---
title: Circular External Difference Families (CEDF)
url: https://www.emergentmind.com/topics/circular-external-difference-family-cedf
type: topic
---

# Circular External Difference Families (CEDF)

A circular external difference family (CEDF) is a collection of pairwise disjoint equal-size subsets of a finite group whose prescribed cyclic external differences cover every nonzero group element with a fixed multiplicity. In the form introduced by Veitch and Stinson, CEDFs arose as the exact combinatorial structures underlying optimal weak circular algebraic manipulation detection (AMD) codes and hence unconditionally secure non-malleable threshold schemes [2305.09405]. Subsequent work by Paterson and Stinson, Huczynska, Jefferson and McCartney, and others developed existence and non-existence theory, graceful-labelling and cyclotomic constructions, digraph-defined generalizations, and extensions to noncyclic abelian and nonabelian groups [2310.02810][2504.20959].

## 1. Formal definition and parameter constraints

Let $G$ be a finite additive abelian group of order $n$. Fix integers $m \ge 2$, $1 \le c \le m-1$, and positive integers $\ell,\lambda$. Suppose
$$
A_0,A_1,\dots,A_{m-1}\subseteq G
$$
are pairwise disjoint and satisfy $|A_j|=\ell$ for all $j$. For two disjoint subsets $X,Y\subseteq G$, define the multiset of external differences
$$
D(X,Y)=\{\,x-y:x\in X,\ y\in Y\,\}.
$$
Then $(A_0,\dots,A_{m-1})$ is an $(n,m,\ell;\lambda)$–$c$-circular external difference family if
$$
\bigcup_{j=0}^{m-1} D(A_{j+c \bmod m},A_j)=\lambda\,(G\setminus\{0\})
$$
as multisets; equivalently, every nonzero $g\in G$ appears exactly $\lambda$ times among all differences $x-y$ with $x\in A_{j+c}$ and $y\in A_j$ [2305.09405].

A necessary size condition is
$$
m\ell^2=\lambda(n-1).
$$
In the common case $\lambda=1$, this forces $n=m\ell^2+1$ [2305.09405]. When $G=\mathbb Z_v$, the family is called *cyclic* [2509.02731]. The terminology “CEDF” is often used for the case $c=1$.

A broader formulation, developed in group-ring language, allows a set of shifts $S\subseteq\{1,2,\dots,m-1\}$. In multiplicative notation, an $(n,m,\ell;\lambda)$–$S$–CEDF satisfies
$$
\sum_{c\in S}\sum_{i=0}^{m-1}A_{i+c}A_i^{(-1)}=\lambda\,(G-1_G)
$$
in $\mathbb Z[G]$ [2310.10200]. This places ordinary CEDFs, $c$-CEDFs, and related external difference families in a common algebraic framework.

## 2. Equivalence with circular AMD codes and non-malleable threshold schemes

The central structural theorem identifies CEDFs with optimal circular AMD codes. In the weak circular AMD game, the adversary picks a nonzero $\Delta\in G$; a source index $i\in\{0,\dots,m-1\}$ is chosen uniformly; a codeword $g\in A_i$ is drawn uniformly; and the adversary wins if $g+\Delta\in A_{i+c \bmod m}$. Such a code is $R$-optimal if the maximum success probability is
$$
\epsilon=\ell/(n-1).
$$
Veitch and Stinson proved that $(A_0,\dots,A_{m-1})$ is an $R$-optimal weak $c$-circular $(n,m,\ell)$-AMD code if and only if it is an $(n,m,\ell;\lambda)$–$c$-CEDF with
$$
\lambda=\frac{m\ell^2}{n-1}.
$$
In particular, in the tight case $\lambda=1$, CEDFs are exactly the optimal weak circular AMD codes [2305.09405].

