Security analysis method based on SelfTargetSIS problem

By performing an explicit search in the SelfTargetSIS problem and combining complexity evaluations of classical and quantum models, the problem of inaccurate complexity evaluation in the SelfTargetSIS problem is solved, and the reliability of security evaluation and parameter selection for quantum signatures is achieved.

CN121907424APending Publication Date: 2026-04-21INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INST OF SOFTWARE - CHINESE ACAD OF SCI
Filing Date
2025-11-28
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies fail to adequately consider the impact of the size of the target output space on the difficulty when assessing the complexity of the SelfTargetSIS problem, resulting in inaccurate complexity assessments and making it difficult to effectively evaluate the security of quantum signatures.

Method used

The objective of solving the SelfTargetSIS problem is modeled as an explicit search across the message set, the allowed vector set, and the challenge vector set. In the classical model, an exhaustive search method is used to estimate the first search complexity, while in the quantum model, Grover's algorithm is used to accelerate the search space by square root. The optimal attack complexity under both classical and quantum models is combined to conduct a security assessment.

Benefits of technology

It achieves a reliable assessment of the effective attack complexity of the SelfTargetSIS problem, which can more comprehensively reflect the attack cost in real-world scenarios, support the selection of security parameters and risk assessment, reveal potential weaknesses, and enhance the security analysis capabilities of quantum signatures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907424A_ABST
    Figure CN121907424A_ABST
Patent Text Reader

Abstract

The invention provides a safety analysis method based on a SelfTargetSIS problem. The method comprises the following steps: modeling a solution target of the SelfTargetSIS problem into explicit search on a message set, an allowable vector set and a challenge vector set; estimating a first search complexity in the classic model under a random oracle model; estimating a second search complexity in the quantum model under a random oracle model; and determining the minimum value of the first search complexity and the known classical optimal attack complexity as the effective attack complexity under the classical model, and determining the minimum value of the second search complexity and the known quantum optimal attack complexity as the effective attack complexity under the quantum model, thereby performing security evaluation on the anti-quantum signature. According to the method, an explicit search path based on a message set, an allowable vector set and a challenge vector set is supplemented and quantified, and the attack cost in the real world can be reflected more comprehensively.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of cryptography and information security technology, and in particular to a security analysis method based on the SelfTargetSIS problem. Background Technology

[0002] In evaluating the complexity of the SelfTargetSIS problem, existing techniques typically treat the estimated complexity of the SelfTargetSIS problem under the same parameters as the complexity of the SIS (Short Integer Solution) problem.

[0003] However, existing techniques often overlook the impact of the size of the target output space on difficulty. A larger output space for a hash function (equivalent to an attacker needing to hit or satisfy conditions from a wider range) may make the problem more difficult; but a smaller range or weaker structure may make it easier. This "range" dimension has not been quantified separately in many analyses.

[0004] Therefore, how to assess the complexity of the SelfTargetSIS problem in order to evaluate the security against quantum signatures and thus more comprehensively reflect the attack cost in real-world scenarios is an urgent problem to be solved. Summary of the Invention

[0005] This invention provides a security analysis method based on the SelfTargetSIS problem, which addresses the shortcomings of existing technologies that typically directly use the estimated complexity of the SelfTargetSIS problem under the same parameters as the complexity of the SIS problem, leading to inaccurate complexity assessment of the SelfTargetSIS problem. This invention enables a reliable assessment of the effective attack complexity of the SelfTargetSIS problem.

[0006] This invention provides a security analysis method based on the SelfTargetSIS problem, comprising: The objective of solving the SelfTargetSIS problem is modeled as an explicit search over the message set, the allowed vector set, and the challenge vector set; In the classic model, the exhaustive search method is used to estimate the first search complexity under the random oracle model; In the quantum model, Grover's algorithm is used to accelerate the search space by square root, and the second search complexity is estimated under the random oracle model. The minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem is determined as the effective attack complexity under the classical model. The minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the quantum model. Security assessment of adversarial quantum signatures is performed based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0007] According to the security analysis method based on the SelfTargetSIS problem provided by the present invention, the first search complexity is estimated by the following method: ; in, The first search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; It means and and The product is directly proportional.

