Papers by Lukas Kölsch
17 paper(s) by this author
· All BibTeX
Triprojective almost perfect nonlinear permutations and functions
We give a large family of almost perfect nonlinear (APN) permutations of finite vector spaces of every odd dimension divisible by three. We also give APN functions that are not bijective on even dimensions and related highly nonlinear functions. The functions we provide admit a so-called triprojective structure induced by the general linear group $\mathrm{GL}(3,2^m)$.
Commutative Semifields from bijections of the Desarguesian plane
The Menichetti-Kaplansky theorem states that a finite semifield that is three-dimensional over its center is either a field or a twisted field of Albert. This implies that a quadratic homogeneous bijection of $\mathbb{P}^2(\mathbb{F}_q)$ is equivalent to a Dembowski-Ostrom monomial. In this paper, we give a large class of semiquadratic homogeneous bijections of $\mathbb{P}^2(\mathbb{F}_q)$ that are inequivalent to Dembowski-Ostrom monomials. Using these bijections, we construct a large family of commutative semifields that are non-isotopic to finite fields or twisted fields, which in turn give rise to a large family of non-Desarguesian commutative semifield planes. Semiquadratic homogeneous bijections of $\mathbb{P}^1(\mathbb{F}_q)$ have been classified only recently by the first-named author, and Ding and Zieve with the result that all such bijections are either equivalent to Dembowski-Ostrom monomials or degenerate. We demonstrate that this is not the case for $\mathbb{P}^2(\mathbb{F}_q)$.
On the Walsh spectra of quadratic APN functions
APN functions play a central role as building blocks in the design of many block ciphers, serving as optimal functions to resist differential attacks. One of the most important properties of APN functions is their linearity, which is directly related to the Walsh spectrum of the function. In this paper, we establish two novel connections that allow us to derive strong conditions on the Walsh spectra of quadratic APN functions. We prove that the Walsh transform of a quadratic APN function $F$ operating on $n=2k$ bits is uniquely associated with a vector space partition of $\mathbb{F}_2^n$ and a specific blocking set in the corresponding projective space $PG(n-1,2)$. These connections allow us to prove a variety of results on the Walsh spectrum of $F$. We prove for instance that $F$ can have at most one component function of amplitude larger than $2^{3n/4}$. We also find the first nontrivial upper bound on the number of bent component functions of a quadratic APN function, and provide conditions for a function to be CCZ-equivalent to a permutation based on its number of bent components.
The autotopism group of a family of commutative semifields
We completely determine the autotopism group of the (as of now) largest family of commutative semifields found by Göloğlu and Kölsch. Since this family of semifields generally does not have large nuclei, this process is considerably harder than for families considered in preceding work. Our results show that all autotopisms are semilinear over the degree 2 subfield and that the autotopism group is always solvable. Using known connections, our results also completely determine the automorphism groups of the associated rank-metric codes and the collineation groups of the associated translation planes.
The combinatorial structure and value distributions of plateaued functions
We study combinatorial properties of plateaued functions $F \colon \mathbb{F}_p^n \rightarrow \mathbb{F}_p^m$. All quadratic functions, bent functions and most known APN functions are plateaued, so many cryptographic primitives rely on plateaued functions as building blocks. The main focus of our study is the interplay of the Walsh transform and linearity of a plateaued function, its differential properties, and their value distributions, i.e., the sizes of image and preimage sets. In particular, we study the special case of ''almost balanced'' plateaued functions, which only have two nonzero preimage set sizes, generalizing for instance all monomial functions. We achieve several direct connections and (non)existence conditions for these functions, showing for instance that plateaued $d$-to-$1$ functions (and thus plateaued monomials) only exist for a very select choice of $d$, and we derive for all these functions their linearity as well as bounds on their differential uniformity. We also specifically study the Walsh transform of plateaued APN functions and their relation to their value distribution.
A unifying construction of semifields of order $p^{2m}$
In this article, we present two new constructions for semifields of order $p^{2m}$. Together, the constructions unify and generalize around a dozen distinct semifield constructions, including both the oldest known construction by Dickson and the largest known construction in odd characteristic by Taniguchi. The constructions also provably yield many new semifields. We give precise conditions when the new semifields we find are equivalent and count precisely how many new inequivalent semifields we construct.
