A finite nonlinear automaton for a one-key blockcipher cryptosystem is presented. The key defines the automaton. The mapping from the “keyspace” to the “automaton-space” is one to one. Similar to other cryptosystems, encryption and decryption is done by repeating a number of simple steps called “rounds”. The number of rounds and the blocksize can be variable and does not depend on the key. The statistical properties measured on the ciphertext are satisfactory and in the same range as the properties of DES (Data Encryption Standard).
We show how to construct infinite families of sequences that have one and two valued autocorrelation and two valued crosscorrelation function. These sequences are obtained via the discrete Fourier transform of integer sequences. The sequences obtained can be complex valued or having entries E {O, 1, ... , p}, p prime, depending on the construction used.
Given an RSA modulus n, a ciphertext c and the encryption exponent e, one can construct the sequence x0 = c mod n, xi+1 = xie mod n; i = 0, 1,... until gcd(xi+1 - x0, n) ≠ 1 or i or i B, B a given boundary. If i ≤ B, there are two cases. Case 1: gcd(xi+1 -x0, n) = n. In this case xi = m and the secret message m can be recovered. Case 2: 1 ≠ gcd(xi+1 - x0; n) ≠ n. In this case, the RSA modulus n can be factorised. If i ≤ B, then Case 2 is much more likely to occur than Case 1. This attack is called a cycling attack. We introduce some new generalised cycling attacks. These attacks work without the knowledge of e and c. Therefore, these attacks can be used as factorisation algorithms. We also translate these attacks to elliptic curves. For this case we call these attacks EC generalised cycling attacks. Finally, we review criteria that a strong RSA prime must satisfy.
We introduce Legendre sequences and generalised Legendre pairs (G L pairs). We show how to construct an Hadamard matrix of order 2£ + 2 from a GL-pair of length f. We review the known constructions for GL pairs and use the discrete Fourier transform (DFT) and power spectral density (PSD) to enable an exhaustive search for GL-pairs for lengths f ::::; 47 and partial searches for other f,
Let A = {ao, ... , ae-d, B = {bO, ••• , be-d be two finite sequences of length £. Their nonperiodic autocorrelation function N A,B (s) is defined as: £-1-8 £-1-8 NA,B(S) = L aiai+s + L bibi+s' S = 0, ... , £ 1, i=O i=O where x* is the complex conjugate of x. If NA,B(S) = ° for S = 1, ... , £-1 then A, B is called a complementary pair. If, furthermore, ai, bi E {-I, I}, i = 0, ... , £-1, or, ai, bi E {-I, 0, I}, i = 0, ... , £-1, then A, B is called a binary complementary pair (BCP), or, a ternary complementary pair (TCP), respectively. A BCP is also called a Golay sequence. A TCP is a generalisation of a BCP. Since Golay sequences are only known to exist for lengths n = 2a lOb26c , a, b, c ~ 0, recent papers have focused on TCP's. The purpose of this paper is to give an overview of existing constructions and techniques and present a variety of new constructions, new restrictions on the deficiencies and new computational results for TCP's. In particular: • We give many new constructions which concatenate shorter groups of sequences to obtain longer sequences. Many of these constructions can be applied recursively and lead to infinite families of TCP's . • We give many new restrictions on TCP's of lengths £ and deficiencies 8 = 2x, where x == £ mod 4. * This research was carried out while the first author was at the University of Wollongong. Australasian Journal of Combinatorics 23(2001), pp.153-170 • We settle all the cases for existence/non-existence of TCP's of lengths R ::; 20 and weights w ::; 40 . • We give TCP's with minimum deficiencies for all lengths R:::; 22.
The security of ordinary digital signature schemes relies on a computational assumption. Fail-stop signature schemes provide security for a sender against a forger with unlimited computational power by enabling the sender to provide a proof of forgery if it occurs. In this paper we give an efficient fail-stop signature scheme that uses two hard problems, discrete logarithm and factorization, as the basis of a receiver's security. We show that the scheme has provable security against adaptively chosen message attack, and is the most efficient scheme with respect to the ratio of the message length to the signature length. The scheme provides an efficient solution to signing messages up to 1881 bits.