[0008] According to a security analysis method based on the SelfTargetSIS problem provided by the present invention, the second search complexity is estimated in the following way: ; in, This represents the second search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; To verify the quantum in the realization of quantum mechanics Resource amplification factor introduced through reversibility; It means and The product is directly proportional.

[0009] According to the security analysis method based on the SelfTargetSIS problem provided by the present invention, the size of the search space is determined in the following way: ; in, For search space, The size of the message set, To allow for the size of the vector set, To determine the size of the challenge vector set.

[0010] According to the present invention, a security analysis method based on the SelfTargetSIS problem is provided, wherein the single candidate triplet is... The time cost of verification is determined in the following way: ; in, The cost is linear algebra. The overhead of hash calculation; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, These are the challenge vectors in the set of challenge vectors.

[0011] According to the security analysis method based on the SelfTargetSIS problem provided by the present invention, before determining the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model, the method further includes: Calculate the classical optimal attack complexity and quantum optimal attack complexity of the standard SIS problem under the same parameters.

[0012] The present invention also provides a security analysis apparatus based on the SelfTargetSIS problem, comprising: The explicit search module is used to model the solution objective of the SelfTargetSIS problem as an explicit search on the message set, the allowed vector set, and the challenge vector set; The first complexity estimation module is used to estimate the first search complexity in the classical model under the random oracle model by exhaustive search. The second complexity estimation module is used to accelerate the search space by the square root of Grover's algorithm in the quantum model and to estimate the second search complexity in the random oracle model. The classical effective complexity determination module is used to determine the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model. The quantum effective complexity determination module is used to determine the minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model; The security assessment module is used to assess the security of adversarial quantum signatures based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0013] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the security analysis method based on the SelfTargetSIS problem as described above.

[0014] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the security analysis method based on the SelfTargetSIS problem as described above.

[0015] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements a security analysis method based on the SelfTargetSIS problem as described above.

[0016] The security analysis method based on the SelfTargetSIS problem provided by this invention models the solution objective of the SelfTargetSIS problem as an explicit search across the message set, the allowed vector set, and the challenge vector set. In the classical model, an exhaustive search method is used to estimate the first search complexity under a random oracle model. In the quantum model, Grover's algorithm is used to accelerate the search space by square root and to estimate the second search complexity under a random oracle model. The minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem is determined as the effective attack complexity under the classical model. The second search complexity is then calculated by subtracting the known classical optimal attack complexity for calculating the standard SIS problem. The minimum value in the quantum optimal attack complexity is determined as the effective attack complexity under the quantum model. This provides a process for calculating the "explicit search complexity" and "lattice algorithm complexity" under both classical and quantum models, and then taking the minimum value. This allows the security assessment of quantum-resistant signatures to no longer rely solely on a single difficulty assumption, but rather to take the actual optimal values ​​of two types of attack paths, achieving a reliable assessment of the effective attack complexity of the SelfTargetSIS problem. Using the effective attack complexity under the classical and quantum models to assess the security of quantum-resistant signatures helps in the selection of security parameters and risk assessment, and can reveal potential weaknesses caused by the structure of the challenge vector or message selection. Unlike traditional assessments based solely on SIS / lattice difficulty, this invention supplements and quantifies the explicit search path based on the message set, the allowed vector set, and the challenge vector set, which can more comprehensively reflect the attack cost in the real world. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0018] Figure 1 This is a flowchart illustrating the security analysis method based on the SelfTargetSIS problem provided in this embodiment of the invention.

[0019] Figure 2 This is a schematic diagram of the security analysis device based on the SelfTargetSIS problem provided in an embodiment of the present invention.

