arXiv is now an independent nonprofit! Learn more
License: arXiv.org perpetual non-exclusive license
arXiv:2004.11859v1 [cs.IT] 24 Apr 2020

Investigations on cc-Boomerang Uniformity and Perfect Nonlinearity

Pantelimon Stănică Affiliation: Applied Mathematics Department, Affiliation: Naval Postgraduate School, Monterey, USA. Affiliation: E-mail: pstanica@nps.edu
Abstract

We defined in [21] a new multiplicative cc-differential, and the corresponding cc-differential uniformity and we characterized the known perfect nonlinear functions with respect to this new concept, as well as the inverse in any characteristic. The work was continued in [29], investigating the cc-differential uniformity for some further APN functions. Here, we extend the concept to the boomerang uniformity, introduced at Eurocrypt ’18 by Cid et al. [16], to evaluate S-boxes of block ciphers, and investigate it in the context of perfect nonlinearity and related functions.

Keywords: Boolean, pp-ary functions, cc-differentials, differential uniformity, boomerang uniformity, perfect and almost perfect cc-nonlinearity
MSC 2000: 06E30, 11T06, 94A60, 94C10.

1 Introduction

In this paper we extend the notion of boomerang uniformity using a previously defined [21] multiplier differential (in any characteristic). We characterize some of the known perfect nonlinear functions and the inverse function through this new concept. We also characterize this concept via the Walsh transforms as Lie et al. [24] did for the classical boomerang uniformity.

The objects of this study are Boolean and pp-ary functions (where pp is an odd prime) and some of their differential properties. We will introduce here only some needed notation, and the reader can consult [9, 12, 13, 19, 27, 30] for more on Boolean and pp-ary functions.

For a positive integer nn and pp a prime number, we let 𝔽pn{\mathbb{F}}_{p^{n}} be the finite field with pnp^{n} elements, and 𝔽pn=𝔽pn{0}{\mathbb{F}}_{p^{n}}^{*}={\mathbb{F}}_{p^{n}}\setminus\{0\} be the multiplicative group (for a0a\neq 0, we often write 1a\frac{1}{a} to mean the inverse of aa in the multiplicative group). We let 𝔽pn{\mathbb{F}}_{p}^{n} be the nn-dimensional vector space over 𝔽p{\mathbb{F}}_{p}. We use #S\#S to denote the cardinality of a set SS and z¯\bar{z}, for the complex conjugate. We call a function from 𝔽pn{\mathbb{F}}_{p^{n}} (or 𝔽pn{\mathbb{F}}_{p}^{n}) to 𝔽p{\mathbb{F}}_{p} a pp-ary function on nn variables. For positive integers nn and mm, any map F:𝔽pn𝔽pmF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{m}} (or, 𝔽pn𝔽pm{\mathbb{F}}_{p}^{n}\to{\mathbb{F}}_{p}^{m}) is called a vectorial pp-ary function, or (n,m)(n,m)-function. When m=nm=n, FF can be uniquely represented as a univariate polynomial over 𝔽pn{\mathbb{F}}_{p^{n}} (using some identification, via a basis, of the finite field with the vector space) of the form F(x)=i=0pn1aixi,ai𝔽pn,F(x)=\sum_{i=0}^{p^{n}-1}a_{i}x^{i},\ a_{i}\in{\mathbb{F}}_{p^{n}}, whose algebraic degree is then the largest Hamming weight of the exponents ii with ai0a_{i}\neq 0. For f:𝔽pn𝔽pf:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p} we define the Walsh-Hadamard transform to be the integer-valued function 𝒲f(u)=x𝔽pnζpf(x)Trn(ux),u𝔽pn,\displaystyle\mathcal{W}_{f}(u)=\sum_{x\in{\mathbb{F}}_{p^{n}}}\zeta_{p}^{f(x)-{\rm Tr}_{n}(ux)},\ u\in\mathbb{F}_{p^{n}}, where ζp=e2πip\zeta_{p}=e^{\frac{2\pi i}{p}} and Trn:𝔽pn𝔽p{\rm Tr}_{n}:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p} is the absolute trace function, given by Trn(x)=i=0n1xpi\displaystyle{\rm Tr}_{n}(x)=\sum_{i=0}^{n-1}x^{p^{i}} (we will denote it by Tr{\rm Tr}, if the dimension is clear from the context). The Walsh transform 𝒲F(a,b)\mathcal{W}_{F}(a,b) of an (n,m)(n,m)-function FF at a𝔽pn,b𝔽pma\in{\mathbb{F}}_{p^{n}},b\in{\mathbb{F}}_{p^{m}} is the Walsh-Hadamard transform of its component function Trm(bF(x)){\rm Tr}_{m}(bF(x)) at aa, that is,

𝒲F(a,b)=x𝔽pnζpTrm(bF(x))Trn(ax).\mathcal{W}_{F}(a,b)=\sum_{x\in{\mathbb{F}}_{p^{n}}}\zeta_{p}^{{\rm Tr}_{m}(bF(x))-{\rm Tr}_{n}(ax)}.

(If one wishes to work with vector spaces, then one can replace the Tr{\rm Tr} by any scalar product on that environment.)

Given a pp-ary function ff, the derivative of ff with respect to a𝔽pna\in{\mathbb{F}}_{p^{n}} is the pp-ary function Daf(x)=f(x+a)f(x), for all x𝔽pn,D_{a}f(x)=f(x+a)-f(x),\mbox{ for all }x\in{\mathbb{F}}_{p^{n}}, which can be naturally extended to vectorial pp-ary functions.

For an (n,n)(n,n)-function FF, and a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, we let ΔF(a,b)=#{x𝔽pn:F(x+a)F(x)=b}\Delta_{F}(a,b)=\#\{x\in{\mathbb{F}}_{p^{n}}:F(x+a)-F(x)=b\}. We call the quantity δF=max{ΔF(a,b):a,b𝔽pn,a0}\delta_{F}=\max\{\Delta_{F}(a,b)\,:\,a,b\in{\mathbb{F}}_{p^{n}},a\neq 0\} the differential uniformity of FF. If δF=δ\delta_{F}=\delta, then we say that FF is differentially δ\delta-uniform. If δ=1\delta=1, then FF is called a perfect nonlinear (PN) function, or planar function. If δ=2\delta=2, then FF is called an almost perfect nonlinear (APN) function. It is well known that PN functions do not exist if p=2p=2.

The paper is organized as follows. Section 2 contains some background on differential and boomerang uniformity and our extension to cc-boomerang uniformity. Section 3 contains some characterizations of this concept and connections with prior cc-differential uniformity, and Section 4 gives its description via Walsh transforms. Section 5 puts together two lemmas needed in the remaining of the paper, and Section 6 deals with perfect nonlinearity and cc-boomerang uniformity. Section 7 characterizes this uniformity for the inverse function in any characteristic and Section 8 concludes the paper. An appendix with some computational data follows the references.

2 Differential and boomerang uniformity

Wagner [32] introduced the boomerang attack against block ciphers using SS-boxes. The concept was picked up and used in [3, 22] on some real ciphers (see also [2, 23]). Ten years later, however, a theoretical new cryptanalysis tool based upon this attack was introduced at EUROCRYPT 2018 by Cid et al. [16] namely, the Boomerang Connectivity Table (BCT) and Boomerang Uniformity. In [16], the authors analyzed some of the properties of BCT, like its relationship with the Differential Distribution Table (DDT). They proved that perfect nonlinear (APN) S-boxes (that is, with 2-uniform DDT) always have 2-uniform BCT and for any choice of the parameters, and also showed that the BCT uniformity is greater than or equal to the DDT uniformity (we will display below precisely the relationship between these).

The initial concept of boomerang uniformity was defined for permutations (of course, proper SS-boxes) in the following way.

Definition 1.

Let FF be a permutation on 𝔽2n{\mathbb{F}}_{2^{n}} and (a,b)𝔽2n×𝔽2n(a,b)\in{\mathbb{F}}_{2^{n}}\times{\mathbb{F}}_{2^{n}}. We define the entries of the Boomerang Connectivity Table (BCT) by

F(a,b)=#{x𝔽2n|F1(F(x)+b)+F1(F(x+a)+b)=a},{\mathcal{B}}_{F}(a,b)=\#\{x\in{\mathbb{F}}_{2^{n}}|F^{-1}(F(x)+b)+F^{-1}(F(x+a)+b)=a\},

where F1F^{-1} is the compositional inverse of FF. The boomerang uniformity of FF is defined as

βF=maxa,b𝔽pnF(a,b).\beta_{F}=\max_{a,b\in{\mathbb{F}_{p^{n}}}*}{\mathcal{B}}_{F}(a,b).

We also say that FF is a βF\beta_{F}-uniform BCT function.

Recently, BCT and the boomerang uniformity were further studied by Boura and Canteaut [6]. They showed that the boomerang uniformity is only an affine equivalence invariant but not necessarily, extended affine nor CCZ-equivalence invariant. Further, they also obtained the boomerang uniformity of the inverse function F(x)=x2n2F(x)=x^{2^{n}-2} over 𝔽2n{\mathbb{F}}_{2^{n}}, for nn even, namely, βF=4,6\beta_{F}=4,6, when n2(mod4)n\equiv 2\pmod{4}, respectively, n0(mod4)n\equiv 0\pmod{4}. Also, for the Gold function G(x)=x2t+1G(x)=x^{2^{t}+1} over 𝔽2n{\mathbb{F}}_{2^{n}}, where n2(mod4)n\equiv 2\pmod{4}, tt even with gcd(t,n)=2\gcd(t,n)=2, then δG=βG=4\delta_{G}=\beta_{G}=4.

Mesnager et al. [28] continued the work and showed that the differential uniformity for quadratic functions on 𝔽qn{\mathbb{F}}_{q^{n}} (qq is a 22-power) is always q\geq q, and if it happens to be equal to qq for a permutations FF then its boomerang uniformity must be qq, as well. In fact [24], in general, for quadratic permutations FF, then we have,

δFβFδF(δF1).\delta_{F}\leq\beta_{F}\leq\delta_{F}(\delta_{F}-1).

It is also easy to show that for monomials F(x)=xdF(x)=x^{d}, then βF=maxb0βF(1,b)\displaystyle\beta_{F}=\max_{b\neq 0}\beta_{F}(1,b). For the Bracken-Tan-Tan function (which is an extension of Budaghyan-Carlet function [10]), F(x)=αx2s+1+α2kx2k+2k+sF(x)=\alpha x^{2^{s}+1}+\alpha^{2^{k}}x^{2^{-k}+2^{k+s}} (under some conditions on the parameters), then βF=4\beta_{F}=4 (see [28]). More work has been done recently on BCT, and we mention here [7, 11, 25, 31].

Surely, ΔF(a,b)=0,2n\Delta_{F}(a,b)=0,2^{n} and F(a,b)=2n{\mathcal{B}}_{F}(a,b)=2^{n} whenever ab=0ab=0. It is well-known from prior work that δF=δF1\delta_{F}=\delta_{F^{-1}} and βF=βF1\beta_{F}=\beta_{F^{-1}}. In general, for permutations, βFδF\beta_{F}\geq\delta_{F} and they are equal for APN permutations. A natural question is what is the algebraic difference between these two concepts and Boura and Canteaut answered that question in [6], showing that

F(a,b)=ΔF(a,b)+γ𝔽pn,γb#(𝒰γ,aF1(b+𝒰γ,aF1)),{\mathcal{B}}_{F}(a,b)=\Delta_{F}(a,b)+\sum_{\gamma\in{\mathbb{F}_{p^{n}}}^{*},\gamma\neq b}\#\left({\mathcal{U}}_{\gamma,a}^{F^{-1}}\cap\left(b+{\mathcal{U}}_{\gamma,a}^{F^{-1}}\right)\right),

where 𝒰γ,aF1={x𝔽pn|DγF1(x)=a}{\mathcal{U}}_{\gamma,a}^{F^{-1}}=\{x\in{\mathbb{F}_{p^{n}}}|D_{\gamma}F^{-1}(x)=a\}. This was reformulated by Mesnager et al. [28] in the following way:

F(a,b)=γ𝔽pn#(𝒰γ,aF(b+𝒰γ,aF)),{\mathcal{B}}_{F}(a,b)=\sum_{\gamma\in{\mathbb{F}_{p^{n}}}^{*}}\#\left({\mathcal{U}}_{\gamma,a}^{F}\cap\left(b+{\mathcal{U}}_{\gamma,a}^{F}\right)\right),

where 𝒰γ,aF={x𝔽pn|DγF(x)=a}{\mathcal{U}}_{\gamma,a}^{F}=\{x\in{\mathbb{F}_{p^{n}}}|D_{\gamma}F(x)=a\}, and further, by Li et al. [24], as

F(a,b)=#{(x,y)𝔽pn×𝔽pn|F(x)+F(y)=bF(x+a)+F(y+a)=b}{\mathcal{B}}_{F}(a,b)=\#\left\{(x,y)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Large\big|\,\begin{subarray}{c}F(x)+F(y)=b\\ F(x+a)+F(y+a)=b\end{subarray}\right\}

and easily observed in [28] that this transforms into (labeling y=x+γy=x+\gamma),

F(a,b)=#{(x,γ)𝔽pn×𝔽pn|F(x+γ)+F(x)=bF(x+γ+a)+F(x+a)=b}=γ𝔽pn#{x𝔽pn|DγF(x)=b and DγF(x+a)=b}.\begin{split}{\mathcal{B}}_{F}(a,b)&=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Large\big|\,\begin{subarray}{c}F(x+\gamma)+F(x)=b\\ F(x+\gamma+a)+F(x+a)=b\end{subarray}\right\}\\ &=\sum_{\gamma\in{\mathbb{F}_{p^{n}}}}\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\big|\,D_{\gamma}F(x)=b\text{ and }D_{\gamma}F(x+a)=b\right\}.\end{split} (1)

Avoiding the inverse of FF, allows these last expressions to define the boomerang uniformity for functions that are not necessarily permutations.

Before, we continue with our approach, let us recall the concept we (along with others) introduced in [21] (we will define it in general on 𝔽pn{\mathbb{F}}_{p^{n}}, pp prime, not only for p=2p=2).

Inspired by a practical differential attack developed in [5] (though, via a different differential), we extended the definition of derivative and differential uniformity in  [21], in the following way. For a pp-ary (n,m)(n,m)-function F:𝔽pn𝔽pmF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{m}}, and c𝔽pmc\in{\mathbb{F}}_{p^{m}}, the (multiplicative) cc-derivative of FF with respect to a𝔽pna\in{\mathbb{F}}_{p^{n}} is the function

DacF(x)=F(x+a)cF(x), for all x𝔽pn.{}_{c}D_{a}F(x)=F(x+a)-cF(x),\mbox{ for all }x\in{\mathbb{F}}_{p^{n}}.

(Observe that, if c=1c=1, then we obtain the usual derivative, and, if c=0c=0 or a=0a=0, then we obtain a shift of the function, in the input/output.)

For an (n,n)(n,n)-function FF, and a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, we let the entries of the cc-Difference Distribution Table (cc-DDT) be defined by ΔFc(a,b)=#{x𝔽pn:F(x+a)cF(x)=b}{{}_{c}\Delta}_{F}(a,b)=\#\{x\in{\mathbb{F}}_{p^{n}}:F(x+a)-cF(x)=b\}. We call the quantity

δF,c=max{ΔFc(a,b)|a,b𝔽pn, and a0 if c=1}\delta_{F,c}=\max\left\{{{}_{c}\Delta}_{F}(a,b)\,|\,a,b\in{\mathbb{F}}_{p^{n}},\text{ and }a\neq 0\text{ if $c=1$}\right\}

the cc-differential uniformity of FF (observe that we slightly change here the way we denoted the cc-differential uniformity in [21]). If δF,c=δ\delta_{F,c}=\delta, then we say that FF is differentially (c,δ)(c,\delta)-uniform (or that FF has cc-uniformity δ\delta, or for short, FF is δ\delta-uniform cc-DDT). If δ=1\delta=1, then FF is called a perfect cc-nonlinear (PcN) function (certainly, for c=1c=1, they only exist for odd characteristic pp; however, as proven in [21], there exist PcN functions for p=2p=2, for all c1c\neq 1). If δ=2\delta=2, then FF is called an almost perfect cc-nonlinear (APcN) function. When we need to specify the constant cc for which the function is PcN or APcN, then we may use the notation cc-PN, or cc-APN. It is easy to see that if FF is an (n,n)(n,n)-function, that is, F:𝔽pn𝔽pnF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{n}}, then FF is PcN if and only if DacF{}_{c}D_{a}F is a permutation polynomial.

Figure 1: View on the cc-boomerang uniformity

In light of the formulations (1) via differentials, by using our cc-differential concept of [21], we extend the notion of boomerang uniformity to cc-boomerang uniformity for all characteristics, in the following way (see Figure 1).

Definition 2.

For an (n,n)(n,n)-function FF, c0c\neq 0, and (a,b)𝔽pn×𝔽pn(a,b)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}, we define the cc-Boomerang Connectivity Table (cc-BCT) entry at (a,b)(a,b) to be

cF(a,b)=#{x𝔽pn|F1(c1F(x+a)+b)F1(cF(x)+b)=a}._{c}{\mathcal{B}}_{F}(a,b)=\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\Big|\,F^{-1}(c^{-1}F(x+a)+b)-F^{-1}(cF(x)+b)=a\right\}. (2)

Further, the cc-boomerang uniformity of FF is defined by

βF,c=maxa,b𝔽pnFc(a,b).\beta_{F,c}=\max_{a,b\in{\mathbb{F}_{p^{n}}}*}{{}_{c}}{\mathcal{B}}_{F}(a,b).

