On a conjecture on the Kasami APN function: reductions, structure theorems, a proof for kmodn∈{1,2,n−2,n−1}, and exhaustive verification for n≤13
Published 19 Aug 2026 in math.CO and math.NT | (2608.18584v1)
Abstract: We study a conjecture on the Kasami almost perfect nonlinear (APN) function F(x)=x<sup>4<sup>k−2<sup>k+1 on GF(2<sup>n), gcd(k,n)=1: for the 2<sup>n−1-element set Δ=F(b)+F(b+1)+1:b∈GF(2<sup>n) and all distinct nonzero v1,v2∈GF(2<sup>n), [ \bigl|{(x,y,z)\inΔ3 : v_1x+v_2y+(v_1+v_2)z=0}\bigr| \;=\; 2{2n-3}. ] The conjecture was proposed at the NSUCRYPTO~2019 cryptographic olympiad (the proposer of the problem was not publicly disclosed). We prove the conjecture for kmodn∈1,2,n−2,n−1, in particular a complete proof for k=2 (d=13) via a quadratic-form theory and an exact root-count reduction, and we verify it exhaustively by computer for every admissible (n,k) with n≤13.
The paper proves the Kasami APN function conjecture for specific cases where k mod n ∈ {1,2,n−2,n−1}, using reductions and structural insights.
Develops three successive reductions to a vanishing character-sum statement, providing a detailed structural analysis of the conjecture over various finite fields.
Verifies the conjecture exhaustively for all admissible (n, k) with n <= 13, using Walsh-Hadamard transforms and random permutations.
The conjecture and its meaning
Let F=F2n and let F(x)=xd with d=4k−2k+1, gcd(k,n)=1, be the Kasami APN monomial. For the 2n−1-element set
Δ={F(b)+F(b+1)+1:b∈F},
the conjecture posed at NSUCRYPTO 2019 (with undisclosed proposer) asserts that for all distinct nonzero v1,v2∈F,
The value 22n−3 is exactly what a single F-linear condition would impose on a perfectly equidistributed subset of size F(x)=xd0; moreover, the paper shows unconditionally that F(x)=xd1 is the average of F(x)=xd2 over F(x)=xd3, so the conjecture asserts that F(x)=xd4 is constant and pinned at its mean. This average identity plays a decisive role later: it converts any lower bound on individual counts into an exact determination.
Reductions to a single character-sum vanishing statement
The paper develops three successive reductions. First, by additive-character orthogonality,
F(x)=xd5
where F(x)=xd6, F(x)=xd7, and F(x)=xd8. Thus the count depends only on F(x)=xd9, with an d=4k−2k+10-symmetry generated by d=4k−2k+11 and d=4k−2k+12.
Second, using the key identity (verified in Lean 4 in a companion repository)
d=4k−2k+13
the conjecture becomes a balancedness statement about the derivative d=4k−2k+14: the map d=4k−2k+15 must vanish exactly d=4k−2k+16 times.
Third — and this is the sharpest reformulation — after a Frobenius transfer reduces to odd d=4k−2k+17 (for which d=4k−2k+18 is a permutation), the conjecture is equivalent to
d=4k−2k+19
where gcd(k,n)=10: a uniform vanishing statement over all planes through the diagonal of gcd(k,n)=11.
One correction to prior informal fact lists is recorded: gcd(k,n)=12 is a permutation only for oddgcd(k,n)=13; for even gcd(k,n)=14 one has gcd(k,n)=15.
Proved cases and structural results
The easy case. For gcd(k,n)=16, one has gcd(k,n)=17 (the trace hyperplane), the support of gcd(k,n)=18 is gcd(k,n)=19, every term of 2n−10 vanishes individually, and the conjecture holds for all 2n−11.
A refuted mechanism. A natural candidate proof would require that no three distinct elements of 2n−12 sum to zero (e.g., support contained in 2n−13). The computations refute this decisively: for every tested pair with 2n−14 the support contains many zero-sum triples (e.g., 2n−15 violating pairs for 2n−16), yet 2n−17 throughout. Any general proof must therefore exploit genuine cancellation between nonzero terms rather than support disjointness. This negative result is arguably the most instructive structural finding short of the main theorem.
The monomial paradigm. For power permutations 2n−18, the scaling fibration 2n−19 collapses Δ={F(b)+F(b+1)+1:b∈F},0 to an exact root count: Δ={F(b)+F(b+1)+1:b∈F},1 where Δ={F(b)+F(b+1)+1:b∈F},2 counts roots of Δ={F(b)+F(b+1)+1:b∈F},3. Using this, the paper proves the analogue holds for all Gold permutations Δ={F(b)+F(b+1)+1:b∈F},4 (Δ={F(b)+F(b+1)+1:b∈F},5 odd) and for inversion Δ={F(b)+F(b+1)+1:b∈F},6 (all Δ={F(b)+F(b+1)+1:b∈F},7). Notably, Δ={F(b)+F(b+1)+1:b∈F},8 itself fails the identity for Δ={F(b)+F(b+1)+1:b∈F},9, so the property genuinely concerns the inverse map; and it is mask-sensitive for non-monomial v1,v2∈F0, while inner scalings v1,v2∈F1 preserve it.
