Bent Functions and Permutation Methods: Binary and Multiple-Valued Bent Functions (Synthesis Lectures on Engineering, Science, and Technology) [2024 ed.] 3031506499, 9783031506499

This book discusses in a uniform way binary, ternary, and quaternary bent functions, while most of the existing books on

113 34 6MB

English Pages 291 [287] Year 2024

Report DMCA / Copyright

DOWNLOAD PDF FILE

Table of contents :
Preface
Contents
List of Figures
List of Tables
1 Basic Concepts and Notations
[DELETE]
1.1 Discrete Functions
1.2 Functional Expressions
1.3 Reed–Muller–Fourier Expressions
1.3.1 RMF-Expressions for Ternary Functions
1.3.2 RMF-Expressions for Quaternary Functions
1.4 Fourier Transforms on Finite Abelian Groups
1.5 Fast Fourier Transform
1.6 Binary Bent Functions
1.7 Ternary Bent Functions
1.8 Quaternary Bent Functions
1.9 Distribution of Function Values and Bentness
1.10 Spectral Invariant Operations
2 Gibbs Derivatives on Finite Abelian Groups
[DELETE]
2.1 Gibbs Derivative for Binary Functions
2.2 Computing the Dyadic Gibbs Derivative
2.3 Gibbs Derivative for Ternary Functions
2.4 Galois Field Gibbs Derivative for Ternary Functions
2.5 Gibbs Derivatives for Quaternary Functions
2.6 Gibbs RMF-Derivative for Quaternary Functions
3 Gibbs Characterization of Binary Bent Functions
[DELETE]
3.1 Properties of the Gibbs Dyadic Derivative of Bent Functions
3.2 Checking if a Binary Function is Bent by Using the Gibbs Dyadic Derivative
3.3 Gibbs Permutation Matrices
3.4 Structure of Gibbs Permutation Matrices
3.5 Binary Bent Functions in Four Variables
4 Gibbs Characterization of Ternary Bent Functions
[DELETE]
4.1 Ternary Bent Functions for n equals 1n=1
4.2 Spectral Invariant Operations and Ternary Bent Functions
4.3 Gibbs Characterization of Ternary Bent Functions
4.3.1 Ternary Bent Functions for n equals 1n=1 and Gibbs Derivatives
4.3.2 Ternary Bent Functions for n equals 2n=2 Characterized by the VC-Gibbs Derivative
4.4 Gibbs Permutation Matrices for Ternary Functions
4.5 Extensions to Any Number of Variables
4.6 Construction Algorithm
4.7 The Galois Field Gibbs Derivatives and Ternary Bent Functions
4.8 Gibbs Characterization of Ternary Functions and Distribution of Function Values
5 Gibbs Characterization of a Class of Quaternary Bent Functions
[DELETE]
5.1 Quaternary Bent Functions for n equals 1n=1
5.1.1 Classes of Quaternary Bent Functions for n equals 1n=1 in Terms of the RMF-Gibbs Derivative
5.1.2 Classes of Quaternary Bent Functions for n equals 1n=1 in Terms of the VC-Gibbs Derivative
5.2 Quaternary Bent Functions for n equals 2n=2
5.3 Experiments for Quaternary Bent Functions in n equals 2n=2 Variables
5.4 Binary and Quaternary Bent Functions
5.5 Generalized Four-Valued Bent Functions
5.6 Construction of Generalized Boolean Bent Functions
5.6.1 Straightforward Algorithm
5.6.2 Construction by Permutation Matrices
5.6.3 Construction of Bent Functions by Combination of Permutation Matrices
6 Matrix-Valued Binary Bent Functions
[DELETE]
6.1 Matrix-Valued Functions
6.1.1 Classification Method
6.2 Classes of Binary Bent Functions for n equals 4n=4
6.3 Classes of Binary Bent Functions for n equals 6n=6
6.3.1 left parenthesis 2 times 2 right parenthesis(2times2)-spectra for Binary Bent Functions for n equals 6n=6
6.3.2 left parenthesis 4 times 4 right parenthesis(4times4)-spectra for Binary Bent Functions for n equals 6n=6
6.4 Classes for Binary Bent Functions for n equals 8n=8
6.4.1 left parenthesis 2 times 2 right parenthesis(2times2)-spectra for Functions in n equals 8n=8 Variables
6.4.2 left parenthesis 4 times 4 right parenthesis(4times4)-spectra for Functions in n equals 8n=8 Variables
7 Matrix-Valued Ternary Bent Functions
[DELETE]
7.1 Matrix-Valued Equivalents of Bent Functions
7.1.1 Similarity of Ternary Bent Functions
7.1.2 Matrix-Valued Vilenkin–Chrestenson Coefficients of Linear Ternary Functions
7.2 Classification Approach for Ternary Bent Functions
7.3 Classes of Ternary Bent Functions for n equals 3n=3 and n equals 4n=4
7.3.1 left parenthesis 3 times 3 right parenthesis(3times3)-spectra for Ternary Bent Functions of the Degree 33 for n equals 3n=3
7.3.2 left parenthesis 3 times 3 right parenthesis(3times3)-spectra for Ternary Bent Functions of the Degree 44 for n equals 3n=3
7.3.3 left parenthesis 3 times 3 right parenthesis(3times3)-spectra for Ternary Functions for n equals 4n=4
7.3.4 Ternary Linear Functions and Ternary Bent Functions
7.4 Construction of Ternary Bent Functions from Ternary Linear Functions
8 Construction of Bent Functions by FFT-like Permutation Matrices
[DELETE]
8.1 FFT-like Permutation Matrices for Binary Bent Functions
8.2 Permutation Matrices for Disjoint Spectral Translation
8.3 Construction of Binary Bent Functions by FFT-like Permutation Matrices
8.4 Gibbs Matrices and FFT-like Permutation Matrices for Binary Functions
8.5 FFT-like Permutation Matrices for Ternary Bent Functions
8.5.1 Kronecker Product Representable Matrices
8.6 Computation with Permutation Matrices
8.7 Extensions to Functions in Arbitrary Number of Variables
8.7.1 Permutation Matrices for Disjoint Spectral Translation
8.7.2 Permutation Matrices for Permutation of Variables
8.7.3 Block Diagonal Permutation Matrices
8.7.4 Block Diagonal Permutation Matrices for n equals 4n=4
8.7.5 Shift-Based Permutation Matrices
8.8 Construction of Ternary Bent Functions by FFT-like Permutation Matrices
8.9 Generalizations
8.9.1 Permutation of Subvectors
8.10 Gibbs and FFT-like Permutation Matrices for Ternary Functions
9 Construction of Ternary Bent Functions From Matrix Representations
[DELETE]
9.1 Matrix Representations of Ternary Bent Functions
9.2 Construction of Ternary Bent Functions from Matrix …
Recommend Papers

Bent Functions and Permutation Methods: Binary and Multiple-Valued Bent Functions (Synthesis Lectures on Engineering, Science, and Technology) [2024 ed.]
 3031506499, 9783031506499

  • 0 0 0
  • Like this paper and download? You can publish your own PDF file online for free in a few minutes! Sign Up
File loading please wait...
Citation preview

Synthesis Lectures on Engineering, Science, and Technology

Radomir S. Stanković · Milena Stanković · Claudio Moraga · Jaakko Astola

Bent Functions and Permutation Methods Binary and Multiple-Valued Bent Functions

Synthesis Lectures on Engineering, Science, and Technology

The focus of this series is general topics, and applications about, and for, engineers and scientists on a wide array of applications, methods and advances. Most titles cover subjects such as professional development, education, and study skills, as well as basic introductory undergraduate material and other topics appropriate for a broader and less technical audience.

Radomir S. Stankovi´c · Milena Stankovi´c · Claudio Moraga · Jaakko Astola

Bent Functions and Permutation Methods Binary and Multiple-Valued Bent Functions

Radomir S. Stankovi´c Mathematical Institute of the Serbian Academy of Sciences and Arts Belgrade, Serbia

Milena Stankovi´c Faculty of Electronic Engineering University of Niš Niš, Serbia

Claudio Moraga Faculty of Computer Science TU Dortmund University Dortmund, Germany

Jaakko Astola Department of Computer Science Tampere University Tampere, Finland

ISSN 2690-0300 ISSN 2690-0327 (electronic) Synthesis Lectures on Engineering, Science, and Technology ISBN 978-3-031-50649-9 ISBN 978-3-031-50650-5 (eBook) https://doi.org/10.1007/978-3-031-50650-5 © The Editor(s) (if applicable) and The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 This work is subject to copyright. All rights are solely and exclusively licensed by the Publisher, whether the whole or part of the material is concerned, specifically the rights of translation, reprinting, reuse of illustrations, recitation, broadcasting, reproduction on microfilms or in any other physical way, and transmission or information storage and retrieval, electronic adaptation, computer software, or by similar or dissimilar methodology now known or hereafter developed. The use of general descriptive names, registered names, trademarks, service marks, etc. in this publication does not imply, even in the absence of a specific statement, that such names are exempt from the relevant protective laws and regulations and therefore free for general use. The publisher, the authors, and the editors are safe to assume that the advice and information in this book are believed to be true and accurate at the date of publication. Neither the publisher nor the authors or the editors give a warranty, expressed or implied, with respect to the material contained herein or for any errors or omissions that may have been made. The publisher remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. This Springer imprint is published by the registered company Springer Nature Switzerland AG The registered company address is: Gewerbestrasse 11, 6330 Cham, Switzerland Paper in this product is recyclable.

Preface

Bent functions are a particular subset of Boolean functions defined as the most non-linear n Boolean functions. Although constituting a very small portion of the total of 22 Boolean functions, where n is the number of variables, they are interesting mathematical objects offering many challenging tasks such as generation, characterization, classification, and counting bent functions. Due to high non-linearity, they also have some applications, since they can serve as a basis for deriving sequences with properties useful in cryptography. Therefore, bent functions and their various generalizations are a subject of intensive research activities. Although initial definitions of generalized bent functions from binary to p-valued cases are rather straightforward generalizations of the concepts from the theory of binary bent functions, a further study of them immediately leads to drastically different properties, which raises new challenges. There are differences among p-valued bent functions for different values of both p and n, starting from the basic questions such as existence to other particular features of p-valued bent functions. This book is concerned with bent functions for p = 2, 3, 4, which we call binary, ternary, and quaternary bent functions. These considerations are built around two main observations. First, in the binary case, the number of non-zero values in the truth-vector is strictly determined to two possible values. These values are related to the number of variables which in the binary case should be an even natural number. It follows that truth-vectors of binary bent functions with the same number of non-zero values are mutually related by permutations. There is an equivalent requirement for function values in the case of multiple-valued bent functions. For a p-valued bent function, the concept of composition specifies how many times each of p values appears in its function vector. The concept of distribution specifies how many times each value must appear in the function vector, however, without precisely pointing out which of the values appears how many times. Therefore, the distribution can be viewed as a more general concept in the sense that a distribution covers various compositions. Thus, p-valued bent functions with the same composition are mutually related by permutations, while those sharing the same distribution are related by the encoding of function values. v

vi

Preface

The second basic observation is that adding an affine function to a bent function preserves its bentness. In the spectral transform interpretation, this feature reads as preserving the flat spectrum in terms of the Walsh and the Vilenkin–Chrestenson transforms for the binary and p-valued cases, respectively, with these transforms uniformly viewed as Fourier transforms on the corresponding finite Abelian groups. A spectrum is called flat if the absolute values of all its spectral coefficients equal p (n/2) . Preserving the flatness directly leads to the spectral invariant operations, the implementation of which reduces to the permutations and sign changes of precisely determined subsets of spectral coefficients. Determining relationships among bent functions through permutations is the central topic of research presented in this book. This has a kind of practical application connotation, in the sense that given a bent function, we can construct some other bent functions by modifying it in terms of permutations. Overall, this appears to be an interesting and challenging task, which follows from the observation that for a p-valued function in n variables specified by the function vector of length p n there are p n ! permutations, while the number of bent functions is a very n small portion of the total number of p-valued functions p p . This implies that the permutations mutually relating bent functions must satisfy certain strong requirements, since there are so few that can be used out of many, which when expressed in terms of permutation matrices results in a particular structure of the corresponding matrices. Determining this structure and relating the corresponding permutation matrices to other mathematical concepts are explored. In the binary case, the Boolean derivatives of bent functions with respect to all the variables should be balanced Boolean functions. We observed that this requirement can be alternatively expressed in terms of the Gibbs dyadic derivative which is a differential operator defined in terms of the Walsh functions. It is often viewed as a hybrid operator in the sense that it converts a binary function in n Boolean variables into an integer-valued function defined in 2n points as its derivative. This facilitates the observation of permutations converting bent functions into each other and in this way also the determination of the structure of the related permutation matrices which we call the Gibbs permutation matrices. Permutations of function values by these permutation matrices correspond to performing a particular subset of spectral invariant operations, and, therefore, preserve bentness when applied to bent functions. Thus, these permutation matrices can be used in constructing bent functions by manipulating given bent functions. Permutations in the spectral domain preserving bentness can be associated with the corresponding permutations in the original domain with values to be permuted determined from steps in the related Fast Fourier Transforms (FFT) used to compute the spectral coefficients. These permutations can be expressed by matrices which are then called FFT-like permutation matrices. Permutations of function values by FFT-like permutation matrices correspond to another subset of spectral invariant operations, different from those performed by the Gibbs permutation matrices. Therefore, these two classes of permutation

Preface

vii

matrices complement each other when applied in constructing bent functions from given bent functions. When dealing with matrices and FFT, it appears natural to consider matrix-valued equivalents of function vectors of either binary or p-valued bent functions and computing with them relates to the implementation of certain steps of the FFT, resulting in patterns of function values in matrix-valued spectral coefficients. The appearance of identical patterns or patterns that can be related to each other by permutations and encoding is a basis for defining classes of bent functions similar to each other in this sense. The considered permutation matrices allow constructing bent functions by modifying given bent functions. The presentation in this book is based on the articles by the authors presented at Eurocast 2015, the International Symposia on Multiple Valued Logic from 2016 to 2023, as well as the 14th International Workshop on Boolean Problems, 2020, and it is organized as follows. Chapter 1 presents fundamentals on bent functions and their representations. Chapter 2 provides definitions of Gibbs derivatives which in the approach followed in this book are used as the main mathematical operator for dealing with bent functions. The characterization of binary, ternary, and quaternary bent functions in terms of Gibbs derivatives is discussed in Chaps. 3–5, respectively. Matrix-valued binary and ternary functions are introduced in Chaps. 6 and 7, respectively, and used to define an approach toward the classification of bent functions. Chapter 8 discusses the construction of bent functions by FFT-like permutation matrices. In Chap. 9, we briefly present some construction methods for ternary bent functions based on their different matrix representations. Niš, Serbia

Radomir S. Stankovi´c [email protected]

Niš, Serbia

Milena Stankovi´c [email protected]

Dortmund, Germany

Claudio Moraga [email protected]

Tampere, Finland

Jaakko Astola [email protected]

Contents

1 Basic Concepts and Notations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.1 Discrete Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.2 Functional Expressions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.3 Reed–Muller–Fourier Expressions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.3.1 RMF-Expressions for Ternary Functions . . . . . . . . . . . . . . . . . . . . . 1.3.2 RMF-Expressions for Quaternary Functions . . . . . . . . . . . . . . . . . . 1.4 Fourier Transforms on Finite Abelian Groups . . . . . . . . . . . . . . . . . . . . . . . 1.5 Fast Fourier Transform . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.6 Binary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.7 Ternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.8 Quaternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1.9 Distribution of Function Values and Bentness . . . . . . . . . . . . . . . . . . . . . . . 1.10 Spectral Invariant Operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

1 1 2 6 6 8 9 11 14 20 24 25 31 40

2 Gibbs Derivatives on Finite Abelian Groups . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.1 Gibbs Derivative for Binary Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.2 Computing the Dyadic Gibbs Derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.3 Gibbs Derivative for Ternary Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2.4 Galois Field Gibbs Derivative for Ternary Functions . . . . . . . . . . . . . . . . . 2.5 Gibbs Derivatives for Quaternary Functions . . . . . . . . . . . . . . . . . . . . . . . . 2.6 Gibbs RMF-Derivative for Quaternary Functions . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

45 47 49 49 51 56 57 60

3 Gibbs Characterization of Binary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . 3.1 Properties of the Gibbs Dyadic Derivative of Bent Functions . . . . . . . . . 3.2 Checking if a Binary Function is Bent by Using the Gibbs Dyadic Derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.3 Gibbs Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

63 70 71 72

ix

x

Contents

3.4 Structure of Gibbs Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . 3.5 Binary Bent Functions in Four Variables . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

76 78 84

4 Gibbs Characterization of Ternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . 4.1 Ternary Bent Functions for n = 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.2 Spectral Invariant Operations and Ternary Bent Functions . . . . . . . . . . . . 4.3 Gibbs Characterization of Ternary Bent Functions . . . . . . . . . . . . . . . . . . . 4.3.1 Ternary Bent Functions for n = 1 and Gibbs Derivatives . . . . . . . 4.3.2 Ternary Bent Functions for n = 2 Characterized by the VC-Gibbs Derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.4 Gibbs Permutation Matrices for Ternary Functions . . . . . . . . . . . . . . . . . . 4.5 Extensions to Any Number of Variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.6 Construction Algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4.7 The Galois Field Gibbs Derivatives and Ternary Bent Functions . . . . . . 4.8 Gibbs Characterization of Ternary Functions and Distribution of Function Values . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

85 86 86 92 94 95 100 106 112 113 114 119

5 Gibbs Characterization of a Class of Quaternary Bent Functions . . . . . . . . . 5.1 Quaternary Bent Functions for n = 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.1.1 Classes of Quaternary Bent Functions for n = 1 in Terms of the RMF-Gibbs Derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.1.2 Classes of Quaternary Bent Functions for n = 1 in Terms of the VC-Gibbs Derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.2 Quaternary Bent Functions for n = 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.3 Experiments for Quaternary Bent Functions in n = 2 Variables . . . . . . . 5.4 Binary and Quaternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.5 Generalized Four-Valued Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.6 Construction of Generalized Boolean Bent Functions . . . . . . . . . . . . . . . . 5.6.1 Straightforward Algorithm . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5.6.2 Construction by Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . 5.6.3 Construction of Bent Functions by Combination of Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

121 124

6 Matrix-Valued Binary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6.1 Matrix-Valued Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6.1.1 Classification Method . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6.2 Classes of Binary Bent Functions for n = 4 . . . . . . . . . . . . . . . . . . . . . . . . 6.3 Classes of Binary Bent Functions for n = 6 . . . . . . . . . . . . . . . . . . . . . . . . 6.3.1 (2 × 2)-spectra for Binary Bent Functions for n = 6 . . . . . . . . . . 6.3.2 (4 × 4)-spectra for Binary Bent Functions for n = 6 . . . . . . . . . .

151 154 155 158 160 160 166

124 128 130 136 137 138 139 140 141 142 149

Contents

xi

Classes for Binary Bent Functions for n = 8 . . . . . . . . . . . . . . . . . . . . . . . . 6.4.1 (2 × 2)-spectra for Functions in n = 8 Variables . . . . . . . . . . . . . . 6.4.2 (4 × 4)-spectra for Functions in n = 8 Variables . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

169 169 171 178

7 Matrix-Valued Ternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7.1 Matrix-Valued Equivalents of Bent Functions . . . . . . . . . . . . . . . . . . . . . . . 7.1.1 Similarity of Ternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . 7.1.2 Matrix-Valued Vilenkin–Chrestenson Coefficients of Linear Ternary Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7.2 Classification Approach for Ternary Bent Functions . . . . . . . . . . . . . . . . . 7.3 Classes of Ternary Bent Functions for n = 3 and n = 4 . . . . . . . . . . . . . . 7.3.1 (3 × 3)-spectra for Ternary Bent Functions of the Degree 3 for n = 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7.3.2 (3 × 3)-spectra for Ternary Bent Functions of the Degree 4 for n = 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7.3.3 (3 × 3)-spectra for Ternary Functions for n = 4 . . . . . . . . . . . . . . 7.3.4 Ternary Linear Functions and Ternary Bent Functions . . . . . . . . . 7.4 Construction of Ternary Bent Functions from Ternary Linear Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

181 181 182

8 Construction of Bent Functions by FFT-like Permutation Matrices . . . . . . . . 8.1 FFT-like Permutation Matrices for Binary Bent Functions . . . . . . . . . . . . 8.2 Permutation Matrices for Disjoint Spectral Translation . . . . . . . . . . . . . . . 8.3 Construction of Binary Bent Functions by FFT-like Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.4 Gibbs Matrices and FFT-like Permutation Matrices for Binary Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.5 FFT-like Permutation Matrices for Ternary Bent Functions . . . . . . . . . . . 8.5.1 Kronecker Product Representable Matrices . . . . . . . . . . . . . . . . . . . 8.6 Computation with Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.7 Extensions to Functions in Arbitrary Number of Variables . . . . . . . . . . . . 8.7.1 Permutation Matrices for Disjoint Spectral Translation . . . . . . . . 8.7.2 Permutation Matrices for Permutation of Variables . . . . . . . . . . . . 8.7.3 Block Diagonal Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . 8.7.4 Block Diagonal Permutation Matrices for n = 4 . . . . . . . . . . . . . . 8.7.5 Shift-Based Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.8 Construction of Ternary Bent Functions by FFT-like Permutation Matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

205 206 207

6.4

183 184 186 187 191 193 195 196 204

219 221 225 228 230 230 234 237 238 241 243 246

xii

Contents

8.9

Generalizations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.9.1 Permutation of Subvectors . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8.10 Gibbs and FFT-like Permutation Matrices for Ternary Functions . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

250 252 255 256

9 Construction of Ternary Bent Functions From Matrix Representations . . . . 9.1 Matrix Representations of Ternary Bent Functions . . . . . . . . . . . . . . . . . . . 9.2 Construction of Ternary Bent Functions from Matrix-Valued Ternary Bent Functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

259 259 264 272

List of Figures

Fig. 1.1 Fig. 1.2 Fig. 1.3 Fig. 2.1 Fig. 3.1 Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig. Fig.

8.1 8.2 8.3 8.4 8.5 8.6 8.7 8.8 8.9 8.10 8.11 8.12 8.13 8.14 8.15 8.16

Fig. 8.17 Fig. 8.18

Flow-graph of the basic computing operation in Cooley–Tukey Fast Walsh and Vilenkin–Chrestenson transforms . . . . . . . . . . . . . . . . . Flow-graph of the FWT for n = 5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph of the Fast Vilenkin–Chrestenson transform for ternary function and n = 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . FFT-like algorithm for computing the dyadic Gibbs derivative for n = 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . The permutation matrix assigned to the function f = x1 x2 ⊕ x2 x3 ⊕ x3 x4 in Example 3.10 . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with P2 and P4 . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with R1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with R2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with R3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with R4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with R5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q1,2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q2,1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q2,4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q4,2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graph for computing with Q1,4,2,3 . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graphs for the permutation matrices Q1 ⊗ I(1) and I(1) ⊗ Q1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graphs for the permutation matrices Q2 ⊗ I(1) and I(1) ⊗ Q2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graphs for the permutation matrices X1 ⊗ I(1) and I(1) ⊗ X1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

13 14 15 50 78 209 209 210 210 211 212 213 214 215 216 217 218 219 220 221 231 231 231 xiii

xiv

Fig. 8.19 Fig. 8.20 Fig. 8.21

List of Figures

Flow-graphs for the permutation matrices X1T ⊗ I(1) and I(1) ⊗ X1T . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graphs for the permutation matrices N1 ⊗ I(1) and I(1) ⊗ N1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Flow-graphs for the permutation matrices P1,2 and P2,2 . . . . . . . . . . . .

232 232 240

List of Tables

Table 1.1 Table 1.2 Table 1.3 Table 1.4 Table 1.5 Table 3.1 Table 3.2 Table 3.3 Table 3.4

Table 3.5 Table 4.1 Table 4.2 Table 4.3 Table 4.4

Table 4.5

Addition and multiplication in G F(4) . . . . . . . . . . . . . . . . . . . . . . . . . Multiplication of variables in RMF-expression for ternary functions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4EXP and 4AND . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Compositions of function values in ternary bent functions f p for n = 1, 2, . . . , 14 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Compositions of function values in ternary bent functions f s for n = 2, 6, 10, 14 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Times [msec] for computing the Walsh spectrum and the Gibbs derivative for binary functions with n variables . . . . . . . . . . . . . . . . . . The 16 bent functions that cannot be obtained by Gibbs permutation matrices from the three basic bent functions . . . . . . . . . . The 16 bent functions that cannot be obtained by permutation matrices from the three basic bent functions in terms of q . . . . . . . . . An example of 8 bent functions from which the first specific bent function with the integer representation 6017 is obtained by using different Gibbs permutation matrices . . . . . . . . . . . . . . . . . . . Correspondence between 16 specific bent functions with respect to the Gibbs permutation matrix assigned to f b1 . . . . . . . . . . . . . . . . . Ternary bent functions for n = 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Even ternary bent functions for n = 2 and their distributions . . . . . . Function vectors, GF-expressions, and RMF-expressions for ternary bent functions in n = 1 variables . . . . . . . . . . . . . . . . . . . . Function vectors, VC-Gibbs derivatives, GF-Gibbs derivatives, and RMF-Gibbs derivatives for ternary function in n = 1 variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Function vectors, sums of VC-Gibbs derivatives, GF-Gibbs derivatives, and RMF-Gibbs derivatives for ternary function in n = 1 variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

3 7 8 27 28 72 80 82

83 83 86 89 95

96

97 xv

xvi

Table 4.6 Table 4.7 Table 4.8 Table 4.9

Table 4.10

Table 4.11 Table 4.12 Table 4.13 Table 4.14 Table 4.15 Table 4.16 Table 4.17

Table 4.18 Table 4.19 Table 5.1 Table 5.2 Table 5.3 Table 5.4 Table 5.5 Table 5.6

List of Tables

Ternary bent functions for n = 2 (1-36) characterized by the VC-Gibbs derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Ternary bent functions for n = 2 (37-54) characterized by the VC-Gibbs derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Basic Gibbs permutation matrices for n = 2 . . . . . . . . . . . . . . . . . . . . Ternary bent functions constructed by the application of the Gibbs permutation matrices for n = 2 to f (x1 , x2 ) = x1 x2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Ternary bent functions constructed by the application of the Gibbs permutation matrices for n = 2 to f (x1 , x2 ) = x12 ⊕ x22 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Spectral invariant operations performed by the Gibbs permutation matrices for n = 2 after permutation of variables . . . . . . Matrices transpose and inverse to the Gibbs permutation matrices assigned to functions in Table 4.6 . . . . . . . . . . . . . . . . . . . . . Functions constructed by Gibbs permutation matrices applied to f = x12 ⊕ 2x22 ⊕ 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Functions constructed by Gibbs permutation matrices applied to f = x12 ⊕ x22 ⊕ 2x1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Permutation matrices for n = 1 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Even functions and their GF-Gibbs derivatives . . . . . . . . . . . . . . . . . . GF-Gibbs and VC-Gibbs derivatives for functions with the distribution D = (1, 4, 4) and with the GF-Gibbs derivative equal to k · φ, k = 0, 1, 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . Bent functions (1–18) with D = (1, 4, 4), their GF-Gibbs derivatives (DG F, f ), and VC-Gibbs (DV C, f ) derivatives . . . . . . . . . . Bent functions (19-27) with D = (1, 4, 4) and their GF-Gibbs derivatives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Quaternary bent functions for n = 1 arranged by the RMF-Gibbs derivatives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Example of functions with different encoding in the RMF-Gibbs derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Classes of quaternary bent functions for n = 1 in terms of the RMF-Gibbs derivative . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Quaternary bent functions for n = 1 arranged by the absolute values of the VC-Gibbs derivatives . . . . . . . . . . . . . . . . . . . . . . . . . . . . Examples of quaternary bent functions for n = 2 and their RMF-Gibbs derivatives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Quaternary bent functions in Table 5.5 and their VC-Gibbs derivatives encoded . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

98 99 101

102

103 104 105 106 107 109 115

116 118 119 125 126 127 129 132 132

List of Tables

Table 5.7 Table 5.8 Table 5.9 Table 5.10 Table 6.1 Table 6.2 Table 6.3 Table 6.4 Table 6.5 Table 6.6 Table 6.7 Table 6.8 Table 6.9 Table 6.10 Table 6.11 Table 7.1

Table 7.2 Table 7.3 Table 7.4 Table 7.5 Table 7.6

xvii

Distributions of values in VC-Gibbs derivatives of functions in Table 5.6 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Examples of quaternary bent functions for n = 2 sharing the same RMF-Gibbs derivatives encoded . . . . . . . . . . . . . . . . . . . . . . Examples of quaternary bent functions for n = 2 and absolute values of their VC-Gibbs derivatives . . . . . . . . . . . . . . . . . . . . . . . . . . . Distribution of absolute values of VC-Gibbs derivatives for functions in Table 5.9 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Representative functions for affine equivalent binary bent functions in n = 6 variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Representative functions for affine equivalent bent functions of degree 3 in n = 8 variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Examples of matrices with the same structure . . . . . . . . . . . . . . . . . . . Classes of affine equivalence representative bent functions for n = 6 with respect to (2 × 2) mv-spectra . . . . . . . . . . . . . . . . . . . . Examples of randomly generated bent functions in n = 6 variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Spectra of randomly generated bent functions in n = 6 variables in Table 6.5 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Classes of affine equivalence representative bent functions for n = 6 with respect to (4 × 4) mv-spectra . . . . . . . . . . . . . . . . . . . . Classes of bent functions for n = 8 with respect to (2 × 2) mv-spectra . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Submatrices in (2 × 2)-spectra for functions in the second class in Table 6.8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Patterns in matrix-valued coefficients of (4 × 4)-spectra for affine equivalence representative functions for n = 8 . . . . . . . . . . Classes of 10 affine equivalence representative functions with respect to (4 × 4)-partial spectra . . . . . . . . . . . . . . . . . . . . . . . . . . Initial ternary bent functions used in experiments and the number of bent functions produced from them by spectral invariant operations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Absolute-valued Vilenkin–Chrestenson coefficients for ternary bent functions for n = 3 of degree 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . Subclasses in Class 3 in Table 7.2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Additional absolute-valued Vilenkin–Chrestenson coefficients for ternary bent functions for n = 3 of degree 4 . . . . . . . . . . . . . . . . . Number of functions per class for considered quadratic ternary bent functions in four variables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Distribution of function values for ternary linear functions for n = 1, 2, 3, 4, 5, 6, 7, 8 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

132 133 134 135 152 152 158 161 163 166 168 170 171 172 178

188 189 189 192 194 195

xviii

List of Tables

Table 7.7 Table 7.8 Table 8.1

Table 8.2 Table 8.3 Table 8.4 Table 8.5

Table 8.6

Table 8.7

Table 8.8 Table 8.9

Table 8.10 Table 8.11 Table Table Table Table

8.12 8.13 8.14 8.15

Table 8.16 Table 8.17

Ternary linear functions for n = 2 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Basic bent functions for n = 1 in terms of square of the variable . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Spectral invariant operations, permutation matrices, truth-vectors of produced functions, their Walsh spectra, and functional expressions for produced bent functions from the function f in Example 8.1 . . . . . . . . . . . . . . . . . . . . . . . . . . . Classes of ternary bent functions for n = 1 . . . . . . . . . . . . . . . . . . . . . Relationships between classes of single variable ternary functions by encoding . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Conversion between the elements of a class . . . . . . . . . . . . . . . . . . . . . Correspondence between the basic permutation matrices and spectral invariant operation xi → k1 xi ⊕ k2 , k1 ∈ {1, 2}, k2 ∈ {0, 1, 2} . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Function vectors and functional expressions for bent functions constructed by the Kronecker product representable FFT-like permutation matrices from the function f in Example 8.11, f = x1 x2 ⊕ x32 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Function vectors Gi and functional expressions gi for bent functions produced by the auxiliary symbolic Kronecker product representable FFT-like permutation matrices from the function f = x1 x2 ⊕ x32 in Example 8.11 . . . . . . . . . . . . . . . Substitutions performed by block diagonal matrices based on basic permutation matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Function vectors and functional expressions for bent functions produced by the block diagonal FFT-like permutation matrices from the function f = x1 x2 ⊕ x32 in Example 8.11 . . . . . . . . . . . . . . . Diagonal permutation matrices for n = 4 and related substitution rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Substitution rules corresponding to the shift-based FFT-like permutation matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Bent functions (1–27) with distribution (5, 2, 2) . . . . . . . . . . . . . . . . . Bent functions (28–54) with distribution (5, 2, 2) . . . . . . . . . . . . . . . . Bent functions with distribution (1, 4, 4) . . . . . . . . . . . . . . . . . . . . . . . Functions obtained from q1 by permutation matrices R1 , R 2 , R 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Construction of ternary bent functions by permutation matrices from q1 with the composition (9, 12, 6) . . . . . . . . . . . . . . . . . . . . . . . . Construction of ternary bent functions by permutation matrices from q2 with the composition (9, 6, 12) . . . . . . . . . . . . . . . . . . . . . . . .

196 199

208 227 227 227

228

233

236 241

242 243 246 247 248 249 251 252 252

List of Tables

Table 8.18 Table 8.19 Table 9.1 Table 9.2

xix

Spectral invariant operations performed by the basic permutation matrices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Bent functions constructed by the basic permutation matrices from the function f in Example 8.24 . . . . . . . . . . . . . . . . . . . . . . . . . . Matrices of different dimensions and corresponding bent functions by their transposition . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . Possible decompositions of function vectors into matrix-valued elements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

254 254 263 265

1

Basic Concepts and Notations

In this chapter, we present the notation and introduce basic concepts that will be used further in this book.

1.1

Discrete Functions

A discrete function with .n inputs and .k outputs is defined as a mapping .

n f = ×i=1 Si → L k , xi ∈ Si ,

f i ∈ L,

where . Si and . L are finite discrete non-empty sets in which variables and respectively outputs take their values. It means the.ith variable.xi ∈ Si . For practical reasons, it is usually assumed that all the outputs take their values in the same set. Therefore, in the case of multiple-output functions, the range is taken as the power of the set . L. If . S1 = S2 = · · · = Sn = L = {0, 1, . . . , p − 1}, then the function is . p-valued. For the particular cases of . p = 2, . p = 3, and . p = 4, the functions are called, respectively, binary or Boolean, ternary, and quaternary. In other words, single output binary, ternary, and quaternary functions in .n variables are defined as mappings

.

f : {0, 1}n → {0, 1}, f : {0, 1, 2}n → {0, 1, 2}, f : {0, 1, 2, 3}n → {0, 1, 2, 3}.

In the present book, we consider such functions, although most of the presented theory can be extended to functions with mutually different sets . Si for inputs and different . L for the output. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_1

1

2

1 Basic Concepts and Notations

To get mathematically tractable models, it is useful to view these functions as functions on finite groups .C2n , .C3n , and .C4n , where .C2 = ({0, 1}, ⊕), .C3 = ({0, 1, 2}, ⊕), and .C4 = ({0, 1, 2, 3}, ⊕) are cyclic groups of order .2, .3, and .4, respectively. For convenience, the group elements are identified as integers and the group operation .⊕ is modulo .2, .3, and .4 addition, respectively. In other words, they are groups of integers modulo .2, .3, and .4. For the range . L of functions, it is useful to assume the algebraic structure of a field. For the functions considered in this book, these fields could be the finite Galois fields of orders .2, .3, and .4, i.e., . G F(2), . G F(3), or . G F(4), and the complex field .C. In some cases, instead of . G F(4), the ring .(Z 4 , +, ·) is used to preserve operations modulo .4. In the case of the field .C, the function values are considered as integers. For multiple-output functions, the outputs are viewed as . p-ary expressions of integers. In this way, both single- and multiple-output functions are viewed as integer-valued functions on finite Abelian groups. These groups are the direct products of the basic groups .Ci , .i = 2, 3, 4, and the .ith variable in a function . f takes the values in the corresponding group .Ci . It is possible to consider functions where variables take values in different groups; however, as already noticed above, such functions are out of the considerations in the present book. If viewed as functions on groups, discrete functions can be represented and processed by Fourier transforms on the corresponding groups. In particular, the Fourier transform is used to characterize bent functions. For the group .C2n , the Fourier transform is the Walsh transform of order .2n , and for the groups .C3n and .C4n , the Vilenkin–Chrestenson transforms of orders .3n and .4n , respectively. Extensions of the considerations to other values of . p different from .2, .3, and .4 are straightforward.

1.2

Functional Expressions

Functional expressions over different algebraic structures are a convenient way to represent discrete functions analytically. In this book, we will use the positive polarity Reed–Muller expressions, also called the Zhegalkin polynomials for binary functions [1, 2], or in cryptography, the algebraic normal form [3], and their counterparts for ternary and quaternary functions. These expressions are also called the Generalized Reed–Muller expressions [4–7]. They can be uniformly viewed as Galois field (GF) expressions since they are defined over the finite fields .G F(2), .G F(3), and .G F(4), respectively [8–11]. In the first two cases, the addition and multiplications are modulo .2 and .3, respectively. Table 1.1 defines the addition and multiplication in .G F(4).

