[論文レビュー] On the Differential-Linear Connectivity Table of Vectorial Boolean Functions
本稿は、ベクトル値ブール関数の微分線形接続表(DLCT)の理論的基盤を確立し、関数の自己相関と関連づけることで、ワルシュ変換および微分分布表を用いて特徴づけ、絶対指標の上限を導出する。本稿では、DLCTにおける最大絶対値が(2倍の係数を除き)絶対指標と一致することを証明し、(n,n)-置換のDLCT要素が4の倍数であることを示し、アフィンおよびEA同値性に関して不変であるが、CCZ同値性に関しては不変でないことを示している。
Vectorial Boolean functions are crucial building-blocks in symmetric ciphers. Different known attacks on block ciphers have resulted in diverse cryptographic criteria for vectorial Boolean functions, such as differential uniformity and nonlinearity. Very recently, Bar-On et al. introduced at Eurocrypt'19 a new tool, called the differential-linear connectivity table (DLCT), which allows for taking into account the dependency between the two subciphers $E_0$ and $E_1$ involved in differential-linear attacks. This new notion leads to significant improvements of differential-linear attacks on several ciphers. This paper presents a theoretical characterization of the DLCT of vectorial Boolean functions and also investigates this new criterion for some families of functions with specific forms. More precisely, we firstly reveal the connection between the DLCT and the autocorrelation of vectorial Boolean functions, we characterize properties of the DLCT by means of the Walsh transform of the function and of its differential distribution table, and we present generic bounds on the highest magnitude occurring in the DLCT of vectorial Boolean functions, which coincides (up to a factor~\(2\)) with the well-established notion of absolute indicator. Next, we investigate the invariance property of the DLCT of vectorial Boolean functions under the affine, extended-affine, and Carlet-Charpin-Zinoviev (CCZ) equivalence and exhaust the DLCT spectra of optimal $4$-bit S-boxes under affine equivalence. Furthermore, we study the DLCT of APN, plateaued and AB functions and establish its connection with other cryptographic criteria. Finally, we investigate the DLCT and the absolute indicator of some specific polynomials with optimal or low differential uniformity, including monomials, cubic functions, quadratic functions and inverses of quadratic permutations.
研究の動機と目的
- ベクトル値ブール関数の微分線形接続表(DLCT)の理論的特徴づけを提供すること。
- DLCTとベクトル値ブール関数の自己相関との関係を調査すること。
- $(n,m)$-関数の絶対指標の一般的な下界を導出し、その可除性の性質を研究すること。
- アフィン、拡張アフィン(EA)、およびCCZ同値性に関して、DLCTおよび自己相関スペクトルの不変性を分析すること。
- アフィン同値性の下で、最適な4ビットSボックスの自己相関スペクトルを体系的に特定し、APN、プレートウッド、AB関数などの特殊クラスを研究すること。
提案手法
- DLCTとベクトル値ブール関数の自己相関表との間の直接的な同等性(2倍の係数を除き)を確立した。
- 関数のワルシュ変換および微分分布表(DDT)を用いてDLCTを特徴づけた。
- DDTおよびワルシュスペクトルの性質を用いて、特に$m \geq n$の場合に、$(n,m)$-関数の絶対指標の一般的な下界を導出した。
- ベクトル値ブール関数の自己相関の可除性に関する性質に基づき、任意の$(n,n)$-置換の自己相関係数が4の倍数であることを証明した。
- アフィン、EA、CCZ同値性に関して、自己相関スペクトルの不変性を分析し、アフィン同値性に関して不変であり、最大絶対値がEA同値性に関して不変であるが、CCZ同値性に関しては不変でないことを示した。
- レアンダーとポシュマンによる分類を用いて、すべての最適な4ビットSボックスの自己相関スペクトルを体系的に計算し、単項式、立方、二次、および二次置換の逆関数などの特殊多項式を研究した。
実験結果
リサーチクエスチョン
- RQ1ベクトル値ブール関数のDLCTは、その自己相関表とどのように関係しているか。この関係は形式的に特徴づけられるか。
- RQ2$(n,m)$-関数の絶対指標(すなわち、最初の行および列を除くDLCTにおける最大絶対値)の一般的な上限は何か。また、既知の暗号的基準とどのように関連しているか。
- RQ3DLCTはアフィン、EA、CCZ同値性に関してどの程度不変であるか。Sボックスの分類に与える影響は何か。
- RQ4APN、プレートウッド、AB関数の自己相関スペクトルは、関連するバランスの取れたブール関数のワルシュ変換とどのように関係しているか。
- RQ5微分均一性が低い単項式、立方関数、二次関数、および二次置換の逆関数の正確な自己相関スペクトルは何か。
主な発見
- 任意のベクトル値ブール関数のDLCTにおける最大絶対値は(2倍の係数を除き)、絶対指標と一致する。これは、暗号的分野で広く知られた測定指標である。
- 任意の$(n,n)$-置換の自己相関係数は4の倍数である。これは、このような関数のDLCTに強い構造的制約をもたらす。
- 自己相関スペクトルはアフィン同値性に関して不変であり、最大絶対値は拡張アフィン(EA)同値性に関して不変であるが、CCZ同値性に関しては不変でない。
- 有限体$\mathbb{F}_{2^n}$上でのゴールドAPN置換$F(x) = x^{2^i+1}$の逆関数の絶対指標は、$n > 5$のとき$2^{(n+1)/2}$より厳密に大きい。これは、それがABでないことを示している。
- n=5の場合、すべてのゴールドAPN置換の逆関数の絶対指標は正確に8である。これは最適ケースにおける明確な定量的値を確認するものである。
- APNおよびAB関数の自己相関は、特定のクラスのバランスの取れたブール関数のワルシュ変換として表現可能であり、DLCTの性質と既知のスペクトル的特性を結びつける。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。