If βF,c=β\beta_{F,c}=\beta, we also say that FF is a β\beta-uniform cc-BCT function.

3 Characterizations of cc-boomerang uniformity

As in the classical case, we find an alternative formulation that avoids inverses, allowing the definition to be extended to all (n,n)(n,n)-function, not only permutations. Though the proof is not complicated, we label as a theorem, since it is the way to extend the definition to non-permutations.

Theorem 3.

For an (n,n)(n,n)-permutation function FF, c0c\neq 0, the entries of the cc-Boomerang Connectivity Table at (a,b)𝔽pn×𝔽pn(a,b)\in{\mathbb{F}}_{p^{n}}\times{\mathbb{F}}_{p^{n}} are given by

Fc(a,b){}_{c}{\mathcal{B}}_{F}(a,b) =#{(x,γ)𝔽pn×𝔽pn|F(x+γ)cF(x)=bF(x+γ+a)c1F(x+a)=b}\displaystyle=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Big|\,\Large\begin{subarray}{c}F(x+\gamma)-cF(x)=b\\ F(x+\gamma+a)-c^{-1}F(x+a)=b\end{subarray}\right\}
=γ𝔽pn#{x𝔽pn|cDγF(x)=b and c1DγF(x+a)=b}.\displaystyle=\sum_{\gamma\in{\mathbb{F}_{p^{n}}}}\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\big|\,_{c}D_{\gamma}F(x)=b\text{ and }_{c^{-1}}D_{\gamma}F(x+a)=b\right\}.

(We shall call the system above, the cc-boomerang system, for easy referral.)

Proof.

Let y=F1(cF(x)+b)y=F^{-1}(cF(x)+b) in (2). If that is the case, then F(y)cF(x)=bF(y)-cF(x)=b. Further, from (2), we obtain,

F1(c1F(x+a)+b)=y+a,F^{-1}(c^{-1}F(x+a)+b)=y+a,

and so,

c1F(x+a)+b=F(y+a)F(y+a)c1F(x+a)=b.c^{-1}F(x+a)+b=F(y+a)\ \Longleftrightarrow\ F(y+a)-c^{-1}F(x+a)=b.

The reciprocal is immediate by backtracking the argument: the second equation in the system implies F(y+a)=c1F(x+a)+bF(y+a)=c^{-1}F(x+a)+b and applying F1F^{-1}, we get F1(c1F(x+a)+b)=y+a=F1(F(y))+a=F1(cF(x)+b)+aF^{-1}(c^{-1}F(x+a)+b)=y+a=F^{-1}(F(y))+a=F^{-1}(cF(x)+b)+a, using the first equation. Finally, taking y=x+γy=x+\gamma, the theorem follows. ∎

Remark 1.

We could have defined the BCT entries of FF at (a,b)(a,b) to be

Fc(a,b)=#{(x,γ)𝔽pn×𝔽pn|F(x+γ)cF(x)=bcF(x+γ+a)F(x+a)=cb},{{}_{c}}{\mathcal{B}}_{F}(a,b)=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Big|\,\Large\begin{subarray}{c}F(x+\gamma)-cF(x)=b\\ cF(x+\gamma+a)-F(x+a)=cb\end{subarray}\right\},

thus allowing c=0c=0. However, in the case of c=0c=0, we would obtain F0(a,b)=#{(x,γ)𝔽pn×𝔽pn|F(x+γ)=b and F(x+a)=0}{{}_{0}}{\mathcal{B}}_{F}(a,b)=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\big|\,F(x+\gamma)=b\text{ and }F(x+a)=0\right\}; when FF is a permutation, we get x=F1(0)ax=F^{-1}(0)-a and γ=F1(b)F1(0)+a\gamma=F^{-1}(b)-F^{-1}(0)+a, rendering βF,0=1\beta_{F,0}=1, regardless of the function. For this reason, we decided to remove c=0c=0 out of allowable multipliers.

Remark 2.

For whatever reason, one can define the cc-DDT and cc-BCT, and the respective uniformities, even for arbitrary (n,m)(n,m)-functions. That is the reason why in some of our results, when it makes no difference for the proofs (except tracking carefully the parameters, of course), we take arbitrary (n,m)(n,m)-functions.

While we already knew that, in general, the cc-differential uniformity of F,F1F,F^{-1} are not the same, we show below a connection (that we did not observe in [21]) between some of the entries in the cc-Differential Distribution Table of a permutation monomial FF and the one of the inverse of FF.

Proposition 4.

Let F(x)=xdF(x)=x^{d} be a permutation ((hence, gcd(d,pn1)=1\gcd(d,p^{n}-1)=1)) monomial function on 𝔽pn{\mathbb{F}_{p^{n}}} and c0c\neq 0. Then,

ΔF1c(a,b)=ΔFcd(bc1,acd).{{}_{c}}\Delta_{F^{-1}}(a,b)={{}_{c^{-d}}}\Delta_{F}(bc^{-1},-a\,c^{-d}).
Proof.

Observe that, in general (assuming c0c\neq 0),

F1(x+a)cF1(x)=b\displaystyle F^{-1}(x+a)-cF^{-1}(x)=b\Longleftrightarrow
F(F1(x+a))=F(cF1(x)+b)\displaystyle F(F^{-1}(x+a))=F(cF^{-1}(x)+b)\Longleftrightarrow
F(cF1(x)+b)x=a\displaystyle F(cF^{-1}(x)+b)-x=a\Longleftrightarrow
F(F1(x))F(cF1(x)+b)=a.\displaystyle F(F^{-1}(x))-F(cF^{-1}(x)+b)=a.

If FF is the monomial xdx^{d}, then the last equation above becomes

F(F1(x))cdF(F1(x)+bc1)=a\displaystyle F(F^{-1}(x))-c^{d}F(F^{-1}(x)+bc^{-1})=a\Longleftrightarrow
F(F1(x)+bc1)cdF(F1(x))=acd,\displaystyle F(F^{-1}(x)+bc^{-1})-c^{-d}F(F^{-1}(x))=-ac^{-d},

and the proposition will follow easily. ∎

We next show a connection between cc-differential and cc-boomerang uniformities.

Theorem 5.

Let FF be a permutation function on 𝔽pn{\mathbb{F}_{p^{n}}}, (a,b)𝔽pn×𝔽pn(a,b)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}} and c0,1c\neq 0,1. Then Fc(0,b)=ΔFc(0,b){{}_{c}}{\mathcal{B}}_{F}(0,b)={{{}_{c}\Delta}}_{F}(0,b). If p=2p=2, then

Fc(a,b)\displaystyle{{}_{c}}{\mathcal{B}}_{F}(a,b) =ΔFc(a,b)+aγ𝔽pn#{x𝔽pn|DγcF(x)=bDγc1F(x+a)=b},\displaystyle={{}_{c}}\Delta_{F}(a,b)+\sum_{a\neq\gamma\in{\mathbb{F}_{p^{n}}}}\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\big|\,\begin{subarray}{c}{}_{c}D_{\gamma}F(x)=b\\ {{}_{c^{-1}}}D_{\gamma}F(x+a)=b\end{subarray}\right\},

if either c=1c=-1 or b=0b=0. Consequently, βF,1δF,1\beta_{F,-1}\geq\delta_{F,-1}, for all permutations FF (it is known [6] that βF,1δF,1\beta_{F,1}\geq\delta_{F,1}).

Proof.

If a=0a=0 and c0,±1c\neq 0,\pm 1, then

Fc(0,b){}_{c}{\mathcal{B}}_{F}(0,b) =#{(x,γ)𝔽pn×𝔽pn|F(x+γ)cF(x)=bF(x+γ)c1F(x)=b},\displaystyle=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Big|\,\Large\begin{subarray}{c}F(x+\gamma)-cF(x)=b\\ F(x+\gamma)-c^{-1}F(x)=b\end{subarray}\right\},

and so, F(x)=0F(x)=0 and F(x+γ)=bF(x+\gamma)=b, which has only one solution (x,γ)=(F1(0),F1(b)F1(0))(x,\gamma)=(F^{-1}(0),F^{-1}(b)-F^{-1}(0)). Further, ΔFc(0,b)=#{x𝔽pn|DγcF(x)=F(x)cF(x)=b}{{{}_{c}\Delta}}_{F}(0,b)=\#\{x\in{\mathbb{F}_{p^{n}}}\,|\,{{}_{c}}D_{\gamma}F(x)=F(x)-cF(x)=b\}, which also has one solution, and so, Fc(0,b)=ΔFc(0,b){{}_{c}}{\mathcal{B}}_{F}(0,b)={{{}_{c}\Delta}}_{F}(0,b). When a=0a=0 and c=1c=-1, the values of the two uniformities are the same, since

F1(0,b)\displaystyle{{}_{-1}}{\mathcal{B}}_{F}(0,b) =#{(x,γ)𝔽pn×𝔽pn|F(x+γ)+F(x)=bF(x+γ)+F(x)=b}\displaystyle=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Big|\,\Large\begin{subarray}{c}F(x+\gamma)+F(x)=b\\ F(x+\gamma)+F(x)=b\end{subarray}\right\}
=#{(x,γ)𝔽pn×𝔽pn|F(x+γ)+F(x)=b}=ΔF1(0,b),\displaystyle=\#\left\{(x,\gamma)\in{\mathbb{F}_{p^{n}}}\times{\mathbb{F}_{p^{n}}}\,\Big|\,F(x+\gamma)+F(x)=b\right\}={{}_{-1}}\Delta_{F}(0,b),

and the first claim is shown.

Assume now that a0a\neq 0. If γ=0\gamma=0, then (we use the logical conjunction “\wedge” to denote “and”).

{x𝔽pn|F(x)cF(x)=bF(x+a)c1F(x+a)=b}\displaystyle\left\{x\in{\mathbb{F}_{p^{n}}}\,\Big|\,F(x)-cF(x)=b\wedge F(x+a)-c^{-1}F(x+a)=b\right\}
=\displaystyle= {x𝔽pn|F(x)=b1cF(x+a)=b1c1}.\displaystyle\left\{x\in{\mathbb{F}_{p^{n}}}\,\big|\,F(x)=\frac{b}{1-c}\wedge F(x+a)=\frac{b}{1-c^{-1}}\right\}.

Thus, for cc fixed, we get x=F1(b1c)x=F^{-1}\left(\frac{b}{1-c}\right) and so, a=F1(b1c1)F1(b1c)a=F^{-1}\left(\frac{b}{1-c^{-1}}\right)-F^{-1}\left(\frac{b}{1-c}\right), since FF is a permutation. Thus, when γ=0\gamma=0,

#{x𝔽pn|F(x)cF(x)=bF(x+a)c1F(x+a)=b}={1 if a=F1(b1c1)F1(b1c)0 otherwise.\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\Big|\,\Large\begin{subarray}{c}F(x)-cF(x)=b\\ F(x+a)-c^{-1}F(x+a)=b\end{subarray}\right\}=\begin{cases}1&\text{ if }a=F^{-1}\left(\frac{b}{1-c^{-1}}\right)-F^{-1}\left(\frac{b}{1-c}\right)\\ 0&\text{ otherwise}.\end{cases}

If γ=a\gamma=a and p=2p=2, then

{x𝔽pn|F(x+a)cF(x)=bF(x)c1F(x+a)=b}={x𝔽pn|F(x+a)cF(x)=bF(x+a)cF(x)=bc},\displaystyle\left\{x\in{\mathbb{F}_{p^{n}}}\,\Large\big|\,\begin{subarray}{c}F(x+a)-cF(x)=b\\ F(x)-c^{-1}F(x+a)=b\end{subarray}\right\}=\left\{x\in{\mathbb{F}_{p^{n}}}\,\Large\big|\,\begin{subarray}{c}F(x+a)-cF(x)=b\\ F(x+a)-cF(x)=-bc\end{subarray}\right\},

which is \emptyset, unless b=0b=0, or c=1c=-1, in which case we have

#{x𝔽pn|F(x+a)cF(x)=b}=ΔFc(a,b),\displaystyle\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\large\big|\,F(x+a)-cF(x)=b\right\}={{}_{c}}\Delta_{F}(a,b),

Thus,

Fc(a,b)\displaystyle{{}_{c}}{\mathcal{B}}_{F}(a,b) =ΔFc(a,b)+aγ𝔽pn#{x𝔽pn|DγcF(x)=bDγc1F(x+a)=b},\displaystyle={{}_{c}}\Delta_{F}(a,b)+\sum_{a\neq\gamma\in{\mathbb{F}_{p^{n}}}}\#\left\{x\in{\mathbb{F}_{p^{n}}}\,\big|\,\begin{subarray}{c}{}_{c}D_{\gamma}F(x)=b\\ {}_{c^{-1}}D_{\gamma}F(x+a)=b\end{subarray}\right\},

if either c=1c=-1 or b=0b=0. ∎

4 Characterizing cc-boomerang uniformity via the Walsh transform

Using a method of Carlet [14] and Chabaud and Vaudenay [15] connecting the differential uniformity of an (n,m)(n,m)-function to its Walsh coefficients, we characterized the cc-differential uniformity in [21] and Li et al. [24] characterized the boomerang uniformity. We can use a similar method to do the same for the cc-boomerang uniformity, in any characteristic.

Theorem 6.

Let c𝔽pmc\in{\mathbb{F}}_{p^{m}}^{*} and n,m,δn,m,\delta be fixed positive integers. Let FF be an (n,m)(n,m)-function, F:𝔽pn𝔽pmF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{m}} and ϕβ(x)=j0Ajxj\phi_{\beta}(x)=\sum_{j\geq 0}A_{j}x^{j} be a polynomial over \mathbb{R} such that ϕβ(x)=0\phi_{\beta}(x)=0 for x,1xβx\in\mathbb{Z},1\leq x\leq\beta, and ϕβ(x)>0\phi_{\beta}(x)>0, for x,x>βx\in\mathbb{Z},x>\beta. We then have

pm+nA0+\displaystyle p^{m+n}A_{0}+ j1p(2j1)(m+n)Ajw1,,wj𝔽pnz1,,zj𝔽pnu1,,uj𝔽pmv1,,vj𝔽pmi=1j(wi+zi)=0i=1j(ui+vi)=0\displaystyle\sum_{j\geq 1}p^{-(2j-1)(m+n)}A_{j}\sum_{\begin{subarray}{c}w_{1},\ldots,w_{j}\in{\mathbb{F}}_{p^{n}}\\ z_{1},\ldots,z_{j}\in{\mathbb{F}}_{p^{n}}\\ u_{1},\ldots,u_{j}\in{\mathbb{F}}_{p^{m}}\\ v_{1},\ldots,v_{j}\in{\mathbb{F}}_{p^{m}}\\ \sum_{i=1}^{j}(w_{i}+z_{i})=0\\ \sum_{i=1}^{j}(u_{i}+v_{i})=0\end{subarray}}
i=1j(𝒲F(ui,zi)𝒲F¯(cui,wi)𝒲F(vi,zi)𝒲F¯(c1vi,wi))0,\displaystyle\qquad\prod_{i=1}^{j}\left({\mathcal{W}}_{F}(u_{i},z_{i})\overline{{\mathcal{W}}_{F}}(cu_{i},-w_{i}){\mathcal{W}}_{F}(v_{i},-z_{i})\overline{{\mathcal{W}}_{F}}(c^{-1}v_{i},w_{i})\right)\geq 0,

with equality if and only if FF is β\beta-uniform cc-BCT.

Proof.

We follow mostly [14, 21, 24], pointing out the differences, where applicable. Let a𝔽pn,d𝔽pma\in{\mathbb{F}}_{p^{n}},d\in{\mathbb{F}}_{p^{m}} be arbitrary elements. We let nF(a,b,c)=#{(x,γ)𝔽pn×𝔽pn|cDγF(x)=DγcF(b),Dγc1F(x+a)=DγcF(b)}=#{(x,y)𝔽pn×𝔽pn|F(y)cF(x)=b,F(y+a)c1F(x+a)=b}0n_{F}(a,b,c)=\#\{(x,\gamma)\in{\mathbb{F}}_{p^{n}}\times{\mathbb{F}}_{p^{n}}\,|\,_{c}D_{\gamma}F(x)={{}_{c}}D_{\gamma}F(b),{{}_{c^{-1}}}D_{\gamma}F(x+a)={{}_{c}}D_{\gamma}F(b)\}=\#\{(x,y)\in{\mathbb{F}}_{p^{n}}\times{\mathbb{F}}_{p^{n}}\,|\,F(y)-cF(x)=b,F(y+a)-c^{-1}F(x+a)=b\}\geq 0. From the definition of ϕβ\phi_{\beta}, for cc fixed, and for all a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, then,

j0Aj(nF(a,b,c))j0,\displaystyle\sum_{j\geq 0}A_{j}\left(n_{F}(a,b,c)\right)^{j}\geq 0,

with equality if and only if Fc(a,b)=β{}_{c}{\mathcal{B}}_{F}(a,b)=\beta. Consequently, running with all a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, any (n,m)(n,m)-function FF satisfies

j0Aja,b𝔽pn(nF(a,b,c))j0,\sum_{j\geq 0}A_{j}\sum_{a,b\in{\mathbb{F}}_{p^{n}}}\left(n_{F}(a,b,c)\right)^{j}\geq 0,

with equality if and only of βF,c=β\beta_{F,c}=\beta.