We discuss difference sets (DS) and supplementary difference sets (SDS) over rings. We survey some constructions of SDS over Galois rings where there are no short orbits. ,From there we move to constructions which involve short orbits. These give rise to new infinite families of SDS over GF(p) x GF(q), p, q both prime powers. Many of these families have λ = 1. We also show some new balanced incomplete block designs and pairwise balanced designs arising from the constructions given here. Disciplines Physical Sciences and Mathematics Publication Details This article was original published as Gysin, M and Seberry, J, On New Families of Supplementary Difference Sets over Rings with Short Orbits, Journal of Combinatorial Mathematics and Combinatorial Computing, 28, 1998, 161-186. This journal article is available at Research Online: http://ro.uow.edu.au/infopapers/346 On New Families of Supplementary Di erence Sets over Rings with Short Orbits Marc Gysin and Jennifer Seberry Centre for Computer Security Research, Department of Computer Science, The University of Wollongong, Wollongong, NSW 2500, Australia Dedicated to Professor Anne Penfold Street Abstract We discuss di erence sets (DS) and supplementary di erence sets (SDS) over rings. We survey some constructions of SDS over Galois rings where there are no short orbits. >From there we move to constructions which involve short orbits. These give rise to new in nite families of SDS over GF (p) GF (q), p, q both prime powers. Many of these families have = 1. We also show some new balanced incomplete block designs and pairwise balanced designs arising from the constructions given here.
We discuss difference sets (DS) and supplementary difference sets(SDS) over rings. We survey some constructions of SDS over Galoisrings where there are no short orbits. From there we move to constructionswhich involve short orbits. These give rise to new infinitefamilies of SDS over GF (p) \Theta GF (q), p, q both prime powers. Manyof these families have = 1.We also show some new balanced incomplete block designs andpairwise balanced designs arising from the constructions given here.1...
Let n be an RSA modulus, that is, n = pq, where p, q are two large primes. We deene the discrete logarithm problem for Lucas sequences and show that solving the discrete logarithm problem for Lucas sequences modulo n gives a polynomial factorisation algorithm. Let d = jq?pj. We calculate m and Vd(m; 1) mod n in polynomial time and then solve for d in O(~ d 1 2 +) time where ~ d is an upper estimate for d such that ~ d d. Hence, we have found a factorisation algorithm that uses Lucas sequences and factorises n in O(~ d 1 2 +) time. This algorithm induces a new class of weak RSA moduli.
We give an overview on the existence of 4-NPAF (1,2w) sequences. We sketch some construction methods which give new 4-NPAF(1,2w) sequences and new orthogonal designs OD(4n;1,2w).
D-optimal designs are n x n ±l-matrices where n == 2 mod 4 with maximum determinant. D-optimal designs obtained via circulant matrices are equivalent to 2-{ v; kl i k2 i k1 + k2 ~(v 1)} supplementary difference sets, where v = ~. We use cyclotomy to construct D-optimal designs, where v is a prime. We give a generalisation of cyclotomy and extend the cyclotomic techniques which enables use to find new D-optimal designs for composite numbers. In particular, we found, via computer-search, D-optimal designs for v = ~ = 7,13,19,21,31,33,37,41,43,61,73,85,91,93,113. The case v 85 = 5 x 17 is completely new. That is, D-optimal designs of order n 2v = 2 x 85 are given here for the first time.
We present a computer-search method for concatenating or "multiplying" binary or ternary complementary pairs. All multiplications by a particular number m are considered. The computer-search method is new and leads to a large set of new results. The results and equivalences are discussed and some applications and numerical consequences are shown. Disciplines Physical Sciences and Mathematics Publication Details Gysin M and Seberry J, Multiplication of ternary complementary pairs, Australasian Journal of Combinatorics, 14 (1996), 165-180. This journal article is available at Research Online: http://ro.uow.edu.au/infopapers/1129 Multiplications of Ternary Complementary Pairs Marc Gysin and Jenniff'l' Seberry Centre for Computer Security Research, Department of Computer Science, The University of Wollongong, Wollongong, NSW 2500 Australia Abstract We present a computer-search method for concatenating or "multiplying" binary or ternary complementary pairs. All multiplications by a particular number m are considered. The computer-search method is new and leads to a large set of new results. The results and equivalences are discussed and some applications and numerical consequences are shown.We present a computer-search method for concatenating or "multiplying" binary or ternary complementary pairs. All multiplications by a particular number m are considered. The computer-search method is new and leads to a large set of new results. The results and equivalences are discussed and some applications and numerical consequences are shown.
An introduction to binary sequences, combi natorial designs and how they are related to communication theory and computer security is given. An exhaustive search algorithm for normal sequences is presented. This is the first time that the lengths n = 24 and n = 25 have been searched through completely. No sequences of length 24 are found. It turns out that all the normal sequences of length 25 can be derived from Turyn sequences. This con struction is subject to a new theorem that is given here.
