Pith. sign in

REVIEW 4 major objections 3 minor 21 references

Differential Spectrum and Boomerang Spectrum of Some Power Mapping

T0 review · 4 major / 3 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read This paper claims complete differential and boomerang spectra for the power family x^{s(p^m−1)} over F_{p^{2m}} for every t=gcd(s,p^m+1).

desk verdict A false uniqueness lemma breaks the frequency accounting; the claimed complete spectra are not established, though the result may be salvageable after major rework. read the letter →

arxiv 2506.05738 v1 pith:SHZ7J6VC submitted 2025-06-06 cs.IT math.IT

classification cs.ITmath.IT MSC 94A6011T06
keywords differentialspectrumboomerangpowermappinglocally-APNfunctionfinitefieldsrationalpointsoncurvesNihotypefunctionsS-box
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper aims to settle, for the entire family of power mappings f(x)=$x^{{s(p^m-1)}}$ over F_{p^n} with n=2m, the full distribution of solutions to the differential equation (x+1)^d-x^d=b and to the analogous boomerang system. The previously published result covered only the case gcd(s,p^m+1)=1; the paper claims to remove that restriction, giving explicit closed-form tables for every prime p, every m, and every t=gcd(s,p^m+1), subject to (p^m+1)/t>3. If correct, this gives cryptographers the exact differential and boomerang spectra of an infinite family of S-box candidates without case-by-case computation, and it supplies a template, based on counting rational points on curves, for treating other Niho-type power functions.

What carries the argument

The engine of the proof is the index partition C_{j1,j2} = {x ∈ F_{p^n}\setminus\{0,-1\} : ind_ψ(x+1) ≡ j1 (mod p^m+1), ind_ψ(x) ≡ j2 (mod p^m+1)}, together with the fact that α=$ψ^{{p^m-1}}$ satisfies $α^{{p^m}}$=$α^{{-1}}$. On each C_{j1,j2}, the difference (x+1)^d-x^d collapses to $α^{{s j1}}$-$α^{{s j2}}$, so counting solutions of the differential or boomerang equations becomes counting F_{p^n}-rational points on affine curves of the form α $X^{{n1}}$+β $Y^{{n2}}$+1=0. The paper imports closed-form point counts for such curves (Lemma 1) and combines them with the two standard identities for the differential spectrum to obtain the frequency tables. A supporting uniqueness claim, Lemma 2, asserts that the sums α^i+α^j determine the unordered pair (i,j); this is used to conclude that distinct index classes produce distinct right-hand sides.

What would settle it

A direct computer enumeration of the differential spectrum for p=3, m=2, t=1 — the function f(x)=$x^{{8}}$ over F_{81} — would settle the main claim for a small case where the uniqueness lemma is already violated. Compare every value δ(1,b) against the rows of Table 4; any mismatch would show the claimed completeness fails, while a match would indicate the damage from the false lemma is confined to the proof rather than the result.

Watch

Extended reading notes

Core claim

The paper's central discovery is that for d=s(p^m-1) with n=2m, the derivative difference (x+1)^d-x^d takes only values of the form $α^{{si}}$-$α^{{sj}}$, where α=$ψ^{{p^m-1}}$ and 0≤i,j≤p^m, and the number of x producing each such value is governed by the number of F_{p^n}-rational points on curves α $X^{{n1}}$+β $Y^{{n2}}$+1=0. By partitioning F_{p^n}\setminus\{0,-1\} into classes indexed by the discrete logs of x and x+1 modulo p^m+1, the paper reduces the spectrum problem to a finite set of curve counts, then uses the two identities Σω_i=p^n and Σ iω_i=p^n to solve for the frequencies. The result is a complete set of tables, Theorems 1 through 6, covering p=2, p=3, and p>3, with separate rows according to which of 2t, 3t, or 6t divides p^m+1, and with worked examples for F_{$5^{4}$}, F_{$11^{4}$}, F_{$3^{8}$}, and F_{$7^{4}$}.

Load-bearing premise

The load-bearing premise is Lemma 2, which says each value α^i+α^j occurs for only one unordered pair (i,j) with 0≤i≤j≤p^m; this fails for p=3,m=1, where α has order 4 in F_9 and $α^{0}$+$α^{2}$=$α^{1}$+$α^{3}$=0, and the proof uses the premise to conclude that different index classes give different b-values.

