A Method for Designing a 16-bit Cipher S-Box Based on ARX Structure
By designing a 16-bit cryptographic S-box using the ARX structure, and constructing an 8-bit S-box sample using modular addition, cyclic shift, and XOR operations combined with affine equivalence, the problem of insufficient security and efficiency of existing 16-bit S-boxes is solved, achieving high security and efficient support for nonlinear transformations.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUILIN UNIV OF ELECTRONIC TECH
- Filing Date
- 2023-10-31
- Publication Date
- 2026-07-31
AI Technical Summary
Existing 16-bit cryptographic S-box design methods are insufficient in terms of security and efficiency, making it difficult to effectively resist the threat of high-performance computing, especially quantum computing. Furthermore, existing design methods have difficulty in balancing multiple security indicators.
A 16-bit cryptographic S-box is designed using the ARX structure. By combining modular addition, cyclic shift and XOR operations, and combining 8-bit S-box samples constructed with affine equivalence, multiple rounds of iteration are performed and output to construct a 16-bit S-box with excellent properties.
It improves the security and software implementation efficiency of the 16-bit cryptographic S-box, provides high-security nonlinear transformation support, and meets the design requirements of block cipher algorithms.
Smart Images

Figure CN117478309B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the design of a nonlinear S-box, a confusion component in block cipher algorithms, specifically a 16-bit cryptographic S-box design method based on the ARX structure. Background Technology
[0002] Cryptography is the cornerstone of information security. Mainstream encryption algorithms fall into two categories: symmetric and asymmetric encryption. Among them, block cipher algorithms in symmetric encryption offer advantages such as consistent encryption and decryption and high efficiency, and have been widely used in practical information security systems.
[0003] With the widespread adoption of IoT applications, a series of new block cipher algorithms are constantly being proposed, and their design still needs to adhere to the confusion and diffusion principles proposed by Shannon. The S-box, as the only nonlinear component in most block cipher algorithms, provides the necessary confusion; therefore, the security strength of the S-box largely determines the overall security strength of the cryptographic algorithm. With the improvement of computing power, the 4 / 8-bit small-state cipher S-box can no longer meet the needs of practical applications and is vulnerable to the potential threats of high-performance computing, especially quantum computing. To effectively resist such attacks, 16 / 32 / 64-bit large-state cipher S-boxes are being designed. Among them, the 16-bit cipher S-box offers a 2% improvement in security strength compared to the 8-bit S-box. 8 The large-state S-box, with its superior cryptographic properties, offers significant advantages in existing applications. Therefore, researching large-state S-boxes with excellent cryptographic properties is a crucial and practically significant endeavor.
[0004] Currently, S-box design methods include random generation, mathematical construction, construction based on nonlinear feedback shift registers (NFSRs), and construction based on cryptographic algorithm structures. Each method has its advantages and disadvantages. Random construction can produce S-boxes with high security strength, but it is extremely time-consuming and costly. Mathematical construction yields a limited number of high-security S-boxes and struggles to balance multiple security metrics. NFSR construction typically involves numerous iterations, resulting in significant latency. Commonly used cryptographic algorithm structures include Feistel, SPN, Lai-Massey, and ARX structures, with ARX offering the advantage of fast software implementation. In existing application scenarios, constructing larger-scale 16-bit cryptographic S-boxes from 8-bit S-boxes based on cryptographic algorithm structures is an effective design approach. Using this approach of constructing a large box from a small box results in a lower equivalent gate count, which reduces hardware implementation costs. The 8-bit S-box occupies relatively little memory, and the use of lookup tables (LUTs) facilitates software implementation. Furthermore, constructing a larger-scale S-box from the cryptographically superior 8-bit S-box helps to obtain a high-quality 16-bit cryptographic S-box, which can effectively provide security guarantees for cryptographic algorithms.
[0005] Metrics for evaluating the security of an S-box include, but are not limited to, algebraic degree, difference uniformity, nonlinearity, transparency order, and strict avalanche criterion. However, these properties often have constraints on each other, and trade-offs need to be considered based on the security requirements of the cryptographic algorithm when designing a cryptographic S-box.
