Investigations on -Boomerang Uniformity and Perfect Nonlinearity
Abstract
We defined in [21] a new multiplicative -differential, and the corresponding -differential uniformity and we characterized the known perfect nonlinear functions with respect to this new concept, as well as the inverse in any characteristic. The work was continued in [29], investigating the -differential uniformity for some further APN functions. Here, we extend the concept to the boomerang uniformity, introduced at Eurocrypt ’18 by Cid et al. [16], to evaluate S-boxes of block ciphers, and investigate it in the context of perfect nonlinearity and related functions.
Keywords:
Boolean,
-ary functions,
-differentials,
differential uniformity,
boomerang uniformity,
perfect and almost perfect -nonlinearity
MSC 2000: 06E30, 11T06, 94A60, 94C10.
1 Introduction
In this paper we extend the notion of boomerang uniformity using a previously defined [21] multiplier differential (in any characteristic). We characterize some of the known perfect nonlinear functions and the inverse function through this new concept. We also characterize this concept via the Walsh transforms as Lie et al. [24] did for the classical boomerang uniformity.
The objects of this study are Boolean and -ary functions (where is an odd prime) and some of their differential properties. We will introduce here only some needed notation, and the reader can consult [9, 12, 13, 19, 27, 30] for more on Boolean and -ary functions.
For a positive integer and a prime number, we let be the finite field with elements, and be the multiplicative group (for , we often write to mean the inverse of in the multiplicative group). We let be the -dimensional vector space over . We use to denote the cardinality of a set and , for the complex conjugate. We call a function from (or ) to a -ary function on variables. For positive integers and , any map (or, ) is called a vectorial -ary function, or -function. When , can be uniquely represented as a univariate polynomial over (using some identification, via a basis, of the finite field with the vector space) of the form whose algebraic degree is then the largest Hamming weight of the exponents with . For we define the Walsh-Hadamard transform to be the integer-valued function where and is the absolute trace function, given by (we will denote it by , if the dimension is clear from the context). The Walsh transform of an -function at is the Walsh-Hadamard transform of its component function at , that is,
(If one wishes to work with vector spaces, then one can replace the by any scalar product on that environment.)
Given a -ary function , the derivative of with respect to is the -ary function which can be naturally extended to vectorial -ary functions.
For an -function , and , we let . We call the quantity the differential uniformity of . If , then we say that is differentially -uniform. If , then is called a perfect nonlinear (PN) function, or planar function. If , then is called an almost perfect nonlinear (APN) function. It is well known that PN functions do not exist if .
The paper is organized as follows. Section 2 contains some background on differential and boomerang uniformity and our extension to -boomerang uniformity. Section 3 contains some characterizations of this concept and connections with prior -differential uniformity, and Section 4 gives its description via Walsh transforms. Section 5 puts together two lemmas needed in the remaining of the paper, and Section 6 deals with perfect nonlinearity and -boomerang uniformity. Section 7 characterizes this uniformity for the inverse function in any characteristic and Section 8 concludes the paper. An appendix with some computational data follows the references.
2 Differential and boomerang uniformity
Wagner [32] introduced the boomerang attack against block ciphers using -boxes. The concept was picked up and used in [3, 22] on some real ciphers (see also [2, 23]). Ten years later, however, a theoretical new cryptanalysis tool based upon this attack was introduced at EUROCRYPT 2018 by Cid et al. [16] namely, the Boomerang Connectivity Table (BCT) and Boomerang Uniformity. In [16], the authors analyzed some of the properties of BCT, like its relationship with the Differential Distribution Table (DDT). They proved that perfect nonlinear (APN) S-boxes (that is, with 2-uniform DDT) always have 2-uniform BCT and for any choice of the parameters, and also showed that the BCT uniformity is greater than or equal to the DDT uniformity (we will display below precisely the relationship between these).
The initial concept of boomerang uniformity was defined for permutations (of course, proper -boxes) in the following way.
Definition 1.
Let be a permutation on and . We define the entries of the Boomerang Connectivity Table (BCT) by
where is the compositional inverse of . The boomerang uniformity of is defined as
We also say that is a -uniform BCT function.
Recently, BCT and the boomerang uniformity were further studied by Boura and Canteaut [6]. They showed that the boomerang uniformity is only an affine equivalence invariant but not necessarily, extended affine nor CCZ-equivalence invariant. Further, they also obtained the boomerang uniformity of the inverse function over , for even, namely, , when , respectively, . Also, for the Gold function over , where , even with , then .
