SM4 key expansion algorithm based on sponge structure and chaotic disturbance

By using the SM4 key expansion algorithm based on sponge structure and chaotic perturbation, the security problem of the SM4 algorithm under quantum attack is solved, achieving higher key security and complexity, and meeting the 256-bit security strength requirement.

CN120915423APending Publication Date: 2025-11-07NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511080199.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-04
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

The SM4 algorithm suffers from insufficient key length and vulnerability to attacks due to fixed parameters when facing quantum attacks, making it particularly vulnerable to security issues in resource-constrained scenarios.

Method used

A key expansion algorithm based on sponge structure and chaotic perturbation is adopted. By initializing the sponge data structure, absorption and iterative function transformation are performed using the rate region and capacity region. The round key is generated by combining chaotic function and T-transform, thereby enhancing the security of key expansion.

Benefits of technology

The SM4 algorithm's resistance to quantum attacks has been improved, the security and complexity of the key have been enhanced, the success probability of classical and quantum attacks has been reduced, and the 256-bit security strength requirement has been met.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915423A_ABST
    Figure CN120915423A_ABST
Patent Text Reader

Abstract

The invention provides an SM4 key expansion algorithm based on a sponge structure and chaotic disturbance. The SM4 key expansion algorithm comprises the following steps: step 10, initializing a sponge data structure; the sponge data structure comprises a rate area and a capacity area, the size of the rate area is 8 bytes, and the size of the capacity area is 24 bytes; step 20, absorbing a master key, an FK constant and a CK constant transformed by adopting a chaotic function in sequence by utilizing a rate region of the initialized sponge data structure; wherein 8 bytes are absorbed every time, iteration function F transformation is carried out on the whole sponge data structure after absorption every time, and the sponge data structure is updated; step 30, extruding the whole sponge data structure for a plurality of times to generate a plurality of rounds of secret keys; and after each round of round key is generated, the sponge data structure is updated. According to the SM4 key expansion algorithm based on the sponge structure and chaotic disturbance provided by the invention, the quantum attack resistance of the SM4 algorithm is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, in particular to a SM4 key expansion algorithm based on sponge structure and chaotic disturbance. BACKGROUND

[0002] The SM4 algorithm is a block symmetric cipher algorithm, the block length and the key length are both 128 bits (16 bytes), based on the Feistel network structure, using 32 rounds of nonlinear iteration mathematical structure, the mathematical architecture, operation rules and the like of the encryption and decryption algorithms are completely the same, and the decryption only needs to use the round keys of the encryption in reverse order, the basic operations include modulo 2 addition (32-bit bitwise XOR operation) and cyclic shift, the basic components include S-box, linear transformation component L and synthetic transformation T, the S-box performs nonlinear substitution in byte units to play a confusion role, the linear transformation component L processes in word units to play a diffusion role, and the synthetic transformation T is composed of the two to comprehensively improve the security, in encryption, 32 round keys of 32 bits are generated through a key expansion algorithm, one round key is used for data processing in each round of iteration, and after 32 rounds, 4 words are inversely spliced to obtain the ciphertext, which is suitable for wireless local area network, financial payment, Internet of Things and the like, and is also widely applied to fields such as government confidential data transmission and telecommunication encryption.

[0003] However, in the face of quantum attacks, the SM4 has some weaknesses, first, the key length is relatively insufficient, the 128-bit key in front of quantum computing, after Grover quantum algorithm, the key exhaustion complexity is reduced from 2^128 to 2^64, with the improvement of quantum computer capacity, if 2^64 quantum computing is feasible, there is a risk of brute force cracking. Secondly, fixed parameters are easy to cause side channel attacks, the fixed and public parameters in the algorithm may become a breakthrough for key leakage, and the attacker can deduce the key by analyzing the power consumption, time and other information combined with the fixed parameters. In addition, the key expansion is relatively complex in the resource-limited scene, and consumes more resources, in the quantum computing environment, if the device resources are tight, the overall operation efficiency and security may be affected, making it more vulnerable. SUMMARY

[0004] The technical problem to be solved by the present application is to provide a SM4 key expansion algorithm based on sponge structure and chaotic disturbance, which can improve the quantum attack resistance of the SM4 algorithm.

