Pith. sign in

REVIEW 3 major objections 3 minor 33 references

A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums

T0 review · 3 major / 3 minor · reviewed 2026-08-12 · deepseek-v4-flash

Pith's one-line read The paper introduces trace rational blocks and claims explicit Kloosterman-sum characterizations for three classes of Dillon-like bent functions.

desk verdict The reader's rejection rests on a misreading—the trace-zero step works because a1 lies in F_q, so the central theorems likely survive and the paper deserves refereeing. read the letter →

arxiv 2411.15750 v1 pith:XTCUICAH submitted 2024-11-24 cs.DM

classification cs.DM MSC 94A6011T7106E3011T23
keywords bentfunctionsDillon-likeexponentsKloostermansumstracerationalBooleanWalshtransformEAequivalence
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Bent functions are Boolean functions on even-dimensional spaces that sit as far as possible from every affine function; they are central to coding theory and cryptography. This paper introduces a family of trace rational blocks $f(x)=\mathrm{Tr}^{2n}_1(a/(x^{2^n-1}+b))$ on $\mathbb{F}_{2^{2n}}$ and claims that certain products and sums of these blocks are bent exactly when the parameters satisfy explicit conditions expressed through binary Kloosterman sums. The three classes it characterizes are the single block, a product of two blocks, and the symmetric pairwise sum of three blocks. If these characterizations are correct, they are the first bent functions built from these rational blocks, and they include functions not equivalent to the known monomial bent functions.

What carries the argument

The carrying object is the exponential sum $\xi(a,b)=\sum_{\lambda\in\mathbb{U}}(-1)^{\mathrm{Tr}^{2n}_1(a/(\lambda+b))}$ on the unit circle $\mathbb{U}=\{\lambda\in\mathbb{F}_{q^2}:\lambda^{q+1}=1\}$. Lemma II.5 evaluates this sum in three regimes — $b\in\mathbb{U}$ with $\mathrm{Tr}^{2n}_n(ab)=0$, $b\in\mathbb{U}$ with nonzero trace, and $b\notin\mathbb{U}$ — in terms of the binary Kloosterman sum $K_n(a)=\sum_{x\in\mathbb{F}_{2^n}}(-1)^{\mathrm{Tr}^n_1(1/x+ax)}$. Together with the Walsh-transform reduction of Proposition II.4 (a Dillon-like function is bent iff the signed unit-circle sum equals $(-1)^{f(0)}$), this turns bentness of the block combinations into exact equalities involving Kloosterman sums.

What would settle it

Take n=3, q=8, b=1, a1 in the subfield with trace 1, and a2 outside the subfield with absolute trace 1; substituting into Eq. (III.3) gives left-hand side 2 and right-hand side -2, so h2 would not be bent even though it satisfies the conditions of Theorem III.2(1).

Watch

Extended reading notes

Core claim

The central claim is that, for $q=2^n$ and $b\in\mathbb{F}_{q^2}^*$, the function $h_2(x)=\mathrm{Tr}^{2n}_1(a_1/(x^{q-1}+b))\cdot\mathrm{Tr}^{2n}_1(a_2/(x^{q-1}+b))$ is bent exactly when one of three parameter conditions holds — for instance $b=1$, $\mathrm{Tr}^n_1(a_1)=1$, and $a_2\in\mathbb{F}_{q^2}\setminus\mathbb{F}_q$ — and that the symmetric sum $h_3(x)=\sum_{i<j}\mathrm{Tr}^{2n}_1(a_i/(x^{q-1}+b))\mathrm{Tr}^{2n}_1(a_j/(x^{q-1}+b))$ is bent under six listed conditions. The route is to reduce the Walsh transform of any Dillon-like function to a signed sum over the unit circle $\mathbb{U}=\{x:x^{q+1}=1\}$ (Proposition II.4), then to evaluate the exponential sums $\xi(a,b)$ that arise, with Lemma II.5 connecting them to the binary Kloosterman sum $K_n$. The paper also derives the ordinary polynomial form of the single block $h_1$, showing it is a full Dillon-type sum, and reports computational checks that the new classes are not EA-equivalent to the five known monomial bent classes.