This equivalence feeds directly into secret sharing. On the secret space $S=\{0,\dots,m-1\}$, define
$$
s' \sim_c s \iff s'=s+c \pmod m.
$$
Feeding an $R$-optimal $c$-circular AMD code into Shamir’s scheme yields a $(k,n)$ threshold scheme that is $\epsilon$-non-malleable with respect to $\sim_c$ [2305.09405]. In the threshold construction, the dealer chooses a secret $s\in S$ uniformly, picks $K\in A_s$ uniformly, distributes shares of $K$ via Shamir over $\mathbb F_q$, and reconstructs by recovering $K$ from $k$ shares and outputting the unique $s$ such that $K\in A_s$ [2305.09405].

The cryptographic interpretation is that tampering attempts to move an encoding of source $i$ into an encoding of source $i+c \pmod m$. Any tampering on a single share shifts $K\mapsto K+\Delta$, and winning the $\sim_c$-malleability game requires $\Delta$ to land in $A_{s+c}$; by $R$-optimality this succeeds with probability at most $\ell/(q-1)$ [2305.09405]. Paterson and Stinson restated the same equivalence for the case $c=1$: an $R$-optimal circular weak $(n,m,\ell)$-AMD code is equivalent to an $(n,m,\ell;1)$-CEDF [2310.02810].

## 3. Existence and non-existence landscape

The known existence theory is most complete in the tight cyclic case $\lambda=1$, where $v=m\ell^2+1$. Several parameter regimes are settled, while others remain open.

| Parameter regime | Cyclic status | Source |
|---|---|---|
| even $m$, any $\ell\ge1$ | $(m\ell^2+1,m,\ell;1)$-CEDF exists | [2310.02810] |
| $m,\ell$ both odd | no cyclic $(m\ell^2+1,m,\ell;1)$-CEDF | [2310.02810] |
| odd $m>1$, $\ell=2$ | cyclic $(4m+1,m,2,1)$-CEDF exists | [2509.02731] |
| $m=3$, even $\ell\ge2$ | cyclic $(3\ell^2+1,3,\ell,1)$-CEDF exists | [2509.02731] |
| $m=4k$, shift $c=2$ | $(4k\ell^2+1,4k,\ell;1)$–2-CEDF exists in $\mathbb Z_{4k\ell^2+1}$ | [2603.05662] |

For cyclic groups, Paterson and Stinson proved that if $m$ is even and $\ell\ge1$ then an $(m\ell^2+1,m,\ell;1)$-CEDF exists, while if $m$ and $\ell$ are both odd then no such cyclic CEDF exists [2310.02810]. The odd-odd non-existence result is described in later work as a parity obstruction: the cyclic symmetry plus odd-odd parameters create a parity-sum contradiction [2509.02731].

The 2025 paper “On circular external difference families” sharpened the cyclic existence picture when $m$ is odd and $\ell$ is even. It constructed cyclic $(4m+1,m,2,1)$-CEDFs for every odd $m>1$, and cyclic $(3\ell^2+1,3,\ell,1)$-CEDFs for every even $\ell\ge2$ [2509.02731]. As stated there, this fills the last gaps for $\ell=2$ in the cyclic case and resolves the entire $m=3$ row for even $\ell$.

A separate line of work provides a uniform explicit cyclic family for all even $m$ in $\mathbb Z_{m\ell^2+1}$, avoiding the earlier case-splitting according to $m\equiv0$ or $2\pmod4$ [2504.20959]. More recently, graph-labelling methods produced the first explicit construction for an infinite family of $2$-CEDFs, achieving all parameter sets for $(n,m,\ell;1)$–$2$-CEDFs with $m\equiv0\pmod4$ sets [2603.05662].

Open cyclic cases remain. For general odd $m>3$ and even $\ell>2$, cyclic constructions beyond $\ell=2$ for all odd $m$ and beyond $m=3$ for all even $\ell$ remain open [2509.02731].

## 4. Construction paradigms

Two construction paradigms dominate the literature: cyclotomy in finite fields and graph-labelling methods.

