On CCZ-equivalence of the inverse function
Abstract
The inverse function on is one of the most studied functions in cryptography due to its widespread use as an S-box in block ciphers like AES. In this paper, we show that, if , every function that is CCZ-equivalent to the inverse function is already EA-equivalent to it. This confirms a conjecture by Budaghyan, Calderini and Villa. We also prove that every permutation that is CCZ-equivalent to the inverse function is already affine equivalent to it. The majority of the paper is devoted to proving that there are no permutation polynomials of the form over if , where are nonzero linear functions. In the proof, we combine Kloosterman sums, quadratic forms and tools from additive combinatorics.
Cite
@article{arxiv.2008.08398,
title = {On CCZ-equivalence of the inverse function},
author = {Lukas Kölsch},
journal= {arXiv preprint arXiv:2008.08398},
year = {2021}
}
Comments
Includes reviewers' comments, in particular an improved introduction, and corrected some typos. Accepted for publication in IEEE Transactions on Information Theory