Lune

CRYPTO2023顶会

Coefficient Grouping for Complex Affine Layers

Fukang Liu, Lorenzo Grassi, Clémence Bouvier, Willi Meier, Takanori Isobe

2023年份
10被引次数

摘要

Designing symmetric-key primitives for applications in Fully Homomorphic Encryption (FHE) has become important to address the issue of the ciphertext expansion. In such a context, cryptographic primitives with a low-AND-depth decryption circuit are desired. Consequently, quadratic nonlinear functions are commonly used in these primitives, including the well-known χ function over F n 2 and the power map over a large finite field Fpn . In this work, we study the growth of the algebraic degree for an SPN cipher over F m 2 n , whose S-box is defined as the combination of a power map x → x 2 d +1 and an F2-linearized affine polynomial x → c0 + w i=1 cix 2 h i where c1, . . . , cw ̸ = 0. Specifically, motivated by the fact that the original coefficient grouping technique published at EUROCRYPT 2023 becomes less efficient for w > 1, we develop a variant technique that can efficiently work for arbitrary w. With this new technique to study the upper bound of the algebraic degree, we answer the following questions from a theoretic perspective:

  1. can the algebraic degree increase exponentially when w = 1? 2. what is the influence of w, d and (h1, . . . , hw) on the growth of the algebraic degree?

Based on this, we show (i) how to efficiently find (h1, . . . , hw) to achieve the exponential growth of the algebraic degree and (ii) how to efficiently compute the upper bound of the algebraic degree for arbitrary (h1, . . . , hw). Therefore, we expect that these results can further advance the understanding of the design and analysis of such primitives.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext fcda10a0-7dd2-4ed6-ac62-1004dcfdb809

它引用的顶会 Paper6

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