Parallel Framework for Evolutionary Blackbox Optimization with Application
Parallel Framework for Evolutionary Blackbox Optimization with Application to Algebraic Cryptanalysis presenter: Stepan Kochemazov A. Pavlenko, A. Semenov, V. Ulyantsev, O. Zaikin {alpavlenko, ulyantsev}@corp. ifmo. ru biclop. rambler@yandex. ru zaikin. icc@gmail. com ITMO University, St. Petersburg, Russia ISDCT SB RAS, Irkutsk, Russia
Cryptanalysis • There a lot of ways to encode and to decode information • HTTPS, mobile traffic … • man in the middle • Algebraic cryptanalysis is a way of analyzing and breaking ciphers • Type of attacks: • Brute-force attack • Guess-and-determine attack 2
Stream ciphers and cryptanalysis Cipher A 5/1 – used in 2 G protocol b 1 A b 2 B b 3 C b 1, b 2, b 3 – clocking bits X = X A ∪ XB ∪ XC X = {x 1, x 2, …, x 64} Y = {y 1, y 2, …, y 128} f : {0, 1}64 → {0, 1}128 f (x) = y Research question: how practically hard it is to decrypt some encrypted text? 3
SAT and SAT-solvers • Boolean SATisfiability – first known NP-complete problem • A dozen of applicable SAT-solvers • minisat, lingeling, ROKK … • SAT, UNSAT • Annular competitions in solving SAT! ⇓ good idea to translate hard problem to SAT 4
Encode to SAT using Transalg* Cipher A 5/1 b 1 SAT-formula Transalg program A b 2 B b 3 manually ⇒ automatically ⇒ C b 1, b 2, b 3 – clocking bits X = X A ∪ XB ∪ XC X = {x 1, x 2, …, x 64} Y = {y 1, y 2, …, y 128} … … *Transalg: [Otpuschennikov, I. , Semenov, A. , Gribanova, I. , Zaikin, O. , Kochemazov, S. : Encoding Cryptographic Functions to SAT Using TRANSALG System. In: ECAI 2016. FAIA, vol. 285, pp. 1594– 1595 (2016)] 5
Example of breaking for Trivium 64 CPU: AMD Opteron 6276 @ 2. 3 GHz x 32 Timelimit: 7 days PLingeling Treengeling Guess-and-determine attack task 1 interrupted 2 d 6 h task 2 interrupted 3 d 2 h 3 d 19 h task 3 interrupted 4 d 10 h 15 h task 4 interrupted 1 d 21 h task 5 interrupted 4 d 3 h 6
2. Guess-and-determine attacks 7
Guess-and-Determine. Backdoor B = { x 1, x 2, x 3, x 4, x 5, x 9, x 12, x 16, x 19, x 20, x 21, x 22, x 23, x 24, x 25, x 27, x 28, x 30, x 36, x 41, x 42, x 43, x 47, x 48, x 49, x 50, x 52, x 60 } 8
Guess-and-Determine. Guess B = { x 1, x 2, x 3, x 4, x 5, x 9, x 12, x 16, x 19, x 20, x 21, x 22, x 23, x 24, x 25, x 27, x 28, x 30, x 36, x 41, x 42, x 43, x 47, x 48, x 49, x 50, x 52, x 60 } 9
Guess-and-Determine solver. solve Result: UNSAT ⇒ Time: 1. 243 c 10
Guess-and-Determine. Definition , τ1 = 1. 243 c 11
How to construct a efficient backdoor? 12
Backdoor-based Decomposition Key stream length s = |B| – power of backdoor set 13
Monte-Carlo Sampling 14
Evaluating If the task is solved in time T, then ξ = 1, else ξ = 0 Fitness function Estimation of breaking time = Fitness value Estimation technics: [Semenov, A. , Zaikin, O. , Otpuschennikov, I. , Kochemazov, S. , Ignatiev, A. : On Cryptographic Attacks Using Backdoors for 15 SAT. In: Proc. of AAAI 2018. pp. 6641– 6648 (2018)]
Intermediate sum-up • Analyzing stream cyphers is a hard problem • We can translate the attack to SAT • We can speedup the SAT-based attack using backdoor • Selecting the efficient backdoor is a hard problem • But there is a way to estimate the attack time for a given backdoor ⇓ magic Estimation of breaking time 16
3. Framework for minimizing a fitness function 17
Framework scheme 18
Algorithm module We apply (1+1)-EA GA (Elitism) Framework supports Tabu Search Simulated Annealing Individual: bit vector, which presents a backdoor set B = { x 1, x 2, x 3, x 4, x 5, x 9, x 12, x 16, x 19, x 20, x 21, x 22, x 23, x 24, x 25, x 27, x 28, x 30, x 36, x 41, x 42, x 43, x 47, x 48, x 49, x 50, x 52, x 60 } ⇓ 19
Predictive function module 20
Concurrency module 21
Solver module Result: SAT Time: 2. 311 c Implemented wrappers: • Mini. Sat • Lingeling • Plingeling • Treengeling • ROKK • Crypto. Mini. Sat • Pa. In. Le. SS Result: UNSAT Time: 0. 526 c Result: SAT Time: 1. 243 c 22
Predictive function module. Evaluating tk – time of solving task k If the task is solved in time T, then ξ = 1, else ξ = 0 23
Experimental results. First function ALIAS* Evo. Guess (1+1)-EA |B| Attack time (s) Grain v 1 160/160 109 4. 04 e+30 100 7. 51 e+30 Trivium 288/300 144 1. 40 e+41 143 3. 51 e+43 Mickey 200/250 158 1. 56 e+48 169 1. 77 e+51 *ALLIAS: [Zaikin O. , Kochemazov S. Pseudo-Boolean Black-Box Optimization Methods in the Context of Divide-and-Conquer Approach to Solving Hard SAT Instances. In DEStech Transactions on Computer Science and Engineering, pp. 76 -87 (2018)] 24
Experimental results. Second function Evo. Guess GA Evo. Guess (1+1)-EA |B| Attack time (s) Grain v 1 160/160 104 4. 71 e+32 103 7. 23 e+31 Trivium 288/300 136 1. 52 e+43 146 5. 08 e+43 Mickey 200/250 159 9. 73 e+50 152 8. 18 e+50 25
Conclusion • We propose new framework for algebraic cryptanalysis. • We used (1+1)-EA and GA to construct SAT-based guess-and-determine attacks on symmetric ciphers. • We could not outperform ALIAS, so we are planning to significantly extend the framework’s spectrum of pseudo-Boolean optimization algorithms and improve the search for guessed bits via tuning parameters of the used SAT solvers. • Supposed by the Russian Science Foundation (project No 18 -71 -00150) 26
Thank you for attention! presenter: Stepan Kochemazov Artem Pavlenko, Alexander Semenov, Vladimir Ulyantsev, Oleg Zaikin {alpavlenko, ulyantsev}@corp. ifmo. ru biclop. rambler@yandex. ru zaikin. icc@gmail. com instagram. com/itmo. ctlab 27
- Slides: 27