[0006] This invention proposes a novel method for constructing 16-bit cryptographic S-boxes based on an ARX structure. The ARX structure is a balanced two-branch structure that combines binary operations such as modular addition, cyclic shift, and XOR operations. It utilizes an 8-bit S-box dataset constructed using affine equivalence to perform multiple rounds of iteration and output, thereby constructing a series of well-structured 16-bit cryptographic S-boxes. This method offers advantages such as simple structure, flexible round function transformation, and user-friendly software implementation. It also addresses the previous weaknesses in cryptographic properties of 16-bit S-boxes, such as differential uniformity and nonlinearity, providing high-security nonlinear transformation support for the design of block cipher algorithms. Summary of the Invention
[0007] The purpose of this invention is to provide a 16-bit cryptographic S-box design method based on the ARX structure. It uses an 8-bit S-box constructed by affine equivalence as a dataset sample and adopts the ARX structure as the whole, which combines modular addition, cyclic shift and XOR operations, performs multiple rounds of iteration and outputs, so that the designed 16-bit S-box has excellent cryptographic properties and is cost-effective for software implementation. The high-security 16-bit cryptographic S-box can be applied to the design of block cipher algorithms to provide effective nonlinear transformation support.
[0008] The technical solution to achieve the objective of this invention is:
[0009] A method for designing a 16-bit cryptographic S-box based on the ARX structure includes the following steps:
[0010] (I): Construct an 8-bit S-box sample set;
[0011] Based on the 8-bit S-box of the AES algorithm with superior cryptographic properties, and utilizing the idea of affine equivalence, we construct the dataset sample for this method.
[0012] (II): Design of a 16-bit cryptographic S-box construction scheme based on ARX structure;
[0013] The operations modulo addition, cyclic shift, and XOR are combined, and two S-boxes, denoted as S1 and S2, are selected based on the 8-bit S-box sample set described in step (I). These are used alternately in different rounds, and the input variables of the left and right branches are processed. Perform a full traversal over the domain, execute multiple rounds of iterations and output the results to construct a 16-bit cryptographic S-box;
[0014] (III): Traverse and search the newly designed 16-bit cryptographic S-box construction scheme;
[0015] Based on the 16-bit cryptographic S-box design scheme described in step (II), two S-boxes are selected from the 8-bit S-box sample set described in step (I) using a full traversal approach. For each selected S-box, the input variables of the left and right branches are... Perform a full traversal on the domain to construct a series of 16-bit cryptographic S-boxes;
[0016] (iv): Test and filter the searched password boxes S;
[0017] For the 16-bit cryptographic S-boxes searched in step (iii), test their algebraic degree, differential uniformity, nonlinearity, transparency order, and strict avalanche criterion security indicators. Based on the test results, select 16-bit S-boxes with excellent cryptographic properties through compromise.
[0018] In the 16-bit cryptographic S-box design method based on the ARX structure of this invention, step (i) involves constructing an 8-bit S-box sample set, which is specifically performed as follows:
[0019] (1.1) Selecting 8-bit S-boxes from the AES algorithm as samples, and using the idea of affine equivalence, construct the dataset samples for this method. The affine equivalence formula is expressed as:
[0020]
[0021] If there exists a pair of invertible affine transformations A(x) and B(x), each affine transformation A(x) can be expressed as: A is an n-order invertible matrix defined on F2, and a is an n-bit constant, i.e. Then two n×n S-boxes S and S′ are said to be affine equivalent;
[0022] (1.2) As can be seen from the construction method of affine equivalence classes, the algebraic degree, difference uniformity, and nonlinearity of the S-box remain unchanged under affine transformation. These are affine equivalence invariants of the S-box. Therefore, the cryptographic properties of the constructed 8-bit S-box are as follows:
[0023] (1.2.1) The algebraic degree is 7, which can effectively resist algebraic attacks, interpolation attacks and cubic attacks;
[0024] (1.2.2) The differential uniformity is 4, which can effectively resist differential cryptanalysis;
[0025] (1.2.3) The nonlinearity is 112, which can effectively resist linear cryptanalysis.
[0026] In the 16-bit cryptographic S-box design method based on the ARX structure of this invention, step (ii) involves designing a 16-bit cryptographic S-box construction scheme based on the ARX structure. This scheme is based on two S-boxes selected from the 8-bit S-box sample set constructed in step (i). The entire structure adopts an ARX structure, and the input variables of the left and right branches are adjusted accordingly. The 16-bit cryptographic S-box is constructed by performing a full traversal over the domain, executing multiple iterations, and outputting the results. The specific steps of this construction scheme are as follows:
[0027] (2.1) Overall Structure
[0028] In the construction of a 16-bit cryptographic S-box in this invention, two 8-bit S-boxes, denoted as S1 and S2, are used. Both S-boxes are selected from the 8-bit S-box sample set constructed in step (i).
[0029] This approach combines binary operations such as modulo addition, circular shift, and XOR, employing the concept of constructing a larger box from a smaller one. It utilizes two selected 8-bit S-box samples, alternating their use in different rounds, and modulates the input variables of the left and right branches. A full traversal is performed over the domain, and multiple rounds of iteration are executed to construct a 16-bit cryptographic S-box, where modulo addition and the selected 8-bit S-box provide the necessary confusion, and cyclic shift and XOR operations are used for diffusion.
