REVIEW 3 major objections 3 minor 33 references
A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums
T0 review · 3 major / 3 minor · reviewed 2026-08-12 · deepseek-v4-flash
Pith's one-line read The paper introduces trace rational blocks and claims explicit Kloosterman-sum characterizations for three classes of Dillon-like bent functions.
desk verdict The reader's rejection rests on a misreading—the trace-zero step works because a1 lies in F_q, so the central theorems likely survive and the paper deserves refereeing. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The carrying object is the exponential sum $\xi(a,b)=\sum_{\lambda\in\mathbb{U}}(-1)^{\mathrm{Tr}^{2n}_1(a/(\lambda+b))}$ on the unit circle $\mathbb{U}=\{\lambda\in\mathbb{F}_{q^2}:\lambda^{q+1}=1\}$. Lemma II.5 evaluates this sum in three regimes — $b\in\mathbb{U}$ with $\mathrm{Tr}^{2n}_n(ab)=0$, $b\in\mathbb{U}$ with nonzero trace, and $b\notin\mathbb{U}$ — in terms of the binary Kloosterman sum $K_n(a)=\sum_{x\in\mathbb{F}_{2^n}}(-1)^{\mathrm{Tr}^n_1(1/x+ax)}$. Together with the Walsh-transform reduction of Proposition II.4 (a Dillon-like function is bent iff the signed unit-circle sum equals $(-1)^{f(0)}$), this turns bentness of the block combinations into exact equalities involving Kloosterman sums.
What would settle it
Take n=3, q=8, b=1, a1 in the subfield with trace 1, and a2 outside the subfield with absolute trace 1; substituting into Eq. (III.3) gives left-hand side 2 and right-hand side -2, so h2 would not be bent even though it satisfies the conditions of Theorem III.2(1).
Extended reading notes
Core claim
The central claim is that, for $q=2^n$ and $b\in\mathbb{F}_{q^2}^*$, the function $h_2(x)=\mathrm{Tr}^{2n}_1(a_1/(x^{q-1}+b))\cdot\mathrm{Tr}^{2n}_1(a_2/(x^{q-1}+b))$ is bent exactly when one of three parameter conditions holds — for instance $b=1$, $\mathrm{Tr}^n_1(a_1)=1$, and $a_2\in\mathbb{F}_{q^2}\setminus\mathbb{F}_q$ — and that the symmetric sum $h_3(x)=\sum_{i<j}\mathrm{Tr}^{2n}_1(a_i/(x^{q-1}+b))\mathrm{Tr}^{2n}_1(a_j/(x^{q-1}+b))$ is bent under six listed conditions. The route is to reduce the Walsh transform of any Dillon-like function to a signed sum over the unit circle $\mathbb{U}=\{x:x^{q+1}=1\}$ (Proposition II.4), then to evaluate the exponential sums $\xi(a,b)$ that arise, with Lemma II.5 connecting them to the binary Kloosterman sum $K_n$. The paper also derives the ordinary polynomial form of the single block $h_1$, showing it is a full Dillon-type sum, and reports computational checks that the new classes are not EA-equivalent to the five known monomial bent classes.
Load-bearing premise
The b=1 cases of Theorems III.2 and III.3 rely on the premise that any element outside the subfield has absolute trace zero, which forces the initial values h2(0) and h3(0) used in the proof.
Editorial extensions
If this is right
- If Theorem III.1 holds, the single trace-rational block is bent exactly under the two listed conditions, making $K_n$ the deciding quantity for the $b\notin\mathbb{U}$ case.
- If Theorem III.2 holds, products of two distinct blocks are bent in exactly the three listed regimes, with the outside-unit-circle regime ruled out for $n\ge 6$.
- If Theorem III.3 holds, the symmetric sum of three blocks admits the six stated parameter families, including a four-Kloosterman-sum relation when $b\notin\mathbb{U}$.
- The paper's polynomial-form derivation implies the single-block class has every Dillon exponent present, distinguishing it from earlier fixed-term Dillon-like constructions.
- The reported equivalence checks indicate the three classes are not EA-equivalent to the known monomial bent classes on the tested fields.
Reading between the lines
- The identity (III.1) is a general Fourier-inversion criterion: for any reduced polynomial $F$, bentness of $F(f_1,\dots,f_t)$ is equivalent to an explicit linear equation in the $\xi$-values, so the same machinery can produce characterizations for $F$ of higher degree.