[0020] Figure 3 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0022] In the description of embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Those skilled in the art will understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0023] Figure 1 This is a flowchart illustrating the security analysis method based on the SelfTargetSIS problem provided in this embodiment of the invention. (Refer to...) Figure 1 This invention provides a security analysis method based on the SelfTargetSIS problem, which specifically includes the following steps: Step 101: Model the objective of solving the SelfTargetSIS problem as an explicit search on the message set, the allowed vector set, and the challenge vector set.

[0024] It should be noted that the execution subject of the security analysis method based on the SelfTargetSIS problem provided in this embodiment of the invention can be an electronic device, a component in the electronic device, an integrated circuit, or a chip. The electronic device can be a mobile electronic device or a non-mobile electronic device. For example, a mobile electronic device can be a mobile phone, tablet computer, laptop computer, PDA, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., while a non-mobile electronic device can be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This embodiment of the invention does not specifically limit the specific implementation of these devices. The following embodiments of the invention describe the execution subject using a server as the execution subject.

[0025] The message set M (message / nonce) can be a set containing all possible messages or nonces, used to represent the message space and random number space that an attacker can freely choose to try to forge signatures.

[0026] Here, the set of allowed vectors Z can be a set consisting of all allowed integer vectors z, used to represent the space of all candidate vectors that may be valid solutions. The norm of the integer vector z can be less than a preset threshold (i.e., the integer vector z is a short vector).

[0027] The challenge vector set C can be a set consisting of all allowed challenge vectors c. The challenge vectors can be generated by a hash function, and the challenge vector set C can be used to characterize the target space of the hash function output.

[0028] In this embodiment of the invention, the objective of solving the SelfTargetSIS problem is modeled as an explicit search across the message set, the allowed vector set, and the challenge vector set. This describes how an attacker, without knowing the key information, solves the SelfTargetSIS problem through a large-scale search, with the goal of finding a triple. It exists simultaneously in the message set, the allowed vector set, and the challenge vector set, and satisfies all the equations set by the cryptosystem, thereby breaking the cryptosystem based on the SelfTargetSIS problem.

[0029] This invention explicitly models the attack surface of the SelfTargetSIS problem as a message. This approach allows for the search of the Cartesian product of vector z and challenge vector c, thus formalizing the hidden "message / challenge exhaustive search" path into a quantifiable search space. This modeling method fills the gap in traditional security analysis that relies solely on SIS / lattice difficulty.

[0030] Step 102: In the classical model, the exhaustive search method is used to estimate the first search complexity under the random oracle model.

[0031] In this embodiment of the invention, the first search complexity can refer to the average number of hash calculations (i.e., querying a random oracle) required to successfully find an input (i.e., given a hash value y, the attacker's goal is to find an input x such that H(x) = y). In the random oracle model, since it is impossible to infer any information about the input x by analyzing the hash value, the attacker needs to keep trying.

[0032] In some embodiments, in the classical model, under the random oracle model, the exhaustive method (linear search) can be used to estimate the first search complexity.

[0033] Step 103: In the quantum model, Grover's algorithm is used to accelerate the search space by square root, and the second search complexity is estimated under the random oracle model.

[0034] In this embodiment of the invention, the second search complexity can refer to the average number of quantum queries required on a quantum computer to successfully find another different input (i.e., given a specific input x1, the attacker's goal is to find another different input x2 such that H(x1) = H(x2)). By employing Grover's algorithm to accelerate the search space with the square root, the properties of quantum superposition and interference are utilized to amplify the probability amplitude of the correct solution at the square root speed, thereby enabling the target (i.e., another different input x2) to be found quickly.

[0035] Step 104: Determine the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model.

[0036] In this embodiment of the invention, the known classical optimal attack complexity of the standard SIS problem is calculated under the same parameters. Compared to the known quantum optimal attack complexity Then, the effective attack complexity under the classic model can be defined as... .

[0037] This invention's embodiments calculate the "explicit search complexity (based on)" under the classical model. The process of taking the minimum value of "first search complexity" and "lattice algorithm complexity (SIS)" is beneficial for accurately assessing whether the signature scheme can withstand attacks from all current and future classical computers by taking the actual optimal value of the classic attack path.

