Dierential Distribution Tables and Other Properties of Substitution Boxes

نویسندگان

  • Xian-Mo Zhang
  • Yuliang Zheng
  • Hideki Imai
چکیده

Due to the success of dierential and linear attacks on a large number of encryption algorithms, it is important t o investigate relationships among the various cryptographic, including dierential and linear, characteristics of an S-box (substitution box). After discussing a precise relationship among three tables, namely the dierence, auto-correlation and correlation immunity distribution tables, of an S-box, we develop a number of results on various properties of S-boxes. These results include: (1) an interesting equivalence relationship between a regular (balanced) S-box and a t i g h t l o wer bound on the sum of elements in the leftmost column of its dierential distribution table, (2) a proof for the nonexistence of quadratic S-boxes with a uniformly half-occupied dierence distribution table for the case of n > = 2m01. This serves as a piece of evidence that further supports an important and unproven conjecture, namely, for all n > m, there exist no n 2 m S-boxes with a uniformly half-occupied dierence distribution table. Prior to this work, the best known result that supports the conjecture is that there exist no quadratic S-boxes with a uniformly half-occupied dierence distribution table if n or m is even, (3) a non-trivial and tight l o wer bound on the differential uniformity of an S-box, and (4) two upper bounds on the nonlinearity o f S-b o xes (one for a general, not necessarily regular, S-box and the other for a regular S-box). I Introduction This paper deals with n 2 m S-boxes with n > m. Success of the notable dierential cryptanalysis on various block ciphers [4, 5] has motivated researchers to investigate properties of the dierence distribution tables of S-boxes. A core topic in the endeavor is to nd out relationships between dierential distribution tables and other properties of S-boxes. In this paper we r s t i n troduce two additional tables associated with an S-box, these being the auto-correlation and correlation immunity distribution tables. Then we establish a precise relationship among the three tables of an S-box (i.e., the dierence, auto-correlation and correlation immunity distribution tables). With this relationship as a basis, we s h o w t h a t an S-box is regular (or balanced) if and only if the sum of the values in the left-most column of its dierent distribution table is 2 2n0m. In a sense, this result complements a well-known fact about …

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Relating Differential Distribution Tables to Other Properties of of Substitution Boxes

Due to the success of differential and linear attacks on a large number of encryption algorithms, it is important to investigate relationships among various cryptographic, including differential and linear, characteristics of an S-box (substitution box). After discussing a precise relationship among three tables, namely the difference, auto-correlation and correlation immunity distribution tabl...

متن کامل

Non-existence of Certain Quadratic S-boxes and Two Bounds on Nonlinear Characteristics of General S-boxes

Due to the success of diierential and linear attacks on a large number of encryption algorithms, it is important to investigate relationships among the various cryptographic, including diierential and linear, characteristics of an S-box (substitution box). After discussing a precise relationship among three tables, namely the diierence, auto-correlation and correlation immunity distribution tab...

متن کامل

Designing cryptographically strong S-boxes with the use of cellular automata

Block ciphers are widely used in modern cryptography. Substitution boxes (S–boxes) are main elements of these types of ciphers. In this paper we propose a new method to create S–boxes, which is based on application of Cellular Automata (CA). We present the results of testing CA-based S–boxes. These results confirm that CA are able to realize efficiently the Boolean function corresponding to cla...

متن کامل

Area, Delay, and Power Characteristics of Standard-Cell Implementations of the AES S-Box

Cryptographic substitution boxes (S-boxes) are an integral part of modern block ciphers like the Advanced Encryption Standard (AES). There exists a rich literature devoted to the efficient implementation of cryptographic S-boxes, wherein hardware designs for FPGAs and standard cells received particular attention. In this paper we present a comprehensive study of different standard-cell implemen...

متن کامل

Applying AXIOM to Partial Di erential Equations

We present an AXIOM environment called JET for geometric computations with partial dierential equations within the framework of the jet bundle formalism. This comprises especially the completion of a given dierential equation to an involutive one according to the Cartan-Kuranishi Theorem and the setting up of the determining system for the generators of classical and non-classical Lie symmetrie...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1997