SearcharxivSearch

arXiv subjects

Baofeng Wu

Publications and source records attributed to Baofeng Wu.

At least 19 recordsLinked to original sources

Correlation Cube Attack Revisited: Improved Cube Search and Superpoly Recovery Techniques

In this paper, we improve the cube attack by exploiting low-degree factors of the superpoly w.r.t. certain "special" index set of cube (ISoC). This can be viewed as a special case of the correlation cube attack proposed at Eurocrypt 2018, but under our framework more beneficial equations on the key variables can be obtained in the key-recovery phase. To mount our attack, one has two challenging problems: effectively recover algebraic normal form of the superpoly and extract out its low-degree factors; and efficiently search a large quantity of good ISoCs. We bring in new techniques to solve both of them. First, we propose the variable substitution technique for middle rounds of a cipher, in which polynomials on the key variables in the algebraic expressions of internal states are substituted by new variables. This will improve computational complexity of the superpoly recovery and promise more compact superpolys that can be easily decomposed with respect to the new variables. Second, we propose the vector numeric mapping technique, which seeks out a tradeoff between efficiency of the numeric mapping technique and accuracy of the monomial prediction technique in degree evaluation of superpolys. Combining with this technique, a fast pruning method is given and modeled by MILP to filter good ISoCs of which the algebraic degree satisfies some fixed threshold. Thanks to automated MILP solvers, it becomes practical to comprehensively search for good cubes across the entire search space. To illustrate the power of our techniques, we apply all of them to Trivium stream cipher. The previous best practical key recovery attack was on 820-round Trivium with complexity $2^{53.17}$. We put forward 820-, 825- and 830-round practical key-recovery attacks, in which there are 2^{80}\times 87.8%, 2^{80}\times 83% and 2^{80}\times 65.7% keys that could be practically recovered, respectively.

cs.CR

Towards non-independence of modular additions in searching differential trails of ARX ciphers: new automatic methods with application to SPECK and Chaskey

ARX-based ciphers, constructed by the modular addition, rotation and XOR operations, have been receiving a lot of attention in the design of lightweight symmetric ciphers. For their differential cryptanalysis, most automatic search methods of differential trails adopt the assumption of independence of modulo additions. However, this assumption does not necessarily hold when the trail includes consecutive modular additions (CMAs). It has already been found that in this case some differential trails searched by automatic methods before are actually impossible, but the study is not in depth yet, for example, few effort has been paid to exploiting the root causes of non-independence between CMAs and accurate calculation of probabilities of the valid trails. In this paper, we devote to solving these two problems. By examing the differential equations of single and consecutive modular additions, we find that the influence of non-independence can be described by relationships between constraints on the intermediate state of two additions. Specifically, constraints of the first addition can make some of its output bits non-uniform, and when they meet the constraints of the second addition, the differential probability of the whole CMA may be different from the value calculated under the independence assumption. As a result, we can build SAT models to verify the validity of a given differential trail of ARX ciphers and #SAT models to calculate the exact probabilities of the differential propagation through CMAs in the trail, promising a more accurate evaluation of probability of the trail. Our automic methods and searching tools are applied to search related-key differential trails of SPECK and Chaskey including CMAs in the key schedule and the round function respectively.

cs.CR

Towards a conjecture on a special class of matrices over commutative rings of characteristic 2

In this paper, we prove the conjecture posed by Keller and Rosemarin at Eurocrypt 2021 on the nullity of a matrix polynomial of a block matrix with Hadamard type blocks over commutative rings of characteristic 2. Therefore, it confirms the conjectural optimal bound on the dimension of invariant subspace of the Starkad cipher using the HADES design strategy. Moreover, we reveal the algebraic structure formed by Hadamard matrices over commutative rings from the perspectives of group algebra and polynomial algebra. An interesting relation between block-Hadamard matrices and Hadamard-block matrices is obtained as well.

cs.CR

A general construction of permutation polynomials of the form $ (x^{2^m}+x+δ)^{i(2^m-1)+1}+x$ over $\F_{2^{2m}}$

