### Efficient Construction of the Boomerang Connection Table

Orr Dunkelman

##### Abstract

Recently, the Boomerang Connection Table was introduced by Cid et al. as a tool to better evaluate the probability of a boomerang distinguisher. To compute the BCT of an $n$-bit to $n$-bit S-box, the inventors of the BCT proposed an algorithm that takes $O(2^{3n})$ time. We show that one can construct the same table in only $O(2^{2n})$ time.

Secret-key cryptography
Keywords
BCTCryptanalysis
