A hybrid quantum and classical symmetric encryption key search method

By dividing the key into classical and quantum parts and combining Hamiltonian operator optimization, the problem of high resource consumption in existing technologies is solved, achieving efficient key search, reducing the resource requirements of quantum hardware and improving search efficiency.

CN121690578BActive Publication Date: 2026-04-17ZHEJIANG ZHIJIANG SHUAN QUANTUM TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ZHEJIANG ZHIJIANG SHUAN QUANTUM TECH CO LTD
Filing Date
2026-02-10
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing variable quantum security analysis methods are optimized on the complete key space, resulting in huge resource overhead and a lack of effective integration with classical search strategies, making it difficult to achieve efficient security analysis with limited quantum resources.

Method used

A hybrid quantum and classical symmetric encryption key search method is adopted, which divides the key into two parts: the classical end traverses one part, and the quantum end is encoded as a superposition state. The remaining part is optimized by Hamiltonian operator. By combining classical traversal and quantum superposition state optimization, the consumption of quantum resources is reduced and a high search success rate is maintained.

Benefits of technology

The algorithm achieves hierarchical and quantized processing of the search space, significantly reducing the number of qubits, alleviating hardware resource pressure, improving the stability and robustness of the algorithm, and enhancing search efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690578B_ABST
    Figure CN121690578B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of secret communication, and discloses a mixed quantum and classical symmetric encryption key security analysis method, receives a plurality of pairs of known plaintext and ciphertext data, constructs a Hamiltonian operator for each pair, makes a quantum state corresponding to correct ciphertext a ground state, divides a key into two segments, and circularly traverses all values of the first segment; in each cycle, a parameterized superposition state composed of all values of the second segment is constructed on a quantum register, and is input into a quantum encryption circuit together with a plaintext quantum state to generate a ciphertext superposition state, a cost function is obtained by measuring a weighted average of Hamiltonian expectation value, and a parameter is optimized by using a quantum variation algorithm until the ciphertext superposition state converges to a state corresponding to a correct key, and the second segment key can be determined by measuring the optimized quantum state, and the complete key is analyzed in combination with the value of the first segment. The method has the advantages of classical enumeration and quantum optimization, reduces the number of quantum bits while maintaining high analysis efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure communication technology, and in particular to a hybrid quantum and classical symmetric encryption key search method. Background Technology

[0002] Existing symmetric encryption algorithms (such as AES and SM4) possess extremely high security strength under classical computing models, but their key spaces grow exponentially, making enumeration methods unsuitable for key security analysis. With the development of quantum computing, researchers have proposed various cryptanalysis methods utilizing quantum parallelism and superposition properties. One representative approach is key search based on variational quantum algorithms. This type of method generates superposition states of candidate keys by constructing parameterized quantum circuits and optimizes the state energy using Hamiltonian operators related to the plaintext-ciphertext relationship, making the quantum state corresponding to the correct key the ground state of the system, thus allowing the correct key to be obtained through measurement.

[0003] However, existing variational quantum security analysis methods typically optimize directly on the complete key space, resulting in a requirement for a number of qubits that is proportional to the key length, leading to enormous resource overhead. Furthermore, these methods rely entirely on the quantum optimization process and lack effective integration with classical search strategies, making it difficult to achieve efficient security analysis under limited quantum resources. Given the current limitations of quantum computing capabilities, effectively reducing the search space and circuit depth under limited quantum resources has become a critical problem that urgently needs to be solved in the field of quantum-assisted symmetric key analysis. Summary of the Invention

[0004] To address the aforementioned shortcomings of existing technologies, this invention proposes a hybrid quantum and classical symmetric encryption key search method. This method traverses a portion of the key bits on the classical side, encodes the remaining key bits into a quantum superposition state, and solves the remaining part through variational optimization. This reduces quantum resource consumption while maintaining a high search success rate.

