Papers
Topics
Authors
Recent
Search
2000 character limit reached

Circular External Difference Families (CEDF)

Updated 10 July 2026
  • CEDF is a collection of disjoint, equal-size subsets of a finite group whose cyclic external differences cover every nonzero element with a fixed multiplicity.
  • CEDFs directly correspond to optimal weak circular AMD codes, enabling unconditionally secure, non-malleable threshold schemes through precise combinatorial design.
  • Research on CEDFs spans explicit cyclotomic and graph-labelling constructions, existence and nonexistence results in cyclic and noncyclic groups, and several open combinatorial problems.

A circular external difference family (CEDF) is a collection of pairwise disjoint equal-size subsets of a finite group whose prescribed cyclic external differences cover every nonzero group element with a fixed multiplicity. In the form introduced by Veitch and Stinson, CEDFs arose as the exact combinatorial structures underlying optimal weak circular algebraic manipulation detection (AMD) codes and hence unconditionally secure non-malleable threshold schemes (Veitch et al., 2023). Subsequent work by Paterson and Stinson, Huczynska, Jefferson and McCartney, and others developed existence and non-existence theory, graceful-labelling and cyclotomic constructions, digraph-defined generalizations, and extensions to noncyclic abelian and nonabelian groups (Paterson et al., 2023, Huczynska et al., 29 Apr 2025).

1. Formal definition and parameter constraints

Let GG be a finite additive abelian group of order nn. Fix integers m2m \ge 2, 1cm11 \le c \le m-1, and positive integers ,λ\ell,\lambda. Suppose

A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G

are pairwise disjoint and satisfy Aj=|A_j|=\ell for all jj. For two disjoint subsets X,YGX,Y\subseteq G, define the multiset of external differences

D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.

Then nn0 is an nn1–nn2-circular external difference family if

nn3

as multisets; equivalently, every nonzero nn4 appears exactly nn5 times among all differences nn6 with nn7 and nn8 (Veitch et al., 2023).

A necessary size condition is

nn9

In the common case m2m \ge 20, this forces m2m \ge 21 (Veitch et al., 2023). When m2m \ge 22, the family is called cyclic (Burgess et al., 2 Sep 2025). The terminology “CEDF” is often used for the case m2m \ge 23.

A broader formulation, developed in group-ring language, allows a set of shifts m2m \ge 24. In multiplicative notation, an m2m \ge 25–m2m \ge 26–CEDF satisfies

m2m \ge 27

in m2m \ge 28 (Wu et al., 2023). This places ordinary CEDFs, m2m \ge 29-CEDFs, and related external difference families in a common algebraic framework.

2. Equivalence with circular AMD codes and non-malleable threshold schemes

The central structural theorem identifies CEDFs with optimal circular AMD codes. In the weak circular AMD game, the adversary picks a nonzero 1cm11 \le c \le m-10; a source index 1cm11 \le c \le m-11 is chosen uniformly; a codeword 1cm11 \le c \le m-12 is drawn uniformly; and the adversary wins if 1cm11 \le c \le m-13. Such a code is 1cm11 \le c \le m-14-optimal if the maximum success probability is

1cm11 \le c \le m-15

Veitch and Stinson proved that 1cm11 \le c \le m-16 is an 1cm11 \le c \le m-17-optimal weak 1cm11 \le c \le m-18-circular 1cm11 \le c \le m-19-AMD code if and only if it is an ,λ\ell,\lambda0–,λ\ell,\lambda1-CEDF with

,λ\ell,\lambda2

In particular, in the tight case ,λ\ell,\lambda3, CEDFs are exactly the optimal weak circular AMD codes (Veitch et al., 2023).

This equivalence feeds directly into secret sharing. On the secret space ,λ\ell,\lambda4, define

,λ\ell,\lambda5

Feeding an ,λ\ell,\lambda6-optimal ,λ\ell,\lambda7-circular AMD code into Shamir’s scheme yields a ,λ\ell,\lambda8 threshold scheme that is ,λ\ell,\lambda9-non-malleable with respect to A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G0 (Veitch et al., 2023). In the threshold construction, the dealer chooses a secret A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G1 uniformly, picks A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G2 uniformly, distributes shares of A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G3 via Shamir over A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G4, and reconstructs by recovering A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G5 from A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G6 shares and outputting the unique A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G7 such that A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G8 (Veitch et al., 2023).

