[论文解读] Estimating the cost of generic quantum pre-image attacks on SHA-2 and SHA-3
本文使用基于表面码的容错量子计算机上的Grover算法,估算通用量子原像攻击在SHA-256和SHA3-256上的资源成本。论文提出了一种时间-面积成本模型,考虑了表面码周期中的逻辑量子比特和电路深度,揭示出实际成本约为$2^{166.5}$个逻辑量子比特-周期——远超基于查询的简单估算($2^{128}$)的2750多亿倍——这是由于魔术态 distillation 和错误校正带来的开销所致。
We investigate the cost of Grover's quantum search algorithm when used in the context of pre-image attacks on the SHA-2 and SHA-3 families of hash functions. Our cost model assumes that the attack is run on a surface code based fault-tolerant quantum computer. Our estimates rely on a time-area metric that costs the number of logical qubits times the depth of the circuit in units of surface code cycles. As a surface code cycle involves a significant classical processing stage, our cost estimates allow for crude, but direct, comparisons of classical and quantum algorithms. We exhibit a circuit for a pre-image attack on SHA-256 that is approximately $2^{153.8}$ surface code cycles deep and requires approximately $2^{12.6}$ logical qubits. This yields an overall cost of $2^{166.4}$ logical-qubit-cycles. Likewise we exhibit a SHA3-256 circuit that is approximately $2^{146.5}$ surface code cycles deep and requires approximately $2^{20}$ logical qubits for a total cost of, again, $2^{166.5}$ logical-qubit-cycles. Both attacks require on the order of $2^{128}$ queries in a quantum black-box model, hence our results suggest that executing these attacks may be as much as $275$ billion times more expensive than one would expect from the simple query analysis.
研究动机与目标
- 评估在考虑简单查询复杂度之外,量子原像攻击在SHA-2和SHA-3哈希函数上的真实成本。
- 对容错量子计算的资源开销进行建模,特别是针对表面码架构。
- 量化由于错误校正和魔术态distillation,实际中量子原像攻击比查询数多出多少成本。
- 使用时间-面积度量,提供经典攻击与量子攻击成本的现实比较。
- 评估错误校正和逻辑门实现对量子密码分析整体可行性的影响。
提出的方法
- 使用Clifford+T门集构建SHA-256和SHA3-256的可逆量子电路。
- 利用T-par量子电路优化工具,对电路进行最小化T-计数和T-深度的优化。
- 通过表面码编码估算容错资源成本,使用逻辑Clifford+T操作。
- 假设阈值错误率为$10^{-5}$,使用表面码对魔术态distillation开销进行建模。
- 使用时间-面积度量,将总成本计算为逻辑量子比特数与表面码周期数的乘积。
- 推导出SHA-256的总成本为$2^{166.4}$,SHA3-256的总成本为$2^{166.5}$,主要由魔术态distillation主导。
实验结果
研究问题
- RQ1在考虑容错量子错误校正时,SHA-256和SHA3-256的量子原像攻击成本比原来高出多少?
- RQ2在基于表面码的量子计算机上执行Grover算法进行哈希原像搜索时,主要的资源瓶颈是什么?
- RQ3与查询数量相比,魔术态distillation使量子原像攻击的总成本增加了多少?
- RQ4当使用现实的纠错架构而非仅考虑查询的模型时,资源需求如何扩展?
- RQ5时间-面积成本度量是否能比标准查询复杂度模型更准确地比较经典攻击与量子攻击?
主要发现
- 对SHA-256的量子原像攻击总成本估算为$2^{166.4}$个逻辑量子比特-周期,其中包含$2^{153.8}$个表面码周期和$2^{12.6}$个逻辑量子比特。
- 对于SHA3-256,攻击成本为$2^{166.5}$个逻辑量子比特-周期,需$2^{146.5}$个表面码周期和$2^{20}$个逻辑量子比特。
- 主要成本因素是魔术态distillation,需294个distillation工厂以满足$T$-门需求,使物理量子比特数量增至$1.63 \times 10^8$。
- 攻击深度受魔术态生成限制,以200 ns周期计算,耗时约$7.23 \times 10^{29}$年。
- 由于错误校正和distillation开销,时间-面积成本远超基于查询复杂度的简单估算$2^{128}$,高出2750多亿倍。
- 结果表明,尽管Grover算法提供二次加速,但容错实现的实际成本严重限制了此类攻击的可行性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。