Mesnager et al. [28] continued the work and showed that the differential uniformity for quadratic functions on ( is a -power) is always , and if it happens to be equal to for a permutations then its boomerang uniformity must be , as well. In fact [24], in general, for quadratic permutations , then we have,
It is also easy to show that for monomials , then . For the Bracken-Tan-Tan function (which is an extension of Budaghyan-Carlet function [10]), (under some conditions on the parameters), then (see [28]). More work has been done recently on BCT, and we mention here [7, 11, 25, 31].
Surely, and whenever . It is well-known from prior work that and . In general, for permutations, and they are equal for APN permutations. A natural question is what is the algebraic difference between these two concepts and Boura and Canteaut answered that question in [6], showing that
where . This was reformulated by Mesnager et al. [28] in the following way:
where , and further, by Li et al. [24], as
and easily observed in [28] that this transforms into (labeling ),
| (1) |
Avoiding the inverse of , allows these last expressions to define the boomerang uniformity for functions that are not necessarily permutations.
Before, we continue with our approach, let us recall the concept we (along with others) introduced in [21] (we will define it in general on , prime, not only for ).
Inspired by a practical differential attack developed in [5] (though, via a different differential), we extended the definition of derivative and differential uniformity in [21], in the following way. For a -ary -function , and , the (multiplicative) -derivative of with respect to is the function
(Observe that, if , then we obtain the usual derivative, and, if or , then we obtain a shift of the function, in the input/output.)
For an -function , and , we let the entries of the -Difference Distribution Table (-DDT) be defined by . We call the quantity
the -differential uniformity of (observe that we slightly change here the way we denoted the -differential uniformity in [21]). If , then we say that is differentially -uniform (or that has -uniformity , or for short, is -uniform -DDT). If , then is called a perfect -nonlinear (PcN) function (certainly, for , they only exist for odd characteristic ; however, as proven in [21], there exist PcN functions for , for all ). If , then is called an almost perfect -nonlinear (APcN) function. When we need to specify the constant for which the function is PcN or APcN, then we may use the notation -PN, or -APN. It is easy to see that if is an -function, that is, , then is PcN if and only if is a permutation polynomial.
In light of the formulations (1) via differentials, by using our -differential concept of [21], we extend the notion of boomerang uniformity to -boomerang uniformity for all characteristics, in the following way (see Figure 1).
Definition 2.
For an -function , , and , we define the -Boomerang Connectivity Table (-BCT) entry at to be
| (2) |
Further, the -boomerang uniformity of is defined by
If , we also say that is a -uniform -BCT function.
3 Characterizations of -boomerang uniformity
As in the classical case, we find an alternative formulation that avoids inverses, allowing the definition to be extended to all -function, not only permutations. Though the proof is not complicated, we label as a theorem, since it is the way to extend the definition to non-permutations.
Theorem 3.
For an -permutation function , , the entries of the -Boomerang Connectivity Table at are given by
(We shall call the system above, the -boomerang system, for easy referral.)
Proof.
Remark 1.
We could have defined the BCT entries of at to be
thus allowing . However, in the case of , we would obtain ; when is a permutation, we get and , rendering , regardless of the function. For this reason, we decided to remove out of allowable multipliers.
Remark 2.
For whatever reason, one can define the -DDT and -BCT, and the respective uniformities, even for arbitrary -functions. That is the reason why in some of our results, when it makes no difference for the proofs (except tracking carefully the parameters, of course), we take arbitrary -functions.
While we already knew that, in general, the -differential uniformity of are not the same, we show below a connection (that we did not observe in [21]) between some of the entries in the -Differential Distribution Table of a permutation monomial and the one of the inverse of .
Proposition 4.
Let be a permutation hence, monomial function on and . Then,
Proof.
Observe that, in general (assuming ),
If is the monomial , then the last equation above becomes
and the proposition will follow easily. ∎
We next show a connection between -differential and -boomerang uniformities.
Theorem 5.
Let be a permutation function on , and . Then . If , then
if either or . Consequently, , for all permutations (it is known [6] that ).
Proof.
If and , then
and so, and , which has only one solution . Further, , which also has one solution, and so, . When and , the values of the two uniformities are the same, since
and the first claim is shown.