Load-bearing premise

The b=1 cases of Theorems III.2 and III.3 rely on the premise that any element outside the subfield has absolute trace zero, which forces the initial values h2(0) and h3(0) used in the proof.

Editorial extensions

If this is right

  • If Theorem III.1 holds, the single trace-rational block is bent exactly under the two listed conditions, making $K_n$ the deciding quantity for the $b\notin\mathbb{U}$ case.
  • If Theorem III.2 holds, products of two distinct blocks are bent in exactly the three listed regimes, with the outside-unit-circle regime ruled out for $n\ge 6$.
  • If Theorem III.3 holds, the symmetric sum of three blocks admits the six stated parameter families, including a four-Kloosterman-sum relation when $b\notin\mathbb{U}$.
  • The paper's polynomial-form derivation implies the single-block class has every Dillon exponent present, distinguishing it from earlier fixed-term Dillon-like constructions.
  • The reported equivalence checks indicate the three classes are not EA-equivalent to the known monomial bent classes on the tested fields.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The identity (III.1) is a general Fourier-inversion criterion: for any reduced polynomial $F$, bentness of $F(f_1,\dots,f_t)$ is equivalent to an explicit linear equation in the $\xi$-values, so the same machinery can produce characterizations for $F$ of higher degree.
  • The explicit polynomial form (IV.2) gives a concrete way to test EA-inequivalence beyond the computationally feasible fields: comparing its coefficient set with Eq. (IV.1) on $\mathbb{F}_{2^{12}}$ or larger would resolve the open question the paper leaves.
  • Because the range of $K_n(a)$ is completely known, the criteria are finitely checkable; an exhaustive small-$n$ enumeration of the parameter triples and quadruples would let one compile a catalogue of the new bent functions and check their duals, which Proposition II.4 makes easy to compute.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 3 minor

Summary. The paper introduces a family H of rational trace functions on F_{2^{2n}} of the form Tr^{2n}_1(a/(x^{2^n-1}+b)) and studies the bentness of Dillon-like Boolean functions built from these blocks via reduced polynomials F. It states an explicit exponential-sum formula (Lemma II.5) for ξ(a,b) and uses it to characterize three classes: h1=Tr^{2n}_1(a1/(x^{q-1}+b)) (Theorem III.1), h2=f1 f2 (Theorem III.2), and h3=f1 f2 + f1 f3 + f2 f3 (Theorem III.3). The h1 characterization and the b∉U cases are not affected by the issue discussed below, but the b∈U branches of Theorems III.2 and III.3 rest on an incorrect identity in Lemma II.5. The specific reviewer objection that h2(0) need not vanish in Theorem III.2(1) does not land: for a1∈F_q one has Tr^{2n}_1(a1)=Tr^n_1(a1+a1^q)=0, so h2(0)=0 automatically. The load-bearing problem lies instead in the claimed equivalence used to prove Eq. (II.7).

Significance. If the characterizations were correct, the paper would be significant: it would give the first bent functions assembled from rational trace blocks, with Kloosterman-sum characterizations and concrete examples of functions apparently not EA-equivalent to known monomial bent functions. The paper does not rely on circular arguments or fitted parameters, and the h1 result and the b∉U parts of the proofs are plausible. However, the central b∈U branch of the key exponential-sum lemma is false, and Theorem III.2 is false as stated for b∈U\{1}; Theorem III.3 is at least unproved and very likely false in the same branch. Since these are the main claimed characterizations, the paper cannot be accepted in its present form.