1.2

Functional Expressions

3

Table 1.1 Addition and multiplication in .G F(4) +

0123

×

0123

0

0123

0

0000

1

1032

1

0123

2

2301

2

0231

3

3210

3

0312

Definition 1.1 A binary function can be expressed in terms of the set of basis functions .φi defined in matrix notation as columns of the matrix n

X2 (n) =

.

[ ] X2 (1), X2 (1) = 1 xi ,

(1.1)

i=1

where .⊗ is the Kronecker product of matrices. Thus, .φi (x1 , x2 , . . . , xn ) = x1i1 x2i2 · · · xnin , .i = (i 0 , i 1 , i 2 , . . . , i n ). It is clear that .φ0 = 1. These functions are somewhere in the literature called the Reed–Muller functions [12]. In other words, the .2n basis functions are products of variables appearing in all subsets of the power set of the set of variables .{x1 , x2 , . . . , xn }. The order of basis functions is determined by the Kronecker product in (1.1), and it is usually called the Hadamard order. Definition 1.2 A binary function . f specified by the truth-vector F2 = [ f (0), f (1), . . . , f (2n − 1)]T

.

is represented as

.

f (x1 , x2 , . . . , xn ) =

n −1 2∑

ri φi (x1 , x2 , . . . , xn ).

i=0

The coefficients .ri viewed as elements of a vector S2 (n) = [r0 , r1 , . . . , r2n −1 ]T

.

are determined as S2 (n) = R2 (n)F2 (n),

.

where

4

1 Basic Concepts and Notations

[

n

R2 (n) =

.

i=1

] 10 R2 (1), R2 (1) = , 11

with computations modulo .2. These functional expressions are often called the Reed–Muller (RM) expressions, or more precisely positive polarity Reed–Muller (PPRM) expressions by referring to the work of Reed [13] and Muller [14]. This precise notation is important to be mentioned since for a given function, the optimization of the RM-expression in the number of product terms is performed by using negative literals for some of the variables leading to the Fixed Polarity Reed–Muller (FPRM) expressions; see, for instance, [12]. The PPRM-expressions are also called Žhegalkin polynomials since they were introduced in another contents in [1, 2]. In cryptography, the term Algebraic Normal Form (ANF) is prevalently used [3, 15]. It is worth noticing that .R(1) and .X(1) and therefore also .R(n) and .X(n) are inverse to each other, assuming that values of binary variables are written as columns of .X(1) and n n .X(n) in order to produce .(2 × 2 ) matrices. Actually, these matrices are self-inverse since .X(1) = R(1). The same approach is used to define functional expressions for ternary and quaternary functions; however, in these cases the self-inverseness over .G F(3) and .G F(4) is not preserved. When ternary and quaternary functions are considered in the ring of integers modulo .3 and .4, respectively, the self-inverseness is preserved in the case of the Reed–Muller–Fourier expressions discussed below and will be used in Chap. 5. Definition 1.3 A ternary function can be expressed in terms of the set of basis functions .φi defined in matrix notation as columns of the matrix n

X3 (n) =

.

[ ] X3 (1), X3 (1) = 1 xi xi2 ,

i=1

where .⊗ is the Kronecker product and all the computations are modulo .3. Definition 1.4 A ternary function . f specified by the function vector F3 = [ f (0), f (1), . . . , f (3n − 1)]T

.

is represented as

.

f (x1 , x2 , . . . , xn ) =

n −1 3∑

i=0

ri φi ,

(1.2)

1.2

Functional Expressions

5

where the coefficients .ri viewed as elements of a vector S3 (n) = [r0 , r1 , . . . , r3n −1 ]T

.

are determined as S3 (n) = R3 (n)F3 (n),

.

where ⎤ 100 .R3 (n) = R3 (1), R3 (1) = ⎣ 0 2 1 ⎦ , i=1 222 ⎡

n

where .⊗ is the Kronecker product of matrices and all computations are modulo .3. ⎤ 100 The matrix .R3 (1) is inverse over .G F(3) to the matrix .X3 (1) = ⎣ 1 1 1 ⎦. Therefore, the 121 same holds for .R3 (n) and .X3 (n). ⎡

Definition 1.5 A quaternary function can be expressed in terms of the set of basis functions φi defined in matrix notation as columns of the matrix

.

n

[ ] X4 (1), X4 (1) = 1 xi xi2 xi3 ,

X4 (n) =

.

(1.3)

i=1

where .⊗ is the Kronecker product of matrices and all computations are in .G F(4). Definition 1.6 A quaternary function . f specified by the function vector F4 = [ f (0), f (1), . . . , f (4n − 1)]T

.

is represented as

.

f (x1 , x2 , . . . , xn ) =

n −1 4∑

ri φi ,

i=1

where the coefficients .ri viewed as elements of a vector .S4 (n) = [r0 , r1 , . . . , r4n −1 ]T are determined as S4 (n) = R4 (n)F4 (n),

.

where

6

1 Basic Concepts and Notations



1 ⎢0 .R4 (n) = R4 (1), R4 (1) = ⎢ ⎣0 i=1 1 n

0 1 1 1

0 3 2 1

⎤ 0 2⎥ ⎥, 3⎦ 1

where .⊗ is the Kronecker product of matrices and all computations are in .G F(4). ⎡

⎤ 1000 ⎢1 1 1 1⎥ ⎥ The matrix .R4 (1) is inverse over .G F(4) to the matrix .X4 (1) = ⎢ ⎣ 1 2 3 1 ⎦. Therefore, 1321 the same is for .R4 (n) and .X4 (n). In the following, the indices in .Fi , .Xi , and .Ri , .i = 2, 3, 4 will be omitted when it is clear from the context to which functions, binary, ternary, or quaternary they are applied.

1.3

Reed–Muller–Fourier Expressions

Reed–Muller–Fourier (RMF) expressions are a generalization of Reed–Muller (RM) expressions for binary switching functions to multiple-valued logic functions including binary, ternary, and quaternary functions as particular examples [12]. These expressions are defined over the ring of integers modulo . p, where . p is not necessarily a prime number. All the operations are modulo . p with the exponentiation in terms of the so-called Gibbs multiplication introduced for the binary case in [16], and defined as follows. Definition 1.7 The Gibbs multiplication is defined as ( f g)(0) = 0,

.

( f g)(x) =

σ (x)−1 ∑

f (σ (x) − 1 − s)g(s),

s=0

where .x = (x1 , x2 , . . . , xn ), with .xi ∈ {0, 1, 2, 3, . . . , p − 1}, and σ (x) =

n ∑

.

xi p n−i .

i=1

1.3.1

RMF-Expressions for Ternary Functions

In the case of Reed–Muller–Fourier expressions for . p = 3, all the computations are modulo .3. For . p = 3 and .n = 1, we define in matrix notation the set of basis functions as

1.3

Reed–Muller–Fourier Expressions

7

Table 1.2 Multiplication of variables in RMF-expression for ternary functions

012 0 000 1 021 2 012

[ ] [ ] X3R M F (1) = xi∗0 xi∗1 xi∗2 = 2 xi∗1 xi∗2 ,

.

where .∗ stands for the Gibbs multiplication used in exponentiation and with the Gibbs exponentiation for the power .0 defined as .xi∗0 = 2, and .xi∗1 = xi . The basis functions, represented as columns of a matrix, are ⎤ 200 .X3R M F (1) = ⎣ 2 1 0 ⎦ . 222 ⎡

The extension to functions in .n variables is obtained through the Kronecker product as n

X3R M F (n) =

n

X3R M F (1) =

.

i=1

[

] 2 xi∗1 xi∗2 ,

i=1

where the multiplication of variables and their powers to form the product terms is the multiplication modulo .3 followed by the multiplications by .2. We denote this operation by . , and it is defined by Table 1.2. These functions represent a complete basis in terms of which the RMF-expressions for ternary functions are defined as .

f (x1 , . . . , xn ) = (−1)n X3R M F (n)S f (n),

where S f (n) = R3R M F (n)F(n),

.

with n

R3R M F (n) =

R3R M F (1),

.

i=1

8

1 Basic Concepts and Notations

Table 1.3 .4EXP and .4AND

∗ 0123

0123

0 3000

0 0000

1 3100

1 0321

2 3230

2 0202

3 3311

3 0123

and ⎤ 100 = 2⎣1 2 0⎦. 111 ⎡

R3R M F (1) = (X3R M F (1))−1

.

1.3.2

RMF-Expressions for Quaternary Functions

In order to generate the product terms of quaternary variables corresponding to these appearing in the Reed–Muller expressions for binary functions and Galois field (GF) expressions for multiple-valued functions, we define in Table 1.3 the .4AND multiplication and .4EXP exponentiation, denoted by . and .∗, respectively. Note that .4AND table is actually the multiplication modulo .4 table multiplied by .3. Define the set of basis functions for .n = 1 as [ ] [ ] X4R M F (1) = xi∗0 xi∗1 xi∗2 xi∗3 = 3 xi∗1 xi∗2 xi∗3 ,

.

where .∗ stands for the Gibbs multiplication and with the Gibbs exponentiation for the power 0 defined as .xi∗0 = 3. The basis functions, represented as columns of a matrix, are

.



3 ⎢3 .X4R M F (1) = ⎢ ⎣3 3

0 1 2 3

0 0 3 1

⎤ 0 0⎥ ⎥. 0⎦ 1

The extension to functions in .n variables is obtained through the Kronecker product as

1.4

Fourier Transforms on Finite Abelian Groups

9

n

X4R M F (n) =

n

X4R M F (1) =

.

i=1

[

] 3 xi∗1 xi∗2 xi∗3 .

i=1

These functions represent a complete basis in terms of which the RMF-expressions for quaternary functions are defined as .

f (x1 , . . . , xn ) = (−1)n X4R M F (n)S f (n),

where S f (n) = R4R M F (n)F(n),

.

with n

R4R M F (n) =

R4R M F (1),

.

i=0

and ⎡

R4R M F (1) = (X4R M F (1))−1

.

1.4

3 ⎢3 =⎢ ⎣3 3

0 1 2 3

0 0 3 1

⎤ 0 0⎥ ⎥. 0⎦ 1

Fourier Transforms on Finite Abelian Groups

The Fourier transforms on Abelian groups are defined in terms of group characters. Since the groups are finite, these transforms can be simply defined in terms of the corresponding transform matrices whose columns are the group characters. In the cases that we consider, domain groups are direct products of cyclic groups.Ci ,.i = 2, 3, 4, and the transform matrices for the Fourier transforms are the Kronecker products of the basic Fourier transform matrices on these constituent subgroups. The columns of these basic transform matrices are the group characters of .Ci , .i = 2, 3, 4. Definition 1.8 (Walsh transform) For a binary function . f (x1 , x2 , . . . , xn ) specified by the function vector F = [ f (0), f (1), . . . , f (2n − 1)]T ,

.

the Walsh spectrum can be represented by a vector S f = [S f (0), S f (1), . . . , S f (2n − 1)]T

.

10

1 Basic Concepts and Notations

determined as n

S f = W(n)F, W(n) =

.

i=1

[

] 1 1 W(1), W(1) = . 1 −1

Definition 1.9 (Vilenkin–Chrestenson transform for ternary functions) For a ternary function . f (x1 , . . . , xn ) specified by the function vector F = [ f (0), f (1), . . . , f (3n − 1)]T ,

.

the Vilenkin–Chrestenson spectrum can be represented by a vector S f = [S f (0), S f (1), . . . , S f (3n − 1)]T

.

determined as S f = V∗ (n)F,

.

where .V∗ (n) is the complex-conjugate transpose of ⎡

⎤ 1 1 1 .V(n) = V(1), V(1) = ⎣ 1 e1 e2 ⎦ , i=1 1 e2 e1 n

√ √ 4πi 1 1 where.e1 = ex p( 2πi 3 ) = − 2 (1 − i 3) and .e2 = ex p( 3 ) = − 2 (1 + i 3). Thus, .e2 is the complex-conjugate of .e1 . Definition 1.10 (Vilenkin–Chrestenson transform for quaternary functions) For a quaternary function . f (x1 , . . . , xn ) specified by the function vector F = [ f (0), f (1), . . . , f (4n − 1)]T ,

.

the Vilenkin–Chrestenson spectrum can be represented by a vector S f = [S f (0), S f (1), . . . , S f (4n − 1)]T

.

determined as S f = V∗ (n)F,

.

where .V∗ (n) is the complex-conjugate transpose of

1.5

Fast Fourier Transform

11



⎤ 1 1 1 1 ⎢ 1 i −1 −i ⎥ ⎥ .V(n) = V(1), V(1) = ⎢ ⎣ 1 −1 1 −1 ⎦ . i=1 1 −i −1 i n

In the case of binary, ternary, and quaternary functions, it is useful to perform the encoding of function values to make them compatible with values taken by the kernels of the Fourier transform, thus, .(0, 1) → (1, −1), and .(0, 1, 2) → (1, e1 , e2 ), and .(0, 1, 2, 3) → (1, i , −1, −i ). The reason is that these encodings make some particular properties of functions to be represented by Fourier spectra more visible and easier to observe. In other words, the spectral coefficients computed after encoding of function values express certain particular properties useful in the analysis of properties of functions represented and other applications. For instance, the encoding .(0, 1) → (1, −1) for binary functions results in even integers with absolute values no larger than .2n as values of Walsh coefficients. In general, these encodings are called the complex encodings, since function values are encoded by complex values on the unit circle. Example 1.1 Consider the ternary function. f (x1 , x2 ) = x1 x2 ⊕ x22 ,.x1 , x2 ∈ {0, 1, 2}, with multiplication defined modulo .3. The function vector is F = [0, 1, 1, 0, 2, 0, 0, 0, 2]T

.

and the encoded function vector is Fe = [1, e1 , e1 , 1, e2 , 1, 1, 1, e2 ]T .

.

The Vilenkin–Chrestenson spectrum is computed as S f = V∗ (2)Fe = 3[1, 1, 1, e1 , 1, e2 , e1 , e2 , 1]T .

.

It may be seen that all coefficients of the spectrum have the same absolute value equal .3, which characterizes a flat spectrum, showing that the given function is bent (see below).

1.5

Fast Fourier Transform

The Cooley–Tukey Fast Fourier transform is an algorithm to efficiently compute the Fourier transform on finite groups in terms of the number of necessary operations of addition and multiplication [17]. The algorithm is based upon the factorization of the Fourier transform matrix into a product of sparse matrices. For a function on a finite group decomposable into .n subgroups, the Fourier spectrum is computed into .n steps, with each step described by a sparse matrix, as it will be illustrated by the examples below. The method generally applies to any Fourier and Fourier-like transform including the Walsh and the Vilenkin–Chrestenson

12

1 Basic Concepts and Notations

transforms used in this book. Moreover, the same principle can be extended to compute the Reed–Muller and Reed–Muller–Fourier transforms leading to the corresponding fast algorithms [18]. There are different ways to factorize the Fourier transform matrix, many of them summarized and presented in details in [19, 20]. We will use the Good–Thomas factorization [21–23], since it takes advantages of the Kronecker product structure of the Walsh and Vilenkin–Chrestenson transform matrices .W(n) and .V(n). The Good–Thomas factorization of the Walsh matrix is defined as [ n n || W(1), j = i , .W(n) = Ci (n), Ci (n) = Aj, Aj = (1.4) I(1), j / = i . i=1

j=1

Each matrix .Ci defines computing in the corresponding step. Due to their Kronecker product structure, identical computations are performed in each step, but on different subsets of data, i.e., over data taken from different positions in the function vector representing the function to be processed. These computations are represented by the so-called butterfly operation, the flow-graph of which is shown in Fig. 1.1a. The weights at the edges of these flow-graphs are determined by the entries of the basic Walsh transform matrix .W(1). Figure 1.1b shows the basic butterfly operation for the Vilenkin–Chrestenson transform for ternary functions. The weights at the edges are determined as elements of .V∗ (1). Example 1.2 For Fourier (Walsh) processing of functions in .5 binary variables, the Walsh matrix .W(5) can be factorized as W(5) = C1 · C2 · C3 · C4 · C5 ,

.

where C1 = W(1) ⊗ I(1) ⊗ I(1) ⊗ I(1) ⊗ I(1),

.

C2 = I(1) ⊗ W(1) ⊗ I(1) ⊗ I(1) ⊗ I(1), C3 = I(1) ⊗ I(1) ⊗ W(1) ⊗ I(1) ⊗ I(1), C4 = I(1) ⊗ I(1) ⊗ I(1) ⊗ W(1) ⊗ I(1), C5 = I(1) ⊗ I(1) ⊗ I(1) ⊗ I(1) ⊗ W(1), where .W(1) is the basic Walsh matrix and .I(1) is the .(2 × 2) identity matrix.

1.5

Fast Fourier Transform 1

f(0) 1 f(1)

13 f (0)+f (1) 1

-1

1

f (0) 1

f (0) - f (1)

1 f (1)

(a)

e2

f (0)+ e2 f (1)+e1 f (2)

e1 1

f (2)

f (0) +f (1)+f (2)

1

e1 e 2

f (0) +e1 f(1)+e2 f(2)

(b)

Fig. 1.1 Flow-graph of the basic computing operation in Cooley–Tukey Fast Walsh and Vilenkin– Chrestenson transforms

It is obvious that in each step .Ci , .i = 1, 2, 3, 4, 5, processing is done with respect to the ith variable, while other variables remain unprocessed. Figure 1.2 shows the flow-graph for computing the Walsh spectrum of functions in .n = 5 variables. Edges to which the weight .−1 is associated are represented by dashed lines. .

The same factorization as in (1.4) applies to the Vilenkin–Chrestenson transform matrix for ternary functions with the difference that the involved basic matrices are.(3 × 3) matrices, i.e., the basic Vilenkin–Chrestenson matrix.V(1) for ternary functions, and the identity matrix .I(1). Example 1.3 The Vilenkin–Chrestenson matrix for ternary functions and .n = 2 can be factorized as V∗ (2) = C1 · C2 ,

.

where C1 = V∗ (1) ⊗ I(1),

.

C2 = I(1) ⊗ V∗ (1), where .V(1) is the basic Vilenkin–Chrestenson matrix and .I(1) is the .(3 × 3) identity matrix. Figure 1.3 shows the flow-graph of the Fast Vilenkin–Chrestenson transform for ternary function and .n = 2. To each edge in the diagram, an element of the basic Vilenkin– Chrestenson matrix is associated. In this figure, edges to which are associated the weights .1, .e1 , and .e2 are represented by solid, dashed, and dot-dashed lines, respectively. The Fast Fourier transform for quaternary functions is defined in the same way in terms of the .(4 × 4) basic Vilenkin–Chrestenson matrix .V∗ (1) for quaternary functions and the corresponding identity matrix .I(1). The same approach holds for the fast computing algorithms for the generalized Reed–Muller transform for ternary and quaternary functions [12], and also for Reed–Muller–Fourier transforms for quaternary functions [24].

14

1 Basic Concepts and Notations f (0)

Sf (0)

f (1)

Sf (1)

f (2) f (3) f (4) f (5) f (6) f (7) f (8) f (9) f (10) f (11) f (12) f (13) f (14) f (15) f (16) f (17) f (18) f (19) f (20) f (21) f (22) f (23) f (24) f (25) f (26) f (27) f (28) f (29) f (30) f (31)

Sf (2) Sf (3) Sf (4) Sf (5) Sf (6) Sf (7) Sf (8) Sf (9) Sf (10) Sf (11) Sf (12) Sf (13) Sf (14) Sf (15) Sf (16) Sf (17) Sf (18) Sf (19) Sf (20) Sf (21) Sf (22) Sf (23) Sf (24) Sf (25) Sf (26) Sf (27) Sf (28) Sf (29) Sf (30) Sf (31)

Fig. 1.2 Flow-graph of the FWT for .n = 5

1.6

Binary Bent Functions

Binary bent functions are defined as maximally non-linear functions, meaning that they are at the largest distance from affine Boolean functions, equivalently from the first order Reed–Muller code. They have several applications in different areas including coding theory, cryptography, spread spectrum communications, and some other areas [15]. For example, they are used in stream cipher systems. The vectorized stream cipher systems use bent

1.6

Binary Bent Functions

15

Fig. 1.3 Flow-graph of the Fast Vilenkin–Chrestenson transform for ternary function and .n = 2

functions generalized to the alphabet. Z q the ring of integers modulo.q [25]. Generalized bent functions are also used in multi-code code-division multiple access (MC-CDMA) systems to reduce the peak-to-power ratio to the lowest possible value. The particular case for .q = 4 is especially interesting and investigated by several authors; see, for example, [3, 26]. Bent functions are a very small fraction of the total number of Boolean functions for .q = 2, and even smaller in the case of functions for .q > 2 [27]. For a uniform notation, in further considerations Boolean functions are called binary functions. Since they are important for applications, and at the same time are so rare, bent functions are not easy to find. An answer is offered by proposing different methods to construct bent functions of a given number of variables from bent functions of smaller number of variables [3, 15]. Another class of construction methods is based on the manipulation of a given bent function to construct other bent functions for a specified number of variables. Various manipulation methods are proposed. Another approach is aimed at providing different characterizations of bent functions reducing the search space to functions with particular appropriately formulated characteristic properties satisfied by bent functions in the original or spectral domain, where the spectra can be the Walsh or the Reed–Muller spectra. Both approaches lead to different classes of bent functions representing particular subsets of the total of bent functions for given .n and .q [3, 26]. Closely related is the problem of splitting the set of bent functions for a given number of variables into classes. For example, the set of binary bent functions for .n = 4, that consists of .896 functions, can be split into .28 classes each with .32 functions with respect to the quadratic terms in their algebraic (Zhegalkin polynomial or positive polarity Reed–Muller) normal form. In [28] is given an affine classification of binary bent functions for .n = 6 into four classes of affine equivalent functions. The corresponding algebraic classification is discussed in [29]. Other

16

1 Basic Concepts and Notations

different classification criteria can be used to split the set of bent functions into classes. For example, properties of related regular graphs are used in [30] for a characterization of Boolean bent functions. In [31], the set of Boolean bent functions for .n = 6 is split into .8 classes with respect to bent-squares assigned to bent functions. See also [32] for a discussion and examples. In the binary case, a linear function is the constant .0 function or the linear combination of Boolean variables over .G F(2). An affine function is a linear function or its complement. Bent functions are a class of binary functions with the highest degree of non-linearity, i.e., at the highest Hamming distance .(2n−1 − 2n/2−1 ) from the affine Boolean functions. In other words, bent functions have the minimum correlation to the set of all affine functions. From the spectral transform point of view, an alternative definition of bent functions is given as follows [33]. Definition 1.11 (Binary bent functions) A binary function is bent iff its Walsh spectrum is flat, meaning that in the encoding .(0, 1) → (1, −1) all its Walsh coefficients have the same absolute value equal to .2n/2 . The Hamming weight, i.e., the number of .1 values in the truth-vector of a bent function is uniquely specified as either .2n−1 − 2n/2−1 or .2n−1 + 2n/2−1 . Thus, every bent function takes the same values as any affine function at the number of points equal to the Hamming weight. The non-linearity is defined as the minimum number of points at which a function equals any affine function and, therefore, for bent functions it is the maximum possible n−1 − 2n/2−1 . This is a necessary but not sufficient criterion for a binary function to be .2 bent. From this property it follows that bent functions cannot be balanced, meaning they cannot have an equal number of zero and non-zero values. The degree of a binary bent function . f , defined as the maximum number of variables in a product term in the positive polarity Reed–Muller expression for . f , is .deg( f ) = n/2. Recall that binary bent functions are defined for an even number of variables. Example 1.4 For a bent function, if .n = 2, the Hamming weight is .1 or .3, whereas if .n = 4, the Hamming weight is .6 or .10. Depending on the number of non-zero values, we split the sets of all Boolean functions into two subsets. The first set contains functions with .2n−1 − 2n/2−1 non-zero values and the other set contains their logic complements. In this area, logic values .0 and .1 are usually encoded by .1 and .−1, respectively, and interpreted as integers. Example 1.5 The function . f = x1 x3 ⊕ x2 x3 ⊕ x2 x4 , whose function vector in the .(1, −1) encoding is F = [1, 1, 1, 1, 1, −1, −1, 1, 1, 1, −1, −1, 1, −1, 1, −1]T ,

.

1.6

Binary Bent Functions

17

is bent, since its Walsh spectrum is S f = [4, 4, 4, 4, 4, −4, 4, −4, 4, −4, −4, 4, 4, 4, −4, −4]T .

.

We see that since .n = 4, the absolute value of the Walsh coefficients is .2n/2 as required for bent functions. Bent functions with the same number of variables and the same number of non-zero values are permuted versions of each other. This follows from the exactly specified number of non-zero values in bent functions. Example 1.6 Consider two bent functions .

f 1 = x1 x2 ⊕ x3 x4 , f 2 = x1 x2 ⊕ x3 x4 ⊕ x1 x3 .

Their function vectors in the encoding .(0, 1) → (1, −1) are F1 = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1]T ,

.

F2 = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, −1, 1, −1, −1, 1, −1]T . It is obvious that these functions are related by the permutation of function values at the positions corresponding to decimal indices .10, .11, .14, and .15, i.e., . f 1 (10) ↔ f 1 (11) and . f 1 (14) ↔ f 1 (15). This permutation can be expressed as . x 2 → x 2 ⊕ x 3 , which is a spectral invariant operation as it will be discussed later in Sect. 1.10. Therefore, bent functions can be viewed as a subset of functions representing solutions of the generalized eigenfunction problem for the Walsh transform since they must satisfy WF = ±2n/2 PF,

.

where .P is a generalized permutation matrix. The generalization means that some of the non-zero elements in .P may have a negative sign, i.e., they may be equal to .−1. Notice that this property is certainly satisfied for the generalized permutation matrices derived from the permutation matrices corresponding to spectral invariant operations for the Walsh transform [34, 35]. The structure of these permutation matrices will be discussed in subsequent chapters. Definition 1.12 A Boolean function derived from the Walsh spectrum of a bent function . f by multiplication of the Walsh coefficients with .2−n/2 is called the dual function . f d of . f .

18

1 Basic Concepts and Notations

Example 1.7 Consider the function defined by the function vector F1 = [−1, −1, 1, −1, −1, 1, 1, 1, 1, 1, −1, 1, −1, 1, 1, 1]T ,

.

where the elements of .F1 are obtained with the .(0, 1) → (1, −1) encoding. Its Walsh spectrum is S f1 = [4, −4, −4, −4, −4, 4, 4, 4, −4, 4, −4, −4, −4, 4, −4, −4]T

.

and since it is flat, the function is bent. Its dual function is Fd1 = [1, −1, −1, −1, −1, 1, 1, 1, −1, 1, −1, −1, −1, 1, −1, −1]T .

.

Notice that in this example, the initial function . f 1 and its dual function . f d1 before the complex encoding have .6 and .10 non-zero values, respectively. The function . f 2 specified by the function vector F2 = [1, 1, 1, 1, 1, 1, −1, −1, 1, −1, 1, −1, 1, −1, −1, 1]T

.

is bent since its Walsh spectrum is S f2 = [4, 4, 4, 4, 4, 4, −4, −4, 4, −4, 4, −4, 4, −4, −4, 4]T ,

.

and its dual function . f d2 is Fd2 = [1, 1, 1, 1, 1, 1, −1, −1, 1, −1, 1, −1, 1, −1, −1, 1]T = F2 .

.

This function has the same number of non-zero values as the initial function; moreover, the Walsh spectrum is equal to the function vector multiplied by .4. Since . Fd2 = F2 , this function is called self-dual. The function . f 3 specified by the function vector F3 = [1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1]T

.

has the Walsh spectrum S f3 = [4, 4, 4, −4, −4, −4, −4, 4, 4, 4, 4, −4, 4, 4, 4, −4]T ,

.

and its dual function . f d3 has the same number of non-zero elements, but it is not identical to . f 3 Fd3 = [1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1, 1, 1, 1, −1]T .

.

1.6

Binary Bent Functions

19

A large class of bent functions can be constructed by using the property that adding an affine function to a bent function preserves bentness, i.e., produces another function that is bent. For a proof, see, for example, [36]. Example 1.8 The function. f 1 in Example 1.7 has the functional expression. f (x1 , x2 , x3 , x4 ) = 1 ⊕ x1 ⊕ x3 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4 . Adding an affine function .g(x1 , x2 , x3 , x4 ) = 1 ⊕ x2 ⊕ x4 produces another bent function .v(x1 , x2 , x3 , x4 ) = x1 ⊕ x2 ⊕ x3 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4 . This function has the encoded function vector V = [1, −1, −1, −1, −1, −1, 1, −1, −1, 1, 1, 1, −1, −1, 1, −1]T ,

.

and the corresponding Walsh spectrum is Sv = [−4, 4, −4, −4, 4, −4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4]T ,

.

which is flat and therefore .v is also bent. Another large class of bent functions may be generated by means of spectral invariant operations [34]. Therefore, adding linear terms to the functional expressions of bent functions can be interpreted as an implementation of certain spectral invariant operations or combinations of them, and vice versa; implementation of spectral invariant operations results in adding particular terms to functional expressions representing the functions. This will be detailed in Sect. 1.10 and also when discussing various construction methods for bent functions. In the literature, the concepts Perfect non-linear functions (PN), Almost perfect non-linear functions (APN), and maximally non-linear functions are frequently mentioned. Definition 1.13 ([37]) Let . A and . B be finite Abelian groups and . f : A → B a function. Furthermore, define δ(a, b) = |{x| f (x + a) − f (x) = b}|.

.

For all .a ∈ A, .a / = 0, and .b ∈ B, let ∆ f = maxa,b δ(a, b).

.

Then . f is said to be differentially .∆ f -uniform. If .∆ f = |B|/|A|, then . f is perfect non-linear (PN). If . f is differentially .(2|A|/|B|)-uniform, then . f is almost perfect non-linear (APN). Definition 1.14 ([38]) A function in .n variables over a finite field of . p elements is called maximally non-linear if it has the greatest non-linearity among all . p-valued functions in .n variables.

20

1.7

1 Basic Concepts and Notations

Ternary Bent Functions

The alternative definition of binary bent functions in terms of the Walsh spectrum served as a basis for generalization of the concept of bentness to . p-valued functions on finite Abelian groups [25, 39–42], and further to non-Abelian groups [43]. It should be noticed that this generalization is not straightforward as it can be possibly expected from the direct extension of the definition in terms of the flat spectrum, which can be seen from some differences in the properties of bent functions on groups different from the finite dyadic group. For example, among the most important differences is the property that in the binary case, bent functions exist just for the even number of variables, while for . p ≥ 3 there are bent functions for both even and odd number of variables; see, for example, [44]. For restrictions when . p = 2 modulo .4, see [25]. Also, for . p > 2, there are bent functions that are not maximally non-linear and, conversely, there are maximally non-linear functions that are not bent [38]. These differences in properties lead to different characterizations of bent functions [25], ways to discuss their properties [33], and methods to generate them [44]. Definition 1.15 (Ternary bent functions) A ternary function is bent iff after complex encoding its Vilenkin–Chrestenson spectrum is flat, meaning that all its Vilenkin–Chrestenson coefficients have the same absolute value equal to .3n/2 . Example 1.9 Consider the ternary function . f (x1 , x2 ) = x1 x2 , .x1 , x2 ∈ {0, 1, 2}, with multiplication defined modulo .3. The function vector of . f is F = [0, 0, 0, 0, 1, 2, 0, 2, 1]T .

.

After encoding .(0, 1, 2) → (1, e1 , e2 ), where .e1 and .e2 are elements of the Vilenkin– √ √ Chrestenson matrix, i.e., .e1 = − 21 (1 − i 3), .e2 = − 21 (1 + i 3), the encoded function vector is Fe = [1, 1, 1, 1, e1 , e2 , 1, e2 , e1 ]T .

.

The Vilenkin–Chrestenson spectrum is computed as S f = V∗ (2)Fe = 3[1, 1, 1, 1, e2 , e1 , 1, e1 , e2 ]T .

.

It may be seen that all coefficients of the spectrum have the same absolute value equal to 3n/2 = 3 since .n = 2, which characterizes a flat spectrum, showing that the given function is bent.

.

Notice the differences compared to the definition of binary bent functions in terms of the Walsh spectra. First, we take absolute values, not just values which can be either positive or negative. It means, we do not preserve the information about the signs of the coefficients.

1.7 Ternary Bent Functions

21

As in the binary case, an important property of ternary bent functions that will be used in discussions below is that they cannot be balanced. Recall that a binary or ternary function in the complex encoding .(1, −1) and .(1, e1 , e2 ), respectively, is balanced if the sum of its values in the function vector is .0, i.e., ∑ f (x ,x ,...,xn ) . e1 1 2 = 0, x1 ,x2 ,...,xn

where .e1 = exp(2πi /3). In other words, a function . f is balanced if all values that it can take appear equally many times in its function vector .F. In the case of balanced ternary functions, there are three possible values .0, 1, 2, and each of them should appear .3n−1 times in the function vector. Another property illustrating the difference with respect to binary bent functions is that the maximal degree of a . p-valued bent function in .n variables for .n even is [67] deg( f ) =

.

( p − 1)n , 2

and for .n odd deg( f ) =

.

( p − 1)n + 1. 2

Thus, for . p = 3 and .n = 2, the maximal degree is .2, and for .n = 3 it is .4. Example 1.10 The ternary function in three variables .

f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 ⊕ x22 x3

is a bent function of degree .3. The degree is determined by the term .x22 x3 , which consists of two variables .x2 and .x3 , but the variable .x2 appears as a square. Thus, the degree is .3. The function vector of this function is F = [0, 1, 1, 0, 2, 0, 0, 2, 0, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 1, 1, 2, 1, 2, 1, 0, 1]T .

.

Its Vilenkin–Chrestenson spectrum S f = [i5.2, 4.5 − i2.6, 4.5 − i2.6, i5.2, 4.5 − i2.6, 4.5 − i2.6, i5.2, 4.5 − i2.6,

.

4.5 − i2.6, 4.5 − i2.6, i5.2, 4.5 − i2.6, −4.5 − i2.6, 4.5 − i2.6, −4.5 − i2.6, i5.2, −4.5 − i2.6, i5.2, 4.5 − i2.6, i .52, 4.5 − i2.6, i5.2, −4.5 − i2.6, i5.2, −4.5 − i2.6, 4.5 − i2.6, −4.5 − i2.6]T has the coefficients with the same absolute value equal to.5.2, which means that the spectrum is flat as required for bent functions.

22

1 Basic Concepts and Notations

The ternary function in three variables .

f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 ⊕ x22 x32

is a bent function of degree .4. Its function vector is F = [0, 1, 1, 0, 2, 2, 0, 2, 2, 0, 1, 1, 1, 0, 0, 2, 1, 1, 0, 1, 1, 2, 1, 1, 1, 0, 0]T .

.

The degree is determined by the term .x22 x32 which consists of two variables which both appear as a square. The Vilenkin–Chrestenson spectrum is S f = [i5.2, 4.5 − i26, 4.5 − i2.6, i5.2, 4.5 − i2.6, 4.5 − i2.6, i5.2, 4.5 − i2.6,

.

4.5 − i2.6, −i5.2, 4.5 + i2.6, 4.5 + i2.6, −4.5 + i2.6, −i5.2, −i5.2, 4.5 + i2.6, −4.5 + i2.6, −4.5 + i2.6, −i5.2, 4.5 + i2.6, 4.5 + i2.6, 4.5 + i2.6, −4.5 + i2.6, −4.5 + i2.6, −4.5 + i2.6, −i5.2, −i5.2]T , √ and the absolute value of all the coefficients is .5.2. Moreover, .5.2 = 3 3. In [44], it is shown that a bent function from . Z np → Z p , where . Z p is the ring of integers smaller than . p, exist for every prime . p when .n is even, and for every prime . p ≥ 3 when .n is odd. Ternary functions are a particular example for . p = 3, which is a prime number. Therefore, they exist for both .n even and odd. In [25], it is stated that bent functions exist for every . p and every .n except when .n is odd and . p = 2 computed modulo .4. Further, ternary bent functions are also perfect non-linear functions and vice versa [44]. However, in [38], it is shown that . p-valued bent functions of the Maiorana–McFarland class are not maximally non-linear. Recall that in the general case, a perfect non-linear function . f : Z np → Z p is bent, but the converse is true if . p is a prime. Example 1.11 The ternary function in four variables .

f (x1 , x2 , x3 , x4 ) = x1 x3 ⊕ x2 x3 ⊕ x2 x4

is bent of degree .2. Its function vector is F = [0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1, 2, 1, 2, 0, 2, 0, 1, 0, 2, 1, 2, 1, 0, 1, 0, 2,

.