Assume now that . If , then (we use the logical conjunction “” to denote “and”).
Thus, for fixed, we get and so, , since is a permutation. Thus, when ,
If and , then
which is , unless , or , in which case we have
Thus,
if either or . ∎
4 Characterizing -boomerang uniformity via the Walsh transform
Using a method of Carlet [14] and Chabaud and Vaudenay [15] connecting the differential uniformity of an -function to its Walsh coefficients, we characterized the -differential uniformity in [21] and Li et al. [24] characterized the boomerang uniformity. We can use a similar method to do the same for the -boomerang uniformity, in any characteristic.
Theorem 6.
Let and be fixed positive integers. Let be an -function, and be a polynomial over such that for , and , for . We then have
with equality if and only if is -uniform -BCT.
Proof.
We follow mostly [14, 21, 24], pointing out the differences, where applicable. Let be arbitrary elements. We let . From the definition of , for fixed, and for all , then,
with equality if and only if . Consequently, running with all , any -function satisfies
with equality if and only of .
Using the well-known,
| (3) |
we see that
which, when run for all tuples of parameters ( is fixed) renders
By (3), , if and , otherwise; similarly, , if and , otherwise. Therefore,
Surely, if , and the theorem follows. ∎
As a particular case, we want to characterize the -uniform -BCT functions. We can take the polynomial , which certainly satisfies the conditions of Theorem 6. Thus and the relation of Theorem 6 simplifies to
Thus, we obtain the next result.
Proposition 7.
Let be fixed positive integers and , . Let be an -function. Then
with equality if and only if is a -uniform -BCT function.
5 Some needed lemmas
In the next few sections, we will investigate some known perfect nonlinear, as well as the inverse function (in all characteristics) with respect to the -boomerang uniformity. We will need the following two lemmas. The proof of Lemma 8 can be found in [1] and Lemma 8 is easy and argued in [21]. The proof of Lemma 9 is contained in [21].
Lemma 8.
Let be a positive integer. We have:
-
The equation , with , , has two solutions in if , and zero solutions otherwise.
-
The equation , with , odd, has (two, respectively, one) solutions in if and only if the discriminant is a (nonzero, respectively, zero) square in .
Lemma 9.
Let be integers greater than or equal to (we take , though the result can be shown in general). Then
Consequently, if either is odd, or and is even, then and , if .
We will be using throughout Hilbert’s Theorem 90 (see [8]), which states that if is a cyclic Galois extension and is a generator of the Galois group , then for , the relative trace if and only if , for some .
6 Perfect nonlinearity and -boomerang uniformity
The following are some of the known (see, for instance, [18, 20]) classes of PN functions ( must be odd).
Theorem 10.
The following functions are perfect nonlinear:
-
on .
-
on is PN if and only if is odd.
-
is PN over if and only if and is odd.
-
is PN over if and only if or is odd. In general, for , is PN over if is odd.
It is known that the boomerang uniformity equals the differential uniformity for perfect nonlinear functions. It is, of course, a natural question to ask what is the connection between these in the “-context”. The reader is pointed to [21] where we discussed the -differential uniformity of the functions in Theorem 10. We will now concentrate on the -boomerang uniformity of all of these classes (for the last function we will just provide some computational data in the appendix). For , and fixed, we let denote the cardinality
| (4) |
where , under , is the Chebyshev polynomial of the first kind. We will be using below the trivial identity, .
Theorem 11.
Let is an odd prime number be the monomial , and be fixed. The following statements hold:
-
If , then .
-
If , , then
Moreover, when is odd, then , and when is even and , for some , then the -boomerang uniformity of is , where .
-
Let . If and , then , where is defined in (4). In particular, when , then
Proof.
Let and consider the system . We do not care for the cases when . If , dividing by and relabeling, we may assume that . Next, subtracting the first from the second equation, we obtain
which, when replaced back into the first equation, and expanded, renders
which has at most four roots, so . We will see in the appendix that all values occur for the first few cases we considered.
We now consider the Gold case, . The -boomerang system (dividing by and relabeling, we can assume that ) becomes
eliminating and expanding the remaining powers, renders
| (5) |
The idea is to vanish the parenthesis containing , that is, and the polynomial in , namely, , which is equivalent to . By relabeling , the second factor can be put into the form
For more accurate count, we let . We easily infer now that, if , .