Editorial extensions

If this is right

  • For any exponent s with gcd(s,p^m+1)=t and (p^m+1)/t>3, the differential and boomerang spectra are given by explicit rational formulas in p^m and t; no per-exponent search is needed.
  • Setting t=1 recovers the previously known spectra, so the new tables genuinely generalize that result.
  • The boomerang spectrum is obtained directly from curve counts rather than by converting the differential spectrum, a different route that may work for other power maps.
  • S-box designers can read off, for this family, how many nonzero shifts b have a given differential or boomerang multiplicity, the data needed to assess resistance to differential and boomerang attacks.
  • The index-partition and curve-counting strategy is a plausible template for other power functions of Niho type.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Because the stated formulas depend on s only through t, the tables imply that every exponent in the same gcd class shares identical spectra; this could be verified inexpensively on a small finite field.
  • The uniqueness claim behind the proof is not generally true: in F_9, with α of order 4, α^0+α^2=α^1+α^3=0, so a fully supported proof needs either an added restriction on the parameters or a separate treatment of colliding sums.
  • The same index partition should apply to extensions F_{p^{km}} with k>2 and to other exponents of the form s(p^m−1), where the curve point counts would take a similar but not identical form.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 3 minor

Summary. The paper studies the power mapping f(x)=x^{s(p^m-1)} over F_{p^n} with n=2m and gcd(s,p^m+1)=t. It claims to determine, for all primes p, all m, and all admissible s, the complete differential spectrum (Theorems 1-3) and boomerang spectrum (Theorems 4-6) by counting F_{p^n}-rational points on affine curves via a cited lemma of Wang-Luo. The proof strategy partitions F_{p^n} into index sets C_{j_1,j_2} and uses a uniqueness statement about sums of powers of α=ψ^{p^m-1} (Lemma 2) to control the support of the derivative and boomerang equations. Several auxiliary lemmas (Lemmas 4, 5, 7, 8) are stated without proof, with the proofs said to be analogous to those of Lemmas 3 and 6.

Significance. If the results were correct, the paper would give a complete closed-form description of the differential and boomerang spectra for a broad family of Niho-type power mappings, extending earlier work by Hu et al. from t=1 to general t. The curve-counting method is potentially attractive and the examples suggest the authors did perform some verification. However, the central frequency-accounting argument rests on a false uniqueness lemma, and there is a concrete internal contradiction in the stated formulas. The paper does not ship machine-checked proofs or independent code; the numerical examples are too sparse to compensate for the broken proof. The claimed completeness is therefore not established.

major comments (4)
  1. [Lemma 2] Lemma 2 is false as stated. For p=3, m=1, α=ψ^{3^1-1}=ψ^2 has order 4 in F_9, and α^0+α^2=1+(-1)=0 while α^1+α^3=α+(-α)=0, giving two distinct pairs (0,2) and (1,3) with the same sum. The same failure occurs for differences: α^0-α^3=1-(-α)=1+α and α^1-α^2=α-(-1)=α+1 are equal. This lemma is invoked in Lemma 3(v) and Lemma 6(v) to conclude that the listed b values are the only ones with nonzero δ(b) or β(b), and it is explicitly delegated to the omitted proofs of Lemmas 4, 5, 7, and 8. Since the distinctness of the sums or differences is load-bearing for the frequency tables in Theorems 1-6, the support claims are not proved.
  2. [Lemma 4] Lemma 4 is internally contradictory and contradicts direct computation. Take p=3, m=1, t=1, s=1, so f(x)=x^2 over F_9, a PN function with δ(1,b)=1 for every b. The standing hypothesis (p^m+1)/t=4>3 is satisfied. Lemma 4(v) gives δ(2α)=t^2=1 because α^si=α≠2. Lemma 4(vii) applies to i=1, j=3, since α^si=α, α^sj=α^3=-α, neither equals 2, i≠j, and α^si-α^sj=2α is neither 1 nor 2; it gives δ(α-α^3)=δ(2α)=2t^2=2. These two parts give different values for the same b, and direct computation gives δ(2α)=1. Thus the case split in Lemma 4 is unsound, and the same defect propagates through the analogous omitted proofs.
  3. [Lemmas 4, 5, 7, 8] The proofs of Lemmas 4, 5, 7, and 8 are entirely omitted with the sentence 'omitting the detailed proof' or 'similar derivations omitted.' These lemmas contain the core curve-counting and support-location arguments for all p>2 cases and for the boomerang spectrum in characteristic 2. Given that the one fully displayed proof (Lemma 3) rests on the false Lemma 2, the unverified lemmas cannot be accepted as routine; they are substantial, load-bearing components of Theorems 2-6.
  4. [Theorems 1-6 and Conclusion] The conclusion states that the differential spectrum and boomerang spectrum are 'completely determined' for the whole family. The internal contradiction in Lemma 4 shows that at least one of the frequency tables is wrong for p=3,m=1,t=1, and the false uniqueness lemma invalidates the zero-frequency counts in every characteristic. The claimed completeness is therefore not merely unproven; it is contradicted by a concrete example within the stated parameter range.
minor comments (3)
  1. [Throughout] The manuscript contains many typographical errors that impede reading: for example, in Lemma 2 the statement mixes 'k, m' and 'n=2km' while the rest of the paper uses n=2m; in Lemma 8(ii) the exponent '2m+1' should presumably be '(p^m+1)/3' or similar; several tables write '2n' and '3n' where the context indicates powers p^n or 2^{2m}.
  2. [Equation (1)] The sums in (1) are stated with δ as both index bound and differential uniformity; this is standard but the notation ω_i requires δ to be known, and the text should clarify that the identity is used only after the possible values of δ(1,b) are established.
  3. [Examples] Examples 1-4 report spectra for specific parameters, but no code or verifiable computation is included, and the examples do not cover the p=3,m=1 case where the formulas conflict; more systematic verification, such as a Magma or Sage script, would have helped detect the inconsistency.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the derivation is a direct rational-point count, and the only self-citation is an independent parameter-free theorem.