[0005] The technical solution of this invention is implemented as follows:

[0006] The technical solution of this invention is implemented as follows:

[0007] A hybrid quantum and classical symmetric encryption key search method, comprising the following steps:

[0008] 1) Receive several pairs of known plaintext and ciphertext data. ,in The sequence number of the plaintext / ciphertext pair; ciphertext... To use the same length Key to plaintext Encrypted and All lengths ;

[0009] 2) For each pair of data Construct Hamiltonian operators respectively , making ciphertext The corresponding quantum state is the Hamiltonian operator. The ground state;

[0010] 3) Divide the key into a first segment and a second segment. Iterate through all values ​​in the first segment, with each iteration including the following sub-steps:

[0011] 31) In each iteration, construct a parameterized superposition state consisting of all values ​​of the second segment, and input it together with the known plaintext quantum state into the quantum encryption circuit to generate a ciphertext superposition state;

[0012] 32) Obtain the superposition state of the ciphertext and measure the Hamiltonian expectation. ;

[0013] 33) Through Hamiltonian expectation Optimize the parameters until the ciphertext superposition state converges to the state corresponding to the correct key, where the state corresponding to the correct key refers to the known ciphertext in step 2). The corresponding quantum state, the parameter optimization process is to make the Hamiltonian operator Compared to possible ciphertext Hamiltonian expectation of superposition state smallest, when Minimum time ciphertext The superposition state is closest to the known ciphertext. The superposition state of the key is closest to the correct key;

[0014] 34) Determine the second segment key and analyze the security of the complete key in conjunction with the value of the first segment.

[0015] Preferably, in step 3), an integer parameter is set. The key is divided into a sequence consisting of the most significant bits. The first segment, and a sequence consisting of the least significant bits. The second segment is divided into two parts, and the first segment bit values ​​of each possible group of keys are iterated over. Each iteration of the iteration includes the following sub-steps:

[0016] 31) In a A parameterized quantum state is constructed on the bit quantum register. The parameterized quantum state is a parameterized superposition state composed of all possible values ​​of the second segment of the key.

[0017] 32) For each pair of data, in a A quantum state corresponding to the known plaintext is constructed on the quantum register. The parameterized superposition state obtained in step 31) and the known plaintext quantum state are input to a quantum-implemented symmetric encryption circuit. The symmetric encryption circuit uses the key obtained by combining the first segment value and the second segment value in the second segment superposition state to encrypt the plaintext to obtain a ciphertext superposition state. The ciphertext superposition state is then stored in the quantum register. A bit quantum register is used to measure the expected value of the Hamiltonian operator for the superposition state of the ciphertext;

[0018] 33) The parameters of the parameterized quantum state are optimized using a weighted average of the expected values ​​of the Hamiltonian operators as the cost function;

[0019] 34) Measure the second segment superposition state after parameter optimization to obtain the value of the second segment, and check whether the correct key is obtained after merging the value of the first segment with the measured value of the second segment. If the correct key is obtained after no more than a limited number of measurements, the loop ends; otherwise, the next loop begins.

[0020] Preferably, the integer parameter The optimal value is selected based on the estimated success rate of the security analysis key, the estimated runtime, and resource limitations. The specific selection method includes the following steps:

[0021] 1) Generate multiple instances of plaintext-ciphertext pairs with known keys;

[0022] 2) Different tests were conducted for the aforementioned examples. The impact of the value on the success rate, runtime, and resource consumption of security analysis keys was investigated, and the respective effects of these factors on the success rate, runtime, and resource consumption were fitted based on the test results. Value dependencies;

[0023] 3) Set limits on the success rate and resource consumption of the security analysis key, and select the method that minimizes the running time while satisfying the limits, based on the aforementioned dependencies. value.

[0024] Preferably, before step 3), a consistency check is performed on the first segment of the candidate key based on the known structure or input-output characteristics of the encryption algorithm. When the check result shows that the first segment does not match any known plaintext-ciphertext pair, the value of the first segment is excluded to reduce the set of first segments that need to be enumerated.

[0025] Preferably, the loops of different first segments can be distributed to different computing nodes for parallel execution, and a centralized classical verification unit is used to summarize and finally verify the candidate keys.