- The explicit polynomial form (IV.2) gives a concrete way to test EA-inequivalence beyond the computationally feasible fields: comparing its coefficient set with Eq. (IV.1) on $\mathbb{F}_{2^{12}}$ or larger would resolve the open question the paper leaves.
- Because the range of $K_n(a)$ is completely known, the criteria are finitely checkable; an exhaustive small-$n$ enumeration of the parameter triples and quadruples would let one compile a catalogue of the new bent functions and check their duals, which Proposition II.4 makes easy to compute.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces a family H of rational trace functions on F_{2^{2n}} of the form Tr^{2n}_1(a/(x^{2^n-1}+b)) and studies the bentness of Dillon-like Boolean functions built from these blocks via reduced polynomials F. It states an explicit exponential-sum formula (Lemma II.5) for ξ(a,b) and uses it to characterize three classes: h1=Tr^{2n}_1(a1/(x^{q-1}+b)) (Theorem III.1), h2=f1 f2 (Theorem III.2), and h3=f1 f2 + f1 f3 + f2 f3 (Theorem III.3). The h1 characterization and the b∉U cases are not affected by the issue discussed below, but the b∈U branches of Theorems III.2 and III.3 rest on an incorrect identity in Lemma II.5. The specific reviewer objection that h2(0) need not vanish in Theorem III.2(1) does not land: for a1∈F_q one has Tr^{2n}_1(a1)=Tr^n_1(a1+a1^q)=0, so h2(0)=0 automatically. The load-bearing problem lies instead in the claimed equivalence used to prove Eq. (II.7).
Significance. If the characterizations were correct, the paper would be significant: it would give the first bent functions assembled from rational trace blocks, with Kloosterman-sum characterizations and concrete examples of functions apparently not EA-equivalent to known monomial bent functions. The paper does not rely on circular arguments or fitted parameters, and the h1 result and the b∉U parts of the proofs are plausible. However, the central b∈U branch of the key exponential-sum lemma is false, and Theorem III.2 is false as stated for b∈U\{1}; Theorem III.3 is at least unproved and very likely false in the same branch. Since these are the main claimed characterizations, the paper cannot be accepted in its present form.
major comments (3)
- [Section II, Lemma II.5, Eq. (II.7)] The proof of Lemma II.5 uses the assertion that for b∈U, a^{q-1}b^2=1 is equivalent to Tr^{2n}_n(ab)=0. This is false for b≠1. For a concrete counterexample with q=4, let ζ be a primitive 5th root of unity in F_{16}, set b=ζ and a=ζ^{-1}. Then ab=1, so Tr^{4}_2(ab)=0; but a^{q-1}b^2 = ζ^{-3}ζ^2 = ζ^4 ≠ 1. Consequently Eq. (II.7) as printed is wrong: in this example the first line would give ξ(a,b)=1+(-1)^{Tr^2_1(a\bar a)}q = 1+4 = 5, while the reduction ξ(a,b)=ξ(a\bar a, a^{q-1}b^2) with a\bar a=1 and a^{q-1}b^2∈U\{1} gives ξ=1 by Eq. (II.8). The correct case distinction for b∈U depends on c=a^{q-1}b^2 (c=1 versus c≠1), not on Tr^{2n}_n(ab); for b∈U\{1} and Tr^{2n}_n(ab)=0 one always has c≠1, hence ξ(a,b)=1.
- [Section III, Theorem III.2] Because of the error in Eq. (II.7), the proof of Theorem III.2 in the case b∈U\{1} is invalid, and conditions (2) and (3) are false. With the correct ξ-values, every a satisfying Tr^{2n}_n(ab)=0 (when b∈U\{1}) has ξ(a,b)=1. In the situation of conditions (2) and (3) this makes ξ(a1,b)=ξ(a2,b)=ξ(a1+a2,b)=1, so the left-hand side of Eq. (III.3) equals q+1+1+1−1 = q+2, which cannot equal 2(−1)^{h2(0)} = ±2 for q≥2. Thus h2 is not bent under these parameter conditions, contradicting the stated 'if and only if' and the corresponding triples in Example 2.