Using the well-known,

v𝔽pmζpTrm(vα)={0 if α0pm if α=0,\displaystyle\sum_{v\in{\mathbb{F}}_{p^{m}}}\zeta_{p}^{{\rm Tr}_{m}(v\alpha)}=\begin{cases}0&\text{ if }\alpha\neq 0\\ p^{m}&\text{ if }\alpha=0,\end{cases} (3)

we see that

nF(a,b,c)=p2mx,yFpn,u,vFpmζpTrm(u(F(y)cF(x)b))+Trm(v(F(y+a)c1F(x+a)b)),\displaystyle n_{F}(a,b,c)=p^{-2m}\sum_{x,y\in F_{p^{n}},u,v\in F_{p^{m}}}\zeta_{p}^{{\rm Tr}_{m}(u(F(y)-cF(x)-b))+{\rm Tr}_{m}(v(F(y+a)-c^{-1}F(x+a)-b))},

which, when run for all jj tuples of parameters (j1j\geq 1 is fixed) renders

a𝔽pn,b𝔽pm(nF(a,b,c))j\displaystyle\sum_{a\in{\mathbb{F}}_{p^{n}},b\in{\mathbb{F}}_{p^{m}}}\left(n_{F}(a,b,c)\right)^{j}
=p2jma𝔽pnb𝔽pmx1,,xj𝔽pny1,,yj𝔽pnu1,,uj𝔽pmv1,,vj𝔽pmζpi=1j[Trm(ui(F(yi)cF(xi)b))+Trm(vi(F(yi+a)c1F(xi+a)b))].\displaystyle=p^{-2jm}\sum_{\begin{subarray}{c}a\in{\mathbb{F}}_{p^{n}}\\ b\in{\mathbb{F}}_{p^{m}}\end{subarray}}\sum_{\begin{subarray}{c}x_{1},\ldots,x_{j}\in{\mathbb{F}}_{p^{n}}\\ y_{1},\ldots,y_{j}\in{\mathbb{F}}_{p^{n}}\\ u_{1},\ldots,u_{j}\in{\mathbb{F}}_{p^{m}}\\ v_{1},\ldots,v_{j}\in{\mathbb{F}}_{p^{m}}\end{subarray}}\zeta_{p}^{\sum_{i=1}^{j}\left[{\rm Tr}_{m}(u_{i}(F(y_{i})-cF(x_{i})-b))+{\rm Tr}_{m}(v_{i}(F(y_{i}+a)-c^{-1}F(x_{i}+a)-b))\right]}.

By (3), wi𝔽pnζpTrn(wi(xixia))=pn\displaystyle\sum_{w_{i}\in{\mathbb{F}}_{p^{n}}}\zeta_{p}^{{\rm Tr}_{n}(w_{i}(x_{i}^{\prime}-x_{i}-a))}=p^{n}, if xi=xi+ax_{i}^{\prime}=x_{i}+a and 00, otherwise; similarly, zi𝔽pnζpTrn(zi(yiyia))=pn\displaystyle\sum_{z_{i}\in{\mathbb{F}}_{p^{n}}}\zeta_{p}^{{\rm Tr}_{n}(z_{i}(y_{i}^{\prime}-y_{i}-a))}=p^{n}, if yi=yi+ay_{i}^{\prime}=y_{i}+a and 00, otherwise. Therefore,

a𝔽pn,b𝔽pm(nF(a,b,c))j=p2mjp2nja𝔽pn,b𝔽pmx1,,xj,x1,,xj𝔽pny1,,yj,y1,,yj𝔽pnw1,,wj,z1,,zj𝔽pnu1,,uj,v1,,vj𝔽pm\displaystyle\sum_{a\in{\mathbb{F}}_{p^{n}},b\in{\mathbb{F}}_{p^{m}}}\left(n_{F}(a,b,c)\right)^{j}=p^{-2mj}\ p^{-2nj}\sum_{a\in{\mathbb{F}}_{p^{n}},b\in{\mathbb{F}}_{p^{m}}}\sum_{\begin{subarray}{c}x_{1},\ldots,x_{j},x_{1}^{\prime},\ldots,x_{j}^{\prime}\in{\mathbb{F}}_{p^{n}}\\ y_{1},\ldots,y_{j},y_{1}^{\prime},\ldots,y_{j}^{\prime}\in{\mathbb{F}}_{p^{n}}\\ w_{1},\ldots,w_{j},z_{1},\ldots,z_{j}\in{\mathbb{F}}_{p^{n}}\\ u_{1},\ldots,u_{j},v_{1},\ldots,v_{j}\in{\mathbb{F}}_{p^{m}}\end{subarray}}
ζpi=1j[Trm(ui(F(yi)cF(xi)b))+Trm(vi(F(yi)c1F(xi)b))+Trn(wi(xixia))+Trn(zi(yiyia))]\displaystyle\zeta_{p}^{\sum_{i=1}^{j}\left[{\rm Tr}_{m}(u_{i}(F(y_{i})-cF(x_{i})-b))+{\rm Tr}_{m}(v_{i}(F(y_{i}^{\prime})-c^{-1}F(x_{i}^{\prime})-b))+{\rm Tr}_{n}(w_{i}(x_{i}^{\prime}-x_{i}-a))+{\rm Tr}_{n}(z_{i}(y_{i}^{\prime}-y_{i}-a))\right]}
=p2(m+n)jw1,,wj,z1,,zj𝔽pnu1,,uj,v1,,vj𝔽pmi=1j(𝒲F(ui,zi)𝒲F¯(cui,wi)𝒲F(vi,zi)𝒲F¯(c1vi,wi))\displaystyle=p^{-2(m+n)j}\sum_{\begin{subarray}{c}w_{1},\ldots,w_{j},z_{1},\ldots,z_{j}\in{\mathbb{F}}_{p^{n}}\\ u_{1},\ldots,u_{j},v_{1},\ldots,v_{j}\in{\mathbb{F}}_{p^{m}}\end{subarray}}\prod_{i=1}^{j}\left({\mathcal{W}}_{F}(u_{i},z_{i})\overline{{\mathcal{W}}_{F}}(cu_{i},-w_{i}){\mathcal{W}}_{F}(v_{i},-z_{i})\overline{{\mathcal{W}}_{F}}(c^{-1}v_{i},w_{i})\right)
a𝔽pn,b𝔽pmζpTrm(ai=1j(wi+zi)bi=1j(ui+vi))\displaystyle\qquad\qquad\qquad\qquad\qquad\qquad\qquad\qquad\sum_{a\in{\mathbb{F}}_{p^{n}},b\in{\mathbb{F}}_{p^{m}}}\zeta_{p}^{{\rm Tr}_{m}\left(-a\sum_{i=1}^{j}(w_{i}+z_{i})-b\sum_{i=1}^{j}(u_{i}+v_{i})\right)}
=p(2j1)(m+n)w1,,wj𝔽pnz1,,zj𝔽pnu1,,uj𝔽pmv1,,vj𝔽pmi=1j(wi+zi)=0i=1j(ui+vi)=0i=1j(𝒲F(ui,zi)𝒲F¯(cui,wi)𝒲F(vi,zi)𝒲F¯(c1vi,wi)).\displaystyle=p^{-(2j-1)(m+n)}\sum_{\begin{subarray}{c}w_{1},\ldots,w_{j}\in{\mathbb{F}}_{p^{n}}\\ z_{1},\ldots,z_{j}\in{\mathbb{F}}_{p^{n}}\\ u_{1},\ldots,u_{j}\in{\mathbb{F}}_{p^{m}}\\ v_{1},\ldots,v_{j}\in{\mathbb{F}}_{p^{m}}\\ \sum_{i=1}^{j}(w_{i}+z_{i})=0\\ \sum_{i=1}^{j}(u_{i}+v_{i})=0\end{subarray}}\prod_{i=1}^{j}\left({\mathcal{W}}_{F}(u_{i},z_{i})\overline{{\mathcal{W}}_{F}}(cu_{i},-w_{i}){\mathcal{W}}_{F}(v_{i},-z_{i})\overline{{\mathcal{W}}_{F}}(c^{-1}v_{i},w_{i})\right).

Surely, if j=0j=0, a𝔽pnb𝔽pm(nF(a,b,c))j=pm+n\displaystyle\sum_{\begin{subarray}{c}a\in{\mathbb{F}}_{p^{n}}\\ b\in{\mathbb{F}}_{p^{m}}\end{subarray}}\left(n_{F}(a,b,c)\right)^{j}=p^{m+n} and the theorem follows. ∎

As a particular case, we want to characterize the 11-uniform cc-BCT functions. We can take the polynomial ϕ1(x)=x1\phi_{1}(x)=x-1, which certainly satisfies the conditions of Theorem 6. Thus A0=1,A1=1A_{0}=-1,A_{1}=1 and the relation of Theorem 6 simplifies to

pn+m+p(n+m)w,z𝔽pnu,v𝔽pmw=z,u=v𝒲F(u,z)𝒲F¯(cu,w)𝒲F(v,z)𝒲F¯(c1v,w)\displaystyle-p^{n+m}+p^{-(n+m)}\sum_{\begin{subarray}{c}w,z\in{\mathbb{F}}_{p^{n}}\\ u,v\in{\mathbb{F}}_{p^{m}}\\ w=-z,u=-v\end{subarray}}{\mathcal{W}}_{F}(u,z)\overline{{\mathcal{W}}_{F}}(cu,-w){\mathcal{W}}_{F}(v,-z)\overline{{\mathcal{W}}_{F}}(c^{-1}v,w)
=z𝔽pnv𝔽pm𝒲F(v,z)𝒲F¯(cv,z)𝒲F(v,z)𝒲F¯(c1v,z)0.\displaystyle=\sum_{\begin{subarray}{c}z\in{\mathbb{F}}_{p^{n}}\\ v\in{\mathbb{F}}_{p^{m}}\end{subarray}}{\mathcal{W}}_{F}(-v,z)\overline{{\mathcal{W}}_{F}}(-cv,z){\mathcal{W}}_{F}(v,-z)\overline{{\mathcal{W}}_{F}}(c^{-1}v,-z)\geq 0.

Thus, we obtain the next result.

Proposition 7.

Let m,nm,n be fixed positive integers and c𝔽pmc\in{\mathbb{F}}_{p^{m}}, c0,1c\neq 0,1. Let FF be an (n,m)(n,m)-function. Then

z𝔽pnv𝔽pm𝒲F(v,z)𝒲F¯(cv,z)𝒲F(v,z)𝒲F¯(c1v,z)p2(n+m),\sum_{\begin{subarray}{c}z\in{\mathbb{F}}_{p^{n}}\\ v\in{\mathbb{F}}_{p^{m}}\end{subarray}}{\mathcal{W}}_{F}(-v,z)\overline{{\mathcal{W}}_{F}}(-cv,z){\mathcal{W}}_{F}(v,-z)\overline{{\mathcal{W}}_{F}}(c^{-1}v,-z)\geq p^{2(n+m)},

with equality if and only if FF is a 11-uniform cc-BCT function.

5 Some needed lemmas

In the next few sections, we will investigate some known perfect nonlinear, as well as the inverse function (in all characteristics) with respect to the cc-boomerang uniformity. We will need the following two lemmas. The proof of Lemma 8(i)(i) can be found in [1] and Lemma 8(ii)(ii) is easy and argued in [21]. The proof of Lemma 9 is contained in [21].

Lemma 8.

Let nn be a positive integer. We have:

  1. (i)(i)

    The equation x2+ax+b=0x^{2}+ax+b=0, with a,b𝔽2na,b\in{\mathbb{F}}_{2^{n}}, a0a\neq 0, has two solutions in 𝔽2n{\mathbb{F}}_{2^{n}} if Tr(ba2)=0{\rm Tr}\left(\frac{b}{a^{2}}\right)=0, and zero solutions otherwise.

  2. (ii)(ii)

    The equation x2+ax+b=0x^{2}+ax+b=0, with a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, pp odd, has (two, respectively, one) solutions in 𝔽pn{\mathbb{F}}_{p^{n}} if and only if the discriminant a24ba^{2}-4b is a (nonzero, respectively, zero) square in 𝔽pn{\mathbb{F}}_{p^{n}}.

Lemma 9.

Let p,k,np,k,n be integers greater than or equal to 11 (we take knk\leq n, though the result can be shown in general). Then

gcd(2k+1,2n1)=2gcd(2k,n)12gcd(k,n)1, and if p>2, then,\displaystyle\gcd(2^{k}+1,2^{n}-1)=\frac{2^{\gcd(2k,n)}-1}{2^{\gcd(k,n)}-1},\text{ and if $p>2$, then},
gcd(pk+1,pn1)=2, if ngcd(n,k) is odd,\displaystyle\gcd(p^{k}+1,p^{n}-1)=2,\text{ if $\frac{n}{\gcd(n,k)}$ is odd},
gcd(pk+1,pn1)=pgcd(k,n)+1, if ngcd(n,k) is even.\displaystyle\gcd(p^{k}+1,p^{n}-1)=p^{\gcd(k,n)}+1,\text{ if $\frac{n}{\gcd(n,k)}$ is even}.

Consequently, if either nn is odd, or n2(mod4)n\equiv 2\pmod{4} and kk is even, then gcd(2k+1,2n1)=1\gcd(2^{k}+1,2^{n}-1)=1 and gcd(pk+1,pn1)=2\gcd(p^{k}+1,p^{n}-1)=2, if p>2p>2.

We will be using throughout Hilbert’s Theorem 90 (see [8]), which states that if 𝔽𝕂\mathbb{F}\hookrightarrow\mathbb{K} is a cyclic Galois extension and σ\sigma is a generator of the Galois group Gal(𝕂/𝔽){\rm Gal}(\mathbb{K}/\mathbb{F}), then for x𝕂x\in\mathbb{K}, the relative trace Tr𝕂/𝔽(x)=0{\rm Tr}_{\mathbb{K}/\mathbb{F}}(x)=0 if and only if x=σ(y)yx=\sigma(y)-y, for some y𝕂y\in\mathbb{K}.

6 Perfect nonlinearity and cc-boomerang uniformity

The following are some of the known (see, for instance, [18, 20]) classes of PN functions (pp must be odd).

Theorem 10.

The following functions :𝔽pn𝔽pn:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{n}} are perfect nonlinear:

  • (1)(1)

    F(x)=x2F(x)=x^{2} on 𝔽pn{\mathbb{F}}_{p^{n}}.

  • (2)(2)

    F(x)=xpk+1F(x)=x^{p^{k}+1} on 𝔽pn{\mathbb{F}}_{p^{n}} is PN if and only if ngcd(k,n)\frac{n}{\gcd(k,n)} is odd.

  • (3)(3)

    F(x)=x(3k+1)/2F(x)=x^{(3^{k}+1)/2} is PN over 𝔽3n{\mathbb{F}}_{3^{n}} if and only if gcd(k,n)=1\gcd(k,n)=1 and nn is odd.

  • (4)(4)

    F(x)=x10±x6x2F(x)=x^{10}\pm x^{6}-x^{2} is PN over 𝔽3n{\mathbb{F}}_{3^{n}} if and only if n=2n=2 or nn is odd. In general, for u𝔽3nu\in{\mathbb{F}}_{3^{n}}, F(x)=x10ux6u2x2F(x)=x^{10}-ux^{6}-u^{2}x^{2} is PN over 𝔽3n{\mathbb{F}}_{3^{n}} if nn is odd.

It is known that the boomerang uniformity equals the differential uniformity for perfect nonlinear functions. It is, of course, a natural question to ask what is the connection between these in the “cc-context”. The reader is pointed to [21] where we discussed the cc-differential uniformity of the functions in Theorem 10. We will now concentrate on the cc-boomerang uniformity of all of these classes (for the last function we will just provide some computational data in the appendix). For c𝔽3nc\in{\mathbb{F}}_{3^{n}}, and bb fixed, we let μc\mu_{c} denote the cardinality

#{(x,γ)|2T3k+12(x+γ1)(cc1)T3k+12(x1)+(c+c1)T3k12(x1)=2b2T3k12(x+γ1)+(c+c1)T3k+12(x1)+(c1c)T3k12(x1)=0},\#\left\{(x,\gamma)\,\Bigg|\,\begin{subarray}{c}2T_{\frac{3^{k}+1}{2}}(x+\gamma-1)-(c-c^{-1})T_{\frac{3^{k}+1}{2}}(x-1)+(c+c^{-1})T_{\frac{3^{k}-1}{2}}(x-1)=2b\\ 2T_{\frac{3^{k}-1}{2}}(x+\gamma-1)+(c+c^{-1})T_{\frac{3^{k}+1}{2}}(x-1)+(c^{-1}-c)T_{\frac{3^{k}-1}{2}}(x-1)=0\end{subarray}\right\}, (4)

where T(w)=u+uT_{\ell}(w)=u^{\ell}+u^{-\ell}, under w=u+u1w=u+u^{-1}, is the Chebyshev polynomial of the first kind. We will be using below the trivial identity, T2(w)+2=T2(w)T_{2\ell}(w)+2=T_{\ell}^{2}(w).

Theorem 11.

Let F:𝔽pn𝔽pnF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{n}} ((pp is an odd prime number)) be the monomial F(x)=xdF(x)=x^{d}, and c0,1c\neq 0,1 be fixed. The following statements hold:

  1. (i)(i)

    If d=2d=2, then βF,c4\beta_{F,c}\leq 4.

  2. (ii)(ii)

    If d=pk+1d=p^{k}+1, δd:=#{γ𝔽pn|zpk+z+d=0}\delta_{d}:=\#\{\gamma\in{\mathbb{F}}_{p^{n}}\,|\,z^{p^{k}}+z+d=0\}, then

    βF,cδ1c1(δ1+c+1).\beta_{F,c}\geq\delta_{1-c^{-1}}\cdot\left(\delta_{1+c}+1\right).