major comments (3)
  1. [Section II, Lemma II.5, Eq. (II.7)] The proof of Lemma II.5 uses the assertion that for b∈U, a^{q-1}b^2=1 is equivalent to Tr^{2n}_n(ab)=0. This is false for b≠1. For a concrete counterexample with q=4, let ζ be a primitive 5th root of unity in F_{16}, set b=ζ and a=ζ^{-1}. Then ab=1, so Tr^{4}_2(ab)=0; but a^{q-1}b^2 = ζ^{-3}ζ^2 = ζ^4 ≠ 1. Consequently Eq. (II.7) as printed is wrong: in this example the first line would give ξ(a,b)=1+(-1)^{Tr^2_1(a\bar a)}q = 1+4 = 5, while the reduction ξ(a,b)=ξ(a\bar a, a^{q-1}b^2) with a\bar a=1 and a^{q-1}b^2∈U\{1} gives ξ=1 by Eq. (II.8). The correct case distinction for b∈U depends on c=a^{q-1}b^2 (c=1 versus c≠1), not on Tr^{2n}_n(ab); for b∈U\{1} and Tr^{2n}_n(ab)=0 one always has c≠1, hence ξ(a,b)=1.
  2. [Section III, Theorem III.2] Because of the error in Eq. (II.7), the proof of Theorem III.2 in the case b∈U\{1} is invalid, and conditions (2) and (3) are false. With the correct ξ-values, every a satisfying Tr^{2n}_n(ab)=0 (when b∈U\{1}) has ξ(a,b)=1. In the situation of conditions (2) and (3) this makes ξ(a1,b)=ξ(a2,b)=ξ(a1+a2,b)=1, so the left-hand side of Eq. (III.3) equals q+1+1+1−1 = q+2, which cannot equal 2(−1)^{h2(0)} = ±2 for q≥2. Thus h2 is not bent under these parameter conditions, contradicting the stated 'if and only if' and the corresponding triples in Example 2.
  3. [Section III, Theorem III.3] The same incorrect ξ-values are used in the b∈U\{1} subcases of Theorem III.3. In particular, condition (5) requires only Tr^{2n}_n(a2/b)≠0, Tr^{2n}_n(a3/b)≠0 and Tr^{2n}_n((a1+a2+a3)/b)≠0; it does not prevent a2^{q-1}b^2, a3^{q-1}b^2, or (a1+a2+a3)^{q-1}b^2 from being 1. When such an element has c=1, its ξ-value is 1+(−1)^{Tr^n_1(a\bar a)}q rather than 1, so the right-hand side of Eq. (III.6) is not forced to be 2. The proof's claims that the listed conditions are necessary and sufficient for these subcases (also repeated in Remark 1) are therefore not established, and Theorem III.3 as stated is not supported.
minor comments (3)
  1. [Section II, Eq. (II.7)] The notation rendered as 'a/a' in the first branch of Eq. (II.7) is ambiguous; it should be a\bar a (the field-theoretic norm to F_q), and this should be defined explicitly at first use.
  2. [Section III, Remark 1] Remark 1 states that the conditions in Theorem III.3 are 'sufficient and necessary', but the theorem itself is written only as an 'if' statement; the paper should either strengthen the theorem or weaken the remark.
  3. [Section IV] The text says 'Section IV discusses the EA equivalence, and Section IV concludes the paper'; the second reference should be to Section V.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the bentness characterizations are derived from independent exponential-sum and Kloosterman-sum calculations, not from fitted parameters or self-citations.

full rationale

The paper's derivation chain is self-contained. The central reduction is Proposition II.4, which reformulates bentness of a Dillon-like function f(x)=g(x^{q-1}) as the unit-circle condition sum_{\lambda\in U} (-1)^{g(\lambda)}=(-1)^{f(0)}. This proposition is proved directly from the Walsh-transform formula in Proposition II.3 and is not assumed from any cited source as a black box. The subsequent exponential-sum machinery is likewise independent: Lemma II.3 derives a Kloosterman-sum identity from character-sum manipulations; Lemma II.4 computes the rational-function sum S = sum (-1)^{Tr(Ax+B)/(x^2+x+\delta)} in terms of Kloosterman sums with its own proof; and Lemma II.5 converts the unit-circle sums \xi(a,b) into Kloosterman values using Lemmas II.1-II.4. All of these lemmas have stated hypotheses involving a,b,A,B,\delta only, and none of the hypotheses include the bentness of the target functions. Theorems III.1-III.3 then evaluate Eq. (III.1) by substituting the explicit expressions from Lemma II.5 and solving the resulting equations for the parameters. For example, in Theorem III.2 the condition Tr_1^n(a_1)=1 and a_2\notin F_q arises algebraically from \Theta = 2+q(1+(-1)^{Tr_1^n(a_1)}) in the case b=1, while the case b\in U\setminus\{1\} is split according to whether Tr_{2n}^n(a_2b) and Tr_{2n}^n((a_1+a_2)b) vanish. These are genuine necessary-and-sufficient reductions, not fitted parameters renamed as predictions. Theorem III.3(6) is a characterization statement: it expresses h_3 being bent as an explicit equation involving four Kloosterman sums. Since bentness is defined by the Walsh transform and the equation is derived from Eq. (III.1) and Lemma II.5, the equivalence is a substantive reduction rather than a definitional tautology. The citations to Li et al. [21] and to the authors' own monograph and papers provide background, prior criteria, and related constructions, but the present proofs do not rely on any load-bearing uniqueness theorem from those works, nor is any ansatz imported solely through a citation. In particular, no parameter is fit to data and later reported as a prediction, and the characterizations are not assumed in the hypotheses of the lemmas. The paper does claim experimental evidence of EA-inequivalence, but that is an ancillary observation and is not part of the derivation chain being assessed.

