Automatic key guessing path searching method for LLLWBC cryptographic algorithm

By automating the construction of key recovery paths for the LLLWBC algorithm using the MILP model, the complexity of the key recovery process in integral attacks is solved, and efficient and optimized key guessing path search is achieved, thereby improving the analysis efficiency and security assessment of block cipher algorithms.

CN121841602APending Publication Date: 2026-04-10GUILIN UNIV OF ELECTRONIC TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUILIN UNIV OF ELECTRONIC TECH
Filing Date
2026-01-15
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technologies struggle to automate the determination of the optimal key guessing path in integral attacks, leading to high complexity in the key recovery process, suboptimal path selection, and cumbersome derivation processes when the number of attack rounds expands, thus affecting the analysis efficiency of block cipher algorithms.

Method used

A mixed-integer linear programming (MILP) model is adopted, which combines the round function structure of the LLLWBC algorithm and the information of the integrator discriminator to automatically construct the key recovery path. The key guessing path is optimized by minimizing the number of key bits guessed.

Benefits of technology

It automates and efficiently solves the key recovery process, reduces attack complexity, improves analysis efficiency and success rate, and is applicable to integral distinguisher scenarios for other block cipher algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841602A_ABST
    Figure CN121841602A_ABST
Patent Text Reader

Abstract

The invention discloses an automatic key guessing path searching method for an LLLWBC cryptographic algorithm, and belongs to the technical field of information security. Aiming at the problem that a key guessing path depends on manual analysis in an integral attack key recovery stage of the LLLWBC block cipher, and optimality is difficult to guarantee, the method comprises the following steps of: uniformly modeling certainty of an intermediate status word and guessing requirements of a round key in a decryption process into binary variables based on an integral discriminator; according to an LLLWBC round function and a key arrangement structure, a state and key dependence constraint is established, a mixed integer linear optimization model is constructed by taking minimization of a key bit number needing guessing as a target, and an optimal key guessing path is obtained through automatic solving. And executing partial decryption based on the optimal path and realizing key recovery by utilizing integral balance judgment. According to the method, the key recovery complexity is remarkably reduced, and the automation degree and the analysis efficiency of integral attacks are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, specifically relating to the security analysis of block ciphers, and more specifically, to a method for automatically searching for the optimal key guessing path in the LLLWBC cryptographic algorithm during integral attacks. Background Technology

[0002] The LLLWBC algorithm, proposed in 2022 by Zhang Lei et al. from the Institute of Software, Chinese Academy of Sciences, is a lightweight block cipher algorithm designed for low-latency applications, exhibiting high encryption and decryption efficiency in both software and hardware implementations. The LLLWBC algorithm uses a 64-bit block length and a 128-bit key length, denoted as LLLWBC-64 / 128. Its round function structure is an extended generalized Feistel structure with 16 branches and 21 rounds of iteration. LLLWBC comprises three parts: a key scheduling algorithm, an encryption algorithm, and a decryption algorithm, with the encryption and decryption algorithms having identical structures. Despite LLLWBC's outstanding performance, its resistance to attacks from novel security analysis techniques requires further evaluation.

[0003] Existing integral attacks, after obtaining the integral discriminator, typically rely on manual determination of round key guess positions and decryption paths during the key recovery phase. However, different guess paths correspond to different key recovery attack complexities, making it difficult to find the optimal guess path. This can easily lead to excessively large key guess bits, difficulty in guaranteeing optimal path selection, and uncertain complexity assessment. Furthermore, the derivation process becomes cumbersome when the attack rounds are extended, thus limiting the automated application and analysis efficiency of integral attacks on complex block cipher structures. Therefore, it is necessary to propose a device that can automatically generate the optimal key guess set and decryption path based on the integral discriminator structure and algorithm structure, and an automatic key recovery path optimization method aimed at minimizing the size of the guessed key.

[0004] Integral analysis [1] was originally proposed by Knudsen et al. to evaluate the security of the Square algorithm. By selecting appropriate plaintext active bits and constant bits to construct the corresponding dataset, and then encrypting the dataset, if the XOR sum of some positions in the obtained ciphertext set is always 0, and this property is independent of the selection of the key, then the attacker has obtained an integral discriminator.