[0005] To solve the above technical problems, the present application provides a SM4 key expansion algorithm based on sponge structure and chaotic disturbance, comprising the following steps: Step 10, initializing the sponge data structure; the sponge data structure includes a rate area and a capacity area, the size of the rate area is 8 bytes, and the size of the capacity area is 24 bytes; Step 20, the rate zone of the initialized sponge data structure is used to sequentially absorb the master key, the FK constant and the CK constant transformed by the chaotic function; wherein, after each absorption, the whole sponge data structure after absorption is transformed by the iteration function F, and the sponge data structure is updated; Step 30, the whole sponge data structure is squeezed for several times to generate several rounds of keys; after each round of key is generated, the sponge data structure is updated.

[0006] As a further improvement of the application, in the step 20, the absorption is specifically XOR between the rate zone of the initialized sponge data structure and the absorption object.

[0007] As a further improvement of the application, the expression of the chaotic function is: Formula (1) In the formula, represents the output value of the (n+1)th iteration of the chaotic system, represents the output value of the nth iteration of the chaotic system, represents the output value of the nth iteration of the coupled chaotic system, and n represents the iteration number, represents the first chaotic parameter, represents the second chaotic parameter.

[0008] As a further improvement of the application, , .

[0009] As a further improvement of the application, n is in the range of 5-12.

[0010] As a further improvement of the application, in the step 20, the iteration function F transformation on the whole sponge data structure includes: first, the capacity zone of the sponge data structure is transformed by confusion, and then each word constituting the whole sponge data structure is individually transformed by T.

[0011] As a further improvement of the application, the confusion transformation on the capacity zone of the sponge data structure specifically includes: The capacity zone is divided into a first half zone and a second half zone with the same size, and each half zone is divided into three words; The three words of the second half zone are XORed with the three words of the first half zone after T transformation, to obtain a new second half zone; The three words of the first half zone and the new second half zone are exchanged in position, to obtain the capacity zone after confusion transformation.

[0012] As a further improvement of the application, in the step 30, the squeezing is XOR between the eight words constituting the whole sponge data structure, and one round of key is output.

[0013] As a further improvement of the present application, the sponge data structure is updated after each round key is generated, specifically comprising: After each round key is output, a T transformation is performed on each word constituting the entire sponge data structure; after two round keys are output, a confusion transformation is performed on the capacity region of the sponge data structure, and then a T transformation is performed on each word constituting the entire sponge data structure.

[0014] As a further improvement of the present application, in step 40, 32 extrusions are performed to generate 32 round keys.

[0015] The SM4 key expansion algorithm based on the sponge structure and chaotic disturbance provided by the present application first initializes the sponge data structure; then the rate region of the sponge data structure is used to sequentially absorb the master key, the FK constant and the CK constant after being transformed by a chaotic function; 8 bytes are absorbed each time, and after each absorption, the entire sponge data structure after absorption is transformed by an iteration function F to update the sponge data structure; finally, the entire sponge data structure is output for several round keys, and the sponge data structure is updated after each round key is generated.

[0016] The method of the present application uses a sponge structure of 8+24, i.e. a total of 32 bytes, as the core framework of key expansion, which can support initial keys of 32x (x≥4) length and round key outputs of 32x (x≥4) length.

[0017] The method of the present application uses a coupled chaotic system to replace the traditional CK constant during absorption, and the two-variable coupled structure greatly increases the phase space dimension, and the reconstructed system needs to crack two chaotic sequences at the same time; the dynamic iteration mechanism ensures that the calculation path is different each time; the output mixing process destroys the weak correlation that may exist, and at least 2^80 operations are required to predict the output of the system; compared with the traditional CK constant, this chaotic enhancement mechanism brings significant security improvement, and the success probability of classical differential attack is reduced from 2^-46 to 2^-96, and the required trajectory sample size for power analysis attack is increased by three orders of magnitude.

[0018] The method of the present application performs an iterative function F transformation on the entire sponge data structure (32 bytes) after absorption, including two steps, first, a confusion transformation is performed on the capacity area of the sponge data structure, and then a T transformation is performed on each word constituting the entire sponge data structure. The confusion transformation specifically includes: first, applying a T transformation to the first half area and mixing in a round count salt value, then performing a mask XOR operation between the result and the second half area as a new second half area, and finally exchanging the positions of the two half areas and implementing a cyclic shift, which ensures the sufficient mixing of the capacity area of the sponge data structure. The sufficient mixing causes each bit of the capacity area to be associated with multiple bits of the original input, forming a complex dependency relationship, making it difficult for attackers to deduce the original key, constant input data, or reverse the intermediate process of the algorithm by analyzing part of the capacity area information, greatly increasing the difficulty of attack. The mixing process can quickly spread small changes in input (such as one-bit difference in the key) to multiple locations in the capacity area, producing an "avalanche effect". Even with slight changes in the initial input, the overall state of the capacity area will change significantly after sufficient mixing, ensuring the independence and difference of the round keys, and avoiding security risks caused by insufficient changes in the round keys due to small changes in input.

