SearcharxivSearch

arXiv subjects

Marco Calderini

Publications and source records attributed to Marco Calderini.

At least 19 recordsLinked to original sources

On the Etzion-Silberstein conjecture for block Ferrers diagrams

Ferrers diagram rank-metric codes are rank-metric codes with prescribed support, and their dimension is bounded from above by the Etzion--Silberstein bound. In this paper, we study this problem for block Ferrers diagrams, namely Ferrers diagrams whose dots are grouped into square blocks of a fixed size. Motivated by the diagonal construction for MDS-constructible Ferrers diagrams, we introduce the notion of MSRD-constructibility, where MDS codes on diagonals are replaced by maximum sum-rank distance (MSRD) codes on block diagonals. We show that MSRD-constructible pairs yield optimal Ferrers diagram rank-metric codes over sufficiently large finite fields. We then relate MSRD-constructibility of a block Ferrers diagram to MDS-constructibility of its contraction, proving an equivalence when the distance is compatible with the block size and giving lifting criteria in the general case. As a consequence, we obtain MSRD-constructibility for strictly block-monotone and initially block-convex diagrams. Finally, we prove a reduction to block triangular diagrams and use it to obtain new arbitrary-field cases of the Etzion--Silberstein conjecture for MSRD-constructible block Ferrers diagrams.

math.CO

Zeros of special polynomials and their impact on a class of APN functions

In 2021, Calderini et al. introduced a construction for APN functions on $\mathbb{F}_{2^{2m}}$ in bivariate form $$ f(x,y)=\big(xy,\, x^{2^r+1} + x^{2^{r+m/2}} y^{2^{m/2}} + bxy^{2^r} + cy^{2^r+1}\big),\quad r < m/2,\quad \gcd(r, m) = 1. $$ They showed that this family exists provided the existence of a polynomial $$ P_{c,b}(X)=(cX^{2^r +1} + b X^{2^r}+1)^{2^{m/2}+1}+X^{2^{m/2}+1}, $$ with no zeros in $\mathbb{F}_{2^{2m}}$. For $m\le 6$ it was shown that we can have APN functions belonging to this family. However, up to now, no construction of such polynomials is known for $m\ge 8$. In this work we provide a non-existence result of such functions whenever $r<m/8-1$, by application of techniques from algebraic varieties over finite fields. In particular, for $r=1$ we have that the construction of Calderini et al. cannot provide an APN function for $m\ge 8$.

math.NT

A geometric invariant of linear rank-metric codes

Rank-metric codes have been a central topic in coding theory due to their theoretical and practical significance, with applications in network coding, distributed storage, crisscross error correction, and post-quantum cryptography. Recent research has focused on constructing new families of rank-metric codes with distinct algebraic structures, emphasizing the importance of invariants for distinguishing these codes from known families and from random ones. In this paper, we introduce a novel geometric invariant for linear rank-metric codes, inspired by the Schur product used in the Hamming metric. By examining the sequence of dimensions of Schur powers of the extended Hamming code associated with a linear code, we demonstrate its ability to differentiate Gabidulin codes from random ones. From a geometric perspective, this approach investigates the vanishing ideal of the linear set corresponding to the rank-metric code.

cs.IT

A new multivariate primitive from CCZ equivalence

Multivariate Cryptography is one of the candidates for Post-quantum Cryptography. Multivariate schemes are usually constructed by applying two secret affine invertible transformations $\mathcal S,\mathcal T$ to a set of multivariate polynomials $\mathcal{F}$ (often quadratic). The polynomials $\mathcal{F}$ possess a trapdoor that allows the legitimate user to find a solution of the corresponding system, while the public polynomials $\mathcal G=\mathcal S\circ\mathcal F\circ\mathcal T$ look like random polynomials. The polynomials $\mathcal G$ and $\mathcal F$ are said to be affine equivalent. In this article, we present a more general way of constructing a multivariate scheme by considering the CCZ equivalence, which has been introduced and studied in the context of vectorial Boolean functions.

