<p>In this paper, we analyse the impact of the HHL quantum algorithm on stream ciphers in a black-box setting. We assume a black-box access to an oracle <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10791_2025_9530_Article_IEq1.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="29" /> </InlineMediaObject> <EquationSource Format="TEX">\(M^S\)</EquationSource> <EquationSource Format="MATHML"><math> <msup> <mi>M</mi> <mi>S</mi> </msup> </math></EquationSource> </InlineEquation> defining the output of the stream cipher. For a state <i>k</i> encapsulating the key material, the value <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10791_2025_9530_Article_IEq2.gif" Format="GIF" Height="17" Rendition="HTML" Resolution="72" Type="Linedraw" Width="52" /> </InlineMediaObject> <EquationSource Format="TEX">\(M^S\cdot k\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <msup> <mi>M</mi> <mi>S</mi> </msup> <mo>·</mo> <mi>k</mi> </mrow> </math></EquationSource> </InlineEquation> is the keystream <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="10791_2025_9530_Article_IEq3.gif" Format="GIF" Height="19" Rendition="HTML" Resolution="72" Type="Linedraw" Width="101" /> </InlineMediaObject> <EquationSource Format="TEX">\((k'_1,k'_2,..., k'_N)\)</EquationSource> <EquationSource Format="MATHML"><math> <mrow> <mo stretchy="false">(</mo> <msubsup> <mi>k</mi> <mn>1</mn> <mo>′</mo> </msubsup> <mo>,</mo> <msubsup> <mi>k</mi> <mn>2</mn> <mo>′</mo> </msubsup> <mo>,</mo> <mo>.</mo> <mo>.</mo> <mo>.</mo> <mo>,</mo> <msubsup> <mi>k</mi> <mi>N</mi> <mo>′</mo> </msubsup> <mo stretchy="false">)</mo> </mrow> </math></EquationSource> </InlineEquation> generated by some stream cipher <i>S</i>. We translate this scenario into the quantum setting and describe how the HHL algorithm could be used to attack this construction. Further, we give simple and verifiable criteria under which a black-box attack on stream ciphers with the HHL algorithm is not efficiently feasible. Usually, these criteria follow from already known design principles for symmetric ciphers and should apply to the ciphers used today. We complement the criteria with a simple test, which confirms the resistance of said cipher. Moreover, we use our technique to test the currently used stream ciphers: Trivium, HC-128, and Salsa20.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Black-box security of stream ciphers under the quantum algorithm for linear systems of equations

  • Cezary Pilaszewicz,
  • Marian Margraf

摘要

In this paper, we analyse the impact of the HHL quantum algorithm on stream ciphers in a black-box setting. We assume a black-box access to an oracle \(M^S\) M S defining the output of the stream cipher. For a state k encapsulating the key material, the value \(M^S\cdot k\) M S · k is the keystream \((k'_1,k'_2,..., k'_N)\) ( k 1 , k 2 , . . . , k N ) generated by some stream cipher S. We translate this scenario into the quantum setting and describe how the HHL algorithm could be used to attack this construction. Further, we give simple and verifiable criteria under which a black-box attack on stream ciphers with the HHL algorithm is not efficiently feasible. Usually, these criteria follow from already known design principles for symmetric ciphers and should apply to the ciphers used today. We complement the criteria with a simple test, which confirms the resistance of said cipher. Moreover, we use our technique to test the currently used stream ciphers: Trivium, HC-128, and Salsa20.