SearcharxivSearch

arXiv subjects

Arne Winterhof

Publications and source records attributed to Arne Winterhof.

At least 19 recordsLinked to original sources

Additive index and Carlitz rank

We compare several complexity measures for self-mappings of finite fields. In particular, we show that Carlitz rank and additive index cannot be small simultaneously up to trivial exceptions. That is, these two measures detect cryptographic weaknesses of different classes of functions. We also study the relationship between additive index and degree or weight, respectively, complementing earlier results of Aksoy et al. and Gómez-Pérez et al. on the relationship between Carlitz rank and degree or weight, respectively. Finally, we show that a function closely related to the discrete logarithm provides an example in which all four complexity measures, degree, weight, additive index and Carlitz rank, are large.

math.NT

Symmetric measures of pseudorandomness for binary sequences

We compare ordinary and symmetric variants of two classical measures of pseudorandomness for binary sequences, the $2$-adic complexity and the linear complexity. In the periodic setting, we show that for binary periodic sequences constructed from the binary expansions of non-palindromic primes, the symmetric $2$-adic complexity can be strictly smaller than the ordinary $2$-adic complexity. We also give a direct proof (of the known result) that the linear complexity of a periodic binary sequence is invariant under reversal, and hence coincides with its symmetric version. In the aperiodic setting, we provide explicit families of finite binary sequences for which both the $N$th symmetric 2-adic complexity and the $N$th symmetric linear complexity are substantially smaller than their ordinary counterparts. Furthermore, we show that the expected values of the $N$th rational complexity and of the $N$th exponential linear complexity exceed those of their symmetric analogues by at least a term of order of magnitude $N$. Thus, the effect of symmetrization is clearly visible on an exponential scale. We also establish lower bounds for the expected values of the symmetric rational complexity, symmetric $2$-adic complexity, symmetric linear complexity, and symmetric exponential linear complexity.

math.NT

On the additive index of the Diffie-Hellman mapping and the discrete logarithm

Several complexity measures such as degree, sparsity and multiplicative index for cryptographic functions including the Diffie-Hellman mapping and the discrete logarithm in a finite field have been studied in the literature. In 2022, Reis and Wang introduced another complexity measure, the additive index, of a self-mapping of a finite field. In this paper, under certain conditions, we determine lower bounds on the additive index of the univariate Diffie-Hellman mapping and a self-mapping of $\mathbb{F}_q$ which can be identified with the discrete logarithm in a finite field.

math.NT

Multiplicative character sums over two classes of subsets of quadratic extensions of finite fields

Let $q$ be a prime power and $r$ a positive even integer. Let $\mathbb{F}_{q}$ be the finite field with $q$ elements and $\mathbb{F}_{q^r}$ be its extension field of degree $r$. Let $χ$ be a nontrivial multiplicative character of $\mathbb{F}_{q^r}$ and $f(X)$ a polynomial over $\mathbb{F}_{q^r}$ with a simple root in $\mathbb{F}_{q^r}$. In this paper, we improve estimates for character sums $\sum\limits_{g \in\mathcal{G}}χ(f(g))$, where $\mathcal{G}$ is either a subset of $\mathbb{F}_{q^r}$ of sparse elements, with respect to some fixed basis of $\mathbb{F}_{q^r}$ which contains a basis of $\mathbb{F}_{q^{r/2}}$, or a subset avoiding affine hyperplanes in general position. While such sums have been previously studied, our approach yields sharper bounds by reducing them to sums over the subfield $\mathbb{F}_{q^{r/2}}$ rather than sums over general linear spaces. These estimates can be used to prove the existence of primitive elements in $\mathcal{G}$ in the standard way.

math.NT

On the $N$th $2$-adic complexity of binary sequences identified with algebraic $2$-adic integers

We identify a binary sequence $\mathcal{S}=(s_n)_{n=0}^\infty$ with the $2$-adic integer $G_\mathcal{S}(2)=\sum\limits_{n=0}^\infty s_n2^n$. In the case that $G_\mathcal{S}(2)$ is algebraic over $\mathbb{Q}$ of degree $d\ge 2$, we prove that the $N$th $2$-adic complexity of $\mathcal{S}$ is at least $\frac{N}{d}+O(1)$, where the implied constant depends only on the minimal polynomial of $G_\mathcal{S}(2)$. This result is an analog of the bound of Mérai and the second author on the linear complexity of automatic sequences, that is, sequences with algebraic $G_\mathcal{S}(X)$ over the rational function field $\mathbb{F}_2(X)$. We further discuss the most important case $d=2$ in both settings and explain that the intersection of the set of $2$-adic algebraic sequences and the set of automatic sequences is the set of (eventually) periodic sequences. Finally, we provide some experimental results supporting the conjecture that $2$-adic algebraic sequences can have also a desirable $N$th linear complexity and automatic sequences a desirable $N$th $2$-adic complexity, respectively.