    Moreover, when n/gcd(n,k){n}/{\gcd{(n,k)}} is odd, then βF,c2\beta_{F,c}\geq 2, and when n/gcd(n,k){n}/{\gcd{(n,k)}} is even and c1=zpk+zc^{-1}=z^{p^{k}}+z, for some z0z\neq 0, then the cc-boomerang uniformity of ff is βF,cpg\beta_{F,c}\geq p^{g}, where g=gcd(n,k)g=\gcd(n,k).

  3. (iii)(iii)

    Let p=3p=3. If d=3k+12\displaystyle d=\frac{3^{k}+1}{2} and ab0ab\neq 0, then Fc(a,b)μc{{}_{c}}{\mathcal{B}}_{F}(a,b)\geq\mu_{c}, where μc\mu_{c} is defined in (4). In particular, when c=1c=-1, then

    Fc(a,b)#{(x,γ)|T3k+12(x+γ1)+T3k12(x1)=2bT3k12(x+γ1)T3k+12(x1)=0}.{{}_{c}}{\mathcal{B}}_{F}(a,b)\geq\#\left\{(x,\gamma)\,\Bigg|\,\begin{subarray}{c}T_{\frac{3^{k}+1}{2}}(x+\gamma-1)+T_{\frac{3^{k}-1}{2}}(x-1)=2b\\ T_{\frac{3^{k}-1}{2}}(x+\gamma-1)-T_{\frac{3^{k}+1}{2}}(x-1)=0\end{subarray}\right\}.
Proof.

Let d=2d=2 and consider the system DγcF(x)=b,Dγc1F(x+a)=b{{}_{c}}D_{\gamma}F(x)=b,{{}_{c^{-1}}}D_{\gamma}F(x+a)=b. We do not care for the cases when ab=0ab=0. If ab0ab\neq 0, dividing by a2a^{2} and relabeling, we may assume that a=1a=1. Next, subtracting the first from the second equation, we obtain

(x+γ)=c1(x+1)2cx212,\displaystyle(x+\gamma)=\frac{c^{-1}(x+1)^{2}-cx^{2}-1}{2},

which, when replaced back into the first equation, and expanded, renders

(12c2+c4)x4+(44c2)x3+(62c2c22c3)x2\displaystyle(1-2c^{2}+c^{4})x^{4}+(4-4c^{2})x^{3}+(6-2c-2c^{2}-2c^{3})x^{2}
+(44c)x+(12c+c24bc2)=0.\displaystyle\qquad\qquad\qquad+(4-4c)x+(1-2c+c^{2}-4bc^{2})=0.

which has at most four roots, so Fc(a,b)4{{}_{c}}{\mathcal{B}}_{F}(a,b)\leq 4. We will see in the appendix that all values occur for the first few cases we considered.

We now consider the Gold case, d=pk+1d=p^{k}+1. The cc-boomerang system DγcF(x)=b,Dγc1F(x+a)=b{{}_{c}}D_{\gamma}F(x)=b,\ {{}_{c^{-1}}}D_{\gamma}F(x+a)=b (dividing by apk+10a^{p^{k+1}}\neq 0 and relabeling, we can assume that a=1a=1) becomes

(x+γ)pk+1cxpk+1=b\displaystyle(x+\gamma)^{p^{k}+1}-cx^{p^{k}+1}=b
(x+γ)pk+1c1(x+1)pk+1+(x+γ)pk+(x+γ)+1=b,\displaystyle(x+\gamma)^{p^{k}+1}-c^{-1}(x+1)^{p^{k}+1}+(x+\gamma)^{p^{k}}+(x+\gamma)+1=b,

eliminating (x+γ)pk+1(x+\gamma)^{p^{k}+1} and expanding the remaining powers, renders

cxpk+1c1(xpk+1+xpk+x+1)+xpk+γpk+x+γ+1=0, or,\displaystyle cx^{p^{k}+1}-c^{-1}(x^{p^{k}+1}+x^{p^{k}}+x+1)+x^{p^{k}}+\gamma^{p^{k}}+x+\gamma+1=0,\text{ or},
(cc1)xpk+1+(1c1)xpk+(1c1)x+(γpk+γ+(1c1))=0.\displaystyle(c-c^{-1})x^{p^{k}+1}+(1-c^{-1})x^{p^{k}}+(1-c^{-1})x+\left(\gamma^{p^{k}}+\gamma+(1-c^{-1})\right)=0. (5)

The idea is to vanish the parenthesis containing γ\gamma, that is, γpk+γ+(1c1)=0\gamma^{p^{k}}+\gamma+(1-c^{-1})=0 and the polynomial in xx, namely, (cc1)xpk+1+(1c1)xpk+(1c1)x=0(c-c^{-1})x^{p^{k}+1}+(1-c^{-1})x^{p^{k}}+(1-c^{-1})x=0, which is equivalent to x((c+1)xpk+xpk1+1)=0x\left((c+1)x^{p^{k}}+x^{p^{k}-1}+1\right)=0. By relabeling x1/xx\mapsto 1/x, the second factor can be put into the form

xpk+x+(c+1)=0,x^{p^{k}}+x+(c+1)=0,

For more accurate count, we let δd=#{γ|zpk+z+d=0}\delta_{d}=\#\{\gamma\,|\,z^{p^{k}}+z+d=0\}. We easily infer now that, if ab0ab\neq 0, Fc(a,b)δ1c1(δ1+c+1){{}_{c}}{\mathcal{B}}_{F}(a,b)\geq\delta_{1-c^{-1}}\cdot\left(\delta_{1+c}+1\right).

Now, to show the second claim of (ii)(ii), we want to argue that for some c0,1c\neq 0,1, we can always find some root γ\gamma for γpk+γ+(1c1)=0\gamma^{p^{k}}+\gamma+(1-c^{-1})=0 in 𝔽pn{\mathbb{F}}_{p^{n}}, pp an odd prime. Let g=gcd(n,k)g=\gcd(n,k).

We recall here the result from [17, 26] (we simplify some parameters, though). Let f(z)=zpkAzBf(z)=z^{p^{k}}-Az-B in 𝔽pn{\mathbb{F}}_{p^{n}}, g=gcd(n,k)g=\gcd(n,k), m=n/gcd(n,k)m=n/\gcd(n,k) and Tr𝔽pn/𝔽pg{\rm Tr}_{{\mathbb{F}}_{p^{n}}/{\mathbb{F}}_{p^{g}}} be the relative trace from 𝔽pn{\mathbb{F}}_{p^{n}} to 𝔽pg{\mathbb{F}}_{p^{g}}. For 0im10\leq i\leq m-1, we define ti=pnmpn(i+1)pn1t_{i}=\frac{p^{nm}-p^{n(i+1)}}{p^{n}-1}, α0=A,β0=B\alpha_{0}=A,\beta_{0}=B. If m>1m>1 (note that, if m=1m=1, gives F(x)=x2F(x)=x^{2}, which was treated earlier), then, for 1rm11\leq r\leq m-1, we let αr=Apk(r+1)1pk1 and βr=i=0rAsiBpki,\alpha_{r}=A^{\frac{p^{k(r+1)}-1}{p^{k}-1}}\text{ and }\beta_{r}=\sum_{i=0}^{r}A^{s_{i}}B^{p^{ki}}, where si=pk(r+1)pk(i+1)pk1s_{i}=\frac{p^{k(r+1)}-p^{k(i+1)}}{p^{k}-1}, for 0ir10\leq i\leq r-1 and sr=0s_{r}=0. The trinomial ff has no roots in 𝔽pn{\mathbb{F}}_{p^{n}} if and only if αm1=1\alpha_{m-1}=1 and βm10\beta_{m-1}\neq 0. If αm11\alpha_{m-1}\neq 1, then it has a unique root, namely x=βm1/(1αm1)x=\beta_{m-1}/(1-\alpha_{m-1}), and, if αm1=1,βm1=0\alpha_{m-1}=1,\beta_{m-1}=0, it has pgp^{g} roots in 𝔽pn{\mathbb{F}}_{p^{n}} given by x+δτx+\delta\tau, where δ𝔽pg\delta\in{\mathbb{F}}_{p^{g}}, τ\tau is fixed in 𝔽pn{\mathbb{F}}_{p^{n}} with τpk1=a\tau^{p^{k}-1}=a (that is, a (pk1)(p^{k}-1)-root of aa), and, for any e𝔽pne\in{\mathbb{F}}^{*}_{p^{n}} with Trg(e)0{\rm Tr}_{g}(e)\neq 0, then x=1Tr𝔽pn/𝔽pg(e)i=0m1(j=0iepkj)AtiBpki\displaystyle x=\frac{1}{{\rm Tr}_{{\mathbb{F}}_{p^{n}}/{\mathbb{F}}_{p^{g}}}(e)}\sum_{i=0}^{m-1}\left(\sum_{j=0}^{i}e^{p^{kj}}\right)A^{t_{i}}B^{p^{ki}}.

Since in our case A=1A=-1, B=c+1B=c+1, and, as we did in [21], if n/gn/g is odd, then γpk+γ+(1c1)=0\gamma^{p^{k}}+\gamma+(1-c^{-1})=0 has a unique root in 𝔽pn{\mathbb{F}}_{p^{n}}, since αng1=1\alpha_{\frac{n}{g}-1}=-1, independent of cc. Now, looking at xpk+x+(c+1)=0x^{p^{k}}+x+(c+1)=0, and by the same argument, it has a unique root, under n/gn/g odd, and so, Fc(a,b)2{{}_{c}}{\mathcal{B}}_{F}(a,b)\geq 2 in this case (we use the prior root x=0x=0, too).

Let m:=n/gm:=n/g be even. We switch the technique now. The equation in xx already has a root, namely x=0x=0, so we want to show that there are values of cc, for which γpk+γ+(1c1)=0\gamma^{p^{k}}+\gamma+(1-c^{-1})=0 has pgp^{g} roots. We will, in fact, find many such classes of parameters cc, below.

We denote by σtt(mod2){0,1}\sigma_{t}\equiv t\pmod{2}\in\{0,1\} the parity of tt. Observe that α0=β0=1\alpha_{0}=\beta_{0}=-1. Since αm1=1\alpha_{m-1}=1 for equation γpk+γ+(1c1)=0\gamma^{p^{k}}+\gamma+(1-c^{-1})=0, we need to show that βm1=0\beta_{m-1}=0, to be able to use [17]. We compute (using the fact that the parities of sis_{i}, 0im20\leq i\leq m-2, are σsi=(m2i+1)(mod2)=σi1\sigma_{s_{i}}=(m-2-i+1)\pmod{2}=\sigma_{i-1}, since mm is even),

βm1\displaystyle\beta_{m-1} =i=0m1(1)si(1c1)pki=i=0m1(1)i1(1(c1)pki)\displaystyle=\sum_{i=0}^{m-1}(-1)^{s_{i}}(1-c^{-1})^{p^{ki}}=\sum_{i=0}^{m-1}(-1)^{i-1}\left(1-(-c^{-1})^{p^{ki}}\right)
=i=0m1(1)i1i=0m1(1)i1+pki(c1)pki, since m is even\displaystyle=\sum_{i=0}^{m-1}(-1)^{i-1}-\sum_{i=0}^{m-1}(-1)^{i-1+p^{ki}}(c^{-1})^{p^{ki}},\text{ since $m$ is even}
=i=0m1(1)i1(c1)pki.\displaystyle=\sum_{i=0}^{m-1}(-1)^{i-1}(c^{-1})^{p^{ki}}.

Now, let z1z\neq 1 be such that zpkm11=0z^{p^{km}-1}-1=0 (this always exists since kmkm is a multiple of nn). Observe (we will be using that later) that zpkmz=0z^{p^{km}}-z=0 and z0,1z\neq 0,1. We now set c1=zpk+zc^{-1}=z^{p^{k}}+z and so, the previous displayed equation becomes

βm1\displaystyle\beta_{m-1} =i=0m1(1)i1(zpk+z)pki\displaystyle=\sum_{i=0}^{m-1}(-1)^{i-1}(z^{p^{k}}+z)^{p^{ki}}
=i=0m1(1)i1zpk(i+1)+i=0m1(1)i1zpki\displaystyle=\sum_{i=0}^{m-1}(-1)^{i-1}z^{p^{k(i+1)}}+\sum_{i=0}^{m-1}(-1)^{i-1}z^{p^{ki}}
=i=1m1((1)i1+(1)i)zpki+zzpkm\displaystyle=\sum_{i=1}^{m-1}\left((-1)^{i-1}+(-1)^{i}\right)z^{p^{ki}}+z-z^{p^{km}}
=zzpkm=0, from our choice of z.\displaystyle=z-z^{p^{km}}=0,\text{ from our choice of $z$}.

Therefore, by the result of [17, 26], we infer that the equation zpk+z+(1c1)=0z^{p^{k}}+z+(1-c^{-1})=0 has pgp^{g} solutions in 𝔽pn{\mathbb{F}}_{p^{n}}. Thus, the initial Equation (5) has at least pgp^{g} solutions, and so, the cc-boomerang uniformity in this case (under ngcd(n,k)\frac{n}{\gcd{(n,k)}} even) is at least pgp^{g}, where g=gcd(n,k)g=\gcd(n,k).

Let us treat now the case of d=(3k+1)/2d=(3^{k}+1)/2 in 𝔽3n{\mathbb{F}}_{3^{n}}, where the system is now (recall that, since p=3p=3, 1=21=-2)

(x+γ)3k+12cx3k+12=b\displaystyle(x+\gamma)^{\frac{3^{k}+1}{2}}-cx^{\frac{3^{k}+1}{2}}=b
(x+γ+1)3k+12c1(x+1)3k+12=b.\displaystyle(x+\gamma+1)^{\frac{3^{k}+1}{2}}-c^{-1}(x+1)^{\frac{3^{k}+1}{2}}=b.

We will not use the same method as in [17], or [21] as permutation polynomials are not visibly involved here, rather we will modify the “seed” of the technique. Since 2|3n12|3^{n}-1, for all nn, then we can always write x1=y+y1x-1=y+y^{-1} and x+γ1=z+z1x+\gamma-1=z+z^{-1}, for some y,z𝔽3ny,z\in{\mathbb{F}}_{3^{n}}. The system becomes

(z+z12)3k+12c(y+y12)3k+12=b\displaystyle(z+z^{-1}-2)^{\frac{3^{k}+1}{2}}-c(y+y^{-1}-2)^{\frac{3^{k}+1}{2}}=b
(z+z1+2)3k+12c1(y+y1+2)3k+12=b,\displaystyle(z+z^{-1}+2)^{\frac{3^{k}+1}{2}}-c^{-1}(y+y^{-1}+2)^{\frac{3^{k}+1}{2}}=b,

that is,

(z1)3k+1z3k+12c(y1)3k+1y3k+12=b\displaystyle\frac{(z-1)^{3^{k}+1}}{z^{\frac{3^{k}+1}{2}}}-c\frac{(y-1)^{3^{k}+1}}{y^{\frac{3^{k}+1}{2}}}=b
(z+1)3k+1z3k+12c1(y+1)3k+1y3k+12=b,\displaystyle\frac{(z+1)^{3^{k}+1}}{z^{\frac{3^{k}+1}{2}}}-c^{-1}\frac{(y+1)^{3^{k}+1}}{y^{\frac{3^{k}+1}{2}}}=b,

which, by expansion, renders

z3k+1z3kz+1z3k+12cy3k+1y3ky+1y3k+12=b\displaystyle\frac{z^{3^{k}+1}-z^{3^{k}}-z+1}{z^{\frac{3^{k}+1}{2}}}-c\frac{y^{3^{k}+1}-y^{3^{k}}-y+1}{y^{\frac{3^{k}+1}{2}}}=b
z3k+1+z3k+z+1z3k+12c1y3k+1+y3k+y+1y3k+12=b, or,\displaystyle\frac{z^{3^{k}+1}+z^{3^{k}}+z+1}{z^{\frac{3^{k}+1}{2}}}-c^{-1}\frac{y^{3^{k}+1}+y^{3^{k}}+y+1}{y^{\frac{3^{k}+1}{2}}}=b,\text{ or},
T3k+12(x+γ1)T3k12(x+γ1)cT3k+12(x1)+cT3k12(x1)=b\displaystyle T_{\frac{3^{k}+1}{2}}(x+\gamma-1)-T_{\frac{3^{k}-1}{2}}(x+\gamma-1)-cT_{\frac{3^{k}+1}{2}}(x-1)+cT_{\frac{3^{k}-1}{2}}(x-1)=b
T3k+12(x+γ1)+T3k12(x+γ1)+c1T3k+12(x1)+c1T3k12(x1)=b,\displaystyle T_{\frac{3^{k}+1}{2}}(x+\gamma-1)+T_{\frac{3^{k}-1}{2}}(x+\gamma-1)+c^{-1}T_{\frac{3^{k}+1}{2}}(x-1)+c^{-1}T_{\frac{3^{k}-1}{2}}(x-1)=b,

where T(u+u1)=u+uT_{\ell}(u+u^{-1})=u^{\ell}+u^{-\ell} is the Chebyshev polynomial of the first kind. Adding and subtracting these two equations will give

2T3k+12(x+γ1)(cc1)T3k+12(x1)+(c+c1)T3k12(x1)=2b2T3k12(x+γ1)+(c+c1)T3k+12(x1)+(c1c)T3k12(x1)=0.\begin{split}&2T_{\frac{3^{k}+1}{2}}(x+\gamma-1)-(c-c^{-1})T_{\frac{3^{k}+1}{2}}(x-1)+(c+c^{-1})T_{\frac{3^{k}-1}{2}}(x-1)=2b\\ &2T_{\frac{3^{k}-1}{2}}(x+\gamma-1)+(c+c^{-1})T_{\frac{3^{k}+1}{2}}(x-1)+(c^{-1}-c)T_{\frac{3^{k}-1}{2}}(x-1)=0.\end{split} (6)

Thus, Fc(a,b)#{(x,γ)|(x,γ) satisfies(6)}=μc{{}_{c}}{\mathcal{B}}_{F}(a,b)\geq\#\{(x,\gamma)\,|\,(x,\gamma)\text{ satisfies}~\eqref{eq:T}\}=\mu_{c}. ∎

7 The cc-boomerang uniformity for the inverse function

We now deal with the binary inverse function.