Assumptions & free parameters 0 free parameters · 5 assumptions · 0 invented entities

The central claims rest on standard Kloosterman-sum bounds and finite-field lemmas (Lachaud-Wolfmann, Rosendahl, quadratic-equation counting). No free parameters are fitted to data. The proofs additionally rely on an implicit, false assumption that elements outside F_q have zero absolute trace; this is flagged as a red flag rather than a ledger axiom.

assumptions (5)
  • standard math Binary Kloosterman sums take exactly the multiples of 4 in the interval [-2^{n/2+1}+1, 2^{n/2+1}+1] (Lachaud-Wolfmann).
    Used in Theorem III.1 to infer K_n(...)=0 from 1-K_n(...)=±1, and in Theorem III.2 to bound |K_n| for excluding b not in U.
  • standard math For b in F_q, the absolute trace of b/(1+b^2) is 0 whenever the quadratic x^2+(b+b^{-1})x+1 has roots in F_q.
    Justifies a substitution in the proof of Lemma II.5, case b in F_q, where the constant term b/(1+b^2) is dropped from the trace condition.
  • standard math Rosendahl's parametrization U\{1} = {(u+A)/(u+\bar{A}) : u in F_q} and Lemma II.2 counting solutions on the unit circle.
    Used in Lemma II.5 to compute M(a,b) via the substitution z=(u+A)/(u+\bar{A}).
  • standard math Walsh inversion formula for the reduced polynomial F, used to express sums over U of (-1)^{F(...)} as combinations of xi(a,b).
    Derives Eq (III.1), the starting point for all three theorems.
  • domain assumption Proposition II.1 (Carlet-Gaborit / Youssef-Gong) connecting hyper-bent functions to weight sums.
    Used in the discussion after Proposition II.4 to note Dillon-like bent functions are hyper-bent; not needed for the main theorem proofs.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums." pith.science (2026). https://pith.science/paper/XTCUICAH

@misc{pith2026241115750,
  author       = {Pith},
  title        = {Pith review of: A Novel Approach for Bent Functions with Dillon-like Exponents and Characterizing Three Classes of Bent Functions via Kloosterman Sums},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/XTCUICAH}},
  note         = {Machine review of arXiv:2411.15750}
}
abstract

Dillon-like Boolean functions are known, in the literature, to be those trace polynomial functions from $\mathbb{F}_{2^{2n}}$ to $\mathbb{F}_{2}$, with all the exponents being multiples of $2^n-1$ often called Dillon-like exponents. This paper is devoted to bent functions in which we study the bentness of some classes of Dillon-like Boolean functions connected with rational trace functions. Specifically, we introduce a special infinite family of trace rational functions. We shall use these functions as building blocks and generalise notably a criterion due to Li et al. published in [IEEE Trans. Inf. Theory 59(3), pp. 1818-1831, 2013] on the bentness of Dillon-like functions in the binary case, we explicitly characterize three classes of bent functions. These characterizations are expressed in terms of the well-known binary Kloosterman sums. Furthermore, analysis and experiments indicate that new functions not EA-equivalent to all known classes of monomial functions are included in our classes.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

