A quantum key recovery attack method and system

By constructing an equivalent cryptographic structure for the wheel and solving a system of linear equations, and extending the periodic function, the problem of polynomial-time key recovery attacks on symmetric key structures in quantum computing environments has been solved. Polynomial-time key recovery for various structures has been achieved, thereby improving the security of quantum communication.

CN121644079BActive Publication Date: 2026-05-29SHANDONG UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG UNIV
Filing Date
2026-02-03
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies struggle to implement polynomial-time key recovery attacks on symmetric key structures in a quantum computing environment. In particular, a complete key recovery attack on a 5-round Feistel-KF structure has failed to be achieved with the minimum n-bit related key setting.

Method used

By constructing an equivalent cryptographic structure for the rounds, and using the Simon periodic search algorithm and a system of linear equations to solve the problem, the periodic function is expanded, and the key is iteratively recovered, achieving key recovery in polynomial time complexity.

Benefits of technology

A polynomial time key recovery attack was implemented for 5-round Feistel-KF, 6-round Feistel-FK, 6-round MISTY L-FK, 5-round MISTY R-FK, 5-round MISTY L-KF, and 5-round MISTY R-KF structures under an n-bit related key setting, thereby improving the security of quantum communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644079B_ABST
    Figure CN121644079B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of key recovery, and provides a quantum key recovery attack method and system, an equivalent cipher structure of a round is constructed by using a cipher algorithm, and the ciphertexts of and are the same, a round period function is constructed; a period is found, whether or is judged, if yes, is made, otherwise, is put into an equation group to solve or, and then is made; whether is greater than a set round is judged, if yes, a new round period function is constructed, a new period is extracted and added to the equation group, and iteration is carried out until the equation group can be solved, and or is recovered; if no, a key recovery attack is performed in a single key scene, and a key is obtained. The application solves the remaining open problem in the prior art, and improves the security of quantum communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of key recovery technology, specifically relating to a quantum key recovery attack method and system. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] The rapid development of quantum computing technology poses a serious threat to the security of modern cryptography. To address this threat, the National Institute of Standards and Technology (NIST) has initiated a standardization process for post-quantum cryptographic algorithms. While the vulnerabilities of public-key schemes such as RSA and ECC under Shor's algorithm are widely acknowledged, research on the impact on symmetric-key cryptography remains insufficient.

[0004] Grover's algorithm provides a quadratic speedup for brute-force key search, The effective security of the bit key is reduced to Computational complexity. While this is weaker than the exponential speedup in public-key cryptography, recent research indicates that symmetric key structures can still be vulnerable to more powerful quantum attacks. In particular, the Simon algorithm has been shown to be able to perform polynomial-time attacks on symmetric primitives by exploiting structural periodicity. A typical example is a quantum-distinguishable attack against a 3-round Feistel structure. Subsequently, attacks targeting various cryptographic structures have been proposed.

[0005] This indicates that the security of symmetric key schemes needs to be reassessed in a quantum environment, especially those that rely on structure iteration and key alternation designs. Understanding these attacks is an important step in developing symmetric primitives with robust post-quantum security.

[0006] Rötteler et al. proposed a quantum correlated key attack model that allows attackers to query the superposition state of correlated keys and plaintext. Under this setting, even against ideal random block ciphers, attackers can recover the key in polynomial time. Cid et al. pointed out that this model's constraints are too weak and further strengthened the constraints on attacker capabilities by limiting the number of correlated keys.

[0007] exist Under the bit-related key settings (where (where n represents the size of a single-round key). Cid et al. implemented a polynomial-time key recovery attack on a 4-round Feistel-KF. They also presented a discriminator for a 5-round Feistel-KF. However, under the same constraints, they failed to implement a polynomial-time key recovery attack on a 5-round Feistel-KF. Such an attack only becomes feasible when the relevant key is extended to 2n bits. This limitation highlights the open question left in their work: is it possible to achieve full key recovery with a minimum n-bit relevant key setting in 5-round encryption? Summary of the Invention

[0008] To address the aforementioned problems, this invention proposes a quantum key recovery attack method and system. This invention resolves the openness issues remaining in the prior art and improves the security of quantum communication.

