Cryptology ePrint Archive: Report 2021/175

On the Relationships between Different Methods for Degree Evaluation (Full Version)

Siwei Chen and Zejun Xiang and Xiangyong Zeng and Shasha Zhang

Abstract: In this paper, we compare several non-tight degree evaluation methods i.e., Boura and Canteaut's formula, Carlet's formula as well as Liu's numeric mapping and division property proposed by Todo, and hope to find the best one from these methods for practical applications. Specifically, for the substitution-permutation-network (SPN) ciphers, we first deeply explore the relationships between division property of an Sbox and its algebraic properties (e.g., the algebraic degree of its inverse). Based on these findings, we can prove theoretically that division property is never worse than Boura and Canteaut's and Carlet's formulas, and we also experimentally verified that the division property can indeed give a better bound than the latter two methods. In addition, for the nonlinear feedback shift registers (NFSR) based ciphers, according to the propagation of division property and the core idea of numeric mapping, we give a strict proof that the estimated degree using division property is never greater than that of numeric mapping. Moreover, our experimental results on Trivium and Kreyvium indicate the division property actually derives a much better bound than the numeric mapping. To the best of our knowledge, this is the first time to give a formal discussion on the relationships between division property and other degree evaluation methods, and we present the first theoretical proof and give the experimental verification to illustrate that division property is the optimal one among these methods in terms of the accuracy of the upper bounds on algebraic degree.

Category / Keywords: secret-key cryptography / Degree Evaluation, Division Property, Numeric Mapping, NFSR, SPN

Original Publication (with minor differences): IACR-ToSC 2021 (Issue 1)

Date: received 18 Feb 2021, last revised 18 Feb 2021

Contact author: chensiwei_hubu at 163 com, xiangzejun at hubu edu cn, xzeng at hubu edu cn, amushasha at 163 com

Available format(s): PDF | BibTeX Citation

Version: 20210220:173353 (All versions of this report)

Short URL: ia.cr/2021/175


[ Cryptology ePrint archive ]