Skip to Content
CryptographyCryptography
  • Article
  • Open Access

29 September 2026

29 Pages

Full-Cycle 8 × 8 S-Box from Bijective Trims of a 9D APN Permutation with Coordinate-Optimized DSAC and BIC

,
,
,
and
1
Department of Information Security, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan
2
Department of Electrical Engineering, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan
3
Department of Computer Software Engineering, National University of Sciences and Technology (NUST), Islamabad 44000, Pakistan
4
School of Electronics, Electrical Engineering and Computer Science, Queen’s University Belfast, Belfast BT9 5BN, UK

Abstract

This paper presents an 8 × 8 S-box construction based on bijective trims of the compositional inverse of a nine-dimensional quadratic APN permutation. An exhaustive evaluation of 1,566,726 parameter combinations yields 3066 bijective trims, all with differential uniformity 4, vectorial nonlinearity 112, maximum linear bias 2 − 4 and Boolean algebraic degree 5. The selected representative S-box exhibits desirable cryptographic and structural properties, including algebraic immunity 4, full-cycle permutation behavior, absence of fixed and opposite fixed points, and practical implementation feasibility. A randomized linear-conjugation search enables the selection of a coordinate-optimized representation with lower DSAC and BIC than the canonical AES byte mapping under the adopted measures. In the matched one-million-matrix control, however, 22,911 AES conjugates (2.2911%) and only one conjugate (0.0001%) of the fixed retained trim satisfied both selected thresholds, so the experiment does not establish an advantage over AES under the same coordinate-optimization search. The selected S-box achieves a single cycle of length 256, mean SAC of 128.125, DSAC of 392, BIC of 0.129412, and maximum differential probability 2 − 6 . Compared with the AES S-box, the selected S * matches its differential uniformity, vectorial nonlinearity, and maximum linear bias, while its Boolean algebraic degree is 5, compared with 7 for AES, and its boomerang uniformity is 18 compared with 6 for AES. For direct construction-based software evaluation, the proposed S * required approximately 2.06 times the execution time of the AES direct-arithmetic implementation on the tested platform, reflecting an implementation-specific trade-off for on-the-fly computation.

1. Introduction

Modern symmetric encryption algorithms employ nonlinear transformations to induce confusion, followed by linear transformations to diffuse statistical properties in the ciphertext. The application of confusion and diffusion is intended to obscure the relationships among the plaintext, ciphertext, and the key. Confusion is one of the vital elements and is generally implemented by an S-box, which is an n × m nonlinear mapping from an n-bit input vector to an m-bit output vector. Mathematically, an S-box is described by the multivariate Boolean function S box : F 2 n → F 2 m defined over the binary field F 2 and implemented as a Lookup Table (LUT). Designing a secure S-box satisfying multiple cryptographic criteria is a challenging problem [1]. S-boxes are commonly generated by three approaches: random selection, metaheuristic construction and algebraic construction. Out of these, algebraic construction is based on a mathematical foundation and offers strong cryptographic strength [2]. In random selection, the mapping from input to output is performed randomly; however, such mappings may have structural flaws and are therefore generally not preferred.
Metaheuristic algorithms are combined with different nonlinear transformations to generate S-boxes for symmetric encryption algorithms. Alhadawi et al. [2] designed S-boxes based on a discrete chaotic map and a cuckoo search algorithm, but the resulting S-boxes exhibited low nonlinearity. Ben Farah et al. [3] proposed a combination of different chaotic maps with optimization algorithms to generate S-boxes, which also resulted in low nonlinearity. Msolli et al. [4] and Artuğer et al. [5] used genetic algorithms to generate S-boxes; however, the reported maximum differential probability is comparatively high, indicating less favorable local differential behavior at the S-box level. Kuznetsov et al. [6] also incorporated a genetic algorithm and exhibited low nonlinearity.
The most common approach to designing secure S-boxes is algebraic construction, and numerous construction methodologies are reported in the literature. A novel algebraic structure using Boolean functions that incorporated a logistic chaotic map was introduced in [7]. Luo et al. [8] integrated an algebraic model with a chaotic map, but not all of the resulting S-boxes achieve ideal nonlinearity. In [9], key-based permutations are applied to nonlinear transformations to create S-boxes; however, the resulting S-box contains high-probability differentials. Özkaynak et al. [10] studied S-box design based on a time-delay chaotic system; however, the resulting S-boxes suffer from both low nonlinearity and high-probability differentials. Malik et al. [11] designed affine transformation-based S-boxes similar to the AES design, in which the affine matrix is generated using a random byte value while retaining an AES-like affine construction. Similarly, Alamsyah et al. [12] also explored affine matrices to generate S-boxes with an algebraic structure similar to that of the AES S-box. Another method to generate S-boxes involves key dependence, and Al-Dweik et al. [13] generated key-dependent S-boxes; however, the analysis cannot be extended to the entire space of possible S-boxes. Ibrahim et al. [14] designed dynamic S-boxes with elliptic curves having low nonlinearity, high differential probability and high linear bias, which are undesirable for cryptographic S-box design. Similar concerns are identified in S-boxes designed by [15].
Fractional and rational transformations have previously been explored for S-box construction. Farwa et al. [16] employed a fractional linear transformation over F 2 8 ; however, the resulting S-box exhibits comparatively weaker diffusion-related indicators and contains opposite fixed points. Chew and Ismail [17] combined a linear fractional transformation with an additional permutation function, but the resulting S-box exhibits comparatively weaker diffusion-related behavior and a fragmented cycle structure. Nitaj et al. [18] proposed to generate secure S-boxes using rational functions; however, 334 of the 540 evaluated S-boxes contain at least one opposite fixed point.
The National Institute of Standards and Technology (NIST) organized the AES competition from 1997 to 2000 to select a new cryptographic algorithm as a replacement for the Data Encryption Standard (DES). AES is published as Federal Information Processing Standard (FIPS) Publication 197 and is globally used for data encryption, network and cloud security, secure communications, and cryptocurrency. It is an international standard and provides adequate security with efficiency. Among the five finalists of the AES competition were the Rijndael, Serpent and Twofish block ciphers, each employing a distinct S-box generation mechanism. Twofish employs key-dependent dynamic S-boxes that are generated mathematically at runtime from the key [19], resulting in an exponential number of dynamic S-boxes; however, not all possible S-boxes are thoroughly analyzed due to computational constraints. Serpent [20] incorporates thirty-two unique S-boxes that are derived from DES [21]. It is noteworthy that DES was designed by International Business Machines (IBM) with significant involvement from the National Security Agency (NSA). The design of the DES S-boxes was not fully public at the time, which later motivated an emphasis on publicly analyzable S-box constructions. Moreover, DES was withdrawn from FIPS because of its short key length. Rijndael [22] was selected as the Advanced Encryption Standard and offers adequate security and high implementation efficiency [23]. AES incorporates only one S-box based on a finite field construction that uses the multiplicative inverse in F 2 8 , followed by an affine transformation over F 2 8 . The AES S-box has a well-studied mathematical structure with strong S-box-level differential and linear characteristics and serves as a benchmark for finite field designs. Nonetheless, with state-of-the-art techniques and tools, several structural indicators of the AES S-box have been discussed in the literature, including short iterative period [24,25] and a sparse univariate polynomial representation with 9 nonzero terms [26], which motivates a comparison of alternative algebraic representations. In addition to this, the canonical AES byte mapping has a distance to the Strict Avalanche Criterion (DSAC) of 432 (a lower value is desirable), which motivates a comparison of alternative binary coordinate representations [18]. Although these indicators do not constitute practical breaks of AES, DSAC and Pearson-correlation BIC are coordinate-dependent descriptive measures, and lower values relative to the canonical representation do not establish an advantage over AES under coordinate optimization or improved resistance to differential, linear, boomerang, or other cryptanalytic attacks. They nevertheless motivate further investigation of finite field transformations that retain strong cryptographic characteristics while enabling an improvement of selected structural and diffusion-related indicators; such improvements are interpreted here as descriptive rather than as direct evidence of cryptanalytic superiority.
  • Our Contribution: This work builds on the nine-dimensional quadratic APN permutation C α of Beierle et al. [27] and the trimming framework of Beierle et al. [28] to systematically construct and characterize 8 × 8 permutations under explicitly specified finite field, embedding, projection, and bit-order conventions. Building on this established foundation, the present study contributes a systematic specialization of the framework to the adopted coordinate realization, an exhaustive characterization of the resulting trim space, an equivalence analysis of the retained mappings, and a subsequent coordinate-representation and structural selection procedure that leads to the final full-cycle representative.
The contribution comprises three main aspects. First, the adopted trim construction is specialized to the present coordinate realization, with corresponding analysis of the bijectivity criterion, inverse relation, and preservation properties of the resulting 8 × 8 mappings. Second, the complete structural parameter space of 1,566,726 triples ( α , β , b ) is evaluated exhaustively, yielding 3066 bijective trims. All retained trims exhibit differential uniformity 4, vectorial nonlinearity 112, maximum linear bias 2 − 4 and Boolean algebraic degree 5. All 3066 retained instances correspond to distinct lookup tables. Exact CCZ-equivalence classification further shows that these mappings comprise 10 distinct CCZ-equivalence classes. The retained mappings are also CCZ-inequivalent to the 552 comparison mappings considered in this study and consequently are EA- and affine-inequivalent to those comparison mappings.
Third, a linear-conjugation search is used to explore alternative binary coordinate representations with respect to the adopted coordinate-dependent diffusion indicators, followed by exhaustive output-translation analysis for fixed points, opposite fixed points, and permutation-cycle structure. For the selected core–matrix pair, an evaluation of all 256 output translations identifies the final full-cycle representative S * with algebraic immunity 4 and no fixed or opposite fixed points. The implementation analysis further examines the software and hardware cost of the selected representation.
  • Paper Organization: The rest of the paper is organized as follows. Section 2 presents the preliminaries. Section 3 explains the proposed methodology to generate 8 × 8 S-boxes from bijective trims of a nine-dimensional APN permutation, along with the inverse S-box generation procedure. Section 4 highlights the theoretical analysis of the proposed S-box construction, and Section 5 presents the cryptographic tests and implementation feasibility of the selected proposed S-box, along with a detailed comparison with the AES S-box and other relevant S-box constructions. Section 6 presents the conclusion.