[0019] After sufficient mixing of the capacity area, combined with the pseudo-random permutation properties of the T transformation and chaotic disturbance, an adversary needs at least 2^96 queries to gain a non-negligible advantage, meeting the 256-bit security strength requirement and effectively resisting various attacks, including quantum attacks. The sufficient mixing makes the Hamming weight distribution of the capacity area more uniform, such as the χ² test statistic improving from 56.7 in the traditional scheme to 9.3 (degrees of freedom = 15), making it difficult for attackers to analyze the key through side channel information such as power consumption and time, reducing the success rate of side channel attacks. In a test set of 100,000 power consumption traces, the success rate of attacks decreased from 78% to 0.003%. The combination of sufficient mixing and dynamic disturbance of chaotic systems can further suppress differential probability. The differential probability in the 32-round key expansion is as low as 2^−106, which is 2^22 times lower than the brute force threshold, providing a strong theoretical guarantee for high security scenarios and effectively resisting differential attacks and other means.

[0020] The method of the present application will perform XOR on 8 words constituting the entire sponge data structure to output a round key, ensuring that each round key contains the entire state information. Experimental measurements show that the influence degree of a single state word on the final round key reaches 98.7%, which is much higher than the 75.2% of the traditional scheme. The enhanced round key and the overall state are associated, so that the round key can fully reflect the state information of the entire system, avoiding the case that the local state is independent of the round key generation process. It ensures that attackers cannot control the round key independently by tampering or analyzing a single state word, and it is also difficult to deduce the rules of the round key through local information, greatly increasing the complexity of the attack. The generation of each round key fully absorbs the randomness of the full state, combined with chaotic disturbance and confusion transformation, further ensuring the independence and unpredictability between the 32 round keys, reducing the risk of breaking the algorithm through round key correlation such as differential attack and linear attack. The round key is deeply bound with the full state, and in the quantum computing environment, even if the attacker tries to exhaust or analyze the quantum of the local state through quantum algorithms, it is difficult to separate the strong association between the single state word and the round key, thereby increasing the difficulty of attacking and cracking the round key. Combined with the capacity area design of the sponge structure, the algorithm's resistance to quantum attacks is strengthened. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 A flowchart of the SM4 key expansion algorithm based on the sponge structure and chaotic disturbance provided by the embodiment of the present application is shown. DETAILED DESCRIPTION

[0022] The technical solutions of the present application will be described in detail below with reference to the accompanying drawings.

[0023] The SM4 key expansion algorithm based on the sponge structure and chaotic disturbance provided by the embodiment of the present application is shown in FIG. 1, which includes the following steps: Figure 1 Step 10, initializing the sponge data structure.

[0024] The size of the sponge data structure is 32 bytes, including a rate area (RATE) and a capacity area (CAPACITY). The size of the rate area is 8 bytes, and the size of the capacity area is 24 bytes. It is ensured that the capacity area can provide sufficient safety margin, and the 192-bit length of the capacity area can resist computational complexity attacks up to 2^96 operations.

[0025] Specifically, the efficient memset function is used to set all 32 bytes (256 bits) of the sponge state to zero. By ensuring the deterministic initialization of all memory areas, the risk of information leakage caused by uninitialized memory is eliminated.

[0026] ​Step 20, the main key, the FK constant and the CK constant transformed by the chaotic function are absorbed in turn by using the rate area of the sponge data structure. The absorption is the exclusive OR operation between the initialized rate area of the sponge data structure and the absorption object. 8 bytes are absorbed each time, and after absorbing 8 bytes each time, the sponge data structure after absorption is transformed by the iteration function F, and the sponge data structure is updated.