Recently, there has been a lot of work on constructions of permutation polynomials of the form $(x^{2^m}+x+δ)^{s}+x$ over the finite field $\F_{2^{2m}}$, especially in the case when $s$ is of the form $s=i(2^m-1)+1$ (Niho exponent). In this paper, we further investigate permutation polynomials with this form. Instead of seeking for sporadic constructions of the parameter $i$, we give a general sufficient condition on $i$ such that $(x^{2^m}+x+δ)^{i(2^m-1)+1}+x$ permutes $\F_{2^{2m}}$, that is, $(2^k+1)i \equiv 1 ~\textrm{or}~ 2^k~(\textrm{mod}~ 2^m+1)$, where $1 \leq k \leq m-1$ is any integer. This generalizes a recent result obtained by Gupta and Sharma who actually dealt with the case $k=2$. It turns out that most of previous constructions of the parameter $i$ are covered by our result, and it yields many new classes of permutation polynomials as well.

cs.IT

More characterizations of generalized bent function in odd characteristic, their dual and the gray image

In this paper, we further investigate properties of generalized bent Boolean functions from $\Z_{p}^n$ to $\Z_{p^k}$, where $p$ is an odd prime and $k$ is a positive integer. For various kinds of representations, sufficient and necessary conditions for bent-ness of such functions are given in terms of their various kinds of component functions. Furthermore, a subclass of gbent functions corresponding to relative difference sets, which we call $\Z_{p^k}$-bent functions, are studied. It turns out that $\Z_{p^k}$-bent functions correspond to a class of vectorial bent functions, and the property of being $\Z_{p^k}$-bent is much stronger then the standard bent-ness. The dual and the generalized Gray image of gbent function are also discussed. In addition, as a further generalization, we also define and give characterizations of gbent functions from $\Z_{p^l}^n$ to $\Z_{p^k}$ for a positive integer $l$ with $l<k$.

math.NT

$\mathbb{Z}_q$-valued generalized bent functions in odd characteristics

In this paper, we investigate properties of functions from $\mathbb{Z}_{p}^n$ to $\mathbb{Z}_q$, where $p$ is an odd prime and $q$ is a positive integer divided by $p$. we present the sufficient and necessary conditions for bent-ness of such generalized Boolean functions in terms of classical $p$-ary bent functions, when $q=p^k$. When $q$ is divided by $p$ but not a power of it, we give an sufficient condition for weakly regular gbent functions. Some related constructions are also obtained.

math.NT

Constructing Boolean Functions With Potential Optimal Algebraic Immunity Based on Additive Decompositions of Finite Fields

We propose a general approach to construct cryptographic significant Boolean functions of $(r+1)m$ variables based on the additive decomposition $\mathbb{F}_{2^{rm}}\times\mathbb{F}_{2^m}$ of the finite field $\mathbb{F}_{2^{(r+1)m}}$, where $r$ is odd and $m\geq3$. A class of unbalanced functions are constructed first via this approach, which coincides with a variant of the unbalanced class of generalized Tu-Deng functions in the case $r=1$. This class of functions have high algebraic degree, but their algebraic immunity does not exceeds $m$, which is impossible to be optimal when $r>1$. By modifying these unbalanced functions, we obtain a class of balanced functions which have optimal algebraic degree and high nonlinearity (shown by a lower bound we prove). These functions have optimal algebraic immunity provided a combinatorial conjecture on binary strings which generalizes the Tu-Deng conjecture is true. Computer investigations show that, at least for small values of number of variables, functions from this class also behave well against fast algebraic attacks.

cs.CR

Complete permutation polynomials induced from complete permutations of subfields

We propose several techniques to construct complete permutation polynomials of finite fields by virtue of complete permutations of subfields. In some special cases, any complete permutation polynomials over a finite field can be used to construct complete permutations of certain extension fields with these techniques. The results generalize some recent work of several authors.

math.NT

The compositional inverses of linearized permutation binomials over finite fields