Veitch and Stinson’s field-based construction begins with a finite field $\mathbb F_q$ such that $q=m\ell^2+1$, a primitive element $\alpha\in\mathbb F_q^\*$, and the subgroup
$$
H=\langle \alpha^{m\ell}\rangle
$$
of order $\ell$. For $j=0,\dots,m-1$, define
$$
C_j=\alpha^jH=\{\alpha^{j+i m\ell}:0\le i<\ell\}.
$$
Then $C_0,\dots,C_{m-1}$ are disjoint $\ell$-subsets of $\mathbb F_q$, and they form a $(q,m,\ell;\lambda)$–$1$-CEDF if and only if
$$
\{\alpha^{k m\ell+1}-1:0\le k<\ell\}
$$
is a full set of coset representatives of $H$ in $\mathbb F_q^\*$; in that case $\lambda=1$ [2305.09405]. The specialization $\ell=2$ gives a particularly concrete criterion: if $q=4m+1$ and $\alpha$ is primitive, then the cosets
$$
H=\{1,-1\},\qquad C_j=\{\alpha^j,-\alpha^j\}
$$
form a $(q,m,2;1)$–$1$-CEDF if and only if $\alpha^4-1$ is a quadratic non-residue [2305.09405].

This cyclotomic approach extends to arbitrary circular step $c$. In the notation of Wang and coauthors, if $q-1=m\ell^2$, $\beta=\theta^\ell$, $C=\langle \beta^m\rangle$, and $A_j=\beta^jC$, then $\{A_j\}$ is a $(q,m,\ell;1)$–$c$-CEDF if and only if
$$
\{\beta^{c+km}-1:0\le k<\ell\}
$$
is a complete set of coset representatives of $H=\langle \beta\rangle$; for $\ell=2$, this is equivalent to requiring $\theta^{4c}-1$ to be a nonsquare [2310.10200]. The same paper also treats multi-shift $S$-CEDFs and a lifting theorem from $\mathbb F_q$ to $\mathbb F_{q^t}$ when $\gcd(\ell,t)=1$ [2310.10200].

The second major paradigm uses graceful labellings. Paterson and Stinson constructed CEDFs from $a$-valuations of the lexicographic product graph $C_m\boldsymbol{\cdot}K_\ell^c$. If a graph has an $a$-valuation, then its blow-up by $K_\ell^c$ does as well, and the labels read modulo $m\ell^2+1$ around the directed cycle produce an $(m\ell^2+1,m,\ell;1)$-CEDF [2310.02810]. This viewpoint has since been generalized to digraph-defined EDFs, in which a small labelled digraph $H$ determines which difference multisets are aggregated; a $c$-CEDF is exactly the case where $H$ is the directed cycle $i\to i+c \pmod m$ [2504.20959].

The 2026 graph-labelling framework broadens $a$-valuations to near $\alpha$-valuations and oriented near $\alpha$-valuations. Combined with graph blow-up, this yields digraph-defined EDFs and, in particular, the infinite family of $2$-CEDFs with $m=4k$ and $n=4k\ell^2+1$ [2603.05662].

## 5. Representative examples and extensions beyond cyclic abelian groups

A standard small example is the $(13,3,2;1)$–$1$-CEDF in $\mathbb Z_{13}$:
$$
A_0=\{1,12\},\qquad A_1=\{4,9\},\qquad A_2=\{3,10\}.
$$
Its three consecutive difference multisets are
$$
D(A_1,A_0)=\{3,5,8,10\},
$$
$$
D(A_2,A_1)=\{1,7,6,12\},
$$
$$
D(A_0,A_2)=\{11,4,9,2\},
$$
whose union is exactly $\mathbb Z_{13}\setminus\{0\}$. Hence $\lambda=1$, and indeed $m\ell^2=3\cdot4=12=\lambda(13-1)$ [2305.09405]. The example was originally built via the primitive root $\alpha=2$ [2305.09405].

Paterson and Stinson also exhibited small cyclic examples such as the $(17,4,2;1)$-CEDF in $\mathbb Z_{17}$
$$
\{1,16\},\ \{9,8\},\ \{13,4\},\ \{15,2\},
$$
and the singleton example $(13,12,1;1)$ in $\mathbb Z_{13}$, given by the cyclic order
$$
0,12,1,11,2,10,3,8,4,7,5,6
$$
[2310.02810].