33 extracted references · 33 canonical work pages

  1. [1]

    Alahmadi, H

    A. Alahmadi, H. Akhazmi, T. Helleseth, R. Hijazi, N.M. Mu thana, P . Sol´ e, On the lifted Zetterberg code, Des. Codes Cryptogr. 80(3), pp. 561-576, 2016

  2. [2]

    Canteaut, P

    A. Canteaut, P . Charpin, G. Kyureghyan, A new class of mon omial bent functions, Finite Fields Appl. 14(1), pp. 221-241, 2008

  3. [3]

    Charpin, G

    P . Charpin, G. Kyureghyan, Cubic monomial bent function s: A subclass of M, SIAM. J. Discr. Math. 22(2), pp. 650-665, 2008

  4. [4]

    Charpin, G

    P . Charpin, G. Gong, Hyperbent functions, Kloosterman s ums and Dickson polynomials, IEEE Trans. Inf. Theory 54(9), pp. 4230-4238, 2008

  5. [5]

    Charpin, E

    P . Charpin, E. Pasalic, C. Tavernier, On bent and semi-be nt quadratic boolean functions, IEEE Trans. Inf. Theory 51(12), pp. 4286-4298, 2005

  6. [6]

    Carlet, E

    C. Carlet, E. Prouff, On plateaued functions and their co nstructions, T. Johansson (Ed.): FSE 2003, LNCS 2887, pp. 54-73, 2003

  7. [7]

    Carlet, On bent and highly nonlinear balanced/resili ent functions and their algebraic immunities, in AAECC (Lec ture Notes in Computer Science), vol

    C. Carlet, On bent and highly nonlinear balanced/resili ent functions and their algebraic immunities, in AAECC (Lec ture Notes in Computer Science), vol. 3857, M. P . C. Fossorier, H. Imai, S. Lin, and A. Poli, Eds. New Y ork, NY , USA: Springer-V erlag, 2006, pp. 1-28

  8. [8]

    Carlet, P

    C. Carlet, P . Gaborit, Hyper-bent functions and cyclic c odes, J. Combin. Theory Ser. A (113), pp. 466-482, 2006

Show all 33 references
  1. [9]

    L. E. Dickson, History of the theory of numbers, V ol. 1, Ch elsea, New Y ork, 1952

  2. [10]

    Dillon, Elementary Hadamard difference sets, PhD di ssertation, University of Maryland

    J. Dillon, Elementary Hadamard difference sets, PhD di ssertation, University of Maryland

  3. [11]

    Dillon, H

    J. Dillon, H. Dobbertin, New cyclic difference sets wit h Singer parameters, Finite Fields Appl. 10(3), pp. 342-389 , 2004. 26

  4. [12]

    Dobbertin, G

    H. Dobbertin, G. Leander, A. Canteaut, C. Carlet, P . Fel ke, P . Gaborit, Construction of bent functions via Niho powe r functions, J. Combin. Theory Ser. A (113), pp. 779-798, 2006

  5. [13]

    Dodunekov, J.E.M

    S.M. Dodunekov, J.E.M. Nilsson, Algebraic decoding of the Zetterberg codes, IEEE Trans. Inf. Theory 38(5), pp. 1570-1573, 1992

  6. [14]

    Fine, Binomial coefficients modulo a prime, Am

    N.J. Fine, Binomial coefficients modulo a prime, Am. Mat h. Monthly, 54, pp. 589-592, 1947

  7. [15]

    Gold, Maximal recursive sequences with 3-valued rec ursive crosscorrelation functions, IEEE Trans

    R. Gold, Maximal recursive sequences with 3-valued rec ursive crosscorrelation functions, IEEE Trans. Inf. Theor y 14(1), pp. 154-156, 1968

  8. [16]

    Kumar, R.A

    P .V . Kumar, R.A. Scholtz, L.R. Welch, Generalized bent functions and their properties, J. Combin. Theory Ser. A (40 ), pp. 90-107, 1985

  9. [17]

    R. Lidl, H. Niederreiter, Finite Fields, Encyclopedia Math. Appl. Cambridge University Press, 1997

  10. [18]