2. Preliminaries

This section defines an S-box and presents the AES S-box.

2.1. Substitution Box

Definition 1
(S-box [29]). It is an n × m nonlinear transformation defined over the binary field F 2 and represented by a multivariate Boolean function:
S box : F 2 n → F 2 m ,
which maps an n-bit input vector to an m-bit output vector.
An n × m S-box can also be represented as a lookup table (LUT) with 2 n entries, each containing an m-bit output.

2.2. Overview of the AES S-Box

Differential [30] and linear cryptanalysis [31] exploit differential and linear propagation across a cipher. At the S-box level, low differential probabilities, low linear biases, and high nonlinearity are desirable because they limit strong local differential and linear approximations [11,32]. The AES S-box was designed with favorable values of these S-box-level characteristics. AES incorporates an 8 × 8 S-box based on Nyberg’s construction [33] and is defined as follows:
Definition 2
(AES S-box [22]). Let F 2 8 denote the finite field defined by the irreducible polynomial P ( x ) = x 8 + x 4 + x 3 + x + 1 . The AES S-box is a nonlinear and bijective mapping S AES : F 2 8 → F 2 8 comprising the multiplicative inverse in F 2 8 followed by an affine transformation over F 2 8 . Formally, for an input byte x ∈ F 2 8 , the S-box output is given by:
S AES ( x ) = M · x − 1 ⊕ b ,
where
x , x − 1 ∈ F 2 8 such that x · x − 1 ≡ 1 mod P ( x ) for x ≠ 0 x 00 , while the multiplicative-inverse stage uses the conventional assignment 0 x 00 − 1 = 0 x 00 . This convention applies only to the inversion stage: after the AES affine transformation with b = 0 x 63 , the complete AES S-box maps 0 x 00 to 0 x 63 , so 0 x 00 is not a fixed point of the AES S-box. The complete AES S-box contains no fixed points. M is an 8 × 8 binary matrix, and b is an 8-bit constant vector. AES specifies b = 0x63 with the following binary matrix:
M = 1 1 1 1 1 0 0 0 0 1 1 1 1 1 0 0 0 0 1 1 1 1 1 0 0 0 0 1 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 0 0 1 1 1 1 1 1 0 0 0 1 .

3. Proposed Methodology

3.1. Nine-Dimensional APN Parent Permutation

The proposed construction employs the nine-dimensional quadratic APN permutation reported by Beierle et al. [27], represented in trivariate form as Equation (1). Related constructions of APN functions from known ones have also been studied in the literature [34].
C α ( x , y , z ) = x 3 + α y 2 z , y 3 + α x z 2 , z 3 + α x 2 y ,
where x , y , z ∈ F 2 3 and α ∈ F 2 3 ∖ { 0 , 1 } . In this work, F 2 3 is represented as F 2 [ t ] / ( t 3 + t + 1 ) using the polynomial basis { 1 , t , t 2 } . Since F 2 3 is a three-dimensional vector space over F 2 , ( F 2 3 ) 3 ≅ F 2 9 and hence C α defines a 9-bit permutation.
The three field coordinates are packed in least-significant-bit-first order, with bits 0–2, 3–5, and 6–8 representing x, y, and z, respectively.

3.2. Eight-Dimensional Trim Construction

The proposed 8 × 8 mapping is obtained from C α − 1 using the trimming framework of Beierle et al. [28], in which a vectorial Boolean function is restricted to an ( n − 1 ) -dimensional hyperplane and its output is projected onto an ( n − 1 ) -dimensional space. For a nonzero vector β ∈ F 2 9 , the eight-dimensional linear hyperplane is defined as
H β = v ∈ F 2 9 : ⟨ β , v ⟩ = 0 .
For reproducibility, a fixed coordinate convention is used for the embedding and projection. Nine-bit vectors are indexed from the least significant bit, with coordinates 0 , … , 8 . For a given nonzero β , let p β denote the lowest index for which the corresponding bit of β is one. An ordered basis of H β is constructed, for j ≠ p β , as
h j = e j , β j = 0 , e j ⊕ e p β , β j = 1 ,
where e j denotes the j-th standard basis vector of F 2 9 . The vectors h j are ordered by increasing j, and ι β maps the eight input bits onto this ordered basis.
Similarly, for a nonzero projection direction b, let p b denote the lowest index for which b p b = 1 . For y ∈ F 2 9 , the projection first forms
y ′ = y ⊕ y p b b ,
so that the p b -th coordinate of y ′ is zero, and then removes that coordinate to obtain the corresponding 8-bit output. This defines the fixed projection π b with kernel ⟨ b ⟩ = { 0 , b } .
Let ι β : F 2 8 → H β denote a linear embedding and let π b : F 2 9 → F 2 8 denote a linear projection with kernel ⟨ b ⟩ , where b ∈ F 2 9 ∖ { 0 } . The resulting 8-bit trim of the inverse parent permutation is defined as
T α , β , b ( u ) = π b C α − 1 ι β ( u ) , u ∈ F 2 8 .
Only parameter combinations ( α , β , b ) for which T α , β , b is bijective are retained as candidate 8 × 8 S-box mappings.

3.3. Bijectivity Criterion for Candidate Trims

Let
Y α , β = C α − 1 ( H β )
denote the set of 256 points obtained after applying the inverse parent permutation to the selected hyperplane. Since the projection π b has kernel
⟨ b ⟩ = { 0 , b } ,
two distinct points y 1 , y 2 ∈ Y α , β produce the same projected output only if
y 1 ⊕ y 2 = b .
Indeed, every fiber of π b is a coset of its kernel and therefore has the form
{ y , y ⊕ b } .
Hence, each fiber contains exactly two points, and three distinct points cannot be mapped to the same projected output.
Therefore, the trim T α , β , b is bijective if and only if
Y α , β ∩ Y α , β ⊕ b = ⌀ .
This condition ensures that no two points in the restricted 256-point set are merged by the projection. Since both the domain and codomain of T α , β , b contain 256 elements, satisfaction of this condition ensures that the resulting mapping is an 8 × 8 permutation. Only parameter combinations satisfying this criterion are retained for subsequent cryptographic evaluation.

3.4. Exhaustive Parameter-Space Evaluation

The complete parameter space of the proposed trim construction is exhaustively evaluated. The parent family C α is considered for all α ∈ F 2 3 ∖ { 0 , 1 } , resulting in six possible values of α [27]. For each parent permutation, all nonzero vectors β ∈ F 2 9 are considered, resulting in 511 possible eight-dimensional hyperplanes. Similarly, all nonzero projection directions b ∈ F 2 9 are examined, giving 511 possible values of b. The resulting structural search space therefore contains
6 × 511 × 511 = 1,566,726
parameter combinations ( α , β , b ) .
For each combination, the bijectivity criterion defined in Section 3.3 is first evaluated. Non-bijective trims are discarded, while every retained 8 × 8 permutation is evaluated for differential uniformity, vectorial nonlinearity, linear approximation characteristics, algebraic degree, boomerang uniformity, SAC, DSAC and BIC. The complete set of bijective trim instances is retained as candidate 8 × 8 mappings for subsequent analysis and linear-conjugation search.

3.5. Linear-Conjugation Search and Matrix Selection

The differential uniformity, vectorial nonlinearity, linear spectrum, algebraic degree, and boomerang uniformity of a bijective trim are preserved under invertible linear conjugation. In contrast, coordinate-dependent diffusion indicators such as SAC, DSAC, and BIC may vary with the binary coordinate representation. Therefore, for each retained bijective trim, linear conjugates of the form
S L ( u ) = L T α , β , b L − 1 u , L ∈ GL ( 8 , 2 ) ,
are considered.
Since exhaustive enumeration of GL ( 8 , 2 ) is computationally infeasible, 1,000,000 distinct random nonsingular 8 × 8 binary matrices are generated once using the fixed random seed 20260813. The same matrix sequence is applied to each of the 3066 retained bijective trims, giving 3,066,000,000 randomized core–L pairs. For every core–L pair, DSAC is evaluated first. Pearson-correlation BIC is then evaluated only for pairs satisfying DSAC < DSAC AES ; this exact screening cannot discard any pair satisfying both search criteria. The implementation also carries one previously fixed baseline matrix in addition to the 1,000,000 random matrices for reproducibility and comparison. Across all 3066 retained trims, this baseline contributes an additional 3066 core–L pairs, giving 3,066,003,066 core–L pairs in the complete implementation run, of which 3,066,000,000 belong to the randomized search. The search identifies mappings simultaneously satisfying
DSAC < DSAC AES
and
BIC < BIC AES .
Here, DSAC AES = 432 and BIC AES = 0.134125 denote the values of the canonical AES byte mapping and are used as the search thresholds.
A single nonsingular matrix is subsequently selected and kept fixed in the final construction. Its hexadecimal row representation is
L = [ D 3 , C 9 , 41 , 3 C , 1 B , 5 E , 20 , 37 ] ,
with inverse
L − 1 = [ 13 , 7 F , 34 , E 4 , 98 , 40 , 17 , E 2 ] .
The hexadecimal rows of L and L − 1 are interpreted using the same LSB-first bit convention as the 8-bit S-box inputs and outputs. Specifically, for an input byte
u = ( u 0 , u 1 , … , u 7 ) T ,
where u 0 is the least significant bit, let r i denote the i-th hexadecimal row byte of the matrix and let r i , j denote bit j of r i , with r i , 0 its least significant bit. The matrix action is
( L u ) i = ⨁ j = 0 7 r i , j u j , i = 0 , … , 7 ,
and output bit i is placed in bit position i of the resulting byte. The identical convention is used for L − 1 . For example, the first row D 3 of L has nonzero bits in positions 0 , 1 , 4 , 6 , 7 , and therefore
( L u ) 0 = u 0 ⊕ u 1 ⊕ u 4 ⊕ u 6 ⊕ u 7 .
Similarly, the first row 13 of L − 1 gives
( L − 1 u ) 0 = u 0 ⊕ u 1 ⊕ u 4 .
The linear-conjugation stage constitutes the coordinate-optimization component of the proposed construction. It is used to select a binary representation of the retained trim with coordinate-optimized diffusion indicators, while preserving differential uniformity, vectorial nonlinearity, the linear spectrum, algebraic degree, and boomerang uniformity.
To examine the effect of the coordinate-optimization stage independently, a matched control experiment was also performed. The same sequence of 10 6 nonsingular 8 × 8 binary matrices, generated with the fixed seed 20260813, was applied separately to the AES S-box and to the fixed retained trim ( α , β , b ) = ( 0 x 06 , 0 x 143 , 0 x 191 ) underlying the selected S * . For each mapping, DSAC and BIC were evaluated for every sampled linear conjugate using the same definitions and implementation. This matched experiment isolates the influence of binary coordinate representation from the preceding structural trim search.