0, 0, 0, 1, 1, 1, 2, 2, 2, 0, 1, 2, 2, 0, 1, 1, 2, 0, 0, 2, 1, 0, 2, 1, 0, 2, 1, 0, 0, 0, 2, 2, 2, 1, 1, 1, 0, 1, 2, 0, 1, 2, 0, 1, 2, 0, 2, 1, 1, 0, 2, 2, 1, 0] T . The Vilenkin–Chrestenson spectrum is

1.7 Ternary Bent Functions

23

S f = [9, 9, 9, 9, 9, 9, 9, 9, 9, 9, −4.5 − i7.8, −4.5 + i7.8, 9, −4.5 − i7.8,

.

−4.5 + i7.8, 9, −4.5 − i7.8, −4.5 + i7.8, 9, −4.5 + i7.8, −4.5 − i7.8, 9, −4.5 + i7.8, −4.5 − i7.8, 9, −4.5 + i7.8, −4.5 − i7.8, 9, −4.5 + i7.8, −4.5 − i7.8, −4.5 − i7.8, 9, −4.5 + i7.8, −4.5 + i7.8, −4.5 − i7.8, 9, 9, 9, 9, −4.5 − i7.8, −4.5 − i7.8, −4.5 − i7.8, −4.5 + i7.8, −4.5 + i7.8, −4.5 + i7.8, 9, −4.5 − i7.8, −4.5 + i7.8, −4.5 − i7.8, −4.5 + i7.8, 9, −4.5 − i7.8, 9, −4.5 − i7.8, −4.5 + i7.8, −4.5 + i7.8, 9, −4.5 − i7.8, −4.5 − i7.8, −4.5 + i7.8, 9, 9, −4.5 + i7.8, −4.5 − i7.8, −4.5 + i7.8, 9, −4.5 − i7.8, 9, −4.5 + i7.8, 9, 9, 9, −4.5 + i7.8, −4.5 + i7.8, −4.5 + i7.8, −4.5 − i7.8, −4.5 − i7.8, −4.5 − i7.8]T , and all the coefficients have the same absolute value equal to .9, and the absolute-valued spectrum is flat. The ternary function with the function vector F = [1, 1, 1, 0, 0, 0, 0, 2, 2, 2, 1, 2, 1, 2, 0, 2, 0, 1, 0, 2, 1, 2, 1, 0, 1, 0, 2,

.

0, 0, 0, 1, 1, 1, 2, 2, 2, 0, 1, 2, 2, 0, 1, 1, 2, 0, 0, 2, 1, 0, 2, 1, 0, 2, 1, 0, 0, 0, 2, 2, 2, 1, 1, 1, 0, 1, 2, 0, 1, 2, 0, 1, 2, 0, 2, 1, 1, 0, 2, 2, 1, 0] T is balanced, thus, it is not bent. Ternary bent functions are interesting mathematical objects, and therefore worth studying. Further motivation to study ternary bent functions relates to their applications; some of them are mentioned below. Generalized bent functions, i.e.,. p-valued bent functions, including ternary bent functions (. p = 3), are useful in the Code Division Multiple Access (CDMA) method, a form of multiplexing, for accessing channels in various radio communication technologies [25, 45]. Most of . p-ary bent functions are weakly regular [46]. Examples of . p-ary bent functions that do not exhibit this feature are given in [47]. Such functions are useful to construct certain combinatorial objects, like strongly regular graphs [48], association schemes, etc., [49]. Further, . p-ary bent functions are closely related to certain combinatorial and algebraic objects such as Hadamard difference sets [50], relative difference sets [41], planar functions, i.e., perfect non-linear functions, and commutative semifields [51]. The partial difference sets constructed from ternary bent functions also correspond to projective two-weight codes in [52].

24

1 Basic Concepts and Notations

In the ternary case, we consider as basic bent functions the functions that are expressed by the sum of disjoint pairs of variables. In the case of an odd .n, a variable is taken as its square. Thus, the basic bent functions for the even and odd number of variables respectively are .

f p (x1 , . . . , xn ) = x1 x2 ⊕ x3 x4 ⊕ . . . ⊕ xn−1 xn ,

and .

f p (x1 , . . . , xn ) = x1 x2 ⊕ x3 x4 ⊕ . . . ⊕ xn−2 xn−1 ⊕ xn2 .

The functions represented by the sum of squares of variables are another example of basic ternary bent functions .

f s (x1 , . . . , xn ) = x12 ⊕ x22 ⊕ . . . ⊕ xn2 ,

where the index .s refers to the sum of squares. These functions are often called quadratic functions.

1.8

Quaternary Bent Functions

Recall that by following the approach assumed in this book, and also adopted by other authors, see for example [44, 53, 54], the term quaternary functions means functions defined as . f : Z 4n → Z 4 , where . Z 4 is the ring of non-negative integers smaller than .4. Thus, the functions and their variables can take four different values conveniently identified with the first four non-negative integers .0, .1, .2, and .3. We process them by using the complex-valued Vilenkin–Chrestenson transform after complex encoding of their values. Therefore, we do not work with bent functions in the finite field .G F(4), although there are numerous studies of such bent functions; see, for example, [38, 55, 56]. For more information, we refer to Chap. 15.4 in [3] and references therein. Nevertheless, we use the operations in .G F(4) to generate sequences of quaternary values as particular examples of quaternary functions. The quaternary bent functions can be characterized in different ways. A probably most common characterization is in terms of the Vilenkin–Chrestenson spectra. See, for example, [57] and references therein. Unlike the binary case, and as in the ternary case, the quaternary bent functions are not necessarily maximally non-linear [38]. As stated in [58], it is possible to construct maximally non-linear quaternary functions that are not bent. Definition 1.16 (Quaternary bent functions) A quaternary function is bent iff after complex encoding of function values its Vilenkin–Chrestenson spectrum is flat, meaning that all its Vilenkin–Chrestenson coefficients have the same absolute value equal to .4n/2 .

1.9

Distribution of Function Values and Bentness

25

Example 1.12 The quaternary function . f (x1 , x2 ) = x1 x2 with multiplication modulo .4 is represented by the vector F = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 0, 2, 0, 3, 2, 1]T ,

.

which after encoding is F = [1, 1, 1, 1, 1, i , −1, −i , 1, −1, 1, −1, 1, −i , −1, i]T ,

.

and its Vilenkin–Chrestenson spectrum is S f = [4, 4, 4, 4, 4, −4i , −4, 4i , 4, −4, 4, −4, 4, 4i , −4, −4i]T .

.

The vector of absolute values of the Vilenkin–Chrestenson coefficients is the constant .4 which equals .4n/2 = 41 , since .n = 2, and it follows that this function is bent. Example 1.13 Unlike the ternary case, the quaternary function in two variables. f (x1 , x2 ) = x12 ⊕ x22 is not bent, but a plateaued function since the coefficients in its Vilenkin– Chrestenson spectrum take two different absolute values [59], S f = [i8, 0, 8, 0, 0, 0, 0, 0, 8, 0, −i8, 0, 0, 0, 0, 0].

.

1.9

Distribution of Function Values and Bentness

As noticed above, a binary bent function can have either .2n−1 − 2n/2−1 or .2n−1 + 2n/2−1 non-zero values. For example, if .n = 4, the function vector of a binary bent function can have either .6 or .10 non-zero elements. It is obvious that for a function . f with the given number of non-zero elements in the function vector, its logic complement . f has the other possible number of non-zero values. For ternary and quaternary functions, there are also some restrictions in the appearance of function values which should be satisfied for a function to be bent. These restrictions are conveniently expressed in terms of concepts of distributions and compositions of function values [60]. The term composition is used when speaking of function values of a concrete function and it shows how many times each of possible values appears in the function vector of a function given. For a . p-valued function, the composition is defined as a . p-tuple .C = (c0 , c1 , . . . , c p−1 ) whose coordinate .ci shows how many times the .ith value appears in the function vector. Functions derived from each other by encoding of function values have compositions identical up to the permutation of their coordinates, but they are viewed as different functions. For this reason the concept of distribution is introduced . D = (d0 , d1 , . . . , d p−1 ), and it shows how many times function values appear in the function vector, but without specifying which value is taken how many times. Unlike the composition where the .ith coordinate .ci corresponds to the .ith value, in distribution this is not necessarily the case. Therefore, functions whose compositions are related by

26

1 Basic Concepts and Notations

permutation of their coordinates have the same distribution. Therefore, for a given function, the distribution is identical to its composition, if the coordinates .di are ordered such that they correspond to the values .0, 1, . . . , p − 1. Accordingly, when we discuss a set of functions derived by manipulating a given function, which is then called the representative or the basic function, the composition of this function is the distribution for the set. Example 1.14 The ternary function . f (x1 , x2 ) = x1 x2 has the function vector F = [0, 0, 0, 0, 1, 2, 0, 2, 1]T ,

.

and its composition is .C = (5, 2, 2), since it takes .5 times the value .0, and other two values two times each. If we perform encoding of function values as .(0, 1, 2) → (1, 0, 2), we get the function whose functional expression is . f e (x1 , x2 ) = 1 ⊕ x1 x2 , and the function vector is Fe = [1, 1, 1, 1, 2, 0, 1, 0, 2]T .

.

For this function, the composition is .Ce = (2, 5, 2). Both functions . f and . f e have the same distribution . D = (5, 2, 2). Regarding the distribution of function values of . p-valued bent functions, the following statement is shown in [44]. Let .n be even and . p a prime. Then, the value distribution of a bent function . f : Z np → Z p is . D = (b0 , b1 , . . . , b p−1 ), where n

b0 = p n−1 ± ( p − 1) p 2 −1 ,

.

bk = p

n−1

∓p

n 2 −1

(1.5)

,

for .k = 1, 2, . . . , p − 1, or its cyclic shift. Here the .± signs are taken correspondingly. Moreover, a regular bent function takes the upper signs. Recall that a bent function is regular if its normalized spectral coefficients are the . pth roots of unity. The spectral coefficients are normalized if they are divided by . p n/2 . The regular bent functions exist for even .n and for odd .n with . p ≡ 1 when computed modulo .4. For . p = 3, regular functions exists in even dimensions and their normalized Vilenkin– Chrestenson coefficients are .1, .e1 , and .e2 . The normalized spectral coefficients of a weakly regular function are a rotation through some multiple of .π/2 of the . pth roots of unity. An example of ternary bent functions having the distribution which is computed by (1.5) using the lower signs are the basic bent functions whose functional expressions are the sum of squares of variables . f s = x12 ⊕ x22 ⊕ · · · ⊕ xn2 when the number of variables .n computed modulo .4 is .2 [44].

1.9

Distribution of Function Values and Bentness

27

Table 1.4 Compositions of function values in ternary bent functions . f p for .n = 1, 2, . . . , 14 .n

Compositions and representatives

1

.C 1

= (0, 1, 2) f p = x12 .C 2 = (5, 2, 2) . f p = x1 x2 .

2

= (6, 9, 12) 2 . f p = x1 x2 ⊕ x 3

3

.C 3

4

.C 4

= (33, 24, 24) f p = x1 x2 ⊕ x3 x4 .C 5 = (72, 81, 90) 2 . f p = x1 x2 ⊕ x3 x4 ⊕ x 5 .

5 6

= (225, 252, 252) f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6

.C 6 .

= (702, 729, 756) 2 . f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x 7

7

.C 7

8

.C 8

9

.C 9

= (2241, 2160, 2160) . f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x7 x8 = (6561, 6642, 6480) f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x7 x8 ⊕ x92 .C 10 = (19845, 19602, 19602) . f p = x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 7 x 8 ⊕ x 9 x 10 .

10 11

= (59049, 59292, 58806) 2 f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x7 x8 ⊕ x9 x10 ⊕ x11

.C 11 .

= (177633, 176904) . f p = x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 7 x 8 ⊕ x 9 x 10 ⊕ x 11 x 12

12

.C 12

13

.C 13

14

.C 14

= (531441, 532170, 530712) 2 . f p = x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 7 x 8 ⊕ x 9 x 10 ⊕ x 11 x 12 ⊕ x 13 .

= (1595781, 1593594, 1593594) f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x7 x8 ⊕ x9 x10 ⊕ x11 x12 ⊕ x13 x14

Table 1.4 shows compositions of function values for the other class of basic ternary bent functions . f p in .n = 1, 2, . . . , 14 variables whose functional expressions are the sum of products of disjoint pairs of variables [61]. The compositions are computed by (1.5) by using the upper signs. These compositions can be viewed as distributions for all ternary bent functions in .n = 1, 2, . . . , 14 variables derived by manipulating these basic ternary bent functions by permuting their values in the function vector, as well as by performing encoding of function values.

28

1 Basic Concepts and Notations

The distribution . D = (d0 , d1 , d2 ) for the basic ternary bent function . f p and .n even for n > 2 is computed from the distribution of bent functions. f p in a smaller number of variables as

.

d0 (n) = 5d0 (n − 2) + 2d1 (n − 2) + 2d2 (n − 2),

.

d1 (n) = 5d1 (n − 2) + 2d0 (n − 2) + 2d2 (n − 2), d2 (n) = 5d2 (n − 2) + 2d0 (n − 2) + 2d1 (n − 2), where .d0 (2) = 5, .d1 (2) = 2, and .d2 (2) = 2. The distribution . D = (d0 , d1 , d2 ) for the function . f p with .n odd and greater than .2 is computed as d0 (n) = d0 (n − 1) + 2d2 (n − 1),

.

d1 (n) = d1 (n − 1) + 2d0 (n − 1), d2 (n) = d2 (n − 1) + 2d1 (n − 1), where .d0 (2) = 5, .d1 (2) = 2, and .d2 (2) = 2. For the functions . f s , if the number of variables .n computed modulo .4 is .0, these functions belong to the class of regular bent functions and in these cases share the same distribution as . f p [44]. If .n is even and .n / = 0 when computed modulo .4, these functions express a distribution different from that for . f p . For convenience, we call this distribution the secondary distribution just to distinguish it from the distribution satisfied by both . f p and . f s . As noticed in [44], for.n = 2 when computed modulo.4, the distribution for. f s is computed by using the lower signs in (1.5), while the distribution for. f p is computed by using the upper signs. Table 1.5 shows compositions for the functions . f s for .n = 2, 6, 10, 14 which are the Table 1.5 Compositions of function values in ternary bent functions . f s for .n = 2, 6, 10, 14 .n

Compositions and representatives

2

.C

= (1, 4, 4) f s = x12 ⊕ x22 .C = (261, 234, 234) 2 2 2 2 2 2 .f = x ⊕x ⊕x ⊕x ⊕x ⊕x 1 2 3 4 6 5 .

6 10

= (19521, 19764, 19764) f = x12 ⊕ x22 ⊕ x32 ⊕ x42 ⊕ x52 ⊕ x62 ⊕ x72 ⊕ x82 2 . ⊕x92 ⊕ x10 .C .

14

= (1592865, 1595052, 1595052) f = x12 ⊕ x22 ⊕ x32 ⊕ x42 ⊕ x52 ⊕ x62 ⊕ x72 ⊕ x82 2 ⊕ x2 ⊕ x2 ⊕ x2 ⊕ x2 . ⊕x92 ⊕ x10 11 12 13 14 .C .

1.9

Distribution of Function Values and Bentness

29

secondary distributions for these and other functions derived from them [61]. These numbers of variables are equal to .2 when computed modulo .4. In the value vector of a ternary bent function, except for .n = 1, all three values conveniently denoted as .{0, 1, 2} should be present under the condition that the function cannot be balanced, i.e., all three values cannot appear equal number of times. For .n = 1, the function vector of a ternary bent function contains two equal values, and the third value is different. In the case of quaternary functions, not all four values should appear in a function vector the Vilenkin–Chrestenson transform of which results in a flat spectrum. In the literature available to the authors, there is no general formula analogous to (1.5) for distributions of quaternary bent functions. Experimental investigation shows that for .n = 2, there are examples of distributions of function values . D = (8, 2, 4, 2), . D = (6, 4, 2, 4), and . D = (6, 4, 6, 0) with permutations of the coordinates allowed, which is equivalent to different encoding of function values. Example 1.15 The quaternary function . f (x1 , x2 ) = x1 x2 where the multiplication is modulo .4 has the function vector F = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 0, 2, 0, 3, 2, 1]T .

.

Therefore, the composition of function values is .C = (8, 2, 4, 2). This function is bent, since the Vilenkin–Chrestenson spectrum is flat S f = [4, 4, 4, 4, 4, −4i , −4, 4i , 4, −4, 4, −4, 4, 4i , −4, −4i]T ,

.

meaning that all the spectral coefficients have the same absolute values. Adding an affine function to a bent function produces another bent function. Thus, the function . f (x1 , x2 ) = x1 x2 ⊕ x1 ⊕ 3, where addition .⊕ is modulo .4 is also bent. Its function vector is F = [3, 0, 1, 2, 3, 1, 3, 1, 3, 2, 1, 0, 3, 3, 3, 3]T ,

.

and the composition is .C = (2, 4, 2, 8). The Vilenkin–Chrestenson spectrum is flat S f = [−4i, −4i , −4i , −4i , 4, −4i , −4, 4i , 4i , −4i , 4i , −4i , −4, −4i , 4, 4i]T .

.

Example 1.16 For the quaternary function . f (x1 , x2 ) = x13 ⊕ x23 where exponentiation and addition are modulo .4, the function vector is F = [0, 1, 0, 3, 1, 2, 1, 0, 0, 1, 0, 3, 3, 0, 3, 2]T ,

.

with the composition .C = (6, 4, 2, 4). This is a bent function, since the Vilenkin– Chrestenson spectrum is flat

30

1 Basic Concepts and Notations

S f = [4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4, −4, −4, −4, −4, 4]T .

.

Example 1.17 The function specified by the function vector F = [0, 0, 0, 2, 0, 1, 1, 2, 2, 2, 0, 2, 1, 0, 2, 1]T

.

has the composition. D = (6, 4, 6, 0), and it is bent, since its Vilenkin–Chrestenson spectrum is flat S f = [4i , −4i , 4, 4i , 4, −4i , −4i , 4i , −4i , −4, 4, −4, 4, 4, 4i , 4]T .

.

This is an example of functions whose function vectors do not contain all the quaternary values. The following examples illustrate functions with secondary distributions. If we consider ∑n functions whose functional expressions are the sum of power of variables . f = i=1 xir , it can be concluded that for .r = p − 1, the functions are bent, while for other values of .r they are not bent. Example 1.18 Notice that in the binary case, the function . f (x1 , x2 ) = x1 ⊕ x2 , with addition modulo .2, is balanced and linear and therefore not bent. It is equivalent to the function 2 2 . f (x 1 , x 2 ) = x ⊕ x , since in the binary case . x i · x i = x i . 1 2 It is similar in the ternary case. The function . f (x1 , x2 ) = x1 ⊕ x2 is balanced and linear, and therefore not bent. In the ternary case, the function . f (x1 , x2 ) = x12 ⊕ x22 is bent. Its composition is .C = (1, 4, 4). The ternary case function . f (x1 , x2 ) = x13 ⊕ x23 has the function vector F = [0, 1, 2, 1, 2, 0, 2, 0, 1]T ,

.

and the composition is .C = (3, 3, 3). Therefore, this function is balanced and does not satisfy the required distribution for ternary bent functions in two variables. For quaternary functions, . f (x1 , x2 ) = x1 ⊕ x2 with addition modulo .4 is linear and balanced, with the function vector F = [0, 1, 2, 3, 1, 2, 3, 0, 2, 3, 0, 1, 3, 0, 1, 2]T ,

.

and therefore, it is not bent. In the quaternary case, the function with the functional expression . f (x1 , x2 ) = x12 ⊕ x22 with addition modulo .4 has the function vector as F = [0, 1, 0, 1, 1, 2, 1, 2, 0, 1, 0, 1, 1, 2, 1, 2]T ,

.

1.10

Spectral Invariant Operations

31

and the value.3 is missing. The composition is.C = (4, 8, 4, 0). The vector of absolute values of the Vilenkin–Chrestenson coefficients is S f = [8, 0, 8, 0, 0, 0, 0, 0, 8, 0, 8, 0, 0, 0, 0, 0]T ,

.

and it is not flat. Therefore, this function is not bent. But, the quaternary function . f (x1 , x2 ) = x13 ⊕ x23 is bent as shown in Example 1.16. The quaternary function specified by the function vector F = [1, 3, 1, 3, 3, 0, 0, 3, 1, 0, 1, 0, 1, 2, 2, 1]T

.

has the composition .C = (4, 6, 2, 4); however, it is not bent which can be seen from the vector of absolute values of its Vilenkin–Chrestenson spectrum rounded to integers S f = [3, 0, 6, 0, 8, 4, 3, 4, 3, 0, 6, 0, 3, 4, 3, 4]T .

.

1.10

Spectral Invariant Operations

In spectral representations of discrete functions, it is useful to consider the so-called spectral invariant operations defined as operations that do not change the absolute values of spectral coefficients. Therefore, when applied to variables and function values, their impact to spectral coefficients reduces to reordering or sign changes of some subsets of coefficients or both at the same time. This reordering of spectral coefficients is not arbitrary, but due to the structure of the transform matrices, it is restricted to permutations of certain precisely determined subsets of spectral coefficients. Due to this feature, spectral invariant operations are particularly interested when discussing bent functions, since their application to a bent function preserves bentness. Various combinations of spectral invariant operations applied in different orders to a bent function produce a variety of bent functions. We will present in detail the spectral invariant operations and determine the corresponding permutations of subsets of spectral coefficients for binary functions and the Walsh transform. The generalization to ternary and quaternary functions and the corresponding Vilenkin– Chrestenson transforms is straightforward [68]. Spectral invariant operations can be enumerated as follows [34, 35]: 1. Polarization of a function, . f (x) → g(x) = f (x) ⊕ k, with .k = 1 for binary and .k ∈ {1, 2}, and .k ∈ {1, 2, 3}, for ternary and quaternary functions, respectively. 2. Polarization of an input variable, .xi → xi ⊕ k, with .k = 1 for binary and .k ∈ {1, 2}, and .k ∈ {1, 2, 3} for ternary and quaternary functions, respectively. Thus, .

f (x1 , . . . , xi , . . . , xn ) → g(x1 , . . . , xi ⊕ k, . . . , xn ).

In the binary case .xi → xi ⊕ 1 = xi , i.e.,

32

1 Basic Concepts and Notations .

f (x1 , . . . , xi , . . . , xn ) → g(x1 , . . . , xi , . . . , xn ).

3. Adding a variable to the function, . f (x) → g(x) = f (x) ⊕ k · xi . In the binary case .g(x) = f (x) ⊕ x i . 4. Interchanging of input variables, .xi ↔ x j . Thus, .

f (x1 , . . . , xi , . . . x j , . . . , xn ) → g(x) = f (x1 , . . . , x j , . . . xi , . . . , xn ).

5. Replacement of an input variable by a sum of variables containing the replaced variable . x i → x i ⊕ (k · x j ), i.e., .

f (x1 , . . . , xi , . . . , xn ) → g(x1 , . . . , xi ⊕ (k · x j ), . . . , xn ).

The restriction is that the replacing sum of variables must contain the replaced variable xi .

.

The operations .3 and .5 are called the disjoint spectral translation and spectral translation, respectively. The above-enumerated spectral invariant operations in the original domain have the corresponding representations in the spectral domain [34, 35], and preserve special properties of a spectrum, from where originates their name. Particularly, they do not change the absolute values of spectral coefficients; thus, they preserve the flatness of the spectrum which is an important property when discussing bent functions. In the spectral domain, spectral invariant operations in the order as enumerated above can be expressed as 1. Multiplication of spectral coefficients with a constant equal to .ek . 2. Componentwise multiplication of the spectrum with the function vector of .xik . 3. Reordering of subsets of spectral coefficients as .

Sgl1 ,...,li ⊕k,...,ln → S fl1 ,...,li ,...,ln ,

where .li for binary, ternary, and quaternary functions are coordinates in binary, ternary, and quaternary representations of indices of spectral coefficients. 4. Reordering of subsets of spectral coefficients as .

S fl1 ,...,li ,...l j ,...,ln → S fl1 ,...,l j ,...li ,...,ln .

5. Reordering of pairs of spectral coefficients as .

Sgl1 ,...,li ,l j⊕( p−k) ,...,ln → S fl1 ,...,li ,l j ,...,ln .

1.10

Spectral Invariant Operations

33

Note that for binary switching functions, polarization actually means taking the complement of a binary variable or the function value. In other words, this is the negation of the binary value and can be expressed as .xi = xi ⊕ 1 for variables and the same for function values . f (i ) = f (i ) ⊕ 1. As a direct generalization, for ternary and quaternary functions the polarization is defined as addition of a constant to a variable or a function, i.e., .xi ⊕ k, and . f ⊕ k, where .k = 1, 2 and .k = 1, 2, 3, for ternary and quaternary functions, respectively. The following example shows how binary bent functions in four variables can be generated from a given bent function of the same number of variables by spectral invariant operations. The extension to any even .n is straightforward. Example 1.19 Consider the set . S4 of all binary bent functions of four variables. The degree of these functions is .2. A computer enumeration over all binary functions for .n = 4 shows that there are .896 bent functions. All functions are in the same class in the classification with respect to the values of Walsh coefficients, since they all have the spectral coefficients with the absolute value .4. Since all these bent functions have the degree .2, they can be generated from the class representative . f (x1 , x2 ) = x1 x2 ⊕ x3 x4 by using the following spectral invariant operations: 1. 2. 3. 4. 5.

Negation of . f , Negation of variables, Permutation of variables, Spectral translation .xi → xi ⊕ x j , Disjoint spectral translation . f → f ⊕ xi .

1. We start from the function . f 1 = x1 x2 ⊕ x3 x4 where the addition is modulo .2. In bent functions, all variables are essential and have to be included in performing spectral invariant operations. 2. By using the permutation of the variables, it is possible to construct two new functions .

f 2 = f 1 (x1 ↔ x3 ) = x2 x3 ⊕ x1 x4 , f 3 = f 1 (x1 ↔ x4 ) = x2 x4 ⊕ x1 x3 .

The application of other permutations produces again these three functions. For example, .

f 1 (x2 ↔ x4 ) = x1 x4 ⊕ x2 x3 = f 2 , f 1 (x2 ↔ x3 ) = x1 x3 ⊕ x2 x4 = f 3 , f 1 (x1 ↔ x2 ) = x1 x2 ⊕ x3 x4 = f 1 , f 1 (x3 ↔ x4 ) = x1 x2 ⊕ x3 x4 = f 1 .

3. By using the spectral translation .xi = xi ⊕ x j , it is possible to increase the number of quadratic terms in the functions. For example,

34

1 Basic Concepts and Notations .

f 4 = f 1 (x1 → x1 ⊕ x3 ) = x1 x2 ⊕ x2 x3 ⊕ x3 x4 , f 5 = f 1 (x1 → x1 ⊕ x4 ) = x1 x2 ⊕ x2 x4 ⊕ x3 x4 , f 6 = f 1 (x2 → x2 ⊕ x3 ) = x1 x2 ⊕ x1 x3 ⊕ x3 x4 , f 7 = f 1 (x2 → x2 ⊕ x4 ) = x1 x2 ⊕ x1 x4 ⊕ x3 x4 .

From each of the three starting functions . f 1 , . f 2 , . f 3 , it is possible to construct other four functions with three quadratic terms. After this operation, there are three functions with two quadratic terms and .12 functions with three quadratic terms. Note that it is possible to increase the number of quadratic terms exclusively if the variables .xi and .x j are from different product terms. If they are taken from the same product term, the result will be an additional linear term witch we do not consider for now, but it will be taken into account later. For example, .

f 1 (x1 → x1 ⊕ x2 ) = x1 x2 ⊕ x2 ⊕ x3 x4 .

4. By using the same invariant operation .xi = xi ⊕ x j , but with other disjoint variable, we construct from each function with three quadratic terms another function with four quadratic terms. For example, .

f 9 = f 4 (x1 → x1 ⊕ x4 ) = x1 x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x3 x4 ,

f 10 = f 5 (x1 → x1 ⊕ x3 ) = x1 x2 ⊕ x2 x3 ⊕ x2 x4 ⊕ x3 x4 , f 11 = f 6 (x2 → x2 ⊕ x4 ) = x1 x2 ⊕ x2 x4 ⊕ x1 x3 ⊕ x3 x4 , f 12 = f 7 (x2 → x2 ⊕ x3 ) = x1 x2 ⊕ x1 x3 ⊕ x1 x4 ⊕ x3 x4 . It is possible to construct.12 functions with four quadratic terms. The number of functions constructed until now is .3 + 12 + 12 = 27. 5. It is possible to show that it is impossible to construct a function with five quadratic terms. Each new operation .xi = xi ⊕ x j results in a quadratic term which already exists in the considered function and that will reduce the number of quadratic terms. For example, .

f 13 = f 9 (x2 → x2 ⊕ x3 ) = x1 (x2 ⊕ x3 ) ⊕ (x2 ⊕ x3 )x4 ⊕ (x2 ⊕ x3 )x3 ⊕ x3 x4 = x1 x2 ⊕ x1 x3 ⊕ x2 x4 ⊕ x2 x3 ⊕ x3 , f 14 = f 13 (x1 → x1 ⊕ x4 ) = (x1 ⊕ x4 )x2 ⊕ (x1 ⊕ x4 )x3 ⊕ x2 x4 ⊕ x2 x3 ⊕ x3 = x1 x2 ⊕ x1 x3 ⊕ x3 x4 ⊕ x2 x3 ⊕ x3 .

However, it is possible to construct a function with .6 quadratic terms. We first perform

1.10

Spectral Invariant Operations .

35

f 15 = f 9 (x2 → x2 ⊕ x3 ) = x1 (x2 ⊕ x3 ) ⊕ (x2 ⊕ x3 )x4 ⊕ (x2 ⊕ x3 )x3 ⊕ x3 x4 = x1 x2 ⊕ x1 x3 ⊕ x2 x4 ⊕ x2 x3 ⊕ x3 .

Then, we perform .

f 16 = f 15 (x2 → x2 ⊕ x4 ) = x1 (x2 ⊕ x4 ) ⊕ x1 x3 ⊕ (x2 ⊕ x4 )x4 ⊕ (x2 ⊕ x4 )x3 ⊕ x3 = x1 x2 ⊕ x1 x4 ⊕ x1 x3 ⊕ x2 x4 ⊕ x4 ⊕ x2 x3 ⊕ x3 x4 ⊕ x3 .

After that, we perform .

f 17 = f 16 ⊕ x3 ⊕ x4 = x1 x2 ⊕ x1 x4 ⊕ x1 x3 ⊕ x2 x4 ⊕ x2 x3 ⊕ x3 x4 .

The number of different bent functions with solely quadratic terms is now .27 + 1 = 28. 6. By using the operation. f ' = f ⊕ xi , from each bent function with solely quadratic terms it is possible to construct .16 functions with additional linear terms. For example, .

f 18 = f 1 ⊕ x1 = x1 x2 ⊕ x3 x4 ⊕ x1 .

The number of bent functions generated until now is .28 × 16 = 448. 7. By using the operation . f ' = f ⊕ 1, the complement of the function . f is be obtained. If the complements of all .448 functions are produced, the total number of binary bent functions for .n = 4 is .896. The spectral invariant operations discussed above are sometimes called classical or affine spectral invariant operations since they can be expressed in terms of the affine transformations over variables and function values [62–64]. In the discussion of bent functions, we will consider also another spectral invariant operation defined in [65]. The definition of this operation is based upon the following considerations. We consider functions whose functional expressions are a homogeneous sum of products of disjoint pairs of variables. The term homogeneous means that in the functional expression all the variables are involved. For functions specified by such functional expressions, adding the product of variables with each variable taken from a different product term does not change the absolute value of spectral coefficients [65, 66]. This operation is called the generalized spectral invariant operation and can be used for either binaryor multiple-valued functions. Example 1.20 illustrates the application of this operation to binary functions defined as the sum of disjoint products of variables.

36

1 Basic Concepts and Notations

Example 1.20 For .n = 2, . f 1 = x1 x2 , . f 2 = x1 x2 ⊕ x1 , and . f 3 = x1 x2 ⊕ x2 have the same absolute-valued Walsh spectra. For .n = 3, functions . f 1 = x1 x2 ⊕ x2 x3 , and . f 2 = x1 x2 ⊕ x1 x3 have the same absolutevalued Walsh spectrum. For .n = 4, functions .

f 1 = x1 x2 ⊕ x3 x4 , f 2 = x1 x2 ⊕ x3 x4 ⊕ x1 x3 , f 3 = x1 x2 ⊕ x3 x4 ⊕ x2 x4 , f 4 = x1 x2 ⊕ x3 x4 ⊕ x1 x4 , f 5 = x1 x2 ⊕ x3 x4 ⊕ x2 x3 , f 6 = x1 x3 ⊕ x2 x4 , f 7 = x1 x3 ⊕ x2 x4 ⊕ x1 x2 , f 8 = x1 x3 ⊕ x2 x4 ⊕ x1 x4 , f 9 = x1 x3 ⊕ x2 x4 ⊕ x2 x3 ,

f 10 = x1 x3 ⊕ x2 x4 ⊕ x3 x4 have the same absolute-valued Walsh spectrum, since they are obtained by using the generalized spectral invariant operation [65, 66]. This operation allows adding product terms consisting of variables from distinct pairs of variables in the initial function represented by the sum of disjoint pairs of variables. As an illustration, we show the Walsh spectra of these functions computed after encoding .(0, 1) → (1, −1) the function values S f1 = [4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4, −4, −4, −4, −4, 4]T ,

.

S f2 = [4, 4, 4, −4, 4, −4, 4, 4, 4, 4, 4, −4, −4, 4, −4, −4]T , S f3 = [4, 4, 4, −4, 4, 4, 4, −4, 4, 4, −4, 4, −4, −4, 4, −4]T , S f4 = [4, 4, 4, −4, 4, 4, −4, 4, 4, 4, 4, −4, −4 − 4, 4, −4]T , S f5 = [4, 4, 4, −4, 4, 4, 4, −4, 4, −4, 4, 4, −4, 4, −4, −4]T , S f6 = [4, 4, 4, 4, 4, −4, 4, −4, 4, 4, −4, −4, 4, −4, −4, 4]T , S f7 = [4, 4, 4, −4, 4, −4, 4, 4, 4, 4, −4, 4, 4, −4, −4, −4]T , S f8 = [4, 4, 4, 4, 4, −4, −4, 4, 4, 4, −4, −4, 4, −4, 4, −4]T , S f9 = [4, 4, 4, 4, 4, −4, 4, −4, 4, −4, −4, 4, 4, 4, −4, −4]T , S f10 = [4, 4, 4, 4, 4, −4, 4, −4, 4, 4, −4, −4, −4, 4, 4, −4]T . For .n = 5, bent functions do not exist, but the generalized spectral operation can be applied to functions whose functional expression is the sum of disjoint pairs of variables

1.10

Spectral Invariant Operations

37

with a variable added. This led to the plateaued functions for .n = 5 whose Walsh spectral coefficients take three values.8,.−8, and.0; see, for instance, [59]. For, example, the functions .

f 1 = x1 x2 ⊕ x3 x4 ⊕ x5 , f 2 = x1 x2 ⊕ x3 x4 ⊕ x1 x3 x5 , f 3 = x1 x2 ⊕ x3 x4 ⊕ x2 x4 x5 , f 4 = x1 x2 ⊕ x3 x4 ⊕ x1 x4 x5 , f 5 = x1 x2 ⊕ x3 x4 ⊕ x2 x3 x5

have the following Walsh spectra: S f1 = [0, 8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 8, 0, 8, 0, −8,

.

0, 8, 0, 8, 0, 8, 0, −8, 0, −8, 0, −8, 0, −8, 0, 8] T , S f2 = [8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 0, 8, 8, 0, 0, −8, 8, 0, 8, 0, 8, 0, −8, 0, −8, 0, 0, −8, −8, 0, 0, 8] T , S f3 = [8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 8, 0, 0, 8, 0, −8, −8, 0, −8, 0, 0, −8, 0, 8] T , S f4 = [8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 8, 0, 0, 8, 0, −8, 8, 0, 8, 0, 8, 0, −8, 0, −8, 0, −8, 0, 0, −8, 0, 8] T , S f5 = [8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 8, 0, 8, 0, −8, 0, 8, 0, 0, 8, 8, 0, 0, −8, −8, 0, 0, −8, −8, 0, 0, 8] T . These functions are mutually related by adding the product term of three variables, each variable taken from a different pair of variables, where the variable .x5 is viewed as a reduced pair. For .n = 6, functions .

f 1 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 , f 2 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5 , f 3 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x6 , f 4 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x4 x5 , f 5 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x4 x6 , f 6 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x2 x3 x5 , f 7 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x2 x3 x6 , f 8 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x2 x4 x5 , f 9 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x2 x4 x6

38

1 Basic Concepts and Notations

have the same absolute-valued Walsh spectra; thus, they are all bent and are derived from the initial function . f 1 by adding a term of three variables, with each variable taken from a different pair of variables in the homogeneous disjoint expression for . f 1 . Example 1.20 illustrates that the generalized spectral invariant operation holds for any number of variables and any . p for functions with the specified functional expressions, leading to either bent or plateaued functions for .n even and odd, respectively [59, 65, 66]. In the case of an even number of variables, the generalized spectral translation says that given a bent function by the homogeneous sum of disjoint pairs of variables, another bent function can be constructed by adding disjoint terms in which variables are taken from different pairs of variables. This constructed function has the identical, but permuted spectral coefficients as the initial function from which it is derived. In Example 1.20, the functions for .n = 6 illustrate this case. The following two examples also illustrate for the binary and the ternary cases construction of new bent functions by adding the product terms while preserving the absolute values of spectral coefficients. It should be noticed that the generalized spectral translation can be used to increase the degree of constructed bent functions. Example 1.21 Given is a binary function in .n = 6 variables as .

f (x1 , . . . , x6 ) = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ,

whose function vector is F = [0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0,

.

