Journal of South China University of Technology (Natural Science Edition) ›› 2008, Vol. 36 ›› Issue (8): 140-144.

• Mathematics • Previous Articles    

Quadratic Equations on S-Boxes and a New S-Box Design Criterion

Zhang Guo-ji Xiao Huang-pei2   

  1. 1. School of Mathematical Sciences, South China University of Technology, Guangzhou 510640, Guangdong, China; 2. School of Computer Science and Engineering, South China University of Technology, Guangzhou 510640, Guangdong, China
  • Received:2007-08-30 Revised:2007-10-19 Online:2008-08-25 Published:2008-08-25
  • Contact: 张国基(1953-),男,教授,博士生导师,主要从事人工智能、密码学及信息安全研究. E-mail:magjzh@scut.edu.cn
  • About author:张国基(1953-),男,教授,博士生导师,主要从事人工智能、密码学及信息安全研究.

Abstract:

As the only nonlinear component in most block ciphers, S-box is responsible for the security of block ciphers. In this paper, the existence of the quadratic equations on S-boxes is theoretically analyzed, and 55 linearly independent quadratic equations on the S-box of the Advanced Encryption Standard (AES) are proved existent in the GF(28) region. All these equations are then given in the paper. Moreover, in order to avoid the algebraic attacks using these equations, such as the eXtended Sparse Linearization (XSL) attack, a new S-box design criterion is presented. In the new S-box there exists no quadratic equation that may be used for algebraic attacks.

Key words: cryptography, Advanced Encryption Standard, S-box, quadratic equation