A substitution box (S-box) in a symmetric primitive is a mapping $F$ that takes $k$ binary inputs and whose image is a binary $m$-tuple for some positive integers $k$ and $m$, which is usually the only nonlinear element of the most modern block ciphers. Therefore, employing S-boxes with good cryptographic properties to resist various attacks is significant. For power permutation $F$ over finite field $\GF{2^k}$, the multiset of values $\beta_F(1,b)=\#\{x\in \GF{2^k}\mid F^{-1}(F(x)+b)+F^{-1}(F(x+1)+b)=1\}$ for $b\in \GF{2^k}$ is called the boomerang spectrum of $F$. The maximum value in the boomerang spectrum is called boomerang uniformity. This paper determines the boomerang spectrum of the power permutation $X^{2^{3n}+2^{2n}+2^{n}-1}$ over $\GF{2^{4n}}$. The boomerang uniformity of that power permutation is $3(2^{2n}-2^n)$. However, on a large subset $\{b\in \GF{2^{4n}}\mid \mathbf{Tr}_n^{4n}(b)\neq 0\}$ of $\GF{2^{4n}}$ of cardinality $2^{4n}-2^{3n}$ (where $ \mathbf{Tr}_n^{4n}$ is the (relative) trace function from $\GF{2^{4n}}$ to $\GF{2^{n}}$), we prove that the studied function $F$ achieves the optimal boomerang uniformity $2$. It is known that obtaining such functions is a challenging problem. More importantly, the set of $b$'s giving this value is explicitly determined for any value in the boomerang spectrum.
翻译:摘要:对称密码原语中的替换盒(S-box)是一个映射 $F$,它接收 $k$ 个二进制输入,并输出一个二进制 $m$ 元组(其中 $k$ 和 $m$ 为正整数),通常是现代分组密码中唯一的非线性元素。因此,采用具有良好密码学性质以抵抗各种攻击的S-box至关重要。对于有限域 $\GF{2^k}$ 上的幂置换 $F$,值集 $\beta_F(1,b)=\#\{x\in \GF{2^k}\mid F^{-1}(F(x)+b)+F^{-1}(F(x+1)+b)=1\}$(其中 $b\in \GF{2^k}$)称为 $F$ 的bomerang谱。bomerang谱中的最大值称为bomerang均匀性。本文确定了 $\GF{2^{4n}}$ 上幂置换 $X^{2^{3n}+2^{2n}+2^{n}-1}$ 的bomerang谱。该幂置换的bomerang均匀性为 $3(2^{2n}-2^n)$。然而,在 $\GF{2^{4n}}$ 的大子集 $\{b\in \GF{2^{4n}}\mid \mathbf{Tr}_n^{4n}(b)\neq 0\}$(其基数为 $2^{4n}-2^{3n}$,其中 $\mathbf{Tr}_n^{4n}$ 是从 $\GF{2^{4n}}$ 到 $\GF{2^{n}}$ 的(相对)迹函数)上,我们证明所研究的函数 $F$ 达到了最优bomerang均匀性 $2$。已知获得此类函数是一个具有挑战性的问题。更重要的是,对于bomerang谱中的任意值,本文明确给出了产生该值的 $b$ 的集合。