[0038] Step 105: Determine the minimum value between the second search complexity and the known quantum optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the quantum model.

[0039] In this embodiment of the invention, the known classical optimal attack complexity of the standard SIS problem is calculated under the same parameters. Compared to the known quantum optimal attack complexity Then, the effective attack complexity under the quantum model can be defined as .

[0040] This invention embodiment calculates the "explicit search complexity (based on)" under the quantum model. The process of taking the minimum value of the second search complexity and the lattice algorithm complexity (SIS) is beneficial for accurately assessing whether the mathematical problem on which the signature scheme depends can be effectively solved by known quantum algorithms by taking the actual optimal value of the quantum attack path.

[0041] This invention formalizes the problem of solving SelfTargetSIS into... This paper presents an explicit search method for attack complexity, estimating its complexity using exhaustive search and Grover search under both classical and quantum oracle models. The results are then compared with the known attack complexity of SIS, providing a reliable method for evaluating "effective attack complexity." This method aids in the selection of security parameters and risk assessment, and can reveal potential weaknesses caused by the structure of the challenge vector c or message selection.

[0042] Step 106: Based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model, perform a security assessment of the adversarial quantum signature.

[0043] In this embodiment of the invention, a comprehensive evaluation strategy combining Grover's approach with classical exhaustive search and comparing it with the optimal attack complexity of SIS to find the minimum value is given. This strategy provides calculations of the "explicit search complexity (based on...") under both classical and quantum models. After the process of minimizing the "lattice algorithm complexity (SIS)," the security assessment of quantum signatures is jointly conducted by using the effective attack complexity under the classical model and the effective attack complexity under the quantum model. This makes the security assessment no longer rely solely on a single difficulty assumption, but rather takes the actual optimal value of the two types of attack paths, which is beneficial for accurately assessing whether the signature scheme can withstand attacks from all current and future classical and quantum computers.

[0044] This invention models the SelfTargetSIS problem as an explicit search across the message set, the allowed vector set, and the challenge vector set. In the classical model, an exhaustive search is used to estimate the first search complexity under a random oracle model. In the quantum model, Grover's algorithm is used to accelerate the search space using the square root and to estimate the second search complexity under a random oracle model. The minimum of the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the classical model. The minimum of the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the classical model. The value is determined as the effective attack complexity under the quantum model, thus providing a process for calculating the "explicit search complexity" and "lattice algorithm complexity" under both classical and quantum models and taking the minimum value. This allows the security assessment of quantum-resistant signatures to no longer rely solely on a single difficulty assumption, but instead takes the actual optimal value of two types of attack paths, achieving a reliable assessment of the effective attack complexity of the SelfTargetSIS problem. Using the effective attack complexity under the classical and quantum models to assess the security of quantum-resistant signatures helps in the selection of security parameters and risk assessment, and can reveal potential weaknesses caused by the structure of the challenge vector or message selection. Unlike traditional assessments based solely on SIS / lattice difficulty, this invention supplements and quantifies the explicit search path based on the message set, the allowed vector set, and the challenge vector set, which can more comprehensively reflect the attack cost in the real world.

[0045] Based on any of the above embodiments, the first search complexity can be estimated in the following way: ; in, The first search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; It means and and The product is directly proportional.

[0046] In this embodiment of the invention, the size of the challenge vector set... It can be used to characterize the number of independent challenge vectors contained in the set of challenge vectors, and is used to determine the size of the search space.

[0047] In this embodiment of the invention, time overhead This can refer to the time required to verify a single candidate triple on a classic computer (i.e., the time required to verify the sub-triple). The time cost of verification typically involves underlying computations such as cryptographic pairing and hash calculations. The complexity and execution speed of these underlying computations determine the time cost.

[0048] In this embodiment of the invention, under linear search, the first search complexity is... It can be used to characterize the trend of classical search complexity as the input size changes.