[0030] (2.2) Number of iteration rounds
[0031] The overall design of the cryptographic S-box is very important. At the same time, the number of iteration rounds is equally important. It is known that the implementation cost of the S-box is proportional to the size of its input and output. In terms of security, the more iteration rounds, the higher the security. In terms of implementation efficiency, the fewer iteration rounds, the lower the implementation cost. Here, the maximum number of iteration rounds is set to r_max rounds, where r_max≥3.
[0032] (2.3) Determine the input and output
[0033] The ARX structure designed in this invention has 8-bit inputs and outputs in both its left and right branches, forming a balanced structure. The initial input variables for the left and right branches are defined as L... 0 and R 0 ,in The current round number is defined as round r, where 1 ≤ r ≤ r_max. Then, the outputs of the intermediate variables of the left and right branches of the iteration round r are defined as L. r and R r The final output variables for the left and right branches are defined as L′ and R′, respectively. And let L′=L r_max ,R′=R r_max ;
[0034] (2.4) How to use an 8-bit S-box
[0035] This construction scheme alternates between two S-boxes, denoted as S1 and S2, in different rounds. During the iteration process, the S-box used in each round is related to the current round number r. S1 is used in odd-numbered rounds, and S2 is used in even-numbered rounds, where 1 ≤ r ≤ r_max. Let Sbox(r) be the S-box used in the r-th round. The specific usage rules are as follows:
[0036]
[0037] (2.5) Output function of the construction scheme
[0038] Based on the newly constructed ARX structure and the multi-round iterative calculation method, the output expression of the new structure is as follows:
[0039] The output of the intermediate variables of the left and right branches in the r-th iteration (1≤r≤r_max) is represented as follows:
[0040]
[0041] Finally, the output of the r_max iteration is assigned to the final left and right branch output variables, as follows:
[0042]
[0043] In the 16-bit cryptographic S-box design method based on the ARX structure of this invention, step (iii) involves a traversal search of the newly designed 16-bit cryptographic S-box construction scheme. The specific steps are as follows:
[0044] (3.1) Begin;
[0045] (3.2) Set up two 8-bit S-box sample sets and The 8-bit S-box constructed based on the AES algorithm's affine equivalence of S-boxes is placed into the set. and middle;
[0046] (3.3) Initialize the vector:
[0047] Set collection and The subscript vectors are m and n, respectively, and m = 0 and n = 0 are initialized.
[0048] Set the index vectors of the left and right branches as i and j respectively, and initialize i = 0, j = 0;
[0049] Set the maximum number of iteration rounds to r_max rounds, and initialize the current round number r = 1;
[0050] Initialize the 256×256 S-box mapping table S_table to be empty;
[0051] Set a 16-bit password S-box set Initially empty;
[0052] (3.4) In the set, follow the full traversal method The first S-box is selected and denoted as S1;
[0053] (3.5) In the set, follow the full traversal method The first S-box is selected and denoted as S2;
[0054] (3.6) Initialize the input variables L of the left and right branches 0 and R 0 ,in For L 0 and R 0 In respectively Iterate through the domain in lexicographical order and take the first number.
[0055] (3.7) Execute the r-th iteration. Based on the two selected S-boxes S1 and S2, and the input variables of the left and right branches, perform calculations according to formulas (2) and (3) to obtain the output L of the intermediate variables of the left and right branches in the r-th iteration. r and R r ;
[0056] (3.8) If r < r_max, then the output L of the r-th round will be... r and R r As the input for the new round, let r++, go to (3.7); otherwise, according to formula (4), the output L of the intermediate variables of the left and right branches of the iterative r_max round is used. r_max and R r_max Assign the values to the final left and right branch output variables L′ and R′, i.e., L′ = L r_max ,R′=R r_max , turn (3.9);
[0057] (3.9) Connect the final left and right branch output variables L′ and R′ and store them in the S-box mapping table S_table;
[0058] (3.10) If the input variable R of the right branch 0 exist If not all values have been traversed and retrieved on the domain, then let R... 0 In the domain, traverse the dictionary order and take the next number, i.e., j++, and let r = 1, go to (3.7); if all values have been taken, go to (3.11);
[0059] (3.11) If the input variable L of the left branch 0 exist If not all values have been traversed and retrieved on the domain, then let L... 0 In the domain, iterate through the lexicographical order to select the next number, while letting R... 0 In the domain, start traversing again in lexicographical order to get the first number, i.e., i++, j=0, and let r=1, go to (3.7); if all values have been traversed, go to (3.12);
[0060] (3.12) After the complete traversal of the inputs from both the left and right branches, a complete 256×256 mapping table S_table is obtained, which is a new 16-bit cipher box S. This is then added to the set. In the middle, the mapping table S_table is set to empty again, and the intermediate variables of the left and right branches are all set to empty;
[0061] (3.13) If full traversal If the iteration does not end, continue traversing and select the next S-box as the new S2, i.e., n++, and let i = 0, j = 0, r = 1, then go to (3.6); if Full traversal complete, go to (3.14);
[0062] (3.14) If full traversal If the process continues without ending, iterate through and select the next S-box as the new S1, and simultaneously begin iterating through and selecting the set again. The first S-box is taken as the new S2, i.e., m++, n=0, and let i=0, j=0, r=1, go to (3.6); if Once the full traversal is complete, the entire traversal search process ends, and we go to (3.15).
