The multivariate method strikes again: New power functions with low differential uniformity in odd characteristic

Patrick Felke · Cryptography and Communications · 2020

Abstract Let f(x) = xd be a power mapping over $\mathbb {F}_{n}$ F n and $\mathcal {U}_{d}$ U d the maximum number of solutions $x\in \mathbb {F}_{n}$ x ∈ F n of ${\Delta }_{f,c}(x):=f(x+c)-f(x)=a\text {, where }c,a\in \mathbb {F}_{n}\text { and } c eq 0$ Δ f , c ( x ) : = f ( x + c ) − f ( x ) = a , where c , a ∈ F n and c ≠ 0 . f is said to be differentially k-uniform if $\mathcal {U}_{d} =k$ U d = k . The investigation of power functions with low differential uniformity over finite fields $\mathbb {F}_{n}$ F n of odd characteristic has attracted a lot of research interest since Helleseth, Rong and Sandberg started to conduct extensive computer search to identify such functions. These numerical results are well-known as the Helleseth-Rong-Sandberg tables and are the basis of many infinite families of power mappings $x^{d_{n}},n \in \mathbb {N},$ x d n , n ∈ ℕ , of low uniformity (see e.g. Dobbertin et al. Discret. Math. 267, 95–112 2003; Helleseth et al. IEEE Trans. Inform Theory, 45, 475–485 1999; Helleseth and Sandberg AAECC, 8, 363–370 1997; Leducq Amer. J. Math. 1(3) 115–123 1878; Zha and Wang Sci. China Math. 53(8) 1931–1940 2010). Recently the crypto currency IOTA and Cybercrypt started to build computer chips around base-3 logic to employ their new ternary hash function Troika, which currently increases the cryptogrpahic interest in such families. Especially bijective power mappings are of interest, as they can also be employed in block- and stream ciphers. In this paper we contribute to this development and give a family of power mappings $x^{d_{n}}$ x d n with low uniformity over $\mathbb {F}_{n}$ F n , which is bijective for p ≡ 3 mod 4. For p = 3 this yields a family $x^{d_{n}}$ x d n with $3\leq \mathcal {U}_{d_{n}}\leq 4,$ 3 ≤ U d n ≤

Read the paper · More papers on PaperTik