We give algorithms and constructions for mathematical and computer searches which allow us to establish the existence of W(4n, 4n - 2) and W (4n, 2n - 1) for many orders 4n less than 4000. We compare these results with the orders for which W(4n, 4n) and W(4n, 2n) are known. We use new algorithms based on the theory
We construct new TW -sequences, weighing matrices and orthogonal designs using near-Yang sequences. In particular we construct new OD(60(2m + 1) + 4t; 13(2m+ 1), 13(2m+ 1), 13(2m+ 1), 13(2m+ 1) and new W(60(2m+ 1) + 4t; 13s(2m+ 1))for all t ≥ O, m ≤ 30, s = 1,2,3,4. Disciplines Physical Sciences and Mathematics Publication Details Marc Gysin and Jennifer Seberry, New results with nearYang sequences, Utilitas Mathematica, 45, (1994), 85-89. This journal article is available at Research Online: http://ro.uow.edu.au/infopapers/1087 New Results with Near-Yang Sequences Marc Gysin and Jennifer Seberry The University of Wollongong Wollongong, NSW 2500 Australia AbstracL We construct new TW -sequences, weighing matrices and onbogooal designs using near-Yang sequences. In panicular we construct new OD(60(2m + 1) + 4t; 13(2m+ I), 13(2m+ I), 13(2m+ I), 13(2m+ 1» and new W(60(2m+ 1) + 4t; 13 .. (2m+ 1» forallt;;:: O,m ~ 30, .. = 1,2,3,4.
Given an RSA modulus n, a ciphertext c and the encryption exponent e, one can construct the sequence x 0 = c mod n; x i+1 = x e i mod n; i = 0; 1; : : : until gcd(x i+1 ? x 0 ; n) 6 = 1 or i > B, B a given boundary. If i B, there are two cases. Case 1: gcd(x i+1 ? x 0 ; n) = n. In this case x i = m and the secret message m can be recovered. Case 2: 1 6 = gcd(x i+1 ? x 0 ; n) 6 = n. In this case, the RSA modulus n can be factorised. If i B, then Case 2 is much more likely to occur than Case 1. This attack is called a cycling attack. We introduce some new generalised cycling attacks. These attacks work without the knowledge of e and c. Therefore, these attacks can be used as factorisation algorithms. We introduce Lucas sequences V (P; 1), the Carmichael function () and we deene the (;) function. The attacks involve Lucas sequences. The Carmichael and the Omega functions then describe an upper bound of the complexity of the attacks. We also translate these attacks to elliptic curves. For this case we call these attacks EC generalised cycling attacks. 1 Preliminaries The reader is assumed to be familiar with the RSA cryptosystem, RivShaAdl78]. We brieey reintroduce Lucas sequences and elliptic curves. Throughout this paper we will use the following notations. If x 0 ; x 1 ; x 2 ; : : : is a sequence of elements, then fXg will denote the whole sequence. If the elements are taken modulo a certain number, say p, and the sequence is periodic, then we will denote its period by fXg;p. We write a j b for a divides b, note that a = b is still possible. (a=n) denotes the Legendre or Jacobi symbol if n is prime or composite, respectively. 1.1 The Carmichael and Omega Function We will make use of the Carmichael and Omega functions () and (;), respectively. () is deened as follows (see, for example, Riesel85]):
Cyclotomy can be used to construct a variety of combinatorial designs, for example, supplementary difference sets, weighing matrices and T -matrices. These designs may be obtained by using linear combinations of the incidence matrices of the cyclotomic cosets. However, cyclotomy only works in the prime and prime power cases. We present a generalisation of cyclotomy and introduce generalised cosets. Combinatorial designs can now be obtained by a search through all linear combinations of the incidence matrices of the generalised cosets. We believe that this search method is new. The generalisation works for all cases and is not restricted to prime powers. The paper presents some new combinatorial designs. We give a new construction for T matrices of order 87 and hence an OD(4 x 87;87,87,87,87). We also give some D-optimal designs of order n = 2v = 2 x 145,2 x 157,2 x 181. Disciplines Physical Sciences and Mathematics Publication Details Marc Gysin and Jennifer Seberry, An experimental search and new combinatorial designs via a generalisation of cyclotomy, Journal of Combinatorial Mathematics and Combinatorial Comuting, 27, (1998), 143-160. This journal article is available at Research Online: http://ro.uow.edu.au/infopapers/1151 An Experimental Search and New Combinatorial Designs via a Generalisation of Cyclotomy Marc Gysin and Jennifer Seberry Centre for Computer Security Research Department of Computer Science The University of Wollongong Wollongong, NSW 2522 Australia email: marc@cs.uow.edu.au j.seberry@cs.uow.edu.au ABSTRACT. Cyclotomy can be used to construct a variety of combinatorial designs, for