Let $q$ be a prime power and $n$ and $r$ be positive integers. It is well known that the linearized binomial $L_r(x)=x^{q^r}+ax\in\mathbb{F}_{q^n}[x]$ is a permutation polynomial if and only if $(-1)^{n/d}a^{{(q^n-1)}/{(q^{d}-1)}}\neq 1$ where $d=(n,r)$. In this paper, the compositional inverse of $L_r(x)$ is explicitly determined when this condition holds.

math.NT

New constructions of quaternary bent functions

In this paper, a new construction of quaternary bent functions from quaternary quadratic forms over Galois rings of characteristic 4 is proposed. Based on this construction, several new classes of quaternary bent functions are obtained, and as a consequence, several new classes of quadratic binary bent and semi-bent functions in polynomial forms are derived. This work generalizes the recent work of N. Li, X. Tang and T. Helleseth.

cs.DM

$\mathcal{P}\mathcal{S}$ bent functions constructed from finite pre-quasifield spreads

Bent functions are of great importance in both mathematics and information science. The $\mathcal{P}\mathcal{S}$ class of bent functions was introduced by Dillon in 1974, but functions belonging to this class that can be explicitly represented are only the $\mathcal{P}\mathcal{S}_{\text{ap}}$ functions, which were also constructed by Dillon after his introduction of the $\mathcal{P}\mathcal{S}$ class. In this paper, a technique of using finite pre-quasifield spread from finite geometry to construct $\mathcal{P}\mathcal{S}$ bent functions is proposed. The constructed functions are in similar styles with the $\mathcal{P}\mathcal{S}_{\text{ap}}$ functions. To explicitly represent them in bivariate forms, the main task is to compute compositional inverses of certain parametric permutation polynomials over finite fields of characteristic 2. Concentrated on the Dempwolff-Müller pre-quasifield, the Knuth pre-semifield and the Kantor pre-semifield, three new subclasses of the $\mathcal{P}\mathcal{S}$ class are obtained. They are the only sub-classes that can be explicitly constructed more than 30 years after the $\mathcal{P}\mathcal{S}_{\text{ap}}$ subclass was introduced.

math.CO

A remark on algebraic immunity of Boolean functions

In this correspondence, an equivalent definition of algebraic immunity of Boolean functions is posed, which can clear up the confusion caused by the proof of optimal algebraic immunity of the Carlet-Feng function and some other functions constructed by virtue of Carlet and Feng's idea.

cs.CR

The compositional inverse of a class of bilinear permutation polynomials over finite fields of characteristic 2

A class of bilinear permutation polynomials over a finite field of characteristic 2 was constructed in a recursive manner recently which involved some other constructions as special cases. We determine the compositional inverses of them based on a direct sum decomposition of the finite field. The result generalizes that in [R.S. Coulter, M. Henderson, The compositional inverse of a class of permutation polynomials over a finite field, Bull. Austral. Math. Soc. 65 (2002) 521-526].

math.CO

Constructing $2m$-variable Boolean functions with optimal algebraic immunity based on polar decomposition of $\mathbb{F}_{2^{2m}}^*$

Constructing $2m$-variable Boolean functions with optimal algebraic immunity based on decomposition of additive group of the finite field $\mathbb{F}_{2^{2m}}$ seems to be a promising approach since Tu and Deng's work. In this paper, we consider the same problem in a new way. Based on polar decomposition of the multiplicative group of $\mathbb{F}_{2^{2m}}$, we propose a new construction of Boolean functions with optimal algebraic immunity. By a slight modification of it, we obtain a class of balanced Boolean functions achieving optimal algebraic immunity, which also have optimal algebraic degree and high nonlinearity. Computer investigations imply that this class of functions also behave well against fast algebraic attacks.

cs.CR

A new proof to complexity of dual basis of a type I optimal normal basis

The complexity of dual basis of a type I optimal normal basis of $\mathbb{F}_{q^n}$ over $\mathbb{F}_{q}$ was determined to be $3n-3$ or $3n-2$ according as $q$ is even or odd, respectively, by Z.-X. Wan and K. Zhou in 2007. We give a new proof to this result by clearly deriving the dual of a type I optimal normal basis with the aid of a lemma on the dual of a polynomial basis.

cs.DM