[0027] Specifically, the main key is first absorbed by using the rate area of the sponge data structure, 8 bytes are absorbed each time, the 8 bytes of the initialized rate area are exclusive ORed with the main key to obtain a new rate area. For example, the main key is 24 bytes in total, and the main key is absorbed by the sponge data structure for 3 times. During the absorption of the main key, the entire sponge data structure is transformed by the iteration function F each time the absorption is performed, and the sponge data structure is updated. After the absorption of the main key is completed, the FK constant is absorbed by using the rate area of the sponge data structure. During the absorption of the FK constant, the entire sponge data structure is transformed by the iteration function F each time the absorption is performed. After the absorption of the FK constant is completed, the CK constant transformed by the chaotic function is absorbed by using the rate area of the sponge data structure. During the absorption of the CK constant transformed by the chaotic function, the entire sponge data structure is transformed by the iteration function F each time the absorption is performed.

[0028] The expression of the chaotic function is: Formula (1) In the formula, represents the output value of the (n+1)th iteration of the chaotic system, represents the output value of the nth iteration of the chaotic system, represents the output value of the nth iteration of the coupled chaotic system, n represents the number of iterations, represents the first chaotic parameter, represents the second chaotic parameter. Preferably, , .

[0029] In this embodiment, the initialization of the chaotic system adopts a static variable storage mechanism to ensure that the system state remains continuous evolution between multiple calls. The initial value is set to x0=y0=0.33, which can avoid rapid convergence to a fixed point. When called each time, the system uses the calculation method of (round % 8) + 5 to dynamically determine the number of iterations of the chaotic system, introduces non-linear dependence through the modulus operation, makes the number of iterations change with the input variable round, disturbs the system state to improve the randomness of the output sequence, and thus enhances the unpredictability of the chaotic system.

[0030] In formula (1), X is the state variable of the chaotic system, serving as the input value of the Logistic map, which generates chaotic behavior through nonlinear iteration. Each iteration updates based on the previous result, accumulating the long-term sensitivity of the chaotic system (i.e., the "butterfly effect"). Y is an auxiliary variable coupled with the chaotic system, updated through an independent chaotic map and reinitialized to the current X value at each function call, but generates a new chaotic trajectory through the coupling map in the loop, interacting with X to enhance the complexity and unpredictability of the system. X and Y are iterated through the Logistic map and the coupling map, respectively, and the final result is mapped to a 32-bit integer through (x + y) * UINT32_MAX / 2. The combination of the outputs of the two chaotic systems improves the statistical complexity and resistance to analysis of the random number.

[0031] During the chaotic sequence generation process, double-precision floating-point operations are used to ensure calculation accuracy, and the state variable is updated immediately after each iteration to avoid intermediate error accumulation. In the output processing stage, a hybrid normalization strategy is adopted, which arithmetically averages the outputs of the two chaotic systems and then uniformly maps them to 32-bit integers by multiplying UINT32_MAX. Compared with simple truncation or modulo operations, this method better preserves the statistical properties of the chaotic sequence. Actual tests show that the generated chaotic values pass all 15 randomness tests of the NIST SP 800-22 test suite.

[0032] During the absorption process, the generated 32-bit chaotic values are injected into the state through the absorption mechanism of the sponge structure. After converting the chaotic values to a byte sequence, the byte sequence is XORed with the state rate part according to the position offset determined by the current round. This dynamic injection method further enhances the system's resistance to analysis, making it difficult for attackers to establish an effective prediction model.

[0033] The two-variable coupling structure significantly increases the phase space dimension, and the reconstructed system needs to crack two chaotic sequences simultaneously; the dynamic iteration mechanism ensures that the calculation path of each call is different; and the output mixing process destroys any weak correlation that may exist. Cryptographic analysis shows that at least 2^80 operations are required to predict the output of this system, fully meeting the security requirements of modern cryptography.

[0034] Compared with traditional CK constants, the chaotic enhancement mechanism brings significant security improvements. The most prominent advantage is in the resistance to differential attacks. Due to the round correlation of chaotic sequences, the success probability of classical differential attacks decreases from 2^-46 to 2^-96. At the same time, in terms of side channel protection, the introduction of the chaotic system increases the number of trajectory samples required for power analysis attacks by three orders of magnitude.

[0035] In step 20, the iteration function F is transformed on the entire sponge data structure (32 bytes) after absorption, which specifically includes: first, the capacity area of the sponge data structure is transformed by confusion, and then each word constituting the entire sponge data structure is individually transformed by T.

[0036] The confusion transformation on the capacity area of the sponge data structure specifically includes: The capacity area is divided into a first half area and a second half area of the same size, and each half area is divided into 3 words. For example, as shown in Figure 1 word2, word3, and word4 are the first half area, and word5, word6, and word7 are the second half area.

