English

On CCZ-equivalence of the inverse function

Information Theory 2021-03-09 v2 Combinatorics math.IT Number Theory

Abstract

The inverse function xx1x \mapsto x^{-1} on F2n\mathbb{F}_{2^n} is one of the most studied functions in cryptography due to its widespread use as an S-box in block ciphers like AES. In this paper, we show that, if n5n\geq 5, every function that is CCZ-equivalent to the inverse function is already EA-equivalent to it. This confirms a conjecture by Budaghyan, Calderini and Villa. We also prove that every permutation that is CCZ-equivalent to the inverse function is already affine equivalent to it. The majority of the paper is devoted to proving that there are no permutation polynomials of the form L1(x1)+L2(x)L_1(x^{-1})+L_2(x) over F2n\mathbb{F}_{2^n} if n5n\geq 5, where L1,L2L_1,L_2 are nonzero linear functions. In the proof, we combine Kloosterman sums, quadratic forms and tools from additive combinatorics.

Cite

@article{arxiv.2008.08398,
  title  = {On CCZ-equivalence of the inverse function},
  author = {Lukas Kölsch},
  journal= {arXiv preprint arXiv:2008.08398},
  year   = {2021}
}

Comments

Includes reviewers' comments, in particular an improved introduction, and corrected some typos. Accepted for publication in IEEE Transactions on Information Theory

R2 v1 2026-06-23T17:57:40.556Z