Paper 2021/175

On the Relationships between Different Methods for Degree Evaluation (Full Version)

Siwei Chen, Zejun Xiang, Xiangyong Zeng, and Shasha Zhang


In this paper, we compare several non-tight degree evaluation methods i.e., Boura and Canteaut's formula, Carlet's formula as well as Liu's numeric mapping and division property proposed by Todo, and hope to find the best one from these methods for practical applications. Specifically, for the substitution-permutation-network (SPN) ciphers, we first deeply explore the relationships between division property of an Sbox and its algebraic properties (e.g., the algebraic degree of its inverse). Based on these findings, we can prove theoretically that division property is never worse than Boura and Canteaut's and Carlet's formulas, and we also experimentally verified that the division property can indeed give a better bound than the latter two methods. In addition, for the nonlinear feedback shift registers (NFSR) based ciphers, according to the propagation of division property and the core idea of numeric mapping, we give a strict proof that the estimated degree using division property is never greater than that of numeric mapping. Moreover, our experimental results on Trivium and Kreyvium indicate the division property actually derives a much better bound than the numeric mapping. To the best of our knowledge, this is the first time to give a formal discussion on the relationships between division property and other degree evaluation methods, and we present the first theoretical proof and give the experimental verification to illustrate that division property is the optimal one among these methods in terms of the accuracy of the upper bounds on algebraic degree.

Available format(s)
Secret-key cryptography
Publication info
Published elsewhere. MINOR revision.IACR-ToSC 2021 (Issue 1)
Degree EvaluationDivision PropertyNumeric MappingNFSRSPN
Contact author(s)
chensiwei_hubu @ 163 com
xiangzejun @ hubu edu cn
xzeng @ hubu edu cn
amushasha @ 163 com
2021-02-20: received
Short URL
Creative Commons Attribution


      author = {Siwei Chen and Zejun Xiang and Xiangyong Zeng and Shasha Zhang},
      title = {On the Relationships between Different Methods for Degree Evaluation (Full Version)},
      howpublished = {Cryptology ePrint Archive, Paper 2021/175},
      year = {2021},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.