Although several quantum cryptanalytic efforts have been made against SM4-like structures,existing key-recovery attacks either require nested applications of Simon’s algorithm or rely on its combination with Grover’...Although several quantum cryptanalytic efforts have been made against SM4-like structures,existing key-recovery attacks either require nested applications of Simon’s algorithm or rely on its combination with Grover’s algorithm.Thus,a 7-round quantum distinguisher is constructed specifically for SM4,which enables a polynomial-time key-recovery attack based on a direct application of Simon’s algorithm in the quantum chosen-plaintext(qCPA)attack model.Moreover,the proposed approach is extended to the d-branch SM4-like structure and a(2d−1)-round key-recovery distinguisher is developed where d is even,yielding a key-recovery attack that also runs in polynomial time.These results provide a simpler and clearer understanding of the resistance of SM4 against quantum attacks.展开更多
基金National Natural Science Foundation of China(623B2067)。
摘要Although several quantum cryptanalytic efforts have been made against SM4-like structures,existing key-recovery attacks either require nested applications of Simon’s algorithm or rely on its combination with Grover’s algorithm.Thus,a 7-round quantum distinguisher is constructed specifically for SM4,which enables a polynomial-time key-recovery attack based on a direct application of Simon’s algorithm in the quantum chosen-plaintext(qCPA)attack model.Moreover,the proposed approach is extended to the d-branch SM4-like structure and a(2d−1)-round key-recovery distinguisher is developed where d is even,yielding a key-recovery attack that also runs in polynomial time.These results provide a simpler and clearer understanding of the resistance of SM4 against quantum attacks.