VLDB 2026 Research / reviewers in the wild / expert
Jan Schoone
dblp:266/5719
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2024
0000-0002-0751-291XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | The state diagram of χabstractAbstract In symmetric cryptography, block ciphers, stream ciphers and permutations often make use of a round function and many round functions consist of a linear and a non-linear layer. One that is often used is based on the cellular automaton that is denoted by $$\chi $$ χ as a Boolean map on bi-infinite sequences, $${\mathbb {F}}_2^{{\mathbb {Z}}}$$ F2Z . It is defined by $$\sigma \mapsto \nu $$ σ↦ν where each $$\nu _i = \sigma _i + (\sigma _{i+1}+1)\sigma _{i+2}$$ νi=σi+(σi+1+1)σi+2 . A map $$\chi _n$$ χn is a map that operates onn-bit arrays with periodic boundary conditions. This corresponds with $$\chi $$ χ restricted to periodic infinite sequences with period that dividesn. This map $$\chi _n$$ χn is used in various permutations, e.g.,Keccak-f (the permutation in SHA-3), ASCON (the NIST standard for lightweight cryptography), Xoodoo, Rasta and Subterranean (2.0). In this paper, we characterize the graph of $$\chi $$ χ on periodic sequences. It turns out that $$\chi $$ χ is surjective on the set ofallperiodic sequences. We will show what sequences will give collisions after one application of $$\chi $$ χ . We prove that, for oddn, the order of $$\chi _n$$ χn (in the group of bijective maps on $${\mathbb {F}}_2^n$$ F2n ) is $$2^{\lceil {\text {lg}}(\frac{n+1}{2})\rceil }$$ 2⌈lg(n+12)⌉ . A given periodic sequence lies on a cycle in the graph of $$\chi $$ χ , or it can be represented as a polynomial. By regarding the divisors of such a polynomial one can see whether it lies in a cycle, or after how many iterations of $$\chi $$ χ it will. Furthermore, we can see, for a given $$\sigma $$ σ , the length of the cycle in its component in the state diagram. Finally, we extend the surjectivity of $$\chi $$ χ to $${\mathbb {F}}_2^{{\mathbb {Z}}}$$ F2Z , thus to include non-periodic sequences. Jan Schoone, Joan Daemen |
Des. Codes Cryptogr. | 1 |
| 2024 | Algebraic properties of the maps χ nabstractAbstract The Boolean map $$\chi _n :\mathbb {F}_2^n \rightarrow \mathbb {F}_2^n,\ x \mapsto y$$ χn:F2n→F2n,x↦y defined by $$y_i = x_i + (x_{i+1}+1)x_{i+2}$$ yi=xi+(xi+1+1)xi+2 (where $$i\in \mathbb {Z}/n\mathbb {Z}$$ i∈Z/nZ ) is used in various permutations that are part of cryptographic schemes, e.g.,Keccak-f (the SHA-3-permutation), ASCON (the winner of the NIST Lightweight competition), Xoodoo, Rasta and Subterranean (2.0). In this paper, we study various algebraic properties of this map. We consider $$\chi _n$$ χn (through vectorial isomorphism) as a univariate polynomial. We show that it is a power function if and only if $$n=1,3$$ n=1,3 . We furthermore compute bounds on the sparsity and degree of these univariate polynomials, and the number of different univariate representations. Secondly, we compute the number of monomials of given degree in the inverse of $$\chi _n$$ χn (if it exists). This number coincides with binomial coefficients. Lastly, we consider $$\chi _n$$ χn as a polynomial map, to study whether the same rule ( $$y_i = x_i + (x_{i+1}+1)x_{i+2}$$ yi=xi+(xi+1+1)xi+2 ) gives a bijection on field extensions of $$\mathbb {F}_2$$ F2 . We show that this is not the case for extensions whose degree is divisible by two or three. Based on these results, we conjecture that this rule does not give a bijection on any extension field of $$\mathbb {F}_2$$ F2 . Jan Schoone, Joan Daemen |
Des. Codes Cryptogr. | 1 |