[0009] According to some embodiments, the present invention adopts the following technical solution:

[0010] A quantum key recovery attack method includes the following steps:

[0011] Using cryptographic algorithms Construct a Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same, the cryptographic algorithm The key is ;

[0012] structure Cyclic function;

[0013] Searching for the cycle ,judge Is it or If so, then let Otherwise, Place into the system of equations In order to find a solution or , and then ;

[0014] Judge at this time Is it greater than the set number of rounds? If so, then construct a new one. Cyclic functions are used to extract new periods and add them to the system of equations. The process is repeated iteratively until the system of equations is reached. Solvable, recoverable or ;

[0015] If not, a key recovery attack is performed in a single-key scenario to obtain the key.

[0016] As an alternative implementation method, cryptographic algorithms are used. Construct a Equivalent cryptographic structure of the wheel The process includes, if the key state The value is known, using a cryptographic algorithm The second round to the 1st Wheel construction Equivalent cryptographic structure of the wheel ;

[0017] If key state The value is known, using a cryptographic algorithm The first round to the Wheel construction Equivalent cryptographic structure of the wheel .

[0018] As an alternative implementation method, determine Is it or The process includes: in Round cryptography algorithm In China, it has not been restored. It has not been restored. And the period is identified from the corresponding i-th cycle periodic function. Then judge Not for or .

[0019] As an alternative implementation method, Place into the system of equations In order to find a solution or The process includes: pre-constructing a set of candidate expressions for the oracle input. and its linear combination, where For any constant, As variables, For any known function, pre-construct a system of equations. And initialize it to an empty set, and discover the periodicity. Included in set and will Insert as the first element into the system of equations .

[0020] As an alternative implementation method, construct a new Cyclic functions are used to extract new periods and add them to the set. and system of equations .

[0021] As a further implementation method, the set The selected value is used as the input to the equivalent cryptographic structure.

[0022] A quantum key recovery attack system, comprising:

[0023] The equivalent cryptographic structure building module is configured to utilize cryptographic algorithms. Construct a Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same, the cryptographic algorithm The key is ;

[0024] The periodic function building module is configured to construct Cyclic function;

[0025] The period determination module is configured to find the period. ,judge Is it or If so, then let Otherwise, Place into the system of equations In order to find a solution or , and then ;

[0026] The iterative execution module is configured to determine at this time. Is it greater than the set number of rounds? If so, then construct a new one. Cyclic functions are used to extract new periods and add them to the system of equations. The process is repeated iteratively until the system of equations is reached. Solvable, recoverable or If not, then perform a key recovery attack in a single-key scenario to obtain the key.

[0027] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the steps in the above method.

[0028] An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the steps in the method described above.

[0029] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0030] This invention implements a 5-round polynomial-time key recovery attack using a Feistel-KF structure and a 6-round polynomial-time key recovery attack using a Feistel-FK structure, extending the attack by one round compared to the work of Cid et al. Furthermore, also using an n-bit related key setting, this invention implements a 6-round polynomial-time key recovery attack using a MISTY L-FK structure, a 5-round polynomial-time key recovery attack using a MISTY R-FK structure, a 5-round polynomial-time key recovery attack using a MISTY L-KF structure, and a 5-round polynomial-time key recovery attack using a MISTY R-KF structure. All of these attacks can be performed in polynomial time complexity.

[0031] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0032] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0033] Figure 1 This is a schematic diagram of a key recovery attack on a 3-round Feistel-KF structure under a single-key setting, according to one embodiment.

[0034] Figure 2 This is a schematic diagram of a key recovery attack on a 5-round Feistle-KF structure under an n-bit related key setting, according to one embodiment.

[0035] Figure 3 This is a schematic diagram of a key recovery attack on a 5-round Feistle-KF structure under an n-bit related key setting, according to another embodiment.

[0036] Figure 4 These are schematic diagrams illustrating key recovery attacks on a 5-round Feistle-KF structure under an n-bit related key setting in three other embodiments;

[0037] Figure 5 This is a flowchart illustrating a full-round key recovery attack performed under a relevant key scenario in one embodiment. Detailed Implementation

[0038] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0039] It should be noted that the following detailed description is illustrative and intended to provide further explanation of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0040] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention. As used herein, the singular form is intended to include the plural form as well, unless the context clearly indicates otherwise. Furthermore, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0041] Where there is no conflict, the embodiments and features described in this application may be combined with each other.