[0005] There are two main types of methods for constructing integral distinguishers. The first type focuses on using algebraic properties to construct integral distinguishers, that is, by evaluating the algebraic degree of the corresponding algebraic expression of the cryptographic algorithm output, and determining the form of the integral distinguisher accordingly. With the introduction of separability, this type of method has been studied in depth. Separability was proposed by Todo et al. [2] in 2015 as a generalized integral property, and subsequently bit separability was further developed. In order to improve the efficiency of distinguisher search, Xiang Zejun et al. [3] proposed a mixed integer linear programming (MILP) modeling method based on separability propagation and an automated search process for integral distinguishers. Wang Chen et al. [4] used the single-term propagation technique combined with MILP tools to search for integral distinguishers, and carried out key recovery calculations through partial and technical means to attack the UBLOCK family cryptographic algorithms, successfully increasing the number of integral attack rounds against the UBLOCK family algorithms.

[0006] However, such methods usually require a relatively refined bit-level analysis model for the round function; for block ciphers with large state scales, as the number of attack rounds increases, the description of bit-level separability often introduces a large number of inequality constraints, leading to a rapid increase in model size and a significant reduction in solution efficiency. To alleviate the above problems, another type of method uses the propagation law of integral properties at the structural level for construction and evaluation. For example, Zhang et al. [5] evaluated the algorithm's resistance to integral attacks by statistically analyzing the number of times plaintext or ciphertext appears in the internal state algebraic expression based on the permutation function property; on this basis, Ye et al. [6] introduced the concept of word propagation trajectory and gave a corresponding automated analysis model; subsequently, Xing et al. [7] proposed a framework for constructing an integral distinguisher from the perspective of algebraic structure, and combined the property of the difference distribution table to give a new algebraic structure with integral properties, using this property to obtain the longest integral distinguisher of the WARP algorithm, and using this integral distinguisher to implement a 26-round key recovery attack.

[0007] Although the aforementioned research has made considerable progress in the construction and automated search of integral distinguishers, making it possible to obtain effective integral distinguishers at higher round numbers, existing technologies mainly focus on the search process of the distinguisher itself and lack effective solutions to the automation problem of the key recovery phase in integral attacks.

[0008] References:

[0009] [1]Knudsen L, Wagner D. Integral cryptanalysis[C] / / Proc of the IntWorks on Fast Software Encryption. Berlin: Springer, 2002: 112-127;

[0010] [2] Todo Y. Structural evaluation by generalized integral property[C] / / Proc of the Annual Int Conf on the Theory and Applications ofCryptographic Techniques. Berlin: Springer, 2015: 287–314;

[0011] [3] Xiang Zejun, Zhang Wentao, Bao Zhenzhen, et al. Applying MILPmethod to searching integral distinguishers based on division property for 6lightweight block ciphers[C] / / Proc of the Int Conf on Fast SoftwareEncryption. Cham: Springer, 2016: 357-377;

[0012] [4] Wang Chen, Cui Jiamin, Li Muzhou, Wang Meiqin, Improvement of uBlock integral attack on block cipher algorithm [J]. Journal of Electronics and Information Technology, 2024, 46(5): 2149-2158;

[0013] [5] Zhang Wenying, Cao Meichun, Guo Jian, et al. Improved security evaluation of SPN block ciphers and its applications in the single-key attack on SKINNY[J]. IACR Transactions on Symmetric Cryptology, 2019.2019(4): 171-191;

[0014] [6] Ye Tao, Wei Yongzhuang, Li Lingchen. Integral analysis of ACE cryptographic algorithm [J]. Journal of Electronics and Information Technology, 2021, 43(4): 908-914;

[0015] [7] Xing Zhaohui, Zhang Wenying, Cao Meichun. Integral analysis of lightweight block cipher WARP from the perspective of algebraic structure [J]. Computer Research and Development, 2023, 60(4): 860-872. Summary of the Invention

[0016] To address the problems mentioned in the background section, this invention aims to provide an automated key guessing path search method for the LLLWBC cryptographic algorithm, thereby enabling automatic search for the optimal path during the key recovery phase of an integral attack, reducing attack complexity, and improving analysis efficiency and automation.