0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 1, 0, 0, 0, 0, 1] T . Its Walsh spectrum is S f = [8, 8, 8, −8, 8, 8, 8, −8, 8, 8, 8, −8, −8, 8, 8, 8,

.

8, 8, 8, −8, 8, 8, 8, −8, 8, 8, 8, −8, −8, −8, −8, 8, 8, 8, 8, −8, 8, 8, 8, −8, 8, 8, 8, −8, −8, −8, −8, 8 −8, −8, −8, 8, −8, −8, −8, 8, −8, −8, −8, 8, 8, 8, 8, −8] T . This shows that the function is bent. The application of the generalized spectral translation permits definition of the following functions:

1.10

Spectral Invariant Operations .

39

f 1 = f ⊕ x1 x3 x5 ,

f 5 = f ⊕ x2 x3 x5 ,

f 2 = f ⊕ x1 x4 x5 ,

f 6 = f ⊕ x2 x4 x5 ,

f 3 = f ⊕ x1 x3 x6 ,

f 7 = f ⊕ x2 x3 x6 ,

f 4 = f ⊕ x1 x4 x6 ,

f 8 = f ⊕ x2 x4 x6 .

These functions have the same absolute-valued Walsh spectra and are all bent. Example 1.22 Given is a ternary bent function in .n = 5 variables as .

f (x1 , . . . , x5 ) = x1 x2 ⊕ x3 x4 ⊕ x52 .

The application of the generalized spectral translation permits definition of the following functions: .

f 1 = f ⊕ x1 x3 x5 , f 2 = f ⊕ x1 x4 x5 , f 3 = f ⊕ x2 x3 x5 , f 4 = f ⊕ x2 x4 x5 , f 5 = f ⊕ x3 x4 x5 .

The Vilenkin–Chrestenson spectra of these functions have identical absolute values of spectral coefficients as the initial function from which they are derived. All these functions are bent. Examples 1.21 and 1.22 lead to a more formal definition of the generalized spectral translation [59, 65], which we present for ternary functions, since in this case we should take into account functions in both even and odd number of variables. The formulations of the corresponding definition for the binary case simply follow from the case of even number of variables. Definition 1.17 Given is a ternary function . f in an even number of variables .n = 2 · q (q ≥ 1) defined by the homogeneous functional expression that is the sum of disjoint pairs of variables

.

.

f (x1 , x2 , · · · , xn ) = xi1 xi2 ⊕ xi3 xi4 ⊕ · · · ⊕ xin−1 xin ,

where .{i 1 , i 2 } ∩ {i 3 , i 4 } ∩ · · · ∩ {i n−1 , i n } = φ. A modification of . f into a function g = f ⊕ k · x j1 x j2 · · · x jq ,

.

40

1 Basic Concepts and Notations

where . j1 ∈ {i 1 , i 2 }, . j2 ∈ {i 3 , i 4 }, .· · · , . jq ∈ {i n−1 , i n }, and .k ∈ {1, 2}, results in the permutation of the following pairs of spectral coefficients .

Sg ··· ,t j

q ,···

↔ S f ··· ,t j

q ⊕k·tl1 ·tl2 ···tlq−1 ,···

,

where .l1 ∈ {i 1 , i 2 }, l1 / = j1 , .l2 ∈ {i 3 , i 4 }, l2 / = j2 , .· · · .lq−1 ∈ {i q−3 , i q−2 }, lq−1 / = jq−1 and all operations are modulo .3. Given is a ternary function . f in an odd number of variables .n = 2q + 1, .(q ≥ 2) defined by the homogeneous functional expression that is the sum of disjoint pairs of variables with the .nth variable appearing as a square .

f (x1 , x2 , · · · , xn ) = xi1 xi2 ⊕ xi3 xi4 ⊕ · · · ⊕ xin−2 xin−1 ⊕ xi2n ,

where .{i 1 , i 2 } ∩ {i 3 , i 4 } ∩ · · · ∩ {i n−2 , i n−1 } ∩ {i n } = φ. Modification of . f into a function g = f ⊕ k · x j1 x j2 · · · x jq x jq+1 ,

.

where . j1 ∈ {i 1 , i 2 }, . j2 ∈ {i 3 , i 4 }, .· · · , . jq ∈ {i n−2 , i n−1 } and . jq+1 = i n , for .k ∈ {1, 2}, results in the permutation of the following pairs of spectral coefficients .

Sg ··· ,t j

q ,···

↔ S f ··· ,t j

q+1 ⊕k·tl1 ·tl2 ···tlq ,···

,

where .l1 ∈ {i 1 , i 2 }, l1 / = j1 , .l2 ∈ {i 3 , i 4 }, l2 / = j2 · · · lq ∈ {i n−2 , i n−1 }, lq / = jq . It is clear that in the above definition, any variable can appear as a square, and the last variable .xn is taken just for the notational convenience. Referring to spectral invariant operations, adding a constant to a ternary bent function preserves its bentness, however, changes the composition it has. For instance, the function. f p for .n = 2 has the composition .(5, 2, 2), and adding the constant .1 changes its composition into.(2, 5, 2), while adding the constant .2 results in a function with the composition.(2, 2, 5). The coordinates of the composition are cyclically shifted. This is clear, since adding a constant to the function values corresponds to the cyclic shift .(0, 1, 2) ⊕ 1 → (1, 2, 0) and .(0, 1, 2) ⊕ 2 → (2, 0, 1). The distribution remains unchanged. As noticed above, adding a constant corresponds to an encoding of function values.

References 1. Zhegalkin, I.I.: On the techniques of calculating sentences in symbolic logic. Math. Sb. 34, 9–28 (1927). (in Russian) 2. Zhegalkin, I.I.: Arithmetic representations for symbolic logic. Math. Sb. 35, 311–377 (1928). (in Russian) 3. Tokareva, N.: Bent Functions - Results and Applications to Cryptography. Elsevier (2015) 4. Falkowski, B.J., Lozano, C.C.: Quaternary fixed-polarity Reed-Muller expansion computation through operations on disjoint cubes and its comparison with other methods. Comput. Electr. Eng. 31(2), 112–131 (2005)

References

41

5. Falkowski, B.J., Rahardja, S.: Efficient algorithm for the generation of fixed polarity quaternary Reed-Muller expansions. In: Proceeding of the 25th International Symposium on MultipleValued Logic, Bloomington, Indiana, USA, May 23–25, 158–163 (1995) 6. Falkowski, B.J., Rahardja, S.: Efficient computation of quaternary fixed polarity Reed-Muller expansions. IEE Proc. Comput. Digital Techn. 142(5), 345–352 (1995) 7. Green, D.H.: Reed-Muller expansions with fixed and mixed polarities over .G F(4). IEE Proc. Comput. Digital Techn. 137(5), 380–388 (1990) 8. Garaev, M.U., Faradzhev, R.G.: On an analog of Fourier expressions over Galois fields and its applications to problems of generalized sequential machines. Izv. Akad. Nauk Aizerb. SSR, Ser. Fiz.-Techn, i Mat. Nauk (6), 69–75 (1968) 9. Jankovi´c, D., Stankovi´c, R.S., Moraga, C.: Optimization of.G F(4) expressions using the extended dual polarity property. In: Proceeding of the 33rd International Symposium on Multiple-valued Logic, Tokyo, Japan, May 16–19, 50–55 (2003) 10. Jankovi´c, D., Stankovi´c, R.S., Moraga, C.: Optimization of polynomial expressions by using the extended dual polarity. IEEE Trans. Comput. 58(12), 1710–1725 (2009) 11. Stankovi´c, R.S., Astola, H., Astola, J.T.: Determining minimized Galois field expressions for ternary functions. In: Proceedings of the 41st International Symposium on Multiple-Valued Logic, Tuusula, Finland, May 23–25, 117–124 (2011) 12. Stankovi´c, R. S. Astola, J.T., Moraga, C.: Representation of Multiple-Valued Logic Functions. Claypool & Morgan Publishers (2012) 13. Reed, I.S.: A class of multiple error correcting codes and their decoding scheme. IRE Trans. Inf. Th. PGIT-4, 38–49 (1954) 14. Muller, D.E.: Boolean algebras in electric circuit design. Amer. Math. Monthly 61(7), Part 11, 27–28 (1954) 15. Cusick, T.W., St˘anic˘a, P.: Cryptographic Boolean Functions and Applications. Academic/Elsevier (2009) 16. Gibbs, J.E.: Instant Fourier transform. Electron. Lett. 13(5), 122–123 (1977) 17. Cooley, J.W., Tukey, J.W.: An algorithms for the machine calculation of complex Fourier series. Math. Comput. 19, 297–301 (1965) 18. Karpovsky, M.G., Stankovi´c, R.S., Astola, J.T.: Spectral Logic and Its Application in the Design of Digital Devices. Wiley (2008) 19. Yaroslavky, L.P.: Digital Picture Processing. Springer (1985) 20. Yaroslavsky, L.P.: Digital Holography and Digital Image Processing: Principles, Methods, Algorithms. Kluwer Academic Publishers (2003) 21. Good, I.J.: The interaction algorithm and practical Fourier analysis. J. Roy. Statist. Soc. Ser. B 20, 361–372 (1958). Addendum 22, 372–375 (1960) 22. Good, I.J.: The relationship between two fast Fourier transforms. IEEE Trans. Comput. C-20, 310–317 (1971) 23. Thomas, L.H.: Using a computer to solve problems in physics. In: Application of Digital Computers. Ginn, Boston, Mass (1963) 24. Stankovi´c, R.S.: The Reed-Muller-Fourier transform - Computing methods and factorizations. In: Seising, R., Allende-Cid, H. (eds.) Claudio Moraga - A Passion for Multi-Valued Logic and Soft Computing, pp. 121–151. Springer (2017) 25. Kumar, P.V., Scholtz, R.A., Welch, L.R.: Generalized bent functions and their properties. J. Combin. Theory Ser. A 40, 90–107 (1985) 26. Carlet, C., Mesnager, S.: Four decades of research on bent functions. Des. Codes Cryptogr. 78, 5–50 (2016) 27. Butler, J.T., Sasao, T.: Boolean functions for cryptography. In: Sasao, T., Butler, J.T. (eds.) Progress in Applications of Boolean Functions. Claypool & Morgan Publishers (2010)

42

1 Basic Concepts and Notations

28. Rothaus, O.: On bent functions. J. Combin. Theory. Ser. A 20(3), 300–305 (1976) 29. Yang, M., Meng, Q., Zhang H.: Evolutionary design of trace form bent functions. Cryptology ePrint Archive, Report 2005/322 30. Bernasconi, A., Codenotti, B., Vanderkam, J.M.: A characterization of bent functions in terms of strongly regular graphs. IEEE Trans. Comput. 50(9), 984–985 (2001) 31. Agievich, S.V.: Bent Rectangles. NATO Advanced Study Institute on Boolean Functions in Cryptology and Information Security, Zvenigorod, Russia, September 8–18 (2007). Proceedings Netherlands, pp. 3–22. IOS Press (2008) 32. Tokareva, N.N.: Nonlinear Boolean Functions - Bent Functions and Their Generalizations. LAP LAMBERT Academic Publishing, Saarbrucken, Germany, 180 p (2011)978-3-8433-0904-2 (in Russian) 33. Xiao, G.Z., Massey, J.L.: A spectral characterization of correlation-immune combining functions. IEEE Trans. Inform. Theory IT-34(3), 569–571 (1988) 34. Hurst, S.L.: Logical Processing of Digital Signals. Crane Russak and Edward Arnold, London and Basel (1978) 35. Hurst, S.L., Miller, D.M., Muzio, J.C.: Spectral Techniques in Digital Logic. Academic, Bristol (1985) 36. MacWilliams, F.J., Sloane, N.J.A.: The Theory of Error-Correcting Codes. North-Holland, Amsterdam (1977) 37. Blondeau, C., Nyberg, K.: Perfect non-linear functions and cryptography. Finite Fields Appl. 32, 120–147 (2015) 38. Ryabov, V.: Nonlinearity of bent functions over finite fields. In: Proceeding of the 10th Workshop on Current Trends in Cryptology, (CTCrypt 2021), June 1–4, 2021, Dorokhovo, Ruza District, Moscow Region, Russia, 210–219 39. Logachev, O.A., Salnikov, A.A., Yashchenko, V.V.: Bent functions on a fnte Abelian group. Discrete Math. Appl. 7(6), 547–564 (1997) 40. Poinsot, L.: Bent functions on a finite non-Abelian group. J. Discrete Math. Sci. Cryptogr. 9(2), 349–364 (2006) 41. Pott, A.: Nonlinear functions in Abelian groups and relative difference sets. Discrete Appl. Math. 138, 177–193 (2004) 42. Solodovnikov, V.I.: Bent functions from a finite Abelian group into a finite Abelian group. Discretnaya Matematika 12(2), 111–126 (2002) 43. Poinsot, L.: Non-Abelian bent functions. Cryptogr. Commun. 4, 1–23 (2012) 44. Nyberg, K.: Constructions of bent functions and difference sets. In: Damgard, I.B. (ed.) Advances in Cryptology - EUROCRYPT 90, pp. 151–160. LNCS 473 (1991) 45. Wada, T.: Characteristic of bit sequences applicable to constant amplitude orthogonal multicode systems. IEICE Trans. Fundam. E83-A(11), 2160–2164 (2000) 46. Helleseth, T., Hollmann, H.D.L., Kholosha, A., Wang, Z., Xiang, Q.: Proofs of two conjectures on ternary weakly regular bent functions. IEEE Trans. Inform. Theory 55, 5272–5283 (2009) 47. Tan, Y., Yang, J., Zhang, X.: A recursive construction of . p-ary bent functions which are not weakly regular. In: 2010 IEEE International Conference on Information Theory and Information Security (ICITIS), Beijing, P. R. China, December 17–19, 56–159 (2010) 48. Chee, Y.M., Tan, Y., Zhang, X.De.: Strongly regular graphs constructed from . p-ary bent functions. J. Algebr. Comb. 34, 251–266 (2011) 49. Pott, A., Tan, Y., Feng, T., Ling, S.: Association schemes arising from bent functions. In: Kholosha, A., Rosnes, E., Parker, M. (eds.) Preproceedings of The International Workshop on Coding and Cryptography, Bergen, 48–61 (2009) 50. Dillon, J.F.: Elementary Hadamard Difference Sets. Ph.D. dissertation, University of Maryland, College Park (1974)

References

43

51. Weng, G.B., Qiu, W.S., Wang, Z.Y., Xiang, Q.: Pseudo-Paley graphs and skew Hadamard difference sets from presemifields. Des. Codes Cryptogr. 44, 49–62 (2007) 52. Calderbank, R., Kantor, W.M.: The geometry of two-weight codes. Bull. London Math. Soc. 18(2), 97–122 (1986) 53. Shaporenko, A.S.: Connections between quaternary and Boolean bent functions. Prikl. Diskr. Mat. Suppl. (12), 73–75 (2019) 54. Tokareva, N.: Generalizations of bent functions. A survey. Translated from Discrete Anal. Oper. Res. (Diskretn. Anal. Issled. Oper.) 17(1), 34–64 (2010) 55. Ambrosimov, A.S.: Properties of bent functions of .q-valued logic over finite fields. Discrete Math. Appl. 4(4), 341–350 (1994) 56. Coulter, R.S., Matthews, R.: Bent polynomials over finite fields. Bullet. Aust. Math. Soc. 56, 429–437 (1997) 57. Stankovi´c, S., Stankovi´c, M., Astola, J.: Representation of multiple-valued functions with flat Vilenkin-Chrestenson spectra by decision diagrams. Mutiple-Valued Log. & Soft Comput. 23(5– 6), 485–501 (2014) 58. Picek, S., Knezevi´c, K., Mariot, L., Jakobovi´c, D., Leporati, A.: Evolving bent quaternary functions. In: IEEE Congress on Evolutionary Computation (CEC), Rio de Janeiro, Brazil, 8 p (2018). https://doi.org/10.1109/CEC.2018.8477900 59. Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Construction of ternary plateaued functions from quadratic forms for ternary bent functions. In: Proceeding of the 51st International Symposium on Multiple-Valued Logic, Nur-Sultatn, Kazakhstan, May 25–27, 1–6 (2021). https://doi.org/10. 1109/ISMVL51352.2021.00010 60. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola. J.: Remarks on similarities among ternary bent functions. In: Proceeding of the 49th International Symposium on Multiple-Valued Logic, Fredericton, Canada, May 21–23, 79–84 (2019) 61. Stankovi´c, M., Stankovi´c, R.S., Moraga, C., Astola, J.T.: Construction of ternary bent functions from ternary linear functions. In: Proceedings of the 52nd International Symposium on Multiple-valued Logic, Dallas, TX, USA, May 18–20, 50–55 (2022). https://doi.org/10.1109/ ISMVL52857.2022.00015 62. Lechner, R.: A transform theory for functions of binary variables. In: Theory of Switching, Harvard Computation Laboratory, Cambridge, Mass., Progress Rept. BL-30, Sec-X, November 1961, 1–37 63. Lechner, R.J.: A transform approach to logic design. In: Proceeding of the 9th Symposium Switching and Automata Theory, 213–214 (1968). Also IEEE Trans. Comput. C-19, 627–640 (1970) 64. Lechner, R.J.: Harmonic analysis of switching functions. In: Mukhopahyay, A. (ed.) Recent Developments in Switching Theory. Academic, New York (1971) 65. Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Some spectral invariant operations for multiplevalued functions with homogeneous disjoint products in the polynomial form. In: Proceeding of the 47th Internatonal Symposium on Multiple-Valued Logic, Novi Sad, Serbia, May 22–24, 61–66 (2017) 66. Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Some spectral invariant operations for functions with disjoint products in the polynomial form. In: Moreno-Diaz, R., Pichler, F., Quesada-Arencibia, A. (eds.) Computer Aided Systems Theory - EUROCAST 2017, 16th International Conference, Las Palmas de Gran Canaria, Spain, February 19–24, 2017. Revised Selected Papers, LNCS, vol. 10672, Part 2, 262–269. Springer (2018) 67. Hou, X.D.:. p-ary and.q-ary versions of certain results about bent functions and resilient functions. Finite Fields Appl. 10, 566–582 (2004) 68. Moraga, C.: Introducing disjoint spectral translation is spectral multiple-valued logic design. Electr. Lett. 14(8), 241–243 (1978)

2

Gibbs Derivatives on Finite Abelian Groups

In this chapter, we present fundamentals of the theory of Gibbs derivatives on finite Abelian groups as these concepts will be used later in the context of bent functions. The concept of the Gibbs dyadic differentiation (more generally Gibbs derivatives) originated in the interest for Walsh analysis in the late sixties and early seventies [1]. At that time, because of the limited computational resources available for performing Fourier analysis, for computational purposes, the main focus was on the discrete Walsh analysis, whose kernels are the discrete Walsh functions, which are viewed as functions on the finite dyadic group .C2n . The discrete Walsh transform is the Fourier transform on this group, and it is computationally very efficient, since Walsh functions take just two integer values .1 and .−1 instead of complex numbers required in the Fourier transform. For an overview of the development of the Walsh dyadic analysis, we refer to [2, 3]. At that time, a missing part of the theory was the concept of a differential operator that will enable differentiation of stepwise functions as the Walsh functions. The finite dyadic group is a natural domain for binary functions in binary variables, i.e., Boolean or logical functions, which explains the name logical derivative initially used by the author of the concept Edmund J. Gibbs [4]. We now use the term Gibbs dyadic derivative. Extension of this definition to real-valued functions of a continuous non-negative real variable was done by Pichler [5]. The concept was extended to the infinite dyadic group, alternatively the interval .[0, 1) by Butzer and Wagner [6]. For more details, see [7]. Therefore, it is natural that the logic (dyadic) derivative and its various generalizations, that we call the Gibbs derivatives, are considered as particular differential operators for functions on groups, not necessarily being Abelian, starting from the finite dyadic group, through the infinite dyadic group, i.e., the set of all binary sequences .x = {xi }, .xi ∈ {0, 1} with the componentwise addition modulo .2, equivalently, the unit interval .[0, 1], to locally compact Abelian and finite non-Abelian groups [7]. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_2

45

46

2 Gibbs Derivatives on Finite Abelian Groups

In this book, we consider the Gibbs derivatives on finite Abelian groups .C2n , .C3n , and .C4n whose group representations respectively are Walsh and Vilenkin–Chrestenson functions [1]. We also use the Gibbs derivatives defined with respect to the GF-expressions and RMFexpressions, viewed as Fourier-like representations for the ternary and quaternary functions, respectively. Since for . p = 3 the GF-expressions and for . p = 4, the RMF-expressions are defined as modulo . p operations, it means that we are working in the rings of integers modulo .3 and .4. The corresponding Gibbs derivatives are used to provide a characterization of binary, ternary, and quaternary bent functions, which are defined uniformly as binary, ternary, and quaternary functions having flat Walsh and Vilenkin–Chrestenson spectra, respectively; see, for example, [8]. There are different ways to introduce the concept of Gibbs derivatives on finite groups. For the considerations in this book, a suitable approach is through the relationship between differential operators and Fourier transforms on groups or the GF and RMF representations viewed as a kind of Fourier-like transforms. In the classical Fourier analysis, the Fourier transform of the derivative (Newton–Leibniz) of a real-valued function . f is .F ( f , ) = iwF ( f ), where .F denotes the Fourier transform operator mapping . f (x) into its Fourier spectrum . S f (w). Thus, the Fourier transform of the Newton–Leibniz derivative . f , of a function . f is the multiple of the Fourier transform of . f . In the case of the Gibbs derivative . D( f ) of a binary, ternary, or quaternary function . f , this property is expressed as .

S D( f ) = wS f ,

where . S f and . S D( f ) are the Walsh, correspondingly the Vilenkin–Chrestenson spectra of . f and its Gibbs derivative . D( f ). From there, in the case of . p-valued functions, . p ∈ {2, 3, 4}, after performing the corresponding inverse transform, the Gibbs derivative is defined in matrix notation as D(n) = p −n T(n)G(n)T∗ (n),

.

(2.1)

where .G(n) = diag(0, 1, . . . , p n − 1) and .T ∈ {W, V}, where .W and .V are the Walsh and Vilenkin–Chrestenson transform matrices. The matrix.D(n) defines the operator of the Gibbs differentiation, and the Gibbs derivative of a function . f is denoted as . f [1] and represented by the vector .F[1] (n) = [ f [1] (0), f [1] (1), . . . , f [1] ( p n − 1)]T of Gibbs coefficients. In this matrix notation, for a . p-valued function . f in .n variables specified by the function vector .F(n) = [ f (0), f (1), . . . , f (n)]T , the Gibbs derivative .F[1] (n) is computed as F[1] (n) = D(n)F(n).

.

2.1

Gibbs Derivative for Binary Functions

2.1

47

Gibbs Derivative for Binary Functions

For binary functions, the matrix .T is the Walsh matrix, and the relation (2.1) reads as D(n) = 2−n W(n)G(n)W(n),

.

(2.2)

where .G(n) = [0, 1, . . . , 2n − 1]T . In matrix notation, the function vector of the Gibbs derivative . f [1] (x) of an .n-variable binary function . f (x) specified by the function vector .F is determined as F[1] = D(n)F,

.

(2.3)

where the .(2n × 2n ) matrix of the dyadic Gibbs derivative .D(n), called the Gibbs matrix, is defined as a matrix whose elements are defined as { ) n−1 ∑ 1 n r r (2 − 1)δ(ξ ⊕ η, 0) − .dξ,η = 2 δ(ξ ⊕ η, 2 ) , 2 r =0

where .δ is the Kronecker delta. The matrix .D(n) can be factorized as in (2.2). Thus, .D(n) is the similarity transformation of .G(n) with respect to the Walsh matrix. The matrix .D(n) is diagonalizable, since it is similar to the diagonal matrix .G(n). From (2.2), we can see that the eigenvalues of .D(n) are n .0, 1, 2, . . . , 2 − 1, and that the Walsh functions are the corresponding eigenvectors. Another way to define the dyadic Gibbs derivative on .C2n is in terms of the partial dyadic Gibbs derivatives, i.e., as a linear combination of partial dyadic Gibbs derivatives on .C2 . Definition 2.1 The partial dyadic Gibbs derivative of a function . f (x1 , . . . , xn ) with respect to the .ith variable .xi , .i = 1, 2, . . . , n is defined as (Di f )(x1 , . . . , xn ) = f (x1 , . . . , xi ⊕ 1, . . . , xn ) − f (x1 , . . . , xi , . . . xn ).

.

(2.4)

The dyadic Gibbs derivative is expressed in terms of partial dyadic Gibbs derivatives as .

f [1] (x1 , . . . , xn ) = −

1 ∑ n−i 2 (Di f )(x1 , . . . , xn ). 2 n

(2.5)

i=1

In matrix notation, the partial Gibbs dyadic derivative can be expressed as ⎧ ] [ ⎪ −1 1 ⎪ ⎪ , for j = i, A(1) = ⎪ ⎪ 1 −1 n ⎨ Θ .Di = Aj, Aj = ] [ ⎪ ⎪ j=1 ⎪ 10 ⎪ ⎪ for j / = i. ⎩ I(1) = 0 1 ,

(2.6)

48

2 Gibbs Derivatives on Finite Abelian Groups

Example 2.1 For .n = 3, the matrix .G(n) = diag(0, 1, 2, 3, 4, 5, 6, 7), and [ W(3) =

.

1 1 1 −1

]⊗3 ,

where .⊗3 is the .3rd power Kronecker product of matrices. A simple computation yields the Gibbs matrix ⎡ ⎤ −7 1 2 0 4 0 0 0 ⎢ 1 −7 0 2 0 4 0 0 ⎥ ⎢ ⎥ ⎢ 2 0 −7 1 0 0 4 0 ⎥ ⎢ ⎥ ⎥ 1⎢ ⎢ 0 2 1 −7 0 0 0 4 ⎥ .D(3) = − ⎢ ⎥. 2 ⎢ 4 0 0 0 −7 1 2 0 ⎥ ⎢ ⎥ ⎢ 0 4 0 0 1 −7 0 2 ⎥ ⎢ ⎥ ⎣ 0 0 4 0 2 0 −7 1 ⎦ 0

0

0

4

0

2

1 −7

The discrete Walsh functions are eigenfunctions of the dyadic Gibbs derivative with eigenvalues in . Bn = {0, 1, 2, . . . , 2n − 1} [9], i.e., the eigenvalues are equal to sequencies (number of zero crossings) of Walsh functions in the so-called sequency ordering [1]. This statement can be easily seen if we multiply the Gibbs matrix from the right with the Walsh matrix, i.e., D(n)W(n) = 2−n (W(n)G(n)W(n))W(n) = W(n)G(n),

.

since the Walsh matrix is a self-inverse matrix up to the constant .2n . Recall that the Walsh matrix is a symmetric matrix whose rows, equivalently columns, are Walsh functions .wal(i, x), .i = 0, 1, . . . , 2n − 1, .x = (x1 , x2 , . . . , xn ); it follows D(n)W(n) = D(n)[wal(0, x), wal(1, x), . . . , wal(2n − 1, x)]

.

= [0, 1 · wal(1, x), 2 · wal(2, x), . . . , (2n − 1) · wal(2n − 1, x)], and, therefore, the Walsh functions .wal(i, x) are eigenfunctions of the Gibbs derivative with eigenvalues .0, 1, . . . , 2n − 1, correspondingly [10–13]. It is useful to observe that the Gibbs matrix is a convolution-like matrix, and although being a singular operator it is possible to reconstruct the function from its Gibbs dyadic derivative by a procedure initially defined in [14] and further discussed elsewhere for various particular generalizations of the Gibbs dyadic derivative. Another property of the Gibbs derivative is that the sum of the Gibbs coefficients is .0. This property follows from the convolution structure of the Gibbs matrix and the property that the sum of elements per rows is .0, as illustrated by Example 2.1. This property can be seen to hold as follows.

2.3

Gibbs Derivative for Ternary Functions

49

Denote by .1 = [1, 1, . . . , 1] a vector of .2n elements that are all equal to .1. Then, [1, 1, . . . , 1]D(n)F = [1, 1, . . . , 1]W(n)G(n)W(n)F

.

= 2n [1, 0, . . . , 0] · diag[0, 1, . . . , 2n − 1]W(n)F = 0. Formulation of the Gibbs derivative in matrix form is useful for its computation, since the fast computation algorithms for the Walsh transform can be used [9, 15].

2.2

Computing the Dyadic Gibbs Derivative

The relation (2.5) shows that the dyadic Gibbs derivative can be computed by a convolutionlike algorithm with complexity equal to that of two times performing the Fast Walsh Transform (FWT) [1, 9]. The definition of the Gibbs dyadic derivative in terms of partial derivatives appears to be very convenient for parallel computations since partial derivatives can be computed simultaneously. Further, even a brief inspection of the matrix interpretation of partial derivatives shows a strong resemblance with steps in FWT-like algorithms for various spectral transforms on finite dyadic groups. Therefore, computing the partial derivative with respect to the variable .xi can be performed by a step of the [ FWT-like]algorithm with the basic butterfly −1 1 . As in all FFT-like algorithms, operation defined by the matrix .Ai = A(1) = 1 −1 butterfly operations are performed in parallel over different sets of data, which ensures the efficiency of the algorithm. Example 2.2 Figure 2.1 shows steps of the FWT-like algorithm for computing dyadic Gibbs derivatives for functions of .n = 4 binary variables. The outputs of these steps .D1 , .D2 , .D3 , and .D4 are used to compute the dyadic Gibbs derivative by (2.5).

2.3

Gibbs Derivative for Ternary Functions

In the case of ternary functions, by the analogy to (2.2) it follows the matrix interpretation of the Gibbs derivative on .C3n in terms of the Vilenkin–Chrestenson transform .V(n) as D f (n) = V(n)G3 (n)V−1 (n),

.

(2.7)

where .G3 (n) = diag(0, 1, . . . , 3n − 1). We call this operator the VC-Gibbs derivative for ternary functions, and elements of .D f (n) the VC-Gibbs coefficients. An alternative definition of the VC-Gibbs derivative as the weighted sum of the corresponding partial VC-Gibbs derivatives is a direct generalization of the same definition for the binary case.

50

2 Gibbs Derivatives on Finite Abelian Groups

F

D1 F

D3 F

D2 F

4

1

2

D4

1/2

+ D Fig. 2.1 FFT-like algorithm for computing the dyadic Gibbs derivative for .n = 4

A basic property of Gibbs derivatives is that the functions used as kernels of the Fourier transform, in the considered case the Walsh and Vilenkin–Chrestenson functions, are their eigenfunctions, i.e., they are solutions of the eigenvalue problem of the form .

D( f ) = w f ,

of which the eigenvalues are .w = 0, 1, . . . , g − 1, where .g is the order of the group .G on which the derivative is defined [16]. For the group .C3n , which is the domain group for the ternary functions as we consider them, the eigenvalues of the VC-Gibbs derivatives are g3 (n) = [0, 1, . . . , 3n − 1]T ,

.

and the eigenfunctions are the Vilenkin–Chrestenson functions represented by columns of the transform matrix .V3 (n). Example 2.3 For .n = 1, the VC-Gibbs derivative is computed as ⎤ 1 g2 g1 −1 .D V C, f (1) = V(1)G(1)V (1) = ⎣ g1 1 g2 ⎦ , g2 g1 1 ⎡

2.4

Galois Field Gibbs Derivative for Ternary Functions

51

1 where .G(1) = diag(0, 1, 2), .g1 = −0.5 − √ i = −0.5 − 0.2887i, .i = 2 3 ∗ g1 . For .n = 2, it is .G(2) = diag(0, 1, 2, 3, 4, 5, 6, 7, 8) and

DV C, f (2) = V(2)G(2)V−1 (2) ⎡ 4 g2 g1 g4 0 0 ⎢g 4 g 0 g 0 ⎢ 1 2 4 ⎢ ⎢ g2 g1 4 0 0 g4 ⎢ ⎢ g 3 0 0 4 g2 g 1 ⎢ =⎢ ⎢ 0 g3 0 g 1 4 g 2 ⎢ 0 0g g g 4 3 2 1 ⎢ ⎢ ⎢ g4 0 0 g3 0 0 ⎢ ⎣ 0 g 4 0 0 g3 0 0 0 g4 0 0 g3

.

where .g1 , .g2 are as above, and .g3 = −1.5 −

√ 3 2 i

g3 0 0 g4 0 0 4 g1 g2

0 g3 0 0 g4 0 g2 4 g1

√ −1, and .g2 =

⎤ 0 0⎥ ⎥ ⎥ g3 ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥, g4 ⎥ ⎥ ⎥ g1 ⎥ ⎥ g2 ⎦ 4

= −1.5 − 0.8660i, .g4 = g3∗ .

Example 2.4 For the function . f in Example 1.9, whose function vector is F = [0, 0, 0, 0, 1, 2, 0, 2, 1]T ,

.

the VC-Gibbs derivative of . f in complex encoding .(0, 1, 2) → (1, e1 , e2 ) is computed as DV C, f (2) = (V(2)G(2)V∗ (2))Fe

.

= [0, 3, 6, 1, −2 + 3.46i, −3.5 − 6.06i, 2, −2.5 − 4.33i, −4 + 6.93i]T . Gibbs derivatives for ternary functions can be computed in the same way as the dyadic Gibbs derivative if the Fast Walsh transform algorithm is replaced by the Fast Vilenkin– Chrestenson algorithm [9, 17].

2.4

Galois Field Gibbs Derivative for Ternary Functions

Besides the Gibbs derivative defined in terms of the Vilenkin–Chrestenson transform, in the study of ternary bent functions we also use the Gibbs derivative over the .G F(3) derived from the Galois field expressions. Therefore, we here briefly present some basic definitions of this derivative which we call the GF-Gibbs derivative. In [18], the Gibbs derivatives for multiple-valued functions in .G F( p) are defined by an analogy to the definition of the Gibbs derivatives for functions on finite Abelian groups into the complex field .C. A characteristic of these derivatives making them analogous to other differential operators for binary and multiple-valued functions is that the coefficients in

52

2 Gibbs Derivatives on Finite Abelian Groups

GF-expressions are equal to the values of the derivatives of the corresponding orders computed at certain points. Another characteristic that makes these operators similar to the Gibbs derivatives is that their eigenfunctions are rows of the GF-matrices used in the definition of GF-expressions [17], with eigenvalues defined as values of the function that is the product of all variables over the considered finite fields. For ternary functions, the GF-Gibbs derivative is defined in terms of partial GF-Gibbs derivatives as follows [18]. The partial GF-Gibbs derivative with respect to the .ith variable for an .n-variable ternary function is defined in matrix notation by DG Fi =

n Θ

.

{ Dij (1), Dij (1) =

j=1

DG F (1), j = i, I3 (1), j / = i,

where .I3 (1) is the .(3 × 3) identity matrix, and DG F, f (1) = R(1)G(1)(R(1))−1 mod 3,

.

where .G(1) = diag(0, 1, 2), .R(1) is the matrix defining the Galois field expressions for n = 1, and .G(1) is the matrix of eigenvalues of GF-Gibbs derivatives, i.e.,

.

⎤ ⎡ ⎤ ⎤ ⎡ 000 100 100 (R(1))−1 = ⎣ 0 2 1 ⎦ , G(1) = ⎣ 0 1 0 ⎦ . . R(1) = ⎣ 1 1 1 ⎦ , 002 121 222 ⎡

Therefore, ⎤ 000 .D(1) = ⎣ 1 0 2 ⎦ . 120 ⎡

It is obvious that the same as all other Gibbs derivatives, this is a singular operator [19]. The GF-Gibbs derivative.DG F (n) is defined as the product of the partial GF-Gibbs derivatives DG F, f (n) =

n ∏

.

DG Fi ,

i=1

which makes the difference with respect to the Gibbs derivatives in terms of the Fourier transforms on groups where the Gibbs derivatives are defined as a weighted sum of the corresponding partial Gibbs derivatives. This modification however ensures that the fundamental property of these differential operators that is the relationship between the spectra of the function and its derivative is preserved in the following manner. For the GF-Gibbs derivative, the GF-spectra of a ternary function and its GF-Gibbs derivative are related by

2.4

Galois Field Gibbs Derivative for Ternary Functions

53

S DG F, f = φ(n) ʘ S f ,

.