[0063] (3.15) The output contains the set of all newly found 16-bit cryptographic S-boxes.
[0064] (3.16) End search.
[0065] The 16-bit cryptographic S-box design method based on the ARX structure of the present invention has the following beneficial effects: (1) The ARX structure adopted by the method of the present invention has a relatively mature security theory. It combines binary operations modulo addition, cyclic shift and XOR operation, and combines the 8-bit S-box dataset samples constructed by affine equivalence to enhance the variability of the structure. It has the advantages of simple structure, flexible round function transformation and software-friendly implementation.
[0066] (2) The method of the present invention adopts the idea of constructing a large box from a small box. Based on the constructed 8-bit S-box sample set with better properties, a larger 16-bit S-box is constructed. This allows for better analysis of the properties of the 16-bit cryptographic S-box, thereby searching for a series of 16-bit S-boxes with excellent cryptographic properties.
[0067] (3) The method of this invention, by testing and screening 16-bit S-boxes with good cryptographic properties, can better meet the needs of application scenarios and provide highly secure nonlinear transformation support for the design of block cipher algorithms. Generally speaking, the larger the size of the S-box, the better its randomness, the greater the cryptographic strength of the S-box, and the higher the security strength of the algorithm. Attached Figure Description
[0068] Figure 1 This is a flowchart of the construction of a 16-bit cryptographic S-box according to the present invention.
[0069] Figure 2 This is a single-round structure diagram of the 16-bit cryptographic S-box based on the ARX structure designed in this invention.
[0070] Figure 3 This is a flowchart of the traversal search based on the newly designed 16-bit cryptographic S-box construction scheme of the present invention. Detailed Implementation
[0071] The present invention will be further described below with reference to the accompanying drawings. The following embodiments will help those skilled in the art to further understand the present invention, but do not limit the present invention in any way. It should be noted that those skilled in the art can make several modifications and improvements without departing from the concept of the present invention, and these all fall within the protection scope of the present invention.
[0072] Example:
[0073] A method for designing a 16-bit cryptographic S-box based on the ARX structure, referring to Figure 1 It includes the following steps:
[0074] (I): Construct an 8-bit S-box sample set;
[0075] Based on the 8-bit S-box of the AES algorithm with superior cryptographic properties, and utilizing the idea of affine equivalence, we construct the dataset sample for this method.
[0076] (II): Design of a 16-bit cryptographic S-box construction scheme based on ARX structure;
[0077] The operations modulo addition, cyclic shift, and XOR are combined, and two S-boxes, denoted as S1 and S2, are selected based on the 8-bit S-box sample set described in step (I). These are used alternately in different rounds, and the input variables of the left and right branches are processed. Perform a full traversal over the domain, execute multiple rounds of iterations and output the results to construct a 16-bit cryptographic S-box;
[0078] (III): Traverse and search the newly designed 16-bit cryptographic S-box construction scheme;
[0079] Based on the 16-bit cryptographic S-box design scheme described in step (II), two S-boxes are selected from the 8-bit S-box sample set described in step (I) using a full traversal approach. For each selected S-box, the input variables of the left and right branches are... Perform a full traversal on the domain to construct a series of 16-bit cryptographic S-boxes;
[0080] (iv): Test and filter the searched password boxes S;
[0081] The 16-bit cryptographic S-boxes searched in step (iii) are tested and screened according to security indicators such as algebraic degree, differential uniformity, nonlinearity, transparency order and strict avalanche criterion to obtain 16-bit S-boxes with excellent properties.