[0017] To achieve the above objectives, the present invention adopts the following technical solution:

[0018] An automated key guessing path search method for the LLLWBC cryptographic algorithm includes the following steps:

[0019] (1) MILP variable initialization: Receive LLLWBC integrator information, and based on the integrator round number R1 and its balance word subscript set BT, extend the encryption direction by R2 rounds;

[0020] Based on the information from the integrator, a binary variable for a mixed-integer linear programming model for key recovery path search is established, including round key guessing variables and round input state determinability variables, and MILP model constraints are constructed based on the balance word subscript set BT.

[0021] (2) Modeling of permutation operation: Based on the algebraic expression of the decryption direction of the round function of the LLLWBC algorithm, the branch equation that only requires linear permutation operation is derived and transformed into the permutation constraint of the MILP model;

[0022] (3) Boolean expression modeling based on word operations: For branches in the LLLWBC algorithm that require F-function operation before linear permutation, a custom Boolean expression model is used. The function transforms branching operations into model constraints, characterizing the dependency relationship between state variables and key variables;

[0023] (4) Objective function modeling: With minimizing the number of guessed key bits as the optimization objective, the objective function of the MILP model is constructed, including round key guessing variables and whitening key variables;

[0024] (5) Search for LLLWBC key guessing path in round R2: Integrate the variables and constraints of steps (1) to (4), traverse the loop through rounds, call variable initialization, permutation constraints, word operation constraints and objective function, complete the output from the integrator, and obtain the optimal key guessing path that minimizes the size of the guessed key;

[0025] (6) MILP model solution: Traverse all non-empty subsets of the balance word index set BT of the integral distinguisher, construct a model for each subset as the attack target, select the subset that minimizes the objective function value as the optimal balance bit attack combination, solve the model with the Gurobi solver, obtain the optimal key guess set corresponding to each balance bit attack combination, and complete the model solution for R2 round key recovery.

[0026] Further, the initialization of the MILP variables in step (1) specifically involves the following steps:

[0027] First, define a MILP model as M, then define the round key guessing variable as... , indicating whether the key for the i-th round of the r-th round needs to be guessed;

[0028] , representing the key used in the r-th round function. Whether it is being speculated upon For binary model variables, when When the value is 1, it means The value needs to be guessed; otherwise, The values ​​do not need to be guessed, among which , ;

[0029] Secondly, define the deterministic variables of the wheel input state as follows: , indicating whether the value of the i-th state in the r-th round can be determined;

[0030] , representing the value of the input state of the function in the r-th round. Whether it can be guessed to determine, where the model variables and Correspondingly, For binary model variables, when When the value is 1, it means The value can be guessed and determined, among which ;

[0031] Finally, constraints for the MILP model are constructed based on a non-empty subset of the balanced word subscript set BT. If the i-th equilibrium position is selected as the attack target, then the state determinism constraint corresponding to that equilibrium position needs to be added to the model. The specific constraint form is as follows: , , ,in For the number of BT, This indicates the output state of the R1 round integrator.

[0032] Furthermore, the permutation operation modeling in step (2) specifically involves the following steps: based on the round function structure of the LLLWBC algorithm, the input state of the r-th round... In the process, eight branches only require linear permutation operations to obtain the output state of the r-th round, while the remaining eight branches first require F function operations, followed by linear permutation operations to obtain the corresponding output state of the r-th round.

[0033] When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches requiring only linear permutation operations. :

[0034] ;

[0035] based on The equations are used to construct MILP model constraints and add them to the model. The specific method is as follows:

[0036]

[0037]

[0038]

[0039]

[0040] When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches requiring only linear permutation operations. :

[0041] ;

[0042] based on The equations are used to construct MILP model constraints and add them to the model. The specific method is as follows:

[0043]

[0044]

[0045]

[0046]

[0047] Furthermore, the Boolean expression modeling based on word operations described in step (3) specifically involves: for the input state in the r-th round of the LLLWBC algorithm... The eight branches, which require an F-function operation followed by a linear permutation operation, are combined with the algebraic expression for the decryption direction in the r-th round of the LLLWBC algorithm. and The corresponding inequalities are obtained, the corresponding equality is derived, and model constraints are constructed, as follows:

[0048] When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches that requires an F-function operation followed by a linear permutation operation. :

[0049] ;

[0050] When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches that requires an F-function operation followed by a linear permutation operation. :

[0051] ;

[0052] exist and In this equation, the determination of the variables on the left side depends on the guessed state of the variables on the right side. Specifically, the value of the variables on the left side can only be determined after all the guesses of the variables on the right side of the equation have been determined.