[0037] After the 3 words of the first half area are respectively transformed by T, they are XORed with the 3 words of the second half area to obtain a new second half area. The first half area remains unchanged. At this time, the first half area is word2, word3, and word4, and the second half area is word5', word6', and word7'.

[0038] The T transformation of SM4 is applied to each word of the first half area to realize nonlinear transformation: T_Li = T(Li ⊕(round_counter<<(i*8))), for i=0,1,2; round_counter is the current round number. This salt injection method ensures the uniqueness of each round of transformation. The transformation result is conditionally XORed with the second half area to realize cross mixing: Ri' = Ri⊕ (T_Li&mask_pattern); mask_pattern is a dynamic mask generated according to a chaotic system, effectively breaking the linear relationship.

[0039] The 3 words of the first half area and the new second half area are exchanged in corresponding positions to obtain the capacity area after confusion transformation. For example, word2 and word5' are exchanged, word3 and word6' are exchanged, and word4 and word7' are exchanged.

[0040] The above not only exchanges the positions of the left and right half areas, but also introduces a circular shift: new_L = (R0',R1',R2')>>>5, new_R = (L0⊕R2', L1⊕R0', L2⊕R1'). This structure ensures sufficient mixing of the capacity part while avoiding the fixed pattern of the traditional Feistel network.

[0041] In step 30, the entire sponge data structure is squeezed several times to generate several round keys. Among them, squeezing is to XOR the 8 words constituting the entire sponge data structure to output a round key. A total of 32 squeezes are performed to generate 32 round keys.

[0042] The embodiment of the present application adopts an iterative generation strategy in the round key generation stage, and through a multi-level state confusion and key extraction mechanism, the strong correlation and independence between round keys are ensured.

[0043] The round key generation process is based on the dynamic evolution of the sponge state, and the 8 words constituting the entire sponge data structure are subjected to full word XOR to extract a 32-bit round key. The 256-bit sponge data structure is regarded as an array of 8 32-bit words (state_words[0] to state_words[7]), and the calculation of the round key rkᵢ adopts a full word XOR strategy: rkᵢ = state_words[0] ⊕ state_words[1] ⊕... ⊕ state_words[7]. This full state mixing design ensures that each round key contains the entire state information. Experimental measurements show that the influence degree of a single state word on the final round key reaches 98.7%, which is much higher than the 75.2% of the traditional scheme.

[0044] Preferably, the method of the embodiment of the present application further comprises: Step 50, updating the sponge data structure after outputting each round key.

[0045] Specifically, after outputting each round key, a T transformation is performed on each word constituting the entire sponge data structure. After outputting two round keys, a confusion transformation is performed on the capacity area of the entire sponge data structure, and a T transformation is performed on each word constituting the entire sponge data structure.

[0046] The T transformation using the SM4 algorithm standard includes an S-box substitution (τ transformation) and a linear transformation L two stages. The S-box substitution stage performs a nonlinear mapping on each byte of the state, and an SM4 standard S-box is used to realize an 8-bit to 8-bit conversion, with a differential uniformity of 8 / 256 and a linear approximation probability of 16 / 256. The linear transformation L realizes bit-level diffusion through a composite shift XOR operation L(x)=x⊕(x<<2)⊕(x<<10)⊕(x<<18)⊕(x<<24).

[0047] The confusion transformation on the capacity area of the entire sponge data structure divides the capacity area into two half areas (each 12 bytes), applies the T transformation to the first half area and mixes in the round count salt value, then performs a masked XOR operation on the result and the second half area, finally exchanges the positions of the two half areas and implements a circular shift, and through the three-round mixing process, deep confusion is realized.

[0048] The performance of the method of the embodiment of the present application is verified as follows.

[0049] 1. Security analysis Let the advantage Adv(A) of the adversary A under adaptive chosen key attack satisfy: ; where c = 192 represents the capacity bit-width, q represents the number of queries, and e(T) represents the pseudo-random permutation (PRP) advantage of the compression function T.

[0050] According to the theoretical derivation of Bertoni et al., this security boundary holds when T satisfies the PRP property. For the T transformation of the SM4 algorithm, e(T) ≤ 2^(-128), which is substituted into the formula as follows: .

[0051] The results show that the adversary needs at least 2^96 queries to obtain a non-negligible advantage, meeting the requirement of 256-bit security strength.