The cryptographic interpretation is that tampering attempts to move an encoding of source A0,A1,,Am1GA_0,A_1,\dots,A_{m-1}\subseteq G9 into an encoding of source Aj=|A_j|=\ell0. Any tampering on a single share shifts Aj=|A_j|=\ell1, and winning the Aj=|A_j|=\ell2-malleability game requires Aj=|A_j|=\ell3 to land in Aj=|A_j|=\ell4; by Aj=|A_j|=\ell5-optimality this succeeds with probability at most Aj=|A_j|=\ell6 (Veitch et al., 2023). Paterson and Stinson restated the same equivalence for the case Aj=|A_j|=\ell7: an Aj=|A_j|=\ell8-optimal circular weak Aj=|A_j|=\ell9-AMD code is equivalent to an jj0-CEDF (Paterson et al., 2023).

3. Existence and non-existence landscape

The known existence theory is most complete in the tight cyclic case jj1, where jj2. Several parameter regimes are settled, while others remain open.

Parameter regime Cyclic status Source
even jj3, any jj4 jj5-CEDF exists (Paterson et al., 2023)
jj6 both odd no cyclic jj7-CEDF (Paterson et al., 2023)
odd jj8, jj9 cyclic X,YGX,Y\subseteq G0-CEDF exists (Burgess et al., 2 Sep 2025)
X,YGX,Y\subseteq G1, even X,YGX,Y\subseteq G2 cyclic X,YGX,Y\subseteq G3-CEDF exists (Burgess et al., 2 Sep 2025)
X,YGX,Y\subseteq G4, shift X,YGX,Y\subseteq G5 X,YGX,Y\subseteq G6–2-CEDF exists in X,YGX,Y\subseteq G7 (Angus et al., 5 Mar 2026)

For cyclic groups, Paterson and Stinson proved that if X,YGX,Y\subseteq G8 is even and X,YGX,Y\subseteq G9 then an D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.0-CEDF exists, while if D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.1 and D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.2 are both odd then no such cyclic CEDF exists (Paterson et al., 2023). The odd-odd non-existence result is described in later work as a parity obstruction: the cyclic symmetry plus odd-odd parameters create a parity-sum contradiction (Burgess et al., 2 Sep 2025).

The 2025 paper “On circular external difference families” sharpened the cyclic existence picture when D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.3 is odd and D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.4 is even. It constructed cyclic D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.5-CEDFs for every odd D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.6, and cyclic D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.7-CEDFs for every even D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.8 (Burgess et al., 2 Sep 2025). As stated there, this fills the last gaps for D(X,Y)={xy:xX, yY}.D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.9 in the cyclic case and resolves the entire nn00 row for even nn01.

A separate line of work provides a uniform explicit cyclic family for all even nn02 in nn03, avoiding the earlier case-splitting according to nn04 or nn05 (Huczynska et al., 29 Apr 2025). More recently, graph-labelling methods produced the first explicit construction for an infinite family of nn06-CEDFs, achieving all parameter sets for nn07–nn08-CEDFs with nn09 sets (Angus et al., 5 Mar 2026).

Open cyclic cases remain. For general odd nn10 and even nn11, cyclic constructions beyond nn12 for all odd nn13 and beyond nn14 for all even nn15 remain open (Burgess et al., 2 Sep 2025).

4. Construction paradigms

Two construction paradigms dominate the literature: cyclotomy in finite fields and graph-labelling methods.

Veitch and Stinson’s field-based construction begins with a finite field nn16 such that nn17, a primitive element nn18, and the subgroup

nn19

of order nn20. For nn21, define

nn22

Then nn23 are disjoint nn24-subsets of nn25, and they form a nn26–nn27-CEDF if and only if

nn28

is a full set of coset representatives of nn29 in nn30; in that case nn31 (Veitch et al., 2023). The specialization nn32 gives a particularly concrete criterion: if nn33 and nn34 is primitive, then the cosets

nn35

form a nn36–nn37-CEDF if and only if nn38 is a quadratic non-residue (Veitch et al., 2023).

This cyclotomic approach extends to arbitrary circular step nn39. In the notation of Wang and coauthors, if nn40, nn41, nn42, and nn43, then nn44 is a nn45–nn46-CEDF if and only if

nn47

is a complete set of coset representatives of nn48; for nn49, this is equivalent to requiring nn50 to be a nonsquare (Wu et al., 2023). The same paper also treats multi-shift nn51-CEDFs and a lifting theorem from nn52 to nn53 when nn54 (Wu et al., 2023).

