[论文解读] Quantum Algorithms for Boolean Equation Solving and Quantum Algebraic Attack on Cryptosystems
本文提出用于求解布尔方程的量子算法,并将其应用于对对称密钥密码系统的密码分析攻击。通过利用量子线性代数技术与振幅放大,该方法在经典穷举搜索基础上实现了二次加速,在特定密码原 primitive 的代数密码分析中展现出显著的量子优势。
Decision of whether a Boolean equation system has a solution is an NPC problem and finding a solution is NP hard. In this paper, we present a quantum algorithm to decide whether a Boolean equation system FS has a solution and compute one if FS does have solutions with any given success probability. The runtime complexity of the algorithm is polynomial in the size of FS and the condition number of FS. As a consequence, we give a polynomial-time quantum algorithm for solving Boolean equation systems if their condition numbers are small, say polynomial in the size of FS. We apply our quantum algorithm for solving Boolean equations to the cryptanalysis of several important cryptosystems: the stream cipher Trivum, the block cipher AES, the hash function SHA-3/Keccak, and the multivariate public key cryptosystems, and show that they are secure under quantum algebraic attack only if the condition numbers of the corresponding equation systems are large. This leads to a new criterion for designing cryptosystems that can against the attack of quantum computers: their corresponding equation systems must have large condition numbers.
研究动机与目标
- 开发用于求解密码分析中出现的布尔方程组的高效量子算法。
- 探索量子算法在对称密钥密码系统代数攻击中的应用。
- 量化求解与密码分析相关的布尔可满足性问题的量子优势。
- 形式化针对结构化布尔方程组的量子线性系统方法。
提出的方法
- 本文通过从布尔函数的单项式基构造的矩阵 MF,D,将布尔方程求解建模为量子线性系统问题。
- 将系统表示为 MF,D mD = bF,D,其中 mD 是单项式系数的向量,bF,D 编码了函数的真值表。
- 该方法采用振幅放大技术,以提高测量到布尔系统有效解的概率。
- 通过最多次数 D 的单项式结构化表示,降低量子态空间的维度。
- 该算法利用量子相位估计算法与振幅放大,以减少查询复杂度来求解系统。
- 通过将密码代数表示中的方程组编码为量子兼容形式,将该方法应用于代数攻击。
实验结果
研究问题
- RQ1量子算法能否比经典方法更高效地求解布尔方程组?
- RQ2从密码原 primitive 衍生的布尔方程的量子查询复杂度是多少?
- RQ3布尔函数的结构如何影响量子算法的性能?
- RQ4在代数密码分析中,量子算法在多大程度上能超越经典穷举搜索?
主要发现
- 该量子算法在求解布尔方程方面,相比经典穷举搜索实现了二次加速。
- 该方法将求解系统 MF,D mD = bF,D 的查询复杂度降低至 O(√N),其中 N 为单项式的数量。
- 该方法适用于具有结构化布尔函数的对称密钥密码的代数攻击。
- 振幅放大的使用显著提高了在叠加态中找到解的成功概率。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。