3.6. Output Translation and Representative S-Box Selection

Following selection of the linear transformation L, the output translation κ ∈ F 2 8 is XORed with the output of the retained trim before the outer application of L. Thus, the final construction is
S * ( u ) = L T α , β , b L − 1 u ⊕ κ , u ∈ F 2 8 .
For each retained core–matrix combination satisfying the prescribed diffusion criteria, all 256 possible values of κ are examined. Output translation does not alter differential uniformity, vectorial nonlinearity, linear approximation characteristics, algebraic degree, boomerang uniformity, SAC, DSAC or BIC. Therefore, the translation stage is used to evaluate structural properties, including fixed points, opposite fixed points, and permutation-cycle structure.
A representative S-box is selected by requiring the absence of fixed and opposite fixed points and by preferring a single permutation cycle of length 256. For the selected core–matrix pair, exhaustive evaluation of all 256 output translations identified 42 values of κ for which both the number of fixed points and opposite fixed points is zero. Among all 256 translations, only κ = 0 x 86 produces a single permutation cycle of length 256. Hence, κ = 0 x 86 is the unique full-cycle translation for the selected core–matrix pair. The resulting representative parameter combination is
( α , β , b , κ ) = ( 0 x 06 , 0 x 143 , 0 x 191 , 0 x 86 ) .

3.7. Inverse S-Box Generation

Since only bijective trims T α , β , b are retained, the inverse mapping T α , β , b − 1 exists uniquely and since the restriction of π b to Y α , β = C α − 1 ( H β ) is bijective for every retained trim, each projected output corresponds to a unique element of Y α , β . Therefore, the inverse trim recovers this unique element, applies C α , and then applies ι β − 1 to recover the original 8-bit input.
Consistently with Section 3.6, κ is XORed with the trim output before the outer application of L. The final S-box is therefore defined as
S * ( u ) = L T α , β , b L − 1 u ⊕ κ .
Accordingly, the inverse S-box is obtained by reversing the sequence of transformations and is given by
S * − 1 ( v ) = L T α , β , b − 1 L − 1 v ⊕ κ , v ∈ F 2 8 .
The inverse therefore satisfies
S * − 1 S * ( u ) = u , u ∈ F 2 8 .
For implementation, T α , β , b − 1 and consequently S * − 1 are generated by reversing the input–output correspondence of the corresponding bijective permutation. Thus, the inverse S-box is uniquely determined by the selected forward S-box and introduces no additional design parameter.
The selected proposed S-box S * and its corresponding inverse S * − 1 are presented in Table 1 and Table 2, respectively.
Table 1. Proposed S-box ( S * ).
Table 2. Proposed inverse S-box ( S * − 1 ).

4. Theoretical Analysis of the Proposed S-Box

This section is concerned with the theoretical properties of the proposed S-box construction. The analysis shows that bijectivity is preserved by output translation and linear conjugation and investigates which cryptographic properties are preserved by these transformations.

4.1. Preservation of Bijectivity

Let T α , β , b : F 2 8 → F 2 8 be a bijective trim satisfying the criterion defined in Section 3.3. The output-translated mapping is defined as
S α , β , b , κ ( u ) = T α , β , b ( u ) ⊕ κ ,
where κ ∈ F 2 8 . In the final construction, this output-translated mapping is subsequently acted on by the outer linear transformation L; hence, κ is applied before the outer L.
Since XOR with a fixed constant κ is a bijective operation on F 2 8 , the output translation preserves bijectivity. Therefore, if T α , β , b is bijective, then S α , β , b , κ is also bijective.
Similarly, let L ∈ GL ( 8 , 2 ) be the fixed nonsingular binary matrix defined in Section 3.5. The final S-box is obtained through linear conjugation as
S * = L ∘ S α , β , b , κ ∘ L − 1 .
Since L, L − 1 , and S α , β , b , κ are all bijective mappings, their composition is also bijective. Therefore,
S * : F 2 8 → F 2 8
is an 8 × 8 permutation.

4.2. Preservation of Differential and Linear Properties

Let S α , β , b , κ be obtained from a bijective trim T α , β , b through output translation by κ ∈ F 2 8 . For any nonzero input difference a ∈ F 2 8 ,
S α , β , b , κ ( u ⊕ a ) ⊕ S α , β , b , κ ( u ) = T α , β , b ( u ⊕ a ) ⊕ T α , β , b ( u ) ,
because the constant κ cancels under XOR. Therefore, output translation preserves the differential distribution and hence the differential uniformity of the trim.
Similarly, addition of a constant output vector does not alter the magnitudes of the Walsh coefficients of a vectorial Boolean mapping. Consequently, vectorial nonlinearity, maximum Walsh magnitude, maximum linear bias, and maximum linear probability are preserved under output translation.
The final mapping
S * = L ∘ S α , β , b , κ ∘ L − 1
is linearly equivalent to S α , β , b , κ , since L ∈ GL ( 8 , 2 ) is invertible. Linear equivalence preserves the differential uniformity and Walsh-spectrum magnitudes of a vectorial Boolean function. Therefore, the differential uniformity, vectorial nonlinearity, maximum Walsh magnitude, maximum linear bias, and maximum linear probability of S * are identical to those of the corresponding bijective trim T α , β , b .
Hence, these core cryptographic properties need only be evaluated once at the bijective-trim stage and are not recomputed for every output translation κ or for the fixed linear conjugation L.

4.3. Algebraic Degree and Affine-Equivalence Considerations

The algebraic degree of a vectorial Boolean function is determined by the maximum algebraic degree among its coordinate Boolean functions. Output translation by a constant vector κ modifies only the constant terms of the coordinate functions and therefore does not alter their algebraic degree. Hence,
deg S α , β , b , κ = deg T α , β , b .
Similarly, composition with invertible linear mappings at the input and output preserves algebraic degree. Since the final S-box is defined by
S * = L ∘ S α , β , b , κ ∘ L − 1 ,
it follows that
deg ( S * ) = deg S α , β , b , κ = deg T α , β , b .
For completeness, the degree preservation can be shown directly for the specific fixed transformation L. Let F = S α , β , b , κ . Since each coordinate of L ∘ F is an F 2 -linear combination of the coordinate functions of F,
deg ( L ∘ F ) ≤ deg ( F ) .
The matrix L is nonsingular and its inverse L − 1 is explicitly specified in the construction. Hence F = L − 1 ∘ ( L ∘ F ) , which gives the reverse inequality
deg ( F ) ≤ deg ( L ∘ F ) .
Therefore,
deg ( L ∘ F ) = deg ( F ) .
Likewise, substituting the linear forms defined by L − 1 for the input variables cannot increase the degree, so
deg ( F ∘ L − 1 ) ≤ deg ( F ) .
Because L − 1 is invertible, F = ( F ∘ L − 1 ) ∘ L , and therefore
deg ( F ) ≤ deg ( F ∘ L − 1 ) .
Thus
deg ( F ∘ L − 1 ) = deg ( F ) ,
and combining the two equalities gives
deg ( L ∘ F ∘ L − 1 ) = deg ( F ) .
Hence the particular fixed linear conjugation used in S * preserves the Boolean algebraic degree exactly.
Consequently, the output translation and fixed linear conjugation do not increase or decrease the algebraic degree of the underlying bijective trim. This property also provides a direct criterion for excluding affine or extended-affine equivalence with an S-box having a different algebraic degree. Since the AES S-box has algebraic degree 7 but the proposed S-box has algebraic degree 5, the proposed S-box S * is not affine-equivalent or extended-affine-equivalent to the AES S-box. Although the proposed S * has a lower Boolean algebraic degree than the AES S-box, all 255 nonzero component functions
f a ( x ) = a · S * ( x ) , a ∈ F 2 8 ∖ { 0 } ,
have algebraic immunity 4. For each component, algebraic immunity was computed as the minimum degree of a nonzero Boolean function g satisfying either f a g = 0 or ( f a + 1 ) g = 0 . The computation was implemented in Python 3.13.5 using exact Gaussian elimination over F 2 . For each candidate degree d, all square-free monomials of degree at most d, including the constant monomial, were evaluated on the support of f a and on its complement. A nonzero annihilator of degree at most d exists when the corresponding evaluation matrix has a nontrivial nullspace. The exhaustive computation gives algebraic immunity 4 for every one of the 255 nonzero component functions of S * . Applying the same procedure to the AES S-box likewise gives algebraic immunity 4 for all 255 nonzero component functions.

4.4. Structural Effects of Output Translation and Linear Conjugation

Although output translation preserves the core differential and linear properties of a bijective trim, it may alter its permutation structure. For
S α , β , b , κ ( u ) = T α , β , b ( u ) ⊕ κ ,
different values of κ may produce different fixed points, opposite fixed points, and cycle decompositions. Therefore, these structural properties are evaluated after applying each output translation.
In contrast, the linear conjugation
S * = L ∘ S α , β , b , κ ∘ L − 1
preserves the cycle structure of S α , β , b , κ . Specifically, if
u 1 → u 2 → … → u r → u 1
is a cycle of S α , β , b , κ , then
L ( u 1 ) → L ( u 2 ) → … → L ( u r ) → L ( u 1 )
is a cycle of S * having the same length. Consequently, the number of disjoint cycles and their corresponding lengths are unchanged under linear conjugation. The number of fixed points is also preserved.
Output translation does not alter derivative-based avalanche behavior, since the constant κ cancels when output differences are computed. Hence, SAC and BIC characteristics remain unchanged by κ . Linear conjugation, however, changes the binary-coordinate representation of the input and output and may therefore alter coordinate-dependent indicators such as SAC, DSAC, and BIC.
Opposite fixed points are defined relative to the specific binary vector 0 xFF . A general linear conjugation does not necessarily preserve this condition unless L ( 0 xFF ) = 0 xFF . Therefore, the absence of opposite fixed points is verified directly for the final mapping S * .
Accordingly, structural and coordinate-dependent indicators are evaluated on the final S-box representation, while the differential uniformity, vectorial nonlinearity, maximum Walsh magnitude, maximum linear bias, maximum linear probability, and algebraic degree established at the bijective-trim stage remain unchanged by the subsequent transformations.