[0026] Preferably, the parameter optimization used in step 33) employs a gradient-based optimization algorithm, and a restart strategy is implemented when the gradient norm is lower than a preset threshold.

[0027] Preferably, the Hamiltonian operator constructed in step 2 The form is

[0028] ,

[0029] in To act on the The first bit of the quantum register Pauli-Z operator for qubits, , , , Let represent the coupling constants of the quartic, cubic, quadratic, and linear terms in the Hamiltonian operator relative to the Pauli-Z operator, respectively. The values ​​of each coupling constant are as follows:

[0030] ,

[0031] in Let be pre-selected real numbers, representing the weights of the corresponding quartic, cubic, quadratic, and linear terms in the Hamiltonian operator, respectively. This indicates the first known ciphertext. bit value The corresponding Pauli-Z operator eigenvalues, used to ensure that the ciphertext corresponds to Hamilton's ground state, are determined by the following equation: .

[0032] Compared with the prior art, the present invention has the following beneficial effects:

[0033] This invention proposes a hybrid quantum and classical symmetric encryption key search method, which combines classical ergodicity with quantum superposition to achieve hierarchical and quantized processing of the search space. This strategy significantly reduces the number of qubits required for quantum circuits while maintaining overall search coverage, thus alleviating the pressure on quantum hardware resources.

[0034] By constructing a corresponding Hamiltonian operator for each plaintext-ciphertext pair, the correctness of encryption can be directly reflected by the magnitude of the Hamiltonian expectation value, thus transforming the key security analysis problem into a quantum state energy minimization problem. This quantized energy characterization method avoids the limitations of traditional quantum search relying on discrete matching or Boolean discriminant functions, improving the stability and interpretability of quantum state optimization;

[0035] Introducing a weighted average of the cost function during quantum state optimization allows the constraints of multiple samples to be incorporated into the optimization objective simultaneously, thereby improving the robustness of the algorithm under conditions of noise or partial plaintext mismatch.

[0036] By adjusting the segment size based on the estimated success rate and resource consumption, a balanced allocation between the quantum and classical parts is achieved, thereby maintaining optimal performance under different encryption algorithms or hardware constraints.

[0037] The consistency detection mechanism eliminates obviously inconsistent key segments before quantum execution, significantly reducing invalid computations and improving overall search efficiency. Attached Figure Description

[0038] Figure 1 This is an overall flowchart of a hybrid quantum and classical symmetric encryption key search method of the present invention;

[0039] Figure 2 This is a quantum circuit used in an embodiment of the present invention to generate a parameterized key second segment superposition state. Detailed Implementation

[0040] The present invention will now be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention.

[0041] like Figure 1 As shown, this invention proposes a hybrid quantum and classical symmetric encryption key search method, which includes the following steps:

[0042] 1) Receive several pairs of known plaintext and ciphertext data. :in The sequence number of the plaintext / ciphertext pair; ciphertext... To use the same length Key to plaintext Encrypted and All lengths ;

[0043] 2) Construct Hamiltonians based on known ciphertexts: For each pair Construct a Hamiltonian operator respectively , making The corresponding quantum state is The ground state;

[0044] 3) Divide the key and traverse the first segment of the key: Set integer parameters The key is divided into a sequence consisting of the most significant bits. The first segment, and a sequence consisting of the least significant bits. The second segment is divided into two parts, and the first segment bit values ​​of each possible group of keys are iterated over in a loop. Each iteration of the loop includes the following sub-steps:

[0045] 31) Constructing the parameterized superposition state of the second segment of the key: in a A parameterized quantum state is constructed on the bit quantum register. The parameterized quantum state is a parameterized superposition state composed of all possible values ​​of the second segment of the key.