full rationale

The paper derives the differential and boomerang spectra of f(x)=x^{s(p^m-1)} by reducing each relevant equation to solution counts of curve families and by invoking the parameter-free rational-point-count Lemma 1 from [18]. That lemma is a prior theorem co-authored by one of the present authors, and it is load-bearing in the calculation, but it is not an input that assumes the target spectrum. Its statement is general, depends only on parameters n1, n2, r1, r2, t, and p, and does not contain the differential uniformity, boomerang uniformity, or any frequency value being derived. Under the provided rules, a self-citation that is parameter-free and whose assumptions do not include the target result is independent support and does not create circularity, even when the citation is mathematically essential. No parameter is fitted to data and subsequently renamed a prediction: the frequency counts are obtained from explicit point counts plus the standard identities in Equation (1). The examples are independent numerical confirmations rather than inputs. The false uniqueness assertion in Lemma 2 is a serious correctness concern that may invalidate the support arguments in Lemmas 3(v), 6(v), and related omitted proofs, but a false lemma is not an instance of circular reasoning and is better categorized as a correctness risk than as a circular step. Therefore no circular step is exhibited, and the score is 0.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

The derivation rests on the known rational-point formula (Lemma 1), a false uniqueness lemma (Lemma 2), and the standard index partition. No free parameters are fitted and no new entities are postulated.

assumptions (3)
  • domain assumption Lemma 1 (from [18]) gives exact counts of F_{p^n}-rational points on curves alpha x^{n1} + beta y^{n2} + 1 = 0.
    This is the primary counting tool used throughout the proofs. It is a published theorem, but the paper does not re-derive it.
  • ad hoc to paper Lemma 2 claims unique representation of sums alpha^i + alpha^j.
    This lemma is false for even-order roots where zero-sum collisions occur, e.g., p=3, m=1. It is used to assert that different index pairs yield different b values, which is load-bearing for the frequency counts.
  • standard math The sets C_{j1,j2} partition F_{p^n} \ {0, -1}.
    The partition by index residues modulo p^m+1 is a standard construction and is correctly stated.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Differential Spectrum and Boomerang Spectrum of Some Power Mapping." pith.science (2026). https://pith.science/paper/SHZ7J6VC

@misc{pith2026250605738,
  author       = {Pith},
  title        = {Pith review of: Differential Spectrum and Boomerang Spectrum of Some Power Mapping},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/SHZ7J6VC}},
  note         = {Machine review of arXiv:2506.05738}
}
abstract

Let $f(x)=x^{s(p^m-1)}$ be a power mapping over $\mathbb{F}_{p^n}$, where $n=2m$ and $\gcd(s,p^m+1)=t$. In \cite{kpm-1}, Hu et al. determined the differential spectrum and boomerang spectrum of the power function $f$, where $t=1$. So what happens if $t\geq1$? In this paper, we extend the result of \cite{kpm-1} from $t=1$ to general case. We use a different method than in \cite{kpm-1} to determine the differential spectrum and boomerang spectrum of $f$ by studying the number of rational points on some curves. This method may be helpful for calculating the differential spectrum and boomerang spectrum of some Niho type power functions.