[0052] 2. Resistance to side-channel analysis The method disclosed in the article "Side-channel Protection Research on SM4 Algorithm" in the Journal of Cryptology, No. 2, 2023, is used for testing. The method of the embodiment of the application introduces a chaotic system, which reduces the correlation coefficient of the power consumption trajectory from 0.35 in the traditional scheme to 0.012.

[0053] The confusion transformation changes the round key to: , which destroys the linear correlation between the state bits and the round key. The Pearson correlation coefficient test shows that the linearity is reduced from 0.82 to 0.11.

[0054] Dynamic capacity confusion makes the distribution of Hamming weight more uniform, and the χ² test statistic is improved from 56.7 to 9.3 (degrees of freedom = 15), which is significantly better than the traditional scheme.

[0055] Using the Inspector platform of Riscure Company for measurement, in a test set of 100,000 power consumption trajectories, the success attack rate is reduced from 78% to 0.003%, meeting the requirements of CC EAL5+ certification.

[0056] 3. Differential property analysis Let the input difference be Δα and the output difference be Δβ. The differential uniformity of the S-box is defined as: . The S-box design of the SM4 algorithm satisfies δS ≤ 8 / 256 (i.e., the maximum differential probability Pmax = 2^(-5)), indicating that any non-zero input difference can only map to a limited output difference. After the diffusion effect of the linear transformation L, the single-round differential probability is further reduced.

[0057] Specifically, the input difference Δτ is generated after the S-box, and then diffuses to the entire state through the avalanche effect of the L transformation. The theoretical upper bound of the single-round maximum differential probability is: ; where w(L) represents the differential branch number of the L transformation (the minimum active S-box number), and experimental verification shows that its value is 1.32.

[0058] In 32 rounds of key expansion, the differential path needs to activate at least 16 S-boxes (the minimum active S-box number constraint of the unbalanced Feistel structure). Therefore, the probability upper bound of the traditional differential path satisfies: The value has been lower than the brute force threshold 2^(-128), but the actual security needs to further consider the dynamic disturbance of the chaotic system. The chaotic system injects a disturbance δi ~ U(F2128) in each round, which causes the differential path to maintain propagation with a probability Pr[δi=0]=2^(-128). The actual differential probability after disturbance is: It can be seen that the uncertainty is enhanced by 2^5 times, which is caused by the 5-round key disturbance of the chaotic system (identified by the CryptoSMT tool).

[0059] To verify the differential probability model under chaotic disturbance, a mixed integer linear programming (MILP) constraint is constructed using a formal method: Objective function: , Constraints: (active flag of each round S-box differential), (minimum active S-box number), (chaotic disturbance embedding).

[0060] The solution result confirms that the optimal differential probability p' diff≤2 ^(-126), and all feasible paths need to cross at least 5 rounds of chaotic interference.

[0061] The method improves the security strength of the key related to quantum exhaustive search. A 32-byte sponge structure with an 8-byte rate area and a 24-byte capacity area is used as the core framework, which supports longer initial keys (32x bytes, x>=4) and round key outputs (32x bytes, x>=4). Compared with the traditional SM4 128-bit (16-byte) key, the longer key length can significantly improve the complexity of key exhaustive search when facing Grover quantum algorithm. The complexity of the traditional 128-bit key is reduced to 2^64 after Grover algorithm, and the key length expansion design of the method greatly increases the difficulty of quantum exhaustive search. Security analysis shows that an adversary needs at least 2^96 queries to gain a non-negligible advantage, meeting the 256-bit security strength requirement, which is much higher than the security boundary of the traditional SM4 under quantum attack, and theoretically guarantees the ability to resist quantum exhaustive attack.

[0062] The method of the present application introduces a chaotic disturbance mechanism to destroy the predictability of quantum attacks. The CK constant after transformation by a chaotic function, the two-variable coupled chaotic system makes the phase space dimension greatly improved, and the reconstructed system needs to crack two chaotic sequences at the same time. The dynamic iteration mechanism ensures that the calculation path is different each time. The output mixing process destroys the weak correlation, and the prediction system output needs at least 2^80 times of operation. This chaotic enhancement mechanism reduces the success probability of classical differential attack from 2^-46 to 2^-96, and increases the required trajectory sample size of power analysis attack by three orders of magnitude. In the context of quantum attacks relying on algorithm regularity and predictability, the high complexity and unpredictability brought by chaotic disturbance significantly reduces the possibility of quantum algorithm breaking the law.