Now, to show the second claim of , we want to argue that for some , we can always find some root for in , an odd prime. Let .
We recall here the result from [17, 26] (we simplify some parameters, though). Let in , , and be the relative trace from to . For , we define , . If (note that, if , gives , which was treated earlier), then, for , we let where , for and . The trinomial has no roots in if and only if and . If , then it has a unique root, namely , and, if , it has roots in given by , where , is fixed in with (that is, a -root of ), and, for any with , then .
Since in our case , , and, as we did in [21], if is odd, then has a unique root in , since , independent of . Now, looking at , and by the same argument, it has a unique root, under odd, and so, in this case (we use the prior root , too).
Let be even. We switch the technique now. The equation in already has a root, namely , so we want to show that there are values of , for which has roots. We will, in fact, find many such classes of parameters , below.
We denote by the parity of . Observe that . Since for equation , we need to show that , to be able to use [17]. We compute (using the fact that the parities of , , are , since is even),
Now, let be such that (this always exists since is a multiple of ). Observe (we will be using that later) that and . We now set and so, the previous displayed equation becomes
Therefore, by the result of [17, 26], we infer that the equation has solutions in . Thus, the initial Equation (5) has at least solutions, and so, the -boomerang uniformity in this case (under even) is at least , where .
Let us treat now the case of in , where the system is now (recall that, since , )
We will not use the same method as in [17], or [21] as permutation polynomials are not visibly involved here, rather we will modify the “seed” of the technique. Since , for all , then we can always write and , for some . The system becomes
that is,
which, by expansion, renders
where is the Chebyshev polynomial of the first kind. Adding and subtracting these two equations will give
| (6) |
Thus, . ∎
7 The -boomerang uniformity for the inverse function
We now deal with the binary inverse function.
Theorem 12.
Let be a positive integer, and be the inverse function defined by . If , and if , . If , . Furthermore, (so, the -boomerang uniformity of is ) if and only if any of the conditions happen:
-
and there exists such that and .
-
and there exists such that and .
-
and there exists such that and .
-
(so, ) and there exists such that and .
Proof.
The claim about follows from the computation displayed in the appendix, so we now assume .
By Theorem 3, we need to investigate the system
| (7) |
Observe that if , then the system becomes , rendering , and since , then . Thus, , which also has one solution , independent of , so .
We next assume that . Dividing (7) by and relabeling , and (all are linear equations), we are led to investigate the system
| (8) |
If , the system (8) transforms into . If , then , which renders the non-permissible . Similarly, , , can only happen if (assuming ) and that is not allowed. If none of these values of happen then the system becomes
with solutions , so , hence (which holds for all , using the previous discussion). We next assume that .
Case : , . The system (8) reduces to and . Since , then , which can only happen if , that is, . This equation in has two solutions, say, , if and only if, by Lemma 8, . Thus, in this case, we have a contribution of (the solutions are ) to , respectively, , otherwise there is no contribution.
Case : , . The system (8) reduces to . If , then and must be 1, an impossibility. If , then and , so, , implying , and so, , which is not allowed. Thus, , and so, renders , which has two roots, say , if and only if, by Lemma 8, . Therefore, if , then we have a contribution of to , respectively, (the solutions are ).
Can equal ? If that is so, then , obtaining , but that is impossible since it will not satisfy (similarly for , etc.). Thus, the two contributions from Case and will not overlap.
Case : , . The system (8) reduces to , so . If , then , and (from the second equation), an impossibility. If , then we must have , and two roots exist (), under , by Lemma 8, if and only if (one such does exist even when (so, is even), as then, , which always exists). Under these circumstances, we have a contribution of to , , respectively, .
Can any of , or be equal to , or ?
- •
If , then as above we get that , assuming . If that is so, plugging this value in any of the component equations, renders , an impossibility.
- •
If , similarly, we get that , assuming and . Putting the value of in any of the component equations, gives , which is impossible.
- •
(under ) when plugged into the equation of , gives , a contradiction.
- •
, similarly renders (under ) when put into the equation of , the value , a contradiction.
Case : , . The system (8) reduces to . If , then , and so, , a contradiction. Thus, and , which, when used in the first equation, gives
which renders two solutions, say , if and only if . For such a , we get a contribution of to , respectively, , assuming .
Can (or ) be equal to , , , or ?
- •
If (or ), then they must satisfy both , from which we infer or , an impossibility.