[0053] by The first equation For example, when , , The value was guessed and the subkey was guessed. back, Only the value of this can be determined; this relationship is established through a function. Indicate:

[0054] ;

[0055] In function In the text, the first line indicates: if , , and If both are 1, then It must be 1; lines 2-5 are used to indicate: when , , and There exists a value of 0, It must be 0;

[0056] This set of constraints precisely describes the requirement that the balance bit verification of the integrator must ensure that the key intermediate states during the decryption process can be derived and determined. This constraint clarifies that the target state variable of round r-1 can only be determined as the variable that needs to be guessed when both the state variable and the round key variable of round r are guessed and determined.

[0057] When the number of rounds At that time, based on Equations and functions Build MILP model constraints and add them to the model The specific method is as follows:

[0058]

[0059]

[0060]

[0061]

[0062] When the number of rounds At that time, based on Equations and functions Build MILP model constraints and add them to the model The specific method is as follows:

[0063]

[0064]

[0065]

[0066]

[0067] Furthermore, the objective function modeling in step (4) involves the following steps: first, defining the model variable corresponding to the whitening key as... , For binary model variables, when When the value is 1, This indicates that the value of the i-th word in the whitening key needs to be guessed; otherwise, it does not need to be guessed.

[0068] At the same time, due to the The output of the round is XORed with the whitening key to obtain the output of the simplified round's cryptographic algorithm. The output of the simplified round is known during the attack; when the attacker guesses the value of the i-th word of the whitening key, i.e., the model variable... The value is 1, at which point encryption is enabled. The value of the i-th byte in the internal state after the round can also be determined by guessing, that is, the value of the model variable is 1. Therefore, we can obtain: ,in ;

[0069] Finally, based on the state and key dependency linear constraints established in steps (1), (2), and (3), a MILP model is constructed with the optimization objective of minimizing the number of key bits required to be guessed during key recovery. The objective function is: .

[0070] Furthermore, the LLLWBC key guessing path search in step (5) of round R2 specifically involves searching the round key guessing MILP variables. State deterministic MILP variables Whitening key MILP variable , and based on round number interval , The constructed permutation operation constraints, and based on , Equation and The Boolean operation constraints of the function construction are uniformly incorporated into the MILP model M initialized in the initialization, and bound to the defined objective function of minimizing the number of guessed key bits. Thus constructing the orientation A complete MILP model for round key recovery.

[0071] Furthermore, the MILP model described in step (6) is solved to obtain the optimal value of the objective function. and key variables of each wheel and the Round Variable , The optimal key guess set corresponding to the whitened key, when When the value is 1, This indicates that the value of the i-th word in the whitening key needs to be guessed; otherwise, it does not need to be guessed.

[0072] Furthermore, the method also includes step (7) complexity evaluation, which involves deriving the number of master key bits to be guessed based on the optimal key guessing set obtained in step (6) and combining the LLLWBC key arrangement algorithm, and evaluating the time complexity, data complexity and storage complexity of the key recovery attack.

[0073] Furthermore, the complexity evaluation in step (7) is specifically conducted by: based on the optimal value of the objective function obtained in step (6). and key variables of each wheel and the Round Variable By combining the LLLWBC key arrangement algorithm, the round key and master key that need to be guessed in each round are calculated. The mapping relationship yields a master key that needs to be guessed, consisting of T bits. Guessing T bits of master key information... Decrypt the ciphertext set of the wheel;

[0074] Finally, determine the first The target word set of the wheel Whether it is balanced, where I represents the optimal combination of balanced bits. If it is unbalanced, it means that the guessed key is wrong; if it is balanced, it means that the guessed key is correct.