[0042] Example 1

[0043] A quantum key recovery attack method under relevant key settings.

[0044] First, the attack model is introduced, including the adversary's capabilities and the oracle access assumptions for Feistel and MISTY. The strategy in this embodiment is to extend the periodic function from a single-key setting to a related-key setting.

[0045] Assume an attacker can perform a chosen-plaintext attack under a quantum setting. That is, for a given... Round cryptography algorithm An attacker can obtain the superposition ciphertext corresponding to any superposition plaintext chosen by the attacker. The quantum-related key model, on the other hand, suggests that it can be modified... The cryptographic algorithm of the round The attacker obtains the key for one or more rounds of the cryptographic algorithm and then retrieves the ciphertext corresponding to the modified key. Clearly, for an attacker, the fewer keys that need to be modified to achieve the same attack effect, the easier the attack is to execute. Correspondingly, a single-key setup means that the cryptographic algorithm cannot be modified. The key.

[0046] The following section describes how to extend the periodic function from a single-key setup to a related-key setup. Assume the input state of the cryptographic algorithm is the independent variable. The key appears in the internal state of the cryptographic algorithm. XOR internal state At that time, among them It is a known public permutation. This embodiment can use the capabilities of the relevant key model to modify the key for this round. After that, the internal state became Clearly, the internal state at this point exhibits a periodicity. ,because Then, using Simon's periodic search algorithm, the function can be obtained in polynomial time complexity. cycle This recovers one round of keys. Using the same approach and method, as many keys as possible can be recovered.

[0047] The preceding introduction explained that the Simon cycle search algorithm can recover the secret cycle, that is, a portion of the key. However, this does not mean that the recovery of the entire round key can be completed in polynomial time. Assume... Round cryptography algorithm The key is , Indicates the first The key for the round. If, in the relevant key settings, the obtained periodic function is... or If the period is fixed, all remaining keys can be recovered directly using the same periodic function; alternatively, different periodic functions can be used to recover different key states, and finally all keys can be recovered by solving a system of linear equations.

[0048] Assumption Round cryptography algorithm A key recovery attack based on a single-key setup already exists. The goal of this embodiment is to recover the key in a relevant key scenario. The complete key of the round instance, where .

[0049] The method specifically includes the following four steps, such as Figure 5 As shown, repeat the first three steps below until you proceed to step 4:

[0050] Step 1: Construction Equivalent cryptographic structure of a wheel Assuming for The cryptographic algorithm of the round It has been obtained The value can exclude cryptographic algorithms. The first round of encryption, that is, the state of the first round, is completely known to the attacker.

[0051] Therefore, cryptographic algorithms can be used. The second round to the 1st Wheel construction Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same. Assume the obtained key state is not... , but Similarly, cryptographic algorithms can be used. The first round to the Wheel construction Equivalent cryptographic structure of the wheel .set up The cryptographic algorithm of the round The key is .

[0052] Step 2: Construction Round periodic function: A periodic function is constructed using the same method described above. Typically, the period of this type of function corresponds to a specific round key or a combination of multiple round keys. If this function can be directly recovered... or If the key is selected, it will be used first. Otherwise, proceed to the next step to solve for the key required for the next round.

[0053] Step 3: Establish a system of equations to solve for the round key: If it is impossible to obtain the key from the cycle... Direct recovery It is also impossible to recover. Therefore, constructing an equivalent oracle with fewer rounds becomes infeasible. This limitation explains why, in the research of Cid et al., a full 5-round key recovery attack could not be achieved when only a single-round key modification was allowed. To address this situation, this embodiment recovers the key by solving a system of equations.

[0054] Assuming in Round cryptography algorithm In China, it has not been restored. It has not been restored. And the period is identified from the corresponding i-th cycle periodic function. Let the set of candidate expressions for the oracle input be... and its linear combination, where For any constant, As variables, Let be any known function. The period will then be discovered. Included in set At this time, it is possible to start from Select values ​​from the set as input to the equivalent cryptographic structure and initialize the empty equation set. ,Will Inserted as the first element—this set of equations is used to solve it. or .

[0055] Then build a new Cyclic function, extract new period and add simultaneously and This iterative process continues until the system of equations is reached. It can be solved, thus restoring or .