∏n where .φ(n) = i=1 xi and .ʘ is the componentwise multiplication of vectors. Notice that due to the decomposable structure of the domain group on which ternary variables are defined, the product of variables .φ(n) in matrix notation can be expressed in terms of the Kronecker product as G(n) =

n Θ

.

G(1).

i=1

Then, the GF-Gibbs derivative can be expressed as DG F, f (n) = R(n)G(n)R(n)−1 .

.

Since all the involved matrices, .R(n), .G(n), and .R(n)−1 , have the Kronecker product structure, it follows from the properties of the Kronecker product that the GF-Gibbs derivative can also be expressed as the Kronecker product of .D(1), DG F, f (n) =

n Θ

.

D(1).

i=1

This makes a difference with respect to the Gibbs derivatives defined in terms of classical Fourier transforms on groups. For instance, the matrix representation of the Gibbs dyadic derivative (2.1), see (2.2), for example, also expresses the block structure, but it is not a Kronecker product representable matrix, since the matrix .G does not have a Kronecker product structure. Lemma 2.1 The GF-Gibbs derivative for a ternary function has a Kronecker product structure. Proof The proof can be derived by induction as follows. Induction basis Let .n = 2, Example 2.5 below. Induction hypothesis Let .n = k, and assume that the GF-Gibbs derivative for ternary functions in .k variables has a Kronecker product structure

54

2 Gibbs Derivatives on Finite Abelian Groups

DG F, f (k) = DG F1 (k) · DG F2 (k) · DG F3 (k) · . . . · DG Fk (k).

.

DG F, f (k) = (DG F (1) ⊗ I3 (1)⊗k−1 ) · (I3 (1) ⊗ DG F (1) ⊗ I3 (1)⊗k−2 ) · (I3 (1)⊗2 ⊗ DG F (1) ⊗ I3 (1)⊗k−3 ) · . . . · (I3 (1)⊗k−1 ⊗ DG F (1)) = DG F (1)⊗k . Induction step Let .n = k + 1, then DG F (k + 1) = (DG F (1) ⊗ (I3 (1)⊗k ) · (I3 (1) ⊗ DG F (1) ⊗ (I3 (1)⊗k−1 )

.

· (I3 (1)⊗2 ⊗ DG F (1) ⊗ (I3 (1)⊗k−2 ) · . . . · (I3 (1)⊗k ⊗ DG F (1)) = (DG F (1) ⊗ I3 (1)⊗k−1 ⊗ I3 (1)) · (I3 (1) ⊗ DG F (1) ⊗ I3 (1)⊗k−2 ⊗ I3 (1)) · (I3 (1)⊗2 ⊗ DG F (1) ⊗ I3 (1)⊗k−3 ⊗ I3 (1)) · . . . · (I3 (1)⊗k−1 ⊗ DG F (1) ⊗ I3 (1)) · (I3 (1)⊗k ⊗ DG F (1)) = (DG F1 (k) ⊗ I3 (1)) · (DG F2 (k) ⊗ I3 (1)) · (DG F3 (k) ⊗ I3 (1)) · (DG F4 (k) ⊗ I3 (1)) · . . . · (DG F(k−1) (k) ⊗ I3 (1)) · (DkG Fk ⊗ I3 (1)) · (I3 (1)⊗k ⊗ DG F (1)) = (DG F1 (k) · DG F2 (k) · DG F3 (k) · . . . · DG Fk (k) ⊗ I3 (1)k ) · (I3 (1)⊗k ⊗ DG F (1)) = (DG F1 (k) · DG F2 (k) · DG F3 (k) · . . . · DG Fk (k)) ⊗ DG F (1) = DG F (1)⊗k ⊗ DG F (1) = DG F (1)⊗k+1 . Example 2.5 As shown in [18], the Gibbs GF-derivative for two-variable ternary functions is given by DG F, f (2) = DG F1 (2)DG F2 (2),

.

where .DG F1 (2) and .DG F2 (2) are defined as DG F1 (2) = DG F (1) ⊗ I3 (1), DG F2 (2) = I3 (1) ⊗ DG F (1).

.

2.4

Galois Field Gibbs Derivative for Ternary Functions

55

Therefore, ⎡

0 ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ .DG F (2) = ⎢ 1 ⎢ ⎢1 ⎢ ⎢0 ⎢ ⎣1 1

0 0 0 0 0 2 0 0 2

0 0 0 0 2 0 0 2 0

0 0 0 0 0 0 0 2 2

0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 0 1 0

0 0 0 0 2 2 0 0 0

0 0 0 0 0 1 0 0 0

⎤ 0 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 1⎥. ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎦ 0

Alternatively, the GF-Gibbs derivative can be computed as DG F (2) = DG F (1) ⊗ DG F (1).

.

Consider the ternary function specified by the function vector F = [0, 1, 1, 2, 0, 2, 2, 1, 1]T .

.

Its GF-spectrum is computed as S f = (R(1))−1 ⊗ (R(1))−1 )F ⎛⎡ ⎤ ⎡ ⎤⎞ 100 100 = ⎝ ⎣ 0 2 1 ⎦ ⊗ ⎣ 0 2 1 ⎦⎠ F 222 222 ⎤ ⎡ ⎤ ⎡ 0 100000000 ⎢0 2 1 0 0 0 0 0 0⎥ ⎢1⎥ ⎥ ⎢ ⎥ ⎢ ⎢2 2 2 0 0 0 0 0 0⎥ ⎢1⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 2 0 0 1 0 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ = ⎢0 0 0 0 1 2 0 2 1⎥ · ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 1 1 1 2 2 2⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎢2 0 0 2 0 0 2 0 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎣0 1 2 0 1 2 0 1 2⎦ ⎣1⎦ 1 111111111

.

= [0, 0, 1, 0, 1, 0, 2, 1, 1]T .

56

2 Gibbs Derivatives on Finite Abelian Groups

The GF-Gibbs derivative is computed as D f = DG F (2)F ⎡ 00000 ⎢0 0 0 0 0 ⎢ ⎢0 0 0 0 0 ⎢ ⎢0 0 0 0 0 ⎢ ⎢ = ⎢1 0 2 0 0 ⎢ ⎢1 2 0 0 0 ⎢ ⎢0 0 0 0 0 ⎢ ⎣1 0 2 2 0 12021

.

0 0 0 0 0 0 0 1 0

0 0 0 0 2 2 0 0 0

0 0 0 0 0 1 0 0 0

⎤ ⎡ ⎤ 0 0 ⎢1⎥ 0⎥ ⎥ ⎢ ⎥ ⎢ ⎥ 0⎥ ⎥ ⎢1⎥ ⎥ ⎥ 0⎥ ⎢ ⎢2⎥ ⎥ ⎢ ⎥ 1⎥ · ⎢0⎥ ⎥ ⎢ ⎥ 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎥ 0⎥ ⎥ ⎢2⎥ 0⎦ ⎣1⎦ 1

0

= [0, 0, 0, 0, 1, 1, 0, 2, 0] . T

The GF-spectrum of the GF-Gibbs derivative is S D f = (R(1))−1 ⊗ (R(1))−1 )D f

.

= [0, 0, 0, 0, 1, 0, 0, 2, 1]T and since .φ = x1 x2 has the function vector .φ(2) = [0, 0, 0, 0, 1, 2, 0, 2, 1]T , it is easy to verify that . S DG F f = φ · S f , i.e., S DG F, f = Φ ʘ S f

.

= [0, 0, 0, 0, 1, 2, 0, 2, 1]T ʘ [0, 0, 1, 0, 1, 0, 2, 1, 1]T = [0, 0, 0, 0, 1, 0, 0, 2, 1]T .

2.5

Gibbs Derivatives for Quaternary Functions

The Gibbs derivatives for quaternary functions are defined in the same way as for the binary and ternary functions in terms of the Walsh and the Vilenkin–Chrestenson transform matrices, respectively. Therefore, the VC-Gibbs derivative for quaternary functions is defined by using .G4 (n) = diag(0, 1, . . . , 4n − 1) and the corresponding Vilenkin–Chrestenson matrices for the direct and the inverse transforms. Thus, D(n) = V(n)G4 (n)V−1 (n) = 4−n V(n)G4 (n)V∗ (n).

.

(2.8)

An alternative definition of the VC-Gibbs derivative for quaternary functions as the weighted sum of the corresponding partial VC-Gibbs derivatives is a direct generalization of the same definition for the binary and ternary cases. This derivative can be computed in the

2.6

Gibbs RMF-Derivative for Quaternary Functions

57

same way as these for binary and ternary functions by using the Fast Vilenkin–Chrestenson algorithms for . p = 4 [9, 17]. Due to the difference in modulo.4 arithmetic and arithmetic of.G F(4), for characterization of quaternary bent functions we use also the Gibbs derivatives defined with respect to the Reed–Muller–Fourier (RMF) transform replacing the Vilenkin–Chrestenson transform. Since the computations are in terms of modulo .4 operations, it follows that this operator is defined over the ring of integers modulo .4.

2.6

Gibbs RMF-Derivative for Quaternary Functions

As explained above, the Gibbs derivatives are formulated as operators whose eigenfunctions are functions in terms of which the Fourier transforms on underlying groups are defined. Viewing the RMF-transform as a Fourier-like transform, the Gibbs derivative for quaternary functions in .n variables in terms of RMF-functions .X4R M F (n) is defined in [18]. For a function. f (x) in a single quaternary variable.x = 0, 1, 2, 3, specified by the function vector .F = [ f (0), f (1), f (2), f (3)]T , the Gibbs RMF-derivative is defined as an operator satisfying the requirement R D f (1) = Φ(1) ʘ R f (1),

.

where .R f (1) and .R D f (1) are the RMF-spectra of . f and its Gibbs derivative . D f , and T .Φ(1) = [0, 1, 2, 3] , .ʘ is the componentwise multiplication of vectors. In matrix notation, since R f = R(1)F ⎡ ⎤ ⎡ ⎤ 1000 f (0) ⎢ 1 3 0 0 ⎥ ⎢ f (1) ⎥ ⎥ ⎢ ⎥ = 3⎢ ⎣ 1 2 1 0 ⎦ · ⎣ f (2) ⎦ 1133 f (3) ⎡ ⎤ 3 f (0) ⎢ 3 f (0) ⊕ f (1) ⎥ ⎥, =⎢ ⎣ 3 f (0) ⊕ 2 f (1) ⊕ 2 f (2) ⎦ 3 f (0) ⊕ 3 f (1) ⊕ f (2) ⊕ f (3)

.

the inverse RMF-transform leads to the Gibbs RMF-derivative for single variable quaternary functions [18]. The Gibbs RMF-derivative for four-valued functions for .n = 1 is defined by the matrix

58

2 Gibbs Derivatives on Finite Abelian Groups

D4R M F (1) = R4R M F (1)G(1)(R4R M F (1))−1 , ⎤ ⎡ ⎤ ⎡ ⎡ 3 0000 1000 ⎢1 3 0 0⎥ ⎢0 1 0 0⎥ ⎢3 ⎥ ⎢ ⎥ ⎢ = 3⎢ ⎣1 2 1 0⎦ · ⎣0 0 2 0⎦ · ⎣3 3 0003 1133 ⎤ ⎡ 0000 ⎢3 1 0 0⎥ ⎥ =⎢ ⎣0 2 2 0⎦.

.

0 1 2 3

0 0 3 1

⎤ 0 0⎥ ⎥ 0⎦ 1

0013 The same as all other Gibbs derivatives [19], this is a singular operator. Another way to introduce the RMF-Gibbs derivative for quaternary functions is in terms of the appropriately defined partial RMF-Gibbs derivatives. Definition 2.2 (Partial Gibbs RMF-derivatives) The partial Gibbs RMF-derivative with respect to the .ith variable for an .n-variable quaternary function is defined in matrix notation by D4R M Fi (n) =

n Θ

.

j=1

{ Dij (1), Dij (1) =

D R M F (1), j = i j / = i. I4 (1),

As pointed out in the definition of the RMF-expressions, when differentiating with respect to the first variable .x1 , we shall use .3D R M F (1). Example 2.6 The partial Gibbs RMF-derivatives for a two-variable quaternary function are given by D R M F1 (2) = 3D R M F (1) ⊗ I4 (1) ⎤ ⎡ ⎡ 10 0000 ⎢3 1 0 0⎥ ⎢0 1 ⎥ ⎢ =⎢ ⎣0 2 2 0⎦ ⊗ ⎣0 0 00 0013

0 0 1 0

⎤ 0 0⎥ ⎥, 0⎦ 1

D R M F2 (2) = I4 (1) ⊗ D R M F (1) ⎡ ⎤ ⎡ 1000 0 ⎢0 1 0 0⎥ ⎢3 ⎥ ⎢ =⎢ ⎣0 0 1 0⎦ ⊗ ⎣0 0001 0

0 0 2 1

⎤ 0 0⎥ ⎥. 0⎦ 3

.

0 1 2 0

2.6

Gibbs RMF-Derivative for Quaternary Functions

59

Definition 2.3 (Total Gibbs RMF-derivative) The total Gibbs RMF-derivative (short Gibbs RMF-derivative) for an .n-variable quaternary function is defined in matrix notation by D R M F (n) =

n ∏

.

D R M Fi .

i=1

For the thus defined Gibbs RMF-derivative, R D4R M F, f (n) = Φ(n) ʘ R f (n),

.

where .Φ(n) is the function vector of the function defined as the product of all the variables φ(n) =

n ∏

.

xi .

i=1

In matrix notation, the function vector for .φ(n) is Φ(n) =

n Θ

.

Φ(1),

i=1

where .Φ(1) = [0, 1, 2, 3]T . If elements of .Φ(n) are written as elements on the main diagonal of a diagonal matrix . G(n) while all other elements are .0, then the RMF-Gibbs derivative can be expressed as D R M F (n) = R4R M F (n)G(n)R4R M F (n)−1 .

.

Since all three involved matrices .R4R M F (n), .G(n), and .R4R M F (1)−1 are Kronecker product representable, it follows from the properties of the Kronecker product that.D R M F (n) is also Kronecker product representable. Therefore, D R M F (n) =

n Θ

.

D R M F (1).

i=1

A formal proof can also be derived by induction in the same way as for the GF-Gibbs derivative for ternary functions. Example 2.7 The Gibbs RMF-derivative for two-variable quaternary functions is D R M F (2) = D R M F1 (2)D R M F2 (2),

.

with the corresponding matrices defined in Example 2.6.

60

2 Gibbs Derivatives on Finite Abelian Groups

The existence of the Fast RMF computing algorithm permits computation of the Gibbs RMF derivative in the same way as in the case of the Gibbs dyadic derivative and its counterpart for ternary functions [15, 17]. Example 2.8 Consider a randomly selected quaternary function. f in two variables specified by the function vector F = [1, 0, 2, 3, 3, 2, 1, 1, 2, 2, 2, 3, 0, 0, 1, 2]T .

.

Its RMF-Gibbs derivative is computed as D R M F, f = D R M F (2)F

.

= [0, 0, 0, 0, 0, 0, 2, 1, 0, 2, 0, 2, 0, 0, 2, 0]T . The RMF-spectra of . f and its RMF-Gibbs derivative, . S R M F f and . S D R M F, f , are S R M F, f = [1, 1, 3, 0, 2, 0, 3, 1, 1, 3, 3, 1, 2, 2, 2, 3]T ,

.

S D R M F, f = [0, 0, 0, 0, 0, 0, 2, 3, 0, 2, 0, 2, 0, 2, 0, 3]T . Since .φ = x1 x2 has the function vector Φ = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 0, 2, 0, 3, 2, 1]T ,

.

it is easy to verify that . S D R M F, f = φ S R M F, f .

References 1. Karpovsky, M.G., Stankovi´c, R.S., Astola, J.T.: Spectral Logic and Its Application in the Design of Digital Devices. Wiley (2008) 2. Stankovi´c, R.S., Butzer, P.L., Schipp, F., Wade, W.R., Su, W., Endow, Y., Fridli, S., Golubov, B.I., Pichler, F., Onneweer, K.C.W.: Dyadic Walsh Analysis from 1924 Onwards Walsh-GibbsButzer Dyadic Differentiation in Science, vol. 1. Foundations, A Monograph Based on Articles of the Founding Authors, Reproduced in Full, Atlantis Studies in Mathematics for Engineering and Science, vol. 12. Atlantis Press, Springer (2015). Print ISBN 978-94-6239-159-8. ISBN 978-94-6239-160-4. https://doi.org/10.2991/978-94-6239-160-4 3. Stankovi´c, R.S., Butzer, P.L., Schipp, F., Wade, W.R., Su, W., Endow, Y., Fridli, S., Golubov, B.I., Pichler, F., Onneweer, K.C.W.: Dyadic Walsh Analysis from 1924 Onwards Walsh-Gibbs-Butzer Dyadic Differentiation in Science, vol. 2. Extensions and Generalizations, A Monograph Based on Articles of the Founding Authors, Reproduced in Full, Atlantis Studies in Mathematics for Engineering and Science, vol. 13. Atlantis Press, Springer (2015). Print ISBN 978-94-6239-1628. Online ISBN 978-94-6239-163-5. https://doi.org/10.2991/978-94-6239-163-5 4. Gibbs, J.E.: Walsh spectrometry a form of spectral analysis well suited to binary digital computation. NPL DES Repts. National Physical Lab, Teddington, Middlesex, England (1967)

References

61

5. Pichler, F.R.: Some aspects of a theory of correlation with respect to walsh harmonic analysis. Technical report R-70-11. University of Maryland Technology Research (1970) 6. Butzer, P.L., Wagner, H.J.: Approximation by Walsh polynomials and the concept of a derivative. In: Proceedings of Symposium on Applications of Walsh Functions, Washington D. C., USA, 388–392 (1972) 7. Stankovi´c, R.S., Astola, J., Moraga, C.: Gibbs dyadic differentiation on groups - Evolution of the concept. In: Moreno-Diaz, R., Pichler, F., Quesada-Arencibia, A. (eds) Computer Aided System Theory, EUROCAST-2017. Lecture Notes in Computer Science, vol. 10672, 229–237. https:// doi.org/10.1007/978-3-319-74727-9-27 8. Poinsot, L.: Bent functions on a finite non-Abelian group. J. Discrete Math. Sci. Cryptogr. 9(2), 349–364 (2006) 9. Stankovi´c, R.S., Moraga, C., Astola, J.T.: Fourier Analysis on Finite Non-Abelian Groups with Applications in Signal Processing and System Design. Wiley/IEEE Press (2005) 10. Gibbs, J.E.: Functions That are Solutions of a Logical Differential Equation. NPL DES Rept., No. 4, iv+21 pp (1970) 11. Gibbs, J.E., Gebbie, H.A.: Application of Walsh functions to transform spectroscopy. Nature 224(5223), 1012–1013 (1969). Publication date 12/1969 12. Gibbs, J.E., Ireland, B.: Walsh functions and differentiation. In: Schreiber, H., Sandy, G.F. (eds.) Applications of Walsh Functions and Sequency Theory, 147–176. IEEE, New York (1974) 13. Gibbs, J.E., Simpson, J.: Differentiation on Finite Abelian Groups. NPL DES Rept., No. 14, 34 pp (1974) 14. Gibbs, J.E.: Walsh Spectrometry, a form of Spectral Analysis Well Suited to Binary Digital Computation, p. 24. National Physical Laboratory, Teddington, Middx, UK (1967) 15. Stankovi´c, R.S.: The Reed-Muller-Fourier transform - Computing methods and factorizations. In: Seising, R., Allende-Cid, H. (eds.) Claudio Moraga - A Passion for Multi-Valued Logic and Soft Computing, 121–151. Springer (2017) 16. Gibbs, J.E.: Walsh functions and the Gibbs derivative. NPL DES Memo. No. 10, ii + 13 (1973) 17. Stankovi´c, R.S. Astola, J.T., Moraga, C.: Representation of Multiple-Valued Logic Functions. Claypool & Morgan Publishers (2012) 18. Stankovi´c, R. S., Moraga, C., Astola, J.T.: Derivatives for multiple-valued functions induced by Galois field and Reed-Muller-Fourier expressions. In: Proceedings of the 34th International Symposium on Multiple-Valued Logic, Toronto, Canada, May 19–22, 184–189 (2004) 19. Stankovi´c, R. S., Butzer, P.L., Schipp, F., Wade, W.R., Su, W., Endow, Y., Fridli, S., Golubov, B.I., Pichler, F., Onnewerr, K.C.W.: Dyadic Walsh Analysis from 1924 Onwards, Walsh-GibbsButzer Dyadic Differentiation in Science, vol. 1. Foundations, A Monograph Based on Articles of the Founding Authors, Reproduced in Full. Atlantis Press, Atlantis Studies in Mathematics for Engineering and Science (2015). ISBN 978-94-6239-162-8. ISBN 978-94-6239-163-5 (eBook)

3

Gibbs Characterization of Binary Bent Functions

In this chapter, we discuss a characterization of binary bent functions by the dyadic Gibbs derivatives. The definition of bent functions in terms of flat Walsh spectrum and definition of the dyadic Gibbs derivative as an operator having Walsh functions as eigenfunctions suggest that it could be interesting to formulate a characterization of bent functions in terms of this differential operator. Statement 3.1 A switching function . f of .n-variables, where .n is an even natural number, is bent if the absolute values of elements of the vector .D f representing its dyadic Gibbs derivative . f [1] (x) are mutually distinct and equal to the elements of the set .G = {0, 1, 2, . . . , 2n − 1}. In other words, . f is bent if its dyadic Gibbs derivative by the absolute values is equal to the eigenvalues of the derivative, permutations allowed. Lemma 3.1 Absolute values of Gibbs coefficients of bent functions are eigenvalues of the Gibbs derivative. It should be noticed that the Gibbs derivatives are expressed as the weighted sum of partial Gibbs derivatives. Therefore, the values assigned to the coordinates .ri in the binary representations .r = (r1 , r2 , . . . , rn ) of the Gibbs coefficients are determined by the corresponding partial derivatives. The coordinates .ri in binary representations of integers are balanced functions. Thus, taking into account that the Gibbs derivatives are computed in terms of the partial Gibbs derivatives, the Gibbs characterization of bent function can be viewed as an expression of the property that a function is bent if, for any non-zero vector .a of length .n, the Boolean difference . Da f (x) = f (x) ⊕ f (x ⊕ a), where .x = (x1 , x2 , . . . , xn ), is balanced. See, for example, [1, 2]. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_3

63

64

3 Gibbs Characterization of Binary Bent Functions

Example 3.1 For .n = 4, the function . f = x1 x2 ⊕ x3 x4 is a quadratic bent function, and it is often considered as the basic bent function in the space of four-variable bent functions. Its function vector in the .(0, 1) → (1, −1) encoding is F = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1]T ,

.

and the Walsh spectrum is S f = [4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4, −4, −4, −4, −4, 4]T .

.

Notice that .S f = 4F. The Gibbs dyadic derivative of this function is D f = [0, 2, 1, −3, 8, 10, 9, −11, 4, 6, 5, −7, −12, −14, −13, 15]T .

.

The negative values in .F and .D f appear at the same positions. The sums of positive and negative Gibbs coefficients are .60 and .−60. The logic complement of . f is specified by the function vector F = [−1, −1, −1, 1, −1, −1, −1, 1, −1, −1, −1, 1, 1, 1, 1, −1]T ,

.

whose Walsh spectrum is S f = [−4, −4, −4, 4, −4, −4, −4, 4, −4, −4, −4, 4, 4, 4, 4, −4]T ,

.

and the Gibbs dyadic derivative D f = [0, −2, −1, 3, −8, −10, −9, 11, −4, −6, −5, 7, 12, 14, 13, −15]T .

.

The negative values in.F and.D f appear at the same positions and these are positions opposite to that in . f . Also for this function, the sums of positive and negative Gibbs coefficients are .60 and .−60. Example 3.2 The function in four variable . f = x1 x4 ⊕ x2 x3 ⊕ x4 has the function vector F = [0, 1, 0, 1, 0, 1, 1, 0, 0, 0, 0, 0, 0, 0, 1, 1]T ,

.

which after encoding is F = [1, −1, 1, −1, 1, −1, −1, 1, 1, 1, 1, 1, 1, 1, −1, −1]T .

.

The Gibbs dyadic derivative is computed as D f = [1, −9, 5, −13, 3, −11, −7, 15, 0, 8, 4, 12, 2, 10, −6, −14]T ,

.

3 Gibbs Characterization of Binary Bent Functions

65

and has the negative values at the same positions as in .F. The sums of positive and negative Gibbs coefficients are .60 and .−60, respectively. The logic complement of . f is specified by the function vector F = [1, 0, 1, 0, 1, 0, 0, 1, 1, 1, 1, 1, 1, 1, 0, 0]T ,

.

whose encoded version is F = [−1, 1, −1, 1, −1, 1, 1, −1, −1, −1, −1, −1, −1, −1, 1, 1]T .

.

The Gibbs dyadic derivative is D f = [−1, 9, −5, 13, −3, 11, 7, −15, 0, −8, −4, −12, −2, −10, 6, 14]T ,

.

and expresses the same properties with respect to the negative coefficients and the sums of positive and negative Gibbs coefficients. Example 3.3 For .n = 6, the basic bent function is the quadratic function . f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 specified by the function vector F = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, − 1, −1, −1, 1, −1, −1, −1, 1, −1, −1, −1, 1, 1, 1, 1, −1]T . Its Gibbs dyadic derivative is D f = [0, 2, 1, −3, 8, 10, 9, −11, 4, 6, 5, −7, −12, −14, −13, 15, 32, 34, 33, −35, 40, 42, 41, −43, 36, 38, 37, −39, −44, −46, −45, 47, 16, 18, 17, −19, 24, 26, 25, −27, 20, 22, 21, −23, −28, −30, −29, 31, −48, −50, −49, 51, −56, −58, −57, 59, −52, −54, −53, 55, 60, 62, 61, −63]T . The sums of positive and negative Gibbs coefficients are .1008 and .−1008, respectively. Example 3.4 Consider the function in .6 variables . f p = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5 whose encoded function vector is F = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1, 1, 1, 1, −1, 1, 1, 1, −1, 1, 1, −1, 1, −1, −1, 1, −1, −1, − 1, −1, 1, −1, −1, −1, 1, −1, −1, 1, −1, 1, 1, −1, 1]T .

66

3 Gibbs Characterization of Binary Bent Functions

Its Gibbs dyadic derivative is D f = [0, 2, 1, −3, 8, 10, 9, −11, 4, 6, 37, −39, −12, −14, −45, 47, 32, 34, 33, − 35, 40, 42, 41, −43, 36, 38, 5, −7, −44, −46, −13, 15, 16, 18, 25, − 27, 24, 26, 17, −19, 22, 20, −63, 61, −30, −28, 55, −53, −48, −50, − 57, 59, −56, −58, −49, 51, −54, −52, 31, −29, 62, 60, −23, 21]T . The sums of positive and negative Gibbs coefficients are .1008 and .−1008, respectively. We present here the proof of Statement 3.1 for the case of quadratic bent functions. Recall that a function is called quadratic if its positive polarity Reed–Muller expression consists of the sum of disjoint pairs of variables. To prove the above statement, we write the values of partial Gibbs derivatives determined in Definition 2.1 as a .(2n × n) matrix .Q = [qx,k ], where .qx,k = Dk f (x). ˜ = [|qx,k |] of the absolute values of .qx,k is such We aim at showing that the matrix .Q that its rows consist of all bit patterns in binary representations of integers .0, 1, . . . , 2n − 1. Moreover, all the non-zero values on the row .x of .Q are positive or negative depending on the value of . f (x) which is either .0 or .1. Consider the partial Gibbs derivative with respect to the first variable .x1 . For the sake of clarity, in the analysis given below, we will use the following notation. Given . f (x), let . f˜(x) denote the complex encoding with .(0, 1) → (1, −1). It is simple to see that . f˜(x) = (−1) f (x) . Moreover, let here .e1 = [1, 0, 0, . . . , 0]. Then, D1 f˜(x) = (−1) f (x⊕e1 ) − (−1) f (x) = (−1)(x1 ⊕1)(x2 )⊕x3 x4 ⊕···⊕xn−1 xn − (−1)x1 x2 ⊕x3 x4 ⊕···⊕xn−1 xn = (−1)(x2 ⊕x1 x2 ⊕···⊕xn−1 xn ) − (−1)(x1 x2 ⊕···⊕xn−1 xn ) = ((−1)x2 − 1)(−1)(x1 x2 ⊕···⊕xn−1 xn ) = −2δ(x2 − 1) f˜(x) { −2 f˜(x), if x2 = 1, = 0, if x2 = 0, where .δ is the Kronecker delta. Correspondingly, .

From here,

D2 f˜(x) =

{

−2 f˜(x), if x1 = 1, 0, if x1 = 0.

3 Gibbs Characterization of Binary Bent Functions

.

D2l+1 f˜(x) = D2l+2 f˜(x) =

{ {

67

−2 f˜(x), if x2l+2 = 1, 0, otherwise, −2 f˜(x), if x2l+1 = 1, 0, otherwise,

for .l = 0, 1, 2, . . . , n/2 − 1. Notice that if we put the partial derivatives in order . D2 , D1 , D4 , D3 and ignore signs, we get the binary numbers in the order .1, 2, 3, . . . , 15. This is an identity permutation and .□ others come in the same natural way. Example 3.5 The partial Gibbs dyadic derivatives with respect to all variables in the function . f = x1 x2 ⊕ x3 x4 are D1 D2 . D3 D4

= = = =

[0, 0, −1, 1, 0, 0, −1, [0, −1, 0, 1, 0, −1, 0, [0, 0, 0, 0, 0, 0, 0, [0, 0, 0, 0, −1, −1, −1,

1, 0, 0, −1, 1, 1, 0, −1, 0, 1, 0, −1, −1, −1, 1, 1, 0, 0, 0, 0,

0, 0, 1, 1,

0, 1, 1, 1,

1, 0, 1, 1,

−1]T , −1]T , −1]T , −1]T .

It is obvious that ignoring signs all bit patterns are present in columns looking elementwise. Each .4-tuple has either .0s and .+1 or .0s and .−1 values. Weighting the rows by .8, .4, .2 , .1, the absolute values of the integers corresponding to the .4-tuples of elements .di ( j) are the elements of . B4 . The following example presents the proof for the values of Gibbs coefficients for bent functions for an example of a function of .6 variables. Example 3.6 Consider . f (x1 , x2 , . . . , x6 ) = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5 . From partial derivatives there are essentially two cases 1. . D1 f (x1 , x2 , . . . , x6 ) = 21 (−1) f (x) ((−1)x3 x5 ⊕x2 − 1), 2. . D2 f (x1 , x2 , . . . , x6 ) = 21 (−1) f (x) ((−1)x2 − 1). Consider the row vector formed of partial derivatives [D1 (x), D2 (x), . . . , D6 (x)].

.

As the factors .((−1)x3 x5 ⊕x2 − 1) and .((−1)x2 − 1) for . D1 and . D2 , and similarly for . D3 , . . . , D6 , can only be zero or negative, all the row vectors correspond to bit patterns of 6 .0, 1, . . . 2 − 1 with all bits either non-negative or non-positive. This means that unless there are .x, y ∈ {0, 1}6 , .x / = y such that [D1 (x), D2 (x), . . . , D6 (x)] = ±[D1 (y), D2 (y), . . . , D6 (y)],

.

68

3 Gibbs Characterization of Binary Bent Functions

the absolute values of Gibbs derivatives . f [1] (x), .x∈{0, 1}, are exactly equal to .0, 1, . . . , 26 − 1 in some order. Assume that there are.x, y ∈ {0, 1}6 ,.x / = y, such that. Di f (x) = Di f (y),.i = 1, 2, . . . , 6. Thus, for . D1 .

1 1 (−1) f (x) ((−1)x3 x5 ⊕x2 − 1) = (−1) f (y) ((−1) y3 y5 ⊕y2 − 1) 2 2

and the same for . D3 , . D5 . For . D2 , .

1 1 (−1) f (x) ((−1)x1 − 1) = (−1) f (y) ((−1) y1 − 1), 2 2

where .(−1)x1 − 1 ∈ {0, −2} and .(−1) y1 − 1 ∈ {0, −2}. From . D2 we see that either .x1 = y1 = 0 or .x1 = y1 = 1 and . f (x) = f (y). Consider the case . D1 . From the condition . D1 f (x) = D1 f (y), it follows either .

f (x) = f (y) and x3 x5 ⊕ x2 = y3 y5 ⊕ y2 = 0,

(3.1)

f (x) / = f (y) and x3 x5 ⊕ x2 = y3 y5 ⊕ y2 .

(3.2)

or .

Combining the derivatives for the case . f (x) = f (y), it follows .

x1 = y1 = x3 = y3 = x5 = y5 = 1, or 0,

and .

x3 x5 ⊕ x2 = y3 y5 ⊕ y2 = x1 x5 ⊕ x4 = y1 y5 ⊕ y4 = x1 x3 ⊕ x6 = y1 y3 ⊕ y6 = 0.

For the case . f (x) / = f (y) it is .

x1 = y1 = x3 = y3 = x5 = y5 = 0,

and .

x3 x5 ⊕ x2 = y3 y5 ⊕ y2 , x1 x5 ⊕ x4 = y1 y5 ⊕ y4 , x1 x3 ⊕ x6 = y1 y3 ⊕ y6 .

In this case, from .

x1 = y1 = x3 = y3 = x5 = y5 = 0,

it follows .x2 = y2 , .x4 = y4 , .x6 = y6 and therefore .x = y. So if . f (x) = f (y), then from

3 Gibbs Characterization of Binary Bent Functions .

69

x1 = y1 , x3 = y3 , x5 = y5 ,

it follows .x2 = y2 , .x4 = y4 , .x6 = y6 , and therefore .x = y. The same consideration can be performed as follows. Assume that there exists .x, y ∈ {0, 1}6 , .x / = y, such that .

D f (x) = [D1 f (x), . . . , D6 f (x)] = ±D f (y) = D f (x) = [D1 f (y), . . . , D6 f (y)].

Let us consider . D1 , D3 , D5 and . D2 , D4 , D6 separately. The equality .

D1 f (x) = ±D1 f (y)

implies .

x3 x5 ⊕ x2 = y3 y5 ⊕ y2 = 0,

(3.3)

x3 x5 ⊕ x2 = y3 y5 ⊕ y2 = 1.

(3.4)

or .

The equality .

D2 f (x) = ±D2 f (y)

implies .

x1 = y1 = 0,

(3.5)

x1 = y1 = 1.

(3.6)

or .

The equality .

D3 f (x) = ±D3 f (y)

implies .

x1 x5 ⊕ x4 = y3 y5 ⊕ y4 = 0,

(3.7)

x3 x5 ⊕ x4 = y3 y5 ⊕ y4 = 1.

(3.8)

or .

From . D4 it follows

70

3 Gibbs Characterization of Binary Bent Functions

x3 = y3 = 0,

(3.9)

x3 = y3 = 1.

(3.10)

x1 x3 ⊕ x6 = y1 y3 ⊕ y6 = 0,

(3.11)

x1 x3 ⊕ x6 = y1 y3 ⊕ y6 = 1.

(3.12)

x5 = y5 = 0,

(3.13)

x5 = y5 = 1.

(3.14)

.

or .

From . D3 f (x) = ±D3 f (y) it follows .

or .

From . D6 it follows .

or .

Similarly we get from . D. Now (3.13) and (3.14) with (3.11) and (3.12) substituted to (3.1) and (3.2) give .x3 = y3 , . x 5 = y5 , . x 2 = y2 . Further, (3.5), (3.6), (3.13), (3.14) and (3.7) and (3.8) give . x 4 = y4 and finally (3.5), (3.6), (3.11), (3.12) give .x6 = y6 . So .x = y.

3.1

Properties of the Gibbs Dyadic Derivative of Bent Functions

Besides the property that the absolute values of Gibbs dyadic coefficients are integers in the set of Gibbs eigenvalues, other main features of the Gibbs dyadic derivative of bent functions relevant for the considerations in the context of permutation matrices are the following. Under relevance, we mean restrictions that these features impose on the structure, i.e., position of non-zero elements in the Gibbs permutation matrices: 1. The Gibbs derivative does not change the sign of the function values of bent functions in the .(0, 1) → (1, −1) encoding. This feature can be easily seen for the functions in Example 3.1 and their Gibbs dyadic derivatives. 2. The Gibbs coefficients of a function. f and its logic complement. f have identical absolute values and the sign opposite each other. That is, if the .ith Gibbs coefficient of . f has the value .di = r , then the value of the corresponding Gibbs coefficient of . f is .d i = −r . This feature is illustrated again by the functions in Example 3.1.

3.2

Checking if a Binary Function is Bent by Using the Gibbs Dyadic Derivative

71

3. The sum of positive Gibbs coefficients is equal to the sum of negative Gibbs coefficients and it is .(2n − 1)(2n−2 ). It is easy to verify that the sum of positive as well as the negative Gibbs coefficients in these examples has magnitude .60 and .1008, for .n = 4 and .n = 6, respectively.

