The optimal branch number of MDS matrices makes them a preferred choice for designing diffusion layers in many block ciphers and hash functions. Consequently, various methods have been proposed for designing MDS matrices, including search and direct methods. While exhaustive search is suitable for small order MDS matrices, direct constructions are preferred for larger orders due to the vast search space involved. In the literature, there has been extensive research on the direct construction of MDS matrices using both recursive and nonrecursive methods. On the other hand, in lightweight cryptography, Near-MDS (NMDS) matrices with sub-optimal branch numbers offer a better balance between security and efficiency as a diffusion layer compared to MDS matrices. However, no direct construction method is available in the literature for constructing recursive NMDS matrices. This paper introduces some direct constructions of NMDS matrices in both nonrecursive and recursive settings. Additionally, it presents some direct constructions of nonrecursive MDS matrices from the generalized Vandermonde matrices. We propose a method for constructing involutory MDS and NMDS matrices using generalized Vandermonde matrices. Furthermore, we prove some folklore results that are used in the literature related to the NMDS code.
翻译:MDS矩阵的最优分支数使其成为众多分组密码和哈希函数中设计扩散层的首选结构。因此,研究人员提出了多种MDS矩阵设计方法,包括搜索法和直接构造法。穷举搜索适用于低阶MDS矩阵,而高阶矩阵由于搜索空间巨大,更倾向于采用直接构造法。现有文献已对递归与非递归两类直接构造MDS矩阵的方法展开了广泛研究。另一方面,在轻量级密码学中,具有次优分支数的近MDS(NMDS)矩阵作为扩散层,相比MDS矩阵能在安全性与效率之间取得更优平衡。然而,目前尚无文献提出递归型NMDS矩阵的直接构造方法。本文首次提出非递归与递归两类NMDS矩阵的直接构造方案,同时基于广义范德蒙德矩阵给出若干非递归MDS矩阵的直接构造方法。我们提出利用广义范德蒙德矩阵构造对合型MDS与NMDS矩阵的方法。此外,本文还证明了文献中若干与NMDS编码相关的未经验证结论。