[0063] The method of the present application strengthens state mixing and diffusion to resist quantum analysis attacks. The confusion transformation of the capacity area realizes sufficient mixing through T transformation, mask XOR, position exchange and cyclic shift operations, so that each bit of the capacity area is associated with multiple bits of the original input, forming a complex dependence relationship. This strong diffusion makes it difficult for quantum attacks to derive overall information through local state analysis. When generating the round key, the design of the XOR output of the eight words that make up the entire sponge data structure makes the influence degree of a single state word on the round key reach 98.7% (much higher than the 75.2% of traditional schemes), ensuring that each round key contains the entire state information. This full-state association makes it difficult for quantum algorithms to analyze local states in isolation to crack the round key, significantly increasing the difficulty of quantum attacks.

[0064] The method of the present application optimizes the differential resistance characteristics and suppresses the quantum attack path. Combined with the strict differential boundary of the S-box, the strong diffusion of the linear transformation and the chaotic dynamic disturbance, the differential probability of the 32-round key expansion is suppressed to 2^-106, which is 2^22 times lower than the brute force threshold. The disturbance injected by the chaotic system in each round makes the probability of maintaining the propagation of the differential path as low as 2^-128, further enhancing the resistance of quantum attacks that rely on differential paths.

[0065] The above shows and describes the basic principles, main features and advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above specific embodiments, and the above specific embodiments and descriptions in the specification are only to further illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection claimed by the present application is defined by the claims and their equivalents.

Claims

1. A SM4 key expansion algorithm based on sponge structure and chaotic disturbance, characterized in that, The method comprises the following steps: Step 10, initializing a sponge data structure; the sponge data structure comprises a rate area and a capacity area, the size of the rate area is 8 bytes, and the size of the capacity area is 24 bytes; Step 20, absorbing the master key, the FK constant and the CK constant transformed by the chaotic function in turn by using the rate area of the initialized sponge data structure; wherein, 8 bytes are absorbed each time, the whole sponge data structure is transformed by the iteration function F after absorbing each time, and the sponge data structure is updated; Step 30, performing extrusion on the whole sponge data structure for several times to generate several round keys; the sponge data structure is updated after generating each round key.

2. The SM4 key expansion algorithm based on sponge structure and chaotic disturbance according to claim 1, characterized in that, In the step 20, the absorption is specifically XOR operation between the rate area of the initialized sponge data structure and the absorption object.

3. The sponge structure and chaotic perturbation based SM4 key expansion algorithm according to claim 1, wherein, The expression of the chaotic function is as follows: Formula (1) wherein represents the output value of the nth iteration of the chaotic system, represents the output value of the nth iteration of the chaotic system, represents the output value of the nth iteration of the coupled chaotic system, n represents the iteration number, represents the first chaotic parameter, represents the second chaotic parameter.

4. The SM4 key expansion algorithm based on sponge structure and chaotic disturbance according to claim 2, characterized in that, , 。 5. The SM4 key expansion algorithm based on sponge structure and chaotic disturbance according to claim 2, characterized in that, The value range of n is 5-12.

6. The sponge structure and chaotic perturbation based SM4 key expansion algorithm according to claim 1, characterized in that, In the step 20, the iteration function F transformation on the whole sponge data structure comprises: firstly, performing confusion transformation on the capacity area of the sponge data structure, and then performing T transformation on each word constituting the whole sponge data structure.

7. The SM4 key expansion algorithm based on sponge structure and chaotic disturbance according to claim 6, characterized in that, The confusion transformation on the capacity area of the sponge data structure comprises the following steps: Dividing the capacity area into a first half area and a second half area with the same size, and dividing each half area into three words; XOR operation is performed between the three words of the second half area and the three words of the first half area after T transformation, to obtain a new second half area; The three words of the first half area and the new second half area are exchanged in corresponding positions, to obtain the confusion transformed capacity area.

8. The sponge structure and chaotic perturbation based SM4 key expansion algorithm according to claim 1, wherein, In the step 30, the extrusion is XOR operation between the eight words constituting the whole sponge data structure, and one round key is outputted.

9. The sponge structure and chaotic perturbation based SM4 key expansion algorithm according to claim 1, wherein, The sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the sponge data structure is updated after generating each round key, and the ​ 10. The sponge structure and chaotic perturbation based SM4 key expansion algorithm according to claim 1, characterized in that, ​