Papers
Topics
Authors
Recent
Search
2000 character limit reached

On a conjecture on the Kasami APN function: reductions, structure theorems, a proof for kmodn{1,2,n2,n1}k\bmod n\in\{1,2,n{-}2,n{-}1\}, and exhaustive verification for n13n\le 13

Published 19 Aug 2026 in math.CO and math.NT | (2608.18584v1)

Abstract: We study a conjecture on the Kasami almost perfect nonlinear (APN) function F(x)=x<sup>4<sup>k2<sup>k+1F(x)=x<sup>{4<sup>k-2<sup>k+1} on GF(2<sup>n)GF(2<sup>n), gcd(k,n)=1\gcd(k,n)=1: for the 2<sup>n12<sup>{n-1}-element set Δ=F(b)+F(b+1)+1:bGF(2<sup>n)Δ={F(b)+F(b+1)+1: b\in GF(2<sup>n)} and all distinct nonzero v1,v2GF(2<sup>n)v_1,v_2\in GF(2<sup>n), [ \bigl|{(x,y,z)\inΔ3 : v_1x+v_2y+(v_1+v_2)z=0}\bigr| \;=\; 2{2n-3}. ] The conjecture was proposed at the NSUCRYPTO~2019 cryptographic olympiad (the proposer of the problem was not publicly disclosed). We prove the conjecture for kmodn1,2,n2,n1k\bmod n\in{1,2,n-2,n-1}, in particular a complete proof for k=2k=2 (d=13d=13) via a quadratic-form theory and an exact root-count reduction, and we verify it exhaustively by computer for every admissible (n,k)(n,k) with n13n\le13.

Authors (2)

Summary

  • The paper proves the Kasami APN function conjecture for specific cases where k mod n ∈ {1,2,n−2,n−1}, using reductions and structural insights.
  • Develops three successive reductions to a vanishing character-sum statement, providing a detailed structural analysis of the conjecture over various finite fields.
  • Verifies the conjecture exhaustively for all admissible (n, k) with n <= 13, using Walsh-Hadamard transforms and random permutations.

The conjecture and its meaning

Let F=F2nF=\mathbb{F}_{2^n} and let F(x)=xdF(x)=x^d with d=4k2k+1d=4^k-2^k+1, gcd(k,n)=1\gcd(k,n)=1, be the Kasami APN monomial. For the 2n12^{n-1}-element set

Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},

the conjecture posed at NSUCRYPTO 2019 (with undisclosed proposer) asserts that for all distinct nonzero v1,v2Fv_1,v_2\in F,

N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.

The value 22n32^{2n-3} is exactly what a single FF-linear condition would impose on a perfectly equidistributed subset of size F(x)=xdF(x)=x^d0; moreover, the paper shows unconditionally that F(x)=xdF(x)=x^d1 is the average of F(x)=xdF(x)=x^d2 over F(x)=xdF(x)=x^d3, so the conjecture asserts that F(x)=xdF(x)=x^d4 is constant and pinned at its mean. This average identity plays a decisive role later: it converts any lower bound on individual counts into an exact determination.

Reductions to a single character-sum vanishing statement

The paper develops three successive reductions. First, by additive-character orthogonality,

F(x)=xdF(x)=x^d5

where F(x)=xdF(x)=x^d6, F(x)=xdF(x)=x^d7, and F(x)=xdF(x)=x^d8. Thus the count depends only on F(x)=xdF(x)=x^d9, with an d=4k2k+1d=4^k-2^k+10-symmetry generated by d=4k2k+1d=4^k-2^k+11 and d=4k2k+1d=4^k-2^k+12.

Second, using the key identity (verified in Lean 4 in a companion repository)

d=4k2k+1d=4^k-2^k+13

the conjecture becomes a balancedness statement about the derivative d=4k2k+1d=4^k-2^k+14: the map d=4k2k+1d=4^k-2^k+15 must vanish exactly d=4k2k+1d=4^k-2^k+16 times.