[0075] Due to the incorrect key The probability of being in equilibrium is N is the number of elements in the optimal balance position combination. The balance judgment process described above can be restored after one execution. After the key information of bits is filtered through plaintext by group Z, the number of erroneous keys is: It can recover T bits of key information, and the remaining... The bit key information was obtained through exhaustive search;

[0076] The time complexity of LLLWBC algorithm decryption is: Second-rate LLLWBC encryption, It is the number of active words, and the data complexity is O(n). The storage complexity is O(n^64) for 64-bit plaintext data. A 128-bit key sum is A 64-bit encrypted data.

[0077] Compared with the prior art, the present invention has the following beneficial effects:

[0078] 1. High efficiency and automation: It transforms the tedious manual key path analysis into an optimization problem that can be solved automatically, greatly improving analysis efficiency and avoiding logical oversights that are prone to occur in manual analysis.

[0079] 2. Guaranteeing optimality: By rigorously solving the mathematical programming model, the number of guesses required for the obtained key guessing path is minimized, thereby improving the economy and success rate of the attack.

[0080] 3. General and Scalable: The constraint modeling framework of this invention does not strictly depend on the specific parameters of LLLWBC. By adjusting the round function mapping relationship and constraint parameters, it can be adapted to the key recovery scenario of the integral distinguisher of other block cipher algorithms, reducing the development cost of attack analysis of new cryptographic algorithms.

[0081] 4. More precise assessment: It provides a calculable and reproducible quantitative assessment basis for the complexity of integral attacks, enhancing the reliability of security assessment. Attached Figure Description

[0082] Figure 1 This is a flowchart of the automated key guessing path search method of the present invention. Detailed Implementation

[0083] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments, but this is not intended to limit the scope of the invention.

[0084] Example 1 The hardware environment of this example is as follows: operating system is Windows 11, processor is Intel i7-13700KF, memory capacity is 32GB; software environment configuration is as follows: programming language is Python 3.10, mathematical programming solver is Gurobi 11.0.0 Academic Edition.

[0085] In this embodiment, taking the attack on the 12-round LLLWBC-64 / 128 algorithm as an example, starting with the output of the 9-round integrator and discriminator, and aiming at 12-round key recovery, the number of integrator and discriminator rounds R1=9, the number of extended rounds R2=3, and the set of balanced word indices of the 9-round integrator and discriminator are as follows: The number of active words is 12. The automated key guessing path search method for the LLLWBC cryptographic algorithm is described in reference [reference needed]. Figure 1 It includes the following steps:

[0086] (1) Input initialization: Receive integrator information, integrator round number R1=9, balance word subscript set of 9 rounds integrator. With an extended number of rounds R2=3, the balance word combination of the 9-round integrator is: , This provides initial conditions for constructing constraints on state variables in subsequent rounds.

[0087] (2) Initialize MILP variables and define the empty MILP model as follows: Initialize 9 rounds of state variables Add constraints: ;

[0088] Simultaneously initialize subkey variables for 10 to 12 rounds. Wheel state variables ,in The above variables are all binary variables, used to represent whether the subkey needs to be guessed and whether the round input state can be determined.

[0089] (3) Modeling of permutation operations: For In each round, based on the algebraic expression of the decryption direction corresponding to the current round number, the branch equations that require only linear permutation operations are derived in two categories:

[0090] when At that time, based on the equation Construct the following MILP model constraints and add them to the model. middle:

[0091]

[0092]

[0093]

[0094]

[0095] when At that time, based on the equation Construct the following MILP model constraints and add them to the model. middle:

[0096]

[0097]

[0098]

[0099]

[0100] when At that time, based on the equation Construct the following MILP model constraints and add them to the model. middle:

[0101]

[0102]

[0103]

[0104]

[0105] (4) Boolean expression modeling based on word operations: for For each round, for branches that require an F-function operation followed by a linear permutation operation, the branch equations are derived in two ways, based on the algebraic expression of the decryption direction corresponding to the current round number:

[0106] when At that time, based on the equation and Construct the following MILP model constraints and add them to the model. middle:

[0107]

[0108]

[0109]

[0110]

[0111]

[0112]

[0113]

[0114]

[0115] when At that time, based on the equation and Construct the following MILP model constraints and add them to the model. middle:

[0116]

[0117]

[0118]

[0119]

[0120]

[0121]

[0122]

[0123]

[0124] when At that time, based on the equation and Construct the following MILP model constraints and add them to the model. middle:

[0125]

[0126]

[0127]

[0128]

[0129]

[0130]

[0131]

[0132]

[0133] (5) Objective function modeling: With minimizing the number of guessed key bits as the optimization objective, and under the constraints of the state and key dependency constructed in the above modules, the objective function is constructed as follows:

[0134] .

