Differentially 4-uniform bijections by permuting the inverse function

نویسندگان

  • Deng Tang
  • Claude Carlet
  • Xiaohu Tang
چکیده

Block ciphers use Substitution boxes (S-boxes) to create confusion into the cryptosystems. Functions used as S-boxes should have low differential uniformity, high nonlinearity and algebraic degree larger than 3 (preferably strictly larger). They should be fastly computable; from this viewpoint, it is better when they are in even number of variables. In addition, the functions should be bijections in a Substitution-Permutation Network. Almost perfect nonlinear (APN) functions have the lowest differential uniformity 2 and the existence of APN bijections over F2n for even n ≥ 8 is a big open problem. In the present paper, we focus on constructing differentially 4-uniform bijections suitable for designing S-boxes for block ciphers. Based on the idea of permuting the inverse function, we design a construction providing a large number of differentially 4-uniform bijections with maximum algebraic degree and high nonlinearity. For every even n ≥ 12, we mathematically prove that the functions in a subclass of the constructed class are CCZ-inequivalent to known differentially 4-uniform power functions and to quadratic functions. This is the first mathematical proof that an infinite class of differentially 4-uniform bijections is CCZ-inequivalent to known differentially 4-uniform power functions and to quadratic functions. We also get a general lower bound on the nonlinearity of our functions, which can be very high in some cases, and obtain three improved lower bounds on the nonlinearity for three special subcases of functions which are extremely large.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

New Construction of Differentially 4-Uniform Bijections

Block ciphers use Substitution boxes (S-boxes) to create confusion into the cryptosystems. For resisting the known attacks on these cryptosystems, the following criteria for functions are mandatory: low differential uniformity, high nonlinearity and not low algebraic degree. Bijectivity is also necessary if the cipher is a Substitution-Permutation Network, and balancedness makes a Feistel ciphe...

متن کامل

Constructing Differentially 4-uniform Permutations over GF(22k) from the Inverse Function Revisited

Constructing S-boxes with low differential uniformity and high nonlinearity is of cardinal significance in cryptography. In the present paper, we show that numerous differentially 4-uniform permutations over F22k can be constructed by composing the inverse function and cycles over F22k . Two sufficient conditions are given, which ensure that the differential uniformity of the corresponding comp...

متن کامل

Further results on differentially 4-uniform permutations over F22m

In this paper, we present several new constructions of differentially 4-uniform permutations over F22m by modifying the values of the inverse function on some subsets of F22m . The resulted differentially 4-uniform permutations have high nonlinearities and algebraic degrees, which provide more choices for the design of crytographic substitution boxes.

متن کامل

An Equivalent Condition on the Switching Construction of Differentially 4-uniform Permutations on F22k from the Inverse Function

Differentially 4-uniform permutations on F22k with high nonlinearity are often chosen as Substitution boxes in block ciphers. Recently, Qu et al. used the powerful switching method to construct such permutations from the inverse function [9], [10]. More precisely, they studied the functions of the form G(x) = 1 x +f( 1 x ), where f is a Boolean function. They proved that if f is a preferred Boo...

متن کامل

A new construction of differentially 4-uniform permutations over $F_{2^{2k}}$

Permutations over F22k with low differential uniform, high algebraic degree and high nonlinearity are of great cryptographical importance since they can be chosen as the substitution boxes (S-boxes) for many block ciphers. A well known example is that the Advanced Encryption Standard (AES) chooses a differentially 4-uniform permutation, the multiplicative inverse function, as its S-box. In this...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2013  شماره 

صفحات  -

تاریخ انتشار 2013