5. Experimental Results and Discussion

5.1. Exhaustive Search and Representative S-Box Selection

The retained parameter instances were first examined for mapping multiplicity by comparing their complete 256-entry lookup tables. All 3066 retained instances correspond to distinct 8 × 8 permutations; no duplicate LUTs were observed. The retained mappings are distributed uniformly over the six admissible values of α : 511 retained triples are obtained for each of α = 0 x 02 , 0 x 03 , 0 x 04 , 0 x 05 , 0 x 06 , and 0 x 07 . Moreover, for every hyperplane H β associated with each admissible α , exactly one of the 511 nonzero projection directions b satisfies the bijectivity criterion. Hence, the multiplicity of valid projection directions is one for every pair ( α , β ) .
To examine structural equivalence among the retained mappings, their differential spectra and absolute extended-Walsh spectra were computed. The 3066 mappings separate into six distinct combined invariant-signature groups having multiplicities 1764, 882, 147, 147, 63, and 63, respectively. Since these spectra are preserved under CCZ equivalence, mappings belonging to different signature groups are CCZ-inequivalent and consequently cannot be EA- or affine-equivalent. Equal invariant signatures alone do not establish CCZ equivalence; therefore, exact CCZ-equivalence testing was subsequently performed within each signature group using the standard binary-code characterization of CCZ equivalence [35]. For an 8 × 8 mapping S, the associated binary linear code was generated by the constant row, the eight input-coordinate rows, and the eight output-coordinate rows,
1 , x 0 , … , x 7 , S 0 ( x ) , … , S 7 ( x ) ,
with the 256 coordinate positions indexed by x = 0 , … , 255 . Within each invariant-signature group, exact code permutation equivalence was tested using SageMath’s LinearCode.is_permutation_equivalent routine. The first mapping initialized the first class; each subsequent mapping was compared with one representative of every previously identified exact class and was assigned to the first permutation-equivalent class, or initialized a new class if no representative was equivalent. No canonical labeling was used. The preserved classification scripts use SageMath for the exact tests. The exact SageMath version used for the original classification run was not recorded and is therefore not retrospectively asserted.
The six invariant-signature groups were found to contain 4, 2, 1, 1, 1, and 1 CCZ-equivalence classes, respectively. Since mappings belonging to different invariant-signature groups cannot be CCZ-equivalent, these results establish that the 3066 retained mappings comprise exactly 10 distinct CCZ-equivalence classes. Because affine and EA equivalence imply CCZ equivalence, mappings belonging to different CCZ classes are necessarily also EA- and affine-inequivalent.
The equivalence analysis was also extended to the previously published 8 × 8 mappings considered in this study. The comparison set comprised the canonical AES S-box, 540 mappings generated according to Nitaj et al. [18], four mappings from Artuğer et al. [5], three mappings from Artuğer [36], and four mappings from Bilal et al. [37], giving 552 comparison mappings in total. None of these mappings shares a combined differential-spectrum and absolute extended-Walsh-spectrum signature with any of the retained trims. Hence, the retained trim mappings are CCZ-inequivalent to all 552 comparison mappings considered here and consequently are also EA- and affine-inequivalent to them. The exact CCZ-classification script is provided as src/ccz/ccz_exact_classify_retained.sage. Class memberships and representatives are reported in data/ccz/exact_classes/ccz_exact_classification_group1.csv through ccz_exact_classification_group6.csv, with the class counts summarized in data/ccz/exact_classes/ccz_exact_class_count_summary.csv. Validation results are provided in data/ccz/ccz_exact_benchmark_results.csv, and the comparison with the 552 external mappings is reported in data/ccz/external_comparison/comparison_552_signature_results.csv.
The complete structural parameter space defined in Section 3.4 was exhaustively evaluated, comprising 1,566,726 combinations ( α , β , b ) . Among these, 3066 parameter combinations satisfied the bijectivity criterion and therefore produced bijective 8 × 8 trim instances, which were retained as candidate S-box mappings. Table 3 summarizes the complete search and representative S-box selection procedure.
Table 3. Summary of the proposed S-box search and selection procedure.
All 3066 bijective trims exhibited differential uniformity 4, vectorial nonlinearity 112, and maximum Walsh magnitude 32, corresponding to a maximum linear bias of 2 − 4 . The Boolean algebraic degree of the retained trims was 5, while their boomerang uniformity ranged from 14 to 20.
The subsequent randomized linear-conjugation search applied the same 1,000,000 distinct nonsingular binary matrices to each of the 3066 retained bijective trims, corresponding to 3,066,000,000 randomized core–L pairs. DSAC was evaluated for every pair, whereas BIC was evaluated only for pairs passing the exact DSAC < DSAC AES screening described in Section 3.5. The additional preserved baseline L contributes 3066 further core–L pairs across the retained trims, giving 3,066,003,066 core–L pairs in the complete implementation run. Eight sampled core–matrix pairs simultaneously achieved DSAC and BIC values below those of the canonical AES byte mapping, namely DSAC = 432 and BIC = 0.134125.
Using the fixed matrix L specified in Section 3.5, the core
( α , β , b ) = ( 0 x 06 , 0 x 143 , 0 x 191 )
was selected. The resulting mapping achieves differential uniformity 4, vectorial nonlinearity 112, maximum linear bias 2 − 4 , algebraic degree 5, boomerang uniformity 18, DSAC 392 and a BIC score of 0.129412 .
The matched coordinate-representation experiment further quantifies the effect of the linear-conjugation stage. For the AES S-box, the 10 6 sampled conjugates produced DSAC values from 284 to 588, with mean 440.044 and median 440, and BIC values from 0.103448 to 0.134975, with mean 0.131870 and median 0.131696. Among these representations, 8.4434% had DSAC ≤ 392 , 15.3782% had BIC ≤ 0.129412 , and 2.2911% satisfied both thresholds simultaneously.
For the fixed retained trim ( α , β , b ) = ( 0 x 06 , 0 x 143 , 0 x 191 ) , the same 10 6 matrices produced DSAC values from 280 to 748, with mean 498.235 and median 496, and BIC values from 0.129412 to 0.571992, with mean 0.255961 and median 0.248287. The selected matrix L gives DSAC = 392 and BIC = 0.129412 . Within this matched search, 1.3684% of the conjugates had DSAC ≤ 392 , while the selected L was the only sampled matrix ( 0.0001 % ) attaining BIC ≤ 0.129412 ; it was also the only sampled matrix satisfying both thresholds simultaneously. Accordingly, the selected S * has lower DSAC and BIC than the canonical AES byte mapping, but the matched control does not establish an advantage over AES under the same coordinate-optimization search. The AES conjugate distribution also exhibits lower mean and median DSAC and BIC values than the corresponding distribution for the fixed retained trim.
These results confirm that DSAC and BIC depend strongly on the selected binary coordinate representation. They also show the role of the linear-conjugation stage within the proposed construction: the retained trim provides the underlying differential and linear characteristics, while the coordinate-optimization stage selects a representation with the reported avalanche and bit-independence indicators.
Finally, with κ XORed with the trim output before the outer application of L, exhaustive evaluation of all 256 output translations identified 42 values of κ producing neither fixed points nor opposite fixed points. Among all translations, only κ = 0 x 86 produces a single permutation cycle of length 256. Therefore, κ = 0 x 86 is selected as the unique full-cycle translation for this core–matrix pair. The resulting mapping is used as the representative proposed S-box, S * , throughout the subsequent comparative analysis. The cryptographic properties of the selected S * , AES S-box, and the compared S-box schemes are summarized in Table 4.
Table 4. Comparison of cryptographic and structural properties. For multi-S-box collections, varying scalar quantities are reported using collection mean, minimum, and maximum values; common values are reported once, and condition counts are reported as k / n .
For the comparative analysis, all S-box mappings were evaluated using the same implementation and identical metric definitions; only the input LUT was changed between evaluations. The comparison comprises the canonical AES S-box, all 540 mappings of Nitaj et al. [18], the four mappings reported by Artuğer et al. [5], the three mappings reported by Artuğer [36], the four mappings reported by Bilal et al. [37], and the selected proposed S * . For Nitaj et al., the complete set of 540 mappings was generated from the parameter sets reported in the cited work; for the other comparison studies, the LUTs reported in the corresponding papers were used directly.
For collections containing multiple mappings, a scalar property that varies within the collection is reported using separate collection mean, minimum, and maximum values. For the “Mean coordinate nonlinearity” row in Table 4, the value for each individual S-box is first computed as the arithmetic mean of the nonlinearities of its eight output-coordinate Boolean functions. For a collection containing multiple S-boxes, the table then reports the collection mean, minimum, and maximum of these per-S-box mean-coordinate values in separate subrows. This quantity is distinct from vectorial nonlinearity, which is defined as the minimum nonlinearity over all 255 nonzero component functions. If all mappings in a collection have the same value, that common value is reported once. Properties representing the occurrence of a condition are reported as counts k / n , where k is the number of mappings satisfying the condition and n is the number of mappings in the corresponding collection. Cycle-related ranges similarly summarize the mappings in the collection rather than representing a single S-box.
Table 4 distinguishes single-mapping values from summaries over multi-S-box collections. In particular, the SAC, DSAC, BIC, differential, linear-bias, and cycle statistics of the multi-mapping studies should be interpreted as distribution summaries rather than as properties of a single representative S-box. The fixed point and opposite fixed point entries are counts of mappings exhibiting at least one such point and are therefore reported relative to the total number of mappings in each collection.
For reproducibility, the source code, retained parameter triples, sampled linear matrices, intermediate results, random seeds, representation conventions, and scripts used for the reported computational analyses are provided as Supplementary Materials.
The preserved run logs record an elapsed time of 62.665  s for the exhaustive structural search and 992.689  s for the linear-conjugation search implementation. The latter run covered 3,066,003,066 core–L pairs in total, comprising 3,066,000,000 randomized pairs and 3066 pairs corresponding to the separately identified preserved baseline matrix. DSAC was evaluated for every pair, whereas BIC was evaluated only for the subset passing the DSAC screening described in Section 3.5. The matched 10 6 -matrix experiments for AES and the selected retained trim recorded elapsed times of 120.884  s and 76.496  s, respectively. The supplied search implementations use serial iteration with Numba just-in-time compilation and do not employ explicit multiprocessing or multithreaded search. The exact CPU, RAM, SageMath version, and peak-memory usage of the original APN and CCZ search runs were not preserved in the original logs and are therefore not retrospectively asserted.