[0135] (6) LLLWBC key guessing path search and MILP model solution in round R2: First, iterate through the balance bit set of the integrator discriminator. All combinations of equilibrium position combinations are generated synchronously to create model input constraints for the corresponding equilibrium position combinations. Then, the Gurobi solver is called to perform the solution operation on the model.

[0136] During the solution process, if an optimal solution exists in the model, the optimal values ​​of the round key guessing variables, the state determinism variables, and the optimal value of the objective function are extracted; ultimately, an optimal key guessing set corresponding to each equilibrium position combination is formed, completing the solution for the round key guessing variable. Solving the model for round key recovery;

[0137] By solving, the equilibrium position combination can be obtained. At that time, the corresponding optimal objective function value 19 and the key variables of each wheel , , And the variables in round 12 , which corresponds to the optimal guess set for the whitened key.

[0138] (7) Complexity assessment:

[0139] (7.1) Based on the key variables of each wheel obtained in step (6) , and and the Round Variable By combining the LLLWBC key arrangement algorithm, the round key and master key that need to be guessed in each round are calculated. Based on the mapping relationship, the set of master keys to be guessed is obtained, as follows:

[0140] For the 10th round, the round key that needs to be guessed is: , Only with the master key Related;

[0141] For round 11, the round key that needs to be guessed is: and , Only with the master key Related, Only with the master key Related;

[0142] For round 12, the round key that needs to be guessed is: , , , and These keys are only related to the master key. , , , and Related;

[0143] Therefore, the set of master keys associated with the round key is: The number of bits required to guess the master key is 28; and according to The value of can determine the post-whitening key that needs to be guessed, that is, the number of bits of the master key that needs to be guessed is 44-bit;

[0144] In summary, the number of bits required to guess the master key is 72 bits, which is the key space to be guessed. ;

[0145] (7.2) Guess the 72-bit key information and decrypt the ciphertext set of the simplified round;

[0146] Finally, determine if the second character in round 9 is balanced. If it is unbalanced, it means the guessed key is wrong; if it is balanced, it means the guessed key is likely correct.

[0147] Due to the incorrect key The probability of being in equilibrium is The above balance judgment process can recover 4 bits of key information in one execution. After 18 groups of plaintext filtering, 72 bits of key information can be recovered. The remaining 56 bits of key information can be obtained by exhaustive search.

[0148] The time complexity of the LLLWBC algorithm for decrypting 3 rounds is: The third round of LLLWBC encryption is equivalent to performing... The encryption process involves 12 rounds of LLLWBC encryption; therefore, the total time complexity required to recover the key is O(n log n). The 12th round of LLLWBC encryption has a data complexity of O(n). The storage complexity is O(n^64) for 64-bit plaintext data. A 128-bit key sum is A 64-bit encrypted data.

[0149] In this embodiment, the final evaluation showed that the time complexity of attacking LLLWBC for 12 rounds was lower than that of the exhaustive attack, proving the effectiveness of the method.

[0150] The focus of this invention is on the automated solution of the key recovery phase of integral attacks. By modeling the determinability of intermediate state words and the round key guessing requirements in the decryption process as binary variables, and combining the round function and key arrangement structure of the LLLWBC algorithm to construct a constraint system, a MILP model is constructed, and the minimum key guessing amount and the optimal key guessing path are automatically solved.

[0151] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Any modifications, equivalent substitutions, or improvements made by those skilled in the art based on the principles of the present invention should be included within the protection scope of the present invention.