- [Section III, Theorem III.3] The same incorrect ξ-values are used in the b∈U\{1} subcases of Theorem III.3. In particular, condition (5) requires only Tr^{2n}_n(a2/b)≠0, Tr^{2n}_n(a3/b)≠0 and Tr^{2n}_n((a1+a2+a3)/b)≠0; it does not prevent a2^{q-1}b^2, a3^{q-1}b^2, or (a1+a2+a3)^{q-1}b^2 from being 1. When such an element has c=1, its ξ-value is 1+(−1)^{Tr^n_1(a\bar a)}q rather than 1, so the right-hand side of Eq. (III.6) is not forced to be 2. The proof's claims that the listed conditions are necessary and sufficient for these subcases (also repeated in Remark 1) are therefore not established, and Theorem III.3 as stated is not supported.
minor comments (3)
- [Section II, Eq. (II.7)] The notation rendered as 'a/a' in the first branch of Eq. (II.7) is ambiguous; it should be a\bar a (the field-theoretic norm to F_q), and this should be defined explicitly at first use.
- [Section III, Remark 1] Remark 1 states that the conditions in Theorem III.3 are 'sufficient and necessary', but the theorem itself is written only as an 'if' statement; the paper should either strengthen the theorem or weaken the remark.
- [Section IV] The text says 'Section IV discusses the EA equivalence, and Section IV concludes the paper'; the second reference should be to Section V.
Circularity Check
No circularity: the bentness characterizations are derived from independent exponential-sum and Kloosterman-sum calculations, not from fitted parameters or self-citations.
full rationale
The paper's derivation chain is self-contained. The central reduction is Proposition II.4, which reformulates bentness of a Dillon-like function f(x)=g(x^{q-1}) as the unit-circle condition sum_{\lambda\in U} (-1)^{g(\lambda)}=(-1)^{f(0)}. This proposition is proved directly from the Walsh-transform formula in Proposition II.3 and is not assumed from any cited source as a black box. The subsequent exponential-sum machinery is likewise independent: Lemma II.3 derives a Kloosterman-sum identity from character-sum manipulations; Lemma II.4 computes the rational-function sum S = sum (-1)^{Tr(Ax+B)/(x^2+x+\delta)} in terms of Kloosterman sums with its own proof; and Lemma II.5 converts the unit-circle sums \xi(a,b) into Kloosterman values using Lemmas II.1-II.4. All of these lemmas have stated hypotheses involving a,b,A,B,\delta only, and none of the hypotheses include the bentness of the target functions. Theorems III.1-III.3 then evaluate Eq. (III.1) by substituting the explicit expressions from Lemma II.5 and solving the resulting equations for the parameters. For example, in Theorem III.2 the condition Tr_1^n(a_1)=1 and a_2\notin F_q arises algebraically from \Theta = 2+q(1+(-1)^{Tr_1^n(a_1)}) in the case b=1, while the case b\in U\setminus\{1\} is split according to whether Tr_{2n}^n(a_2b) and Tr_{2n}^n((a_1+a_2)b) vanish. These are genuine necessary-and-sufficient reductions, not fitted parameters renamed as predictions. Theorem III.3(6) is a characterization statement: it expresses h_3 being bent as an explicit equation involving four Kloosterman sums. Since bentness is defined by the Walsh transform and the equation is derived from Eq. (III.1) and Lemma II.5, the equivalence is a substantive reduction rather than a definitional tautology. The citations to Li et al. [21] and to the authors' own monograph and papers provide background, prior criteria, and related constructions, but the present proofs do not rely on any load-bearing uniqueness theorem from those works, nor is any ansatz imported solely through a citation. In particular, no parameter is fit to data and later reported as a prediction, and the characterizations are not assumed in the hypotheses of the lemmas. The paper does claim experimental evidence of EA-inequivalence, but that is an ancillary observation and is not part of the derivation chain being assessed.
Assumptions & free parameters
assumptions (5)
- standard math Binary Kloosterman sums take exactly the multiples of 4 in the interval [-2^{n/2+1}+1, 2^{n/2+1}+1] (Lachaud-Wolfmann).
- standard math For b in F_q, the absolute trace of b/(1+b^2) is 0 whenever the quadratic x^2+(b+b^{-1})x+1 has roots in F_q.
- standard math Rosendahl's parametrization U\{1} = {(u+A)/(u+\bar{A}) : u in F_q} and Lemma II.2 counting solutions on the unit circle.
- standard math Walsh inversion formula for the reduced polynomial F, used to express sums over U of (-1)^{F(...)} as combinations of xi(a,b).
- domain assumption Proposition II.1 (Carlet-Gaborit / Youssef-Gong) connecting hyper-bent functions to weight sums.