[0056] Step 4: Perform a key recovery attack in a single-key scenario: Once an equivalent cryptographic structure of R rounds is constructed, the relevant key settings become irrelevant because existing techniques can be directly used to recover the complete key. Round key. This embodiment focuses on the analysis of relevant key setting scenarios.

[0057] This embodiment proposes a novel attack scheme, achieving a 5-round polynomial-time key recovery attack using a Feistel-KF structure and a 6-round polynomial-time key recovery attack using a Feistel-FK structure, both with an n-bit associated key setting. This scheme extends the attack by one round compared to the work of Cid et al. Furthermore, also with an n-bit associated key setting, this embodiment implements a 6-round polynomial-time key recovery attack using a MISTY L-FK structure, a 5-round polynomial-time key recovery attack using a MISTY R-FK structure, a 5-round polynomial-time key recovery attack using a MISTY L-KF structure, and a 5-round polynomial-time key recovery attack using a MISTY R-KF structure. All of these attacks can be performed in polynomial time complexity.

[0058] The following example, using a 5-round Feistel-KF structure with an n-bit related key setting and a polynomial-time key recovery attack, illustrates the specific effectiveness of this technical solution. First, a 3-round Feistel-KF structure is susceptible to a single-key polynomial-time key recovery attack, for the following reasons: According to... Figure 1 Let the inputs of the Feistel-KF structure be respectively Where c is any fixed constant, Traversal After three rounds of encryption, the left branch output of the Feistel-KF structure is: ,in Indicates the first The wheel's wheel function, constructor ,Right now .because Therefore, it is possible to construct a system based on... For a periodic function with periodicity, calling Simon's periodic search algorithm, under the quantum model, the key can be obtained by querying the quantum oracle of polynomial degree. Following the steps provided in the previous section, it can then be recovered with the same complexity. Thus, the proof of a polynomial-time key recovery attack on a 3-round Feistel-KF structure with a single key is complete. The following explains how to use this 3-round Feistel-KF structure with a single key to perform a 5-round Feistel-KF structure polynomial-time key recovery attack with an n-bit related key setting.

[0059] For convenience, it is assumed that the round function used in each round of Feistel-KF is the same, which is... .according to Figure 2 As shown, let the inputs of the Feistel-KF structure be respectively , Traversal Unlike single-key settings, n-bit correlated key settings allow an adversary to inject their chosen state into a round key, in a Feistel-KF structure. Injection After 5 rounds of encryption, the left branch output of the Feistel-KF structure is: ,in , .because Therefore, and At this point, if there is a polynomial-time key recovery attack under a single key for a 4-round Feistel-KF structure, then according to the method proposed in the previous section, a polynomial-time key recovery attack for a 5-round Feistel-KF structure with an n-bit related key setting can be directly obtained. However, only a 3-round Feistel-KF structure has a polynomial-time key recovery attack under a single key, so the analysis will continue under the related key setting.

[0060] Known key Afterwards, the attacker can directly obtain the result of the first round of Feistel-KF structure encryption. According to Figure 3 Let the inputs of the 5-wheel Feistel-KF structure be respectively The state after the first round of Feistel-KF structure encryption becomes Similarly, in the Feistel-KF structure, the round key... Injection After 5 rounds of encryption, the output of the right branch is ,in Constructing periodic functions By invoking Simon's periodic search algorithm, under the quantum model, a query of a polynomial-degree quantum oracle can obtain the periodic value containing key information. .

[0061] according to Figure 4 As shown, let the inputs of the 5-round Feistel-KF structure be respectively The state after the first round of Feistel-KF structure encryption becomes Similarly, in the Feistel-KF structure, the round key... Injection After 5 rounds of encryption, the output of the left branch is .use You can obtain the round key for the final round. .

[0062] Recovery Key and Afterwards, in the 5-round Feistel-KF structure, only the middle 3 rounds are unknown to the attacker. At this point, a polynomial-time key recovery attack using a single key on the 3-round Feistel-KF structure can recover the keys of the middle 3 rounds. Note that because the key recovery attack using a single key setting targets the middle 3 rounds of the 5-round Feistel-KF structure, the actual key recovered under a single key setting is... Thus, the five-round Feistel-KF polynomial time key recovery attack under bit-related key settings is complete.