A major development is that CEDFs are not confined to cyclic groups. Huczynska, Jefferson and McCartney constructed the first infinite family of $(3\ell^2+1,3,\ell,1)$-CEDFs in a noncyclic abelian group,
$$
G=\mathbb Z_{3\ell^2+1}\times \mathbb Z_2,
$$
for every odd $\ell\equiv3\pmod4$ [2504.20959]. They also produced, by computational search, the first CEDF in a nonabelian group: a $(28,3,3,1)$-CEDF in the dihedral group
$$
D_{28}=\langle r,s\mid r^{14}=1,\ s^2=1,\ srs=r^{-1}\rangle
$$
with blocks
$$
A_0=\{1_D,r^{11},r^8\},\quad
A_1=\{r^4,sr^2,sr^6\},\quad
A_2=\{r^3,sr^5,sr^4\}
$$
[2504.20959].

These examples clarify a common misconception. The statement “if $m$ and $\ell$ are both odd, no CEDF exists” is only a cyclic non-existence theorem. The noncyclic abelian family in $\mathbb Z_{3\ell^2+1}\times\mathbb Z_2$ shows that the odd-odd nonexistence hurdle in the cyclic case can be overcome by moving to a slightly larger noncyclic group, and the dihedral example shows that nonabelian CEDFs do exist [2504.20959].

## 6. Strong variants, generalizations, and open problems

The strong analogue of a CEDF is a strong circular external difference family (SCEDF). If $A=\{A_0,\dots,A_{m-1}\}$ is an $(n,m,\ell;\lambda)$-SCEDF, then for each $j$ one requires
$$
D(A_{j+1 \pmod m},A_j)=\lambda(G\setminus\{0\}).
$$
Thus each adjacent pair alone must realize all nonzero differences with multiplicity $\lambda$, and necessarily
$$
\ell^2=\lambda(n-1)
$$
[2310.02810].

Although SCEDFs are a natural strengthening, the existence theory is degenerate. Paterson and Stinson showed that a family is an $(n,m,\ell;\lambda)$-SCEDF if and only if each adjacent pair $\{A_j,A_{j+1}\}$ is an $(n,2,\ell;\lambda)$-SEDF, and since no SEDF on more than two sets can exist in an abelian group, it follows that no SCEDF with $m\ge3$ exists [2310.02810]. Wang and coauthors sharpened this into the statement that all SCEDFs are exactly the cyclic re-packagings of two-set strong EDFs; there are no non-trivial SCEDFs [2310.10200].

This non-existence does not eliminate the strong circular AMD viewpoint. Paterson and Stinson used cyclotomic numbers to construct circular strong AMD codes whose success probability is
$$
\epsilon=\frac1f\max_{0\le i<e}(i,i+1\!\!\pmod e)_e
$$
for cyclotomic classes $C_i$ of order $e$ in $\mathbb F_q$, where the $R$-optimal bound would be $1/e$ [2310.02810]. For $m>2$, these codes do not reach the $R$-optimal bound, but they provide near-optimal strong circular AMD codes [2310.02810].

Several open problems remain active. In the cyclic setting, for general odd $m>3$ and even $\ell>2$, the existence problem is open outside the families $\ell=2$ and $m=3$ settled in 2025 [2509.02731]. The more general notion of a $c$-CEDF is equivalent to the $c=1$ case whenever $\gcd(c,m)=1$, but systematic constructions for general $c$ are not yet known [2509.02731]. In the graph-labelling framework, open directions include extending the approach to non-bipartite graphs, obtaining $\lambda>1$ families directly, and finding valuations for further graph families such as grids and higher $c$-CEDFs [2603.05662].

Across these developments, one conclusion has remained stable: circular external difference families provide the exact combinatorial structures for optimal weak $c$-circular AMD codes, and those AMD codes yield unconditionally secure, $\epsilon$-non-malleable threshold schemes with respect to the additive relation $s'=s+c\pmod m$ [2305.09405].

Source: https://www.emergentmind.com/topics/circular-external-difference-family-cedf