Christof Beierle

dblp:160/3831 · DBLP profile ↗
← Back
19ranked-venue papers
18as first author
13since 2021 · last 2026
0000-0002-5558-0722ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 16 first-author · 11 since 2021Theory of computation · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 When the Wrong Key Lives On: The Key-Recovery Procedure in Integral Attacks
Christof Beierle, Gregor Leander, Yevhen Perehuda
EUROCRYPT1
2025 Integral Resistance of Block Ciphers with Key Whitening by Modular Addition
Christof Beierle, Phil Hebborn, Gregor Leander, Yevhen Perehuda
CRYPTO (5)1
2025 INDIANA - Verifying (Random) Probing Security Through Indistinguishability Analysis
Christof Beierle, Jakob Feldtkeller, Anna Guinet, Tim Güneysu, Gregor Leander, Jan Richter-Brockmann, Pascal Sasdrich
EUROCRYPT (8)1
2025 Commutative cryptanalysis as a generalization of differential cryptanalysis
abstract
Abstract Recently, Baudrin et al. analyzed a special case of Wagner’s commutative diagram cryptanalysis, referred to as commutative cryptanalysis. For a family $$(E_k)_k$$ ( E k ) k of permutations on a finite vector space G, commutative cryptanalysis exploits the existence of affine permutations $$A,B :G \rightarrow G$$ A , B : G → G , $$I \notin \{A,B\}$$ I ∉ { A , B } such that $$E_k \circ A (x) = B \circ E_k(x)$$ E k ∘ A ( x ) = B ∘ E k ( x ) holds with high probability, taken over inputs x, for a significantly large set of weak keys k. Several attacks against symmetric cryptographic primitives can be formulated within the framework of commutative cryptanalysis, most importantly differential attacks, as well as rotational and rotational-differential attacks. Besides, the notion of c-differentials on S-boxes can be analyzed as a special case within this framework. We discuss the relations between a general notion of commutative cryptanalysis, with A and B being arbitrary functions over a finite Abelian group, and differential cryptanalysis, both from the view of conducting an attack on a symmetric cryptographic primitive, as well as from the view of a theoretical study of cryptographic S-boxes.
Jules Baudrin, Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Léo Perrin, Lukas Stennes
Des. Codes Cryptogr.2
2025 Revisiting products of the form X times a linearized polynomial L(X)
abstract
Abstract For a q-polynomial L over a finite field $$\mathbb {F}_{q^n}$$ F q n , we characterize the differential spectrum of the function $$f_L:\mathbb {F}_{q^n} \rightarrow \mathbb {F}_{q^n}, x \mapsto x \cdot L(x)$$ f L : F q n → F q n , x ↦ x · L ( x ) and show that, for $$n \le 5$$ n ≤ 5 , it is completely determined by the image of the rational function $$r_L :\mathbb {F}_{q^n}^* \rightarrow \mathbb {F}_{q^n}, x \mapsto L(x)/x$$ r L : F q n ∗ → F q n , x ↦ L ( x ) / x . This result follows from the classification of the pairs (L, M) of q-polynomials in $$\mathbb {F}_{q^n}[X]$$ F q n [ X ] , $$n \le 5$$ n ≤ 5 , for which $$r_L$$ r L and $$r_M$$ r M have the same image, obtained in Csajbók et al. (Ars Math Contemp 16(2):585–608, 2019). For the case of $$n>5$$ n > 5 , we pose an open question on the dimensions of the kernels of $$x \mapsto L(x) - ax$$ x ↦ L ( x ) - a x for $$a \in \mathbb {F}_{q^n}$$ a ∈ F q n . We further present a link between functions $$f_L$$ f L of differential uniformity bounded above by q and scattered q-polynomials and show that, for odd values of q, we can construct CCZ-inequivalent functions $$f_M$$ f M
Christof Beierle
Des. Codes Cryptogr.1
2023 On Perfect Linear Approximations and Differentials over Two-Round SPNs
Christof Beierle, Patrick Felke, Gregor Leander, Patrick Neumann 0004, Lukas Stennes
CRYPTO (3)1
2023 Gold functions and switched cube functions are not 0-extendable in dimension n > 5
abstract
Abstract In the independent works by Kalgin and Idrisova and by Beierle, Leander and Perrin, it was observed that the Gold APN functions over $$\mathbb {F}_{2^5}$$ F 2 5 give rise to a quadratic APN function in dimension 6 having maximum possible linearity of $$2^5$$ 2 5 (that is, minimum possible nonlinearity $$2^4$$ 2 4 ). In this article, we show that the case of $$n \le 5$$ n ≤ 5 is quite special in the sense that Gold APN functions in dimension $$n>5$$ n > 5 cannot be extended to quadratic APN functions in dimension $$n+1$$ n + 1 having maximum possible linearity. In the second part of this work, we show that this is also the case for APN functions of the form $$x \mapsto x^3 + \mu (x)$$ x ↦ x 3 + μ ( x ) with $$\mu $$ μ being a quadratic Boolean function.