math.NT

Quaternary Legendre pairs II

Quaternary Legendre pairs are pertinent to the construction of quaternary Hadamard matrices and have many applications, for example in coding theory and communications. In contrast to binary Legendre pairs, quaternary ones can exist for even length $\ell$ as well. It is conjectured that there is a quaternary Legendre pair for any even $\ell$. The smallest open case until now had been $\ell=28$, and $\ell=38$ was the only length $\ell$ with $28\le \ell\le 60$ resolved before. Here we provide constructions for $\ell=28,30,32$, and $34$. In parallel and independently, Jedwab and Pender found a construction of quaternary Legendre pairs of length $\ell=(q-1)/2$ for any prime power $q\equiv 1\bmod 4$, which in particular covers $\ell=30$, $36$, and $40$, so that now $\ell=42$ is the smallest unresolved case. The main new idea of this paper is a way to separate the search for the subsequences along even and odd indices which substantially reduces the complexity of the search algorithm. In addition, we use Galois theory for cyclotomic fields to derive conditions which improve the PSD test.

math.CO

Some notes on the pseudorandomness of Legendre symbol and Liouville function

We improve bounds on the degree and sparsity of Boolean functions representing the Legendre symbol as well as on the $N$th linear complexity of the Legendre sequence. We also prove similar results for both the Liouville function for integers and its analog for polynomials over $\mathbb{F}_2$, or more general for any (binary) arithmetic function which satisfies $f(2n)=-f(n)$ for $n=1,2,\ldots$

math.NT

On the cross-correlation of Golomb Costas permutations

In the most interesting case of safe prime powers $q$, Gómez and Winterhof showed that a subfamily of the family of Golomb Costas permutations of $\{1,2,\ldots,q-2\}$ of size $φ(q-1)$ has maximal cross-correlation of order of magnitude at most $q^{1/2}$. In this paper we study a larger family of Golomb Costas permutations and prove a weaker bound on its maximal cross-correlation. Considering the whole family of Golomb Costas permutations we show that large cross-correlations are very rare. Finally, we collect several conditions for a small cross-correlation of two Costas permutations. Our main tools are the Weil bound and the Szemerédi-Trotter theorem for finite fields.

math.CO

Primitive elements of finite fields $\mathbf{F}_{q^r}$ avoiding affine hyperplanes for $q=4$ and $q=5$

For a finite field $\mathbf{F}_{q^r}$ with fixed $q$ and $r$ sufficiently large, we prove the existence of a primitive element outside of a set of $r$ many affine hyperplanes for $q=4$ and $q=5$. This complements earlier results by Fernandes and Reis for $q\ge 7$. For $q=3$ the analogous result can be derived from a very recent bound on character sums of Iyer and Shparlinski. For $q=2$ the set consists only of a single element, and such a result is thus not possible.

math.NT

Maximum-order complexity and $2$-adic complexity

The $2$-adic complexity has been well-analyzed in the periodic case. However, we are not aware of any theoretical results on the $N$th $2$-adic complexity of any promising candidate for a pseudorandom sequence of finite length $N$ or results on a part of the period of length $N$ of a periodic sequence, respectively. Here we introduce the first method for this aperiodic case. More precisely, we study the relation between $N$th maximum-order complexity and $N$th $2$-adic complexity of binary sequences and prove a lower bound on the $N$th $2$-adic complexity in terms of the $N$th maximum-order complexity. Then any known lower bound on the $N$th maximum-order complexity implies a lower bound on the $N$th $2$-adic complexity of the same order of magnitude. In the periodic case, one can prove a slightly better result. The latter bound is sharp which is illustrated by the maximum-order complexity of $\ell$-sequences. The idea of the proof helps us to characterize the maximum-order complexity of periodic sequences in terms of the unique rational number defined by the sequence. We also show that a periodic sequence of maximal maximum-order complexity must be also of maximal $2$-adic complexity.