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

21 extracted references · 21 canonical work pages

  1. [11]

    Hu, Z., Li, N., Xu, L., Zeng, X., Tang, X.: The differential spectrum and boomerang spectrum of a class of locally-APN functions. Des. Codes Cryptogr. 91(5), 1695-1711 (2023)

  2. [1]

    Finite Fields Appl

    Bracken, C., Byrne, E., Markin, N., McGuire, G.: New families of quadratic almost perfect nonlinear trinomials and multinomials. Finite Fields Appl. 14(3), 703-714 (2008)

  3. [2]

    Blondeau, C., Canteaut, A., Charpin, P.: Differential properties of power functions. Int. J. Inf. Coding Theory. 1, 149-170 (2010)

  4. [3]

    IEEE Trans

    Blondeau, C., Canteaut, A., Charpin, P.: Differential properties of x 7→ x2t−1. IEEE Trans. Inf. Theory, 57(12), 8127-8137 (2011)

  5. [4]

    Biham, E., Shamir, A.: Differential cryptanalysis of DES-like cryptosystems. J. Cryptol. 4(1), 3-72 (1991)

  6. [5]

    IEEE Trans

    Budaghyan, L., Carlet, C., Helleseth, T., Li, N., Sun, B.: On upper bounds for algebraic degrees of APN functions. IEEE Trans. Inf. Theory 64(6), 4399-4411 (2017)

  7. [6]

    IEEE Trans

    Carlet, C.: Characterizations of the differential uniformity of vectorial functions by the Walsh trans- form. IEEE Trans. Inf. Theory 64(6), 6443-6453 (2017)

  8. [7]

    In: Nielsen, J.B., Rijmen, V

    Cid, C., Huang, T., Peyrin, T., Sasaki, Y., Song, L.: Boomerang connectivity table: A new crypt- analysis tool. In: Nielsen, J.B., Rijmen, V. (eds.) Advances in Cryptology - EUROCRYPT 2018 -37th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Tel Aviv, Israel, April 29 - May 3, 2018 Proceedings, Part II, volume ...

Show all 21 references
  1. [8]

    Charpin, P., Peng, J.: Differential uniformity and the associated codes of cryptographic functions. Adv. Math. Commun. 13(4), 579-600 (2019)

  2. [9]

    IEEE Trans

    Dobbertin, H., Helleseth, T., Kumar, P.V., Martinsen, H.: Ternary m-sequences with three-valued cross-correlation function: new decimations of Welch and Niho type. IEEE Trans. Inf. Theory 47(4), 1473-1481 (2001)

  3. [10]

    Cryptogr

    Eddahmani, S., Mesnager, S.: Explicit values of the DDT, the BCT, the FBCT, and the FBDT of the inverse the gold and the Bracken–Leander S-boxes. Cryptogr. Commun. 14(6), 1301-1344 (2022)

  4. [12]

    Cryptogr

    Jiang, S., Li, K., Li, Y., Qu, L.: Differential and boomerang spectrums of some power permutations. Cryptogr. Commun. 14, 371-393 (2022)

  5. [13]

    IEEE Trans

    Li, K., Qu, L., Sun, B., Li, C.: New results about the boomerang uniformity of permutation poly- nomials. IEEE Trans. Inf. Theory 65(11), 7542-7553 (2019)

  6. [14]

    Cryptogr

    Mesnager, S., Mandal, B., Msahli, M.: Survey on recent trends towards generalized differential and boomerang uniformities. Cryptogr. Commun. 1-45 (2022)

  7. [15]

    in Workshop on the Theory and Application of of Cryptographic Techniques, Berlin, Germany:Springer, 1993

    Nyberg, K.: Differentially uniform mappings for cryptography. in Workshop on the Theory and Application of of Cryptographic Techniques, Berlin, Germany:Springer, 1993. 17

  8. [16]

    IEEE Trans

    Tang, C., Ding, C., Xiong, M.: Codes, Differentially δ-Uniform Functions, and t-Designs. IEEE Trans. Inf. Theory 66(6), 3691-3703 (2019)

  9. [17]

    In: Knudsen, L.R

    Wagner, D.A.: The boomerang attack. In: Knudsen, L.R. (ed.) Fast Software Encryption, 6th International Workshop, FSE ’99, Rome, Italy, March 24-26, 1999, Proceedings, volume 1636 of Lecture Notes in Computer Science, pp. 156-170. Springer (1999)

  10. [18]

    Wang, L., Luo, J.: Rational points and zeta functions of some curves over finite fields. Sci. China Math 53, 2855-2863 (2010)

  11. [19]

    Yan, H., Li, Z., Song, Z., Feng, R.: Two classes of power mappings with boomerang uniformity 2. Adv. Math. Commun. 16(4), 1111-1120 (2022)

  12. [20]

    IEEE Trans

    Yan, H., Xia, Y., Li, C., Helleseth, T., Xiong, M., Luo, J.: The Differential Spectrum of the Power Mapping xpn−3. IEEE Trans. Inf. Theory 68(8), 5535-5547 (2022)

  13. [21]

    In: 10th International Workshop on Signal Design and Its Applications in Communications (IWSDA), pp

    Yan, H., Zhang, Z., Li, Z.: Boomerang spectrum of a class of power functions. In: 10th International Workshop on Signal Design and Its Applications in Communications (IWSDA), pp. 1–4 (2022) 18

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.