Claims

1. An automated key guessing path search method for the LLLWBC cryptographic algorithm, characterized in that, Includes the following steps: (1) MILP variable initialization: Receive LLLWBC integrator information, and based on the integrator round number R1 and its balance word subscript set BT, extend the encryption direction by R2 rounds; Based on the information from the integrator, a binary variable for a mixed-integer linear programming model for key recovery path search is established, including round key guessing variables and round input state determinability variables, and MILP model constraints are constructed based on the balance word subscript set BT. (2) Modeling of permutation operation: Based on the algebraic expression of the decryption direction of the round function of the LLLWBC algorithm, the branch equation that only requires linear permutation operation is derived and transformed into the permutation constraint of the MILP model; (3) Boolean expression modeling based on word operations: For branches in the LLLWBC algorithm that require F-function operation before linear permutation, a custom Boolean expression model is used. The function transforms branching operations into model constraints, characterizing the dependency relationship between state variables and key variables; (4) Objective function modeling: With minimizing the number of guessed key bits as the optimization objective, the objective function of the MILP model is constructed, including round key guessing variables and whitening key variables; (5) Search for LLLWBC key guessing path in round R2: Integrate the variables and constraints of steps (1) to (4), traverse the loop through rounds, call variable initialization, permutation constraints, word operation constraints and objective function, complete the output from the integrator, and obtain the optimal key guessing path that minimizes the size of the guessed key; (6) MILP model solution: Traverse all non-empty subsets of the balance word index set BT of the integral distinguisher, construct a model for each subset as the attack target, select the subset that minimizes the objective function value as the optimal balance bit attack combination, solve the model with the Gurobi solver, obtain the optimal key guess set corresponding to each balance bit attack combination, and complete the model solution for R2 round key recovery.

2. The method according to claim 1, characterized in that, The initialization of the MILP variables in step (1) specifically involves the following steps: First, define a MILP model as M, then define the round key guessing variable as... , indicating whether the key for the i-th round of the r-th round needs to be guessed; , representing the key used in the r-th round function. Whether it is being speculated upon For binary model variables, when When the value is 1, it means The value needs to be guessed; otherwise, The values ​​do not need to be guessed, among which , ; Secondly, define the deterministic variables of the wheel input state as follows: , indicating whether the value of the i-th state in the r-th round can be determined; , representing the value of the input state of the function in the r-th round. Whether it can be guessed to determine, where the model variables and Correspondingly, For binary model variables, when When the value is 1, it means The value can be guessed and determined, among which ; Finally, constraints for the MILP model are constructed based on a non-empty subset of the balanced word subscript set BT. If the i-th equilibrium position is selected as the attack target, then the state determinism constraint corresponding to that equilibrium position needs to be added to the model. The specific constraint form is as follows: , , ,in For the number of BT, This indicates the output state of the R1 round integrator.

3. The method according to claim 1, characterized in that, The permutation operation modeling in step (2) involves the following steps: based on the round function structure of the LLLWBC algorithm, the input state of the r-th round... In the process, eight branches only require linear permutation operations to obtain the output state of the r-th round, while the remaining eight branches first require F function operations, followed by linear permutation operations to obtain the corresponding output state of the r-th round. When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches requiring only linear permutation operations. : ; based on The equations are used to construct MILP model constraints and add them to the model. The specific method is as follows: When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches requiring only linear permutation operations. : ; based on The equations are used to construct MILP model constraints and add them to the model. The specific method is as follows:

4. The method according to claim 1, characterized in that, Step (3) involves modeling Boolean expressions based on word operations. Specifically, this involves considering the input state in the r-th round of the LLLWBC algorithm. The eight branches, which require an F-function operation followed by a linear permutation operation, are combined with the algebraic expression for the decryption direction in the r-th round of the LLLWBC algorithm. and The corresponding inequalities are obtained, the corresponding equality is derived, and model constraints are constructed, as follows: When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches that requires an F-function operation followed by a linear permutation operation. : ; When the number of rounds At that time, the algebraic expression for the decryption direction in the r-th round based on the LLLWBC algorithm. This yields an equation with eight branches that requires an F-function operation followed by a linear permutation operation. : ; exist and In this equation, the determination of the variables on the left side depends on the guessed state of the variables on the right side. Specifically, the value of the variables on the left side can only be determined after all the guesses of the variables on the right side of the equation have been determined. by The first equation For example, when , , The value was guessed and the subkey was guessed. back, Only the value of this can be determined; this relationship is established through a function. Indicate: ; In function In the text, the first line indicates: if , , and If both are 1, then It must be 1; lines 2-5 are used to indicate: when , , and There exists a value of 0, It must be 0; This set of constraints precisely describes the requirement that the balance bit verification of the integrator must ensure that the key intermediate states during the decryption process can be derived and determined. This constraint clarifies that the target state variable of round r-1 can only be determined as the variable that needs to be guessed when both the state variable and the round key variable of round r are guessed and determined. When the number of rounds At that time, based on Equations and functions Build MILP model constraints and add them to the model The specific method is as follows: When the number of rounds At that time, based on Equations and functions Build MILP model constraints and add them to the model The specific method is as follows:

