
Ciphers built on bitwise AND, XOR, and rotation are highly competitive for resource‑constrained Internet of Things devices. A representative example is the SIMON family of lightweight block ciphers, introduced by the U.S. National Security Agency in 2013. Differential‑linear (DL) cryptanalysis of such ciphers comprises two central tasks: identifying promising DL distinguishers and evaluating their correlations. Recent notable works, including the Differential‑Linear Connectivity Table (DLCT), the Differential Algebraic Transitional Form (DATF), and new evaluation methods from boomerang and truncated differential perspectives, have made significant progress in correlation evaluation. Beyond correlation evaluation, efficiently finding long DL distinguishers with high correlation remains a crucial challenge, particularly for AndRX ciphers. To address this, we propose a two‑step solver‑aided strategy. The first step employs an automated solver to generate a large pool of DL distinguisher candidates by concatenating truncated differentials with linear approximations. In this step, we derive a rigorous probability formula for SIMON‑like round functions to enable fast correlation estimation. To the best of our knowledge, this is the first formula for computing truncated differential probabilities of such round functions. The second step re‑evaluates the DL correlations using the DLCT technique to ensure accuracy and mitigate clustering effects. Applied to all variants of SIMON and SIMECK, our method yields the longest DL distinguishers reported to date: 14, 17, 21, 29, and 37 rounds for SIMON‑32/48/64/96/128, respectively, and 14, 21, and 26 rounds for SIMECK‑32/48/64, respectively.
Abstract We construct $$\mathbb {Z}_p$$ Z p -lattices and $$\mathbb {F}_q[\![t]\!]$$ F q [ [ t ] ] -lattices from cyclic $$(f,\sigma )$$ ( f , σ ) -codes over finite chain rings, employing quotients of natural nonassociative orders and principal left ideals in carefully chosen and not necessarily associative algebras. This approach generalizes the classical Construction A that obtains $$\mathbb {Z}$$ Z -lattices from linear codes over finite fields or commutative rings to the nonassociative setting. We mostly use (associative or nonassociative) cyclic algebras that are defined over field extensions of p -adic fields. This means we focus on certain skew constacyclic codes over finite rings to obtain $$\mathbb {Z}_p$$ Z p -lattices, hence $$\mathbb {Z}_p$$ Z p -lattice codes. We construct linear maximum rank distance (MRD) codes that are $$\mathbb {Z}_p$$ Z p -lattice codes employing the left multiplication of a nonassociative algebra over a finite chain ring. Possible other applications of our constructions include cryptography involving p -adic lattices, e.g. learning with errors.
In this paper, we address two problems that could not be solved until now. First, we determine, with explicit proofs, the weight spectra of the generalized Reed–Muller codes RM_q((m-2)(q-1)+3,m) for q=5 and m≥ 2 , and we almost determine it exactly for q=7 and m≥ 2 . Second, we determine with a mathematical proof, that for every m≥ 2 and q≥ 4 , the fourth weight of RM_q((m-2)(q-1)+3,m) equals one among the two possible values q^2-2q-2 and q^2-2q-1 , and computer investigations lead us to conjecture that it equals the maximum of these two values.
A perfect code C in a graph Γ is an independent set of vertices such that every vertex not in C is adjacent to exactly one vertex in C. A subgroup perfect code of a group G is a subgroup that forms a perfect code in some Cayley graph of G. An N-group is defined as a group in which all local subgroups are solvable. As an initial effort toward a systematic classification of perfect codes across all subgroups of a simple group, this paper concentrates on simple N-groups and provides a complete determination of their subgroup perfect codes. The method of this paper primarily relies on resolving the construction of subgroup perfect codes by reducing them to structures within the field.
Duadic codes are an interesting subclass of cyclic codes since they have large dimensions and their minimum distances may have a square-root lower bound. The objective of this paper is to construct several families of q^2 -ary duadic codes of dimension near n/2 with good lower bounds on their minimum distances. In this paper, we propose a construction for q^2 -ary duadic codes whose splitting is given by μ _-q . Using this construction, we obtain four infinite families of q^2 -ary duadic codes with lower bounds on their minimum distances exceeding the square-root lower bound. As byproducts, we derive several families of Hermitian self-dual codes and Hermitian self-orthogonal cyclic codes with lower bounds on their minimum distances also exceeding the square-root lower bound. These codes include distance-optimal codes and codes with the best known parameters.
Generalized Hamming weights are fundamental invariants of linear codes that provide a refined description of the support structure of subcodes. While the weight hierarchies of Maximum Distance Separable (MDS) codes and Near-MDS (NMDS) codes are well investigated, much less is known about Almost-MDS (AMDS) codes that are not NMDS. In this paper, we prove that an [n, k] linear code is AMDS but not NMDS if and only if its first two generalized Hamming weights are n-k and n-k+1 , respectively. By introducing the concept of s-gap AMDS codes, we obtain that the unique missing entry in the AMDS hierarchy is n-k+s , 2≤ s≤ k . Moreover, we apply this framework to twisted Reed-Solomon codes, transforming the construction of s-gap AMDS codes into a problem of counting roots of specific polynomials over finite fields. Based on this transformation, we establish explicit construction criteria for three families of s-gap AMDS codes, along with several concrete illustrative examples.