The second major paradigm uses graceful labellings. Paterson and Stinson constructed CEDFs from nn55-valuations of the lexicographic product graph nn56. If a graph has an nn57-valuation, then its blow-up by nn58 does as well, and the labels read modulo nn59 around the directed cycle produce an nn60-CEDF (Paterson et al., 2023). This viewpoint has since been generalized to digraph-defined EDFs, in which a small labelled digraph nn61 determines which difference multisets are aggregated; a nn62-CEDF is exactly the case where nn63 is the directed cycle nn64 (Huczynska et al., 29 Apr 2025).

The 2026 graph-labelling framework broadens nn65-valuations to near nn66-valuations and oriented near nn67-valuations. Combined with graph blow-up, this yields digraph-defined EDFs and, in particular, the infinite family of nn68-CEDFs with nn69 and nn70 (Angus et al., 5 Mar 2026).

5. Representative examples and extensions beyond cyclic abelian groups

A standard small example is the nn71–nn72-CEDF in nn73:

nn74

Its three consecutive difference multisets are

nn75

nn76

nn77

whose union is exactly nn78. Hence nn79, and indeed nn80 (Veitch et al., 2023). The example was originally built via the primitive root nn81 (Veitch et al., 2023).

Paterson and Stinson also exhibited small cyclic examples such as the nn82-CEDF in nn83

nn84

and the singleton example nn85 in nn86, given by the cyclic order

nn87

(Paterson et al., 2023).

A major development is that CEDFs are not confined to cyclic groups. Huczynska, Jefferson and McCartney constructed the first infinite family of nn88-CEDFs in a noncyclic abelian group,

nn89

for every odd nn90 (Huczynska et al., 29 Apr 2025). They also produced, by computational search, the first CEDF in a nonabelian group: a nn91-CEDF in the dihedral group

nn92

with blocks

nn93

(Huczynska et al., 29 Apr 2025).

These examples clarify a common misconception. The statement “if nn94 and nn95 are both odd, no CEDF exists” is only a cyclic non-existence theorem. The noncyclic abelian family in nn96 shows that the odd-odd nonexistence hurdle in the cyclic case can be overcome by moving to a slightly larger noncyclic group, and the dihedral example shows that nonabelian CEDFs do exist (Huczynska et al., 29 Apr 2025).

6. Strong variants, generalizations, and open problems

The strong analogue of a CEDF is a strong circular external difference family (SCEDF). If nn97 is an nn98-SCEDF, then for each nn99 one requires

m2m \ge 200

Thus each adjacent pair alone must realize all nonzero differences with multiplicity m2m \ge 201, and necessarily

m2m \ge 202

(Paterson et al., 2023).

Although SCEDFs are a natural strengthening, the existence theory is degenerate. Paterson and Stinson showed that a family is an m2m \ge 203-SCEDF if and only if each adjacent pair m2m \ge 204 is an m2m \ge 205-SEDF, and since no SEDF on more than two sets can exist in an abelian group, it follows that no SCEDF with m2m \ge 206 exists (Paterson et al., 2023). Wang and coauthors sharpened this into the statement that all SCEDFs are exactly the cyclic re-packagings of two-set strong EDFs; there are no non-trivial SCEDFs (Wu et al., 2023).

This non-existence does not eliminate the strong circular AMD viewpoint. Paterson and Stinson used cyclotomic numbers to construct circular strong AMD codes whose success probability is

m2m \ge 207

for cyclotomic classes m2m \ge 208 of order m2m \ge 209 in m2m \ge 210, where the m2m \ge 211-optimal bound would be m2m \ge 212 (Paterson et al., 2023). For m2m \ge 213, these codes do not reach the m2m \ge 214-optimal bound, but they provide near-optimal strong circular AMD codes (Paterson et al., 2023).

Several open problems remain active. In the cyclic setting, for general odd m2m \ge 215 and even m2m \ge 216, the existence problem is open outside the families m2m \ge 217 and m2m \ge 218 settled in 2025 (Burgess et al., 2 Sep 2025). The more general notion of a m2m \ge 219-CEDF is equivalent to the m2m \ge 220 case whenever m2m \ge 221, but systematic constructions for general m2m \ge 222 are not yet known (Burgess et al., 2 Sep 2025). In the graph-labelling framework, open directions include extending the approach to non-bipartite graphs, obtaining m2m \ge 223 families directly, and finding valuations for further graph families such as grids and higher m2m \ge 224-CEDFs (Angus et al., 5 Mar 2026).

Across these developments, one conclusion has remained stable: circular external difference families provide the exact combinatorial structures for optimal weak m2m \ge 225-circular AMD codes, and those AMD codes yield unconditionally secure, m2m \ge 226-non-malleable threshold schemes with respect to the additive relation m2m \ge 227 (Veitch et al., 2023).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to Circular External Difference Family (CEDF).