cs.CR

Optimal s-boxes against alternative operations and linear propagation

Civino et al. (2019) have shown how some diffusion layers can expose a Substitution-Permutation Network to vulnerability from differential cryptanalysis when employing alternative operations coming from groups isomorphic to the translation group on the message space. In this study, we present a classification of diffusion layers that exhibit linearity with respect to certain parallel alternative operations, enabling the possibility of an alternative differential attack simultaneously targeting all the s-boxes within the block. Furthermore, we investigate the differential behaviour with respect to alternative operations for all classes of optimal 4-bit s-boxes, as defined by Leander and Poschmann (2007). Our examination reveals that certain classes contain weak permutations w.r.t. alternative differential attacks. Finally, we leverage these vulnerabilities to execute a series of experiments showing the effectiveness of the cryptanalysis performed with a parallel alternative operation compared to the classical one.

cs.CR

Differential experiments using parallel alternative operations

The use of alternative operations in differential cryptanalysis, or alternative notions of differentials, are lately receiving increasing attention. Recently, Civino et al. managed to design a block cipher which is secure w.r.t. classical differential cryptanalysis performed using XOR-differentials, but weaker with respect to the attack based on an alternative difference operation acting on the first s-box of the block. We extend this result to parallel alternative operations, i.e. acting on each s-box of the block. First, we recall the mathematical framework needed to define and use such operations. After that, we perform some differential experiments against a toy cipher and compare the effectiveness of the attack w.r.t. the one that uses XOR-differentials.

cs.CR

On Dillon's property of $(n,m)$-functions

Dillon observed that an APN function $F$ over $\mathbb{F}_2^{n}$ with $n$ greater than $2$ must satisfy the condition $\{F(x) + F(y) + F(z) + F(x + y + z) \,:\, x,y,z \in\mathbb{F}_2^n\}= \mathbb{F}_2^n$. Recently, Taniguchi (2023) generalized this condition to functions defined from $\mathbb{F}_2^n$ to $\mathbb{F}_2^m$, with $m>n$, calling it the D-property. Taniguchi gave some characterizations of APN functions satisfying the D-property and provided some families of APN functions from $\mathbb{F}_2^n$ to $\mathbb{F}_2^{n+1}$ satisfying this property. In this work, we further study the D-property for $(n,m)$-functions with $m\ge n$. We give some combinatorial bounds on the dimension $m$ for the existence of such functions. Then, we characterize the D-property in terms of the Walsh transform and for quadratic functions we give a characterization of this property in terms of the ANF. We also give a simplification on checking the D-property for quadratic functions, which permits to extend some of the APN families provided by Taniguchi. We further focus on the class of the plateaued functions, providing conditions for the D-property.

cs.IT

Two new families of bivariate APN functions

In this work, we present two new families of quadratic APN functions. The first one (F1) is constructed via biprojective polynomials. This family includes one of the two APN families introduced by G\"olo\v{g}lu in 2022. Then, following a similar approach as in Li \emph{et al.} (2022), we give another family (F2) obtained by adding certain terms to F1. As a byproduct, this second family includes one of the two families introduced by Li \emph{et al.} (2022). Moreover, we show that for $n=12$, from our constructions, we can obtain APN functions that are CCZ-inequivalent to any other known APN function over $\mathbb{F}_{2^{12}}$.

cs.IT

Low c-differential uniformity for functions modified on subfields

In this paper, we construct some piecewise defined functions, and study their $c$-differential uniformity. As a by-product, we improve upon several prior results. Further, we look at concatenations of functions with low differential uniformity and show several results. For example, we prove that given $\beta_i$ (a basis of $\mathbb{F}_{q^n}$ over $\mathbb{F}_q$), some functions $f_i$ of $c$-differential uniformities $\delta_i$, and $L_i$ (specific linearized polynomials defined in terms of $\beta_i$), $1\leq i\leq n$, then $F(x)=\sum_{i=1}^n\beta_i f_i(L_i(x))$ has $c$-differential uniformity equal to $\prod_{i=1}^n \delta_i$.

cs.IT

Higher Order $c$-Differentials

EFRST20, the notion of $c$-differentials was introduced as a potential expansion of differential cryptanalysis against block ciphers utilizing substitution boxes. Drawing inspiration from the technique of higher order differential cryptanalysis, in this paper we propose the notion of higher order $c$-derivatives and differentials and investigate their properties. Additionally, we consider how several classes of functions, namely the multiplicative inverse function and the Gold function, perform under higher order $c$-differential uniformity.