[0049] The embodiments of the present invention are as follows: The total cost of an exhaustive search attack can be accurately quantified, showing that the efficiency of the attack is limited by the size of the search space and the overhead of a single verification.

[0050] Based on any of the above embodiments, the second search complexity is estimated in the following way: ; in, This represents the second search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; To verify the quantum in the realization of quantum mechanics Resource amplification factor introduced through reversibility; It means and The product is directly proportional.

[0051] In this embodiment of the invention, the size of the challenge vector set... It can be used to characterize the number of independent challenge vectors contained in the set of challenge vectors, and is used to determine the size of the search space.

[0052] In this embodiment of the invention, time overhead This can refer to the time required to verify a single candidate triple on a classic computer (i.e., the time required to verify the sub-triple). The time cost of verification typically involves underlying computations such as cryptographic pairing and hash calculations. The complexity and execution speed of these underlying computations determine the time cost.

[0053] In this embodiment of the invention, the resource amplification factor This refers to a classic, irreversible computational unit. The resource overhead (or amplification factor) introduced when converting to an equivalent, reversible quantum circuit that can be executed on a quantum computer is the additional cost that must be paid due to the physical principle (reversibility) required when moving from classical computing to quantum computing.

[0054] This invention provides a quantifiable model of the cost of quantum realization (introducing...). ), will verify the sub Additional resources for reversibility in quantum circuits are treated as independent parameters. Complexity assessment is incorporated, enabling quantum security estimates to reflect the engineering overhead of hashing and arithmetic reversibility.

[0055] This invention combines the sparsity of the challenge vector c with the cost of quantum invertibility. Including this in the evaluation can reveal performance / security trade-offs at the implementation level, thereby supporting more robust parameter selection for quantum-resistant signatures based on the SelfTargetSIS problem.

[0056] This invention uses the hash value range to estimate the number of solutions under a random oracle model. By utilizing the random oracle (RO) assumption, the number of objective solutions is estimated as follows: This significantly simplifies the complexity of classical exhaustive search and quantum Grover's search to that of... Related expressions (classical approx.) Quantum is approximately This serves as a key parameter for parameter recommendations and problem difficulty assessment.

[0057] Based on any of the above embodiments, the size of the search space is determined in the following way: ; in, For search space, The size of the message set, To allow for the size of the vector set, To determine the size of the challenge vector set.

[0058] In this embodiment of the invention, the objective of SelfTargetSIS is modeled as an explicit search over sets M (messages / nonces), Z (allowed z-vectors), and C (allowed c-vectors), and the search space size can be denoted as... .

[0059] In some embodiments, M size =|M|,Z size =|Z|,Csize =|C|, search space .

[0060] In this embodiment of the invention, the search space size is denoted as... This can be directly related to the security analysis, parameter selection, and quantitative assessment of the anti-attack capability of quantum signature schemes.

[0061] This invention, through its embodiment, explicitly models the attack surface of the SelfTargetSIS problem as a Cartesian product search problem of message μ, vector z, and challenge vector c, thereby formalizing the hidden "message / challenge exhaustive search" path into a quantifiable search space. This modeling fills a gap in traditional analysis that relies solely on SIS / lattice difficulty.

[0062] Based on any of the above embodiments, the process for a single candidate triplet... The time cost of verification can be determined in the following ways: ; in, The cost is linear algebra. The overhead of hash calculation; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, These are the challenge vectors in the set of challenge vectors.

[0063] In this embodiment of the invention, hash calculation overhead may refer to the time or computing resources required to execute all cryptographic hash functions during the verification process.

[0064] In this embodiment of the invention, linear algebra overhead can refer to the time or computational resources required to perform linear algebra-related operations during the verification process, such as computation. and wait.

[0065] The embodiments of the present invention verify the sub- Time cost is broken down into It can accurately quantify the evaluation of a single candidate triplet. Time overhead of verification .

[0066] Based on any of the above embodiments, before determining the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model, it may further include: calculating the classical optimal attack complexity and the quantum optimal attack complexity of the standard SIS problem under the same parameters.