example, supplementary difference sets, weighing matrices and T -matrices. These designs may be obtained by using linear combinations of the incidence matrices of the cyclotomic cosets. However, cyclotomy only works in the prime and prime power cases. We present a generalisation of cyclotomy and introduce generalised c05ets. Combinatorial designs can now be obtained by a search through all linear combinations of the incidence matrices of the generalised cosets. We believe that this search method is new. The generalisation works for all cases and is not restricted to prime powers. The paper presents some new combinatorial designs. We give a new construction for T -matrices of order 87 and hence an 0 D( 4 x 87; 87,87, 87, 87). We also give some D-optimal designs of order n = 2v = 2 x 145,2 x 157,2 x 181. Cyclotomy can be used to construct a variety of combinatorial designs, for example, supplementary difference sets, weighing matrices and T -matrices. These designs may be obtained by using linear combinations of the incidence matrices of the cyclotomic cosets. However, cyclotomy only works in the prime and prime power cases. We present a generalisation of cyclotomy and introduce generalised c05ets. Combinatorial designs can now be obtained by a search through all linear combinations of the incidence matrices of the generalised cosets. We believe that this search method is new. The generalisation works for all cases and is not restricted to prime powers. The paper presents some new combinatorial designs. We give a new construction for T -matrices of order 87 and hence an 0 D( 4 x 87; 87,87, 87, 87). We also give some D-optimal designs of order n = 2v = 2 x 145,2 x 157,2 x 181. 1 Cyclotomy The methods and techniques in this paper have been inspired by many authors including Dokovic [2], Furino [4] and Hunt and Wallis [9]. We use these methods and further generalisations to find many new combinatorial designs. We now give a short introduction to cyclotomy. More details are given in [5] and [16]. We let In be the identity matrix of order nand I n be the matrix of n x n 1 's. JCMCC 27 (1998), pp. 143-160 Definition 1 Let x be a primitive element of F = GF(q), where q = pOl = ef + 1 is a prime power. Write G = . The cyclotomic cosets C i in F are: Ci = {X,,""+i : s = 0,1, ... , f I}, i = 0,1, ... , e-1. We note that the Ci'S are pairwise disjoint and their union is G = F\ {O}. For fixed i and j, the cyclotomic number (i, j) is defined to be the number of solutions of the equation Zi + 1 = Zj (Zi E Ci , Zj E Cj ), where 1 = xO is the multiplicative unit of F. That is, (i,j) is the number of ordered pairs s, t such that X,,""+i + 1 = xet+j (0 S s,t Sf-I). Note that the number of times is the cyclotomic number (k j, i j). It can be shown (see for example [16] or [19]) that (k j, i j) = (j k, i k). Notation 1 Let A = {al, a2, ... , ak} be a k-set; then we will use .6.A for the collection of differences between distinct elements of A, i.e, .6.A = [~ aj : i # j, 1 S i,j S k]. Now .6.Ci = (0, O)Ci + (1, O)Ci+l + (2, 0)Ci+2 + ... and (0, O)Cj + (1, O)Cj+l + ... . . . + (0, O)Ci + (1, O)Ci+l + ... . . . + (0, i j)Cj + (1, i j)Cj+l + .. . ... + (O,j i)Ci + (l,j i)Ci+l + ... . Notation 2 We use Ca&Cb to denote the adjunction of two sets with repetitions remaining. If A = {a, b, c, d} and B = {b, c, e}, then A&B = [a, b, b, c, c, d, e]. Ca '" Cb is used to denote adjunction, but with the elements of the second set becoming signed. So A '" B = [a, b, -b, c, -c, d, -e].
University of Wollongong Copyright Warning You may print or download ONE copy of this document for the purpose of your own research or study. The University does not authorise you to copy, communicate or otherwise make available electronically to any other person any copyright material contained on this site. You are reminded of the following: This work is copyright. Apart from any use permitted under the Copyright Act 1968, no part of this work may be reproduced by any process, nor may any other exclusive right be exercised, without the permission of the author. Copyright owners are entitled to take legal action against persons who infringe their copyright. A reproduction of material that is protected by copyright may be a copyright infringement. A court may impose penalties and award damages in relation to offences and infringements relating to copyright material. Higher penalties may apply, and higher damages may be awarded, for offences and infringements involving the conversion of material into digital or electronic form. Unless otherwise indicated, the views expressed in this thesis are those of the author and do not necessarily represent the views of the University of Wollongong.