Third — and this is the sharpest reformulation — after a Frobenius transfer reduces to odd d=4k2k+1d=4^k-2^k+17 (for which d=4k2k+1d=4^k-2^k+18 is a permutation), the conjecture is equivalent to

d=4k2k+1d=4^k-2^k+19

where gcd(k,n)=1\gcd(k,n)=10: a uniform vanishing statement over all planes through the diagonal of gcd(k,n)=1\gcd(k,n)=11.

One correction to prior informal fact lists is recorded: gcd(k,n)=1\gcd(k,n)=12 is a permutation only for odd gcd(k,n)=1\gcd(k,n)=13; for even gcd(k,n)=1\gcd(k,n)=14 one has gcd(k,n)=1\gcd(k,n)=15.

Proved cases and structural results

The easy case. For gcd(k,n)=1\gcd(k,n)=16, one has gcd(k,n)=1\gcd(k,n)=17 (the trace hyperplane), the support of gcd(k,n)=1\gcd(k,n)=18 is gcd(k,n)=1\gcd(k,n)=19, every term of 2n12^{n-1}0 vanishes individually, and the conjecture holds for all 2n12^{n-1}1.

A refuted mechanism. A natural candidate proof would require that no three distinct elements of 2n12^{n-1}2 sum to zero (e.g., support contained in 2n12^{n-1}3). The computations refute this decisively: for every tested pair with 2n12^{n-1}4 the support contains many zero-sum triples (e.g., 2n12^{n-1}5 violating pairs for 2n12^{n-1}6), yet 2n12^{n-1}7 throughout. Any general proof must therefore exploit genuine cancellation between nonzero terms rather than support disjointness. This negative result is arguably the most instructive structural finding short of the main theorem.

The monomial paradigm. For power permutations 2n12^{n-1}8, the scaling fibration 2n12^{n-1}9 collapses Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},0 to an exact root count: Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},1 where Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},2 counts roots of Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},3. Using this, the paper proves the analogue holds for all Gold permutations Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},4 (Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},5 odd) and for inversion Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},6 (all Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},7). Notably, Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},8 itself fails the identity for Δ={F(b)+F(b+1)+1: bF},\Delta=\{F(b)+F(b+1)+1:\ b\in F\},9, so the property genuinely concerns the inverse map; and it is mask-sensitive for non-monomial v1,v2Fv_1,v_2\in F0, while inner scalings v1,v2Fv_1,v_2\in F1 preserve it.

Closed form. For odd v1,v2Fv_1,v_2\in F2, a Gold substitution yields a second rational parametrization v1,v2Fv_1,v_2\in F3 with v1,v2Fv_1,v_2\in F4 bijective on v1,v2Fv_1,v_2\in F5, converting the conjecture into a plain point count over the trace coset.

The main theorem: the case v1,v2Fv_1,v_2\in F6

The first genuinely open case, v1,v2Fv_1,v_2\in F7 (v1,v2Fv_1,v_2\in F8, v1,v2Fv_1,v_2\in F9 forced odd), is proved in full. Since here N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.0, every relevant character sum becomes a quadratic-form Gauss sum governed by radicals N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.1 of dimension N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.2. Three stages complete the proof:

  1. Master correspondence. Incidences N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.3 are classified into two low-degree families — type I, parametrized by roots of the Bluher polynomial N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.4, and type II via N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.5 — with exact counts N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.6.
  2. Counting theorem. Compatibility values satisfy N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.7 on type I and N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.8 on type II. A global-versus-local double count of "null pairs" (exactly N(v1,v2)={(x,y,z)Δ3: v1x+v2y+(v1+v2)z=0}=22n3.N(v_1,v_2)=\bigl|\{(x,y,z)\in\Delta^3:\ v_1x+v_2y+(v_1+v_2)z=0\}\bigr|=2^{2n-3}.9 globally) forces 22n32^{2n-3}0: hence 22n32^{2n-3}1, and consequently 22n32^{2n-3}2 is exactly 2-to-1 on 22n32^{2n-3}3 with trace-split fibers. The spectrum of 22n32^{2n-3}4 is thereby pinned inside 22n32^{2n-3}5 without any Arf-invariant computation.
  3. Sign elimination. A monomial change of variables removes all signs, reducing 22n32^{2n-3}6 to the exact root count

22n32^{2n-3}7

over parameters 22n32^{2n-3}8. The explicit root 22n32^{2n-3}9 shows FF0, and since FF1 by the unconditional average identity, each term must vanish: FF2, hence FF3.