Theorem 12.

Let n3n\geq 3 be a positive integer, 0,1c𝔽2n0,1\neq c\in{\mathbb{F}}_{2^{n}} and F:𝔽2n𝔽2nF:{\mathbb{F}}_{2^{n}}\to{\mathbb{F}}_{2^{n}} be the inverse function defined by F(x)=x2n2F(x)=x^{2^{n}-2}. If n=2n=2, Fc(a,b)1{{}_{c}}{\mathcal{B}}_{F}(a,b)\leq 1 and if n=3n=3, Fc(a,b)2{{}_{c}}{\mathcal{B}}_{F}(a,b)\leq 2. If n4n\geq 4, Fc(a,b)3{{}_{c}}{\mathcal{B}}_{F}(a,b)\leq 3. Furthermore, Fc(a,ab)=3{{}_{c}}{\mathcal{B}}_{F}(a,ab)=3 (so, the cc-boomerang uniformity of FF is βF,c=3\beta_{F,c}=3) if and only if any of the conditions happen:

  1. (i)(i)

    Tr(c)=0{\rm Tr}(c)=0 and there exists bb such that (b2c+bc2+b+c2+1)20(b^{2}c+bc^{2}+b+c^{2}+1)^{2}\neq 0 and Tr(b2c2(bc+c+1)(b2c+bc2+b+c2+1)2)=0{\rm Tr}\left(\frac{b^{2}c^{2}(bc+c+1)}{(b^{2}c+bc^{2}+b+c^{2}+1)^{2}}\right)=0.

  2. (ii)(ii)

    Tr(1/c)=0{\rm Tr}(1/c)=0 and there exists bb such that (b2c+bc2+b+c2+1)20(b^{2}c+bc^{2}+b+c^{2}+1)^{2}\neq 0 and Tr(b2c2(bc+c+1)(b2c+bc2+b+c2+1)2)=0{\rm Tr}\left(\frac{b^{2}c^{2}(bc+c+1)}{(b^{2}c+bc^{2}+b+c^{2}+1)^{2}}\right)=0.

  3. (iii)(iii)

    Tr(c3(c2+c+1)2)=0{\rm Tr}\left(\frac{c^{3}}{(c^{2}+c+1)^{2}}\right)=0 and there exists bb such that (b2c+bc2+b+c2+1)20(b^{2}c+bc^{2}+b+c^{2}+1)^{2}\neq 0 and Tr(b2c2(bc+c+1)(b2c+bc2+b+c2+1)2)=0{\rm Tr}\left(\frac{b^{2}c^{2}(bc+c+1)}{(b^{2}c+bc^{2}+b+c^{2}+1)^{2}}\right)=0.

  4. (iv)(iv)

    c2+c+1=0c^{2}+c+1=0 (so, n0(mod2)n\equiv 0\pmod{2}) and there exists bb such that b2+b+10b^{2}+b+1\neq 0 and Tr(b2c(b+c)(b2+b+1)2)=0{\rm Tr}\left(\frac{b^{2}c(b+c)}{(b^{2}+b+1)^{2}}\right)=0.

Proof.

The claim about n=2,3n=2,3 follows from the computation displayed in the appendix, so we now assume n4n\geq 4.

By Theorem 3, we need to investigate the system

(x+γ)2n2+cx2n2=b(x+γ+a)2n2+c1(x+a)2n2=b.\begin{array}[]{lcl}(x+\gamma)^{2^{n}-2}+cx^{2^{n}-2}&=&b\\ (x+\gamma+a)^{2^{n}-2}+c^{-1}(x+a)^{2^{n}-2}&=&b.\end{array} (7)

Observe that if a=0a=0, then the system becomes (x+γ)2n2+cx2n2=b=(x+γ)2n2+c1x2n2(x+\gamma)^{2^{n}-2}+cx^{2^{n}-2}=b=(x+\gamma)^{2^{n}-2}+c^{-1}x^{2^{n}-2}, rendering (c+c1)x2n2=0(c+c^{-1})x^{2^{n}-2}=0, and since c0,1c\neq 0,1, then x=0x=0. Thus, γ2n2=b\gamma^{2^{n}-2}=b, which also has one solution γ\gamma, independent of bb, so Fc(0,b)=1{{}_{c}}{\mathcal{B}}_{F}(0,b)=1.

We next assume that 0c1,a00\neq c\neq 1,a\neq 0. Dividing (7) by aa and relabeling x/axx/a\mapsto x, γ/aγ\gamma/a\mapsto\gamma and abbab\mapsto b (all are linear equations), we are led to investigate the system

(x+γ)2n2+cx2n2=b(x+γ+1)2n2+c1(x+1)2n2=b.\begin{array}[]{lcl}(x+\gamma)^{2^{n}-2}+cx^{2^{n}-2}&=&b\\ (x+\gamma+1)^{2^{n}-2}+c^{-1}(x+1)^{2^{n}-2}&=&b.\end{array} (8)

If b=0b=0, the system (8) transforms into (x+γ)2n2=cx2n2,(x+γ+1)2n2=c1(x+1)2n2(x+\gamma)^{2^{n}-2}=cx^{2^{n}-2},(x+\gamma+1)^{2^{n}-2}=c^{-1}(x+1)^{2^{n}-2}. If x=0x=0, then γ=0\gamma=0, which renders the non-permissible c=1c=1. Similarly, x=1x=1, x=γx=\gamma, x=γ+1x=\gamma+1 can only happen if c=1c=1 (assuming b=0b=0) and that is not allowed. If none of these values of xx happen then the system becomes

x+γ=c1x,x+γ+1=cx+c,x+\gamma=c^{-1}x,\ x+\gamma+1=cx+c,

with solutions γ=1,x=cc+10,1\gamma=1,x=\frac{c}{c+1}\neq 0,1, so x{0,1,γ,γ+1}x\notin\{0,1,\gamma,\gamma+1\}, hence Fc(a,0)=1{{}_{c}}{\mathcal{B}}_{F}(a,0)=1 (which holds for all aa, using the previous discussion). We next assume that b0b\neq 0.

Case 11: b0b\neq 0, x=0x=0. The system (8) reduces to γ2n2=b\gamma^{2^{n}-2}=b and (γ+1)2n2c1=b(\gamma+1)^{2^{n}-2}-c^{-1}=b. Since b0b\neq 0, then γ=1/b\gamma=1/b, which can only happen if bb+1=b+c1\frac{b}{b+1}=b+c^{-1}, that is, b2+c1b+c1=0b^{2}+c^{-1}b+c^{-1}=0. This equation in bb has two solutions, say, b1,b1=1/(cb1)b_{1},b_{1}^{\prime}=1/(cb_{1}), if and only if, by Lemma 8, Tr(c1/c2)=Tr(c)=0{\rm Tr}(c^{-1}/c^{-2})={\rm Tr}(c)=0. Thus, in this case, we have a contribution of 11 (the solutions are (x,γ)=(0,1/b1),(0,1/b1)(x,\gamma)=(0,1/b_{1}),(0,1/b_{1}^{\prime})) to Fc(a,ab1){{}_{c}}{\mathcal{B}}_{F}(a,ab_{1}), respectively, F(a,ab1){\mathcal{B}}_{F}(a,ab_{1}^{\prime}), otherwise there is no contribution.

Case 22: b0b\neq 0, x=1x=1. The system (8) reduces to (γ+1)2n2=b+c,γ2n2=b(\gamma+1)^{2^{n}-2}=b+c,\gamma^{2^{n}-2}=b. If b=1b=1, then γ=1\gamma=1 and cc must be 1, an impossibility. If b=c1b=c\neq 1, then γ=1/b\gamma=1/b and (γ+1)2n2=0(\gamma+1)^{2^{n}-2}=0, so, γ=1\gamma=1, implying b=1b=1, and so, c=1c=1, which is not allowed. Thus, 1bc1\neq b\neq c, and so, γ=1/b\gamma=1/b renders b2+cb+c=0b^{2}+cb+c=0, which has two roots, say b2,b2=c/b2b_{2},b_{2}^{\prime}=c/b_{2}, if and only if, by Lemma 8, Tr(1/c)=0{\rm Tr}(1/c)=0. Therefore, if Tr(1/c)=0{\rm Tr}(1/c)=0, then we have a contribution of 11 to Fc(a,ab2){{}_{c}}{\mathcal{B}}_{F}(a,ab_{2}), respectively, Fc(a,ab2){{}_{c}}{\mathcal{B}}_{F}(a,ab_{2}^{\prime}) (the solutions are (x,γ)=(1,1/b2),(1,1/b2)(x,\gamma)=(1,1/b_{2}),(1,1/b_{2}^{\prime})).

Can b1,b1b_{1},b_{1}^{\prime} equal b2,b2b_{2},b_{2}^{\prime}? If that is so, then c1b1+c1=cb1+cc^{-1}b_{1}+c^{-1}=cb_{1}+c, obtaining b1=1b_{1}=1, but that is impossible since it will not satisfy b2+bc+c=0b^{2}+bc+c=0 (similarly for b1=b2b_{1}^{\prime}=b_{2}, etc.). Thus, the two contributions from Case 11 and 22 will not overlap.

Case 33: b0b\neq 0, x=γx=\gamma. The system (8) reduces to cx2n2=b,1+c1(x+1)2n2=bcx^{2^{n}-2}=b,1+c^{-1}(x+1)^{2^{n}-2}=b, so x=c/bx=c/b. If b=cb=c, then x=1x=1, and b=1b=1 (from the second equation), an impossibility. If bcb\neq c, then we must have b2+c2+c+1cb+c=0b^{2}+\frac{c^{2}+c+1}{c}b+c=0, and two roots bb exist (b3,c/b3b_{3},c/b_{3}), under c2+c+10c^{2}+c+1\neq 0, by Lemma 8, if and only if Tr(c3(c2+c+1)2)=0{\rm Tr}\left(\frac{c^{3}}{(c^{2}+c+1)^{2}}\right)=0 (one such b3b_{3}^{\prime} does exist even when c2+c+1=0c^{2}+c+1=0 (so, nn is even), as then, b3=c1/2b_{3}^{\prime}=c^{1/2}, which always exists). Under these circumstances, we have a contribution of 11 to Fc(a,ab3){{}_{c}}{\mathcal{B}}_{F}(a,ab_{3}), Fc(a,ac/b3){{}_{c}}{\mathcal{B}}_{F}(a,ac/b_{3}), respectively, Fc(a,ab3){{}_{c}}{\mathcal{B}}_{F}(a,ab_{3}^{\prime}).

Can any of b3b_{3}, or b3b_{3}^{\prime} be equal to b1b_{1}, or b2b_{2}?

  • If b3=b1b_{3}=b_{1}, then as above we get that b1=b3=c2+c+1(c+1)2b_{1}=b_{3}=\frac{c^{2}+c+1}{(c+1)^{2}}, assuming Tr(c)=Tr(cc2+c+1)=0{\rm Tr}(c)={\rm Tr}\left(\frac{c}{c^{2}+c+1}\right)=0. If that is so, plugging this value in any of the component equations, renders c4(c+1)4=0\frac{c^{4}}{(c+1)^{4}}=0, an impossibility.

  • If b3=b2b_{3}=b_{2}, similarly, we get that b=cc+1b=\frac{c}{c+1}, assuming Tr(1c)=0{\rm Tr}\left(\frac{1}{c}\right)=0 and Tr(cc2+c+1)=0{\rm Tr}\left(\frac{c}{c^{2}+c+1}\right)=0. Putting the value of bb in any of the component equations, gives c(c+1)2=0\frac{c}{(c+1)^{2}}=0, which is impossible.

  • b3=c1/2=b1b_{3}^{\prime}=c^{1/2}=b_{1} (under c2+c+1=0c^{2}+c+1=0) when plugged into the equation of b1b_{1}, gives c=1c=1, a contradiction.

  • b3=c1/2=b2b_{3}^{\prime}=c^{1/2}=b_{2}, similarly renders (under c2+c+1=0c^{2}+c+1=0) when put into the equation of b2b_{2}, the value c=0c=0, a contradiction.

Case 44: b0b\neq 0, x=γ+1x=\gamma+1. The system (8) reduces to 1+cx2n2=b,c1(x+1)=b1+cx^{2^{n}-2}=b,c^{-1}(x+1)=b. If b=1b=1, then x=0x=0, and so, c1=b=1c^{-1}=b=1, a contradiction. Thus, b1b\neq 1 and x=c/(b+1)x=c/(b+1), which, when used in the first equation, gives

b2+c2+c+1cb+1c=0,b^{2}+\frac{c^{2}+c+1}{c}b+\frac{1}{c}=0,

which renders two solutions, say b4,b4=1/(cb4)b_{4},b_{4}^{\prime}=1/(cb_{4}), if and only if Tr(c(c2+c+1)2)=0{\rm Tr}\left(\frac{c}{(c^{2}+c+1)^{2}}\right)=0. For such a cc, we get a contribution of 11 to Fc(a,ab4){{}_{c}}{\mathcal{B}}_{F}(a,ab_{4}), respectively, Fc(a,ab4){{}_{c}}{\mathcal{B}}_{F}(a,ab_{4}^{\prime}), assuming Tr(c(c2+c+1)2)=0{\rm Tr}\left(\frac{c}{(c^{2}+c+1)^{2}}\right)=0.

Can b4b_{4} (or b4b_{4}^{\prime}) be equal to b1,b1b_{1},b_{1}^{\prime}, b2,b2b_{2},b_{2}^{\prime}, b3b_{3}, or b3b_{3}^{\prime}?

  • If b4=b1b_{4}=b_{1} (or b1b_{1}^{\prime}), then they must satisfy both cb2+b+1=0,cb2+(c2+c+1)b+1=0cb^{2}+b+1=0,cb^{2}+(c^{2}+c+1)b+1=0, from which we infer b=0b=0 or c=0,1c=0,1, an impossibility.

  • If b4=b2b_{4}=b_{2} (or b2b_{2}^{\prime}), then they must satisfy both b2+bc+c=0,cb2+(c2+c+1)b+1=0b^{2}+bc+c=0,cb^{2}+(c^{2}+c+1)b+1=0, implying b=c+1b=c+1, which does not satisfy b2+bc+c=0b^{2}+bc+c=0.

  • If b4=b3b_{4}=b_{3}, then they must satisfy both equations cb2+(c2+c+1)b+c2=0,cb2+(c2+c+1)b+1=0cb^{2}+(c^{2}+c+1)b+c^{2}=0,cb^{2}+(c^{2}+c+1)b+1=0, inferring c=1c=1, an impossibility.

  • If b4=b3(=c1/2)b_{4}=b_{3}^{\prime}(=c^{1/2}), then c2+c+1=0c^{2}+c+1=0 (so, n0(mod2)n\equiv 0\pmod{2}) and cb42+(c+1)b+(c+1)=0cb_{4}^{2}+(c+1)b+(c+1)=0. Thus, c2=(c+1)c1/2c^{2}=(c+1)c^{1/2}, which combined with c2+c+1=0c^{2}+c+1=0, renders (c+1)(c1/2+1)=0(c+1)(c^{1/2}+1)=0, that is, c=1c=1, an impossibility.

Case 55. Assuming now that x(x+1)(x+γ)(x+γ+1)0x(x+1)(x+\gamma)(x+\gamma+1)\neq 0, and multiplying the first equation of (8) by x(x+γ)x(x+\gamma) and the second by c(x+1)(x+γ+1)c(x+1)(x+\gamma+1) we obtain the new system

1+cx+bx2+(c+bx)γ=01+c+bc+(1+c)x+bcx2+(1+bc+bcx)γ=0.\begin{split}1+cx+bx^{2}+(c+bx)\gamma&=0\\ 1+c+bc+(1+c)x+bcx^{2}+(1+bc+bcx)\gamma&=0.\end{split} (9)

Observe that xc/bx\neq c/b since, otherwise, c=0c=0 (inferred from the first equation), a contradiction. If xc/bx\neq c/b, then using γ=bx2+cx+xbx+c\displaystyle\gamma=\frac{bx^{2}+cx+x}{bx+c} found from the first equation and replacing it into the second, we get

b2cx2+(b2c+bc2+b+c2+1)x+bc2+c2+c=0,b^{2}cx^{2}+(b^{2}c+bc^{2}+b+c^{2}+1)x+bc^{2}+c^{2}+c=0,

or

x2+b2c+bc2+b+c2+1b2cx+bc+c+1b2=0.x^{2}+\frac{b^{2}c+bc^{2}+b+c^{2}+1}{b^{2}c}x+\frac{bc+c+1}{b^{2}}=0. (10)

If b2c+bc2+b+c2+1=0b^{2}c+bc^{2}+b+c^{2}+1=0, we have a contribution of 11 to Fc(a,ab){{}_{c}}{\mathcal{B}}_{F}(a,ab). If b2c+bc2+b+c2+10b^{2}c+bc^{2}+b+c^{2}+1\neq 0, by Lemma 8, Equation (9) will have two solutions if and only if

Tr(bc+c+1b2(b2c+bc2+b+c2+1b2c)2)=Tr(b2c2(bc+c+1)(b2c+bc2+b+c2+1)2)=0.{\rm Tr}\left(\frac{\frac{bc+c+1}{b^{2}}}{\left(\frac{b^{2}c+bc^{2}+b+c^{2}+1}{b^{2}c}\right)^{2}}\right)={\rm Tr}\left(\frac{b^{2}c^{2}(bc+c+1)}{(b^{2}c+bc^{2}+b+c^{2}+1)^{2}}\right)=0. (11)

Therefore, under the above trace condition on bb for a fixed cc, we have a contribution of 22 to Fc(a,ab){{}_{c}}{\mathcal{B}}_{F}(a,ab).