cs.IT

Pseudorandom binary sequences: quality measures and number-theoretic constructions

In this survey we summarize properties of pseudorandomness and non-randomness of some number-theoretic sequences and present results on their behaviour under the following measures of pseudorandomness: balance, linear complexity, correlation measure of order $k$, expansion complexity and $2$-adic complexity. The number-theoretic sequences are the Legendre sequence and the two-prime generator, the Thue-Morse sequence and its sub-sequence along squares, and the prime omega sequences for integers and polynomials.

math.NT

Quaternary Legendre Pairs

We introduce quaternary Legendre pairs of length $\ell$. In contrast to binary Legendre pairs they can exist for even $\ell$ as well. First we show that they are pertinent to the construction of quaternary Hadamard matrices of order $2\ell+2$ and thus of binary Hadamard matrices of order $4\ell+4$. Then for a prime $p>2$ we present a construction of a pair of sequences of length $p$ from which we can derive quaternary Legendre pairs of length $\ell=2p$ by decompression for $p=3,5,7,13,19,31,41$. Moreover, we give also constructions of Legendre pairs of length $\ell$ for all remaining even $\ell\le 24$.

math.CO

Character sums over sparse elements of finite fields

We estimate mixed character sums of polynomial values over elements of a finite field $\mathbb F_{q^r}$ with sparse representations in a fixed ordered basis over the subfield $\mathbb F_q$. First we use a combination of the inclusion-exclusion principle with bounds on character sums over linear subspaces to get nontrivial bounds for large $q$. Then we focus on the particular case $q=2$, which is more intricate. The bounds depend on certain natural restrictions. We also provide families of examples for which the conditions of our bounds are fulfilled. In particular, we completely classify all monomials as argument of the additive character for which our bound is applicable. Moreover, we also show that it is applicable for a large family of rational functions, which includes all reciprocal monomials.

math.NT

Arithmetic crosscorrelation of pseudorandom binary sequences of coprime periods

The (classical) crosscorrelation is an important measure of pseudorandomness of two binary sequences for applications in communications. The arithmetic crosscorrelation is another figure of merit introduced by Goresky and Klapper generalizing Mandelbaum's arithmetic autocorrelation. First we observe that the arithmetic crosscorrelation is constant for two binary sequences of coprime periods which complements the analogous result for the classical crosscorrelation. Then we prove upper bounds for the constant arithmetic crosscorrelation of two Legendre sequences of different periods and of two binary $m$-sequences of coprime periods, respectively.

cs.CR

Balance and pattern distribution of sequences derived from pseudorandom subsets of $\mathbb{Z}_q$

Let $q$ be a positive integer and $\mathcal{S}=\left\{x_0,x_1,\ldots,x_{T-1}\right\}\subseteq\mathbb{Z}_q=\{0,1,\ldots,q-1\}$ with $$0\leq x_0<x_1<\ldots< x_{T-1}\leq q-1.$$ We derive from $\mathcal{S}$ three (finite) sequences. 1. For an integer $M\geq 2$ let $(s_n)$ be the $M$-ary sequence defined by \begin{eqnarray*} s_n\equiv x_{n+1}-x_n \bmod M, \qquad n=0,1,\ldots, T-2. \end{eqnarray*} 2. For an integer $m\geq 2$ let $(t_n)$ be the binary sequence defined by \begin{eqnarray*} t_n=\left\{\begin{array}{ll} 1, & \hbox{if } 1\leq x_{n+1}-x_n\leq m-1, \\ 0, & \hbox{otherwise}, \end{array}\right. \qquad n=0,1,\ldots, T-2. \end{eqnarray*} 3. Let $(u_n)$ be the characteristic sequence of $\mathcal{S}$, \begin{eqnarray*} u_n=\left\{\begin{array}{ll} 1, & \hbox{if } n\in \mathcal{S}, \\ 0, & \hbox{otherwise}, \end{array}\right. \qquad n=0,1,\ldots, q-1. \end{eqnarray*} We study the balance and pattern distribution of the sequences $(s_n)$, $(t_n)$ and $(u_n)$. For sets $\mathcal{S}$ with desirable pseudorandom properties, more precisely, sets with low correlation measures, we show the following: 1. The sequence $(s_n)$ is (asymptotically) balanced and has uniform pattern distribution if $T$ is of smaller order of magnitude than $q$. 2. The sequence $(t_n)$ is balanced and has uniform pattern distribution if $T$ is approximately $\left(1-\frac{1}{2^{1/(m-1)}}\right)q$. 3. The sequence $(u_n)$ is balanced and has uniform pattern distribution if $T$ is approximately $\frac{q}{2}$. These results are motivated by earlier results for the sets of quadratic residues and primitive roots modulo a prime. We unify these results and derive many further (asymptotically) balanced sequences with uniform pattern distribution from pseudorandom subsets.