Geometrically, the residual claim states that on the supersingular Fermat cubic FF4, the system FF5, FF6 has the unique solution FF7 — a translation by the rational 3-torsion point FF8; the 14 remaining intersection points of a degree-15 correspondence are never rational. Via Frobenius transfer this settles the conjecture for all FF9.

Byproducts include an APN-free proof that F(x)=xdF(x)=x^d00 for F(x)=xdF(x)=x^d01, and the trace-separation lemma showing fibers of F(x)=xdF(x)=x^d02 pair one element of F(x)=xdF(x)=x^d03 with one of F(x)=xdF(x)=x^d04.

Numerical verification

All admissible F(x)=xdF(x)=x^d05 with F(x)=xdF(x)=x^d06 were verified exhaustively over all F(x)=xdF(x)=x^d07 (equivalently, all pairs F(x)=xdF(x)=x^d08 up to the proved scaling invariance), implemented from first principles in pure Python with Walsh–Hadamard transforms; counts equal F(x)=xdF(x)=x^d09 in every instance, with brute-force cross-checks for F(x)=xdF(x)=x^d10. Every theoretical identity (closed form, master correspondence, F(x)=xdF(x)=x^d11-values, counting ingredients, root-count reduction) was independently validated at F(x)=xdF(x)=x^d12, and random permutations fail F(x)=xdF(x)=x^d13, confirming the property is special rather than generic.

Limitations and open questions

The general case remains open for F(x)=xdF(x)=x^d14. The refuted termwise mechanism means no currently available Walsh-spectrum technology (Bluher root counts, Dillon–Dobbertin machinery) directly classifies the needed cancellation; the spectra are not uniformly plateaued and vary with the cyclotomic class of F(x)=xdF(x)=x^d15. The closed form requires odd F(x)=xdF(x)=x^d16, though the reduction to the F(x)=xdF(x)=x^d17-statement holds for both parities and even-F(x)=xdF(x)=x^d18 cases are verified exhaustively up to F(x)=xdF(x)=x^d19. The difference-set connection shows the conjecture is a canonical third moment beyond the Dillon–Dobbertin pair correlation, but generic Singer-parameter sets have non-flat triple correlations, so the difference-set property alone cannot suffice. The authors identify as most promising the template suggested by F(x)=xdF(x)=x^d20: prove the analogue of the trace-splitting/2-to-1 statement for general even F(x)=xdF(x)=x^d21, and find the monomial substitutions adapted to the Gold-ratio structure F(x)=xdF(x)=x^d22 that eliminate sign dependence.

It should also be noted plainly that the proofs were obtained by prompting an AI assistant (Claude Fable 5) and subsequently formalized in Lean 4 (by Aristotle, Harmonic); the mathematical content stands on the Lean verification and the self-contained arguments reproduced in the paper, but the provenance is unconventional.

Conclusion

The paper converts an open olympiad conjecture into a single clean vanishing statement for F(x)=xdF(x)=x^d23, proves it completely for F(x)=xdF(x)=x^d24 — including a fully unconditional, self-contained treatment of F(x)=xdF(x)=x^d25 via quadratic forms, Bluher-type classifications, a double-counting theorem, and a Fermat-cubic root count — verifies all cases with F(x)=xdF(x)=x^d26 exhaustively, and establishes by counterexample that only genuine cancellation mechanisms can close the remaining residue classes.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.