Cite this review
Pith. "Pith review of A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums." pith.science (2026). https://pith.science/paper/XTCUICAH
@misc{pith2026241115750,
author = {Pith},
title = {Pith review of: A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums},
year = {2026},
howpublished = {\url{https://pith.science/paper/XTCUICAH}},
note = {Machine review of arXiv:2411.15750}
}
abstract
Dillon-like Boolean functions are known, in the literature, to be those trace polynomial functions from $\mathbb{F}_{2^{2n}}$ to $\mathbb{F}_{2}$, with all the exponents being multiples of $2^n-1$ often called Dillon-like exponents. This paper is devoted to bent functions in which we study the bentness of some classes of Dillon-like Boolean functions connected with rational trace functions. Specifically, we introduce a special infinite family of trace rational functions. We shall use these functions as building blocks and generalise notably a criterion due to Li et al. published in [IEEE Trans. Inf. Theory 59(3), pp. 1818-1831, 2013] on the bentness of Dillon-like functions in the binary case, we explicitly characterize three classes of bent functions. These characterizations are expressed in terms of the well-known binary Kloosterman sums. Furthermore, analysis and experiments indicate that new functions not EA-equivalent to all known classes of monomial functions are included in our classes.
Reference graph
Works this paper leans on
-
[1]
A. Alahmadi, H. Akhazmi, T. Helleseth, R. Hijazi, N.M. Mu thana, P . Sol´ e, On the lifted Zetterberg code, Des. Codes Cryptogr. 80(3), pp. 561-576, 2016
work page 2016
-
[2]
A. Canteaut, P . Charpin, G. Kyureghyan, A new class of mon omial bent functions, Finite Fields Appl. 14(1), pp. 221-241, 2008
work page 2008
-
[3]
P . Charpin, G. Kyureghyan, Cubic monomial bent function s: A subclass of M, SIAM. J. Discr. Math. 22(2), pp. 650-665, 2008
work page 2008
-
[4]
P . Charpin, G. Gong, Hyperbent functions, Kloosterman s ums and Dickson polynomials, IEEE Trans. Inf. Theory 54(9), pp. 4230-4238, 2008
work page 2008
-
[5]
P . Charpin, E. Pasalic, C. Tavernier, On bent and semi-be nt quadratic boolean functions, IEEE Trans. Inf. Theory 51(12), pp. 4286-4298, 2005
work page 2005
- [6]
-
[7]
C. Carlet, On bent and highly nonlinear balanced/resili ent functions and their algebraic immunities, in AAECC (Lec ture Notes in Computer Science), vol. 3857, M. P . C. Fossorier, H. Imai, S. Lin, and A. Poli, Eds. New Y ork, NY , USA: Springer-V erlag, 2006, pp. 1-28
work page 2006
- [8]
Show all 33 references
-
[9]
L. E. Dickson, History of the theory of numbers, V ol. 1, Ch elsea, New Y ork, 1952
1952
-
[10]
Dillon, Elementary Hadamard difference sets, PhD di ssertation, University of Maryland
J. Dillon, Elementary Hadamard difference sets, PhD di ssertation, University of Maryland
-
[11]
Dillon, H
J. Dillon, H. Dobbertin, New cyclic difference sets wit h Singer parameters, Finite Fields Appl. 10(3), pp. 342-389 , 2004. 26
2004
-
[12]
Dobbertin, G
H. Dobbertin, G. Leander, A. Canteaut, C. Carlet, P . Fel ke, P . Gaborit, Construction of bent functions via Niho powe r functions, J. Combin. Theory Ser. A (113), pp. 779-798, 2006
2006
-
[13]
Dodunekov, J.E.M
S.M. Dodunekov, J.E.M. Nilsson, Algebraic decoding of the Zetterberg codes, IEEE Trans. Inf. Theory 38(5), pp. 1570-1573, 1992
1992
-
[14]
Fine, Binomial coefficients modulo a prime, Am
N.J. Fine, Binomial coefficients modulo a prime, Am. Mat h. Monthly, 54, pp. 589-592, 1947
1947
-
[15]
Gold, Maximal recursive sequences with 3-valued rec ursive crosscorrelation functions, IEEE Trans
