[论文解读] On the boomerang uniformity of (quadratic) permutations over $F_{2^n}$
本论文为 $\mathbb{F}_{2^n}$ 上的二次置换提出了一种新的回旋均匀性公式,将其与二阶导数的零点联系起来。研究证明,在偶数维下,差分均匀性为 4 的二次置换,其回旋均匀性也为 4,从而建立了一个新的最优 S盒家族,适用于对称密码学并具备抵抗回旋攻击的能力。
At Eurocrypt'18, Cid, Huang, Peyrin, Sasaki, and Song introduced a new tool called Boomerang Connectivity Table (BCT) for measuring the resistance of a block cipher against the boomerang attack (which is an important cryptanalysis technique introduced by Wagner in 1999 against block ciphers). Next, Boura and Canteaut introduced an important parameter (related to the BCT) for cryptographic Sboxes called boomerang uniformity. In this context, we present a brief state-of-the-art on the notion of boomerang uniformity of vectorial functions (or Sboxes) and provide new results. More specifically, we present a slightly different (and more convenient) formulation of the boomerang uniformity and show that the row sum and the column sum of the boomerang connectivity table can be expressed in terms of the zeros of the second-order derivative of the permutation or its inverse. Most importantly, we specialize our study of boomerang uniformity to quadratic permutations in even dimension and generalize the previous results on quadratic permutation with optimal BCT (optimal means that the maximal value in the Boomerang Connectivity Table equals the lowest known differential uniformity). As a consequence of our general result, we prove that the boomerang uniformity of the binomial differentially $4$-uniform permutations presented by Bracken, Tan, and Tan equals $4$. This result gives rise to a new family of optimal Sboxes.
研究动机与目标
- 改进并简化向量函数回旋均匀性的表述。
- 建立回旋均匀性与置换二阶导数之间的联系。
- 推广关于具有最优回旋连通性表(BCT)的二次置换的现有结果。
- 证明 Bracken、Tan 和 Tan 提出的二项式差分 4-均匀置换具有回旋均匀性 4。
- 识别在偶数维下具有最优回旋均匀性的新二次置换家族。
提出的方法
- 利用置换的二阶导数,提出回旋均匀性的修订公式。
- 将回旋连通性表(BCT)的行和列和表示为 $F$ 或 $F^{-1}$ 的二阶导数的零点。
- 分析 $\mathbb{F}_{2^n}$ 上偶数维的二次置换,重点关注差分均匀性为 4 的情况。
- 通过证明 BCT 中的最大值受差分均匀性限制,证明此类置换的回旋均匀性等于 4。
- 利用有限域的代数恒等式和性质,证明在特定条件下 $\mathrm{BCT}_F(a,b) \leq q$,从而得出 $\beta(F) = q$。
- 将一般结果应用于已知构造,包括 $F(x) = x^{2^t+1}$ 和 $F(x) = x^{2^m+2} + \lambda x$,并验证其回旋均匀性。
实验结果
研究问题
- RQ1能否更方便地利用二阶导数表征二次置换的回旋均匀性?
- RQ2BCT 的行和列和与置换的二阶导数的零点之间存在何种关系?
- RQ3所有在 $\mathbb{F}_{2^n}$ 上差分均匀性为 4 且 $n$ 为偶数的二次置换是否都具有回旋均匀性 4?
- RQ4该一般结果能否用于构造具有最优回旋均匀性的新置换家族?
- RQ5在已知构造之外,是否存在大量具有最优 BCT 的二次置换示例?
主要发现
- 对于满足 $n \equiv 2 \pmod{4}$ 且 $\gcd(t,n) = 2$ 的二项式差分 4-均匀置换 $F(x) = x^{2^t+1}$,其回旋均匀性恰好为 4。
- 对于满足 $n = 2m$、$m$ 为奇数、且 $\lambda$ 在 $\mathbb{F}_{2^n}^*$ 中阶为 3 的置换 $F(x) = x^{2^m+2} + \lambda x$,其回旋均匀性为 4。
- 一般性结果证明:任何在 $\mathbb{F}_{2^n}$ 上差分均匀性为 4 且 $n$ 为偶数的二次置换,其回旋均匀性均为 4。
- 此外,由 $F(x) = \beta x^{2^s+1} + \beta^{2^k} x^{2^{-k}+2^{k+s}}$ 定义的另一类置换,其中 $n=3k$、$k \equiv 2 \pmod{4}$、$3 \nmid k$,且 $\gcd(n,s)=2$,其回旋均匀性也为 4。
- 在 $\mathbb{F}_{2^6}$ 上的数值实验表明,存在 960 个形如 $F(x) = x^{2^{s+1}+2} + A x + B x^4 + C x^{16}$ 的二次置换,满足 $\gcd(n,s)=2$ 且 $n \equiv 2 \pmod{4}$,其 BCT 为最优。
- 此类置换的数量超过文献 [4, Proposition 8] 和 [23, Theorem 5.3] 中已知的构造,表明存在大量最优 S盒。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。