[0082] In the embodiment of the 16-bit cryptographic S-box design method based on the ARX structure, refer to Figure 1 The specific steps for constructing the 8-bit S-box sample set in step (1) are as follows:
[0083] (1.1) Selecting 8-bit S-boxes from the AES algorithm as samples, and using the idea of affine equivalence, construct the dataset samples for this method. The affine equivalence formula is expressed as:
[0084]
[0085] If there exists a pair of invertible affine transformations A(x) and B(x), each affine transformation A(x) can be expressed as: A is an n-order invertible matrix defined on F2, and a is an n-bit constant, i.e. Then two n×n S-boxes S and S′ are said to be affine equivalent;
[0086] When constructing affine equivalent samples, a pair of 8th-order invertible matrices A and B defined on F2, as well as two 8-bit constants a and b, are obtained using a random generation algorithm. The specific steps are as follows:
[0087] (1.1.1) Randomly generate an 8-bit constant p, and set it as the first row element of matrix A bit by bit from left to right, i.e. from the most significant bit to the least significant bit;
[0088] (1.1.2) The remaining rows of matrix A are obtained by cyclically shifting the first row. The shift amount is different for each row. The second row is obtained by cyclically shifting the first row one position to the right; the third row is obtained by cyclically shifting the first row two positions to the right; and so on. The kth row is obtained by cyclically shifting the first row k-1 positions to the right, where 2≤k≤8, thus generating an 8th order matrix.
[0089] (1.1.3) Determine whether the 8th order matrix is invertible. If it is not invertible, go to (1.1.1); otherwise, go to (1.1.4).
[0090] (1.1.4) Randomly generate an 8-bit constant q, and set it as the first row element of matrix B bit by bit from left to right, i.e. from the most significant bit to the least significant bit;
[0091] (1.1.5) The remaining rows of matrix B are obtained by cyclically shifting the first row. The shift amount of each row is different. The second row is obtained by cyclically shifting the first row one position to the right; the third row is obtained by cyclically shifting the first row two positions to the right; and so on. The kth row is obtained by cyclically shifting the first row k-1 positions to the right, where 2≤k≤8, thus generating an 8th order matrix.
[0092] (1.1.6) Determine whether the 8th order matrix is invertible. If it is not invertible, go to (1.1.4); otherwise, go to (1.1.7).
[0093] (1.1.7) Randomly generate two 8-bit constants a and b;
[0094] (1.1.8) Substitute into formula (1) to calculate the affine equivalence class of the 8-bit S-box of the AES algorithm, and add it to the 8-bit S-box sample set;
[0095] (1.2) As can be seen from the construction method of affine equivalence classes, the algebraic degree, difference uniformity, and nonlinearity of the S-box remain unchanged under affine transformation. These are affine equivalence invariants of the S-box. Therefore, the cryptographic properties of the constructed 8-bit S-box are as follows:
[0096] (1.2.1) The algebraic degree is 7, which can effectively resist algebraic attacks, interpolation attacks and cubic attacks;
[0097] (1.2.2) The differential uniformity is 4, which can effectively resist differential cryptanalysis;
[0098] (1.2.3) The nonlinearity is 112, which can effectively resist linear cryptanalysis.
[0099] In the embodiment of the 16-bit cryptographic S-box design method based on the ARX structure, refer to Figure 1 and Figure 2The design of the 16-bit cryptographic S-box construction scheme based on the ARX structure described in step (ii) is based on two S-boxes selected from the 8-bit S-box sample set described in step (i). The overall structure adopts the ARX structure, and the input variables of the left and right branches are processed... The 16-bit cryptographic S-box is constructed by performing a full traversal over the domain, executing multiple iterations, and outputting the results. The specific steps of this construction scheme are as follows:
[0100] (2.1) Overall Structure
[0101] In the construction of a 16-bit cryptographic S-box in this invention, two 8-bit S-boxes, denoted as S1 and S2, are used. Both S-boxes are selected from the 8-bit S-box sample set constructed in step (i).
[0102] This approach combines binary operations such as modulo addition, circular shift, and XOR, employing the concept of constructing a larger box from a smaller one. It utilizes two selected 8-bit S-box samples, alternating their use in different rounds, and modulates the input variables of the left and right branches. A full traversal is performed over the domain, and multiple rounds of iteration are executed to construct a 16-bit cryptographic S-box, where modulo addition and the selected 8-bit S-box provide the necessary confusion, and cyclic shift and XOR operations are used for diffusion.
[0103] (2.2) Number of iteration rounds
[0104] The design of the overall structure of the cryptographic S-box is very important. At the same time, the number of iteration rounds is equally important. It is known that the implementation cost of the S-box is proportional to the size of its input and output. In terms of security, the more iteration rounds, the higher the security. In terms of implementation efficiency, the fewer iteration rounds, the lower the implementation cost. In the embodiment, the maximum number of iteration rounds r_max of the new structure is set to 4.