[0046] 32) Obtain the superposition of ciphertext states and measure the Hamiltonian expectation: for each pair In one Construct a corresponding plaintext on a bit quantum register The quantum state, the superposition state obtained in step 31), and the plaintext The quantum state is input to a quantum-realized symmetric encryption circuit, which uses a key obtained by combining the first segment value with the second segment value in a superposition state to pair the plaintext. Encryption is performed to obtain a ciphertext superposition state, and the ciphertext superposition state is stored in the... A bit quantum register is used to measure the Hamiltonian operator for the superposition state of the ciphertext. Expected value ;

[0047] 33) Optimize parameters using Hamiltonian expectation: The weighted average is used as the cost function to optimize the parameters of the parameterized quantum state, through the Hamiltonian expectation value. Optimize the parameters until the ciphertext superposition state converges to the state corresponding to the correct key, where the state corresponding to the correct key refers to the known ciphertext in step 2). The corresponding quantum state, the parameter optimization process is to make the Hamiltonian operator Compared to possible ciphertext Hamiltonian expectation of superposition state smallest, when Minimum time ciphertext The superposition state is closest to the known ciphertext. The superposition state of the key is closest to the correct key;

[0048] 34) Measure the security analysis key of the second segment: Measure the superposition state of the second segment after parameter optimization to obtain the value of the second segment, and check whether the correct key is obtained after merging the value of the first segment with the measured value of the second segment. If the correct key is obtained after no more than a limited number of measurements, the loop ends; otherwise, the next loop begins.

[0049] The integer parameter The optimal value is selected based on the estimated success rate of the security analysis key, the estimated runtime, and resource limitations.

[0050] It also includes, before step 3), performing a consistency check on the first segment of the candidate key based on the known structure or input-output characteristics of the encryption algorithm. When the check result shows that the first segment does not match any known plaintext-ciphertext pair, the value of the first segment is excluded to reduce the set of first segments that need to be enumerated.

[0051] The loops of different first segments can be distributed to different computing nodes for parallel execution, and a centralized classical verification unit is used to summarize and finally verify the candidate keys.

[0052] The parameter optimization used in step 33) employs a gradient-based optimization algorithm, and a restart strategy is implemented when the gradient norm falls below a preset threshold.

[0053] The Hamiltonian operator constructed in step 2 The form is

[0054] ,

[0055] in To act on the The first bit of the quantum register Pauli-Z operator for qubits, , , , Let represent the coupling constants of the quartic, cubic, quadratic, and linear terms in the Hamiltonian operator relative to the Pauli-Z operator, respectively. The values ​​of each coupling constant are as follows:

[0056] ,

[0057] in Let be pre-selected real numbers, representing the weights of the corresponding quartic, cubic, quadratic, and linear terms in the Hamiltonian operator, respectively. This indicates the first known ciphertext. bit value The corresponding Pauli-Z operator eigenvalues, used to ensure that the ciphertext corresponds to Hamilton's ground state, are determined by the following equation: .

[0058] Embodiments of the present invention:

[0059] This embodiment takes the simplified AES algorithm (S-AES) as an example to provide a complete implementation scheme of a hybrid quantum and classical symmetric encryption key search method. The steps of this method are as follows.

[0060] Step 1: Receive 5 pairs of known plaintext and ciphertext data. The key length Bits, plaintext and ciphertext length The encryption algorithm is S-AES, and all ciphertexts are generated using the same 16-bit key.

[0061] Step 2: Prepare a 16-bit quantum register Used to store the quantum states corresponding to plaintext and ciphertext. For each ciphertext... Construct Hamiltonian operators of the following form. :

[0062] ,

[0063] in To act on The Middle The Pauli-Z operator for qubits has the following coefficient values:

[0064] ,

[0065] in From the known ciphertext, the first bit value Determined: .

[0066] Step 3: Set parameters The 16-bit key is divided into a first segment consisting of the highest 4 bits and a second segment consisting of the lowest 12 bits. A 12-bit quantum register is prepared. Used to store the quantum states corresponding to the second segment. For all of the first segment... The possible values ​​are iterated through in a loop, and each iteration includes the following sub-steps:

[0067] Step 3.1 In Preparation of parameterized quantum states The operator unitary operator , and Constructed by:

[0068] ,

[0069] right Initialize the bit strings so that all candidate bit strings have non-zero amplitudes. Provides adjustable local single-bit rotation. Introducing correlation and interference between in-situ entities, their forms are as follows:

[0070] ,

[0071] ,

[0072] ,

[0073] in and For angle parameters, Indicates the first One bit rotated relative to the Y-axis Angle rotation operator, Indicates the first One bit rotated relative to the Z-axis Angle rotation operator, Indicates the first Bit as control bit for the first The control Z-gate for bit application operations, .