- •
If (or ), then they must satisfy both , implying , which does not satisfy .
- •
If , then they must satisfy both equations , inferring , an impossibility.
- •
If , then (so, ) and . Thus, , which combined with , renders , that is, , an impossibility.
Case . Assuming now that , and multiplying the first equation of (8) by and the second by we obtain the new system
| (9) |
Observe that since, otherwise, (inferred from the first equation), a contradiction. If , then using found from the first equation and replacing it into the second, we get
or
| (10) |
If , we have a contribution of to . If , by Lemma 8, Equation (9) will have two solutions if and only if
| (11) |
Therefore, under the above trace condition on for a fixed , we have a contribution of to .
To avoid speaking about an empty condition, we want to argue next that (11) will happen for a fixed , so it will be sufficient to find a values of where the trace above is 0. If (and so, ), then the trace becomes , which will always happen if the dimension is even, the Equation (10) is then (with two distinct roots), so in this case we have a contribution of to , where satisfies (11), otherwise there is none.
For the remainder of the proof below we assume that is odd. Taking, for example, (for this value, , since otherwise, we would get , so , a contradiction), since the dimension is odd and , the above trace calculation reduces to
which is obviously true, and so there are two roots to the Equation (10).
We need to make sure that the solutions will not satisfy , so we go back (replacing ) to Equation (10), obtaining
If , then , which is not allowed. If , then we get , and so, , which is not allowed. If , then the system (9) becomes
which is impossible since . If , the system is now
which can only happen if , an impossibility.
Putting together the above cases, we see that, if , the only possibility is for at most three solutions of the -boomerang system: we get three solutions if Case 5 is combined with any of the previous 4 cases (for we use to simplify the trace expression), and therefore, the -boomerang uniformity is , but not higher. Our theorem is shown. ∎
Remark 3.
From the previous proof, we do get a lot more information about the Boomerang Connectivity Table for the binary inverse function, but we preferred to simply give just the maximum -BCT entries.
We now treat the case of the inverse for odd characteristic. We let , where is a set with a defined multiplication on it.
Theorem 13.
Let be an odd prime, be a positive integer, and be the inverse -ary function defined by . For any , the -BCT entries . Furthermore,
-
If and , then (e.g., for such , if , then ).
-
If and , then (e.g., for such , if , then ).
Proof.
For , the corresponding system has one solution . We assume now that . Multiplying by and relabeling, the -boomerang system becomes
| (12) |
If , we easily get only one solution, so we may assume below that .
Case . Let . The -boomerang system is , so , and (surely, , since, otherwise, , and so, , an impossibility). Thus, is a solution assuming satisfies . By Lemma 8, a unique exists if and only if the discriminant , that is . Again, from Lemma 8, two solutions (we call these, here and in the next three cases, by the same label, as it will not matter in our argument) exist if and only if , . In either case, there is a contribution of to the respective -BCT entry.
Case . If , the -boomerang system is now , so , which used in the first equation renders , which simplified gives (again, , since otherwise , and so, , an impossibility). By Lemma 8, a unique exists if and only if the discriminant , so , and two solutions exist if and only if , (thus, ). In either case, there is a contribution of to the respective -BCT entry.
Case . Let . The -boomerang system is now . Thus, (if , then , and the second equation gives us, , an impossibility). Using (observe that ) in the second equation we obtain , which has a unique solution if and only if . There are two roots if and only if , or equivalently, .
Case . Let . The -boomerang system becomes . Then (if , then , and using the second equation, we get , that is, , an impossibility), which used in the second equation gives . This equation has a root if and only if , and two roots if and only if , or equivalently, .
We now need to check if overlaps exist among the ’s of various cases, and therefore the contributions to the -BCT entries will be added.
- •
If (or ) equals (or ), then these must satisfy both , , that is, , which when used in the first equation gives . Observe that vanish this expression if and only if . So, we have a contribution of to the respective -BCT entry if and only if (this includes the cases ).
- •
If (or ) equals (or ), then these must satisfy both , , giving , which when used in the first equation implies , an impossibility.
- •
If (or ) equals (or ), then these must satisfy both , , implying that either , or , none of which will work.
- •
If (or ) equals (or ), then these must satisfy both , , which will not work (same argument as in the previous item).
- •
If (or ) equals (or ), then these must satisfy both , , so , which when replaced into the first equation gives , an impossibility.
