在真实量子硬件上首次实现对10轮对称密码的周期恢复,突破此前4轮纪录。
Quantum Cryptanalysis on IBM Quantum Hardware: Extending Even--Mansour Period Recovery from $N=4$ to $N=10$

- 基于西蒙算法,在真实量子设备上破解多轮对称结构的隐藏周期。
- 成功在6位和8位块大小下恢复3轮费斯泰尔结构周期,10位块大小实例已提交硬件运行。
- 提供涵盖四种密码范式的可复现量子攻击基准,适合关注后量子安全的工程师参考。
本文在真实IBM量子硬件(ibm_kingston,Heron架构)上,首次实现无需编译、忠实于教科书的量子密码分析。利用西蒙算法,将埃文-曼索尔密码的隐含周期恢复能力从此前最大记录的N=4扩展至N=10。同时,成功在块长为6和8的3轮费斯泰尔结构中清晰恢复周期;一个21量子比特的块长10实例已完成仿真验证并提交硬件执行。此外,本文还构建了一个广度优先的基准测试,涵盖五种真实的量子攻击,覆盖四种对称密码设计范式:伯恩斯坦-瓦齐拉尼(线性结构,单次查询)、格罗弗(SPN密钥搜索,二次加速)、西蒙(埃文-曼索尔、CBC-MAC伪造、费斯泰尔;查询复杂度由指数降至多项式)。所有攻击均在25量子比特经典模拟上限内验证。研究明确指出:这些攻击针对的是简化或有结构的构造,遵循生日界渐近行为,不构成对经典碰撞查找的量子优势,未破解完整版AES/RSA或16轮DES,且依赖错误缓解而非容错纠错。贡献在于实现在最大结构规模下的真实硬件演示、跨四大范式的算法覆盖面以及公开可复现的基准数据集。
原文摘要 · Abstract (English)
We report genuine-un-compiled, textbook-faithful-quantum cryptanalysis of symmetric-cipher structures executed on real IBM quantum hardware (ibm\_kingston, Heron generation). Using Simon's algorithm we recover the hidden period of the Even-Mansour cipher up to security parameter N = 10 on real hardware, beyond the largest previously reported real-hardware key recovery of N = 4, and we cleanly recover the periods of a 3-round Feistel (DES-family) construction at block sizes 6 and 8; a 21-qubit block-10 instance is verified in simulation and submitted to hardware. We further provide a breadth-first benchmark of five genuine quantum attacks spanning four symmetric-cipher design paradigms -- Bernstein-Vazirani (linear structure, single query), Grover (SPN key search, quadratic), and Simon (Even-Mansour, CBC-MAC forgery, and Feistel; exponential-to-polynomial in query complexity) -- validated to the classical-simulation ceiling of 25 qubits. We are deliberately explicit about scope: these attacks target reduced or structured constructions in the Q2 (quantum-query) model, asymptotically follow the birthday bound and therefore do not constitute quantum advantage over classical collision-finding, do not break full AES/RSA or 16-round DES, and rely on error mitigation rather than fault-tolerant error correction. Our contribution is the real-hardware demonstration at record structure sizes, the breadth of genuine algorithmic coverage across four paradigms, and an honest, reproducible benchmark with public artifacts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。