A new almost perfect nonlinear function which is not quadratic

نویسندگان

  • Yves Edel
  • Alexander Pott
چکیده

Following an example in [13], we show how to change one coordinate function of an almost perfect nonlinear (APN) function in order to obtain new examples. It turns out that this is a very powerful method to construct new APN functions. In particular, we show that the approach can be used to construct “non-quadratic” APN functions. This new example is in remarkable contrast to all recently constructed functions which have all been quadratic. 1 Preliminaries In this paper, we consider functions F : F n 2 → F n 2 with “good” differential and linear properties. Motivated by applications in cryptography, a lot of research has been done to construct functions which are “as nonlinear as possible”. We discuss two possibilities to define nonlinearity: One approach uses differential properties of linear functions, the other measures the “distance” to linear functions. Let us begin with the differential properties. Given F : F n 2 → F n 2 , we define ∆F (a, b) := |{x : F (x+ a)− F (x) = b}|. We have ∆F (0, 0) = 2 , and ∆F (0, b) = 0 if b 6= 0. Since we are working in fields of characteristic 2, we may replace the “−” by + and write F (x+a)+F (x) instead of F (x−a)−F (x). We say that F is almost perfect nonlinear (APN) if ∆F (a, b) ∈ {0, 2} for all a, b ∈ F n 2 , a 6= 0. Note that ∆F (a, b) ∈ {0, 2} if F is linear, hence the condition ∆F (a, b) ∈ {0, 2} identifies functions which are quite different from linear mappings. Since we are working in characteristic 2, it is impossible that ∆F (a, b) = 1 for some a, b, since the values ∆F (a, b) must be even: If x is a solution of F (x + a)− F (x) = b, then x + a, too. In the case of odd characteristic, functions F : F n q → F n q with ∆F (a, b) = 1 for all a 6= 0 do exist, and they are called perfect nonlinear or planar. In the last few years, many new APN functions have been constructed. The first example of a non-power mapping has been described in [26]. Infinite series are contained in [5, 10, 11, 12, 13, 16, 17]. Also some new planar functions have been found, see [15, 22, 36]. There may be a possibility for a unified treatment of (some of) these constructions in the even and odd characteristic case. In particular, we suggest to look more carefully at the underlying design of an APN function, similar to the designs corresponding to planar functions, which are projective planes, see [29]. Department of Pure Mathematics and Computer Algebra, Ghent University, Krijgslaan 281, S22, B-9000 Ghent, Belgium. The research is supported by the Interuniversitary Attraction Poles Programme-Belgian State-Belgian Science Policy: project P6/26-Bcrypt. Department of Mathematics, Otto-von-Guericke-University Magdeburg, D-39016 Magdeburg, Germany An equivalent function has been found independently by Brinkmann and Leander [7]. However, they claimed that their function is CCZ equivalent to a quadratic one. In this paper we give several reasons why this new function is not equivalent to a quadratic one

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Determining the Optimal Value Bounds of the Objective Function in Interval Quadratic Programming Problem with Unrestricted Variables in Sign

In the most real-world applications, the parameters of the problem are not well understood. This is caused the problem data to be uncertain and indicated with intervals. Interval mathematical models include interval linear programming and interval nonlinear programming problems.A model of interval nonlinear programming problems for decision making based on uncertainty is interval quadratic prog...

متن کامل

A new approach based on state conversion to stability analysis and control design of switched nonlinear cascade systems

In this paper, the problems of control and stabilization of switched nonlinear cascade systems is investigated. The so called simultaneous domination limitation (SDL) is introduced in previous works to assure the existence of a common quadratic Lyapunov function (CQLF) for switched nonlinear cascade systems. According to this idea, if all subsystems of a switched system satisfy the SDL, a CQLF ...

متن کامل

Quadratic Equations from APN Power Functions

We develop several tools to derive quadratic equations from algebraic S-boxes and to prove their linear independence. By applying them to all known almost perfect nonlinear (APN) power functions and the inverse function, we can estimate the resistance against algebraic attacks. As a result, we can show that APN functions have different resistance against algebraic attacks, and especially S-boxe...

متن کامل

Binary quasi-perfect linear codes from APN quadratic functions

A mapping f from F2m to itself is almost perfect nonlinear (APN) if its directional derivatives in nonzero directions are all 2-to-1. Let Cf be the binary linear code of length 2 − 1, whose parity check matrix has its j-th column [ π f(π) ] , where π is a primitive element in F2m and j = 0, 1, · · · , 2 − 2. For m ≥ 3 and any quadratic APN function f(x) = ∑m−1 i,j=0 ai,jx 2+2 , ai,j ∈ F2m , it ...

متن کامل

On Quadratic Almost Perfect Nonlinear Functions and Their Related Algebraic Object

It is well known that almost perfect nonlinear (APN) functions achieve the lowest possible differential uniformity for functions defined on fields with even characteristic, and hence, from this point of view, they are the most ideal choices for S-boxes in block and stream ciphers. They are also interesting as the link to many other areas, for instance topics in coding theory and combinatorics. ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • IACR Cryptology ePrint Archive

دوره 2008  شماره 

صفحات  -

تاریخ انتشار 2008