3.2

Checking if a Binary Function is Bent by Using the Gibbs Dyadic Derivative

A straightforward way to check if a switching function is bent is to compute its Walsh spectrum and see if it is flat. The WFT algorithm ensures that this can be done efficiently in terms of time. Computing the dyadic Gibbs derivative can be performed faster than computing the Walsh spectrum if the algorithm in terms of partial dyadic Gibbs derivatives is used, since partial derivatives can be computed in parallel provided sufficient computing resources are available. This algorithm is very suitable for implementation on Graphics Processing Units (GPU)-based systems. To check if a function is bent, we need to check if the values of its dyadic Gibbs derivative are all distinct and by the absolute values are in the set .{0, 1, 2, . . . , 2n − 1}. In programming implementation this can be done as follows. We define an auxiliary vector .V = [V (0), V (1), . . . , V (2n − 1)]T , with initial values .V (i) = 0. Then, when computed, values of the dyadic Gibbs derivative are stored in the positions .V (|D(i)|) = D(i). If .|D(i)| > 2n − 1, an error occurs, which means that the function is not bent. After the computing is done, we check if .V (i) / = 0 for .i = 1, . . . , 2n − 1. Notice that .0 is saved in the position .V (0). In this way, we avoid ordering of values of the dyadic Gibbs derivative, and complexity of the procedure is comparable to checking if the absolute values of elements of the Walsh spectrum are equal to .2n/2 . We compared the computing times for calculating the Walsh spectrum and the dyadic Gibbs derivative on the GPU Nvidia GTX 560 Ti that has .8 streaming multiprocessors with .48 streaming processors each which makes .384 in total, with .1 GB GDDR5 RAM and .128 GB/s memory bandwidth with the CPU Intel i7-920 running at .2.8 GHz. For this hardware platform, the computations were done in the following way: 1. For .n < 8, all partial derivatives are computed in parallel. 2. For .n = 8, 9, 10, up to .7 partial derivatives are computed in parallel on the hardware level. 3. For .n = 11, 12, up to 4 partial derivatives are computed in parallel. 4. For .n = 13, two partial derivatives are computed in parallel. 5. For .n ≥ 14, partial derivatives are computed sequentially.

72

3 Gibbs Characterization of Binary Bent Functions

Table 3.1 Times [msec] for computing the Walsh spectrum and the Gibbs derivative for binary functions with .n variables Walsh coefficients Gibbs derivative

Memory transfers Task parallelism

6

11.0

2.8

3.0

All partial derivatives

7

11.8

3.1

3.1

8

13.3

3.8

3.1

9 10

15.7 19.8

4.6 6.0

3.3 3.7

11

30.1

10.5

5.0

12

32.6

10.6

7.4

13

34.7

17.3

15.2

.2

14

38.0

31.8

25.8

Partial derivatives computed sequentially

15 16 17

69.4 132.8 266.6

64.7 127.8 303.9

47.5 91.2 178.2

Up to .7 partial derivatives

Up to .4 partial derivatives partial derivatives

Table 3.1 taken from [3] shows the computing times for the Walsh spectrum and the dyadic Gibbs derivative and the time for necessary memory transfers which is equal in both cases. When partial derivatives can be computed in parallel, the corresponding algorithm is faster. For .n = 17 and larger, the computation of the Walsh spectrum becomes faster on the used hardware, since the partial dyadic Gibbs derivatives are computed sequentially with the so-called atomic operations used in to ensure correctness of the computations in (2.5). It follows that the characterization of bent functions in terms of the dyadic Gibbs derivative can be useful in checking if a given switching function is bent or otherwise. It is assumed that the underlying hardware platform allows parallel computing of partial dyadic Gibbs derivatives.

3.3

Gibbs Permutation Matrices

For a given number of variables .n, the set of all binary bent functions can be split into two subsets of the same cardinality, i.e., into two halves, with respect to the number of non-zero values, the Hamming weight, the functions with the Hamming weight of .w( f ) = 2n−1 − 2(n/2)−1 , and the set of their logic complements with .w( f ) = 2n−1 + 2(n/2)−1 .

3.3

Gibbs Permutation Matrices

73

Example 3.7 For .n = 4, there are in total .896 bent functions. We usually consider .448 of them, since the other functions are their logic complements. Since all .448 bent functions have the same number of non-zero values, they mutually differ in the positions of these values. Therefore, the function vectors of bent functions are permutations of the binary vectors with .2n−1 − 2n/2−1 or .2n−1 + 2n/2−1 non-zero values. In the encoding .(0, 1) → (1, −1), non-zero values are replaced with negative values. An additional condition is that they cannot be balanced. These permutations are not arbitrary, but very specific, since the number of bent functions is very small compared to the number of all .n-variable binary functions. The permutations are not easy to trace in the binary domain, since just two different values at different positions are permuted. It is the same in the Walsh spectral domain since the spectrum is flat and again there are just two different values .2n/2 and .−2n/2 that are permuted. Further, the correspondence between the positive and negative values in the function vector of . f and its Walsh spectrum . S f is not simple to be established. The situation is a bit simpler with the Gibbs coefficients as it will be seen from the considerations below. The Gibbs derivative of a bent function can be represented as a vector whose elements are all elements in the set . Bn = {0, 1, 2, . . . , 2n − 1} [3]. The .ith Gibbs coefficient .d(i) has the same sign as the function value . f (i) in complex encoding. The values of Gibbs coefficients are all distinct and belong to the set . Bn . Therefore, for all bent functions the vectors of the Gibbs coefficients are permuted versions of each other, and these permutations are easier to trace since values of Gibbs coefficients are distinct. Since the function vectors are of finite length, a way to represent these permutations is by permutation matrices. These observations imply definition of a particular class of permutation matrices that we call the Gibbs permutation matrices. Absolute values of Gibbs coefficients of bent functions are eigenvalues of the Gibbs derivative. In other words, Gibbs coefficients are permuted versions of the vector .Bn = [0, 1, 2, . . . , 2n − 1]T . A different permutation of these values corresponds to another bent function and, therefore, bent functions can be uniquely characterized by the permutations determined by the Gibbs coefficients [3]. Definition 3.1 The permutation matrix .P assigned by the Gibbs derivative of a bent function . f in .n variables is the .(2n × 2n ) permutation matrix that permutes the vector n T into the vector of absolute values of the Gibbs coefficients .Bn = [0, 1, 2, . . . , 2 − 1] of . f . Since for bent functions the Gibbs coefficients are eigenvalues of the Gibbs derivative, it follows Definition 3.2. Definition 3.2 The Gibbs permutation matrix is a .(2n × 2n ) matrix .Pg = [ pi, j ], whose element . pi, j = 1 if the .ith Gibbs coefficient has the absolute value . j, otherwise . pi, j = 0.

74

3 Gibbs Characterization of Binary Bent Functions

Example 3.8 The function . f = x1 x2 has the function vector .F1 = [0, 0, 0, 1]T which after encoding is .F1i = [1, 1, 1, −1]T , and the Walsh spectrum is .S f1 = [2, 2, 2, −2]T . If we permute the last two elements in the spectrum, we get.S f 4 = [2, 2, −2, 2]T . This permutation can be expressed by the permutation matrix ⎡

P S1,4

.

1 ⎢0 =⎢ ⎣0 0

0 1 0 0

0 0 0 1

⎤ 0 0⎥ ⎥. 1⎦ 0

The produced spectrum .S f4 is the Walsh spectrum for the function .F4 = [1, −1, 1, 1]T . This function can be obtained from the initial function . f 1 by either the permutation matrix ⎡

P f1,4

.

1 ⎢0 =⎢ ⎣0 0

0 0 1 0

0 0 0 1

0 0 0 1

0 0 1 0

⎤ 0 1⎥ ⎥, 0⎦ 0

or ⎡

P f1,4

.

1 ⎢0 =⎢ ⎣0 0

⎤ 0 1⎥ ⎥. 0⎦ 0

The corresponding function expression is . f 4 = x2 ⊕ x1 x2 . In terms of spectral invariant operations, . f 4 is obtained from . f 1 by .x1 → x1 ⊕ x2 . Therefore, . f 1 = x1 x2 → (x1 ⊕ x2 )x2 = x1 x2 ⊕ x2 = f 4 . Since the first three elements in both function vector and the spectrum of . f 1 are equal, . f 4 can be obtained by using some other permutation matrices as, for example, ⎡

P S1,4

.

0 ⎢1 =⎢ ⎣0 0

1 0 0 0

0 0 0 1

⎤ 0 0⎥ ⎥. 1⎦ 0

Therefore, the corresponding permutation matrices are not uniquely determined. For any number of variables .n, the basic bent function that is expressed as the sum of products of disjoint pairs of variables, the Walsh spectrum is equal to the complex encoded function vector multiplied by .2n/2 . Therefore, the signs of Walsh coefficients for basic bent functions are equal to that of function values. The Gibbs derivative for . f 1 is . D f1 = [0, 2, 1, −3]T . The Gibbs derivative for . f 4 is . D f4 = [1, −3, 0, 2]T . Since for both functions all Gibbs coefficients are different, there is a single permutation matrix converting the vector of eigen-

3.3

Gibbs Permutation Matrices

75

values of the Gibbs derivative .E = [0, 1, 2, 3]T into the vector of the Gibbs derivative for . f 1 . This is the matrix ⎡

P D1

.

1 ⎢0 =⎢ ⎣0 0

0 0 1 0

0 1 0 0

⎤ 0 0⎥ ⎥. 0⎦ 1

It is the same for . f 4 . In this case the permutation matrix is ⎡

P D4

.

0 ⎢0 =⎢ ⎣1 0

1 0 0 0

0 0 0 1

⎤ 0 1⎥ ⎥. 0⎦ 0

Therefore, this matrix uniquely determines the bent function . f 4 . We call these permutation matrices the permutation matrices assigned to the functions . f 1 and . f 4 , respectively. If .P D1 is applied to . f 2 defined as .F2 = [1, 1, −1, 1]T , we get the function . f 4 with .F4 = [1, −1, 1, 1]T . If it is applied to . f 4 , we get the function . f 2 defined by .F2 = [1, 1, −1, 1]T . If it is applied to . f 2 , we get . f 4 . In general, when a permutation matrix assigned by the Gibbs derivative to a bent function . f is applied to a bent function, another bent function is produced. In some cases, the initial bent function is obtained. The signs of Gibbs coefficients for any bent function are equal to the signs of its function values after the complex encoding. Therefore, unlike the Walsh coefficients where this property holds just for basic bent functions, it is true for Gibbs coefficient for all bent functions. Example 3.9 For function . f specified by the encoded function vector F = [−1, −1, 1, −1, −1, 1, 1, 1, 1, 1, −1, 1, −1, 1, 1, 1]T ,

.

the Walsh spectrum is S f = [4, −4, −4, −4, −4, 4, 4, 4, −4, 4, −4, −4, −4, 4, −4, −4]T .

.

The Gibbs derivative is D f1 = [−10, −12, 11, −13, −3, 5, 2, 4, 14, 8, −15, 9, −7, 1, 6, 0]T ,

.

and the corresponding permutation matrix is

76

3 Gibbs Characterization of Binary Bent Functions



P f1

.

0 ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 =⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎣0 1

0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0

0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0

0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0

0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0

0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0

1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0

0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0

⎤ 0 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥. 0⎥ ⎥ 0⎥ ⎥ 1⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎦ 0

This permutation can be expressed with the product of cycles .

P = (5)(0, 10, 15)(1, 12, 7, 4, 3, 13, 1)(2, 11, 9, 8, 14, 6),

which leads to the factorization into three sparse matrices.

3.4

Structure of Gibbs Permutation Matrices

In this section, we specify requirements that should be satisfied in order that a .(2n × 2n ) permutation matrix, where .n is a natural number, be a Gibbs permutation matrix. Each Gibbs permutation matrix is composed of the following five submatrices: [ ] [ ] [ ] [ ] [ ] 00 01 00 10 00 .A = ,B = ,C = D= ,0 = . 01 00 10 00 00 Except the zero submatrix .0, each submatrix appears .2(n−2) times in the .(2n × 2n ) Gibbs permutation matrix. Being a permutation matrix, the single non-zero element should be in each row and column which determines the possible distribution of these submatrices within a Gibbs permutation matrix. Therefore, the following requirements should be satisfied: 1. No two identical submatrices can appear in the same row or column except for the submatrix .0, therefore, neither .AA, nor .BB, nor .CC, nor .DD in the same row or column. 2. No two .A and .C in the same row.

3.4

3. 4. 5. 6.

Structure of Gibbs Permutation Matrices

77

No two .B and .D in the same row. No two .A and .B in the same column. No two .C and .D in the same column. Allowed combinations of submatrices are .A, B, and .C, D for rows and .A, C, and .B, D for columns.

An additional requirement is that each four of these different non-zero submatrices should be placed in such a way that they form vertices of a rectangle. In each rectangle, the position of the vertices should be such that the componentwise sum of binary representations of the coordinates should be the zero .2(n − 1)-tuple. In other words, if .ai, j , .bi, j , .ci, j , and .di, j are elements of the submatrices .A, .B, .C, and .D, then it should be a00 ⊕ b00 ⊕ c00 ⊕ d00 = 0, a01 ⊕ b01 ⊕ c01 ⊕ d01 = 0, a10 ⊕ b10 ⊕ c10 ⊕ d10 = 0, a11 ⊕ b11 ⊕ c11 ⊕ d11 = 0. These requirements specified above determine the structure of the Gibbs permutation matrices, and they are necessary and sufficient conditions for a.(2n × 2n ) permutation matrix to be a Gibbs permutation matrix. Example 3.10 The Gibbs dyadic derivative of the function . f = x1 x2 ⊕ x2 x3 ⊕ x3 x4 is D f = [0, 2, 5, −7, 10, 8, −15, 13, 4, 6, 1, −3, −14, −12, 11, −9]T .

.

This derivative determines the Gibbs permutation matrix as shown in Fig. 3.1. The submatrices .A, .B, .C, .D are arranged as vertices in four rectangles, which we call from left to the right Red, Brown, Green, Violet, or in short R, B, G, V. We label four vertices of each rectangle as .00, .01, .10 and .11. The coordinates of submatrices in the vertices are R00 R01 . R10 R11

= 000|000, = 000|001, = 101|000, = 101|001,

B00 B01 B10 B11

= 001|010, = 001|011, = 100|010, = 100|011,

G 00 G 01 G 10 G 11

= 010|100, = 010|101, = 111|100, = 111|101,

V00 V01 V10 V11

= 011|110, = 011|111, = 110|110, = 110|111.

It can be observed that the componentwise sum of the same coordinates in these rectangles is a zero coordinate

78

3 Gibbs Characterization of Binary Bent Functions 000

001

010

011

100

101

110

111

000 001 010 P=

011 100 101 110 111

Fig. 3.1 The permutation matrix assigned to the function . f = x1 x2 ⊕ x2 x3 ⊕ x3 x4 in Example 3.10

R00 ⊕ B00 ⊕ G 00 ⊕ V00 = 000|000 ⊕ 001|010 ⊕ 010|100 ⊕ 011|110 = 000|000, R01 ⊕ B01 ⊕ G 01 ⊕ V01 = 000|001 ⊕ 001|011 ⊕ 010|101 ⊕ 011|111 = 000|000, R10 ⊕ B10 ⊕ G 10 ⊕ V10 = 101|000 ⊕ 100|010 ⊕ 111|100 ⊕ 110|110 = 000|000, R11 ⊕ B11 ⊕ G 11 ⊕ V11 = 101|001 ⊕ 100|011 ⊕ 111|101 ⊕ 110|111 = 000|000. This is another rule that should be satisfied when constructing Gibbs permutation matrices. We refer to [4] for more examples of the Gibbs permutation matrices.

3.5

Binary Bent Functions in Four Variables

In this section, we present some observations derived from a computer verification of certain properties of Gibbs permutation matrices for functions in four variables. For .n = 4, there are .896 bent functions; half of them, .448, are logic complements of the other half. Therefore, in this computer verification, we consider .448 bent functions with .6 non-zero values. Functions with .10 non-zero values are their logic complements. Since the Gibbs permutation matrices are defined with respect to the absolute values of Gibbs coefficients, there are .448 different permutation matrices. Recall that the Gibbs coefficients for a function . f and its logic complement . f differ just in the sign but have identical absolute values.

3.5

Binary Bent Functions in Four Variables

79

Remark 3.1 When a given Gibbs permutation matrix is applied to all bent functions, all these functions are again obtained. It follows that each Gibbs permutation matrix converts a bent function into a bent function of the same number of variables. When all Gibbs permutation matrices are applied to the same bent function, a subset of bent functions is obtained. This observation will be discussed in more detail on the following example. Consider the basic bent function for.n = 4 and two functions derived from it by permuting the variables .

f b1 = x1 x2 ⊕ x3 x4 , f b2 = x1 x3 ⊕ x2 x4 , f b3 = x1 x4 ⊕ x2 x3 .

When all .448 Gibbs permutation matrices are applied to . f b1 , we obtain 1. .192 other mutually different bent functions. 2. Additional .16 functions are obtained .16 times each. This means that .16 different Gibbs permutation matrices produce a specific bent function. f s1 when applied to. f b1 . Another.16 Gibbs permutation matrices produce another specific function . f b2 . There are .16 specific functions produced by .16 different subsets of Gibbs permutation matrices. 3. .240 bent functions are not generated from . f b1 by the application of all .448 Gibbs permutation matrices. The term specific functions is used with no other reason or justification but to differentiate these .16 functions that cannot be obtained from the three basic bent functions from other bent functions obtained by the application of the Gibbs permutation matrices to them. The same results are obtained when the permutation matrices are applied to other two basic functions derived by permuting variables in . f b1 . For the three basic functions, the sets of .192 functions obtained by the application of all Gibbs permutation matrices as well as sets of .16 functions obtained .16 times are different but not disjoint. The same is true when all Gibbs permutation matrices are applied to any bent function not just the basic functions. When all permutation matrices are applied to two basic bent functions, for example, . f b1 = x 1 x 2 ⊕ x 3 x 4 and . f b2 = x 1 x 3 ⊕ x 2 x 4 , then .256 functions are generated a single time, .64 are generated .2 times, .32 are generated .16 times, and .96 functions are not generated. The same results are obtained for any combination of two basic functions. When we apply all .448 permutation matrices to the three basic bent functions, all bent functions except .16 are produced. These .16 functions that cannot be obtained in this way and their Reed–Muller spectra and the corresponding functional expressions are given in Table 3.2. In this case, .192 functions are generated a single time, other .192 functions are

80

3 Gibbs Characterization of Binary Bent Functions

Table 3.2 The .16 bent functions that cannot be obtained by Gibbs permutation matrices from the three basic bent functions .

f , .F, .Sr m

= [1, 0, 0, 0, 0, 0, 0, 1, 1, 1, 1, 0, 1, 0, 0, 0]T T .Sr m1 = [1, 1, 1, 1, 1, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 1 = 1 ⊕ x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2

1

.F1

2

.F2

3

.F3

4

.F4

5

.F5

6

.F6

7

.F7

8

.F8

9

.F9

10

.F10

11

.F11

12

.F12

= [1, 0, 0, 0, 1, 1, 1, 0, 0, 0, 0, 1, 1, 0, 0, 0]T T .Sr m2 = [1, 1, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 2 = 1 ⊕ x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 1, 1, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 0, 0, 0]T T .Sr m3 = [0, 1, 1, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 3 = x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [1, 0, 1, 1, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 0]T T .Sr m4 = [1, 1, 0, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 4 = 1 ⊕ x4 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 1, 0, 0, 1, 1, 0, 1, 0, 0, 1, 0, 0, 1, 0, 0]T T .Sr m5 = [0, 1, 0, 1, 1, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 5 = x4 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 1, 0, 0, 0, 0, 1, 0, 1, 1, 0, 1, 0, 1, 0, 0]T T .Sr m6 = [0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 6 = x4 ⊕ x3 x4 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [1, 1, 0, 1, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 1, 0]T T .Sr m7 = [1, 0, 1, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 7 = 1 ⊕ x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 0, 0, 0, 0, 1, 0]T T .Sr m8 = [0, 0, 1, 1, 1, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 8 = x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 0, 1, 0, 0, 1, 0, 0, 1, 0, 1, 1, 0, 0, 1, 0]T T .Sr m9 = [0, 0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 9 = x3 ⊕ x3 x4 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2 = [0, 0, 0, 1, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 0]T T .Sr m10 = [0, 0, 0, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 10 = x 3 x 4 ⊕ x 2 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2 = [1, 1, 1, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 0, 0, 1]T T .Sr m11 = [1, 0, 0, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 11 = 1 ⊕ x 3 x 4 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2 = [0, 0, 0, 1, 0, 1, 1, 1, 1, 0, 0, 0, 0, 0, 0, 1]T T .Sr m12 = [0, 0, 0, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 12 = x 3 x 4 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2 (continued)

3.5

Binary Bent Functions in Four Variables

81

Table 3.2 (continued) .

f , .F, .Sr m

= [0, 0, 0, 1, 1, 0, 0, 0, 0, 1, 1, 1, 0, 0, 0, 1]T T .Sr m13 = [0, 0, 0, 1, 1, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 13 = x 3 x 4 ⊕ x 2 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2

13

.F13

14

.F14

15

.F15

16

.F16

= [0, 0, 1, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 1, 0, 1]T T .Sr m14 = [0, 0, 1, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 14 = x 3 ⊕ x 3 x 4 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2 = [0, 1, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 1, 0, 1, 1]T T .Sr m15 = [0, 1, 0, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 0] . f 15 = x 4 ⊕ x 3 x 4 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 x 4 ⊕ x 1 x 3 ⊕ x 1 x 2 = [1, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 1, 1, 1]T T .Sr m16 = [1, 1, 1, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 0, 0, 0] . f 16 = 1 ⊕ x 4 ⊕ x 3 ⊕ x 3 x 4 ⊕ x 2 ⊕ x 2 x 4 ⊕ x 2 x 3 ⊕ x 1 ⊕ x1 x4 ⊕ x1 x3 ⊕ x1 x2

generated two times, and .48 functions are obtained .16 times. It means, for each of these .48 functions, there are .16 permutation matrices that generate them. The .16 functions that cannot be generated by the Gibbs permutation matrices from the basic bent functions are defined as functions whose Reed–Muller expression consists of products of all possible pairs of variables and all possible linear functions for .n = 4, with the linear functions in more than two variables negated. In Table 3.3, these .16 functions are written in terms of the function .q defined in terms of all possible pairs of variables as q = x1 x2 ⊕ x1 x3 ⊕ x1 x4 ⊕ x2 x3 ⊕ x2 x4 ⊕ x3 x4 .

.

In this table, the second column shows integers whose binary representations are the corresponding function vectors. In other words, the integer .r f representation of a function is ∑2n −1 i 2 f (i), where . f (i) are elements of the truth-vector .F of . f . determined as .r f = i=0 These .16 functions are obtained by the application of the Gibbs permutation matrices to some bent functions other than the three basic functions. The specific bent functions can be obtained from other bent functions by using different Gibbs permutation matrices. Table 3.4 shows .8 functions from which the specific function with integer representation .6017 is obtained. In this table, the first column shows the integer corresponding to the function the permutation matrix assigned to which is applied to the function in the second column. The third column is the vector of Gibbs coefficients determining the used permu-

82

3 Gibbs Characterization of Binary Bent Functions

Table 3.3 The .16 bent functions that cannot be obtained by permutation matrices from the three basic bent functions in terms of .q .r

f

Expression for . f

1

33047

.

f1 = q ⊕ 1

2

33256

.

f 2 = q ⊕ x1

3

36376

.

f 3 = q ⊕ x2

4

45604

.

f 4 = q ⊕ x3

5

54338

.

f 5 = q ⊕ x4

6

28952

.

f 6 = q ⊕ ⊕x2 ⊕ x1

7

19748

.

f 7 = q ⊕ x3 ⊕ x1

8

11074

.

f 8 = q ⊕ x4 ⊕ x1

9

17108

.

f 9 = q ⊕ x3 ⊕ x2

10

9394

.

f 10 = q ⊕ x4 ⊕ x2

11

6286

.

f 11 = q ⊕ x4 ⊕ x3

12

16939

.

f 12 = q ⊕ 1 ⊕ x3 ⊕ x2 ⊕ x1

13

9293

.

f 13 = q ⊕ 1 ⊕ x4 ⊕ x2 ⊕ x1

14

6257

.

f 14 = q ⊕ 1 ⊕ x4 ⊕ x3 ⊕ x1

15

6017

.

f 15 = q ⊕ 1 ⊕ x4 ⊕ x3 ⊕ x2

16

59521

.

f 16 = q ⊕ 1 ⊕ x4 ⊕ x3 ⊕ x2 ⊕ x1

tation matrix and the function vector of the function to which the permutation matrix is applied to get the function with the integer representation .6017. It is interesting to observe that the considered specific .16 functions are a closed set with respect to the Gibbs permutation matrices in the sense that if any Gibbs permutation matrix is applied to them, the same set of bent functions is reproduced. Table 3.5 shows the correspondence between the considered .16 specific bent functions with respect to the Gibbs permutation matrix assigned to the basic bent function . f b1 . The second and the third column show the integers representing functions to which the Gibbs permutation matrix for . f b1 is applied and the obtained functions, respectively. It should be observed that in the case of functions enumerated as .1, .6, .11, .16, the application of the selected Gibbs permutation matrix produces the initial functions. There are pairs of functions reciprocal to each other, .2 and .3, .4 and .5, .7 and .10, .8 and .9, .12 and .13, .14 and .15. Similar conclusions are obtained when Gibbs permutation matrices assigned to other two basic bent functions are used, since these functions differ in just permutation of variables.

3.5

Binary Bent Functions in Four Variables

83

Table 3.4 An example of .8 bent functions from which the first specific bent function with the integer representation .6017 is obtained by using different Gibbs permutation matrices .f

1

854

.6017

.D f and .F

16939

.D f

1

= [0, 8, 4, 12, 2, 10, −6, −14, 1, −9, 5, −13, 3, −11, −7, 15]T

.F1 = [0, 1, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 1, 0, 1, 1]T

2

857

13834

.D f

= [0, 8, 4, 12, 10, 2, −14, −6, 5, −13, 1, −9, −15, 7, 11, −3]T

3

869

7714

.D f

= [0, 8, 12, 4, 2, 10, −14, −6, 3, −11, −15, 7, 1, −9, 13, −5]T

4

874

16939

.D f

5

23648

45604

.D f

6

59416

36376

.D f

2 .F2 = [0, 0, 1, 1, 0, 1, 1, 0, 0, 0, 0, 0, 1, 0, 1, 0]T 3 .F3 = [0, 0, 0, 1, 1, 1, 1, 0, 0, 0, 1, 0, 0, 0, 1, 0]T 4

= [8, 0, 4, 12, 2, 10, −14, −6, −15, 7, 3, −11, 5, −13, 9, −1]T

.F4 = [0, 1, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 1, 0, 1, 1]T

= [5, −1, 9, −13, −14, −10, 2, 6, 3, −7, −15, 11, 8, 12, 4, 0]T

5 .F5 = [1, 0, 1, 1, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 0]T 6

= [−8, −14, −13, 11, −3, 5, 6, 0, 12, 10, 9, −15, −7, 1, 2, 4]T

.F6 = [1, 0, 0, 0, 1, 1, 1, 0, 0, 0, 0, 1, 1, 0, 0, 0]T

7

59428

45604

.D f

= [−8, −14, −5, 3, −11, 13, 6, 0, 10, 12, −7, 1, 9, −15, 4, 2]T

8

59458

54338

.D f

= [−8, −6, −13, 3, −11, 5, 14, 0, 9, −7, 12, 2, 10, 4, −15, 1]T

7 .F7 = [1, 0, 1, 1, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 0]T 8 .F8 = [1, 1, 0, 1, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 1, 0]T

Table 3.5 Correspondence between .16 specific bent functions with respect to the Gibbs permutation matrix assigned to . f b1 Initial . f

Derived . f

Expression for . f

1

33047

33047

. f1 = q ⊕ 1

2

36376

33256

. f 2 = q ⊕ x1

3

33256

36376

. f 3 = q ⊕ x2

4

54338

45604

. f 4 = q ⊕ x3

5

45604

54338

. f 5 = q ⊕ x4

6

28952

28952

. f 6 = q ⊕ ⊕x 2 ⊕ x 1

7

9394

19748

. f 7 = q ⊕ x3 ⊕ x1

8

17108

11074

. f 8 = q ⊕ x4 ⊕ x1

9

11074

17108

. f 9 = q ⊕ x3 ⊕ x2

10

19748

9394

. f 10 = q ⊕ x 4 ⊕ x 2

11

6286

6286

. f 11 = q ⊕ x 4 ⊕ x 3

12

9293

16939

. f 12 = q ⊕ 1 ⊕ x 3 ⊕ x 2 ⊕ x 1

13

16939

9293

. f 13 = q ⊕ 1 ⊕ x 4 ⊕ x 2 ⊕ x 1

14

6017

6257

. f 14 = q ⊕ 1 ⊕ x 4 ⊕ x 3 ⊕ x 1

15

6257

6017

. f 15 = q ⊕ 1 ⊕ x 4 ⊕ x 3 ⊕ x 2

16

59521

59521

. f 16 = q ⊕ 1 ⊕ x 4 ⊕ x 3 ⊕ x 2 ⊕ x 1

84

3 Gibbs Characterization of Binary Bent Functions

References 1. Carlet, C., Mesnager, S.: On Dillon’s class . H of bent functions, Niho bent functions and .opolynomials. J. Comb. Theory Ser. A 118, 2392–2410 (2011) 2. MacWilliams, F.J., Sloane, N.J.A.: The Theory of Error-Correcting Codes. North-Holland, Amsterdam (1977) 3. Stankovi´c, R.S., Astola, J.T., Moraga, C., Stankovi´c, M., Gaji´c, D.: Remarks on characterization of bent functions in terms of Gibbs dyadic derivatives. In: Moreno-Diaz, R., Pichler, F., QuesadaArencibia, A. (eds.) Eurocast 2015. Computer Aided Systems Theory - EUROCAST 2015, 15th International Conference, Las Palmas de Gran Canaria, Spain, February 8–13, 2015. Revised Selected Papers LNCS, vol. 9520, 632–639. Springer (2015) 4. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of binary bent functions by FFT-like permutation algorithms. In: Drechsler, R., Grosse, D. (eds.) Recent Findings in Boolean Techniques, Selected Papers from the 14th International Workshop on Boolean Problems, 105– 124. Springer (2021). ISBN 978-3-030-68070-1, eBook ISBN 978-3-030-68071-8

4

Gibbs Characterization of Ternary Bent Functions

In this chapter, the Gibbs characterization of binary bent functions is extended to ternary functions. Due to the differences between binary and ternary bent functions, a straightforward extension is impossible, and not all ternary bent functions can be conveniently characterized in terms of the Gibbs derivatives; still some interesting conclusions can be derived. As already discussed in previous chapters, when computing the Walsh spectra of binary functions in the encoding .(0, 1) → (1, −1) there are some restrictions to the possible values of Walsh spectral coefficients. In particular, all the coefficients are either .0 or even integers with absolute value no larger than .2n , where .n is the number of variables. Moreover, not all possible combinations of even integers in this range are allowed in the spectrum of a binary function, but certain precisely defined combinations [1, 2]. These requirements characterize Walsh spectra of binary functions compared to the spectra of other discrete functions that can take more than two values. Similar restrictions are imposed on the Vilenkin–Chrestenson spectra of ternary functions. In the encoding .(0, 1, 2) → (1, e1 , e2 ), not all combinations of values for real and imaginary parts for complex numbers of Vilenkin–Chrestenson spectral coefficients are allowed in the case of spectra of ternary functions. These restrictions are a characterization of Vilenkin–Chrestenson spectra of ternary functions. Bent functions are defined by requiring that their Vilenkin–Chrestenson spectra are flat. The Gibbs derivatives on finite Abelian groups, which include the group .C3n which is the domain group for ternary functions, are defined in terms of the Vilenkin–Chrestenson transform instead of the Walsh transform used in the binary case. Restrictions ensuring that Vilenkin–Chrestenson spectral coefficients are coefficients in the spectrum of a ternary function, and the restrictions that the spectrum must be flat for bent functions leads to certain restrictions of the Gibbs coefficients of bent functions. In this chapter, we discuss restrictions on the values of Gibbs coefficients which can be used to characterize at least some subsets of ternary bent functions. © The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_4

85

86

4 Gibbs Characterization of Ternary Bent Functions

Table 4.1 Ternary bent functions for .n = 1 .F1

= [0, 1, 1]T

T .F4 = [0, 2, 2] T .F7 = [1, 0, 0] T .F10 = [2, 0, 0] T .F13 = [2, 1, 1] T .F16 = [1, 2, 2]

4.1

.F2

= [1, 0, 1]T

T .F5 = [2, 0, 2] T .F8 = [0, 1, 0] T .F11 = [0, 2, 0] T .F14 = [1, 2, 1] T .F17 = [2, 1, 2]

.F3

= [1, 1, 0]T

.F6

= [2, 2, 0]T

.F9

= [0, 0, 1]T

.F12

= [0, 0, 2]T

.F15

= [1, 1, 2]T

.F18

= [2, 2, 1]T

Ternary Bent Functions for .n = 1

There are .18 ternary bent functions in a single variable whose function vectors are shown in Table 4.1. Notice that these functions are mutually related by spectral invariant operations. For example, the functions in the second row of Table 4.1, . f 4 , . f 5 , . f 6 are the functions in the first row . f 1 , . f 2 , . f 3 multiplied by .2 modulo .3. The same is with functions in the fourth row that are multiple by .2 of functions in the third row. Functions in the .6-th row are multiples by .2 modulo .3 of functions in the .5-th row. These functions are also related by the spectral invariant operation of adding constants modulo .3. For example, . f 10 = f 1 ⊕ 2, . f 10 = f 16 ⊕ 1, . f 13 = f 7 ⊕ 1, . f 18 = f 12 ⊕ 2, and . f 17 = f 2 ⊕ 1. It can be observed that in each function vector there are two identical values and the third is different. Thus, the distribution of single variable ternary bent functions is . D = (0, 1, 2). Not all three possible values are present in the function vector, and the resulting restriction is that two values should be equal and the third value is different.

4.2

Spectral Invariant Operations and Ternary Bent Functions

Recall that in the case of ternary functions, a necessary and sufficient condition for a function f to be bent is that the absolute value of all its Vilenkin–Chrestenson coefficients is equal to .3n/2 . Consider the set . Sn of all ternary bent functions for a given number of variables .n. To stay in this set, the transformations that can be applied to a bent function are restricted to these which ensure that

.

1. The spectrum produced by the used transformations is the spectrum of a ternary function and not a function taking more than three values. This requires that spectral coefficients satisfy allowed combinations of complex numbers for the Vilenkin–Chrestenson coefficients of ternary functions. In our best knowledge, possible combinations of values for Vilenkin–Chrestenson spectra are not yet explicitly formulated, at least in the literature

4.2

Spectral Invariant Operations and Ternary Bent Functions

87

accessible to the authors. Such conditions are not specified even for the binary functions and their Walsh spectra. There are in both cases, binary and ternary, examples for given number of variables which illustrate well the possible combinations of values. 2. The used operations do not change the absolute values of spectral coefficients to preserve bentness. Therefore, they have to be selected among spectral invariant operations. As in the binary case, application of spectral invariant operations to a ternary function . f either 1. Permute its spectral coefficients in a strictly defined manner, meaning that not single coefficients, but certain subsets of coefficients have to be permuted, or 2. Change the polarity of some of the coefficients, under the restriction that polarities of subsets of coefficients have to be changed simultaneously, or 3. Perform both at the same time, permute and change the polarity of precisely defined subsets of coefficients. It is clear that various spectral invariant operations can be applied in a different order to a given function, which results in other ternary bent functions. As is discussed below, transformations in the spectral domain by spectral invariant operations can be related to particular permutations of function values in the original domain. Thus, permutation in the original domain derived from spectral invariant operations results in ternary bent functions with no change of the absolute values of spectral coefficients. It means that by such a permutation a function with a flat spectrum will be converted into another function with a flat spectrum which is the basic requirement here. Another restriction is that we should pay attention to the distribution of function values. Permutations cannot change the distribution of function values. Thus, we need to consider as basic bent functions representatives for each possible distribution for a given .n, as discussed in Sect. 1.9. Therefore, starting from a bent function, the set . Sn of all ternary bent functions with the same distribution can be derived by the application of spectral invariant operations. It is natural to select the simplest bent functions as the basic bent functions in . Sn and derive all other functions from them. The term simplest depends on the context where bent functions are discussed. It usually means the smaller number of product terms in the functional expression for ternary functions representing a corresponding generalization of the positive polarity Reed–Muller expression for binary functions. As noticed in Chap. 1, these expressions are also called the Galois field (GF) expressions [3]. As pointed out in Sect. 1.7, another criterion for simplicity could be a characteristic form of the functional expression, as, for example, the sum of products of disjoint pairs of variables, or the sum of squares of variables. This is also related to the distribution of function values as discussed in Sect. 1.9.

