通信学报 ›› 2023, Vol. 44 ›› Issue (6): 175-182.doi: 10.11959/j.issn.1000-436x.2023109

• 学术论文 • 上一篇    下一篇

轻量级分组密码Piccolo的量子密码分析

杜小妮1,2, 王香玉1, 梁丽芳1, 李锴彬3   

  1. 1 西北师范大学数学与统计学院,甘肃 兰州 730070
    2 西北师范大学密码技术与数据分析重点实验室,甘肃 兰州 730070
    3 西北师范大学计算机科学与工程学院,甘肃 兰州 730070
  • 修回日期:2023-04-08 出版日期:2023-06-25 发布日期:2023-06-01
  • 作者简介:杜小妮(1972- ),女,甘肃庆阳人,博士,西北师范大学教授、博士生导师,主要研究方向为密码学与信息安全等
    王香玉(1997- ),女,河南开封人,西北师范大学硕士生,主要研究方向为密码学与信息安全等
    梁丽芳(1995- ),女,甘肃定西人,西北师范大学硕士生,主要研究方向为密码学与信息安全等
    李锴彬(1997- ),男,甘肃天水人,西北师范大学硕士生,主要研究方向为密码学与信息安全等
  • 基金资助:
    国家自然科学基金资助项目(62172337);甘肃省自然科学基金重点资助项目(23JRRA685)

Quantum cryptanalysis of lightweight block cipher Piccolo

Xiaoni DU1,2, Xiangyu WANG1, Lifang LIANG1, Kaibin LI3   

  1. 1 College of Mathematics and Statistic, Northwest Normal University, Lanzhou 730070, China
    2 Key Laboratory of Cryptography and Data Analytics, Northwest Normal University, Lanzhou 730070, China
    3 College of Computer Science and Engineering, Northwest Normal University, Lanzhou 730070, China
  • Revised:2023-04-08 Online:2023-06-25 Published:2023-06-01
  • Supported by:
    The National Natural Science Foundation of China(62172337);Key Project of Gansu Natural Science Foundation(23JRRA685)

摘要:

根据Piccolo算法RP置换的结构特点,提出3轮量子区分器,并用Grover meets Simon算法进行6轮量子密钥恢复攻击。分析结果表明,该攻击可恢复密钥56 bit,时间复杂度为228,共需量子比特数为464;当攻击轮数大于6 轮时,时间复杂度为228+16(r-6),降至Grover量子暴力搜索的 1 2 68 。与传统差分和线性分析相比,所提攻击方法时间复杂度更低,且较Grover暴力搜索的时间复杂度大幅降低,为后续轻量级分组密码的量子攻击的研究奠定了基础。

关键词: 量子密码分析, Piccolo算法, Grover算法, Simon算法

Abstract:

By taking the characteristics of the structure of Piccolo algorithm RP permutation into consideration, a 3-round quantum distinguisher was proposed.Based on Grover meets Simon algorithm, the 6-round of quantum key recovery attack was given.The results show that the key can be recovered 56 bit with the time complexity 2 28 and the occupation of 464 qubit.Moreover, if attack rounds r>6,the time complexity is 2 28+16(r-6), which is 1 2 68 of Grover quantum brute-force search.The time complexity of the proposed attack method is significantly reduced compared with Grover search and is also better than that of traditional cryptanalysis, which lays a foundation for the subsequent research on quantum attacks of lightweight block ciphers.

Key words: quantum cryptanalysis, Piccolo algorithm, Grover algorithm, Simon algorithm

中图分类号: 

No Suggested Reading articles found!