math.NT

Normality of the Thue-Morse function for finite fields along polynomial values

Let ${\mathbb F}_q$ be the finite field of $q$ elements, where $q=p^r$ is a power of the prime $p$, and $\left(β_1, β_2, \dots, β_r \right)$ be an ordered basis of ${\mathbb F}_q$ over ${\mathbb F}_p$. For $$ξ=\sum_{i=1}^rx_iβ_i, \quad \quad x_i\in{\mathbb F}_p,$$ we define the Thue-Morse or sum-of-digits function $T(ξ)$ on ${\mathbb F}_q$ by \[ T(ξ)=\sum_{i=1}^{r}x_i.%,\quad ξ=x_1β_1+\cdots +x_rβ_r\in {\mathbb F}_q. \] For a given pattern length $s$ with $1\le s\le q$, a subset ${\cal A}=\{α_1,\ldots,α_s\}\subset {\mathbb F}_q$, a polynomial $f(X)\in{\mathbb F}_q[X]$ of degree $d$ and a vector $\underline{c}=(c_1,\ldots,c_s)\in{\mathbb F}_p^s$ we put \[ {\cal T}(\underline{c},{\cal A},f)=\{ξ\in{\mathbb F}_q : T(f(ξ+α_i))=c_i,~i=1,\ldots,s\}. \] In this paper we will see that under some natural conditions, the size of~${\cal T}(\underline{c},{\cal A},f)$ is asymptotically the same for all~$\underline{c}$ and ${\cal A}$ in both cases, $p\rightarrow \infty$ and $r\rightarrow \infty$, respectively. More precisely, we have \[ \left||{\cal T}(\underline{c},{\cal A},f)|-p^{r-s}\right|\le (d-1)q^{1/2}\] under certain conditions on $d,q$ and $s$. For monomials of large degree we improve this bound as well as we find conditions on $d,q$ and $s$ for which this bound is not true. In particular, if $1\le d<p$ we have the dichotomy that the bound is valid if $s\le d$ and fails for some $\underline{c}$ and ${\cal A}$ if $s\ge d+1$. The case $s=1$ was studied before by Dartyge and Sárközy.

math.NT

Binary Sequences Derived from Differences of Consecutive Primitive Roots

Let $1<g_1<\ldots<g_{φ(p-1)}<p-1$ be the ordered primitive roots modulo~$p$. We study the pseudorandomness of the binary sequence $(s_n)$ defined by $s_n\equiv g_{n+1}+g_{n+2}\bmod 2$, $n=0,1,\ldots$. In particular, we study the balance, linear complexity and $2$-adic complexity of $(s_n)$. We show that for a typical $p$ the sequence $(s_n)$ is quite unbalanced. However, there are still infinitely many $p$ such that $(s_n)$ is very balanced. We also prove similar results for the distribution of longer patterns. Moreover, we give general lower bounds on the linear complexity and $2$-adic complexity of~$(s_n)$ and state sufficient conditions for attaining their maximums. Hence, for carefully chosen $p$, these sequences are attractive candidates for cryptographic applications.

math.NT

Pseudorandom sequences derived from automatic sequences

Many automatic sequences, such as the Thue-Morse sequence or the Rudin-Shapiro sequence, have some desirable features of pseudorandomness such as a large linear complexity and a small well-distribution measure. However, they also have some disastrous properties in view of certain applications. For example, the majority of possible binary patterns never appears in automatic sequences and their correlation measure of order 2 is extremely large. Certain subsequences, such as automatic sequences along squares, may keep the good properties of the original sequence but avoid the bad ones. In this survey we investigate properties of pseudorandomness and non-randomness of automatic sequences and their subsequences and present results on their behaviour under several measures of pseudorandomness including linear complexity, correlation measure of order $k$, expansion complexity and normality. We also mention some analogs for finite fields.

math.NT