Most existing fully homomorphic encryption (FHE) security models cannot resist attacks from a malicious server that can arbitrarily replace the ciphertexts and evaluation functions used during homomorphic evaluation and obtain the decryption results of the evaluated ciphertexts. To address this security issue of FHE caused by the breakdown of computational integrity, we proposed two new primitives, called tagged-FHE and tagged^* -FHE with corresponding security notions IND-TAG-CCA and IND- TAG^* -CCA. Unlike the verifiable FHE, which also focuses on preserving computational integrity, the new primitives and security concepts still require the compactness of ciphertexts. The size of the output of the evaluation algorithm must be independent of the complexity of the function during evaluation. Tagged-FHE enables users to detect whether a server has replaced the input ciphertexts of evaluation. While tagged^* -FHE additionally enables users to detect whether a server has replaced the evaluation function. We present generic constructions for these two primitives with corresponding security notions. The IND-TAG-CCA tagged-FHE is achievable in the standard model using IND-CPA multi-key FHE and IND-CCA2 public-key encryption. The IND- TAG^* -CCA tagged^* -FHE additionally uses NIZK and SNARG and requires a heuristic assumption related to hash function collision resistance. These notions provide enhanced protection for FHE in the presence of malicious third-party servers.
We present constructions of small 2n-covers of the hyperbolic quadric Q^+ (4n+1,q) . We also present a lower bound on the size of a 2n-cover of Q^+ (4n+1,q) .
Abstract We construct a family of cyclic completely regular codes (CRCs) of length $$n=2^m-1$$ n = 2 m - 1 and compute their intersection arrays. These codes, denoted $$C_{1,5}$$ C 1 , 5 , are generated by the product $$m_1(x)m_5(x)$$ m 1 ( x ) m 5 ( x ) , where $$m_i(x)$$ m i ( x ) is the minimal polynomial of $$\alpha ^i$$ α i , and $$\alpha $$ α is a primitive element of the finite field $$\mathbb {F}_{2^m}$$ F 2 m . We consider two main cases: odd m and $$m \equiv 2 \pmod {4}$$ m ≡ 2 ( mod 4 ) . For odd m , these codes are known to be completely regular with covering radius $$\rho =3$$ ρ = 3 and minimum distance $$d=5$$ d = 5 . We prove that, for any m , the codes $$C_{1,3}$$ C 1 , 3 and $$C_{1,5}$$ C 1 , 5 are non-equivalent despite sharing the same parameters and intersection array. For $$m \equiv 2 \pmod {4}$$ m ≡ 2 ( mod 4 ) , we demonstrate that $$C_{1,5}$$ C 1 , 5 forms a new family of completely regular codes with covering radius $$\rho =3$$ ρ = 3 , minimum distance $$d=3$$ d = 3 , and intersection array $$\operatorname {IA}=[n, n-3, \frac{3n+7}{4}; 1, 4, \frac{n-3}{4}]$$ IA = [ n , n - 3 , 3 n + 7 4 ; 1 , 4 , n - 3 4 ] . Moreover, the corresponding extended cyclic codes $$C_{1,5}^*$$ C 1 , 5 ∗ are completely regular $$[n+1, n-2m, 4; 4]$$ [ n + 1 , n - 2 m , 4 ; 4 ] -codes with intersection array $$\operatorname {IA}=[n+1, n, n-3, \frac{3n+7}{4}; 1, 4, \frac{n-3}{4}, n+1]$$ IA = [ n + 1 , n , n - 3 , 3 n + 7 4 ; 1 , 4 , n - 3 4 , n + 1 ] . We also describe the parameters and some properties of the coset graphs associated to these completely regular codes which form distance-regular graphs.
We first find an explicit criterion for a p-ary function to produce a symmetric association scheme. As the next step, we proceed to apply this criterion to the p-ary plateaued functions of ℓ -form. We thus obtain a necessary and sufficient condition for the p-ary plateaued functions of ℓ -form to yield symmetric association schemes; in fact, this condition is that f is weakly regular partially bent. For the proof of our main results, we use the equivalent characterizations for the gcd-condition of p-ary plateaued functions of ℓ -form (including non-weakly regular bent functions). Using this characterization, we also find some sufficient conditions for p-ary plateaued functions of ℓ -form to satisfy the gcd-condition. In particular, we show that the gcd-condition holds for any non-weakly regular bent function of ℓ -form. We further provide explicit constructions for two families of 3-class and 4-class association schemes using our main results.
