{"title":"针对量子攻击的 Atom 分析","authors":"Ravi Anand, Rimpa Nandi, Takanori Isobe","doi":"10.1049/qtc2.12076","DOIUrl":null,"url":null,"abstract":"<p>A significant amount of study is being done to review the security promises made for the various ciphers now in use as a result of the development of quantum computing technology. A general attack against symmetric key cryptography primitives that can reduce search costs to the square root is Grover's search algorithm. To implement Grover's algorithm, it is necessary that the target cipher be implemented as a quantum circuit. Despite being relatively new, this area of study has received significant attention from the research community. The authors have estimated the cost of Grover's key search attack against the stream cipher Atom, for the first time, under circuit depth restrictions defined in National Institute of Standards and Technology (NIST) PQC standardisation process. The authors implement the quantum circuit of Atom in QISKIT, (open-source software development kit for working with quantum computers running on IBM Quantum Experience). The results are also compared with other existing literature on LFSR-based stream ciphers, such as Grain-v1, Grain-128-AEAD, and Lizard. The authors also find that, to the best of their knowledge, in the existing literature on estimating the cost of Grover's attack on symmetric ciphers, Atom is the only 128-bit key cipher that meets the threshold of ≈2<sup>170</sup> set by NIST for quantum security of 128-bit key ciphers. The authors also analyse the security of Atom against quantum TMDTO attacks.</p>","PeriodicalId":100651,"journal":{"name":"IET Quantum Communication","volume":"5 1","pages":"88-102"},"PeriodicalIF":2.5000,"publicationDate":"2023-11-09","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/qtc2.12076","citationCount":"0","resultStr":"{\"title\":\"Analysis of Atom against quantum attacks\",\"authors\":\"Ravi Anand, Rimpa Nandi, Takanori Isobe\",\"doi\":\"10.1049/qtc2.12076\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p>A significant amount of study is being done to review the security promises made for the various ciphers now in use as a result of the development of quantum computing technology. A general attack against symmetric key cryptography primitives that can reduce search costs to the square root is Grover's search algorithm. To implement Grover's algorithm, it is necessary that the target cipher be implemented as a quantum circuit. Despite being relatively new, this area of study has received significant attention from the research community. The authors have estimated the cost of Grover's key search attack against the stream cipher Atom, for the first time, under circuit depth restrictions defined in National Institute of Standards and Technology (NIST) PQC standardisation process. The authors implement the quantum circuit of Atom in QISKIT, (open-source software development kit for working with quantum computers running on IBM Quantum Experience). The results are also compared with other existing literature on LFSR-based stream ciphers, such as Grain-v1, Grain-128-AEAD, and Lizard. The authors also find that, to the best of their knowledge, in the existing literature on estimating the cost of Grover's attack on symmetric ciphers, Atom is the only 128-bit key cipher that meets the threshold of ≈2<sup>170</sup> set by NIST for quantum security of 128-bit key ciphers. The authors also analyse the security of Atom against quantum TMDTO attacks.</p>\",\"PeriodicalId\":100651,\"journal\":{\"name\":\"IET Quantum Communication\",\"volume\":\"5 1\",\"pages\":\"88-102\"},\"PeriodicalIF\":2.5000,\"publicationDate\":\"2023-11-09\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://onlinelibrary.wiley.com/doi/epdf/10.1049/qtc2.12076\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"IET Quantum Communication\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://onlinelibrary.wiley.com/doi/10.1049/qtc2.12076\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q3\",\"JCRName\":\"QUANTUM SCIENCE & TECHNOLOGY\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Quantum Communication","FirstCategoryId":"1085","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/qtc2.12076","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"QUANTUM SCIENCE & TECHNOLOGY","Score":null,"Total":0}
引用次数: 0
摘要
由于量子计算技术的发展,目前正在进行大量研究,以审查目前使用的各种密码的安全承诺。格罗弗搜索算法是针对对称密钥加密原理的一般攻击,它可以将搜索成本降低到平方根。要实现格罗弗算法,必须将目标密码作为量子电路来实现。尽管这一研究领域相对较新,但已受到研究界的极大关注。作者首次估算了在美国国家标准与技术研究院(NIST)PQC 标准化流程规定的电路深度限制下,格罗弗针对流密码 Atom 的密钥搜索攻击的成本。作者在 QISKIT(用于在 IBM Quantum Experience 上运行量子计算机的开源软件开发工具包)中实现了 Atom 的量子电路。研究结果还与基于 LFSR 的流密码的其他现有文献进行了比较,如 Grain-v1、Grain-128-AEAD 和 Lizard。作者还发现,据他们所知,在估算格罗弗对对称密码攻击成本的现有文献中,Atom 是唯一符合 NIST 为 128 位密钥密码量子安全性设定的 ≈2170 门限的 128 位密钥密码。作者还分析了 Atom 对抗量子 TMDTO 攻击的安全性。
A significant amount of study is being done to review the security promises made for the various ciphers now in use as a result of the development of quantum computing technology. A general attack against symmetric key cryptography primitives that can reduce search costs to the square root is Grover's search algorithm. To implement Grover's algorithm, it is necessary that the target cipher be implemented as a quantum circuit. Despite being relatively new, this area of study has received significant attention from the research community. The authors have estimated the cost of Grover's key search attack against the stream cipher Atom, for the first time, under circuit depth restrictions defined in National Institute of Standards and Technology (NIST) PQC standardisation process. The authors implement the quantum circuit of Atom in QISKIT, (open-source software development kit for working with quantum computers running on IBM Quantum Experience). The results are also compared with other existing literature on LFSR-based stream ciphers, such as Grain-v1, Grain-128-AEAD, and Lizard. The authors also find that, to the best of their knowledge, in the existing literature on estimating the cost of Grover's attack on symmetric ciphers, Atom is the only 128-bit key cipher that meets the threshold of ≈2170 set by NIST for quantum security of 128-bit key ciphers. The authors also analyse the security of Atom against quantum TMDTO attacks.