To avoid speaking about an empty condition, we want to argue next that (11) will happen for a fixed c0,1c\neq 0,1, so it will be sufficient to find a values of bb where the trace above is 0. If b=1b=1 (and so, 1+b+b2c+c2+bc201+b+b^{2}c+c^{2}+bc^{2}\neq 0), then the trace becomes Tr(1)=0{\rm Tr}(1)=0, which will always happen if the dimension is even, the Equation (10) is then x2+x+1=0x^{2}+x+1=0 (with two distinct roots), so in this case we have a contribution of 22 to Fc(a,ab){{}_{c}}{\mathcal{B}}_{F}(a,ab), where bb satisfies (11), otherwise there is none.

For the remainder of the proof below we assume that nn is odd. Taking, for example, b=c2+c10b=c^{2}+c^{-1}\neq 0 (for this value, 1+b+b2c+c2+bc201+b+b^{2}c+c^{2}+bc^{2}\neq 0, since otherwise, we would get c5+c4+c+1=(c+1)5=0c^{5}+c^{4}+c+1=(c+1)^{5}=0, so c=1c=1, a contradiction), since the dimension is odd and c0,1c\neq 0,1, the above trace calculation reduces to

Tr(c(1+c+c2)2(1+c)4)=Tr(c(1+c)2+c2(1+c)4)=0,{\rm Tr}\left(\frac{c(1+c+c^{2})^{2}}{(1+c)^{4}}\right)={\rm Tr}\left(\frac{c}{(1+c)^{2}}+\frac{c^{2}}{(1+c)^{4}}\right)=0,

which is obviously true, and so there are two roots xx to the Equation (10).

We need to make sure that the solutions x,γx,\gamma will not satisfy x(x+1)(x+γ)(x+γ+1)=0x(x+1)(x+\gamma)(x+\gamma+1)=0, so we go back (replacing b=c2+c1b=c^{2}+c^{-1}) to Equation (10), obtaining

x2+c4+c3+c2+c(c2+c+1)2x+c3(c2+c+1)2=0x^{2}+\frac{c^{4}+c^{3}+c^{2}+c}{(c^{2}+c+1)^{2}}x+\frac{c^{3}}{(c^{2}+c+1)^{2}}=0

If x=0x=0, then c=0c=0, which is not allowed. If x=1x=1, then we get 1+c(c2+c+1)2=0\frac{1+c}{(c^{2}+c+1)^{2}}=0, and so, c=1c=1, which is not allowed. If x=γx=\gamma, then the system (9) becomes

x=0,(c3+c+1)x+c3+c=0,x=0,(c^{3}+c+1)x+c^{3}+c=0,

which is impossible since c0,1c\neq 0,1. If x=γ+1x=\gamma+1, the system is now

x+1=0,(c3+c+1)x+c2=0,x+1=0,(c^{3}+c+1)x+c^{2}=0,

which can only happen if c3+c2+c+1=(c+1)3=0c^{3}+c^{2}+c+1=(c+1)^{3}=0, an impossibility.

Putting together the above cases, we see that, if n4n\geq 4, the only possibility is for at most three solutions of the cc-boomerang system: we get three solutions if Case 5 is combined with any of the previous 4 cases (for (iv)(iv) we use c2+c=1=0c^{2}+c=1=0 to simplify the trace expression), and therefore, the cc-boomerang uniformity is 3\leq 3, but not higher. Our theorem is shown. ∎

Remark 3.

From the previous proof, we do get a lot more information about the Boomerang Connectivity Table for the binary inverse function, but we preferred to simply give just the maximum cc-BCT entries.

We now treat the case of the inverse for odd characteristic. We let [A]2={x2|xA}[A]^{2}=\{x^{2}\,|\,x\in A\}, where AA is a set with a defined multiplication on it.

Theorem 13.

Let pp be an odd prime, n1n\geq 1 be a positive integer, 0,1c𝔽pn0,1\neq c\in{\mathbb{F}}_{p^{n}} and F:𝔽pn𝔽pnF:{\mathbb{F}}_{p^{n}}\to{\mathbb{F}}_{p^{n}} be the inverse pp-ary function defined by F(x)=xpn2F(x)=x^{p^{n}-2}. For any a,b𝔽pna,b\in{\mathbb{F}}_{p^{n}}, the cc-BCT entries Fc(a,ab)4{{}_{c}}{\mathcal{B}}_{F}(a,ab)\leq 4. Furthermore,

  1. (i)(i)

    If 1+2c2c2+2c3+c4=01+2c-2c^{2}+2c^{3}+c^{4}=0 and 32c+3c2,14c,c24c[𝔽pn]23-2c+3c^{2},1-4c,c^{2}-4c\in[{\mathbb{F}}_{p^{n}}]^{2}, then βF,c=4\beta_{F,c}=4 (e.g., for such cc, if b=c21c2+1b=\frac{c^{2}-1}{c^{2}+1}, then Fc(a,ab)=4{{}_{c}}{\mathcal{B}}_{F}(a,ab)=4).

  2. (ii)(ii)

    If 12c2c22c3+c4=01-2c-2c^{2}-2c^{3}+c^{4}=0 and 16c+c2,14c,c24c[𝔽pn]21-6c+c^{2},1-4c,c^{2}-4c\in[{\mathbb{F}}_{p^{n}}]^{2}, then βF,c=4\beta_{F,c}=4 (e.g., for such cc, if b=c212cb=\frac{c^{2}-1}{2c}, then Fc(a,ab)=4{{}_{c}}{\mathcal{B}}_{F}(a,ab)=4).

Proof.

For a=0a=0, the corresponding system (x+γ)pn2cxpn2=b,(x+γ)pn2c1xpn2=b(x+\gamma)^{p^{n}-2}-cx^{p^{n}-2}=b,(x+\gamma)^{p^{n}-2}-c^{-1}x^{p^{n}-2}=b has one solution (x,γ)(x,\gamma). We assume now that a0a\neq 0. Multiplying by aa and relabeling, the cc-boomerang system becomes

(x+γ)pn2cxpn2=b.(x+γ+1)pn2c1(x+1)pn2=b.\begin{split}(x+\gamma)^{p^{n}-2}-cx^{p^{n}-2}=b.\\ (x+\gamma+1)^{p^{n}-2}-c^{-1}(x+1)^{p^{n}-2}=b.\end{split} (12)

If b=0b=0, we easily get only one solution, so we may assume below that b0b\neq 0.

Case 11. Let x=0x=0. The cc-boomerang system is γpn2=b,(γ+1)pn2c1=b\gamma^{p^{n}-2}=b,(\gamma+1)^{p^{n}-2}-c^{-1}=b, so γ=1/b\gamma=1/b, and (1b+1)pn2=b+1c(\frac{1}{b}+1)^{p^{n}-2}=b+\frac{1}{c} (surely, b+1c0b+\frac{1}{c}\neq 0, since, otherwise, b=1b=-1, and so, c=1c=1, an impossibility). Thus, (0,1b)(0,\frac{1}{b}) is a solution assuming bb satisfies b2+1cb+1c=0b^{2}+\frac{1}{c}b+\frac{1}{c}=0. By Lemma 8, a unique b1b_{1}^{\prime} exists if and only if the discriminant D1=c24c1=0D_{1}=c^{-2}-4c^{-1}=0, that is c=41c=4^{-1}. Again, from Lemma 8, two solutions b1b_{1} (we call these, here and in the next three cases, by the same label, as it will not matter in our argument) exist if and only if 14c[𝔽pn]21-4c\in[{\mathbb{F}}_{p^{n}}]^{2}, c41c\neq 4^{-1}. In either case, there is a contribution of 11 to the respective cc-BCT entry.

Case 22. If x=1x=-1, the cc-boomerang system is now (γ1)pn2+c=b,γpn2=b(\gamma-1)^{p^{n}-2}+c=b,\gamma^{p^{n}-2}=b, so γ=1/b\gamma=1/b, which used in the first equation renders (1b1)pn2=bc(\frac{1}{b}-1)^{p^{n}-2}=b-c, which simplified gives b2bc+c=0b^{2}-bc+c=0 (again, bcb\neq c, since otherwise 1/b=11/b=1, and so, c=1c=1, an impossibility). By Lemma 8, a unique b2b_{2}^{\prime} exists if and only if the discriminant D2=c24c=0D_{2}=c^{2}-4c=0, so c=4c=4, and two solutions b2b_{2} exist if and only if D2[𝔽pn]2D_{2}\in[{\mathbb{F}}_{p^{n}}]^{2}, c4c\neq 4 (thus, D2[𝔽pn]2D_{2}\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}). In either case, there is a contribution of 11 to the respective cc-BCT entry.

Case 33. Let x=γx=-\gamma. The cc-boomerang system is now cγpn2=b,1c1(1γ)pn2=bc\gamma^{p^{n}-2}=b,1-c^{-1}(1-\gamma)^{p^{n}-2}=b. Thus, γ=c/b\gamma=c/b (if b=0b=0, then γ=0\gamma=0, and the second equation gives us, c1=b=0c^{-1}=b=0, an impossibility). Using γ=c/b\gamma=c/b (observe that b1b\neq 1) in the second equation we obtain b2bc2+c1c+c=0b^{2}-b\frac{c^{2}+c-1}{c}+c=0, which has a unique solution b3b_{3}^{\prime} if and only if D3=12cc22c3+c4c2=(13c+c2)(1+c+c2)c2=0D_{3}=\frac{1-2c-c^{2}-2c^{3}+c^{4}}{c^{2}}=\frac{(1-3c+c^{2})(1+c+c^{2})}{c^{2}}=0. There are two roots b3b_{3} if and only if D3[𝔽pn]2D_{3}\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}, or equivalently, (13c+c2)(1+c+c2)[𝔽pn]2(1-3c+c^{2})(1+c+c^{2})\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}.

Case 44. Let x=γ1x=-\gamma-1. The cc-boomerang system becomes 1cxpn2=b,c1(x+1)pn2=b-1-cx^{p^{n}-2}=b,-c^{-1}(x+1)^{p^{n}-2}=b. Then x=cb+1x=-\frac{c}{b+1} (if b=1b=-1, then x=0x=0, and using the second equation, we get c1=b-c^{-1}=b, that is, c=1c=1, an impossibility), which used in the second equation gives b2bc2c1c+1c=0b^{2}-b\frac{c^{2}-c-1}{c}+\frac{1}{c}=0. This equation has a root b4b_{4}^{\prime} if and only if D4=12cc22c3+c4c2=(13c+c2)(1+c+c2)c2=0D_{4}=\frac{1-2c-c^{2}-2c^{3}+c^{4}}{c^{2}}=\frac{(1-3c+c^{2})(1+c+c^{2})}{c^{2}}=0, and two roots b4b_{4} if and only if D4[𝔽pn]2D_{4}\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}, or equivalently, (13c+c2)(1+c+c2)[𝔽pn]2(1-3c+c^{2})(1+c+c^{2})\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}.

We now need to check if overlaps exist among the bb’s of various cases, and therefore the contributions to the cc-BCT entries will be added.

  • If b1b_{1} (or b1b_{1}^{\prime}) equals b2b_{2} (or b2b_{2}^{\prime}), then these must satisfy both b2+1cb+1c=0b^{2}+\frac{1}{c}b+\frac{1}{c}=0, b2bc+c=0b^{2}-bc+c=0, that is, b=c21c2+1b=\frac{c^{2}-1}{c^{2}+1}, which when used in the first equation gives 1+2c2c2+2c3+c4=01+2c-2c^{2}+2c^{3}+c^{4}=0. Observe that c=4,41c=4,4^{-1} vanish this expression if and only if p=19p=19. So, we have a contribution of 22 to the respective cc-BCT entry if and only if 1+2c2c2+2c3+c4=01+2c-2c^{2}+2c^{3}+c^{4}=0 (this includes the cases c=4,41c=4,4^{-1}).

  • If b1b_{1} (or b1b_{1}^{\prime}) equals b3b_{3} (or b3b_{3}^{\prime}), then these must satisfy both b2+1cb+1c=0b^{2}+\frac{1}{c}b+\frac{1}{c}=0, b2c2+c1cb+c=0b^{2}-\frac{c^{2}+c-1}{c}b+c=0, giving b=c1cb=\frac{c-1}{c}, which when used in the first equation implies 1=01=0, an impossibility.

  • If b1b_{1} (or b1b_{1}^{\prime}) equals b4b_{4} (or b4b_{4}^{\prime}), then these must satisfy both b2+1cb+1c=0b^{2}+\frac{1}{c}b+\frac{1}{c}=0, b2c2c1cb+1c=0b^{2}-\frac{c^{2}-c-1}{c}b+\frac{1}{c}=0, implying that either c=0,1c=0,1, or b=0b=0, none of which will work.

  • If b2b_{2} (or b2b_{2}^{\prime}) equals b3b_{3} (or b3b_{3}^{\prime}), then these must satisfy both b2bc+c=0b^{2}-bc+c=0, b2c2+c1cb+c=0b^{2}-\frac{c^{2}+c-1}{c}b+c=0, which will not work (same argument as in the previous item).

  • If b2b_{2} (or b2b_{2}^{\prime}) equals b4b_{4} (or b4b_{4}^{\prime}), then these must satisfy both b2bc+c=0b^{2}-bc+c=0, b2c2c1cb+1c=0b^{2}-\frac{c^{2}-c-1}{c}b+\frac{1}{c}=0, so b=c1b=c-1, which when replaced into the first equation gives 1=01=0, an impossibility.

  • If b3b_{3} (or b3b_{3}^{\prime}) equals b4b_{4} (or b4b_{4}^{\prime}), then these must satisfy both b2c2+c1cb+c=0b^{2}-\frac{c^{2}+c-1}{c}b+c=0, b2c2c1cb+1c=0b^{2}-\frac{c^{2}-c-1}{c}b+\frac{1}{c}=0, and so, b=c212cb=\frac{c^{2}-1}{2c}, which implies 12c2c22c3+c4=01-2c-2c^{2}-2c^{3}+c^{4}=0.

Observe that other combinations cannot occur above.

Case 55. Assume now that x0,1,γ,γ+1x\neq 0,1,\gamma,\gamma+1. Multiplying the first equation by x(x+γ)x(x+\gamma) and the second by c(x+1)(x+γ+1)c(x+1)(x+\gamma+1) renders

xc(x+γ)\displaystyle x-c(x+\gamma) =bx(x+γ)\displaystyle=bx(x+\gamma)
c(x+1)(x+γ+1)\displaystyle c(x+1)-(x+\gamma+1) =bc(x+1)(x+γ+1).\displaystyle=bc(x+1)(x+\gamma+1).

Solving for γ\gamma in the first equation, we get γ=xcxbx2c+bx\gamma=\frac{x-cx-bx^{2}}{c+bx} (observe that xc/bx\neq-c/b), which used in the second equation gives us the equation

x2+bc2+b2c+b+1c2b2cx+bcc+1b2=0,x^{2}+\frac{bc^{2}+b^{2}c+b+1-c^{2}}{b^{2}c}x+\frac{bc-c+1}{b^{2}}=0,

with a unique root xx if and only if

b4c2D5\displaystyle b^{4}c^{2}D_{5} =1+2b+b2+2b2c+2b3c2c22b2c2\displaystyle=1+2b+b^{2}+2b^{2}c+2b^{3}c-2c^{2}-2b^{2}c^{2}
+b4c2+2b2c32b3c3+c42bc4+b2c4\displaystyle\quad\quad+b^{4}c^{2}+2b^{2}c^{3}-2b^{3}c^{3}+c^{4}-2bc^{4}+b^{2}c^{4}
=(1+bc)(1c+bc)(1+b+2c+b2c+c2bc2)=0,\displaystyle=(1+b-c)(1-c+bc)(1+b+2c+b^{2}c+c^{2}-bc^{2})=0,

and two distinct roots xx if and only if

(1+bc)(1c+bc)(1+b+2c+b2c+c2bc2)[𝔽pn]2.(1+b-c)(1-c+bc)(1+b+2c+b^{2}c+c^{2}-bc^{2})\in[{\mathbb{F}}_{p^{n}}^{*}]^{2}.

Putting together our discussion, we see that the largest cc-BCT entry can only be 44; we do get that value if Case 5 is combined with combinations of the other cases cc-BCT namely, both Case 1 and Case 2, or both Case 3 and Case 4.

The proof of the theorem is done. ∎

Remark 4.

From the previous proof, we do get a lot more information about the cc-Boomerang Connectivity Table for the pp-ary inverse function, but, as for the binary case, we preferred to just give the maximum cc-BCT entries.

8 Concluding remarks

We defined a new concept, we call cc-boomerang uniformity based upon a previously defined multiplicative differential. We characterized the new concept in terms of the Walsh transforms and investigated the properties of some perfect nonlinear functions, as well as the inverse function in all characteristics via this new concept.

It would certainly be interesting to see how other perfect nonlinear, as well as almost perfect nonlinear functions behave under this new cc-boomerang uniformity.

