Papers
Topics
Authors
Recent
Search
2000 character limit reached

An Affine Equivalence Algorithm for S-boxes based on Matrix Invariants

Published 19 Nov 2024 in cs.CR and cs.DS | (2411.12360v1)

Abstract: We investigate the affine equivalence (AE) problem of S-boxes. Given two S-boxes denoted as S1S_1 and S2S_2, we aim to seek two invertible AE transformations A,BA,B such that S1∘A=B∘S2S_1\circ A = B\circ S_2 holds. Due to important applications in the analysis and design of block ciphers, the investigation of AE algorithms has performed growing significance. In this paper, we propose zeroization on S-box firstly, and the AE problem can be transformed into $2n$ linear equivalence problems by this zeroization operation. Secondly, we propose standard orthogonal spatial matrix (SOSM), and the rank of the SOSM is invariant under AE transformations. Finally, based on the zeroization operation and the SOSM method, we propose a depth first search (DFS) method for determining AE of S-boxes, named the AE_SOSM_DFS algorithm. Using this matrix invariant, we optimize the temporal complexity of the algorithm to approximately 12<sup>n\frac{1}{2<sup>n} of the complexity without SOSM. Specifically, the complexity of our algorithm is O(2<sup>3n)O(2<sup>{3n}). In addition, we also conducted experiments with non-invertible S-boxes, and the performance is similar to that of invertible S-boxes. Moreover, our proposed algorithm can effectively handle S-boxes with low algebraic degree or certain popular S-boxes such as namely AES and ARIA_s2, which are difficult to be handled by the algorithm proposed by Dinur (2018). Using our algorithm, it only takes 5.5 seconds to find out that the seven popular S-boxes namely AES, ARIA_s2, Camellia, Chiasmus, DBlock, SEED_S0, and SMS4 are affine equivalent and the AE transformations of these S-boxes are provided.

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.