On the Boomerang Spectrum of Power Permutation over $\GF{2^{4n}}$ and Extraction of Optimal Uniformity Boomerang Functions
arXiv:2305.12655
Abstract
A substitution box (S-box) in a symmetric primitive is a mapping that takes binary inputs and whose image is a binary -tuple for some positive integers and , which is usually the only nonlinear element of the most modern block ciphers. Therefore, employing S-boxes with good cryptographic properties to resist various attacks is significant. For power permutation over finite field $\GF{2^k}$, the multiset of values $β_F(1,b)=\#\{x\in \GF{2^k}\mid F^{-1}(F(x)+b)+F^{-1}(F(x+1)+b)=1\}$ for $b\in \GF{2^k}$ is called the boomerang spectrum of . The maximum value in the boomerang spectrum is called boomerang uniformity. This paper determines the boomerang spectrum of the power permutation over $\GF{2^{4n}}$. The boomerang uniformity of that power permutation is . However, on a large subset $\{b\in \GF{2^{4n}}\mid \mathbf{Tr}_n^{4n}(b)\neq 0\}$ of $\GF{2^{4n}}$ of cardinality (where is the (relative) trace function from $\GF{2^{4n}}$ to $\GF{2^{n}}$), we prove that the studied function achieves the optimal boomerang uniformity . It is known that obtaining such functions is a challenging problem. More importantly, the set of 's giving this value is explicitly determined for any value in the boomerang spectrum.