References

  • [1] E. R. Berlekamp, H. Rumsey, G. Solomon, On the solutions of algebraic equations over finite fields, Information and Control 10 (1967), 553–564.
  • [2] E. Biham, O. Dunkelman, N. Keller, New results on boomerang and rectangle attacks, In: Daemen J., Rijmen V. (eds.), Fast Software Encryption, FSE 2002, LNCS 2365, 2002, pp. 1–16, Springer, Berlin, Heidelberg.
  • [3] A. Biryukov, D. Khovratovich, Related-key cryptanalysis of the full AES-192192 and AES-256256, In: Matsui M. (ed.), Advances in Cryptology – ASIACRYPT 2009, LNCS 5912, 2009, pp. 1–18, Springer, Berlin, Heidelberg.
  • [4] A.W. Bluher, On xq+1+ax+bx^{q+1}+ax+b, Finite Fields Appl. 10 (3) (2004), 285–305.
  • [5] N. Borisov, M. Chew, R. Johnson, D. Wagner, Multiplicative Differentials, In: Daemen J., Rijmen V. (eds.), Fast Software Encryption, FSE 2002, LNCS 2365, pp. 17–33, Springer, Berlin, Heidelberg, 2002.
  • [6] C. Boura, A. Canteaut, On the boomerang uniformity of cryptographic Sboxes, IACR Trans. Symmetric Cryptol. 3 (2018), pp. 290-310.
  • [7] C. Boura, L. Perrin, S. Tian, Boomerang Uniformity of Popular S-box Constructions, Workshop on Cryptography and Coding, Paper 15, https://www.lebesgue.fr/sites/default/files/proceedings_WCC/WCC_2019_paper_15.pdf.
  • [8] N. Bourbaki, Elements of Mathematics, Algebra II (translated by P. M. Cohn and J. Howie), Springer, Berlin, 1990.
  • [9] L. Budaghyan, Construction and Analysis of Cryptographic Functions, Springer-Verlag, 2014.
  • [10] L. Budaghyan, C. Carlet, Classes of quadratic APN trinomials and hexanomials and related structures, IEEE Trans. Inform.Theory 54:5 (2008), 2354–2357.
  • [11] M. Calderini, I.Villa, On the Boomerang Uniformity of some Permutation Polynomials, https://eprint.iacr.org/2019/881.pdf.
  • [12] C. Carlet, Boolean functions for cryptography and error correcting codes, In: Y. Crama, P. Hammer (eds.), Boolean Methods and Models, Cambridge Univ. Press, Cambridge, pp. 257–397, 2010.
  • [13] C. Carlet, Vectorial Boolean Functions for Cryptography, In: Y. Crama, P. Hammer (eds.), Boolean Methods and Models, Cambridge Univ. Press, Cambridge, pp. 398–472, 2010.
  • [14] C. Carlet, Characterizations of the Differential Uniformity of Vectorial Functions by the Walsh Transform, IEEE Trans. Inf. Theory 64:9 (2018), 6443–6453.
  • [15] F. Chabaud, S. Vaudenay, Links between differential and linear cryptanalysis, In: A. De Santis (ed.), Adv. in Crypt – EUROCRYPT ’94, LNCS 950, pp. 356–365, 1995, Springer.
  • [16] C. Cid, T. Huang, T. Peyrin, Y. Sasaki, L. Song, Boomerang Connectivity Table: A new cryptanalysis tool, In: J. B. Nielsen and V. Rijmen (eds.), Adv. in Crypt. – EUROCRYPT ’18, pp. 683–714, Cham, 2018. Springer.
  • [17] R. S. Coulter, M. Henderson, A note on the roots of trinomials over a finite field, Bull. Austral. Math. Soc. 69 (2004), 429–432.
  • [18] R. S. Coulter, R. W. Matthews, Planar functions and planes of Lenz-Barlotti class II, Des. Codes Cryptogr. 10 (1997), 167–184.
  • [19] T. W. Cusick, P. Stănică, Cryptographic Boolean Functions and Applications (Ed. 2), Academic Press, San Diego, CA, 2017.
  • [20] C. Ding, J. Yuan, A new family of skew Paley-Hadamard difference sets, J. Comb. Theory Ser. A 113 (2006), 1526–1535.
  • [21] P. Ellingsen, P. Felke, C. Riera P. Stănică, A. Tkachenko, CC-differentials, multiplicative uniformity and (almost) perfect cc-nonlinearity, to appear in IEEE Trans. Inf. Theory, 2020, DOI: 10.1109/TIT.2020.2971988.
  • [22] J. Kelsey, T. Kohno and B. Schneier, Amplified boomerang attacks against reduced-round MARS and Serpent, In: Goos G., Hartmanis J., van Leeuwen J., Schneier B. (eds,), Fast Software Encryption, FSE 2000. LNCS 1978. Springer, Berlin, Heidelberg.
  • [23] J. Kim, S. Hong, B. Preneel, E. Biham, O. Dunkelman, Related-Key Boomerang and Rectangle Attacks: Theory and Experimental Analysis, IEEE Trans. Inf. Theory 58(7) (2012), 4948–4966.
  • [24] K. Li, L. Qu, B. Sun, C. Li, New results about the boomerang uniformity of permutation polynomials, IEEE Trans. Inf. Theory 65(11) (2019), 7542–7553.
  • [25] N. Li, Z. Hu, M. Xiong, X. Zeng, 44-uniform BCT permutations from generalized butterfly structure, https://arxiv.org/abs/2001.00464.
  • [26] J. Liang, On the solutions of trinomial equations over finite fields, Bull. Cal. Math. Soc. 70 (1978), 379–382.
  • [27] S. Mesnager, Bent functions: fundamentals and results, Springer Verlag, 2016.
  • [28] S. Mesnager, C. Tang, M. Xiong, On the boomerang uniformity of quadratic permutations, https://eprint.iacr.org/2019/277.pdf.
  • [29] C. Riera, P. Stănică, Investigations on cc-(almost) perfect nonlinear functions, manuscript.
  • [30] N. Tokareva, Bent Functions, Results and Applications to Cryptography, Academic Press, San Diego, CA, 2015.
  • [31] Z. Tu, N. Li, X. Zeng, J. Zhou, A class of quadrinomial permutation with boomerang uniformity four, to appear in IEEE Trans. Inf. Theory.
  • [32] D. Wagner, The boomerang attack, In: L. R. Knudsen (ed.), Fast Software Encryption, FSE ’99, LNCS 1636, pages 156–170, 1999, Springer, Heidelberg.

9 Appendix

We list all the uniformity values for the considered functions in the paper, for 2n42\leq n\leq 4, and some values of the parameter kk, if involved, computed via SageMath. Below, α\alpha denotes a primitive root in the respective field. For p=2p=2, to construct 𝔽2n{\mathbb{F}}_{2^{n}}, 2n42\leq n\leq 4, we take the primitive polynomials, x2+x+1,x3+x+1,x4+x+1x^{2}+x+1,x^{3}+x+1,x^{4}+x+1, respectively. If p=3p=3, to construct 𝔽3n{\mathbb{F}}_{3^{n}}, 2n52\leq n\leq 5, we take the primitive polynomials, x2+2x+2,x3+2x+1,x4+2x3+2,x5+2x+1x^{2}+2x+2,x^{3}+2x+1,x^{4}+2x^{3}+2,x^{5}+2x+1, respectively. If p=5p=5, to construct 𝔽5n{\mathbb{F}}_{5^{n}}, 2n42\leq n\leq 4, we take the primitive polynomials, x2+4x+2,x3+3x+3,x4+4x2+4x+2x^{2}+4x+2,x^{3}+3x+3,x^{4}+4x^{2}+4x+2.

We will only mention the nonzero entries (surely, for some parameters, a,b,ca,b,c, Fc(a,b)=0{{}_{c}}{\mathcal{B}}_{F}(a,b)=0, but we are not concerned with that). First, if f(x)=x2f(x)=x^{2}, the possible cc-BCT entries (c0,1CLOSE(c\neq 0,1)for f(x)=x2f(x)=x^{2}, 2n42\leq n\leq 4, are [1,2][1,2] for n=2n=2, respectively, [1,2,3,4][1,2,3,4] for n=3,4n=3,4.

Table 2: Possible cc-BCT entries for the inverse f(x)=xpn2f(x)=x^{p^{n}-2}, 2n42\leq n\leq 4, p=2,3p=2,3, c0,1c\neq 0,1 pp nn possible values of Fc(a,b){{}_{c}}{\mathcal{B}}_{F}(a,b) 2 2 [1][1] 3 [1,2][1,2] 4 [1,2,3][1,2,3] 3 2 [1,2][1,2] 3 [1,2,3][1,2,3] 4 [1,2,3,4][1,2,3,4]

Table 4: Possible cc-BCT entries for the Gold f(x)=x3k+1f(x)=x^{3^{k}+1}, 2n42\leq n\leq 4, 1k31\leq k\leq 3, c0,1c\neq 0,1 kk nn possible values of Fc(a,b){{}_{c}}{\mathcal{B}}_{F}(a,b) 1 2 [1,2,4,6,9][1,2,4,6,9] 3 [1,2,3][1,2,3] 4 [1,2,3,4,5,6,7,8,9][1,2,3,4,5,6,7,8,9] 2 2 [1,2][1,2] 3 [1,2,3][1,2,3] 4 [1,2,4,72,73,81,82,90,91,100][1,2,4,72,73,81,82,90,91,100] 3 2 [1,2,4,6,9][1,2,4,6,9] 3 [1,2,3,4][1,2,3,4] 4 [1,2,3,4,5,6,7,8,9][1,2,3,4,5,6,7,8,9]

Table 6: Possible cc-BCT entries for f(x)=x3k+12f(x)=x^{\frac{3^{k}+1}{2}}, 2n42\leq n\leq 4, 1k31\leq k\leq 3, c0,1c\neq 0,1 kk nn possible values of Fc(a,b){{}_{c}}{\mathcal{B}}_{F}(a,b) 1 2 [1,2][1,2] 3 [1,2,3,4][1,2,3,4] 4 [1,2,3,4][1,2,3,4] 2 2 [1,2][1,2] 3 [1,2,3,4][1,2,3,4] 4 [1,2,3,4,5,6,7,8,9,10,12,18][1,2,3,4,5,6,7,8,9,10,12,18] 3 2 [1,2][1,2] 3 [1,2,3,4,6,7,8][1,2,3,4,6,7,8] 4 [1,2,3,4,5][1,2,3,4,5]

Let f(x)=x10x6x2f(x)=x^{10}-x^{6}-x^{2} on 𝔽32{\mathbb{F}}_{3^{2}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 22 (all cc-BCT entries of [1,2][1,2] occur): (2,2α),(α+2,α+2),(2α,2α),(α+2,2α),(2α+1,2α),(2α+1,α+2),(α,2α),(2,2),(2,α+2),(2α,α+2),(α,α+2).(2,2\alpha),(\alpha+2,\alpha+2),(2\alpha,2\alpha),(\alpha+2,2\alpha),(2\alpha+1,2\alpha),(2\alpha+1,\alpha+2),(\alpha,2\alpha),(2,2),(2,\alpha+2),(2\alpha,\alpha+2),(\alpha,\alpha+2).

Let f(x)=x10x6x2f(x)=x^{10}-x^{6}-x^{2} on 𝔽33{\mathbb{F}}_{3^{3}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 44 (all cc-BCT entries of [1,2,3,4][1,2,3,4] occur): (2α,α2),(α2+α,α2+α+1),(α2+2,α2),(2α+1,α2+α+1),(2α+2,α2+2α+1),(α2+2α,α2+2α+1).(2\alpha,\alpha^{2}),(\alpha^{2}+\alpha,\alpha^{2}+\alpha+1),(\alpha^{2}+2,\alpha^{2}),(2\alpha+1,\alpha^{2}+\alpha+1),(2\alpha+2,\alpha^{2}+2\alpha+1),(\alpha^{2}+2\alpha,\alpha^{2}+2\alpha+1).

Let f(x)=x10x6x2f(x)=x^{10}-x^{6}-x^{2} on 𝔽34{\mathbb{F}}_{3^{4}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 66 (all cc-BCT entries of [1,2,3,4,5,6][1,2,3,4,5,6] occur): (2,2α3+2α2),(2,α3+α2+2).(2,2\alpha^{3}+2\alpha^{2}),(2,\alpha^{3}+\alpha^{2}+2).

Let f(x)=x10x6x2f(x)=x^{10}-x^{6}-x^{2} on 𝔽35{\mathbb{F}}_{3^{5}} (the complexity of this computation is about 2322^{32}, and if we were to go up to n=6n=6, it would be 2402^{40} operations, so we stopped at n=5n=5). We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 66 (all cc-BCT entries of [1,2,3,4,5,6][1,2,3,4,5,6] occur):

(α4+α3+α2+2α,α4+α2+2α+1),(2α2+2α,α4+2α3+α2+1),\displaystyle(\alpha^{4}+\alpha^{3}+\alpha^{2}+2\alpha,\alpha^{4}+\alpha^{2}+2\alpha+1),(2\alpha^{2}+2\alpha,\alpha^{4}+2\alpha^{3}+\alpha^{2}+1),
(α4+α2+2,2α3+2α),(2α4+α3+α2+2α+2,α3+α2+α),\displaystyle(\alpha^{4}+\alpha^{2}+2,2\alpha^{3}+2\alpha),(2\alpha^{4}+\alpha^{3}+\alpha^{2}+2\alpha+2,\alpha^{3}+\alpha^{2}+\alpha),
(2α3+α2+α+2,α4+2α3+2α+1),(2α+1,2α4+α2+2α+2),\displaystyle(2\alpha^{3}+\alpha^{2}+\alpha+2,\alpha^{4}+2\alpha^{3}+2\alpha+1),(2\alpha+1,2\alpha^{4}+\alpha^{2}+2\alpha+2),
(α3+α2+α,α4+2α3+1),(α4+α3+2α2+2α+2,α4+2α3+2α+1),\displaystyle(\alpha^{3}+\alpha^{2}+\alpha,\alpha^{4}+2\alpha^{3}+1),(\alpha^{4}+\alpha^{3}+2\alpha^{2}+2\alpha+2,\alpha^{4}+2\alpha^{3}+2\alpha+1),
(2α4+α3+α2+2,2α4+α3+α2+2α+2),(α4+2α2,α4+α3+2α2+α+1),\displaystyle(2\alpha^{4}+\alpha^{3}+\alpha^{2}+2,2\alpha^{4}+\alpha^{3}+\alpha^{2}+2\alpha+2),(\alpha^{4}+2\alpha^{2},\alpha^{4}+\alpha^{3}+2\alpha^{2}+\alpha+1),
(2α4+α3+2α2+2α+1,2α4+α3+2α2+α+2),(2α2+2,α4+2α2+2α+1),\displaystyle(2\alpha^{4}+\alpha^{3}+2\alpha^{2}+2\alpha+1,2\alpha^{4}+\alpha^{3}+2\alpha^{2}+\alpha+2),(2\alpha^{2}+2,\alpha^{4}+2\alpha^{2}+2\alpha+1),
(α4+α3+1,2α4+α3+α2+2),(α3+2α,α4+2α2+2α+1),\displaystyle(\alpha^{4}+\alpha^{3}+1,2\alpha^{4}+\alpha^{3}+\alpha^{2}+2),(\alpha^{3}+2\alpha,\alpha^{4}+2\alpha^{2}+2\alpha+1),
(α4+2α+2,α4+α3+2α2+α+1),(α4+α3+α2+α,2α4+α2+2α+2),\displaystyle(\alpha^{4}+2\alpha+2,\alpha^{4}+\alpha^{3}+2\alpha^{2}+\alpha+1),(\alpha^{4}+\alpha^{3}+\alpha^{2}+\alpha,2\alpha^{4}+\alpha^{2}+2\alpha+2),
(2α3+1,2α4+α3+2α+2),(2α4+2α3+α+2,α4+α+1),\displaystyle(2\alpha^{3}+1,2\alpha^{4}+\alpha^{3}+2\alpha+2),(2\alpha^{4}+2\alpha^{3}+\alpha+2,\alpha^{4}+\alpha+1),
(2α3+α+2,2α4+α3+α2+2),(α4+α3+2α2+1,α4+α2+2α+1),\displaystyle(2\alpha^{3}+\alpha+2,2\alpha^{4}+\alpha^{3}+\alpha^{2}+2),(\alpha^{4}+\alpha^{3}+2\alpha^{2}+1,\alpha^{4}+\alpha^{2}+2\alpha+1),
(2α4+2α3+α2+1,α3+α2+α),(2α3+2α2+2,2α4+α3+2α+2),\displaystyle(2\alpha^{4}+2\alpha^{3}+\alpha^{2}+1,\alpha^{3}+\alpha^{2}+\alpha),(2\alpha^{3}+2\alpha^{2}+2,2\alpha^{4}+\alpha^{3}+2\alpha+2),
(α4+2α3+1,α4+α3+1),(α3+α2+2α+2,α4+α3+1),\displaystyle(\alpha^{4}+2\alpha^{3}+1,\alpha^{4}+\alpha^{3}+1),(\alpha^{3}+\alpha^{2}+2\alpha+2,\alpha^{4}+\alpha^{3}+1),
(α3+2α2+α+2,α4+2α3+α2+1),(α4+α3+α,2α3+2α),\displaystyle(\alpha^{3}+2\alpha^{2}+\alpha+2,\alpha^{4}+2\alpha^{3}+\alpha^{2}+1),(\alpha^{4}+\alpha^{3}+\alpha,2\alpha^{3}+2\alpha),
(2α2+α+2,α4+α+1),(2α3+2α2+α,2α4+α3+2α2+α+2),\displaystyle(2\alpha^{2}+\alpha+2,\alpha^{4}+\alpha+1),(2\alpha^{3}+2\alpha^{2}+\alpha,2\alpha^{4}+\alpha^{3}+2\alpha^{2}+\alpha+2),
(α2+α+2,2α4+α3+α2+2α+2),(α4+α3+2α,α4+2α3+1).\displaystyle(\alpha^{2}+\alpha+2,2\alpha^{4}+\alpha^{3}+\alpha^{2}+2\alpha+2),(\alpha^{4}+\alpha^{3}+2\alpha,\alpha^{4}+2\alpha^{3}+1).