- •
If (or ) equals (or ), then these must satisfy both , , and so, , which implies .
Observe that other combinations cannot occur above.
Case . Assume now that . Multiplying the first equation by and the second by renders
Solving for in the first equation, we get (observe that ), which used in the second equation gives us the equation
with a unique root if and only if
and two distinct roots if and only if
Putting together our discussion, we see that the largest -BCT entry can only be ; we do get that value if Case 5 is combined with combinations of the other cases -BCT namely, both Case 1 and Case 2, or both Case 3 and Case 4.
The proof of the theorem is done. ∎
Remark 4.
From the previous proof, we do get a lot more information about the -Boomerang Connectivity Table for the -ary inverse function, but, as for the binary case, we preferred to just give the maximum -BCT entries.
8 Concluding remarks
We defined a new concept, we call -boomerang uniformity based upon a previously defined multiplicative differential. We characterized the new concept in terms of the Walsh transforms and investigated the properties of some perfect nonlinear functions, as well as the inverse function in all characteristics via this new concept.
It would certainly be interesting to see how other perfect nonlinear, as well as almost perfect nonlinear functions behave under this new -boomerang uniformity.
References
- [1] E. R. Berlekamp, H. Rumsey, G. Solomon, On the solutions of algebraic equations over finite fields, Information and Control 10 (1967), 553–564.
- [2] E. Biham, O. Dunkelman, N. Keller, New results on boomerang and rectangle attacks, In: Daemen J., Rijmen V. (eds.), Fast Software Encryption, FSE 2002, LNCS 2365, 2002, pp. 1–16, Springer, Berlin, Heidelberg.
- [3] A. Biryukov, D. Khovratovich, Related-key cryptanalysis of the full AES- and AES-, In: Matsui M. (ed.), Advances in Cryptology – ASIACRYPT 2009, LNCS 5912, 2009, pp. 1–18, Springer, Berlin, Heidelberg.
- [4] A.W. Bluher, On , Finite Fields Appl. 10 (3) (2004), 285–305.
- [5] N. Borisov, M. Chew, R. Johnson, D. Wagner, Multiplicative Differentials, In: Daemen J., Rijmen V. (eds.), Fast Software Encryption, FSE 2002, LNCS 2365, pp. 17–33, Springer, Berlin, Heidelberg, 2002.
- [6] C. Boura, A. Canteaut, On the boomerang uniformity of cryptographic Sboxes, IACR Trans. Symmetric Cryptol. 3 (2018), pp. 290-310.
- [7] C. Boura, L. Perrin, S. Tian, Boomerang Uniformity of Popular S-box Constructions, Workshop on Cryptography and Coding, Paper 15, https://www.lebesgue.fr/sites/default/files/proceedings_WCC/WCC_2019_paper_15.pdf.
- [8] N. Bourbaki, Elements of Mathematics, Algebra II (translated by P. M. Cohn and J. Howie), Springer, Berlin, 1990.
- [9] L. Budaghyan, Construction and Analysis of Cryptographic Functions, Springer-Verlag, 2014.
- [10] L. Budaghyan, C. Carlet, Classes of quadratic APN trinomials and hexanomials and related structures, IEEE Trans. Inform.Theory 54:5 (2008), 2354–2357.
- [11] M. Calderini, I.Villa, On the Boomerang Uniformity of some Permutation Polynomials, https://eprint.iacr.org/2019/881.pdf.
- [12] C. Carlet, Boolean functions for cryptography and error correcting codes, In: Y. Crama, P. Hammer (eds.), Boolean Methods and Models, Cambridge Univ. Press, Cambridge, pp. 257–397, 2010.
- [13] C. Carlet, Vectorial Boolean Functions for Cryptography, In: Y. Crama, P. Hammer (eds.), Boolean Methods and Models, Cambridge Univ. Press, Cambridge, pp. 398–472, 2010.
- [14] C. Carlet, Characterizations of the Differential Uniformity of Vectorial Functions by the Walsh Transform, IEEE Trans. Inf. Theory 64:9 (2018), 6443–6453.
- [15] F. Chabaud, S. Vaudenay, Links between differential and linear cryptanalysis, In: A. De Santis (ed.), Adv. in Crypt – EUROCRYPT ’94, LNCS 950, pp. 356–365, 1995, Springer.