[0067] In this embodiment of the invention, the known classical and quantum optimal attack complexities of the standard SIS problem can be calculated under the same parameters. and (It can be given by existing lattice algorithms, sieving, BKZ (Block Korkine-Zolotarev, a Lattice Basis Reduction algorithm), etc.)

[0068] This invention formalizes the problem of solving SelfTargetSIS into... This paper presents an explicit search method for attack complexity, estimating the search complexity using exhaustive search and Grover's algorithm under both classical and quantum oracle models. The results are then compared with the known attack complexity of SIS (Security Strategies), providing a reliable method for evaluating "effective attack complexity." This method aids in the selection of security parameters and risk assessment, and can reveal potential weaknesses caused by the structure of the challenge vector c or message selection.

[0069] The security analysis apparatus based on the SelfTargetSIS problem provided by the present invention is described below. The security analysis apparatus based on the SelfTargetSIS problem described below can be referred to in correspondence with the security analysis method based on the SelfTargetSIS problem described above.

[0070] Figure 2 This is a schematic diagram of the security analysis device based on the SelfTargetSIS problem provided in an embodiment of the present invention. (Refer to...) Figure 2 This invention provides a security analysis device based on the SelfTargetSIS problem, which may specifically include the following modules: The display search module 210 is used to model the solution objective of the SelfTargetSIS problem as an explicit search on the message set, the allowed vector set, and the challenge vector set; The first complexity estimation module 220 is used to estimate the first search complexity in the classical model under the random oracle model by exhaustive search. The second complexity estimation module 230 is used to estimate the second search complexity in the quantum model by using the Grover algorithm to accelerate the search space with the square root. The classical effective complexity determination module 240 is used to determine the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model. The quantum effective complexity determination module 250 is used to determine the minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model. The security assessment module 260 is used to assess the security of adversarial quantum signatures based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0071] This invention models the SelfTargetSIS problem as an explicit search across the message set, the allowed vector set, and the challenge vector set. In the classical model, an exhaustive search is used under a random oracle model to estimate the first search complexity. In the quantum model, Grover's algorithm is used to accelerate the search space using the square root and to estimate the second search complexity under a random oracle model. The minimum of the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the classical model. The minimum of the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the classical model. This invention defines the effective attack complexity under the quantum model, providing a process for calculating the "explicit search complexity" and "lattice algorithm complexity" under both classical and quantum models, and then taking the minimum value. This allows the security assessment of quantum-resistant signatures to no longer rely solely on a single difficulty assumption, but instead takes the actual optimal value of two types of attack paths, achieving a reliable assessment of the effective attack complexity of the SelfTargetSIS problem. Using the effective attack complexity under both the classical and quantum models to assess the security of quantum-resistant signatures helps in the selection of security parameters and risk assessment, and can reveal potential weaknesses caused by the structure of the challenge vector or message selection. Unlike traditional assessments based solely on SIS / lattice difficulty, this invention supplements and quantifies the explicit search path based on the message set, the allowed vector set, and the challenge vector set, which can more comprehensively reflect the attack cost in the real world.

[0072] Figure 3 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 3As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communications bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other through the communications bus 340. Processor 310 can invoke logical instructions in memory 330 to execute a security analysis method based on the SelfTargetSIS problem. This method includes: modeling the solution objective of the SelfTargetSIS problem as an explicit search over a set of messages, a set of allowed vectors, and a set of challenge vectors; estimating a first search complexity using an exhaustive search method under a random oracle model in a classical model; estimating a second search complexity under a random oracle model by using Grover's algorithm to accelerate the search space with a square root in a quantum model; determining the minimum of the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the classical model; determining the minimum of the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model; and performing a security assessment of the adversarial quantum signature based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0073] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0074] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the security analysis method based on the SelfTargetSIS problem provided by the above methods. The method includes: modeling the solution objective of the SelfTargetSIS problem as an explicit search on the message set, the allowed vector set, and the challenge vector set; estimating the first search complexity using an exhaustive method under a random oracle model in the classical model; estimating the second search complexity under a random oracle model by using Grover's algorithm to accelerate the search space with square roots in the quantum model; determining the minimum value between the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the classical model; determining the minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model; and performing a security assessment of adversarial quantum signatures based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0075] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the security analysis method based on the SelfTargetSIS problem provided by the above methods. This method includes: modeling the solution objective of the SelfTargetSIS problem as an explicit search over a set of messages, a set of allowed vectors, and a set of challenge vectors; estimating a first search complexity using an exhaustive method under a random oracle model in a classical model; estimating a second search complexity under a random oracle model by using Grover's algorithm to accelerate the search space with a square root in a quantum model; determining the minimum of the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the classical model; determining the minimum of the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model; and performing a security assessment of adversarial quantum signatures based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