5.2. Differential and Boomerang Cryptanalysis

Differential cryptanalysis is a chosen-plaintext technique that exploits the propagation of input differences through a cipher to identify high-probability differential characteristics [30]. At the S-box level, differential behavior is commonly characterized by differential uniformity [38] and maximum differential probability ( DP max ); smaller values are desirable because they limit the probability of individual S-box differentials [32]. Boomerang uniformity (BU), derived from the Boomerang Connectivity Table (BCT), provides a related S-box-level measure for boomerang-style differential behavior, for which a lower value is desirable [39].
The AES S-box and the selected proposed S-box S * are both differentially 4-uniform permutations with DP max = 2 − 6 [22]. Thus, under the adopted S-box-level measures, both mappings exhibit the same maximum differential probability. These local S-box characteristics do not by themselves establish resistance of a complete cipher to differential cryptanalysis, which additionally depends on the cipher structure, diffusion layer, number of active S-boxes, round configuration, trail bounds, and key schedule.
The AES S-box has boomerang uniformity 6, whereas the selected proposed S-box S * has boomerang uniformity 18. Hence, although the two mappings have the same differential uniformity, the AES S-box exhibits substantially lower boomerang uniformity. Since boomerang uniformity is the maximum nontrivial entry of the BCT, the larger value for S * indicates that some local boomerang transitions have higher connectivity than for the AES S-box. Consequently, when S * is embedded in a cipher, such transitions may provide a less favorable local contribution to a boomerang trail, and the higher BU therefore constitutes a limitation relative to AES. However, BU alone does not establish vulnerability of a complete cipher to a boomerang-style attack. The probability and feasibility of a full-cipher boomerang characteristic additionally depend on the diffusion layer, the number and arrangement of active S-boxes, compatibility of differential trails across rounds, the number of rounds, and the key schedule. Accordingly, determining whether the higher BU leads to an exploitable full-cipher weakness requires analysis of a specific cipher construction, which is outside the scope of the present S-box-level study.

5.3. Linear Cryptanalysis

Linear cryptanalysis exploits statistical linear approximations between selected input, output, and key bits of a cipher [31]. At the S-box level, the strength of such approximations is characterized using the maximum Walsh magnitude W max , the maximum linear bias ε , and the corresponding maximum linear probability LP max . For an 8 × 8 S-box, the terminology used throughout this work follows
ε = W max 2 9 , LP max = 1 2 + ε .
Thus, W max = 32 corresponds to ε = 2 − 4 = 0.0625 and LP max = 0.5625 [32]. A smaller maximum linear bias is desirable because it limits the strength of individual linear approximations.
For an 8 × 8 S-box S = ( S 0 , … , S 7 ) , two nonlinearity summaries are distinguished in this work. The mean coordinate nonlinearity is
NL coord ( S ) = 1 8 ∑ j = 0 7 NL ( S j ) ,
where NL ( S j ) is the minimum Hamming distance of the coordinate Boolean function S j from the set of affine Boolean functions. In contrast, the vectorial nonlinearity is
NL vec ( S ) = min a ∈ F 2 8 ∖ { 0 } NL ( a · S ) ,
and therefore considers all 255 nonzero component functions. Table 4 reports mean coordinate nonlinearity, whereas statements of “vectorial nonlinearity” elsewhere in the manuscript refer to NL vec . Higher values are desirable under either measure [40].
For both the AES S-box and the selected proposed S-box S * , the maximum linear bias is ε = 2 − 4 , corresponding to LP max = 0.5625 [22]. Both mappings also have vectorial nonlinearity 112. Therefore, under the adopted S-box-level linear measures, the selected S * matches the AES S-box in maximum linear bias, maximum linear probability, and vectorial nonlinearity.
These quantities characterize the local linear-approximation behavior of the S-box mappings. They do not by themselves establish resistance of a complete cipher to linear cryptanalysis, which also depends on the round function, diffusion layer, number and arrangement of active S-boxes, trail bounds, number of rounds, and key schedule.

5.4. Multivariate Quadratic (MQ) System Analysis

The algebraic representation of an S-box as a multivariate quadratic (MQ) system depends on the selected variables and modeling convention. Therefore, construction-specific equation counts are distinguished here from a direct input–output quadratic-relation analysis performed under an identical convention for the AES S-box and the selected proposed S-box S * .
For the proposed construction, a natural lifted representation follows directly from its internal structure. Let
u = ( u 0 , … , u 7 ) , w = ( w 0 , … , w 8 ) , v = ( v 0 , … , v 7 )
denote the input bits, the internal nine-bit parent-state variables, and the output bits, respectively. Since the nonlinear stage employs the compositional inverse C α − 1 , its direct expansion is avoided by introducing the equivalent relation
C α ( w ) = ι β L − 1 u .
Because C α is quadratic, this relation yields nine quadratic Boolean equations. The subsequent projection, output translation and linear transformation are represented by
v = L π b ( w ) ⊕ κ ,
which yields eight affine equations. Hence, this construction-specific lifted representation contains 25 Boolean variables and 17 equations: nine quadratic and eight affine equations. The complete system was verified over all 256 input–output pairs of the selected S * . Since such counts depend on the chosen internal variables, they are not used directly for comparison with AES.
For a common comparison, both AES and S * are instead analyzed using the same direct input–output quadratic-relation convention. Let
p = ( p 0 , … , p 7 ) , q = ( q 0 , … , q 7 )
denote the LSB-first input and output bits of an S-box, and let
z = ( p 0 , … , p 7 , q 0 , … , q 7 ) .
Over the Boolean variables z 0 , … , z 15 , all square-free monomials of degree at most two are considered:
M 2 = { 1 } ∪ { z i : 0 ≤ i ≤ 15 } ∪ { z i z j : 0 ≤ i < j ≤ 15 } .
Thus,
| M 2 | = 1 + 16 + 16 2 = 137 .
For each S-box, the 137 monomials are evaluated on all 256 graph points ( p , S ( p ) ) , producing an evaluation matrix
E S ∈ F 2 256 × 137 .
A coefficient vector c ∈ F 2 137 defines a quadratic input–output relation satisfied by every graph point if and only if
E S c = 0 .
Consequently, the number of linearly independent quadratic relations is
137 − rank ( E S ) .
Using this identical convention, the AES S-box gives
rank ( E AES ) = 98 ,
and therefore admits 39 independent quadratic relations. For the selected proposed S-box S * ,
rank ( E S * ) = 136 ,
giving only one independent quadratic relation under the same convention. See Table 5.
Table 5. Direct quadratic input–output relation analysis under a common modeling convention.
Under the common direct input–output representation, the selected S * is substantially less overdefined at degree two than the AES S-box, admitting one independent quadratic relation compared with 39 for AES. Thus, under the adopted representation, fewer direct low-degree algebraic relations are exposed by S * . However, the number of quadratic relations depends on the selected representation and does not by itself determine the complexity of an algebraic attack. Solving complexity also depends on factors such as equation structure, sparsity, dependencies, the surrounding cipher construction, and the solving method. Accordingly, the relation counts are reported as algebraic structural characteristics and are not interpreted as evidence of stronger complete-cipher security.
The complete machine-readable quadratic-relation systems and the scripts used to generate and verify them over all 256 input–output pairs are provided in the Supplementary Materials. The construction-specific lifted MQ system of S * is also included separately.

5.5. Fixed Points and Opposite Fixed Points

The presence of fixed points and opposite fixed points in an S-box reflects undesirable structural regularities. A fixed point satisfies S ( x ) = x , whereas an opposite fixed point satisfies S ( x ) = x ⊕ 0 xFF . Eliminating such points is commonly considered a desirable design criterion in S-box constructions [41].
The designers of Rijndael imposed the restriction that the AES S-box should contain neither fixed points nor opposite fixed points [22]. In the proposed construction, these properties are examined during the output-translation stage. After selecting the structural parameters ( α , β , b ) and the fixed linear transformation L, all 256 possible values of κ ∈ F 2 8 are evaluated for fixed points and opposite fixed points. The representative S-box S * , obtained using
( α , β , b , κ ) = ( 0 x 06 , 0 x 143 , 0 x 191 , 0 x 86 ) ,
contains no fixed points and no opposite fixed points. Thus, the selected S-box satisfies the same structural restriction adopted in the AES S-box.

5.6. Strict Avalanche Criterion and Distance to SAC

The Strict Avalanche Criterion (SAC) evaluates the effect of complementing one input bit on each output bit of an S-box. Ideally, each output bit should change with probability 0.5 for every single-bit input perturbation [18]. For an 8 × 8 S-box S, define
d i , j ( x ) = bit j S ( x ) ⊕ S ( x ⊕ 2 i ) , i , j ∈ { 0 , … , 7 } ,
where input and output bits are indexed in least-significant-bit-first order. The corresponding SAC count matrix A ∈ Z 8 × 8 is defined as
A i , j = ∑ x = 0 255 d i , j ( x ) .
Thus, A i , j is the number of the 256 possible inputs for which output bit j changes when input bit i is complemented. The ideal value of each SAC count is 128 [18].
The mean SAC value reported in this work is the arithmetic mean of the 64 SAC-count entries,
SAC mean = 1 64 ∑ i = 0 7 ∑ j = 0 7 A i , j .
The corresponding probability-normalized value is SAC mean / 256 .
The distance to SAC (DSAC) is computed as
DSAC = ∑ i = 0 7 ∑ j = 0 7 A i , j − 128 .
Hence, a lower DSAC indicates a smaller cumulative deviation from the ideal SAC count. All SAC and DSAC values reported in this work are obtained by exhaustive deterministic evaluation over all 256 inputs.
The canonical AES byte mapping gives SAC mean = 129.25 and DSAC = 432 , whereas the selected proposed S-box S * gives SAC mean = 128.125 and DSAC = 392 . The corresponding probability-normalized mean SAC value of S * is 0.50048828125 . These values characterize the respective binary coordinate representations; their comparative interpretation is considered together with the coordinate-representation search. The difference between the reported DSAC values is interpreted only as a difference in cumulative deviation from the ideal SAC count under the selected binary representations. No direct reduction in the probability or complexity of a specific cryptanalytic attack is inferred from DSAC alone.
To complement the mean SAC and DSAC measures, the dispersion of the 64 entries of the SAC-count matrix is quantified by the population standard deviation
σ SAC = 1 64 ∑ i = 0 7 ∑ j = 0 7 A i , j − SAC mean 2 .
For the selected S * , σ SAC = 8.831 counts. This statistic describes the dispersion of the individual SAC-matrix entries and complements the cumulative DSAC measure; it is not a sampling-error estimate because the SAC matrix is evaluated exhaustively over all 256 inputs. For multi-S-box comparison collections, Table 4 reports the collection mean, minimum, and maximum of the corresponding per-S-box values of σ SAC .