- [16] C. Cid, T. Huang, T. Peyrin, Y. Sasaki, L. Song, Boomerang Connectivity Table: A new cryptanalysis tool, In: J. B. Nielsen and V. Rijmen (eds.), Adv. in Crypt. – EUROCRYPT ’18, pp. 683–714, Cham, 2018. Springer.
- [17] R. S. Coulter, M. Henderson, A note on the roots of trinomials over a finite field, Bull. Austral. Math. Soc. 69 (2004), 429–432.
- [18] R. S. Coulter, R. W. Matthews, Planar functions and planes of Lenz-Barlotti class II, Des. Codes Cryptogr. 10 (1997), 167–184.
- [19] T. W. Cusick, P. Stănică, Cryptographic Boolean Functions and Applications (Ed. 2), Academic Press, San Diego, CA, 2017.
- [20] C. Ding, J. Yuan, A new family of skew Paley-Hadamard difference sets, J. Comb. Theory Ser. A 113 (2006), 1526–1535.
- [21] P. Ellingsen, P. Felke, C. Riera P. Stănică, A. Tkachenko, -differentials, multiplicative uniformity and (almost) perfect -nonlinearity, to appear in IEEE Trans. Inf. Theory, 2020, DOI: 10.1109/TIT.2020.2971988.
- [22] J. Kelsey, T. Kohno and B. Schneier, Amplified boomerang attacks against reduced-round MARS and Serpent, In: Goos G., Hartmanis J., van Leeuwen J., Schneier B. (eds,), Fast Software Encryption, FSE 2000. LNCS 1978. Springer, Berlin, Heidelberg.
- [23] J. Kim, S. Hong, B. Preneel, E. Biham, O. Dunkelman, Related-Key Boomerang and Rectangle Attacks: Theory and Experimental Analysis, IEEE Trans. Inf. Theory 58(7) (2012), 4948–4966.
- [24] K. Li, L. Qu, B. Sun, C. Li, New results about the boomerang uniformity of permutation polynomials, IEEE Trans. Inf. Theory 65(11) (2019), 7542–7553.
- [25] N. Li, Z. Hu, M. Xiong, X. Zeng, -uniform BCT permutations from generalized butterfly structure, https://arxiv.org/abs/2001.00464.
- [26] J. Liang, On the solutions of trinomial equations over finite fields, Bull. Cal. Math. Soc. 70 (1978), 379–382.
- [27] S. Mesnager, Bent functions: fundamentals and results, Springer Verlag, 2016.
- [28] S. Mesnager, C. Tang, M. Xiong, On the boomerang uniformity of quadratic permutations, https://eprint.iacr.org/2019/277.pdf.
- [29] C. Riera, P. Stănică, Investigations on -(almost) perfect nonlinear functions, manuscript.
- [30] N. Tokareva, Bent Functions, Results and Applications to Cryptography, Academic Press, San Diego, CA, 2015.
- [31] Z. Tu, N. Li, X. Zeng, J. Zhou, A class of quadrinomial permutation with boomerang uniformity four, to appear in IEEE Trans. Inf. Theory.
- [32] D. Wagner, The boomerang attack, In: L. R. Knudsen (ed.), Fast Software Encryption, FSE ’99, LNCS 1636, pages 156–170, 1999, Springer, Heidelberg.
9 Appendix
We list all the uniformity values for the considered functions in the paper, for , and some values of the parameter , if involved, computed via SageMath. Below, denotes a primitive root in the respective field. For , to construct , , we take the primitive polynomials, , respectively. If , to construct , , we take the primitive polynomials, , respectively. If , to construct , , we take the primitive polynomials, .
We will only mention the nonzero entries (surely, for some parameters, , , but we are not concerned with that). First, if , the possible -BCT entries )for , , are for , respectively, for .
Table 2: Possible -BCT entries for the inverse , , , possible values of 2 2 3 4 3 2 3 4
Table 4: Possible -BCT entries for the Gold , , , possible values of 1 2 3 4 2 2 3 4 3 2 3 4
Table 6: Possible -BCT entries for , , , possible values of 1 2 3 4 2 2 3 4 3 2 3 4
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on (the complexity of this computation is about , and if we were to go up to , it would be operations, so we stopped at ). We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . We list all values of , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur):
Let on . There are pairs , for which the -DDT entry (for some ) equals the -boomerang uniformity of (all -BCT entries of occur). We shall list here only the different values of :