On CCZ-Equivalence of the Inverse Function

Lukas Kölsch,Lukas Kolsch
DOI: https://doi.org/10.1109/tit.2021.3065068
IF: 2.5
2021-07-01
IEEE Transactions on Information Theory
Abstract:The inverse function $x mapsto x^{-1}$ on $mathbb F_{2^{n}}$ is one of the most studied functions in cryptography due to its widespread use as an S-box in block ciphers like AES. In this paper, we show that, if $ngeq 5$ , every function that is CCZ-equivalent to the inverse function is already EA-equivalent to it. This confirms a conjecture by Budaghyan, Calderini and Villa. We also prove that every permutation that is CCZ-equivalent to the inverse function is already affine equivalent to it. The majority of the paper is devoted to proving that there is no permutation polynomial of the form $L_{1}(x^{-1})+L_{2}(x)$ over $mathbb F_{2^{n}}$ if $ngeq 5$ , where $L_{1},L_{2}$ are nonzero linear functions. In the proof, we combine Kloosterman sums, quadratic forms and tools from additive combinatorics.
computer science, information systems,engineering, electrical & electronic
What problem does this paper attempt to address?