[0105] (2.3) Determine the input and output
[0106] The ARX structure designed in this invention has 8-bit inputs and outputs in both its left and right branches, forming a balanced structure. The initial input variables for the left and right branches are defined as L... 0 and R 0 ,in The current round number is defined as round r, where 1 ≤ r ≤ r_max. Then, the outputs of the intermediate variables of the left and right branches of the iteration round r are defined as L. r and R r The final output variables for the left and right branches are defined as L′ and R′, respectively. And let L′=L r_max ,R′=R r_max ;
[0107] (2.4) How to use an 8-bit S-box
[0108] This construction scheme alternates between two S-boxes, denoted as S1 and S2, in different rounds. During the iteration process, the S-box used in each round is related to the current round number r. S1 is used in odd-numbered rounds, and S2 is used in even-numbered rounds, where 1 ≤ r ≤ r_max. Let Sbox(r) be the S-box used in the r-th round. The specific usage rules are as follows:
[0109]
[0110] (2.5) Output function of the construction scheme
[0111] Based on the newly constructed ARX structure and the multi-round iterative calculation method, the output expression of the new structure is as follows:
[0112] The output of the intermediate variables of the left and right branches in the r-th iteration (1≤r≤r_max) is represented as follows:
[0113]
[0114] Finally, the output of the r_max iteration is assigned to the final left and right branch output variables, as follows:
[0115]
[0116] In the embodiment of the 16-bit cryptographic S-box design method based on the ARX structure, refer to Figure 1 and Figure 3 Step (iii) involves a traversal search of the newly designed 16-bit cryptographic S-box construction scheme. The specific steps are as follows:
[0117] (3.1) Begin;
[0118] (3.2) Set up two 8-bit S-box sample sets and The 8-bit S-box constructed based on the AES algorithm's affine equivalence of S-boxes is placed into the set. and middle;
[0119] (3.3) Initialize the vector:
[0120] Set collection and The subscript vectors are m and n, respectively, and m = 0 and n = 0 are initialized.
[0121] Set the index vectors of the left and right branches as i and j respectively, and initialize i = 0, j = 0;
[0122] Set the maximum number of iteration rounds to r_max = 4 rounds, and initialize the current round number r = 1;
[0123] Initialize the 256×256 S-box mapping table S_table to be empty;
[0124] Set a 16-bit password S-box set Initially empty;
[0125] (3.4) In the set, follow the full traversal method The first S-box is selected and denoted as S1;
[0126] (3.5) In the set, follow the full traversal method The first S-box is selected and denoted as S2;
[0127] (3.6) Initialize the input variables L of the left and right branches 0 and R 0 ,in For L 0 and R 0 In respectively Iterate through the domain in lexicographical order and take the first number.
[0128] (3.7) Execute the r-th iteration. Based on the two selected S-boxes S1 and S2, and the input variables of the left and right branches, perform calculations according to formulas (2) and (3) to obtain the output L of the intermediate variables of the left and right branches in the r-th iteration. r and R r ;
[0129] (3.8) If r < 4, change the output L of the r-th round. r and R r As the input for the new round, let r++, go to (3.7); otherwise, according to formula (4), the output L of the intermediate variables of the left and right branches of the four iterations is used. 4 and R 4 Assign the values to the final left and right branch output variables L′ and R′, i.e., L′ = L 4 ,R′=R 4 , turn (3.9);
[0130] (3.9) Connect the final left and right branch output variables L′ and R′ and store them in the S-box mapping table S_table;
[0131] (3.10) If the input variable R of the right branch 0 exist If not all values have been traversed and retrieved on the domain, then let R... 0 In the domain, traverse the dictionary order and take the next number, i.e., j++, and let r = 1, go to (3.7); if all values have been taken, go to (3.11);
[0132] (3.11) If the input variable L of the left branch0 exist If not all values have been traversed and retrieved on the domain, then let L... 0 In the domain, iterate through the lexicographical order to select the next number, while letting R... 0 In the domain, start traversing again in lexicographical order to get the first number, i.e., i++, j=0, and let r=1, go to (3.7); if all values have been traversed, go to (3.12);
[0133] (3.12) After the complete traversal of the inputs from both the left and right branches, a complete 256×256 mapping table S_table is obtained, which is a new 16-bit cipher box S. This is then added to the set. In the middle, the mapping table S_table is set to empty again, and the intermediate variables of the left and right branches are all set to empty;
[0134] (3.13) If full traversal If the iteration does not end, continue traversing and select the next S-box as the new S2, that is, increment n and set i = 0, j = 0, r = 1, then go to (3.6); if Full traversal complete, go to (3.14);
[0135] (3.14) If full traversal If the process continues without ending, iterate through and select the next S-box as the new S1, and simultaneously begin iterating through and selecting the set again. The first S-box is taken as the new S2, that is, let m++, n=0, and let i=0, j=0, r=1, go to (3.6); if Once the full traversal is complete, the entire traversal search process ends, and we go to (3.15).
[0136] (3.15) The output contains the set of all newly found 16-bit cryptographic S-boxes.