cs.IT

On the infiniteness of a family of APN functions

APN functions play a fundamental role in cryptography against attacks on block ciphers. Several families of quadratic APN functions have been proposed in the recent years, whose construction relies on the existence of specific families of polynomials. A key question connected with such constructions is to determine whether such APN functions exist for infinitely many dimensions or not. In this paper we consider a family of functions recently introduced by Li et al. in 2021 showing that for any dimension $m\geq 3$ there exists an APN function belonging to such a family. Our main result is proved by a combination of different techniques arising from both algebraic varieties over finite fields connected with linearized permutation rational functions and {partial vector space partitions}, together with investigations on the kernels of linearized polynomials.

math.CO

On construction and (non)existence of $c$-(almost) perfect nonlinear functions

Functions with low differential uniformity have relevant applications in cryptography. Recently, functions with low $c$-differential uniformity attracted lots of attention. In particular, so-called APcN and PcN functions (generalization of APN and PN functions) have been investigated. Here, we provide a characterization of such functions via quadratic polynomials as well as non-existence results.

math.CO

On properties of translation groups in the affine general linear group with applications to cryptography

The affine general linear group acting on a vector space over a prime field is a well-understood mathematical object. Its elementary abelian regular subgroups have recently drawn attention in applied mathematics thanks to their use in cryptography as a way to hide or detect weaknesses inside block ciphers. This paper is focused on building a convenient representation of their elements which suits better the purposes of the cryptanalyst. Several combinatorial counting formulas and a classification of their conjugacy classes are given as well.

math.GR

Differentially low uniform permutations from known 4-uniform functions

Functions with low differential uniformity can be used in a block cipher as S-boxes since they have good resistance to differential attacks. In this paper we consider piecewise constructions for permutations with low differential uniformity. In particular, we give two constructions of differentially 6-uniform functions, modifying the Gold function and the Bracken-Leander function on a subfield.

cs.IT

Primitivity of the group of a cipher involving the action of the key-schedule

The algebraic structure of the group generated by the encryption functions of a block cipher depends on the key schedule algorithm used for generating the round keys. For such a reason, in general, studying this group does not appear to be an easy task. Previous works, focusing on the algebraic properties of groups associated to a cipher, have studied the group generated by the round functions of the cipher considering independent round keys. In this paper, we want to study the more realistic group generated by the encryption functions, where the key schedule satisfies certain requirements. In this contest, we are able to identify sufficient conditions that permit to guarantee the primitivity of this group and the security of the cipher with respect to the partition-based trapdoor. This type of trapdoor has been recently introduced by Bannier et al. (2016) and it is a generalization of that introduced by Paterson in 1999.

math.GR

Some group-theoretical results on Feistel Networks in a long-key scenario

The study of the trapdoors that can be hidden in a block cipher is and has always been a high-interest topic in symmetric cryptography. In this paper we focus on Feistel-network-like ciphers in a classical long-key scenario and we investigate some conditions which make such a construction immune to the partition-based attack introduced recently by Bannier et al.

math.GR

On Hidden Sums Compatible with A Given Block Cipher Diffusion Layer

Sometimes it is possible to embed an algebraic trapdoor into a block cipher. Building on previous research, in this paper we investigate an especially dangerous algebraic structure, which is called a hidden sum and which is related to some regular subgroups of the affine group. Mixing group theory arguments and cryptographic tools, we pass from characterizing our hidden sums to designing an efficient algorithm to perform the necessary preprocessing for the exploitation of the trapdoor.

math.GR

Wave-Shaped Round Functions and Primitive Groups

Round functions used as building blocks for iterated block ciphers, both in the case of Substitution-Permutation Networks and Feistel Networks, are often obtained as the composition of different layers which provide confusion and diffusion, and key additions. The bijectivity of any encryption function, crucial in order to make the decryption possible, is guaranteed by the use of invertible layers or by the Feistel structure. In this work a new family of ciphers, called wave ciphers, is introduced. In wave ciphers, round functions feature wave functions, which are vectorial Boolean functions obtained as the composition of non-invertible layers, where the confusion layer enlarges the message which returns to its original size after the diffusion layer is applied. This is motivated by the fact that relaxing the requirement that all the layers are invertible allows to consider more functions which are optimal with regard to non-linearity. In particular it allows to consider injective APN S-boxes. In order to guarantee efficient decryption we propose to use wave functions in Feistel Networks. With regard to security, the immunity from some group-theoretical attacks is investigated. In particular, it is shown how to avoid that the group generated by the round functions acts imprimitively, which represent a serious flaw for the cipher.

math.GR