5. The method according to claim 1, characterized in that, The objective function modeling in step (4) involves the following steps: First, define the model variable corresponding to the whitening key as follows: , For binary model variables, when When the value is 1, This indicates that the value of the i-th word in the whitening key needs to be guessed; otherwise, it does not need to be guessed. At the same time, due to the The output of the round is XORed with the whitening key to obtain the output of the simplified round's cryptographic algorithm. The output of the simplified round is known during the attack; when the attacker guesses the value of the i-th word of the whitening key, i.e., the model variable... The value is 1, at which point encryption is enabled. The value of the i-th byte in the internal state after the round can also be determined by guessing, that is, the value of the model variable is 1. Therefore, we can obtain: ,in ; Finally, based on the state and key dependency linear constraints established in steps (1), (2), and (3), a MILP model is constructed with the optimization objective of minimizing the number of key bits required to be guessed during key recovery. The objective function is: .

6. The method according to claim 1, characterized in that, Step (5) describes the LLLWBC key guessing path search in round R2, specifically involving the round key guessing MILP variables. State deterministic MILP variables Whitening key MILP variable , and based on round number interval , The constructed permutation operation constraints, and based on , Equation and The Boolean operation constraints of the function construction are uniformly incorporated into the MILP model M initialized in the initialization, and bound to the defined objective function of minimizing the number of guessed key bits. Thus constructing the orientation A complete MILP model for round key recovery.

7. The method according to claim 1, characterized in that, Step (6) involves solving the MILP model to obtain the optimal value of the objective function. and key variables of each wheel and the Round Variable , The optimal key guess set corresponding to the whitened key, when When the value is 1, This indicates that the value of the i-th word in the whitening key needs to be guessed; otherwise, it does not need to be guessed.

8. The method according to claim 1, characterized in that, It also includes step (7) complexity evaluation, which derives the number of master key bits to be guessed based on the optimal key guess set obtained in step (6) and the LLLWBC key arrangement algorithm, and evaluates the time complexity, data complexity and storage complexity of key recovery attacks.

9. The method according to claim 8, characterized in that, The complexity evaluation in step (7) is specifically based on the optimal value of the objective function obtained in step (6). and key variables of each wheel and the Round Variable By combining the LLLWBC key arrangement algorithm, the round key and master key that need to be guessed in each round are calculated. The mapping relationship yields a master key that needs to be guessed, consisting of T bits. Guessing T bits of master key information... Decrypt the ciphertext set of the wheel; Finally, determine the first The target word set of the wheel Whether it is balanced, where I represents the optimal combination of balanced bits. If it is unbalanced, it means that the guessed key is wrong. If the result is balanced, it means the guessed key is correct; Due to the incorrect key The probability of being in equilibrium is N is the number of elements in the optimal balance position combination. The balance judgment process described above can be restored after one execution. After the key information of bits is filtered through plaintext by group Z, the number of erroneous keys is: It can recover T bits of key information, and the remaining... The bit key information was obtained through exhaustive search; The time complexity of LLLWBC algorithm decryption is: Second-rate LLLWBC encryption, It is the number of active words, and the data complexity is O(n). The storage complexity is O(n^64) for 64-bit plaintext data. A 128-bit key sum is A 64-bit encrypted data.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the automated key guessing path search method of the LLLWBC cryptographic algorithm as described in any one of claims 1 to 9.