5.7. Univariate Interpolation Representation

An S-box can be represented by a univariate polynomial over a finite field, which is relevant to interpolation-based analysis [42,43]. In this work, the univariate interpolation is considered over
F 2 8 = F 2 [ x ] / x 8 + x 4 + x 3 + x + 1 ,
using the polynomial basis
{ 1 , x , x 2 , … , x 7 } .
An 8-bit value a = ( a 7 a 6 … a 1 a 0 ) 2 is identified with the field element
a 0 + a 1 x + ⋯ + a 7 x 7 .
Using all 256 input–output pairs of an S-box, the unique polynomial
P S ( X ) = ∑ i = 0 255 c i X i
satisfying
P S ( a ) = S ( a ) , a ∈ F 2 8 ,
is obtained by Lagrange interpolation. The univariate interpolation degree is the largest exponent with a nonzero coefficient, while the number of nonzero terms is the number of nonzero coefficients of P S ( X ) . These quantities are distinct from the Boolean algebraic degree defined from the algebraic normal forms of the coordinate Boolean functions.
Under the above field representation, the AES S-box has univariate interpolation degree 254 with 9 nonzero terms, whereas the selected S * has degree 248 with 219 nonzero terms. Thus, under this common representation, the polynomial representation of S * is considerably denser than that of AES.
The interpolation degree and the number of nonzero terms depend on the selected field representation, basis, and byte-to-field identification. Therefore, the comparison above is specific to the representation defined here and is not treated as an invariant cryptographic property.

5.8. Cycle Structure and Periodicity

Cycle structure refers to the long-term permutation behavior of an S-box under repeated applications and offers insight into its structural properties [24].
The AES S-box has five disjoint cycles of lengths 2, 27, 59, 81, and 87, resulting in five corresponding permutation periods [24], whereas the selected proposed S-box S * is a unicursal permutation, i.e., it forms a single cycle of length 2 8 with all 2 8 elements in F 2 8 . Structurally, the proposed S-box exhibits full-cycle behavior under repeated substitution, traversing all 256 elements before returning to the starting value. The full-cycle property is reported as a structural characteristic of the selected permutation and is not interpreted as an independent security advantage.

5.9. Bit Independence Criterion

The Bit Independence Criterion (BIC) measures the independence between output-bit changes produced by single-bit input differences [44]. In this work, BIC is evaluated using the Pearson correlation coefficient [24].
Using the derivative bits d i , j ( x ) defined in Section 5.6, for each input bit i ∈ { 0 , … , 7 } and each unordered pair of distinct output bits 0 ≤ j < k ≤ 7 , the Pearson correlation is defined as
ρ i , j , k = ∑ x = 0 255 d i , j ( x ) − d ¯ i , j d i , k ( x ) − d ¯ i , k ∑ x = 0 255 d i , j ( x ) − d ¯ i , j 2 ∑ x = 0 255 d i , k ( x ) − d ¯ i , k 2 ,
where
d ¯ i , j = 1 256 ∑ x = 0 255 d i , j ( x ) .
If either derivative sequence has zero variance, the corresponding correlation is assigned the value zero, consistent with the implementation.
The scalar BIC score reported in this work is
BIC = max 0 ≤ i ≤ 7 0 ≤ j < k ≤ 7 ρ i , j , k .
Thus, all eight single-bit input differences and all 8 2 = 28 unordered pairs of distinct output bits are included, giving 8 × 28 = 224 unique correlations. The scalar BIC value is therefore the maximum absolute Pearson correlation rather than the mean correlation.
All BIC values are obtained by exhaustive deterministic evaluation over all 256 inputs. Decimal values are rounded representations of these deterministic calculations rather than statistical estimates. The same SAC, DSAC, and Pearson-correlation BIC definitions are used for the proposed mappings and the comparison S-box mappings evaluated in this study.
Under the adopted measure, the canonical AES byte mapping gives BIC = 0.134125 when rounded to six decimal places, whereas the selected proposed S-box S * gives BIC = 0.129412 when rounded to six decimal places. The comparative interpretation of these coordinate-dependent values is considered together with the coordinate-representation search. Since the BIC values are obtained exhaustively over all 256 inputs, their numerical difference is not a sampling artifact. However, no direct cryptanalytic advantage is established from the lower BIC value; it is treated only as a coordinate-dependent descriptive measure of output-bit derivative correlation.

5.10. Implementation Feasibility

To determine the feasibility of the proposed S-box beyond its cryptographic indicators, implementation efficiency is evaluated in both software and hardware. The software benchmark was repeated on an Intel Core i5-1135G7 system with 16 GB RAM running Microsoft Windows 11. Both software implementations were compiled using GCC 15.2.0 with the flags -O3 -march=native -std=c11. Timing was performed using QueryPerformanceCounter. The process was pinned to logical CPU 0, while processor turbo and frequency settings were left at the system default and were not manually modified.
For each software experiment, 30 measured repetitions were performed, with 50 million input evaluations per S-box in each repetition. Five untimed warm-up passes over one million inputs preceded the measurements. A single deterministic input array generated using xorshift64star with fixed seed 0xA5A5D3C4B2E18769 was reused for both S-boxes and all repetitions. The execution order was alternated between AES-first and proposed-S-box-first across successive repetitions to reduce ordering bias. No explicit cache flush was applied. In the LUT experiment, both 256-byte lookup tables were warmed before measurement. For each measured repetition, throughput is computed from that repetition’s elapsed time as 50 × 10 6 evaluated bytes divided by the elapsed time and is converted to decimal MB/s. The reported mean throughput is the arithmetic mean of the 30 per-repetition throughput values; it is not computed by dividing 50 MB by the mean elapsed time.
Throughput is reported in decimal MB/s, where 1 MB = 10 6 bytes. Cycles/byte are not reported because hardware cycle counters were not used, and no cycle estimate is derived from the nominal processor frequency.
Hardware synthesis is evaluated separately using Verilog Hardware Description Language (HDL) and Yosys. The AES S-box [22] and the proposed S-box S * given in Table 1 are evaluated under the corresponding software and hardware setups described below.

5.10.1. LUT Implementation (Software)

The AES S-box and proposed S-box S * are implemented in C as precomputed 256-entry lookup tables, where each 8-bit input directly indexes its corresponding output. Each measured repetition consisted of 50 million lookups using the common benchmarking protocol described above. A total of 30 measured repetitions were performed for each S-box.
The results are presented in Table 6. Over 30 measured repetitions, the AES LUT achieved a mean throughput of 650.842 MB/s and a median throughput of 687.940 MB/s, whereas the proposed S * LUT achieved a mean throughput of 586.060 MB/s and a median throughput of 605.870 MB/s. The corresponding throughput standard deviations were 112.115 MB/s and 153.701 MB/s, respectively. The observed run-to-run variability does not support attributing an intrinsic software-speed advantage to either LUT implementation. Both 8 × 8 S-boxes use the same 256-entry byte-indexed lookup mechanism and require the same lookup-table storage capacity.
Table 6. Performance comparison of AES S-box and proposed S-box over 50 M inputs per repetition.

5.10.2. Real-Time Computation (Construction-Based Evaluation)

In this experiment, an 8-bit input is transformed into its corresponding 8-bit output through direct arithmetic as specified in Definition 2 for the AES S-box and according to the proposed construction in Section 3 for S * . No precomputed 256-entry final S-box LUT is used during the timed evaluation.
For the AES implementation, the multiplicative inverse is evaluated directly in F 2 8 . For each nonzero input x, x − 1 is computed as x 254 using binary square-and-multiply, with finite field multiplication reduced modulo the AES irreducible polynomial x 8 + x 4 + x 3 + x + 1 ; the zero input is mapped to zero. The extended Euclidean algorithm and log/antilog tables are not used, and no precomputed inverse table is employed. The resulting inverse is then followed by the standard AES affine transformation.
For the proposed construction, C α − 1 denotes the compositional inverse of the 9-bit parent permutation C α , rather than finite field multiplicative inversion. For the selected α = 0 x 06 , C α − 1 is evaluated directly using finite field arithmetic over F 2 3 , without using a precomputed 512-entry inverse-parent lookup table. The remaining embedding, projection, output-translation, and linear-conjugation operations are then applied according to Section 3.
Before timing, both direct implementations were exhaustively verified over all 256 possible inputs against their corresponding reference LUTs. Each measured repetition then consisted of 50 million direct evaluations using the common benchmarking protocol described in Section 5.10, and 30 measured repetitions were performed for each S-box.
The results are given in Table 6. Across 30 measured repetitions, the AES direct-arithmetic implementation required a mean time of 6.753542 s and achieved a mean throughput of 7.449 MB/s, with median values of 6.539015 s and 7.646 MB/s. The proposed direct construction required a mean time of 13.950351 s and achieved a mean throughput of 3.612 MB/s, with median values of 13.457737 s and 3.715 MB/s. The corresponding throughput standard deviations were 0.555 MB/s and 0.295 MB/s, respectively.
Under this specific C implementation and hardware platform, the proposed direct construction requires approximately 2.06 times the execution time of the AES direct-arithmetic implementation. These measurements characterize the evaluated software implementations and platform and are not interpreted as architecture-independent implementation costs.