Closed form. For odd v1,v2∈F2, a Gold substitution yields a second rational parametrization v1,v2∈F3 with v1,v2∈F4 bijective on v1,v2∈F5, converting the conjecture into a plain point count over the trace coset.
The main theorem: the case v1,v2∈F6
The first genuinely open case, v1,v2∈F7 (v1,v2∈F8, v1,v2∈F9 forced odd), is proved in full. Since here N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.0, every relevant character sum becomes a quadratic-form Gauss sum governed by radicals N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.1 of dimension N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.2. Three stages complete the proof:
Master correspondence. Incidences N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.3 are classified into two low-degree families — type I, parametrized by roots of the Bluher polynomial N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.4, and type II via N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.5 — with exact counts N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.6.
Counting theorem. Compatibility values satisfy N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.7 on type I and N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.8 on type II. A global-versus-local double count of "null pairs" (exactly N(v1,v2)={(x,y,z)∈Δ3:v1x+v2y+(v1+v2)z=0}=22n−3.9 globally) forces 22n−30: hence 22n−31, and consequently 22n−32 is exactly 2-to-1 on 22n−33 with trace-split fibers. The spectrum of 22n−34 is thereby pinned inside 22n−35 without any Arf-invariant computation.
Sign elimination. A monomial change of variables removes all signs, reducing 22n−36 to the exact root count
22n−37
over parameters 22n−38. The explicit root 22n−39 shows F0, and since F1 by the unconditional average identity, each term must vanish: F2, hence F3.
Geometrically, the residual claim states that on the supersingular Fermat cubic F4, the system F5, F6 has the unique solution F7 — a translation by the rational 3-torsion point F8; the 14 remaining intersection points of a degree-15 correspondence are never rational. Via Frobenius transfer this settles the conjecture for all F9.
Byproducts include an APN-free proof that F(x)=xd00 for F(x)=xd01, and the trace-separation lemma showing fibers of F(x)=xd02 pair one element of F(x)=xd03 with one of F(x)=xd04.
Numerical verification
All admissible F(x)=xd05 with F(x)=xd06 were verified exhaustively over all F(x)=xd07 (equivalently, all pairs F(x)=xd08 up to the proved scaling invariance), implemented from first principles in pure Python with Walsh–Hadamard transforms; counts equal F(x)=xd09 in every instance, with brute-force cross-checks for F(x)=xd10. Every theoretical identity (closed form, master correspondence, F(x)=xd11-values, counting ingredients, root-count reduction) was independently validated at F(x)=xd12, and random permutations fail F(x)=xd13, confirming the property is special rather than generic.
Limitations and open questions
The general case remains open for F(x)=xd14. The refuted termwise mechanism means no currently available Walsh-spectrum technology (Bluher root counts, Dillon–Dobbertin machinery) directly classifies the needed cancellation; the spectra are not uniformly plateaued and vary with the cyclotomic class of F(x)=xd15. The closed form requires odd F(x)=xd16, though the reduction to the F(x)=xd17-statement holds for both parities and even-F(x)=xd18 cases are verified exhaustively up to F(x)=xd19. The difference-set connection shows the conjecture is a canonical third moment beyond the Dillon–Dobbertin pair correlation, but generic Singer-parameter sets have non-flat triple correlations, so the difference-set property alone cannot suffice. The authors identify as most promising the template suggested by F(x)=xd20: prove the analogue of the trace-splitting/2-to-1 statement for general even F(x)=xd21, and find the monomial substitutions adapted to the Gold-ratio structure F(x)=xd22 that eliminate sign dependence.
It should also be noted plainly that the proofs were obtained by prompting an AI assistant (Claude Fable 5) and subsequently formalized in Lean 4 (by Aristotle, Harmonic); the mathematical content stands on the Lean verification and the self-contained arguments reproduced in the paper, but the provenance is unconventional.
Conclusion
The paper converts an open olympiad conjecture into a single clean vanishing statement for F(x)=xd23, proves it completely for F(x)=xd24 — including a fully unconditional, self-contained treatment of F(x)=xd25 via quadratic forms, Bluher-type classifications, a double-counting theorem, and a Fermat-cubic root count — verifies all cases with F(x)=xd26 exhaustively, and establishes by counterexample that only genuine cancellation mechanisms can close the remaining residue classes.