simulated attack path meets the second adjustment condition, an adjustment strategy is determined based on the simulated attack path, and the model parameters of the generator model are adjusted according to the adjustment strategy.

10. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of a method for simulating a cryptographic attack operation as described in any one of claims 1 to 9 when executing the computer program.

Citation Information

Patent Citations

  • Attack path identification method of complex network and related device

    CN120301695A

  • Machine learning techniques for analyzing operational technology networks

    US20250274476A1