5.10.3. Hardware-Level Efficiency (FPGA and Standard-Cell Mapping)

The hardware evaluation was performed using direct arithmetic/algebraic HDL descriptions of both the AES S-box and the proposed S-box S * . The AES implementation evaluates inversion in F 2 8 , followed by the AES affine transformation, whereas the proposed implementation directly evaluates the embedding, inverse-parent mapping, quotient projection, output translation, and linear transformations defined in Section 3. No precomputed 256-entry final S-box lookup table is used in either implementation.
For the FPGA evaluation, both designs were synthesized and placed-and-routed under identical conditions using Apio 1.5.1 with the openXC7 toolchain (version 2026.08.20), including Yosys 0.63+173 and nextpnr-xilinx. No physical FPGA board was used; all reported FPGA resource-utilization and timing results were obtained from synthesis and place-and-route reports for the specified target device. The common target was the Xilinx Artix-7 XC7A35T-1CPG236C device, and a 10.000 ns (100 MHz) clock constraint was applied to identical registered timing wrappers surrounding the combinational S-box logic. The wrappers define a common register-to-register timing boundary and are not part of the S-box constructions themselves.
For the standard-cell comparison, the same direct HDL descriptions were mapped using Yosys/ABC to the Nangate Open Cell Library 45 nm typical Liberty model (NangateOpenCellLibrary_typical.lib). Mapped cell area was obtained from the Liberty cell areas. Equivalent gate count was computed by normalizing the mapped area to the area of the NAND2_X1 cell from the same library, whose area is 0.798 library area units. Thus,
GE = mapped cell area area ( NAND 2 _ X 1 ) .
Heterogeneous generic-cell counts are not used as a physical-area metric, because different cell types do not have equal area.
Table 7 shows that, under the common Artix-7 implementation flow, the AES and proposed S-box implementations use the same reported slice-LUT and mapped-multiplexer resources. The proposed implementation has a post-route critical path of approximately 2.63 ns compared with 2.54 ns for AES, corresponding to maximum reported clock frequencies of 379.79 MHz and 393.08 MHz, respectively. Thus, the proposed implementation exhibits approximately 3.4% lower maximum clock frequency under this FPGA flow.
Table 7. Hardware implementation comparison of the AES S-box and proposed S-box.
Under the common Nangate45 standard-cell mapping, the proposed direct HDL implementation yields a mapped cell area of 654.892 library area units (820.67 GE), compared with 2232.006 area units (2797.00 GE) for the direct AES implementation. This corresponds to approximately 70.66% lower mapped cell area for the proposed implementation under the specified HDL descriptions, synthesis flow, and standard-cell library. This result is implementation-flow-specific and should not be interpreted as a universal hardware-area advantage over all possible AES implementations. Complete HDL sources, synthesis and place-and-route commands, constraints, technology-mapping scripts, and generated reports are provided with the Supplementary Materials.

5.11. Summary of Cryptographic Tests and Implementation Feasibility

The cryptographic properties of the selected proposed S-box S * are compared with the AES S-box [22] as well as with schemes proposed in [5,18,36,37]. The selected S * has vectorial nonlinearity 112, maximum differential probability 2 − 6 , maximum linear bias 2 − 4 , no fixed points or opposite fixed points, and a unicursal permutation structure consisting of a single cycle of length 256. It has Boolean algebraic degree 5, univariate interpolation degree 248 with 219 nonzero terms, mean SAC 128.125, DSAC 392, and BIC 0.129412.
Relative to the AES S-box, the selected S * matches its differential uniformity, vectorial nonlinearity, and maximum linear bias but has lower Boolean algebraic degree (5 compared with 7) and higher boomerang uniformity (18 compared with 6). The latter two differences constitute limitations of the selected mapping relative to AES. These quantities characterize properties of the S-box mappings themselves and do not, in isolation, establish resistance of a complete cipher to differential, linear, boomerang, or algebraic cryptanalysis.
Table 4 summarizes results of cryptographic tests performed on the proposed S-box, the AES S-box and other S-box schemes. The implementation results show comparable FPGA resource usage and storage requirements, with higher real-time arithmetic computation cost. The hardware evaluation further provides exact-device post-route timing and technology-mapped standard-cell area measurements under common implementation conditions.
The exact-device FPGA results show equal mapped LUT and multiplexer-resource usage for the AES and proposed implementations, with post-route critical-path delays of approximately 2.54 ns and 2.63 ns, respectively. Under the common Nangate45 standard-cell mapping, the proposed direct HDL implementation has a mapped area of 654.892 library area units (820.67 GE), compared with 2232.006 area units (2797.00 GE) for the direct AES implementation. These implementation results are specific to the stated HDL descriptions, synthesis flows, target device, constraints, and standard-cell library.

6. Conclusions

In this research, an 8 × 8 S-box construction is developed from bijective trims of the compositional inverse of a nine-dimensional quadratic APN permutation, followed by linear-conjugation-based coordinate optimization and output translation. An exhaustive evaluation of 1,566,726 structural parameter combinations ( α , β , b ) yields 3066 bijective trims with differential uniformity 4, vectorial nonlinearity 112, and Boolean algebraic degree 5. The selected S * matches the AES S-box in differential uniformity, vectorial nonlinearity, and maximum linear bias but has lower Boolean algebraic degree (5 versus 7) and higher boomerang uniformity (18 versus 6), which constitute limitations relative to AES. A subsequent randomized linear-conjugation search identifies coordinate-optimized representations, leading to the selected S * . The selected S-box has a full 256-cycle, no fixed or opposite fixed points, and a denser univariate interpolation representation, while the selected S * achieves lower DSAC and BIC values than the canonical AES byte mapping under the adopted evaluation measures. However, the matched one-million-matrix control does not establish an advantage over AES under the same coordinate-optimization search since 22,911 AES conjugates (2.2911%), compared with one conjugate (0.0001%) of the fixed retained trim, satisfy both selected thresholds. These values are interpreted as coordinate-dependent descriptive indicators and are not claimed to demonstrate improved cryptanalytic resistance relative to AES. The direct construction-based software evaluation also shows a substantial performance trade-off: under the tested C implementation and hardware platform, the proposed S * requires approximately 2.06 times the execution time of the AES direct-arithmetic implementation. The direct on-the-fly software implementation therefore involves a performance trade-off on the tested platform; this observation is implementation-specific and should not be generalized to precomputed LUT implementations or other implementation architectures.

Supplementary Materials

The following supporting information can be downloaded at https://www.mdpi.com/article/10.3390/cryptography10050072/s1. The package contains the source code, configuration files, retained parameter triples, sampled-matrix and intermediate search results, CCZ-equivalence material, cryptographic and algebraic evaluation scripts and outputs, machine-readable versions of the reported tables, software-benchmark source code and raw measurements, direct HDL implementations, FPGA and standard-cell mapping material, random seeds, representation conventions, software requirements, and the available computational-environment records.

Author Contributions

Conceptualization, R.S. and A.G.; methodology, R.S.; software, R.S.; validation, R.S., A.G. and M.K.; formal analysis, R.S., A.G., M.K. and A.K.; investigation, R.S.; resources, A.G. and M.T.A.; data curation, R.S.; writing—original draft preparation, R.S.; writing—review and editing, A.G., M.K., A.K. and M.T.A.; visualization, R.S. and M.T.A.; supervision, A.G. and M.T.A.; project administration, M.K. All authors have read and agreed to the published version of the manuscript.

Funding

This research received no external funding.

Data Availability Statement

The original contributions presented in this study are included in the article/Supplementary Materials. Further inquiries can be directed to the corresponding author.

Acknowledgments

The authors would like to acknowledge the support and contributions of colleagues and collaborators during the development of this work.

Conflicts of Interest

The authors declare no conflicts of interest.

Abbreviations

The following abbreviations are used in this manuscript:
AESAdvanced Encryption Standard
APNAlmost Perfect Nonlinear
BCTBoomerang Connectivity Table
BICBit Independence Criterion
BUBoomerang Uniformity
CCZCarlet–Charpin–Zinoviev
CPUCentral Processing Unit
DESData Encryption Standard
DPDifferential Probability
DSACDistance to Strict Avalanche Criterion
EAExtended Affine
FIPSFederal Information Processing Standard
FPGAField-Programmable Gate Array
GEGate Equivalent
HDLHardware Description Language
IBMInternational Business Machines
LPLinear Probability
LSBLeast Significant Bit
LUTLookup Table
MQMultivariate Quadratic
NISTNational Institute of Standards and Technology
NSANational Security Agency
RAMRandom-Access Memory
SACStrict Avalanche Criterion
S-boxSubstitution Box
XORExclusive OR

