基于MILP的ECLBC算法积分区分器搜索OA
MILP-Based Search for Integral Distinguishers of ECLBC Algorithm
ECLBC 算法是 Guo 等人于 2024 年提出的一种 SPN 结构的轻量级分组算法,具有错误检测和纠错机制,能够实现数据的安全传输,在物联网领域具有广阔的应用前景.积分分析是一种常用的密码分析方式,利用三子集比特可分性质,结合 MILP 自动化搜索工具,可以更精确、更有效地找到积分区分器.本文针对分组密码 ECLBC 算法,利用 MILP 模型寻找基于三子集比特可分性的积分区分器.值得注意的是,在对 ECLBC 算法非线性层可分性质建模时,使用"S-box"技术,将非线性层看作"S-box"层,在描述非线性运算 S 盒可分性质传播时,使用"先扩充再缩减"的约简算法来生成相应的不等式集.首先,在原凸包计算方法生成的不等式集的基础上生成一个更大的不等式集.其次,从上一步的大集合中选择一个小而充分的不等式子集.通过本文方法,大大缩减了 ECLBC 算法"S-box"可分性质传播的线性不等式数量.此外,通过交叉传播,将搜索密码算法 r 轮三子集可分性的积分区分器转化为求解 r 个 MILP 模型,首次找到了 ECLBC 算法的 9 轮积分区分器,比之前的最佳结果多了一轮.
ECLBC algorithm is a lightweight block cipher with SPN structure proposed by Guo et al.in 2024,which has error detection and error correction mechanism,and can realize the secure transmission of data,and has a broad application prospect in the field of Internet of Things(IoT).Integral analysis is a commonly used way of cryptanalysis,using the three-subset bit division property,combined with the MILP automated search tool,can be more accurate and effective to find the integral distinguisher.This study uses the MILP model to find the integral distinguisher based on the three-subset bit division for the block cipher ECLBC algorithm.It is worth noting that,in modelling the division of the nonlinear layer of the ECLBC algorithm,the"S-box"technique is used,where the nonlinear layer is regarded as the"S-box"layer,and in describing the propagation of the division of the S-box of the nonlinear operations,the"expand-and-reduce"technique is used,where the nonlinear layer is regarded as the"S-box"layer.In describing the propagation of the division property of the nonlinear S-box,the"expand-and-reduce"reduction algorithm is used to generate the corresponding inequality sets.Firstly,a larger set of inequalities is generated based on the original set of inequalities generated by the convex method.Secondly,a small and sufficient subset of inequalities is selected from the large set in the previous step.By proposed method,the number of linear inequalities propagated by the"S-box"division property of the ECLBC algorithm is greatly reduced.In addition,through cross propagation,the integral distinguisher for searching for the division property of three-subset of an algorithm with r rounds is transformed into solving r MILP models,and for the first time,a 9-round integral distinguisher is found for the ECLBC algorithm,which is one round more than the previous best result.
李艳俊;张黎仙;林怡平;陈颖;谢惠琴
中国电子科技集团公司第十五研究所 信息产业信息安全测评中心,北京 100083||北京电子科技学院 密码科学与技术系,北京 100070北京电子科技学院 密码科学与技术系,北京 100070北京电子科技学院 网络空间安全系,北京 100070北京电子科技学院 密码科学与技术系,北京 100070北京电子科技学院 密码科学与技术系,北京 100070
信息技术与安全科学
ECLBC算法三子集MILP约简算法交叉传播
ECLBCthree-subsetMILPreduction algorithmcross propagation
《密码学报(中英文)》 2026 (2)
310-324,15
北京市自然科学基金(4234084)Natural Science Foundation of Beijing Municipality(4234084)
评论