[0137] (3.16) End search.
[0138] In the embodiment of the 16-bit cryptographic S-box design method based on the ARX structure, refer to Figure 1 The specific steps for testing and filtering the searched password S boxes in step (iv) are as follows:
[0139] For the 16-bit cryptographic S-boxes that were searched, their algebraic degree, differential uniformity, nonlinearity, transparency order, and strict avalanche criterion security indicators were tested. Based on the test results, 16-bit S-boxes with good cryptographic properties were selected by compromise.
[0140] In the example, one S-box was randomly selected from a large number of 16-bit cryptographic S-boxes for testing. The test results showed that the S-box satisfies the bijective property, the algebraic degree of each component reaches the optimal 15, the difference uniformity is 18, the nonlinearity is 31954, the transparency order is 15.9824, and it satisfies the strict avalanche property from the second round onwards.
[0141] The examples demonstrate that the 16-bit S-box constructed using the method of this invention has excellent cryptographic properties and can provide high-security S-box support for the design of block cipher algorithms.
[0142] It should be emphasized that the examples described in this invention are illustrative rather than limiting. Therefore, this invention is not limited to the examples described in the specific embodiments. Any other embodiments derived by those skilled in the art based on the technical solutions of this invention, without departing from the spirit and scope of this invention, whether modifications or substitutions, are also within the protection scope of this invention.
Claims
1. A method for designing a 16-bit cryptographic S-box based on an ARX structure, characterized in that, The method includes the following steps: (a): Construct an 8-bit S-box sample set; Based on the 8-bit S-box of the AES algorithm with superior cryptographic properties, and utilizing the idea of affine equivalence, we construct the dataset sample for this method. (II): Design a 16-bit cryptographic S-box construction scheme based on the ARX structure; The three operations of modulo addition, cyclic shift, and XOR are combined, and two S-boxes are selected based on the 8-bit S-box sample set described in step (i), denoted as... and Alternating between different rounds, by inputting variables into the left and right branches. Perform a full traversal over the domain, execute multiple rounds of iterations and output the results to construct a 16-bit cryptographic S-box; (iii): Traverse and search the newly designed 16-bit cryptographic S-box construction scheme; Based on the 16-bit cryptographic S-box construction scheme described in step (II), two S-boxes are selected from the 8-bit S-box sample set described in step (I) using a full traversal approach. For each selected S-box, the input variables of the left and right branches are processed... Perform a full traversal on the domain to construct a series of 16-bit cryptographic S-boxes; (iv): Test and filter the searched password boxes S; For the 16-bit cryptographic S-boxes searched in step (iii), test their algebraic degree, differential uniformity, nonlinearity, transparency order, and strict avalanche criterion security indicators. Based on the test results, select 16-bit S-boxes with excellent cryptographic properties through compromise.
2. The method of designing a 16-bit cryptographic S-box based on ARX structure according to claim 1, wherein, In step (i), the construction of the 8-bit S-box sample set is specifically carried out as follows: (1.1) Selecting 8-bit S-boxes from the AES algorithm as samples, and using the idea of affine equivalence, construct the dataset samples for this method. The affine equivalence formula is expressed as: (1) If there exists a pair of invertible affine transformations and Each affine transformation It can be represented as , It is defined in On an invertible matrix of order n. yes Bit constant, i.e. Then they are called two S box and Affine equivalence; (1.2) As can be seen from the construction method of affine equivalence classes, the algebraic degree, difference uniformity, and nonlinearity of the S-box remain unchanged under affine transformation. These are affine equivalence invariants of the S-box. Therefore, the cryptographic properties of the constructed 8-bit S-box are as follows: (1.2.1) The algebraic degree is 7, which can effectively resist algebraic attacks, interpolation attacks and cubic attacks; (1.2.2) The differential uniformity is 4, which can effectively resist differential cryptanalysis; (1.2.3) The nonlinearity is 112, which can effectively resist linear cryptanalysis.
