How Small Can S-boxes Be?
Abstract: S-boxes are the most popular nonlinear building blocks used in symmetrickey primitives. Both cryptographic properties and implementation cost of an S-box are crucial for a good cipher design, especially for lightweight ones. This paper aims to determine the exact minimum area of optimal 4-bit S-boxes (whose differential uniform and linearity are both 4) under certain standard cell library. Firstly, we evaluate the upper and lower bounds upon the minimum area of S-boxes, by proposing a Prim-like greedy algorithm and utilizing properties of balanced Boolean functions to construct bijective S-boxes. Secondly, an SAT-aided automatic search tool is proposed that can simultaneously consider multiple cryptographic properties such as the uniform, linearity, algebraic degree, and the implementation costs such as area, and gate depth complexity. Thirdly, thanks to our tool, we manage to find the exact minimum area for different types of 4-bit S-boxes. The measurement in this paper uses the g.... https://tosc.iacr.org/index.php/ToSC/article/view/12088
- Standort
-
Deutsche Nationalbibliothek Frankfurt am Main
- Umfang
-
Online-Ressource
- Sprache
-
Englisch
- Erschienen in
-
How Small Can S-boxes Be? ; volume:2025 ; number:1 ; year:2025
IACR transactions on symmetric cryptology ; 2025, Heft 1 (2025)
- Urheber
-
Jia, Chenhao
Cui, Tingting
Ling, Qing
He, Yan
Hu, Kai
Sun, Yu
Wang, Meiqin
- DOI
-
10.46586/tosc.v2025.i1.592-622
- URN
-
urn:nbn:de:101:1-2503121754205.506118737815
- Rechteinformation
-
Open Access; Der Zugriff auf das Objekt ist unbeschränkt möglich.
- Letzte Aktualisierung
-
15.08.2025, 07:19 MESZ
Datenpartner
Deutsche Nationalbibliothek. Bei Fragen zum Objekt wenden Sie sich bitte an den Datenpartner.
Beteiligte
- Jia, Chenhao
- Cui, Tingting
- Ling, Qing
- He, Yan
- Hu, Kai
- Sun, Yu
- Wang, Meiqin