[论文解读] Benchmarking the quantum cryptanalysis of symmetric, public-key and hash-based cryptographic schemes
本文针对基于容错量子计算模型的对称密码、哈希函数以及公钥方案(如RSA和ECC)的量子破解攻击,提供了最先进的资源估算。该研究利用表面码纠错和优化的量子电路,量化了在现实硬件约束下破解这些方案所需的物理量子比特、T门和时间,为不同安全等级的密码原语提供了量子风险评估的基准。
Quantum algorithms can break factoring and discrete logarithm based cryptography and weaken symmetric cryptography and hash functions. In order to estimate the real-world impact of these attacks, apart from tracking the development of fault-tolerant quantum computers it is important to have an estimate of the resources needed to implement these quantum attacks. For attacking symmetric cryptography and hash functions, generic quantum attacks are substantially less powerful than they are for today's public-key cryptography. So security will degrade gradually as quantum computing resources increase. At present, there is a substantial resource overhead due to the cost of fault-tolerant quantum error correction. We provide estimates of this overhead using state-of-the-art methods in quantum fault-tolerance. We use state-of-the-art optimized circuits, though further improvements in their implementation would also reduce the resources needed to implement these attacks. To bound the potential impact of further circuit optimizations we provide cost estimates assuming trivial-cost implementations of these functions. These figures indicate the effective bit-strength of the various symmetric schemes and hash functions based on what we know today (and with various assumptions on the quantum hardware), and frame the various potential improvements that should continue to be tracked. As an example, we also look at the implications for Bitcoin's proof-of-work system. For many of the currently used asymmetric (public-key) cryptographic schemes based on RSA and elliptic curve discrete logarithms, we again provide cost estimates based on the latest advances in cryptanalysis, circuit compilation and quantum fault-tolerance theory. These allow, for example, a direct comparison of the quantum vulnerability of RSA and elliptic curve cryptography for a fixed classical bit strength.
研究动机与目标
- 在容错量子计算假设下,评估对广泛部署的密码方案进行量子攻击的实际资源成本。
- 量化量子算法(尤其是Grover算法和Shor算法)对对称、哈希和公钥密码安全性的影响。
- 利用最先进的量子容错技术(如晶格手术和表面码纠错)提供更新的、基于硬件的资源成本估算。
- 实现对不同密码方案(如RSA与ECC)在等效经典安全级别下的量子脆弱性进行直接比较。
- 作为基准,用于追踪未来量子算法、电路优化和纠错效率方面的进展。
提出的方法
- 作者采用基于表面码的容错量子计算模型来模拟量子攻击,估算在现实误差率下的逻辑与物理资源成本。
- 他们使用为密码函数(如AES、SHA-256、RSA模指数运算)优化的量子电路,并以T门计数和T门深度作为量子资源开销的代理指标。
- 分析中引入了晶格手术技术,与早期方法相比,将逻辑量子比特和表面码周期的需求降低了约5倍。
- 资源估算覆盖了从10⁻⁵到10⁻³的物理误差率范围,空间(量子比特)与时间(表面码周期)之间的权衡在对数坐标图中可视化。
- 研究包含两种成本模型:一种采用优化电路,另一种假设实现成本可忽略,以界定未来潜在改进的上限。
- 对于公钥方案,分析采用了Shor算法编译和模指数运算电路优化的最新进展。
实验结果
研究问题
- RQ1在容错表面码纠错下,使用Grover算法破解AES-128所需的最少物理量子比特数和表面码周期数是多少,假设执行时间为一天?
- RQ2RSA-2048的资源估算如何随物理误差率和时间约束而变化?其与具有等效经典安全性的ECC方案的估算相比如何?
- RQ3在现实量子硬件假设下,对称和哈希密码方案在遭受量子攻击时的有效比特强度是多少?
- RQ4近期容错量子计算进展(如晶格手术)如何降低量子密码分析的资源开销?
- RQ5电路优化对量子攻击可行性有何影响?平凡成本实现如何界定未来潜在改进的上限?
主要发现
- 使用Grover算法破解AES-128需约214万个物理量子比特和2.93×10¹³个表面码周期,物理误差率为10⁻⁵,假设执行时间为一天。
- 对于RSA-2048,攻击需约978万个物理量子比特和2.35×10¹⁴个表面码周期,物理误差率为10⁻⁵,含2.41×10¹²个T门和4,098个逻辑量子比特。
- RSA-3072需约2550万个物理量子比特和7.91×10¹⁴个周期,物理误差率为10⁻⁵,对应128位经典安全强度。
- RSA-4096需约5700万个物理量子比特和1.88×10¹⁵个周期,物理误差率为10⁻⁵,含1.92×10¹³个T门和8,194个逻辑量子比特。
- RSA-7680最多需74.1亿个物理量子比特和2.47×10¹⁶个周期,物理误差率为10⁻⁵,对应192位经典安全强度。
- 研究表明,晶格手术相比早期表面码方法将内存成本降低了约5倍,显著提升了大规模量子密码分析的可行性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。