    Leander, Monomial bent functions, IEEE Trans

    G. Leander, Monomial bent functions, IEEE Trans. Inf. T heory 52(2), pp. 738-743, 2006

  11. [19]

    Leander, A

    G. Leander, A. Kholosha, Bent functions with 2r Niho exponents, IEEE Trans. Inf. Theory 52(12), pp. 5529-55 32, 2006

  12. [20]

    Lachaud, J

    G. Lachaud, J. Wolfmann, The weights of the orthogonals of the extended quadratic binary Goppa codes, IEEE Trans. Inf. Theory 36(3), pp. 686-692, 1990

  13. [21]

    N. Li, T. Helleseth, X. Tang, A. Kholosha, Several new cl asses of bent functions from Dillon exponents, IEEE Trans. Inf. Theory 59(3), pp. 1818-1831, 2013

  14. [22]

    Mesnager, Bent functions-Fundamentals and Results , Springer Cham, Switzerland, 2016

    S. Mesnager, Bent functions-Fundamentals and Results , Springer Cham, Switzerland, 2016

  15. [23]

    Mesnager, A new class of bent and hyper-bent Boolean f unctions in polynomial forms, Des

    S. Mesnager, A new class of bent and hyper-bent Boolean f unctions in polynomial forms, Des. Codes Cryptogr. 59, pp. 265-279, 2011

  16. [24]

    Mesnager, Bent and hyper-bent functions in polynomi al form and their link with some exponential sums and Dickson polynomials, IEEE Trans

    S. Mesnager, Bent and hyper-bent functions in polynomi al form and their link with some exponential sums and Dickson polynomials, IEEE Trans. Inf. Theory 57(9), pp. 5996-6009, 2011

  17. [25]

    Rothaus, On bent functions, J

    O.S. Rothaus, On bent functions, J. Combin. Theory Ser. A (20), pp. 300-305, 1976

  18. [26]

    Rosendahl, Niho type cross-correlation functions a nd related equations, PhD dissertation, Univ

    P . Rosendahl, Niho type cross-correlation functions a nd related equations, PhD dissertation, Univ. Turku, Turku, Finland, 2004

  19. [27]

    Schmidt, M.G

    K.U. Schmidt, M.G. Parker, A. Pott, Negabent functions in the Maiorana-McFarland Class, S.W. Golomb et al. (Eds.): SETA 2008, LNCS 5203, pp. 390-402, 2008

  20. [28]

    Z. Tu, X. Zeng, C. Li, T. Helleseth, A class of new permuta tion trinomials, Finite Fields Appl. 50, pp. 178-195, 2018

  21. [29]

    C. Tang, Z. Zhou, Y . Qi, X. Zhang, C. Fan, T. Helleseth, Ge neric construction of Bent functions and Bent idempotents with any possible algebraic degrees, IEEE Trans. Inf. Theor y 63(10), pp. 6149-6157 , 2017

  22. [30]

    Y oussef, G

    A.M. Y oussef, G. Gong, Hyper-bent functions, Advances in Cryptology-Eurocrypt 2001, Lecture Notes in Computer Science, vol. 2045, Springer, Berlin, pp. 406-419, 2001

  23. [31]

    N.Y . Y u, G. Gong, Constructions of quadratic bent funct ions in polynomial forms, IEEE Trans. Inf. Theory 52(7), pp. 3291-3299, 2006

  24. [32]

    L. Y u, H. Liu, D. Zheng, On more bent functions from Dillo n exponents, Appl. Algebra Eng. Commun. Comput. 26, pp. 389-408, 2015

  25. [33]

    Zheng, X

    Y . Zheng, X. Zhang, Plateaued Functions, Plateaued Fun ctions, V . V aradharajan and Y . Mu (Eds.): ICICS’99, LNCS 1726, pp. 284-300, 1999. APPENDIX A1: T HE EXPLICIT ORDINARY POLYNOMIAL FORM OF h1 To deduce the explicit polynomial form of h1, a basic fact is that for integer...

Pith tools

Reviewed August 12, 2026 · model on record in the stance chip above.