On 3-to-1 and Power APN S-Boxes
Almost Perfect Nonlinear (APN) S-boxes are used in block ciphers to prevent differential attacks. The non-evidence of permutation APN S-box on even number of variables and the efficiency of power functions bring the importance of power APN S-boxes to use in block ciphers. We present a special class of 3-to-1 S-box (named as S3-to-1 S-box) on even number of variables. The power APN S-boxes on even number of variables fall in this class. Further, another important class of APN functions X3 + tr(X9) too falls in this class. We study some results of S3-to-1 S-boxes. In another section we present a necessary condition for power functions to be APN. Using this necessary condition we can filter out some non-APN power functions. Specifically, if the number of variables is multiple of small primes, then one can filter out many non-APN functions.
KeywordsS-box Power Function APN Function Differential Cryptanalysis
Unable to display preview. Download preview PDF.
- 3.Budaghyan, L., Carlet, C., Leander, G.: Constructing new APN functions from known ones. Cryptology ePrint Archive: report 2007/063Google Scholar
- 6.Comtet, L.: Advanced combinatorics. Reidel Publication (1974)Google Scholar
- 7.Nyberg, K., Knudsen, L.R.: Provable security against differential cryptanalysis. In: Brickell, E.F. (ed.) CRYPTO 1992. LNCS, vol. 740, pp. 566–574. Springer, Heidelberg (1993)Google Scholar
- 8.Nyberg, K.: Differentially uniform mappings for cryptography. In: Helleseth, T. (ed.) EUROCRYPT 1993. LNCS, vol. 765, pp. 55–64. Springer, Heidelberg (1994)Google Scholar