3. The method of designing a 16-bit cryptographic S-box based on ARX structure according to claim 1, wherein, In step (ii), the design of the 16-bit cryptographic S-box construction scheme based on the ARX structure is based on two S-boxes selected from the sample set of the 8-bit S-box construction described in step (i). The overall structure adopts the ARX structure, and the input variables of the left and right branches are processed... The 16-bit cryptographic S-box is constructed by performing a full traversal over the domain, executing multiple iterations, and outputting the results. The specific steps of this construction scheme are as follows: (2.1) Overall structure The construction of a 16-bit cryptographic S-box uses two 8-bit S-boxes, denoted as . and Both of these S-boxes are selected from the 8-bit S-box sample set constructed in step (i); This approach combines binary operations such as modulo addition, circular shift, and XOR, employing the concept of constructing a larger box from a smaller one. It utilizes two selected 8-bit S-box samples, alternating their use in different rounds, and modulates the input variables of the left and right branches. A full traversal is performed over the domain, and multiple rounds of iteration are executed to construct a 16-bit cryptographic S-box, where modulo addition and the selected 8-bit S-box provide the necessary confusion, and cyclic shift and XOR operations are used for diffusion. (2.2) Number of iterations The overall structure design of the S-box is crucial, and the number of iteration rounds is equally important. It is known that the implementation cost of an S-box is directly proportional to the size of its input and output. In terms of security, more iteration rounds result in higher security; conversely, fewer iteration rounds result in lower implementation cost. Therefore, we set the maximum number of iteration rounds to [value missing]. Wheel, among which ; (2.3) Determine the input and output The designed ARX structure has 8-bit inputs and outputs in both its left and right branches, forming a balanced structure. The initial input variables for the left and right branches are defined as follows: and ,in The current round number is defined as Wheel, among which Then iteration The outputs of the intermediate variables in the left and right branches are defined as follows: and The final output variables for the left and right branches are defined as follows: and ,in And let ; (2.4) Usage of 8-bit S-box This construction scheme uses two S-boxes alternately in different rounds, denoted as... and During the iteration process, the S-box used in each round is related to the current round number. Related, used in odd-numbered rounds Use in even-numbered rounds ,in Let the first The S-box used by the wheel is The specific usage rules are as follows: (2); (2.5) Output function of the construction scheme Based on the newly constructed ARX structure and the multi-round iterative calculation method, the output expression of the new structure is as follows: Iteration The output of the intermediate variables in the left and right branches of the wheel is represented as follows: (3) Finally, the outputs of the iterations the final left and right branch output variables, denoted as: (4)。 4. The method of designing a 16-bit cryptographic S-box based on ARX structure according to claim 3, characterized in that, In step (iii), the traversal search of the newly designed 16-bit cryptographic S-box construction scheme is carried out, and the specific steps are as follows: (3.1) Begin; (3.2) Set two 8-bit S-box sample sets and Place 8-bit S-boxes constructed based on the affine equivalence of the AES algorithm S-box into the sets and ; (3.3) Initialize the vector: set of settings and the subscripted vectors and are initialized ; The subscript vectors of the left and right branches are respectively and , and the initializations ; Set the maximum iteration round number to Round, initialize the current round number ; Initialization S-box mapping table of is empty; Setting up a 16-bit cipher S-box set initially empty; (3.4) selecting the first S-box in the set in a full traversal manner and recording as ; (3.5) In the set, follow the full traversal method The first S-box is selected and denoted as ; (3.6) Initialize the input variables of the left and right branches and ,in ,for and In respectively Iterate through the domain in lexicographical order and take the first number. (3.7) Execute the first Round iteration, based on the two selected S-boxes and Based on the input variables of the left and right branches, the calculation is performed according to formulas (2) and (3) to obtain the iterative result. Output of intermediate variables in the left and right branches and ; (3.8) If , will the Wheel output and As a new round of input, and let , go to (3.7); otherwise, according to formula (4), the iteration will be performed. Output of intermediate variables in the left and right branches and Assign values to the final left and right branch output variables. and ,Right now , turn (3.9); (3.9) Output variables of the final left and right branches and Perform the connection and store it in the S-box mapping table. middle; (3.10) If the input variable of the right branch exist If not all values have been traversed and retrieved on the field, then let In the field, traverse lexicographically and take the next number, that is... And let Go to (3.7); if all values have been traversed, go to (3.11). (3.11) If the input variable of the left branch exist If not all values have been traversed and retrieved on the field, then let In the field, traverse lexicographically to select the next number, and simultaneously let... In the field, start traversing again in lexicographical order and take the first number, that is... And let Go to (3.7); if all values have been traversed, go to (3.12). (3.12) After the left and right branches have been fully traversed, the complete result is obtained. mapping table That is, a new 16-bit cryptographic S-box is obtained and added to the set. In, and again map the table Set the variables to empty, and simultaneously set all intermediate variables in both the left and right branches to empty; (3.13) If the entire traversal is performed If the process has not ended, continue iterating and selecting the next S-box as the new S-box. ,Right now And let , go to (3.6); if Full traversal complete, go to (3.14); (3.14) If the entire traversal is performed If the process has not ended, continue iterating and selecting the next S-box as the new S-box. At the same time, start traversing the selection set again. The first S box as a new ,Right now And let , go to (3.6); if Once the full traversal is complete, the entire traversal and search process ends, and we go to (3.15). (3.15) output the set containing all newly found 16-bit S-boxes ; (3.16) End the search.