Factorization and irreducibility of composed products
Brawley and Carlitz introduced diamond products of elements of finite fields and associated composed products of polynomials in 1987. Composed products yield a method to construct irreducible polynomials of large composite degrees from irreducible polynomials of lower degrees. We show that the composed product of two irreducible polynomials of degrees $m$ and $n$ is again irreducible if and only if $m$ and $n$ are coprime and the involved diamond product satisfies a special cancellation property, the so-called conjugate cancellation. This completes the characterization of irreducible composed products, considered in several previous papers. More generally, we give precise criteria when a diamond product satisfies conjugate cancellation. For diamond products defined via bivariate polynomials, we prove simple criteria that characterize when conjugate cancellation holds. We also provide efficient algorithms to check these criteria. We achieve stronger results as well as more efficient algorithms in the case that the polynomials are bilinear. Lastly, we consider possible constructions of normal elements using composed products and the methods we developed.
On a recent extension of a family of biprojective APN functions
APN functions play a big role as primitives in symmetric cryptography as building blocks that yield optimal resistance to differential attacks. In this note, we consider a recent extension of a biprojective APN family by Göloğlu defined on $\mathbb{F}_{2^{2m}}$. We show that this generalization yields functions equivalent to Göloğlu's original family if $3\nmid m$. If $3|m$ we show exactly how many inequivalent APN functions this new family contains. We also show that the family has the minimal image set size for an APN function and determine its Walsh spectrum, hereby settling some open problems. In our proofs, we leverage a group theoretic technique recently developed by Göloğlu and the author in conjunction with a group action on the set of projective polynomials.
Value Distributions of Perfect Nonlinear Functions
Published in Kölsch, L., Polujan, A. Value Distributions of Perfect Nonlinear Functions. Combinatorica (2023)
• View Publication
• BIB
In this paper, we study the value distributions of perfect nonlinear functions, i.e., we investigate the sizes of image and preimage sets. Using purely combinatorial tools, we develop a framework that deals with perfect nonlinear functions in the most general setting, generalizing several results that were achieved under specific constraints. For the particularly interesting elementary abelian case, we derive several new strong conditions and classification results on the value distributions. Moreover, we show that most of the classical constructions of perfect nonlinear functions have very specific value distributions, in the sense that they are almost balanced. Consequently, we completely determine the possible value distributions of vectorial Boolean bent functions with output dimension at most 4. Finally, using the discrete Fourier transform, we show that in some cases value distributions can be used to determine whether a given function is perfect nonlinear, or to decide whether given perfect nonlinear functions are equivalent.
Counting the number of non-isotopic Taniguchi semifields
We investigate the isotopy question for Taniguchi semifields. We give a complete characterization when two Taniguchi semifields are isotopic. We further give precise upper and lower bounds for the total number of non-isotopic Taniguchi semifields, proving that there are around $p^{m+s}$ non-isotopic Taniguchi semifields of size $p^{2m}$ where $s$ is the largest divisor of $m$ with $2s\neq m$. This result proves that the family of Taniguchi semifields is (asymptotically) the biggest known family of semifields of odd order. The key ingredient of the proofs is a technique to determine isotopy that uses group theory to exploit the existence of certain large subgroups of the autotopism group of a semifield.
Equivalences of biprojective almost perfect nonlinear functions
Published
• View Publication
• BIB
Two important problems on almost perfect nonlinear (APN) functions are the enumeration and equivalence problems. In this paper, we solve these two problems for any biprojective APN function family by introducing a strong group theoretic method for those functions. Roughly half of the known APN families of functions on even dimensions are biprojective. By our method, we settle the equivalence problem for all known biprojective APN functions. Furthermore, we give a new family of biprojective APN functions. Using our method, we count the number of inequivalent APN functions in all known biprojective APN families and show that the new family found in this paper gives exponentially many new inequivalent APN functions. Quite recently, the Taniguchi family of APN functions was shown to contain an exponential number of inequivalent APN functions by Kaspers and Zhou (J. Cryptol. 34 (1), 2021) which improved their previous count (J. Comb. Th. A 186, 2022) for the Zhou-Pott family. Our group theoretic method substantially simplifies the work required for proving those results and provides a generic natural method for every family in the large super-class of biprojective APN functions that contains these two family along with many others.
An exponential bound on the number of non-isotopic commutative semifields
We show that the number of non-isotopic commutative semifields of odd order $p^{n}$ is exponential in $n$ when $n = 4t$ and $t$ is not a power of $2$. We introduce a new family of commutative semifields and a method for proving isotopy results on commutative semifields that we use to deduce the aforementioned bound. The previous best bound on the number of non-isotopic commutative semifields of odd order was quadratic in $n$ and given by Zhou and Pott [Adv. Math. 234 (2013)]. Similar bounds in the case of even order were given in Kantor [J. Algebra 270 (2003)] and Kantor and Williams [Trans. Amer. Math. Soc. 356 (2004)].
