Polynomials with maximal differential uniformity and the exceptional APN conjecture

Yves Aubry,Fabien Herbaut,Ali Issa
DOI: https://doi.org/10.48550/arXiv.2207.13945
2022-07-28
Abstract:We contribute to the exceptional APN conjecture by showing that no polynomial of degree m = 2 r (2 {\ell} + 1) where gcd(r, {\ell}) 2, r 2, {\ell} 1 with a nonzero second leading coefficient can be APN over infinitely many extensions of the base field. More precisely, we prove that for n sufficiently large, all polynomials of F 2 n [x] of such a degree with a nonzero second leading coefficient have a differential uniformity equal to m -- 2.
Number Theory
What problem does this paper attempt to address?
The problem that this paper attempts to solve is whether a polynomial of a specific form can be an almost perfect nonlinear (APN) function. Specifically, the authors studied polynomials of the form \( m = 2^r(2\ell + 1) \), where \(\gcd(r, \ell) \leqslant 2\), \( r \geqslant 2\), and \(\ell \geqslant 1\), and when the second - highest - degree coefficient of these polynomials is non - zero, whether they can maintain the APN property in infinitely many finite field extensions. ### Background and Problem Statement In cryptography, differential uniformity is used to measure the ability of a mapping to resist differential cryptanalysis. For a polynomial \( f \in F_q[x] \) in the finite field \( F_q \), its differential uniformity is defined as: \[ \delta_{F_q}(f) := \max_{(\alpha, \beta) \in F_q^* \times F_q} \# \{ x \in F_q \mid f(x + \alpha) - f(x) = \beta \} \] In particular, in the case of even characteristics, the minimum differential uniformity value is 2, and the polynomial at this time is called an almost perfect nonlinear (APN) polynomial. APN polynomials are of great significance in cryptography. ### Research Objectives The main objective of this paper is to prove that for a sufficiently large \( n \), all polynomials of the form \( f = \sum_{k = 0}^m a_{m - k}x^k\in F_{2^n}[x] \), if their degree is \( m = 2^r(2\ell + 1) \) and the second - highest - degree coefficient \( a_1\neq 0 \), then their differential uniformity reaches the maximum value \( m - 2 \). This means that these polynomials cannot be exceptional APN (i.e., maintain the APN property in infinitely many finite field extensions). ### Main Conclusions The main conclusion of the article is: \[ \text{Theorem: Let } m = 2^r(2\ell + 1) \text{, where } \gcd(r, \ell) \leqslant 2, r\geqslant 2 \text{ and } \ell \geqslant 1 \text{. For a sufficiently large } n \text{, all polynomials of the form } f=\sum_{k = 0}^m a_{m - k}x^k\in F_{2^n}[x] \text{, if } a_1\neq 0 \text{, then their differential uniformity } \delta(f)=m - 2 \text{.} \] In other words, this type of polynomial cannot be an exceptional APN polynomial. ### Methods and Tools The authors used the Chebotarev density theorem in algebraic number theory to prove this conclusion. Through this method, they were able to handle the Morse property of polynomials and use tools such as symmetric groups and Galois theory, and finally proved the above conclusion. This result provides a new perspective for the study of the exceptional APN conjecture and solves two open cases: when the degree \( m = 4e \) and \( e \) is a Gold number, and when the degree \( m\equiv 0\pmod{8} \).