Let (G,+) be a finite group, and let W be a set of integers greater than 1. A (G, W, 1)-difference packing is a family of subsets of G, each of size from W, whose list of differences covers every element of G at most once. Such a packing is balanced if it contains the same number of blocks of size w for each w∈ W . In this paper, we focus on constructing optimal balanced (ℤ_m×ℤ_n,{4,5},1) -difference packings for all even integers m, n satisfying mn≡ 032 . As an application, we establish the corresponding family of optimal balanced (m,n,{4,5},1) -optical orthogonal signature pattern codes. A new recursive construction based on balanced {m,n} -cyclic group divisible designs plays a key role.
Let 𝒮 be a finite thick generalized quadrangle, and let G≤Aut(𝒮) act primitively on both points and lines. Building on the almost simple reduction for point-primitive and line-primitive actions, we study the case where the socle of G is the projective symplectic group PSp_4(q) with q≥ 3 . We show that, up to duality, either 𝒮≅ W(3,q) for q≥ 3 , or q=3 and 𝒮≅ H(3,4) .
Using methods from the theory of algebraic curves over finite fields, together with recent results on the arithmetic of cubic equations over finite fields, we obtain new upper bounds on the second generalized covering radius of binary primitive triple-error-correcting BCH codes. In particular we introduce the notion of weak second generalized covering radius R^(0)_2(BCH(3,m)) , where BCH(3, m) is the binary primitive triple-error-correcting code of length 2^m-1 . This accounts almost all 2-dimensional 𝔽_2 -linear subspaces of 𝔽^n-3m_2 . Among other results, we show that R^(0)_2(BCH(3,m)) ≤ 9 if m is odd and m ≥ 11 (and if m is even and m ≥ 20 ).
Rotation symmetric Boolean functions (RSBFs) have received considerable attention for their excellent cryptographic properties and efficient implementation. These functions have been extensively studied in relation to bentness, correlation immunity, and nonlinearity. While numerous constructions exist for balanced odd-variable RSBFs with optimal algebraic immunity, developing balanced even-variable RSBFs with optimal algebraic immunity remains a significant and largely unresolved challenge. In this paper, we present a novel construction of balanced 2^k -variable RSBFs with optimal algebraic immunity (k≥ 4) using integer compositions. The constructed functions obtain a nonlinearity superior to previous construction methods, and their algebraic degree can be maximized under certain conditions.
In this paper, we completely determine the dimension of Hermitian hulls of Reed–Solomon codes for lengths n equal to the cardinality of the underlying finite field 𝔽_q^2 or to k+1 , where k is the dimension of the Reed–Solomon code, by explicitly constructing a basis. We also determine, in some cases, whether Hermitian hulls of Reed–Solomon codes are generalized Reed–Solomon (GRS) codes. Consequently, we apply our results to construct MDS entanglement-assisted quantum error-correcting codes (EAQECCs).
In this paper, we first generalize the LCP of codes over finite fields to the 𝔽_2𝔽_4 -additive complementary pair ( 𝔽_2𝔽_4 -ACP) of codes over the mixed alphabet 𝔽_2𝔽_4 . Then we provide three judging criteria for an 𝔽_2𝔽_4 -additive code pair (C, D) to be an 𝔽_2𝔽_4 -ACP of codes. Meanwhile, we also give a sufficient condition for an 𝔽_2𝔽_4 -additive code pair (C, D) to be an 𝔽_2𝔽_4 -ACP of codes. In addition, we exhibit properties and characterizations for an 𝔽_2𝔽_4 -additive code pair (C, D) to be an 𝔽_4 -additive complementary pair ( 𝔽_4 -ACP) of codes. Finally, we provide an interesting application of an 𝔽_2𝔽_4 -ACP of codes in coding for the two-user binary adder channel.
Receiver selective opening (RSO) security considers the security of encryption schemes under the scenario of a single sender and multiple receivers, where an adversary is allowed to adaptively corrupt some receivers’ secret keys. RSO security has been proven to be more secure than indistinguishability-based security notions. A lot of research has focused on RSO security in terms of public-key encryption and identity-based encryption (IBE); however, hierarchical IBE (HIBE), which is a generalization of IBE, is still lacking in the study, and how to obtain such a construction remains an open problem. To address this gap, we initiate a study of RSO security on HIBE in this work. Precisely, we first formalize the definition of simulation-based RSO against identity-chosen-plaintext/ciphertext attacks in the k-challenge setting (SIM-ID-RSO _k -CPA/CCA) for HIBE. We then present generic SIM-ID-RSO _k -CCA secure HIBE constructions by introducing the double secret key paradigm. Specifically, we show that a SIM-ID-RSO _k -CCA secure HIBE scheme can be obtained from an IND-ID-CPA secure HIBE scheme as well as a one-time signature scheme that satisfies strong unforgeability. Through our general construction, we can derive various concrete schemes based on different hard assumptions (e.g., lattice-based and pairing-based SIM-ID-RSO _k -CCA secure HIBE schemes) according to usage requirements.