arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.24799quant-phcs.CR

掩码差分线性区分器与量子方法

Masked Differential-linear Distinguishers and Quantum Approaches

Shobhit Pandey, Sarbani Sen, Debajyoti Bera, Ravi Anand

AI总结:

该研究提出掩码自相关基元及相关量子攻击流程,给出求解MAC Fishing问题的常数查询量子算法并证明经典指数下界,还构建了带量子加速的区分器与密钥恢复攻击,通过mini-AES实验验证了结论。

AI中文摘要:

我们提出了掩码自相关(masked auto-correlation)这一用于对称密钥原语密码分析的新基元,同时构建了基于该基元的量子攻击流程。对于置换$f$、输出掩码$\alpha,\beta$以及输入差分$w$,掩码自相关(MAC)用于衡量掩码输出$\alpha\cdot f(x)$与$\beta\cdot f(x\oplus w)$之间的相关性。与之相关的掩码差分线性(MDL)逼近严格推广了多种经典技术:普通线性密码分析、差分线性密码分析以及差分线性连接表都是其特例。我们的核心研究对象是寻找具有大掩码互相关的掩码对(这类掩码对可生成强区分器),我们将该问题称为MAC Fishing(MAC捕捞)。我们提出了一种常数查询的量子算法,能够按照掩码对的平方相关系数对其进行采样;同时通过适配Fourier Fishing(傅里叶捕捞)的难度,证明了经典算法的查询下界为指数级的$\Omega(N/\log N)$。据我们所知,这是首个针对识别高相关逼近这一核心任务,同时给出量子上界与经典下界的结果,表明量子算法是解决该问题的必需手段。在此基础上,我们分析了随机置换的掩码自相关分布,随后分别构建了经典的以及借助振幅估计实现二次量子加速的、基于容量的区分器和密钥恢复攻击。我们通过在缩减轮次的mini-AES上开展实验,验证了上述结论。

英文摘要:

We introduce masked auto-correlation, a new primitive for the cryptanalysis of symmetric-key primitives, together with a quantum attack pipeline built on it. For a permutation $f$, output masks $α,β$, and an input difference $w$, masked auto-correlation (MAC) measures the correlation between the masked outputs $α\cdot f(x)$ and $β\cdot f(x\oplus w)$. The associated masked differential-linear (MDL) approximations strictly generalize several classical techniques; ordinary linear cryptanalysis, differential-linear cryptanalysis, and the differential-linear connectivity table all arise as special cases. Our central object of study is the problem of finding mask pairs with large masked cross-correlation -- those that yield powerful distinguishers -- which we call MAC Fishing. We give a constant-query quantum algorithm that samples such pairs according to their squared correlation, and we prove an exponential classical lower bound of $Ω(N/\log N)$ queries, by adapting the hardness of Fourier Fishing. To our knowledge this is the first result pairing a quantum upper bound with a classical lower bound for the core task of identifying high-correlation approximations, making quantum algorithms an absolute necessity. Building on this, we analyse the distribution of masked auto-correlation for random permutations, and then construct capacity-based distinguishers and key-recovery attacks, both classically and with a quadratic quantum speed-up using amplitude estimation. We validate our claims with experiments on reduced-round mini-AES.

↑