Skip to main content
QUICK REVIEW

[Paper Review] A lower bound on the number of inequivalent APN functions

Christian Kaspers, Yue Zhou|arXiv (Cornell University)|Feb 3, 2020
Coding theory and cryptography10 references4 citations
TL;DR

This paper establishes a lower bound on the number of CCZ-inequivalent almost perfect nonlinear (APN) functions over finite fields of size $\mathbb{F}_{2^{2m}}$ for even $m \geq 4$. It proves that Pott-Zhou APN functions—parameterized by $k$, $s$, and $\alpha$—are pairwise CCZ-inequivalent when $k$ and $s$ differ, yielding a lower bound of $\left(\left\lfloor \frac{m}{4} \right\rfloor + 1\right) \cdot \frac{\phi(m)}{2}$ inequivalent functions. The automorphism groups of these functions are also fully characterized.

ABSTRACT

In this paper, we establish a lower bound on the total number of inequivalent APN functions on the finite field with $2^{2m}$ elements, where $m$ is even. We obtain this result by proving that the APN functions introduced by Pott and the second author, that depend on three parameters $k$, $s$ and $α$, are pairwise inequivalent for distinct choices of the parameters $k$ and $s$. Moreover, we determine the automorphism group of these APN functions.

Motivation & Objective

  • To determine a lower bound on the number of CCZ-inequivalent APN functions over $\mathbb{F}_{2^{2m}}$ for even $m \geq 4$.
  • To prove that Pott-Zhou APN functions with distinct parameters $k$ and $s$ are CCZ-inequivalent.
  • To characterize the automorphism groups of Pott-Zhou APN functions under CCZ- and EA-equivalence.
  • To address the open problem of the total number of inequivalent APN functions on $\mathbb{F}_{2^n}$, particularly for $n$ divisible by 4.
  • To provide a benchmark for the growth of inequivalent APN functions in even-dimensional vector spaces over $\mathbb{F}_2$.

Proposed method

  • Uses bivariate representation of Pott-Zhou APN functions: $f_{k,s,\alpha}(x,y) = \left( x^{2^k+1} + \alpha y^{(2^k+1)2^s}, xy \right)$.
  • Applies CCZ-equivalence theory to analyze when two such functions are equivalent.
  • Employs algebraic techniques involving linearized polynomials and properties of finite fields to derive conditions under which equivalence fails.
  • Analyzes the automorphism group by solving functional equations over $\mathbb{F}_{2^m}$, particularly focusing on the structure of solutions to $a^{2^k+1} = c$ and $\alpha^{2^u-1} = 1$.
  • Uses computational verification in Magma for small cases ($m = 2, 4$) to confirm theoretical results.
  • Relies on number-theoretic tools such as Euler's totient function $\phi(m)$ to count valid parameter choices.

Experimental results

Research questions

  • RQ1Are Pott-Zhou APN functions with different parameters $k$ and $s$ always CCZ-inequivalent?
  • RQ2What is the exact size of the automorphism group of a Pott-Zhou APN function for even $m$?
  • RQ3Can the number of CCZ-inequivalent APN functions over $\mathbb{F}_{2^{2m}}$ be bounded from below for even $m$?
  • RQ4How does the structure of the Pott-Zhou construction compare to other known families of quadratic APN functions in terms of equivalence?
  • RQ5Does the lower bound on the number of inequivalent APN functions extend to dimensions not divisible by 4?

Key findings

  • The number of CCZ-inequivalent Pott-Zhou APN functions over $\mathbb{F}_{2^{2m}}$ is at least $\left(\left\lfloor \frac{m}{4} \right\rfloor + 1\right) \cdot \frac{\phi(m)}{2}$ for even $m \geq 4$.
  • Two Pott-Zhou APN functions $f_{k,s,\alpha}$ and $f_{\ell,t,\beta}$ are CCZ-equivalent if and only if $k = \ell$ and $s = t$, proving their pairwise inequivalence for distinct $k,s$.
  • The linear automorphism group $\operatorname{Aut}_L(f_{k,s})$ has order $3m(2^m - 1)$ if $s \in \{0, m/2\}$, and $\frac{3}{2}m(2^m - 1)$ otherwise.
  • The full automorphism group $\operatorname{Aut}(f_{k,s})$ has order $3m \cdot 2^m (2^m - 1)$ if $s \in \{0, m/2\}$, and $3m \cdot 2^{m-1} (2^m - 1)$ otherwise.
  • For $m = 2$, the unique Pott-Zhou APN function is linearly equivalent to the Gold function $x \mapsto x^3$, with $|\operatorname{Aut}_L(f_{1,0})| = 360$ and $|\operatorname{Aut}(f_{1,0})| = 5760$.
  • The lower bound $\frac{m\sqrt{m}}{2}$ holds for $m > 2^{10}$, and the upper bound $\frac{m(m+4)}{16}$ is sharp when $m$ is a power of 2.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.