Image sets of perfectly nonlinear maps
We consider image sets of differentially $d$-uniform maps of finite fields. We present a lower bound on the image size of such maps and study their preimage distribution, by extending methods used for planar maps. We apply the results to study $d$-uniform Dembowski-Ostrom polynomials. Further, we focus on a particularly interesting case of APN maps on binary fields. We show that APN maps with the minimal image size must have a very special preimage distribution. We prove that for an even $n$ the image sets of several well-studied families of APN maps are minimal. We present results connecting the image sets of special maps with their Walsh spectrum. Especially, we show that the fact that several large classes of APN maps have the classical Walsh spectrum is explained by the minimality of their image sets. Finally, we present upper bounds on the image size of APN maps.
Formal self duality
Published in Kölsch, L., Schüler, R. Formal self duality. Cryptogr. Commun. (2021)
• View Publication
• BIB
We study the notion of formal self duality in finite abelian groups. Formal duality in finite abelian groups has been proposed by Cohn, Kumar, Reiher and Schürmann. In this paper we give a precise definition of formally self dual sets and discuss results from the literature in this perspective. Also, we discuss the connection to formally dual codes. We prove that formally self dual sets can be reduced to primitive formally self dual sets similar to a previously known result on general formally dual sets. Furthermore, we describe several properties of formally self dual sets. Also, some new examples of formally self dual sets are presented within this paper. Lastly, we study formally self dual sets of the form $\{(x,F(x)) \ : \ x\in\mathbb{F}_{2^n}\}$ where $F$ is a vectorial Boolean function mapping $\mathbb{F}_{2^n}$ to $\mathbb{F}_{2^n}$.
On CCZ-equivalence of the inverse function
Published
• View Publication
• BIB
The inverse function $x \mapsto x^{-1}$ on $\mathbb{F}_{2^n}$ is one of the most studied functions in cryptography due to its widespread use as an S-box in block ciphers like AES. In this paper, we show that, if $n\geq 5$, every function that is CCZ-equivalent to the inverse function is already EA-equivalent to it. This confirms a conjecture by Budaghyan, Calderini and Villa. We also prove that every permutation that is CCZ-equivalent to the inverse function is already affine equivalent to it. The majority of the paper is devoted to proving that there are no permutation polynomials of the form $L_1(x^{-1})+L_2(x)$ over $\mathbb{F}_{2^n}$ if $n\geq 5$, where $L_1,L_2$ are nonzero linear functions. In the proof, we combine Kloosterman sums, quadratic forms and tools from additive combinatorics.
On subspaces of Kloosterman zeros and permutations of the form $L_1(x^{-1})+L_2(x)$
Permutations of the form $F=L_1(x^{-1})+L_2(x)$ with linear functions $L_1,L_2$ are closely related to several interesting questions regarding CCZ-equivalence and EA-equivalence of the inverse function. In this paper, we show that $F$ cannot be a permutation if the kernel of $L_1$ or $L_2$ is too large. A key step of the proof is a new result on the maximal size of a subspace of $\mathbb{F}_{2^n}$ that contains only Kloosterman zeros, i.e. a subspace $V$ such that $K_n(v)=0$ for all $v \in V$ where $K_n(v)$ denotes the Kloosterman sum of $v$.}
On the inverses of Kasami and Bracken-Leander exponents
We explicitly determine the binary representation of the inverse of all Kasami exponents $K_r=2^{2r}-2^r+1$ modulo $2^n-1$ for all possible values of $n$ and $r$. This includes as an important special case the APN Kasami exponents with $\gcd(r,n)=1$. As a corollary, we determine the algebraic degree of the inverses of the Kasami functions. In particular, we show that the inverse of an APN Kasami function on $\mathbb{F}_{2^n}$ always has algebraic degree $\frac{n+1}{2}$ if $n\equiv 0 \pmod 3$. For $n\not\equiv 0 \pmod 3$ we prove that the algebraic degree is bounded from below by $\frac{n}{3}$. We consider Kasami exponents whose inverses are quadratic exponents or Kasami exponents. We also determine the binary representation of the inverse of the Bracken-Leander exponent $BL_r=2^{2r}+2^r+1$ modulo $2^n-1$ where $n=4r$ and $r$ odd. We show that the algebraic degree of the inverse of the Bracken-Leander function is $\frac{n+2}{2}$.