[0074] Operator The corresponding circuit is as follows Figure 2 As shown.

[0075] Step 3.2 For each pair ,exist Construct a corresponding plaintext quantum state The second segment superposition state With the known plaintext quantum state The input is fed into a quantum-implemented S-AES encryption circuit, which uses a first segment value and... The key pair obtained by merging the values ​​of the second segment in the middle Encryption is performed to obtain a ciphertext superposition state, and the ciphertext superposition state is stored in... And for the measurement of the superposition state of the ciphertext Expected value ;

[0076] Step 3.3 As a cost function, the parameters of the parameterized quantum state are calculated using the stochastic gradient descent algorithm. and Optimize to make The minimum value is reached when the gradient norm is below the threshold. If necessary, restart the optimization process.

[0077] Step 3.4 Optimize the parameters of the state The value of the second segment is obtained through measurement. The current first segment is merged with the measured second segment. The merged result is used as the key, and classic S-AES encryption is used to verify the known plaintext-ciphertext pair to determine if the key is correct. If the verification passes, the key is output and the process terminates; otherwise, the next loop continues.

[0078] In the above key security analysis process, for Different choices of values ​​will affect several metrics of key security analysis, such as the number of qubits required, the success rate of key security analysis, and the overall runtime of the method. In practical implementation, multiple plaintext-ciphertext pairs with known keys can be generated first to test different... The influence of the value on the aforementioned indicators is then determined, and an upper limit for the number of qubits and a lower limit for the success rate of security analysis are set. Under the premise of satisfying these constraints, the option that minimizes the running time is selected. value.

[0079] As can be seen from the embodiments of this invention, this invention proposes a hybrid quantum and classical symmetric encryption key search method. It utilizes a combination of classical ergodicity and quantum superposition to achieve hierarchical and quantized processing of the search space. This strategy significantly reduces the number of qubits required by quantum circuits while ensuring overall search coverage, thus alleviating the pressure on quantum hardware resources. By constructing corresponding Hamiltonian operators for each pair of plaintext and ciphertext, the encryption correctness can be directly reflected by the magnitude of the Hamiltonian expectation value, thereby transforming the key security analysis problem into a quantum state energy minimization problem. This quantized energy characterization method avoids the limitations of traditional quantum search relying on discrete matching or Boolean discriminant functions, improving the stability and interpretability of quantum state optimization. The introduction of a weighted average of the cost function during quantum state optimization allows constraints from multiple samples to be simultaneously incorporated into the optimization objective, thereby enhancing the algorithm's robustness under conditions of noise or partial plaintext mismatch. By adjusting the segment size based on the estimated success rate and resource consumption, a balanced allocation between the quantum and classical parts is achieved, maintaining optimal performance under different encryption algorithms or hardware constraints. The consistency detection mechanism eliminates obviously inconsistent key segments before quantum execution, significantly reducing invalid computation and improving overall search efficiency.

[0080] The method of this invention is used for security assessment, penetration testing and vulnerability verification within the authorized scope, and its application requires explicit authorization from the system owner.

[0081] The receipt and processing of data related to this invention must comply with the relevant laws, regulations and standards of the relevant countries and regions. The sale, transfer and deployment of the tools or systems involved must comply with the relevant laws and regulations of the country regarding cryptographic technology and network security products.