[0063] Example 2

[0064] A quantum key recovery attack system, comprising:

[0065] The equivalent cryptographic structure building module is configured to utilize cryptographic algorithms. Construct a Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same, the cryptographic algorithm The key is ;

[0066] The periodic function building module is configured to construct Cyclic function;

[0067] The period determination module is configured to find the period. ,judge Is it or If so, then let Otherwise, Place into the system of equations In order to find a solution or , and then ;

[0068] The iterative execution module is configured to determine at this time. Is it greater than the set number of rounds? If so, then construct a new one. Cyclic functions are used to extract new periods and add them to the system of equations. The process is repeated iteratively until the system of equations is reached. Solvable, recoverable or If not, then perform a key recovery attack in a single-key scenario to obtain the key.

[0069] Example 3

[0070] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the steps in the method provided in Embodiment 1.

[0071] Example 4

[0072] An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the steps in the method provided in Embodiment 1.

[0073] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of one or more computer-usable storage media (including, but not limited to, disk storage, etc.) containing computer-usable program code. CD - ROM It takes the form of a computer program product implemented on (such as optical memory, etc.).

[0074] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0075] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0076] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0077] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made by those skilled in the art without creative effort within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A quantum key recovery attack method, characterized in that, Includes the following steps: Using cryptographic algorithms Construct a Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same, the cryptographic algorithm The key is ; structure Cyclic function; Searching for the cycle ,judge Is it or If so, then let Otherwise, Place into the system of equations In order to find a solution or , and then ; Judge at this time Is it greater than the set number of rounds? If so, then construct a new one. Cyclic functions are used to extract new periods and add them to the system of equations. The process is repeated iteratively until the system of equations is reached. Solvable, recoverable or ; If not, a key recovery attack is performed in a single-key scenario to obtain the key.

2. The quantum key recovery attack method as described in claim 1, characterized in that, Using cryptographic algorithms Construct a Equivalent cryptographic structure of the wheel The process includes, if the key state The value is known, using a cryptographic algorithm The second round to the 1st Wheel construction Equivalent cryptographic structure of the wheel ; If key state The value is known, using a cryptographic algorithm The first round to the Wheel construction Equivalent cryptographic structure of the wheel .

3. The quantum key recovery attack method as described in claim 1, characterized in that, judge Is it or The process includes: in Round cryptography algorithm In China, it has not been restored. It has not been restored. And the period is identified from the corresponding i-th cycle periodic function. Then judge Not for or .

4. The quantum key recovery attack method as described in claim 1, characterized in that, Will Place into the system of equations In order to find a solution or The process includes: pre-constructing a set of candidate expressions for the oracle input. and its linear combination, where For any constant, As variables, For any known function, pre-construct a system of equations. And initialize it to an empty set, and discover the periodicity. Included in set and will Insert as the first element into the system of equations .

5. A quantum key recovery attack method as described in claim 1, characterized in that, Build a new Cyclic functions are used to extract new periods and add them to the set. and system of equations .

6. The quantum key recovery attack method as described in claim 5, characterized in that, gather The selected value is used as the input to the equivalent cryptographic structure.

7. A quantum key recovery attack system, characterized in that, include: The equivalent cryptographic structure building module is configured to utilize cryptographic algorithms. Construct a Equivalent cryptographic structure of the wheel ,make and The ciphertext is the same, the cryptographic algorithm The key is ; The periodic function building module is configured to construct Cyclic function; The period determination module is configured to find the period. ,judge Is it or If so, then let Otherwise, Place into the system of equations In order to find a solution or , and then ; The iterative execution module is configured to determine the current state. Is it greater than the set number of rounds? If so, then construct a new one. Cyclic functions are used to extract new periods and add them to the system of equations. The process is repeated iteratively until the system of equations is reached. Solvable, recoverable or If not, then perform a key recovery attack in a single-key scenario to obtain the key.

8. A quantum key recovery attack system as described in claim 7, characterized in that, The equivalent cryptographic structure building module is configured to, if the key state The value is known, using a cryptographic algorithm The second round to the 1st Wheel construction Equivalent cryptographic structure of the wheel ; If key state The value is known, using a cryptographic algorithm The first round to the Wheel construction Equivalent cryptographic structure of the wheel .

9. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed by a processor, complete the steps of the method according to any one of claims 1-7.

10. An electronic device, characterized in that, It includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the steps of the method according to any one of claims 1-7.