References

  1. Tian, Y.; Lu, Z. S-box: Six-dimensional compound hyperchaotic map and artificial bee colony algorithm. J. Syst. Eng. Electron. 2016, 27, 232–241. Available online: https://ieeexplore.ieee.org/document/7424939/ (accessed on 15 September 2026).
  2. Alhadawi, H.S.; Majid, M.A.; Lambić, D.; Ahmad, M. A novel method of S-box design based on discrete chaotic maps and cuckoo search algorithm. Multimed. Tools Appl. 2021, 80, 7333–7350. [Google Scholar] [CrossRef] [Scilit]
  3. Farah, M.B.; Farah, A.; Farah, T. An image encryption scheme based on a new hybrid chaotic map and optimized substitution box. Nonlinear Dyn. 2020, 99, 3041–3064. [Google Scholar] [CrossRef] [Scilit]
  4. Msolli, A.; Hagui, I.; Helali, A. Dynamic S-boxes generation for IoT security enhancement: A genetic algorithm approach. Ain Shams Eng. J. 2024, 15, 103049. [Google Scholar] [CrossRef] [Scilit]
  5. Artuğer, F.; Özkaynak, F. SBOX-CGA: Substitution box generator based on chaos and genetic algorithm. Neural Comput. Appl. 2022, 34, 20203–20211. [Google Scholar] [CrossRef] [Scilit]
  6. Kuznetsov, O.; Poluyanenko, N.; Frontoni, E.; Arnesano, M.; Smirnov, O. Evolutionary approach to S-box generation: Optimizing nonlinear substitutions in symmetric ciphers. arXiv 2024, arXiv:2407.03510. [Google Scholar] [CrossRef] [Scilit]
  7. Hussain, I. True-chaotic substitution box based on Boolean functions. Eur. Phys. J. Plus 2020, 135, 663. [Google Scholar] [CrossRef] [Scilit]
  8. Luo, C.; Wang, Y.; Fu, Y.; Zhou, P.; Wang, M. Constructing dynamic S-boxes based on chaos and irreducible polynomials for image encryption. Nonlinear Dyn. 2024, 112, 6695–6713. [Google Scholar] [CrossRef] [Scilit]
  9. Ullah, S.; Liu, X.; Waheed, A.; Zhang, S. An efficient construction of S-box based on the fractional-order Rabinovich–Fabrikant chaotic system. Integration 2024, 94, 102099. [Google Scholar] [CrossRef] [Scilit]
  10. Özkaynak, F.; Yavuz, S. Designing chaotic S-boxes based on time-delay chaotic system. Nonlinear Dyn. 2013, 74, 551–557. [Google Scholar] [CrossRef] [Scilit]
  11. Malik, M.S.M.; Ali, M.A.; Khan, M.A.; Ehatisham-Ul-Haq, M.; Shah, S.N.M.; Rehman, M.; Ahmad, W. Generation of highly nonlinear and dynamic AES substitution-boxes (S-boxes) using chaos-based rotational matrices. IEEE Access 2020, 8, 35682–35695. [Google Scholar] [CrossRef] [Scilit]
  12. Alamsyah; Setiawan, A.; Putra, A.T.; Budiman, K.; Muslim, M.A.; Salahudin, S.N.; Prasetiyo, B. AES S-box modification uses affine matrices exploration for increased S-box strength. Nonlinear Dyn. 2025, 113, 3869–3890. [Google Scholar] [CrossRef] [Scilit]
  13. Al-Dweik, A.Y.; Hussain, I.; Saleh, M.; Mustafa, M.T. A novel method to generate key-dependent S-boxes with identical algebraic properties. J. Inf. Secur. Appl. 2022, 64, 103065. [Google Scholar] [CrossRef] [Scilit]
  14. Ibrahim, S.; Abbas, A.M. Efficient key-dependent dynamic S-boxes based on permutated elliptic curves. Inf. Sci. 2021, 558, 246–264. [Google Scholar] [CrossRef] [Scilit]
  15. Hoseini, R.; Behnia, S.; Sarmady, S.; Fathizadeh, S. Construction of dynamical S-boxes based on piecewise map: Image encryption approach. Res. Sq. 2022; preprint. [CrossRef] [Scilit] [PubMed]
  16. Farwa, S.; Shah, T.; Idrees, L. A highly nonlinear S-box based on a fractional linear transformation. SpringerPlus 2016, 5, 1658. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  17. Chew, L.C.N.; Ismail, E.S. S-box construction based on linear fractional transformation and permutation function. Symmetry 2020, 12, 826. [Google Scholar] [CrossRef] [Scilit]
  18. Nitaj, A.; Susilo, W.; Tonien, J. Enhanced S-boxes for the Advanced Encryption Standard with maximal periodicity and better avalanche property. Comput. Stand. Interfaces 2024, 87, 103769. [Google Scholar] [CrossRef] [Scilit]
  19. Schneier, B.; Kelsey, J.; Whiting, D.; Wagner, D.; Hall, C.; Ferguson, N. Twofish: A 128-Bit Block Cipher. NIST AES Candidate Submission. 1998. Available online: https://www.schneier.com/academic/twofish/ (accessed on 15 September 2026).
  20. Biham, E.; Anderson, R.; Knudsen, L. Serpent: A new block cipher proposal. In Proceedings of the 5th International Workshop on Fast Software Encryption (FSE’98), Paris, France, 23–25 March 1998; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1998; Volume 1372, pp. 222–238. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  21. National Institute of Standards and Technology (NIST). Data Encryption Standard (DES). In Federal Information Processing Standards Publication 46-3; National Institute of Standards and Technology: Gaithersburg, MD, USA, 1999. Available online: https://csrc.nist.gov/pubs/fips/46-3/final (accessed on 15 September 2026).
  22. Daemen, J.; Rijmen, V. The Design of Rijndael: AES—The Advanced Encryption Standard; Springer: Berlin/Heidelberg, Germany, 2002. [Google Scholar] [CrossRef] [Scilit]
  23. National Institute of Standards and Technology (NIST). Announcing the Advanced Encryption Standard (AES). In Federal Information Processing Standards Publication 197; National Institute of Standards and Technology: Gaithersburg, MD, USA, 2001. [Google Scholar] [CrossRef] [Scilit]
  24. Nitaj, A.; Susilo, W.; Tonien, J. A new improved AES S-box with enhanced properties. In Proceedings of the 25th Australasian Conference on Information Security and Privacy (ACISP 2020), Perth, WA, Australia, 30 November–2 December 2020; Lecture Notes in Computer Science; Springer: Cham, Switzerland, 2020; Volume 12248, pp. 125–141. [Google Scholar] [CrossRef] [Scilit]
  25. Cui, J.; Huang, L.; Zhong, H.; Chang, C.C.; Yang, W. An improved AES S-box and its performance analysis. Int. J. Innov. Comput. Inf. Control 2011, 7, 2291–2302. [Google Scholar]
  26. Sakallı, M.T.; Aslan, B.; Buluş, E.; Mesut, A.Ş.; Büyüksaraçoğlu, F.; Karaahmetoğlu, O. On the algebraic expression of the AES S-box like S-boxes. In Proceedings of the 2nd International Conference on Networked Digital Technologies (NDT 2010), Prague, Czech Republic, 7–9 July 2010; Communications in Computer and Information Science; Springer: Berlin/Heidelberg, Germany, 2010; Volume 87, pp. 213–227. [Google Scholar] [CrossRef] [Scilit]
  27. Beierle, C.; Carlet, C.; Leander, G.; Perrin, L. A further study of quadratic APN permutations in dimension nine. Finite Fields Appl. 2022, 81, 102049. [Google Scholar] [CrossRef] [Scilit]
  28. Beierle, C.; Leander, G.; Perrin, L. Trims and extensions of quadratic APN functions. Des. Codes Cryptogr. 2022, 90, 1009–1036. [Google Scholar] [CrossRef] [Scilit]
  29. Waheed, A.; Subhan, F.; Suud, M.M.; Alam, M.; Ahmad, S. An analytical review of current S-box design methodologies, performance evaluation criteria, and major challenges. Multimed. Tools Appl. 2023, 82, 29689–29712. [Google Scholar] [CrossRef] [Scilit]
  30. Biham, E.; Shamir, A. Differential cryptanalysis of DES-like cryptosystems. J. Cryptol. 1991, 4, 3–72. [Google Scholar] [CrossRef] [Scilit]
  31. Matsui, M. Linear cryptanalysis method for DES cipher. In Proceedings of the Advances in Cryptology—EUROCRYPT ’93, Lofthus, Norway, 23–27 May 1993; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1994; Volume 765, pp. 386–397. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  32. Heys, H.M. A tutorial on linear and differential cryptanalysis. Cryptologia 2002, 26, 189–221. [Google Scholar] [CrossRef] [Scilit]
  33. Nyberg, K. Perfect nonlinear S-boxes. In Proceedings of the Advances in Cryptology—EUROCRYPT ’91, Brighton, UK, 8–11 April 1991; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1991; Volume 547, pp. 378–386. [Google Scholar] [CrossRef] [Scilit] [PubMed]
  34. Budaghyan, L.; Carlet, C.; Leander, G. Constructing new APN functions from known ones. Finite Fields Appl. 2009, 15, 150–159. [Google Scholar] [CrossRef] [Scilit]
  35. Carlet, C.; Charpin, P.; Zinoviev, V. Codes, bent functions and permutations suitable for DES-like cryptosystems. Des. Codes Cryptogr. 1998, 15, 125–156. [Google Scholar] [CrossRef] [Scilit]
  36. Artuğer, F. Strong S-box construction approach based on Josephus problem. Soft Comput. 2024, 28, 10201–10213. [Google Scholar] [CrossRef] [Scilit]
  37. Bilal, M.; Murtaza, G.; Demir, B.; Bustamante, M.D.; Hayat, U. An efficient algorithm to generate dynamic substitution-boxes and its applications in image encryption. Alex. Eng. J. 2025, 116, 214–231. [Google Scholar] [CrossRef] [Scilit]
  38. Carlet, C. Two generalizations of almost perfect nonlinearity. J. Cryptol. 2025, 38, 20. [Google Scholar] [CrossRef] [Scilit]
  39. Boura, C.; Canteaut, A. On the boomerang uniformity of cryptographic S-boxes. IACR Trans. Symmetric Cryptol. 2018, 2018, 290–310. [Google Scholar] [CrossRef]
  40. Carlet, C. Boolean functions for cryptography and error correcting codes. In Boolean Models and Methods in Mathematics, Computer Science, and Engineering; Crama, Y., Hammer, P.L., Eds.; Cambridge University Press: Cambridge, UK, 2010; pp. 257–397. [Google Scholar] [CrossRef] [Scilit]
  41. Bucholc, K. An approach to evaluation of S-boxes. Prz. Elektrotech. 2017, 93, 82–86. [Google Scholar] [CrossRef] [Scilit]
  42. Jakobsen, T.; Knudsen, L.R. The interpolation attack on block ciphers. In Proceedings of the 4th International Workshop on Fast Software Encryption (FSE’97), Haifa, Israel, 20–22 January 1997; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1997; Volume 1267, pp. 28–40. [Google Scholar] [CrossRef] [Scilit]
  43. Arabnezhad, H.; Sadeghiyan, B. Parameters of Algebraic Representation vs. Efficiency of Algebraic Cryptanalysis. Cryptology ePrint Archive, Paper 2024/1133. 2024. Available online: https://eprint.iacr.org/2024/1133 (accessed on 15 September 2026).
  44. Webster, A.F.; Tavares, S.E. On the design of S-boxes. In Proceedings of the Advances in Cryptology—CRYPTO ’85, Santa Barbara, CA, USA, 18–22 August 1985; Lecture Notes in Computer Science; Springer: Berlin/Heidelberg, Germany, 1986; Volume 218, pp. 523–534. [Google Scholar] [CrossRef] [Scilit] [PubMed]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Article Metrics

Citations

Article Access Statistics

Multiple requests from the same IP address are counted as one view.