88

4 Gibbs Characterization of Ternary Bent Functions

This property was used in [4] to compactly represent ternary bent functions by Vilenkin– Chrestenson decision diagrams and due to that, a method is derived with linear complexity for the construction of ternary bent functions of arbitrary sizes. Example 4.1 In the binary case, for .n = 2, the simplest in the number of terms count is the function . f p = x1 x2 . For .n = 4 this could be the function . f p (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 . In the ternary case, for .n = 2, we consider two basic functions . f p (x1 , x2 ) = x1 x2 and . f s (x1 , x2 ) = x12 ⊕ x22 , each of them representing a possible distribution .(5, 2, 2) and .(1, 4, 4), respectively. The same as in the binary case, by using classical spectral invariant operations discussed in Sect. 1.10, we generate just functions of a specified degree. To generate ternary bent functions of higher degree, the generalized spectral invariant operations should be used, some of them defined in [5, 6]. As noticed in these publications, some of the possible spectral invariant operations can be observed just in the case of functions of a larger number of variables. Therefore, they are not all explicitly defined in the literature available to the authors of this book and can be viewed as a subject of a future study. The following example illustrates how all .486 ternary bent functions in two variables can be generated from the basic function . f (x1 , x2 ) = x1 x2 by spectral invariant operations.

.

Example 4.2 Disjoint spectral translation applied to a ternary function in two variables f (x1 , x2 ) produces the following .9 ternary functions: 1. 2. 3. 4. 5. 6. 7. 8. 9.

f (x1 , x2 ), f (x1 , x2 ) ⊕ x1 , . f (x 1 , x 2 ) ⊕ x 2 , . f (x 1 , x 2 ) ⊕ x 1 ⊕ x 2 , . f (x 1 , x 2 ) ⊕ 2x 1 , . f (x 1 , x 2 ) ⊕ 2x 2 , . f (x 1 , x 2 ) ⊕ 2x 1 ⊕ x 2 , . f (x 1 , x 2 ) ⊕ x 1 ⊕ 2x 2 , . f (x 1 , x 2 ) ⊕ 2x 1 ⊕ 2x 2 . . .

The polarity of a ternary function .g, defined as .g ⊕ 1 and .g ⊕ 2, provides from each function other two functions. Permutation of variables is obviously not effective, since as the basic function we use either . f (x1 , x2 ) = x1 x2 or . f (x1 , x2 ) = x12 ⊕ x22 . Further, there are .18 quadratic forms of two ternary variables. They are derived by adding quadratic terms to the basic two forms, which are the first and .11-th form in the enumeration in Table 4.2, which are equivalent in the sense that can be derived from each other if the substitutions .u Θ v and .u ⊕ v are performed.

4.2

Spectral Invariant Operations and Ternary Bent Functions

89

Table 4.2 Even ternary bent functions for .n = 2 and their distributions .

f

.F

.D

= [000012021]T

.(5, 2, 2) .(5, 2, 2)

2.

f 1 (x1 , x2 ) = x1 x2 . f 2 (x 1 , x 2 ) = 2x 1 x 2

3.

.

T .F = [000021012] T .F = [000120102]

.(5, 2, 2)

.

T .F = [000102120] T .F = [000201210] T .F = [000210201] T .F = [011020002]

.(5, 2, 2)

T .F = [011002020] T .F = [022001010]

.(5, 2, 2)

f 10 (x1 , x2 ) = 2x22 ⊕ 2x1 x2

T .F = [022010001]

.(5, 2, 2)

f 11 (x1 , x2 ) = x12 ⊕ x22 2 2 . f 12 (x 1 , x 2 ) = 2x ⊕ x 1 2

.F

= [011122122]T

.(1, 4, 4)

.F

= [011200200]T

.(5, 2, 2)

2 2 . f 13 (x 1 , x 2 ) = x ⊕ 2x 1 2 2 2 . f 14 (x 1 , x 2 ) = 2x ⊕ 2x 1 2

T .F = [022100100] T .F = [022211211]

.(5, 2, 2)

f 15 (x1 , x2 ) = x12 ⊕ x1 x2 ⊕ 2x22

T .F = [022112121]

.(1, 4, 4)

f 16 (x1 , x2 ) = 2x12 ⊕ x1 x2 ⊕ x22

.F

= [011212221]T

.(1, 4, 4)

f 17 (x1 , x2 ) = x12 ⊕ 2x1 x2 ⊕ 2x22

.F

= [022121112]T

.(1, 4, 4)

f 18 (x1 , x2 ) = 2x12 ⊕ 2x1 x2 ⊕ x22

.F

= [011221212]T

.(1, 4, 4)

1.

4. 5.

.

f 3 (x1 , x2 ) = x12 ⊕ x1 x2 2 . f 4 (x 1 , x 2 ) = x ⊕ 2x 1 x 2 1 f 5 (x1 , x2 ) = 2x12 ⊕ x1 x2

6.

.

f 6 (x1 , x2 ) =

7.

.

f 7 (x1 , x2 ) =

8.

.

f 8 (x1 , x2 ) =

9.

.

f 9 (x1 , x2 ) =

10.

.

11.

.

12. 13. 14. 15.

.

16.

.

17.

.

18.

.

2x12 ⊕ 2x1 x2 x22 ⊕ x1 x2 x22 ⊕ 2x1 x2 2x22 ⊕ x1 x2

.F

.(5, 2, 2)

.(5, 2, 2)

.(5, 2, 2)

.(5, 2, 2)

.(1, 4, 4)

These .18 functions, shown in Table 4.2 are called in [7] the symmetric ternary functions of two variables in the sense that they satisfy the relation . f (−x) = f (x), .x being the ternary representation of the first nine non-negative integers and negation understood as componentwise subtraction modulo .3 [7]. This should not be confused with the usual definition of symmetric functions as invariance of function values to the permutation of variables . f (x1 , · · · , xi , · · · , xk , · · · , xn ) = f (x1 , · · · , xk , · · · , xi , · · · , xn ) for any pair of .i, k ∈ {1, 2, . . . , n}. For this reason, when we later refer to these functions, we will call them even ternary functions. It can be observed that these functions are squares of ternary variables and their linear combinations with multiplicative coefficients .0, 1, 2, to which the product of variables multiplied by .1 or .2 is added. For instance, . f 18 in Table 4.2 is the sum of squares of variables, where the square of the first variable .x1 is multiplied by .2, to which is added the product . x 1 x 2 multiplied by .2. Therefore, . f 18 = 2 f 3 .

90

4 Gibbs Characterization of Ternary Bent Functions

Notice that functions . f 1 and . f 2 in Table 4.2 are both even and symmetric. Recall that if a ternary function in two variables is even, then its function vector has the structure F = [a, b, b, c, d, e, c, e, d]T .

.

The function vector of a symmetric ternary function in two variables has the structure F = [a, b, c, b, d, e, c, e, g]T .

.

There are bent functions that are neither even nor symmetric. An example is the function . f 2 in Example 4.3 below. The disjoint spectral translation can be applied to each of these even functions and the polarity can be changed as described above. The total number of functions is .9 × 3 × 18 = 486, which is the number of ternary bent functions as shown by a computer enumeration out of .19683 ternary functions of two variables [14]. This Example 4.2 illustrates the possibility to formulate the following statement. Statement 4.1 For a specified distribution of function values, a function . f 2 can be derived from a given bent function. f 1 with the same distribution by permuting elements of the function vector .F1 of . f 1 to get the function vector .F2 of . f 2 . Since bent functions by definition have flat spectra the allowed permutations are restricted to the set of permutations that can be obtained as combinations of permutations corresponding to spectral invariant operations taken arbitrarily many times and in an arbitrary order. The following example illustrates this statement. Example 4.3 Consider the basic ternary bent function in two variables . f (x1 , x2 ) = x1 x2 whose distribution of function values is .(5, 2, 2) as can be seen from its function vector T .F = [0, 0, 0, 0, 1, 2, 0, 2, 1] . The permutation matrix ⎡ ⎤ 010000000 ⎢0 0 1 0 0 0 0 0 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢1 0 0 0 0 0 0 0 0⎥ ⎢ ⎥ ⎢0 0 0 0 1 0 0 0 0⎥ ⎢ ⎥ .P = ⎢ 0 0 0 0 0 1 0 0 0 ⎥ ⎢ ⎥ ⎢0 0 0 1 0 0 0 0 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢0 0 0 0 0 0 0 1 0⎥ ⎢ ⎥ ⎣0 0 0 0 0 0 0 0 1⎦ 000000100 produces the function vector

4.2

Spectral Invariant Operations and Ternary Bent Functions

91

F2 = PF = [0, 0, 0, 1, 2, 0, 2, 1, 0]T

.

of another ternary bent function . f 2 = x1 x2 ⊕ x1 . It follows that the considered permutation matrix .P performs a permutation that for this particular function corresponds to the addition of the variable .x1 . Thus, F 2 = F ⊕ x1

.

= [0, 0, 0, 0, 1, 2, 0, 2, 1]T ⊕ [0, 0, 0, 1, 1, 1, 2, 2, 2]T = [0, 0, 0, 1, 2, 0, 2, 1, 0]T . It can be observed that the matrix has a block structure, since it can be written as ⎡ .P ⎤ 010 .P = diag(R, R, R), where .R = ⎣ 0 0 1 ⎦. It can be observed that the matrix .R converts 100 function vectors .F1 , .F4 , .F7 , .F10 , .F13 , .F16 in Table 4.1 into .F3 , .F6 , .F9 , .F12 , .F15 , .F18 . The relationships between ternary bent functions in terms of permutation matrices will be used later in Chap. 8 for the construction of ternary bent functions. Further, we also present there the correspondence between spectral invariant operations and certain permutation matrices. When discussing construction of bent functions, it should be noticed that repeated application of some spectral invariant operations might result in bent functions which can be produced by other spectral invariant operations. The same holds for application of permutation matrices to function vectors of ternary bent functions, since some permutation matrices correspond to spectral invariant operations. In this case, different permutation matrices applied to different initial functions can produce identical bent functions. Further, in function vectors of ternary bent functions there might be blocks of identical values. Permutation matrices derived from spectral invariant operations have a block structure which corresponds to sequences of identical values or identical subsequences in ternary variables. Therefore, when such permutation matrices are applied to a sequence of identical values, the sequence remains unchanged. In the same way, permutation of identical subsequences is invariant. Due to that, a given permutation matrix when applied to certain bent function might produce the same function, whereas it produces different functions from other bent functions. In another wording, a spectral operation can be expressed in different ways in terms of other spectral invariant operations. A permutation matrix can be expressed in different ways as a product of other permutation matrices. This is an explanation why by using spectral invariant operations or permutation matrices, the same functions can be derived in different manners.

92

4.3

4 Gibbs Characterization of Ternary Bent Functions

Gibbs Characterization of Ternary Bent Functions

In Chap. 3, specified are relationships between properties of binary bent functions and their dyadic Gibbs derivatives. The generalizations of these properties from binary functions to ternary functions are not straightforward as it can be seen from Example 4.5 below. The reason is that among the Vilenkin–Chrestenson functions, the kernels of the Vilenkin– Chrestenson transform, there are pairs of complex-conjugate functions. Therefore, the absolute values of spectral coefficients of a function with flat spectrum corresponding to complexconjugate basis functions are equal valued. In this way, a piece of information is suppressed, since the difference among coefficients taking complex-conjugate values is not taken into account. In the functional domain, the Vilenkin–Chrestenson functions and their complexconjugate counterpart functions correspond to the variables and squares of variables, and sums of variables and sums of squares of variables, respectively. Since the bentness is defined by referring to the absolute values of Vilenkin–Chrestenson coefficients, a distinction between the coefficients corresponding to variables and their squares cannot be made. The following example explains the correspondence between the Vilenkin–Chrestenson coefficients, variables, and squares of variables. Example 4.4 For .n = 1, the function expression is defined in terms of .[1, x, x 2 ] with computations in .G F(3), i.e., modulo .3. The Vilenkin–Chrestenson transform is defined in terms of the Vilenkin–Chresentenson function represented by columns of the matrix .V(1) defined in (1.4) as ⎤ 1 1 1 .V(1) = ⎣ 1 e1 e2 ⎦ . 1 e2 e1 ⎡

[ ]T By definition of the Vilenkin–Chrestenson transform, these columns . 1 e1 e2 and [ ]T 2 . 1 e2 e1 corresponding to .x and .x respectively are mutually complex-conjugate. In the binary case, there are no squares of variables, therefore, a direct generalization of Gibbs characterization to ternary functions is possible just for ternary bent functions whose functional expressions do not contain squares of variables. In what follows, the elements of the vector representing the Gibbs derivative of a function will be simply called the Gibbs coefficients of the function. Statement 4.2 A ternary function . f of .n-variables such that its Galois field (GF) expression does not contain the square of a variable .xi2 , .i = 1, 2, . . . , n is bent if the absolute values of elements of the vector .D f representing its Gibbs coefficients, i.e., elements of its Gibbs derivative defined with respect to the Vilenkin–Chrestenson transform, short VC-

4.3

Gibbs Characterization of Ternary Bent Functions

93

Gibbs derivative . D f computed in the .(0, 1, 2) → (1, e1 , e2 ) encoding, are elements of the set .G = {0, 1, . . . , 3n − 1}. In other words, a function . f without squares of variables in its GF-expression is bent if its VC-Gibbs derivative by the absolute values is equal to the eigenvalues of the derivative, permutations allowed. In these cases, we say that the ternary bent function has a Gibbs characterization corresponding to the Gibbs characterization of binary functions. The following example illustrates this statement. Example 4.5 Consider the ternary bent functions. f p (x1 , x2 ) = x1 x2 and. f s (x1 , x2 ) = x12 ⊕ x22 . Their function vectors are F p = [0, 0, 0, 0, 1, 2, 0, 2, 1]T ,

.

Fs = [0, 1, 1, 1, 2, 2, 1, 2, 2]T . In complex encoding, these function vectors are F p = [1, 1, 1, 1, e1 , e2 , 1, e2 , e1 ]T ,

.

Fs = [1, e1 , e1 , e1 , e2 , e2 , e1 , e2 , e2 ]T . The Vilenkin–Chrestenson spectra, respectively, are S f p = 3[1, 1, 1, 1, e2 , e1 , 1, e1 , e2 ]T ,

.

S fs = −3[1, e1 , e1 , e1 , e2 , e2 , e1 , e2 , e2 ]T , and the absolute values of all spectral coefficients are .3. Note that for . f p , the spectrum equals the complex-conjugate of its complex encoding scaled by .3. In the case of . f s , the spectrum equals the complex encoding scaled by .−3. Therefore, referring to the eigenvalue problem discussed in Chap. 1, the permutation matrix .P is the identity matrix. It is similar for the binary function . f (x1 , x2 ) = x1 x2 , whose Walsh spectrum is the function vector in −1 . .(0, 1) → (1, −1) encoding multiplied by .2 The integer parts of the coefficients of the Gibbs derivatives of these functions as defined in (2.7) are T F[1] p = [0, 3, 6, 1, −2 + 3i, −3 − 6i, 2, −2 − 4i, −4 + 7i] ,

.

Fs[1] = [6 − 3i, −1 + 5i, −1 + 6i, −3 + 2i, 2 − 3i, 1 − 3i, −2 + 4i, −1 − 3i, −2 − 3i]T ,

94

4 Gibbs Characterization of Ternary Bent Functions

and the absolute values of elements of the derivatives rounded to integers are T |D[1] f p | = [0, 3, 6, 1, 4, 7, 2, 5, 8] ,

.

T |D[1] f s | = [7, 5, 6, 3, 4, 4, 5, 4, 4] .

The first function . f p does not contain squares of variables, which makes that it satisfies the requirement of the above statement, and .|D f p | has all eigenvalues of the Gibbs derivative. Thus, . f p has a Gibbs characterization, while . f s does not have a Gibbs characterization in terms of the Gibbs derivative defined with respect to the Vilenkin–Chrestenson transform in the same sense as determined in the case of binary bent functions. The values of the Gibbs coefficients for . f s and the number of appearances of identical values can however be used as another way for characterization of ternary bent functions. This would be analog to the characterization of ternary bent functions based on the distribution of function values. In the following sections, we present a more detailed discussion of relationships between bent functions and their Gibbs derivatives for particular number of variables.

4.3.1

Ternary Bent Functions for .n = 1 and Gibbs Derivatives

For .n = 1, there are .18 bent functions out of the total of .27 single variable ternary functions. Absolute values of their Vilenkin–Cherestenson spectra computed after encoding √ .(0, 1, 2) → (1, e1 , e2 ) are all equal . 3 = 1.73 meaning that spectra are flat as it should be in bent functions. Table 4.3 shows function vectors of these functions, their GF-expressions, and RMF-expressions. Table 4.4 shows their VC-Gibbs derivatives, GF-Gibbs derivatives, and RMF-Gibbs derivatives. Table 4.5 shows the sum of function values .σ f , the sum of coefficients in VC-Gibbs derivatives .σ DV C , the sum of coefficients in GF-Gibbs derivatives .σG F , and the sum of coefficients in RMF-Gibbs derivatives .σ R M F . It could be observed that the sum of function values of ternary bent functions for .n = 1 computed modulo .3 is either .2 or .0. The sum of the absolute values of coefficients of the VC-Gibbs derivative in all cases equals .0. The sum of values of the GF-Gibbs derivatives as well as the sum of values of the RMF-Gibbs derivatives are either .1 or .2. Values of these sums are taken in the opposite way to the sum of function values. When .σ f = 1, then .σG F = σ R M F = 2, and vice versa.

4.3

Gibbs Characterization of Ternary Bent Functions

95

Table 4.3 Function vectors, GF-expressions, and RMF-expressions for ternary bent functions in = 1 variables

.n

Function vector

GF-expression

RMF-expression .x

+ x ∗2

1.

.F1

= [011]

2 .x

2.

.F2

= [101]

.1

⊕ x ⊕ x2

.2

+ 2x + x + x ∗2

2 .1 ⊕ 2x ⊕ x 2 .2x

.2

+ x ∗2

.1

+ x + 2x ∗2

.1

+ 2x ∗2

.2

+ 2x + 2x ∗2

.x

+ 2x ∗2

3.

.F3

= [110]

4.

.F4

= [022]

5.

.F5

= [202]

6.

.F6

= [220]

2 .2 ⊕ 2x ⊕ 2x 2 .2 ⊕ x ⊕ 2x

7.

.F7

= [100]

2 .1 ⊕ 2x

8.

.F8

= [010]

.2x

= [001]

⊕ 2x 2

.2x

+ 2x ∗2

∗2

9.

.F9

10.

.F10

= [200]

2 . x ⊕ 2x 2 .2 ⊕ x

11.

.F11

= [020]

.x

2 .2x ⊕ x 2 .2 ⊕ 2x

∗2 .x .1

+ 2x + 2x ∗2

.2

+ x + 2x ∗2

.2

+ 2x ∗2

.2

+ x + x ∗2

12.

.F12

= [002]

13.

.F13

= [211]

⊕ x2

14.

.F14

= [121]

15.

.F15

= [112]

2 .1 ⊕ 2x ⊕ 2x 2 .1 ⊕ x + 2x

.2x .1

+ x + x ∗2

.2x

+ x ∗2

16.

.F16

= [122]

2 .1 ⊕ x

17.

.F17

= [212]

.2

⊕ x ⊕ x2

.1

+ 2x + x ∗2

= [221]

2 .2 ⊕ 2x ⊕ x

.1

+ x ∗2

18.

4.3.2

.F18

Ternary Bent Functions for .n = 2 Characterized by the VC-Gibbs Derivative

In this section, we discuss ternary bent functions in two variables which can be characterized by referring to the eigenvalues of the Gibbs derivative defined with respect to the Vilenkin– Chrestenson transform. There are .54 functions out of .486 ternary bent functions in two variables that do not have powers of variables in their GF-expressions. These are functions derived from the basic ternary bent function. f (x1 , x2 ) = x1 x2 by adding the linear combination of variables as well as constants .1 and .2. For these functions, the VC-Gibbs derivative is a vector with elements the absolute values of which are all eigenvalues of the derivative, i.e., the elements of the set . G = {0, 1, 2, 3, 4, 5, 6, 7, 8}. There are no other ternary functions out of the total of .19683 functions in two variables which express this property. Therefore, VC-Gibbs derivative can differentiate bent functions whose GF-expressions do not contain the powers of variables. The difference between functions is in the permutation of the values of the Gibbs derivative.

96

4 Gibbs Characterization of Ternary Bent Functions

Table 4.4 Function vectors, VC-Gibbs derivatives, GF-Gibbs derivatives, and RMF-Gibbs derivatives for ternary function in .n = 1 variables Function vector

VC-Gibbs derivative GF-Gibbs derivative RMF-Gibbs derivative

1.

.[011]

.[4.5, −1.5, −3]

.[0, 2, 2]

.[0, 1, 0]

2.

.[101]

.[−3.0, 4.5, −1.5]

.[0, 0, 1]

.[0, 2, 2]

3.

.[110]

.[−1.5, −3.0, 4.5]

.[0, 1, 0]

.[0, 0, 1]

4.

.[022]

.[4.5, −3.0, −1.5]

.[0, 1, 1]

.[0, 2, 0]

5.

.[202]

.[−1.5, 4.5, −3.0]

.[0, 0, 2]

.[0, 1, 2]

6.

.[220]

.[−3.0, −1.5, 4.5]

.[0, 2, 0]

.[0, 0, 2]

7.

.[100]

.[−4.5, 1.5, 3.0]

.[0, 1, 1]

.[0, 2, 0]

8.

.[010]

.[3.0, −4.5, 1.5]

.[0, 0, 2]

.[0, 1, 1]

9.

.[001]

.[1.5, 3.0, −4.5]

.[0, 2, 0]

.[0, 0, 2]

10.

.[200]

.[−4.5, 3.0, 1.5]

.[0, 2, 2]

.[0, 1, 0]

11.

.[020]

.[1.5, −4.5, 3.0]

.[0, 0, 1]

.[0, 2, 2]

12.

.[002]

.[3.0, 1.5, −4.5]

.[0, 1, 0]

.[0, 0, 1]

13.

.[211]

.[0.0, 1.5, −1.5]

.[0, 1, 1]

.[0, 2, 0]

14.

.[121]

.[−1.5, 0.0, 1.5]

.[0, 0, 2]

.[0, 1, 1]

15.

.[112]

.[1.5, −1.5, 0.0]

.[0, 2, 0]

.[0, 0, 2]

16.

.[122]

.[0.0, −1.5, 1.5]

.[0, 2, 2]

.[0, 1, 0]

17.

.[212]

.[1.5, 0.0, −1.5]

.[0, 0, 1]

.[0, 2, 2]

18.

.[221]

.[−1.5, 1.5, 0.0]

.[0, 1, 0]

.[0, 0, 1]

Table 4.6 and Table 4.7 show these .54 ternary bent functions in two variables that can be characterized by the VC-Gibbs derivative. There are some interesting observations that can be even called curiosities, about these.54 ternary bent functions in two variables which are characterized by their VC-Gibbs derivatives. Lemma 4.1 If . f (x1 , x2 ) is bent and is characterized by the absolute values of its VC-Gibbs derivative, then . f (x1 , x2 ) ⊕ 1 and . f (x1 , x2 ) ⊕ 2 are also bent, and have the same Gibbs characterization. Proof. Adding a constant to a function is a spectral invariant operation, and therefore the produced function is bent. The sum of elements in the rows of the Gibbs matrix defining the Gibbs derivative is .0. Therefore, the Gibbs derivative of a constant is a zero vector. Since the Gibbs derivative is a linear operator, the derivative of a function plus a constant is equal to the derivative of the function plus the derivative of the constant, which is a zero vector.

4.3

Gibbs Characterization of Ternary Bent Functions

97

Table 4.5 Function vectors, sums of VC-Gibbs derivatives, GF-Gibbs derivatives, and RMF-Gibbs derivatives for ternary function in .n = 1 variables Function

.σ f

.σ V C

.σG F



1.

.[011]

.2

.0

.1

.1

2.

.[101]

.2

.0

.1

.1

3.

.[110]

.2

.0

.1

.1

4.

.[022]

.1

.0

.2

.2

5.

.[202]

.1

.0

.2

.2

6.

.[220]

.1

.0

.2

.2

7.

.[100]

.1

.0

.2

.2

8.

.[010]

.1

.0

.2

.2

9.

.[001]

.1

.0

.2

.2

10.

.[200]

.2

.0

.1

.1

11.

.[020]

.2

.0

.1

.1

12.

.[002]

.2

.0

.1

.1

13.

.[211]

.1

.0

.2

.2

14.

.[121]

.1

.0

.2

.2

15.

.[112]

.1

.0

.2

.2

16.

.[122]

.2

.0

.1

.1

17.

.[212]

.2

.0

.1

.1

18.

.[221]

.2

.0

.1

.1

RM F

Therefore, . f and . f ⊕ c, where .c ∈ {1, 2} have the same characterization in terms of the Gibbs derivative. Let .Fe denote the function vector of . f (x1 , x2 ) in the .(0, 1, 2) → (1, e1 , e2 ) encoding. Let the value vector of . f (x1 , x2 ) ⊕ 1 in the same encoding be called .F+1 . It is obtained from ( f (x1 ,x2 )⊕1) f (x ,x ) f (x ,x ) .e = e1 1 2 · e11 = e11 · e1 1 2 , leading to the function vector .F+1 = e1 I · Fe . 1 Then, D(2)F+1 = D(2)(e1 I · Fe ) = e1 D(2)(I · Fe ) = e1 D(2)(Fe ).

.

Since .|e1 D(2)(Fe )| = |e1 | · |D(2)(Fe )| and .|e1 | = 1, the first assertion follows. Recall that .(e1 )2 = e2 and .|e2 | = 1. Therefore, the same proof scheme holds for the second assertion. Lemma 4.1 represents an equivalence relation, which partitions the set of.54 bent functions mentioned above listed in Table 4.6 into three blocks of .18 functions each. The basic block comprising functions .1 through .18 is given in Table 4.6. The other blocks are obtained by adding .1 or .2 (modulo .3) to the functions of the basic block. These are shown in the block

98

4 Gibbs Characterization of Ternary Bent Functions

Table 4.6 Ternary bent functions for .n = 2 (1-36) characterized by the VC-Gibbs derivative .f

.F

.D f

1.

. f = x1 x2

.F = [000012021]T

.DV C = [036147258]T

2.

. f = 2x 1 x 2

.F = [000021012]T

.DV C = [063285174]T

3.

. f = x1 x2 ⊕ x1

.F = [000120210]T

.DV C = [360471582]T

. f = x 1 x 2 ⊕ 2x 1

.F = [000201102]T

.DV C = [603714825]T

. f = x1 x2 ⊕ x2

.F = [012021000]T

.DV C = [147258036]T

6.

. f = x 1 x 2 ⊕ 2x 2

.F = [021000012]T

.DV C = [258036147]T

7.

. f = x1 x2 ⊕ x1 ⊕ x2

.F = [012102222]T

.DV C = [471582360]T

8.

. f = x 1 x 2 ⊕ 2x 1 ⊕ x 2

.F = [012210111]T

.DV C = [714825603]T

9.

. f = x 1 x 2 ⊕ x 1 ⊕ 2x 2

.F = [021111201]T

.DV C = [582360471]T

10.

. f = x 1 x 2 ⊕ 2x 1 ⊕ 2x 2

.F = [021222120]T

.DV C = [825603714]T

. f = 2x 1 x 2 ⊕ x 1

.F = [000102201]T

.DV C = [306528417]T

. f = 2x 1 x 2 ⊕ 2x 1

.F = [000210120]T

.DV C = [630852741]T

13.

. f = 2x 1 x 2 ⊕ x 2

.F = [012000021]T

.DV C = [174063285]T

14.

. f = 2x 1 x 2 ⊕ 2x 2

.F = [021012000]T

.DV C = [285174063]T

15.

. f = 2x 1 x 2 ⊕ x 1 ⊕ x 2

.F = [012111210]T

.DV C = [417306528]T

16.

. f = 2x 1 x 2 ⊕ 2x 1 ⊕ x 2

.F = [012222102]T

.DV C = [741630852]T

17.

. f = 2x 1 x 2 ⊕ x 1 ⊕ 2x 2

.F = [021120222]T

.DV C = [528417306]T

. f = 2x 1 x 2 ⊕ 2x 1 ⊕ 2x 2

.F = [021201111]T

.DV C = [852741630]T

. f = x1 x2 ⊕ 1

.F = [111120102]T

.DV C = [036147258]T

20.

. f = 2x 1 x 2 ⊕ 1

.F = [111102120]T

.DV C = [063285174]T

21.

. f = x1 x2 ⊕ x1 ⊕ 1

.F = [111201021]T

.DV C = [360471582]T

22.

. f = x 1 x 2 ⊕ 2x 1 ⊕ 1

.F = [111012210]T

.DV C = [603714825]T

23.

. f = x1 x2 ⊕ x2 ⊕ 1

.F = [120102111]T

.DV C = [147258036]T

24.

. f = x 1 x 2 ⊕ 2x 2 ⊕ 1

.F = [102111120]T

.DV C = [258036147]T

. f = x1 x2 ⊕ x1 ⊕ x2 ⊕ 1

.F = [120210000]T

.DV C = [471582360]T

. f = x 1 x 2 ⊕ 2x 1 ⊕ x 2 ⊕ 1

.F = [120021222]T

.DV C = [714825603]T

27.

. f = x 1 x 2 ⊕ x 1 ⊕ 2x 2 ⊕ 1

.F = [102222012]T

.DV C = [582360471]T

28.

. f = x 1 x 2 ⊕ 2x 1 ⊕ 2x 2 ⊕ 1

.F = [102000201]T

.DV C = [825603714]T

29.

. f = 2x 1 x 2 ⊕ x 1 ⊕ 1

.F = [111210012]T

.DV C = [306528417]T

30.

. f = 2x 1 x 2 ⊕ 2x 1 ⊕ 1

.F = [111021201]T

.DV C = [630852741]T

31.

. f = 2x 1 x 2 ⊕ x 2 ⊕ 1

.F = [120111102]T

.DV C = [174063285]T

. f = 2x 1 x 2 ⊕ 2x 2 ⊕ 1

.F = [102120111]T

.DV C = [285174063]T

. f = 2x 1 x 2 ⊕ x 1 ⊕ x 2 ⊕ 1

.F = [120222021]T

.DV C = [417306528]T

34.

. f = 2x 1 x 2 ⊕ 2x 1 ⊕ x 2 ⊕ 1

.F = [120000210]T

.DV C = [741630852]T

35.

. f = 2x 1 x 2 ⊕ x 1 ⊕ 2x 2 ⊕ 1

.F = [102201000]T

.DV C = [528417306]T

36.

. f = 2x 1 x 2 ⊕ 2x 1 ⊕ 2x 2 ⊕ 1

.F = [102012222]T

.DV C = [852741630]T

4. 5.

11. 12.

18. 19.

25. 26.

32. 33.

in the bottom part of Table 4.6 and the block in Table 4.7. As shown in Lemma 4.1, the functions of these two blocks share the Gibbs characterization with that of the basic block.

4.3

Gibbs Characterization of Ternary Bent Functions

99

Table 4.7 Ternary bent functions for .n = 2 (37-54) characterized by the VC-Gibbs derivative .f

37.

.f

38.

.f

39.

.f

.F

.D f

= x1 x2 ⊕ 2

.F

= [222201210]T

.D V C

= [036147258]T

= 2x1 x2 ⊕ 2

.F = [222210201]T .F = [222012102]T

.D V C

= [063285174]T

.D V C

= [360471582]T

40.

= x1 x2 ⊕ x1 ⊕ 2 . f = x 1 x 2 ⊕ 2x 1 ⊕ 2

.F

= [222120021]T

.D V C

= [603714825]T

41.

.f

.F

= [201210222]T

.D V C

= [147258036]T

42.

= x1 x2 ⊕ x2 ⊕ 2 . f = x 1 x 2 ⊕ 2x 2 ⊕ 2

.D V C

= [258036147]T

43.

.f

.F = [210222201]T .F = [201021111]T

.D V C

= [471582360]T

.F = [201102000]T .F = [210000120]T

.D V C

= [714825603]T

.D V C

= [582360471]T

= x1 x2 ⊕ x1 ⊕ x2 ⊕ 2

44.

.f

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ 2

45.

.f

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2

46.

.f

= [210111012]T

.D V C

= [825603714]T

.f

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ 2 = 2x1 x2 ⊕ x1 ⊕ 2

.F

47.

.F

= [222021120]T

.D V C

= [306528417]T

.F = [222102012]T .F = [201222210]T

.D V C

= [630852741]T

.D V C

= [174063285]T

.D V C

= [285174063]T

.D V C

= [417306528]T

48.

.f

= 2x1 x2 ⊕ 2x1 ⊕ 2

49.

.f

= 2x1 x2 ⊕ x2 ⊕ 2

50.

.f

= 2x1 x2 ⊕ 2x2 ⊕ 2

51.

.f

= 2x1 x2 ⊕ x1 ⊕ x2 ⊕ 2

.F = [210201222]T .F = [201000102]T

52.

.f

= 2x1 x2 ⊕ 2x1 ⊕ x2 ⊕ 2

.F

= [201111021]T

.D V C

= [741630852]T

53.

.f

= 2x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2

.F

= [210012111]T

.D V C

= [528417306]T

= 2x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ 2

.F = [210120000]T

.D V C

= [852741630]T

54.

.f

This represents an equivalence relation, which partitions the set of .54 bent functions mentioned above into three blocks of .18 functions each. Corollary 4.1 If . f is a ternary bent function with the Gibbs characterization, then . f = (2 − f )mod 3, which is also bent, has the same Gibbs characterization as .2 f . Proof. . f = 2 ⊕ 2 f mod 3. Palindrome functions satisfy the equality . f (x1 , x2 ) = f (x 1 , x 2 ). In the basic block of .18 ternary bent functions, there are two palindromes, functions .10 and .15, such that their function vectors are related by a factor .2 (mod .3) and their Gibbs characterizations exhibit a .0 at the middle position and are the mirror of each other. No other function of the block has this property. It is simple to see that if . f is a palindrome, then also . f ⊕ 1 and . f ⊕ 2 are palindromes and share the same Gibbs characterization as the original ones.

100

4.4

4 Gibbs Characterization of Ternary Bent Functions

Gibbs Permutation Matrices for Ternary Functions

The sequences of absolute values of the VC-Gibbs derivative for functions in the basic block in Table 4.6 determine .18 different Gibbs permutation matrices. Example 4.6 For the function . f (x1 , x2 ) = x1 x2 , the VC-Gibbs derivative maps the sequence .(0, 1, 2, 3, 4, 5, 6, 7, 8) into the sequence .(0, 3, 6, 1, 4, 7, 2, 5, 8). This mapping can be expressed by the Gibbs permutation matrix ⎡ ⎤ 100000000 ⎢0 0 0 1 0 0 0 0 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢0 0 0 0 0 0 1 0 0⎥ ⎢ ⎥ ⎢0 1 0 0 0 0 0 0 0⎥ ⎢ ⎥ .P = ⎢ 0 0 0 0 1 0 0 0 0 ⎥ , ⎢ ⎥ ⎢0 0 0 0 0 0 0 1 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢0 0 1 0 0 0 0 0 0⎥ ⎢ ⎥ ⎣0 0 0 0 0 1 0 0 0⎦ 000000001 since P · [0, 1, 2, 3, 4, 5, 6, 7, 8]T = [0, 3, 6, 1, 4, 7, 2, 5, 8]T .

.