Let f(x)=x10+x6x2f(x)=x^{10}+x^{6}-x^{2} on 𝔽32{\mathbb{F}}_{3^{2}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 22 (all cc-BCT entries of [1,2][1,2] occur): (2,2α+1),(2α+1,α),(2α,2α+1),(α,α),(α+2,2α+1),(2α+1,2α+1),(2,1),(2α,α),(2,α),(α,2α+1),(α+2,α).(2,2\alpha+1),(2\alpha+1,\alpha),(2\alpha,2\alpha+1),(\alpha,\alpha),(\alpha+2,2\alpha+1),(2\alpha+1,2\alpha+1),(2,1),(2\alpha,\alpha),(2,\alpha),(\alpha,2\alpha+1),(\alpha+2,\alpha).

Let f(x)=x10+x6x2f(x)=x^{10}+x^{6}-x^{2} on 𝔽33{\mathbb{F}}_{3^{3}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 33 (all cc-BCT entries of [1,2,3][1,2,3] occur):

(α2+α+2,α2+2α+2),(2α2+2α,α2+2α+2),(α2+α+2,α+1),(α2+2,2),(α2+1,α),\displaystyle(\alpha^{2}+\alpha+2,\alpha^{2}+2\alpha+2),(2\alpha^{2}+2\alpha,\alpha^{2}+2\alpha+2),(\alpha^{2}+\alpha+2,\alpha+1),(\alpha^{2}+2,2),(\alpha^{2}+1,\alpha),
(2α2,α+1),(2α2+α+2,α),(α2+2α+2,α),(α,α2+α+2),(2α+1,2α2+2),(α2+α,2),\displaystyle(2\alpha^{2},\alpha+1),(2\alpha^{2}+\alpha+2,\alpha),(\alpha^{2}+2\alpha+2,\alpha),(\alpha,\alpha^{2}+\alpha+2),(2\alpha+1,2\alpha^{2}+2),(\alpha^{2}+\alpha,2),
(α2+α,2α2+2),(2α+1,2),(2α,2),(α2+α+2,α+2),(α2+α+1,2α2+2α+1),\displaystyle(\alpha^{2}+\alpha,2\alpha^{2}+2),(2\alpha+1,2),(2\alpha,2),(\alpha^{2}+\alpha+2,\alpha+2),(\alpha^{2}+\alpha+1,2\alpha^{2}+2\alpha+1),
(2α2+2α+2,α),(α2+2,2α2+α+1),(2α2+1,α2+α+2),(α2+2α+1,2α2+α+1),\displaystyle(2\alpha^{2}+2\alpha+2,\alpha),(\alpha^{2}+2,2\alpha^{2}+\alpha+1),(2\alpha^{2}+1,\alpha^{2}+\alpha+2),(\alpha^{2}+2\alpha+1,2\alpha^{2}+\alpha+1),
(2α,2α2+α+1),(2α+2,2α2+2α+1),(α+1,α2+1),(2α2,α+2),(2α2+2,2α2+α+1),\displaystyle(2\alpha,2\alpha^{2}+\alpha+1),(2\alpha+2,2\alpha^{2}+2\alpha+1),(\alpha+1,\alpha^{2}+1),(2\alpha^{2},\alpha+2),(2\alpha^{2}+2,2\alpha^{2}+\alpha+1),
(α2,2α2+2),(α2+2α,2α2+2α+1),(α2+2α+2,α2+1),(α+2,α2+2α+2),(2α+2,2),\displaystyle(\alpha^{2},2\alpha^{2}+2),(\alpha^{2}+2\alpha,2\alpha^{2}+2\alpha+1),(\alpha^{2}+2\alpha+2,\alpha^{2}+1),(\alpha+2,\alpha^{2}+2\alpha+2),(2\alpha+2,2),
(2α2,α2+2α+2),(2α2+α+2,α2+α+2),(2α2+2α+2,α+1),(α2+2α+2,α+1),\displaystyle(2\alpha^{2},\alpha^{2}+2\alpha+2),(2\alpha^{2}+\alpha+2,\alpha^{2}+\alpha+2),(2\alpha^{2}+2\alpha+2,\alpha+1),(\alpha^{2}+2\alpha+2,\alpha+1),
(2α2+α+1,2α2+2α+1),(2α2+α+2,α+2),(α2+1,α+2),(α2+2α,2),\displaystyle(2\alpha^{2}+\alpha+1,2\alpha^{2}+2\alpha+1),(2\alpha^{2}+\alpha+2,\alpha+2),(\alpha^{2}+1,\alpha+2),(\alpha^{2}+2\alpha,2),
(α2+1,α2+α+2),(2α2+α,α2+1),(2α2+2α+1,2α2+2),(2α2+2α+2,α2+1).\displaystyle(\alpha^{2}+1,\alpha^{2}+\alpha+2),(2\alpha^{2}+\alpha,\alpha^{2}+1),(2\alpha^{2}+2\alpha+1,2\alpha^{2}+2),(2\alpha^{2}+2\alpha+2,\alpha^{2}+1).

Let f(x)=x10+x6x2f(x)=x^{10}+x^{6}-x^{2} on 𝔽34{\mathbb{F}}_{3^{4}}. We list all values of (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 77 (all cc-BCT entries of [1,2,3,4,5,6,7][1,2,3,4,5,6,7] occur): (α2+2α+1,2α3+2α2+1),(α2+α+2,α3+α2),(α3+2α+1,α3+α2),(2α3+α2+α,2α3+2CLOSE.(\alpha^{2}+2\alpha+1,2\alpha^{3}+2\alpha^{2}+1),(\alpha^{2}+\alpha+2,\alpha^{3}+\alpha^{2}),(\alpha^{3}+2\alpha+1,\alpha^{3}+\alpha^{2}),(2\alpha^{3}+\alpha^{2}+\alpha,2\alpha^{3}+2.

Let f(x)=x10+x6x2f(x)=x^{10}+x^{6}-x^{2} on 𝔽35{\mathbb{F}}_{3^{5}}. There are 160160 pairs (c,b)(c,b), for which the cc-DDT entry (for some aa) equals the cc-boomerang uniformity of 55 (all cc-BCT entries of [1,2,3,4,5][1,2,3,4,5] occur). We shall list here only the 140140 different values of cc:

2α+α3+α4,2+2α2+α3,1+2α3,1+α+α2,2+α2+α4,1+α+2α3,α+α2,2α+α2,1+2α,1+2α+α2,\displaystyle 2\alpha+\alpha^{3}+\alpha^{4},2+2\alpha^{2}+\alpha^{3},1+2\alpha^{3},1+\alpha+\alpha^{2},2+\alpha^{2}+\alpha^{4},1+\alpha+2\alpha^{3},\alpha+\alpha^{2},2\alpha+\alpha^{2},1+2\alpha,1+2\alpha+\alpha^{2},
1+2α+α2+2α3,α2,1+α+α3,α+2α2+2α3+2α4,2+2α+α2+α4,1+2α+2α2+2α4,1+2α+α3+α4,\displaystyle 1+2\alpha+\alpha^{2}+2\alpha^{3},\alpha^{2},1+\alpha+\alpha^{3},\alpha+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+2\alpha+\alpha^{2}+\alpha^{4},1+2\alpha+2\alpha^{2}+2\alpha^{4},1+2\alpha+\alpha^{3}+\alpha^{4},
2+α+α2+2α3+2α4,2+2α,α2+α3,2+2α+α2+2α3+α4,α4,α+2α2+2α3+α4,1+α+α3+α4,α3+2α4,\displaystyle 2+\alpha+\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+2\alpha,\alpha^{2}+\alpha^{3},2+2\alpha+\alpha^{2}+2\alpha^{3}+\alpha^{4},\alpha^{4},\alpha+2\alpha^{2}+2\alpha^{3}+\alpha^{4},1+\alpha+\alpha^{3}+\alpha^{4},\alpha^{3}+2\alpha^{4},
1+α3,2+α+2α2+2α3+2α4,2α+2α2+α3+α4,2α+2α2+α3,1+2α+2α2+2α3,2α+2α2+α4,2α+α2+α3,\displaystyle 1+\alpha^{3},2+\alpha+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},2\alpha+2\alpha^{2}+\alpha^{3}+\alpha^{4},2\alpha+2\alpha^{2}+\alpha^{3},1+2\alpha+2\alpha^{2}+2\alpha^{3},2\alpha+2\alpha^{2}+\alpha^{4},2\alpha+\alpha^{2}+\alpha^{3},
1+α2+2α4,1+α2+2α3+2α4,1+α+α2+α4,α2+α4,α2+α3+2α4,2+2α4,2+2α+2α4,2α+α2+α4,\displaystyle 1+\alpha^{2}+2\alpha^{4},1+\alpha^{2}+2\alpha^{3}+2\alpha^{4},1+\alpha+\alpha^{2}+\alpha^{4},\alpha^{2}+\alpha^{4},\alpha^{2}+\alpha^{3}+2\alpha^{4},2+2\alpha^{4},2+2\alpha+2\alpha^{4},2\alpha+\alpha^{2}+\alpha^{4},
α+α3+2α4,2+2α+2α2+α4,1+α,2+2α2+α3+2α4,α2+2α3+α4,2+α2+α3,α+α2+2α4,α2+2α3,\displaystyle\alpha+\alpha^{3}+2\alpha^{4},2+2\alpha+2\alpha^{2}+\alpha^{4},1+\alpha,2+2\alpha^{2}+\alpha^{3}+2\alpha^{4},\alpha^{2}+2\alpha^{3}+\alpha^{4},2+\alpha^{2}+\alpha^{3},\alpha+\alpha^{2}+2\alpha^{4},\alpha^{2}+2\alpha^{3},
α+2α4,1+α3+α4,2+2α+2α3+2α4,1+α2,2α+α2+2α3+2α4,2+2α+α4,2+α+α2+2α3+α4,\displaystyle\alpha+2\alpha^{4},1+\alpha^{3}+\alpha^{4},2+2\alpha+2\alpha^{3}+2\alpha^{4},1+\alpha^{2},2\alpha+\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+2\alpha+\alpha^{4},2+\alpha+\alpha^{2}+2\alpha^{3}+\alpha^{4},
1+α+α2+α3+2α4,α+2α2+α3+2α4,2+α+α3,1+α+α3+2α4,α3,2+α+2α2+2α4,2+α2+α3+2α4,\displaystyle 1+\alpha+\alpha^{2}+\alpha^{3}+2\alpha^{4},\alpha+2\alpha^{2}+\alpha^{3}+2\alpha^{4},2+\alpha+\alpha^{3},1+\alpha+\alpha^{3}+2\alpha^{4},\alpha^{3},2+\alpha+2\alpha^{2}+2\alpha^{4},2+\alpha^{2}+\alpha^{3}+2\alpha^{4},
1+2α+α2+α3,2α+α2+2α3,2α+α4,1+α+2α2+α3+2α4,2+2α2+2α3+α4,1+2α+α2+2α3+α4,\displaystyle 1+2\alpha+\alpha^{2}+\alpha^{3},2\alpha+\alpha^{2}+2\alpha^{3},2\alpha+\alpha^{4},1+\alpha+2\alpha^{2}+\alpha^{3}+2\alpha^{4},2+2\alpha^{2}+2\alpha^{3}+\alpha^{4},1+2\alpha+\alpha^{2}+2\alpha^{3}+\alpha^{4},
1+2α3+2α4,2+2α2+2α3,1+2α2+α3+2α4,2+α2+2α4,2+2α3,1+α+α2+2α3+α4,α+α2+α3+α4,\displaystyle 1+2\alpha^{3}+2\alpha^{4},2+2\alpha^{2}+2\alpha^{3},1+2\alpha^{2}+\alpha^{3}+2\alpha^{4},2+\alpha^{2}+2\alpha^{4},2+2\alpha^{3},1+\alpha+\alpha^{2}+2\alpha^{3}+\alpha^{4},\alpha+\alpha^{2}+\alpha^{3}+\alpha^{4},
1+2α+2α2+2α3+2α4,2+2α2+2α3+2α4,2+α2+2α3+2α4,2+α+2α2+α4,α+α2+α3,2α+2α4,\displaystyle 1+2\alpha+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+\alpha+2\alpha^{2}+\alpha^{4},\alpha+\alpha^{2}+\alpha^{3},2\alpha+2\alpha^{4},
α+α2+2α3,2α2,2+α+α2+2α3,1+2α+2α2+2α3+α4,1+α+α2+α3+α4,2+α3+α4,α+2α2+α3,\displaystyle\alpha+\alpha^{2}+2\alpha^{3},2\alpha^{2},2+\alpha+\alpha^{2}+2\alpha^{3},1+2\alpha+2\alpha^{2}+2\alpha^{3}+\alpha^{4},1+\alpha+\alpha^{2}+\alpha^{3}+\alpha^{4},2+\alpha^{3}+\alpha^{4},\alpha+2\alpha^{2}+\alpha^{3},
2+α2+2α3,α+2α2,α,1+2α+α2+α3+α4,α+2α2+2α4,2+2α+2α2+α3+α4,α+α3+α4,\displaystyle 2+\alpha^{2}+2\alpha^{3},\alpha+2\alpha^{2},\alpha,1+2\alpha+\alpha^{2}+\alpha^{3}+\alpha^{4},\alpha+2\alpha^{2}+2\alpha^{4},2+2\alpha+2\alpha^{2}+\alpha^{3}+\alpha^{4},\alpha+\alpha^{3}+\alpha^{4},
2α2+α4,1+α+2α2+2α4,2α2+2α3,2α+α2+2α3+α4,1+2α+2α4,2α3+2α4,2α+α2+α3+2α4,\displaystyle 2\alpha^{2}+\alpha^{4},1+\alpha+2\alpha^{2}+2\alpha^{4},2\alpha^{2}+2\alpha^{3},2\alpha+\alpha^{2}+2\alpha^{3}+\alpha^{4},1+2\alpha+2\alpha^{4},2\alpha^{3}+2\alpha^{4},2\alpha+\alpha^{2}+\alpha^{3}+2\alpha^{4},
1+2α2+2α3+2α4,2+α+2α3+α4,α+2α2+α4,2+α+α4,2α2+2α3+α4,1+2α+2α3+2α4,2+α+2α3,\displaystyle 1+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+\alpha+2\alpha^{3}+\alpha^{4},\alpha+2\alpha^{2}+\alpha^{4},2+\alpha+\alpha^{4},2\alpha^{2}+2\alpha^{3}+\alpha^{4},1+2\alpha+2\alpha^{3}+2\alpha^{4},2+\alpha+2\alpha^{3},
2+α+2α4,2α2+α3+2α4,α+2α3,2+2α+2α2+α3,2+α+α2+2α4,α+α2+α4,2+2α3+α4,α+α4,\displaystyle 2+\alpha+2\alpha^{4},2\alpha^{2}+\alpha^{3}+2\alpha^{4},\alpha+2\alpha^{3},2+2\alpha+2\alpha^{2}+\alpha^{3},2+\alpha+\alpha^{2}+2\alpha^{4},\alpha+\alpha^{2}+\alpha^{4},2+2\alpha^{3}+\alpha^{4},\alpha+\alpha^{4},
1+2α2+α4,α2+α3+α4,2+2α+2α2+2α3,α+2α3+α4,2+α+2α2+2α3+α4,1+2α3+α4,\displaystyle 1+2\alpha^{2}+\alpha^{4},\alpha^{2}+\alpha^{3}+\alpha^{4},2+2\alpha+2\alpha^{2}+2\alpha^{3},\alpha+2\alpha^{3}+\alpha^{4},2+\alpha+2\alpha^{2}+2\alpha^{3}+\alpha^{4},1+2\alpha^{3}+\alpha^{4},
2+2α+α2+α3+2α4,α+α2+2α3+2α4,2+2α+2α2+α3+2α4,1+2α4,2+α+α2,2+α2+2α3+α4,\displaystyle 2+2\alpha+\alpha^{2}+\alpha^{3}+2\alpha^{4},\alpha+\alpha^{2}+2\alpha^{3}+2\alpha^{4},2+2\alpha+2\alpha^{2}+\alpha^{3}+2\alpha^{4},1+2\alpha^{4},2+\alpha+\alpha^{2},2+\alpha^{2}+2\alpha^{3}+\alpha^{4},
1+α+α2+α3,1+α+α2+2α4,2+2α2+2α4,2+2α+α2+α3,1+α3+2α4,2+2α+α3+α4,\displaystyle 1+\alpha+\alpha^{2}+\alpha^{3},1+\alpha+\alpha^{2}+2\alpha^{4},2+2\alpha^{2}+2\alpha^{4},2+2\alpha+\alpha^{2}+\alpha^{3},1+\alpha^{3}+2\alpha^{4},2+2\alpha+\alpha^{3}+\alpha^{4},
α2+2α3+2α4,2α2+2α4,2+2α+2α2+2α3+2α4,1+2α+α2+2α3+2α4,,2α+2α2+2α3+α4.\displaystyle\alpha^{2}+2\alpha^{3}+2\alpha^{4},2\alpha^{2}+2\alpha^{4},2+2\alpha+2\alpha^{2}+2\alpha^{3}+2\alpha^{4},1+2\alpha+\alpha^{2}+2\alpha^{3}+2\alpha^{4},,2\alpha+2\alpha^{2}+2\alpha^{3}+\alpha^{4}.