R. Gold, Maximal recursive sequences with 3-valued rec ursive crosscorrelation functions, IEEE Trans. Inf. Theor y 14(1), pp. 154-156, 1968
1968
-
[16]
Kumar, R.A
P .V . Kumar, R.A. Scholtz, L.R. Welch, Generalized bent functions and their properties, J. Combin. Theory Ser. A (40 ), pp. 90-107, 1985
1985
-
[17]
R. Lidl, H. Niederreiter, Finite Fields, Encyclopedia Math. Appl. Cambridge University Press, 1997
1997
-
[18]
Leander, Monomial bent functions, IEEE Trans
G. Leander, Monomial bent functions, IEEE Trans. Inf. T heory 52(2), pp. 738-743, 2006
2006
-
[19]
Leander, A
G. Leander, A. Kholosha, Bent functions with 2r Niho exponents, IEEE Trans. Inf. Theory 52(12), pp. 5529-55 32, 2006
2006
-
[20]
Lachaud, J
G. Lachaud, J. Wolfmann, The weights of the orthogonals of the extended quadratic binary Goppa codes, IEEE Trans. Inf. Theory 36(3), pp. 686-692, 1990
1990
-
[21]
N. Li, T. Helleseth, X. Tang, A. Kholosha, Several new cl asses of bent functions from Dillon exponents, IEEE Trans. Inf. Theory 59(3), pp. 1818-1831, 2013
2013
-
[22]
Mesnager, Bent functions-Fundamentals and Results , Springer Cham, Switzerland, 2016
S. Mesnager, Bent functions-Fundamentals and Results , Springer Cham, Switzerland, 2016
2016
-
[23]
Mesnager, A new class of bent and hyper-bent Boolean f unctions in polynomial forms, Des
S. Mesnager, A new class of bent and hyper-bent Boolean f unctions in polynomial forms, Des. Codes Cryptogr. 59, pp. 265-279, 2011
2011
-
[24]
Mesnager, Bent and hyper-bent functions in polynomi al form and their link with some exponential sums and Dickson polynomials, IEEE Trans
S. Mesnager, Bent and hyper-bent functions in polynomi al form and their link with some exponential sums and Dickson polynomials, IEEE Trans. Inf. Theory 57(9), pp. 5996-6009, 2011
2011
-
[25]
Rothaus, On bent functions, J
O.S. Rothaus, On bent functions, J. Combin. Theory Ser. A (20), pp. 300-305, 1976
1976
-
[26]
Rosendahl, Niho type cross-correlation functions a nd related equations, PhD dissertation, Univ
P . Rosendahl, Niho type cross-correlation functions a nd related equations, PhD dissertation, Univ. Turku, Turku, Finland, 2004
2004
-
[27]
Schmidt, M.G
K.U. Schmidt, M.G. Parker, A. Pott, Negabent functions in the Maiorana-McFarland Class, S.W. Golomb et al. (Eds.): SETA 2008, LNCS 5203, pp. 390-402, 2008
2008
-
[28]
Z. Tu, X. Zeng, C. Li, T. Helleseth, A class of new permuta tion trinomials, Finite Fields Appl. 50, pp. 178-195, 2018
2018
-
[29]
C. Tang, Z. Zhou, Y . Qi, X. Zhang, C. Fan, T. Helleseth, Ge neric construction of Bent functions and Bent idempotents with any possible algebraic degrees, IEEE Trans. Inf. Theor y 63(10), pp. 6149-6157 , 2017
2017
-
[30]
Y oussef, G
A.M. Y oussef, G. Gong, Hyper-bent functions, Advances in Cryptology-Eurocrypt 2001, Lecture Notes in Computer Science, vol. 2045, Springer, Berlin, pp. 406-419, 2001
2001
-
[31]
N.Y . Y u, G. Gong, Constructions of quadratic bent funct ions in polynomial forms, IEEE Trans. Inf. Theory 52(7), pp. 3291-3299, 2006
2006
-
[32]
L. Y u, H. Liu, D. Zheng, On more bent functions from Dillo n exponents, Appl. Algebra Eng. Commun. Comput. 26, pp. 389-408, 2015
2015
-
[33]
Zheng, X
Y . Zheng, X. Zhang, Plateaued Functions, Plateaued Fun ctions, V . V aradharajan and Y . Mu (Eds.): ICICS’99, LNCS 1726, pp. 284-300, 1999. APPENDIX A1: T HE EXPLICIT ORDINARY POLYNOMIAL FORM OF h1 To deduce the explicit polynomial form of h1, a basic fact is that for integer...
1999
Reviewed August 12, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.