[0076] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0077] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0078] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A security analysis method based on the SelfTargetSIS problem, characterized in that, include: The objective of solving the SelfTargetSIS problem is modeled as an explicit search over the message set, the allowed vector set, and the challenge vector set; In the classic model, the exhaustive search method is used to estimate the first search complexity under the random oracle model; In the quantum model, Grover's algorithm is used to accelerate the search space by square root, and the second search complexity is estimated under the random oracle model. The minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem is determined as the effective attack complexity under the classical model. The minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem is determined as the effective attack complexity under the quantum model. Security assessment of adversarial quantum signatures is performed based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

2. The security analysis method based on the SelfTargetSIS problem according to claim 1, characterized in that, The first search complexity was estimated in the following way: ; in, The first search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; It means and and The product is directly proportional.

3. The security analysis method based on the SelfTargetSIS problem according to claim 1, characterized in that, The second search complexity was estimated in the following way: ; in, This represents the second search complexity; The size of the challenge vector set; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, The challenge vectors in the set of challenge vectors; To verify the quantum in the realization of quantum mechanics Resource amplification factor introduced through reversibility; It means and The product is directly proportional.

4. The security analysis method based on the SelfTargetSIS problem according to claim 1, characterized in that, The size of the search space is determined in the following way: ; in, For search space, The size of the message set, To allow for the size of the vector set, The size of the challenge vector set.

5. The security analysis method based on the SelfTargetSIS problem according to claim 2 or 3, characterized in that, The single candidate triplet The time cost of verification is determined in the following way: ; in, The cost is linear algebra. The overhead of hash calculation; For a single candidate triple The time cost of verification For messages in the message set, For allowed vectors in the allowed vector set, These are the challenge vectors in the set of challenge vectors.

6. The security analysis method based on the SelfTargetSIS problem according to claim 1, characterized in that, Before determining the minimum of the first search complexity and the known classical optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the classical model, the following steps are also included: Calculate the classical optimal attack complexity and quantum optimal attack complexity of the standard SIS problem under the same parameters.

7. A security analysis device based on the SelfTargetSIS problem, characterized in that, include: The explicit search module is used to model the solution objective of the SelfTargetSIS problem as an explicit search on the message set, the allowed vector set, and the challenge vector set; The first complexity estimation module is used to estimate the first search complexity in the classical model under the random oracle model by exhaustive search. The second complexity estimation module is used to accelerate the search space by the square root of Grover's algorithm in the quantum model and to estimate the second search complexity in the random oracle model. The classical effective complexity determination module is used to determine the minimum value between the first search complexity and the known classical optimal attack complexity for calculating the standard SIS problem as the effective attack complexity under the classical model. The quantum effective complexity determination module is used to determine the minimum value between the second search complexity and the known quantum optimal attack complexity for computing the standard SIS problem as the effective attack complexity under the quantum model. The security assessment module is used to assess the security of adversarial quantum signatures based on the effective attack complexity under the classical model and the effective attack complexity under the quantum model.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the security analysis method based on the SelfTargetSIS problem as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the security analysis method based on the SelfTargetSIS problem as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the security analysis method based on the SelfTargetSIS problem as described in any one of claims 1 to 6.