Claims

1. A hybrid quantum and classical symmetric encryption key search method, characterized by, Includes the following steps: 1) Receive several pairs of known plaintext and ciphertext data, where the ciphertext is obtained by encrypting the plaintext using a key of the same length; 2) Construct a Hamiltonian operator for each pair of data, such that the quantum state corresponding to the ciphertext is the ground state of the Hamiltonian operator; 3) Set integer parameters The key is divided into a sequence consisting of the most significant bits. The first segment, and a sequence consisting of the least significant bits. The second segment is divided into two parts, and the first segment bit values ​​of each possible group of keys are iterated over. Each iteration of the iteration includes the following sub-steps: 31) In one constructing a parameterized quantum state on a qubit quantum register, the parameterized quantum state being a parameterized superposition state of all possible values of a key second segment; 32) For each pair of data, in a A quantum state corresponding to the known plaintext is constructed on the quantum register. The parameterized superposition state obtained in step 31) and the known plaintext quantum state are input to a quantum-implemented symmetric encryption circuit. The symmetric encryption circuit uses the key obtained by combining the first segment value and the second segment value in the second segment superposition state to encrypt the plaintext to obtain a ciphertext superposition state. The ciphertext superposition state is then stored in the quantum register. A bit quantum register is used to measure the expected value of the Hamiltonian operator for the superposition state of the ciphertext; 33) The parameters of the parameterized quantum state are optimized using a weighted average of the expected values ​​of the Hamiltonian operators as the cost function; 34) Measure the second segment superposition state after parameter optimization to obtain the value of the second segment, and check whether the correct key is obtained after merging the value of the first segment with the measured value of the second segment. If the correct key is obtained after no more than a limited number of measurements, the loop ends; otherwise, the next loop begins.

2. The hybrid quantum and classical symmetric encryption key search method of claim 1, wherein, The integer parameter The optimal value is selected based on the estimated success rate of the security analysis key, the estimated runtime, and resource limitations. The specific selection method includes the following steps: 1) Generate multiple instances of plaintext-ciphertext pairs with known keys; 2) Different tests were conducted for the aforementioned examples. The impact of the value on the success rate, runtime, and resource consumption of security analysis keys was investigated, and the respective effects of these factors on the success rate, runtime, and resource consumption were fitted based on the test results. Value dependencies; 3) setting limits on the success rate of security analysis keys and resource consumption, and selecting the value that results in the shortest running time under the constraints according to the dependencies values.

3. The hybrid quantum and classical symmetric encryption key search method of claim 1, wherein, It also includes, before step 3), performing a consistency check on the first segment of the candidate key based on the known structure or input-output characteristics of the encryption algorithm. When the check result shows that the first segment does not match any known plaintext-ciphertext pair, the value of the first segment is excluded to reduce the set of first segments that need to be enumerated.

4. The hybrid quantum and classical symmetric encryption key search method of claim 1, wherein, The loops of different first segments can be distributed to different computing nodes for parallel execution, and a centralized classical verification unit is used to summarize and finally verify the candidate keys.

5. The hybrid quantum and classical symmetric encryption key search method of claim 1 or 3 or 4, wherein, The parameter optimization used in step 33) employs a gradient-based optimization algorithm, and a restart strategy is implemented when the gradient norm falls below a preset threshold.

6. The hybrid quantum and classical symmetric encryption key search method of claim 1 or 3 or 4, wherein, where the Hamiltonian operator constructed in step 2 is of the form , in To act on the The first bit of the quantum register Pauli-Z operator for qubits, , , , Let represent the coupling constants of the quartic, cubic, quadratic, and linear terms in the Hamiltonian operator relative to the Pauli-Z operator, respectively. The values ​​of each coupling constant are as follows: ,in Let be pre-selected real numbers, representing the weights of the corresponding quartic, cubic, quadratic, and linear terms in the Hamiltonian operator, respectively. This indicates the first known ciphertext. bit value The corresponding Pauli-Z operator eigenvalues, used to ensure that the ciphertext corresponds to Hamilton's ground state, are determined by the following equation: .

Citation Information

Patent Citations

  • Attack method for data encryption standard and advanced data encryption standard

    CN115333717A

  • Multi-strategy combined key search method and device based on Grover algorithm

    CN116389124A