Christof Beierle, Claude Carlet
Des. Codes Cryptogr.1
2022 Constructing and Deconstructing Intentional Weaknesses in Symmetric Ciphers
Christof Beierle, Tim Beyne, Patrick Felke, Gregor Leander
CRYPTO (3)1
2022 Trims and extensions of quadratic APN functions
abstract
Abstract In this work, we study functions that can be obtained by restricting a vectorial Boolean function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n to an affine hyperplane of dimension $$n-1$$ n-1 and then projecting the output to an $$n-1$$ n-1 -dimensional space. We show that a multiset of $$2 \cdot (2^n-1)^2$$ 2·(2n-1)2 EA-equivalence classes of such restrictions defines an EA-invariant for vectorial Boolean functions on $$\mathbb {F}_{2}^n$$ F2n . Further, for all of the known quadratic APN functions in dimension $$n < 10$$ n<10 , we determine the restrictions that are also APN. Moreover, we construct 6368 new quadratic APN functions in dimension eight up to EA-equivalence by extending a quadratic APN function in dimension seven. A special focus of this work is on quadratic APN functions with maximum linearity. In particular, we characterize a quadratic APN function $$F :\mathbb {F}_{2}^n \rightarrow \mathbb {F}_{2}^n$$ F:F2n→F2n with linearity of $$2^{n-1}$$ 2n-1 by a property of the ortho-derivative of its restriction to a linear hyperplane. Using the fact that all quadratic APN functions in dimension seven are classified, we are able to obtain a classification of all quadratic 8-bit APN functions with linearity $$2^7$$ 27 up to EA-equivalence.
Christof Beierle, Gregor Leander, Léo Perrin
Des. Codes Cryptogr.1
2022 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Marek Broll, Federico Canale, Nicolas David 0001, Antonio Flórez-Gutiérrez, Gregor Leander, María Naya-Plasencia, Yosuke Todo
J. Cryptol.1
2022 New Instances of Quadratic APN Functions
abstract
In a recent work, Beierle, Brinkmann and Leander presented a recursive tree search for finding APN permutations with linear self-equivalences in small dimensions. In this paper, we describe how this search can be adapted to find many new instances of quadratic APN functions. In particular, we found 12,921 new quadratic APN functions in dimension eight, 35 new quadratic APN functions in dimension nine and five new quadratic APN functions in dimension ten up to CCZ-equivalence. Remarkably, two of the 35 new APN functions in dimension nine are APN permutations. Among the 8-bit APN functions, there are three extended Walsh spectra that do not correspond to any of the previously-known quadratic 8-bit APN functions and, surprisingly, there exist at least four CCZ-inequivalent 8-bit APN functions with linearity 27, i.e., the highest possible non-trivial linearity for quadratic functions in dimension eight.
Christof Beierle, Gregor Leander
IEEE Trans. Inf. Theory1
2021 Cryptanalysis of the GPRS Encryption Algorithms GEA-1 and GEA-2
Christof Beierle, Patrick Derbez, Gregor Leander, Gaëtan Leurent, Håvard Raddum, Yann Rotella, David Rupprecht, Lukas Stennes
EUROCRYPT (2)1
2021 Linearly Self-Equivalent APN Permutations in Small Dimension
abstract
All almost perfect nonlinear (APN) permutations that we know to date admit a special kind of linear self-equivalence, i.e., there exists a permutation G in their CCZ-equivalence class and two linear permutations A and B, such that G °A = B °G. After providing a survey on the known APN functions with a focus on the existence of self-equivalences, we search for APN permutations in dimension 6, 7, and 8 that admit such a linear self-equivalence. In dimension six, we were able to conduct an exhaustive search and obtain that there is only one such APN permutation up to CCZ-equivalence. In dimensions 7 and 8, we performed an exhaustive search for all but a few classes of linear self-equivalences and we did not find any new APN permutation. As one interesting result in dimension 7, we obtain that all APN permutation polynomials with coefficients in \mathbb F2must be (up to CCZ-equivalence) monomial functions.
Christof Beierle, Marcus Brinkmann, Gregor Leander
IEEE Trans. Inf. Theory1
2020 Alzette: A 64-Bit ARX-box - (Feat. CRAX and TRAX)
Christof Beierle, Alex Biryukov, Luan Cardoso dos Santos, Johann Großschädl, Léo Perrin, Aleksei Udovenko, Vesselin Velichkov, Qingju Wang 0001
CRYPTO (3)1
2020 Improved Differential-Linear Attacks with Applications to ARX Ciphers
Christof Beierle, Gregor Leander, Yosuke Todo
CRYPTO (3)1
2017 Proving Resistance Against Invariant Attacks: How to Choose the Round Constants
Christof Beierle, Anne Canteaut, Gregor Leander, Yann Rotella
CRYPTO (2)1
2016 The SKINNY Family of Block Ciphers and Its Low-Latency Variant MANTIS
Christof Beierle, Jérémy Jean, Stefan Kölbl, Gregor Leander, Amir Moradi 0001, Thomas Peyrin, Yu Sasaki 0001, Pascal Sasdrich, Siang Meng Sim
CRYPTO (2)1
2016 Lightweight Multiplication in GF(2^n) with Applications to MDS Matrices
Christof Beierle, Thorsten Kranz, Gregor Leander
CRYPTO (1)1
2015 Analyzing Permutations for AES-like Ciphers: Understanding ShiftRows
Christof Beierle, Philipp Jovanovic, Martin M. Lauridsen, Gregor Leander, Christian Rechberger
CT-RSA1