We use the following notation to formally describe these .18 Gibbs permutation matrices. Define a .(3 × 3) matrix ⎤ g0 g1 g2 .G = ⎣ g3 g4 g5 ⎦ . g6 g7 g8 ⎡

Now, define the matrices .Gi as matrices where .gi = 1 and all other .8 elements are .0. Then, ⎡

⎡ ⎡ ⎤ ⎤ ⎤ 100 010 001 G 0 = ⎣ 0 0 0 ⎦ , G1 = ⎣ 0 0 0 ⎦ , G2 = ⎣ 0 0 0 ⎦ 000 000 000 ⎡

⎡ ⎡ ⎤ ⎤ ⎤ 000 000 000 . G3 = ⎣ 1 0 0 ⎦ , G4 = ⎣ 0 1 0 ⎦ , G5 = ⎣ 0 0 1 ⎦ 000 000 000 ⎡

⎡ ⎡ ⎤ ⎤ ⎤ 000 000 000 G6 = ⎣ 0 0 0 ⎦ , G7 = ⎣ 0 0 0 ⎦ , G8 = ⎣ 0 0 0 ⎦ . 100 010 001

4.4

Gibbs Permutation Matrices for Ternary Functions

Table 4.8 Basic Gibbs permutation matrices for .n = 2 ⎤ ⎤ ⎡ ⎡ G0 G3 G6 G0 G6 G3 ⎥ ⎥ ⎢ ⎢ .P1 = ⎣ G1 G4 G7 ⎦ .P2 = ⎣ G2 G8 G5 ⎦ G G G G G G ⎡ 2 5 8⎤ ⎡ 1 7 4⎤ G6 G0 G3 G1 G4 G7 ⎥ ⎥ ⎢ ⎢ .P4 = ⎣ G7 G1 G4 ⎦ .P5 = ⎣ G2 G5 G8 ⎦ G G G G G G ⎡ 8 2 5⎤ ⎡ 0 3 6⎤ G4 G7 G1 G7 G1 G4 ⎥ ⎥ ⎢ ⎢ .P7 = ⎣ G5 G8 G2 ⎦ .P8 = ⎣ G8 G2 G5 ⎦ G G G G G G ⎡ 3 6 0 ⎤ ⎡ 6 0 3 ⎤ G8 G2 G5 G3 G0 G6 ⎢ ⎢ ⎥ ⎥ .P10 = ⎣ G6 G0 G3 ⎦ .P11 = ⎣ G5 G2 G8 ⎦ G G G G G G ⎡ 7 1 4⎤ ⎡ 4 1 7⎤ G1 G7 G4 G2 G8 G5 ⎥ ⎥ ⎢ ⎢ .P13 = ⎣ G0 G6 G3 ⎦ .P14 = ⎣ G1 G7 G4 ⎦ G G G G G G ⎡ 2 8 5⎤ ⎡ 0 6 3⎤ G7 G4 G1 G5 G2 G8 ⎢ ⎢ ⎥ ⎥ .P16 = ⎣ G6 G3 G0 ⎦ .P17 = ⎣ G4 G1 G7 ⎦ G8 G5 G2 G3 G0 G6

101

⎤ G3 G6 G0 ⎥ ⎢ .P3 = ⎣ G4 G7 G1 ⎦ G G G ⎡ 5 8 8⎤ G2 G5 G8 ⎥ ⎢ .P6 = ⎣ G0 G3 G6 ⎦ G G G ⎡ 1 4 7⎤ G5 G8 G2 ⎥ ⎢ .P9 = ⎣ G3 G6 G0 ⎦ G G G ⎡ 4 7 1 ⎤ G6 G3 G0 ⎢ ⎥ .P12 = ⎣ G8 G5 G2 ⎦ G G G ⎡ 7 4 1⎤ G4 G1 G7 ⎥ ⎢ .P15 = ⎣ G3 G0 G6 ⎦ G G G ⎡ 5 2 8⎤ G8 G5 G2 ⎢ ⎥ .P18 = ⎣ G7 G4 G1 ⎦ G6 G3 G0 ⎡

With this notation, the matrix .P in Example 4.6 can be written in a compact form as ⎡

⎤ G0 G3 G6 .P = ⎣ G1 G4 G7 ⎦ . G2 G5 G8 It can be observed that the indices of .Gi are elements of the VC-Gibbs derivative of . f (x 1 , x 2 ) = x 1 x 2 . Thus, they are .0, 3, 6, 1, 4, 7, 2, 5, 8. The other .17 permutation matrices from Table 4.6 can be written in terms of the matrices .Gi in the same way. Table 4.8 shows all .18 Gibbs permutation matrices derived from the first .18 functions in Table 4.6. These matrices can be viewed as the basic Gibbs permutation matrices, and combining them into products or Kronecker product for larger .n provides many more Gibbs permutation matrices. These Gibbs permutation matrices are derived from the basic bent function . f (x1 , x2 ) = x1 x2 and functions derived from it by adding all possible linear combinations of variables and constants .1 and .2. It is important to observe that when applied to any ternary bent functions, they produce another ternary bent function with the same distribution of function values. Depending on the ternary bent function to which they are applied, the resulting function

102

4 Gibbs Characterization of Ternary Bent Functions

Table 4.9 Ternary bent functions constructed by the application of the Gibbs permutation matrices for .n = 2 to . f (x1 , x2 ) = x1 x2 Matrix

Function

.P1

.x1 x2

.P2

.x1 x2

.P3

.2x 1

.P4

.x1

⊕ x1 x2

.P5

.x2

⊕ x1 x2

.P6

.2x 2

.P7

.2

⊕ x2 ⊕ 2x1 ⊕ x1 x2

.P8

.1

⊕ x2 ⊕ x1 ⊕ x1 x2

.P9

.1

⊕ 2x1 ⊕ 2x2 ⊕ x1 x2

.P10

.2

⊕ 2x2 ⊕ x1 ⊕ x1 x2

⊕ x1 x2

⊕ x1 x2

may be the same as the initial function or a function that can be obtained from it by the application of some other Gibbs permutation matrix. Example 4.7 Table 4.9 shows bent functions constructed by the application of the first .10 Gibbs permutation matrices .P1 , . . . , P10 to the first symmetric bent function . f (x1 , x2 ) = x1 x2 . It can be observed that.9 other bent functions are constructed. Matrices.P1 and.P2 result in the initial function, while .P11 , .P12 , .P13 , .P14 , .P15 , .P16 , .P17 , and .P18 result in functions already constructed by matrices .P3 , .P4 , .P6 , .P5 , .P9 , .P10 , .P7 , and .P8 , respectively (Table 4.10). It can be observed that matrices .P1 , .P2 , .P8 , .P9 , .P15 , and .P18 are self-inverse. Further, the product of matrices .P11 · P3 when applied to .x1 x2 produces the function .2 ⊕ 2x1 ⊕ x2 ⊕ x1 x2 that is constructed by the matrix .P7 , although .P11 · P3 / = P7 . The function . f = x2 ⊕ x22 ⊕ x12 is invariant to the application of .P7 , while the application of .P11 · P3 to this function leads to the function . f 1 = x22 ⊕ 2x1 ⊕ x12 . The application of the matrix .P3 · P11 to .x1 x2 produces the function .1 ⊕ 2x2 ⊕ 2x1 ⊕ x1 x2 which is already produced by .P9 , although .P3 · P11 / = P9 . We can conclude that products of some other combinations of matrices might produce functions constructed by different matrices. As explained by Lemma 4.1, the functions in the second block of Table 4.6 and in Table 4.7 have the same VC-Gibbs derivatives as functions in the first block in Table 4.6 since these derivatives are invariant to adding the constant as these functions are derived. This follows from the property that the VC-Gibbs derivative is a linear operator and the sum of elements in the rows of the matrix .DV C is .0. Thus, the VC-Gibbs derivative of a constant function is

4.4

Gibbs Permutation Matrices for Ternary Functions

103

Table 4.10 Ternary bent functions constructed by the application of the Gibbs permutation matrices for .n = 2 to . f (x1 , x2 ) = x12 ⊕ x22 Matrix

Function

.P1

.x

.P2

2 2 1 ⊕ x2 2 2 .x ⊕ x 1 2

.P3

.1

⊕ x2 ⊕ x22 ⊕ x12

.P4

.1

⊕ 2x2 ⊕ x22 ⊕ x12

.P5

.1

⊕ 2x1 ⊕ x22 ⊕ x12

.P6

.1

⊕ x1 ⊕ x22 ⊕ x12

.P7

.2

⊕ x2 ⊕ 2x1 ⊕ x22 ⊕ x22

.P8

.2

⊕ 2x2 ⊕ 2x1 ⊕ x22 ⊕ x12

.P9

.2

⊕ x21 ⊕ x1 ⊕ x22 ⊕ x12

.P10

.2

⊕ 2x2 ⊕ x1 ⊕ x22 ⊕ x12

zero. Therefore, these functions and their VC-Gibbs derivatives do not lead to new Gibbs permutation matrices. As already explained for the binary case, spectral invariant operations perform particular permutations of spectral coefficients. These permutations in the spectral domain can be interpreted as the corresponding permutations in the original domain, i.e., in terms of permutations of functional values that are involved in computing the spectral coefficients to be permuted. It follows that these permutations correspond to spectral invariant operations in the original domain, and, therefore, can be expressed in terms of operations over ternary variables and function values. Table 4.11 shows the spectral invariant operations performed by the Gibbs permutation matrices for .n = 2. The product of two basic Gibbs permutation matrices is another permutation matrix; however, it is not necessarily another Gibbs permutation matrix, since it corresponds to the sequential performing of spectral invariant operations described by the factor matrices in the product of matrices. Therefore, this combination of spectral invariant operations can be a different spectral invariant operation compared to these corresponding to the Gibbs permutation matrices. Example 4.8 Consider the product of two randomly selected basic Gibbs permutation matrices

104

4 Gibbs Characterization of Ternary Bent Functions

Table 4.11 Spectral invariant operations performed by the Gibbs permutation matrices for .n = 2 after permutation of variables Matrix

Invariant operation

.P1

.−−−

.P2

.x1

→ 2x1 , x2 → 2x2

.P3

.x2

→ x2 ⊕ 2

.P4

.x2

.P5

→ x2 ⊕ 1 .x1 → x1 ⊕ 1

.P6

.x1

.P7

→ x1 ⊕ 2 . x 1 → x 1 ⊕ 1, . x 2 → x 2 ⊕ 2

.P8

.x1

.P9

→ x1 ⊕ 1, .x2 → x2 ⊕ 1 . x 1 → x 1 ⊕ 2, . x 2 → x 2 ⊕ 2

.P10

.x1

.P11

→ x1 ⊕ 2, .x2 → x2 ⊕ 1 . x 1 → 2x 1 , . x 2 → 2x 2 ⊕ 1

.P12

.x1

→ 2x1 , .x2 → 2x2 ⊕ 2

.P13

.x1

→ 2x1 ⊕ 1, .x2 → 2x2

.P14

.x1

→ 2x1 ⊕ 2, .x2 → 2x2

.P15

.x1

→ 2x1 ⊕ 1, .x2 → 2x2 ⊕ 1

.P16

.x1

→ 2x1 ⊕ 1, .x2 → 2x2 ⊕ 2

.P17

.x1

→ 2x1 ⊕ 2, .x2 → 2x2 ⊕ 1

.P18

.x1

→ 2x1 ⊕ 2, .x2 → 2x2 ⊕ 2

G = P4 · P7 ⎡ 000 ⎢0 0 0 ⎢ ⎢ ⎢0 0 0 ⎢ ⎢0 0 1 ⎢ =⎢ ⎢1 0 0 ⎢0 1 0 ⎢ ⎢ ⎢0 0 0 ⎢ ⎣0 0 0 000

.

0 0 0 0 0 0 0 1 0

0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 1 0 0

0 1 0 0 0 0 0 0 0

0 0 1 0 0 0 0 0 0

⎤ 1 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥. 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎦ 0

When this matrix is applied to the function vector .F = [2, 1, 0, 0, 1, 2, 1, 1, 1]T of the bent function . f = 2x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2, the function vector .F = [1, 1, 1, 0, 2, 1, 2, 0, 1]T of the function . f = 2x1 x2 ⊕ 2x1 ⊕ 1 is obtained. This function can be derived from the initial function by the spectral invariant operations .x1 → x1 ⊕ 1, .x2 → x2 ⊕ 2 corresponding to .P7 followed by the spectral invariant operation .x2 → x2 ⊕ 1 corresponding to .P4 .

4.4

Gibbs Permutation Matrices for Ternary Functions

105

Table 4.12 Matrices transpose and inverse to the Gibbs permutation matrices assigned to functions in Table 4.6 .P1 .P2 .P3 .P4 .P5 .P6 .P7 .P8 .P9 .P10 .P11 .P12 .P13 .P14 .P15 .P16 .P17 .P18

−1 1 −1 .P 2 −1 .P 3 −1 .P 4 −1 .P 5 −1 .P 6 −1 .P 7 −1 .P 8 −1 .P 9 −1 .P 10 −1 .P 11 −1 .P 12 −1 .P 13 −1 .P 14 −1 .P 15 −1 .P 16 −1 .P 17 −1 .P 18 .P

= P1T = P1 = P2T = P2 = P3T = P5 = P4T = P6 = P5T = P3 = P6T = P4 = P7T = P7 = P8T = P9 = P9T = P8 T =P = P10 10 T =P = P11 13 T =P = P12 14 T =P = P13 11 T =P = P14 12 T =P = P15 15 T =P = P16 17 T =P = P17 16 T =P = P18 18

Table 4.12 shows the .18 Gibbs permutation matrices derived from VC-Gibbs derivatives of functions in Table 4.6 and their transposed and inverse matrices. It can be observed that these matrices are either self-transpose and self-inverse or equal to some other matrices from this set of Gibbs matrices. Therefore, for .n = 2, taking transpose and inverse matrices does not extend the set of Gibbs permutation matrices derived from the VC-Gibbs derivatives of the function . f (x1 , x2 ) = x1 x2 and functions derived from it by adding all possible linear combinations of variables and constants .1 and .2. Different Gibbs permutation matrices applied to the same function might result in the identical functions, which also could be the initial function to which they are applied. This is a quite natural feature of permutation matrices when applied to ternary vectors. The function values in the function vector might be positioned in such a way that their permutation produces the identical function vector. The following examples illustrate such possibilities. Example 4.9 Tables 4.13 and 4.14 show functions constructed by the application of the .18 Gibbs permutation matrices to functions .x12 ⊕ 2x22 ⊕ 1 and .x12 ⊕ x22 ⊕ x2 , respectively.

106

4 Gibbs Characterization of Ternary Bent Functions

Table 4.13 Functions constructed by Gibbs permutation matrices applied to . f = x12 ⊕ 2x22 ⊕ 1 Matrix

Function

.P1

.1

⊕ x22 ⊕ 2x12

.P2

.1

⊕ x22 ⊕ 2x12

.P3

.2

⊕ x2 ⊕ x22 ⊕ 2x12

.P4

.2

⊕ 2x2 ⊕ x22 ⊕ 2x12

.P5

.x

.P6 .P7 .P8 .P9 .P10 .P11 .P12 .P13 .P14 .P15 .P16 .P17 .P18

4.5

2 2 2 ⊕ x 1 ⊕ 2x 1 2 2 . x ⊕ 2x 1 ⊕ 2x 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ x 1 ⊕ 2x 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ x 1 ⊕ 2x 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ 2x 1 ⊕ 2x 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ 2x 1 ⊕ 2x 2 1 2 2 .2 ⊕ x 2 ⊕ x ⊕ 2x = f 3 2 1 2 2 .2 ⊕ 2x 2 ⊕ x ⊕ 2x = f 4 2 1 2 2 . x ⊕ 2x 1 ⊕ 2x = f 6 2 1 2 2 . x ⊕ x 1 ⊕ 2x = f 5 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ 2x 1 ⊕ 2x = f 9 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ 2x 1 ⊕ 2x = f 10 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ x 1 ⊕ 2x = f 7 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ x 1 ⊕ 2x = f 8 2 1

Extensions to Any Number of Variables

For the extension of the proposed approach to the number of variables larger than two, we distinguish the situations for .n even and odd. There are two possibilities for .n even as enumerated below. 1. We can use the VC-Gibbs derivative for the given even.n and apply it to the basic function . f p (n) whose functional expression is the sum of disjoint pairs of variables, and functions derived from it by adding linear combinations of variables. In this way we get a library of Gibbs permutation matrices in the same manner as for .n = 2. 2. We can compute the Kronecker product of the Gibbs permutation matrices for small values of.n to determine a Gibbs permutation matrix for the required number of variables. For.n odd, just the second option is possible, since in this case a variable appears as a square in the functional expression for the basic bent function . f p (n), and the Gibbs coefficients may have identical values. Then, not all non-zero integers up to .3n appear as values of the VC-Gibbs derivative, and therefore it cannot be used to define a permutation matrix.

4.5

Extensions to Any Number of Variables

107

Table 4.14 Functions constructed by Gibbs permutation matrices applied to . f = x12 ⊕ x22 ⊕ 2x1 Matrix

Function

.P1

.2x

.P2 .P3 .P4 .P5 .P6 .P7 .P8 .P9 .P10 .P11 .P12 .P13 .P14 .P15 .P16 .P17 .P18

2 2 2 2 ⊕ x2 ⊕ x1 2 2 .x2 ⊕ x ⊕ x 2 1 2 2 .2 ⊕ x ⊕ x 2 1 2 2 .x2 ⊕ x ⊕ x 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ 2x 1 ⊕ x 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ x 1 ⊕ x 2 1 2 2 . x ⊕ 2x 1 ⊕ x 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ 2x 1 ⊕ x 2 1 2 2 .x ⊕ x1 ⊕ x 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ x 1 ⊕ x 2 1 2 2 .2x 2 ⊕ x ⊕ x = f 1 2 1 2 2 .2 ⊕ x ⊕ x = f 3 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ x 1 ⊕ x = f 10 2 1 2 2 .1 ⊕ x 2 ⊕ x ⊕ 2x 1 ⊕ x = f 8 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ x 1 ⊕ x = f 6 2 1 2 2 .x ⊕ x1 ⊕ x = f 9 2 1 2 2 .1 ⊕ 2x 2 ⊕ x ⊕ 2x 1 ⊕ x = f 5 2 1 2 2 . x ⊕ 2x 1 ⊕ x = f 7 2 1

The first option is a straightforward implementation of the VC-Gibbs derivative and requires dealing with large matrices, although the computations can be performed by using steps of Fast Fourier Transform (FFT)-like algorithms [8, 9]. Moreover, unlike the FFT, these steps can be performed in parallel, which reduces the computation time to the time required for the implementation of a single FFT step followed by the addition of computed values [8]. This makes the approach computationally feasible for large .n especially when implemented on GPU-based architectures [10]. Example 4.10 The VC-Gibbs derivative for .n = 4 of the basic bent function . f (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 transforms the vector .G(4) = diag(0, 1, . . . , 80) of its eigenvalues into the vector

108

4 Gibbs Characterization of Ternary Bent Functions

D f (4) = [0, 3, 6, 1, 4, 7, 2, 5, 8, |27, 30, 33, 28, 31, 34, 29, 32, 35, |

.

54, 57, 60, 55, 58, 61, 56, 59, 62, |9, 12, 15, 10, 13, 16, 11, 14, 17, | 36, 39, 42, 37, 40, 43, 38, 41, 44, |63, 66, 69, 64, 67, 70, 65, 68, 71| 18, 21, 24, 19, 22, 25, 20, 23, 26, |45, 48, 51, 46, 49, 52, 47, 50, 53, | 72, 75, 78, 73, 76, 79, 74, 77, 80]T . It is obvious that this vector is derived from the VC-Gibbs derivative for . f (x1 , x2 ) = x1 x2 which is .D f (2) = [0, 3, 6, 1, 4, 7, 2, 5, 8]T . We split .D f (4) into .9 subvectors .q4 (i) consisting of .9 elements .g4 (i, j) separated with the symbol .|. The first subvector is identical to .D f (2) for . f = x1 x2 . The . j-th element of the .i-th subvector .q4 (i, j) = 9 · q2 (i) + q2 ( j). For example, the first element in the second subvector is .27. It is computed as the second element in .D f (2) which is .3 times .9 plus the first element in .q2 which is .0 and equals .27. The second element in the second subvector of .q4 is .30. It is computed as the second element in .q2 which is .3, multiplied by .9 plus the second element in .q2 , thus, .3 × 9 + 3 = 30. The same vector is obtained by the matrix .P1 (4) = P1 (2) ⊗ P1 (2), where .P1 (2) is as in Table 4.6, i.e., it is the Gibbs permutation matrix derived from the VC-Gibbs derivative of . f (x 1 , x 2 ) = x 1 x 2 . Example 4.11 Consider the matrix .P3 (4) = P3 (2) ⊗ P3 (2). It converts the vector of the first .81 non-negative integers .G(4) = diag(0, 1, . . . , 80) into the vector DV C, f (4) = [60, 54, 57, 61, 55, 58, 62, 56, 59, |6, 0, 3, 7, 1, 4, 8, 2, 5, |

.

33, 27, 30, 34, 28, 31, 35, 39, 32, |69, 63, 66, 70, 64, 67, 71, 65, 68, | 15, 9, 12, 16, 10, 13, 17, 11, 14, |42, 36, 39, 43, 37, 40, 44, 38, 41, | 78, 72, 75, 79, 73, 76, 80, 74, 77, |24, 18, 21, 25, 19, 22, 26, 20, 23, | 51, 45, 48, 52, 46, 49, 53, 47, 50]T . By using this matrix, the function . f (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 is converted into the function. f 1 (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ 2x1 ⊕ x3 x4 ⊕ 2x3 . Permutations of variables.x1 ↔ x2 and .x3 ↔ x4 which are performed by the Gibbs permutation matrices do not have an effect on the considered function . f . The function . f 1 can be obtained from the initial function . f by the substitutions .x2 → x2 ⊕ 2 and .x4 → x4 ⊕ 2. From Table 4.11, this is the spectral invariant operation applied to the second variable in the pair of variables. This is the reason why this spectral invariant operation is applied to .x2 and .x4 . Example 4.12 Consider the matrix.P4 (4) = P4 (2) ⊗ P4 (2). This matrix converts the vector of the first .81 non-negative integers into the vector

4.5

Extensions to Any Number of Variables

109

Table 4.15 Permutation matrices for .n = 1 .I(1)

→ (1, 2, 3) ⎤ 100 ⎢ ⎥ .⎣ 0 1 0 ⎦ 001

.Q2

→ (1, 3, 2) ⎤ 100 ⎢ ⎥ .⎣ 0 0 1 ⎦ 010

.Q1

T → (2, 3, 1) ⎡1 ⎤ 010 ⎢ ⎥ .⎣ 0 0 1 ⎦ 100

.X1

→ (3, 1, 2) ⎤ 001 ⎢ ⎥ .⎣ 1 0 0 ⎦ 010

.N1



.X





= (2, 1, 3) ⎤ 010 ⎢ ⎥ .⎣ 1 0 0 ⎦ 001 ⎡

= (3, 2, 1) ⎤ 001 ⎢ ⎥ .⎣ 0 1 0 ⎦ 100 ⎡

DV C, f (4) = [30, 33, 27, 31, 34, 28, 32, 35, 29, |57, 60, 54, 58, 61, 55, 59, 62, 56, |

.

3, 6, 0, 4, 7, 1, 5, 8, 2, |39, 42, 36, 40, 43, 37, 41, 44, 38, | 66, 69, 63, 67, 70, 64, 68, 71, 65, |12, 15, 9, 13, 16, 10, 14, 17, 11, | 48, 51, 45, 49, 52, 46, 50, 53, 47, |75, 78, 72, 76, 79, 73, 77, 80, 74, | 21, 24, 18, 22, 25, 19, 23, 26, 20]T . When applied to the function vector of . f (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 , we get the function vector of bent function. f 3 = x1 x2 ⊕ x1 ⊕ x3 x4 ⊕ x3 . The corresponding spectral invariant operations are permutations .x1 ↔ x2 and .x3 ↔ x4 and substitutions .x2 → x2 ⊕ 1 and . x 4 → x 4 ⊕ 1 as can be seen from Table 4.11. For a transition from functions in .n variables to functions in .(n + 1) variables, we can use .(3 × 3) permutation matrices assigned to the permutation in the set of three elements. Table 4.15 shows these permutation matrices. The justification is in the feature that these matrices map a bent function in a single variable into other bent functions in the same number of variables up to the encoding of function values. More precisely, there are .18 bent functions in a single variable. The basis function is . f 1 (x1 ) = x12 whose function vector is T .F = [0, 1, 1] . The other two basis functions are obtained by adding the constants .1 and 2 2 .2 to it, thus, . f 2 (x 1 ) = x ⊕ 1, and . f 3 (x 1 ) = x ⊕ 2. These three functions differ up to the 1 1 encoding of function values. Any permutation of elements in their function vectors is another bent function, which makes .18 bent functions in a single variable. The permutation matrices in Table 4.15 permute these functions to each other. Further, we use the following considerations. Recall that spectral invariant operations correspond to the permutation of precisely defined subsets of Vilenkin–Chrestenson coefficients [1, 2]. These permutations in the spectral domain can be expressed by the corresponding transformations in the original domain, which can also be expressed by suitably defined permutation matrices in the original domain.

110

4 Gibbs Characterization of Ternary Bent Functions

The Gibbs permutation matrices are a subset of such permutation matrices in the original domain. If we consider the Kronecker product of permutation matrices, each submatrix, depending on its position in the Kronecker product, permutes a particular subset of spectral coefficients or correspondingly function values. This permutation corresponds to a spectral invariant operation over a subset of variables. Therefore, the Kronecker product of Gibbs permutation matrices corresponds to the application of a set of spectral invariant operations in a certain order and with respect to a subset of variables after another set of spectral invariant operations is already performed over a different subset of variables. From this consideration the following observation is derived. Given are two permutation matrices .P1 and .P2 preserving bentness of bent functions in .m and .n variables, respectively. Then, the Kronecker product .P1 ⊗ P2 preserves bentness of functions in .m · n variables. In dealing with the Kronecker product of Gibbs permutation matrices, we can select 1. Spectral invariant operations by selecting the Gibbs permutation matrices of small dimensions as factor matrices in the Kronecker product, 2. Subset of variables to which the spectral invariant operation will be applied by selecting the position in the Kronecker product for each Gibbs permutation matrix. At other positions the .(3 × 3) identity matrices are assigned. The following examples illustrate these features of the proposed method. Example 4.13 Consider the matrix .P7 (2) assigned to the function . f 2 in Table 4.6. Define a matrix .P1 (3) = I(1) ⊗ P7 (2), where .I(1) is the .(3 × 3) identity matrix. The position of .P7 (2) in the Kronecker product determines that it will perform the spectral invariant operation over the variables .x2 and .x3 . Thus, from Table 4.11, after the permutation of these variables . x 2 ↔ x 3 , it follows . x 2 → x 2 ⊕ 1 and . x 3 → x 3 ⊕ 2. This matrix permutes the elements of a vector .G(3) of first .27 non-negative integers into the vector G1 (3) = [7, 1, 4, 8, 2, 5, 6, 0, 3, |

.

16, 10, 13, 17, 11, 14, 15, 9, 12, | 25, 19, 22, 26, 20, 23, 24, 18, 21]T . When this matrix is applied to the function vector F1 = [0, 0, 0, 1, 1, 1, 1, 1, 1, |

.

0, 1, 2, 1, 2, 0, 1, 2, 0, | 0, 2, 1, 1, 0, 2, 1, 0, 2]T of the function . f 1 (x1 , x2 , x3 ) = x1 x3 ⊕ x22 , we get the function vector

4.5

Extensions to Any Number of Variables

111

F2 = [1, 0, 1, 1, 0, 1, 1, 0, 1, |

.

2, 1, 2, 0, 2, 0, 1, 0, 1, | 0, 2, 0, 2, 1, 2, 1, 0, 1]T of . f 2 (x1 , x2 , x3 ) = 1 ⊕ x3 ⊕ x32 ⊕ x1 ⊕ x1 x2 . This function. f 2 is obtained from. f 1 by the spectral invariant operations over the variables . x 2 and . x 3 as permutation of variables . x 2 and . x 3 followed by . x 2 → x 2 ⊕ 1, . x 3 → x 3 ⊕ 2. Thus, the spectral invariant operations corresponding to .P7 are performed over the last two variables .x2 and .x3 . The matrix .P2 (3) = P7 (2) ⊗ I(1) converts the vector .G(3) into the vector G2 (3) = [21, 22, 23, 3, 4, 5, 12, 13, 14, |

.

24, 25, 26, 6, 7, 8, 15, 16, 17, | 18, 19, 20, 0, 1, 2, 9, 10, 11]T . When .P2 (3) is applied to .F1 , we get the function vector F3 = [1, 0, 2, 1, 1, 1, 1, 2, 0, |

.

1, 0, 2, 1, 1, 1, 1, 2, 0, | 0, 2, 1, 0, 0, 0, 0, 1, 2]T of the function . f 3 (x1 , x2 , x3 ) = 1 ⊕ 2x3 ⊕ x2 x3 ⊕ 2x1 ⊕ x12 . This function is obtained by the spectral invariant operations performed by .P2 (2), but over the first two variables corresponding to the position of this factor matrix in the Kronecker product. Therefore, . f 1 is converted into . f 3 by .x1 ↔ x2 followed by .x1 → x1 ⊕ 1, and .x2 → x2 ⊕ 2. Example 4.14 Consider the matrix P3 (3) = X1T ⊗ P16 (2).

.

This matrix permutes the vector .G(3) into the vector G3 (3) = [16, 13, 10, 15, 12, 9, 17, 14, 11, |

.

25, 22, 19, 24, 27, 18, 26, 23, 20, | 7, 4, 1, 6, 3, 0, 8, 5, 2]T . This matrix converts the function vector of the bent function. f 1 = x1 x3 ⊕ x22 into the function vector

112

4 Gibbs Characterization of Ternary Bent Functions

F2 = [2, 2, 1, 1, 1, 0, 0, 0, 2, |

.

0, 0, 2, 1, 1, 0, 2, 2, 1, | 1, 1, 0, 1, 1, 0, 1, 1, 0]T . of . f 2 = 2 ⊕ 2x3 ⊕ x32 ⊕ 2x2 ⊕ x1 ⊕ 2x1 x2 . This function can be derived from the function T . f 1 by the substitution . x 1 = x 1 ⊕ 1 performed by .X followed by permutation of variables 1 . x 2 and . x 3 and substitutions . x 2 → 2x 2 ⊕ 1, and . x 3 → 2x 3 ⊕ 2 due to .P16 . Consider the matrix P4 (3) = P16 ⊗ X1T .

.

This matrix converts the function vector of . f 1 = x1 x3 ⊕ x22 into the vector G4 (3) = [22, 23, 21, 13, 14, 12, 4, 5, 3, |

.

19, 20, 18, 10, 11, 9, 1, 2, 0, | 25, 26, 24, 16, 17, 15, 7, 2, 6]T . The permutation matrix .P4 (3) = P16 ⊗ X1T converts the function vector of . f 1 into the function vector F2 = [0, 2, 1, 2, 0, 1, 1, 1, 1, |

.

2, 1, 0, 1, 2, 0, 0, 0, 0, | 0, 2, 1, 2, 0, 1, 1, 1, 1]T of the function. f 3 = 2x3 ⊕ 2x2 ⊕ 2x2 x3 ⊕ x1 ⊕ x12 . This function can be derived from. f 1 by the permutation of variables .x1 and .x2 and substitutions .x1 → 2x1 ⊕ 1, and .x2 → 2x2 ⊕ 2, corresponding to .P16 followed by the substitution .x3 → x3 ⊕ 1 corresponding to .X1T . For more examples on this subject, see [11].

4.6

Construction Algorithm

The presented approach directly leads to a simple construction algorithm for bent functions for any .n by using the Gibbs permutation matrices. Algorithm 4.1 (Construction by Gibbs matrices) Given are a library .M of Gibbs matrices for .n = 1, 2 and a list .L of ternary bent functions of a required number of variables .n.

4.7 The Galois Field Gibbs Derivatives and Ternary Bent Functions

113

1. Define a .(3n × 3n ) permutation matrix .P as the Kronecker product of matrices in .M. 2. Apply .P to a function . f ∈ L. Check if the constructed function . f c is already contained in .L. If . yes delete it, if .not save it in .L. 3. Repeat .2 to another . f ∈ L and continue with computing over all functions in .L. 4. Define another permutation matrix .P by changing factor matrices in the Kronecker product and repeat .2 and .3. 5. Stop when depending on the intended application the determined number of different bent functions is reached.

4.7

The Galois Field Gibbs Derivatives and Ternary Bent Functions

As already discussed, Gibbs derivatives defined in terms of the Vilenkin–Chrestenson transform can be used to characterize just a small number of ternary bent functions, i.e., the bent functions described by functional expressions containing no squares of variables. Therefore, in [12] was explored the application of the Gibbs derivative defined in terms of the Galois Field (GF) expressions for ternary functions, the GF-Gibbs derivatives defined in Chap. 1 to the characterization of ternary bent functions. The following statement is presented in [12]. Statement 4.3 A ternary function . f of .n > 1 variables is a bent function iff 1. The function vector .F of . f contains all three values from the set .{0, 1, 2}, 2. . f is not balanced, and 3. The ternary GF-Gibbs derivative of . f is equal to .k · φ(n), for .k ∈ {0, 1, 2}, where .φ(n) is defined as the product of variables φ(n) =

n ∏

.

xi , i = 1, 2, . . . , n.

i=1

Example 4.15 (Analysis for .n = 2) A computer enumeration over ternary functions for .n = 2 shows that there are .3 × 243 = 729 functions satisfying the third requirement, i.e., whose ternary GF-Gibbs derivative is of the form .k · φ; however, .75 functions do not contain all three values .0, .1, and .2 in the function vector, while other .168 are balanced. Therefore, these .75 + 168 = 243 functions cannot be bent functions. The remaining .486 functions constitute the set of all ternary bent functions of two variables. Among them, the number of functions having the GF-Gibbs derivative equal to .k · φ is .108, .189, and .189 for .k = 0, 1, 2, respectively. The following example illustrates GF-Gibbs characterization of particular ternary bent functions.

114

4 Gibbs Characterization of Ternary Bent Functions

Example 4.16 Table 4.16 shows the GF-Gibbs derivatives for .18 functions in Table 4.2. It can be seen that functions which do not contain the product term with distinct variables, i.e., . x 1 x 2 have the GF-Gibbs derivative equal to the constant .0, while for all other functions the GF-Gibbs derivative is equal to the function .k · φ for .k = 1, 2. Seven of them, .1, .3, .5, .6, .7, .9, .16 have the term .x1 x2 in the GF-expression and their GF-Gibbs derivative is equal to .φ = x1 x2 . The other seven have the term .2x1 x2 and their GF-Gibbs derivative is equal to .2φ. The remaining four functions, .11, .12, .13, .14, do not contain this product term and their GF-Gibbs derivative is the constant .0, i.e., this is the case when .k = 0 in .k · φ. A good feature of this characterization of bent functions, which can be considered as an advantage compared to other characterizations, is the speed of computations required to check if a function is bent. Check if all three values for a ternary function are present in the function vector is of the same complexity as checking if all the coefficients have the same absolute values. Computing the spectral coefficients for a function of .n variables requires .n steps which are by definition preformed sequentially. The GF-Gibbs derivative is defined in terms of the partial derivatives that can be computed in parallel and then multiplied [13]. Therefore, computing the GF-Gibbs derivative is by definition .n − 2 times faster when performed on an architecture allowing parallel computation as GPUs [10]. Eliminating balanced functions reduces to checking if the sum of elements in the function vector in the complex encoding is equal to .0.

4.8

Gibbs Characterization of Ternary Functions and Distribution of Function Values

In Table 4.2, functions .1, .2, .3, .4, .5, .6, .7, .8, .9, .10, .12, .13 have the distribution .(5, 2, 2). Functions .11, .14, .15, .16, and .17 have the distribution .(1, 4, 4). It can be observed that functions with different distributions have the same Gibbs characterization, and, conversely, functions with the same distribution might have different Gibbs characterizations. Therefore, it is interesting to discuss this feature for other ternary bent functions. We will use the notation .i(k) to denote that the value .i appears .k times as an element of a vector. For .n = 2, there are .108 functions with the GF-Gibbs derivative equal to the zero vector, .54 of them per each distribution. The VC-Gibbs derivative of ternary bent functions in .n = 2 variables with the distribution .(5, 2, 2) is the vector whose elements are .3(1), 4(3), 5(2), 6(3), where the number in the brackets shows how many times the corresponding value appears. Example 4.17 The VC-Gibbs derivative for the function. f (x1 , x2 ) = 2x2 ⊕ 2x12 ⊕ x22 with the distribution .(5, 2, 2) and the function vector

4.8

Gibbs Characterization of Ternary Functions and Distribution of Function Values

115

Table 4.16 Even functions and their GF-Gibbs derivatives Function

Function vector

GF-Gibbs derivative

1.

.x1 x2

.F = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

2.

.2x 1 x 2 . x 12 ⊕ x 1 x 2 . x 12 ⊕ 2x 1 x 2 .2x 12 ⊕ x 1 x 2 .2x 12 ⊕ 2x 1 x 2 . x 22 ⊕ x 1 x 2 . x 22 ⊕ 2x 1 x 2 .2x 22 ⊕ x 1 x 2 .2x 22 ⊕ 2x 1 x 2 . x 12 ⊕ x 22 .2x 12 ⊕ x 22 . x 12 ⊕ 2x 22 .2x 12 ⊕ 2x 22 . x 12 ⊕ x 1 x 2 ⊕ 2x 22 .2x 12 ⊕ x 1 x 2 ⊕ x 22 . x 12 ⊕ 2x 1 x 2 ⊕ 2x 22 .2x 12 ⊕ 2x 1 x 2 ⊕ x 22

.F = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.F = [0, 0, 0, 1, 2, 0, 1, 0, 2]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 0, 0, 1, 0, 2, 1, 2, 0]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.F = [0, 0, 0, 2, 0, 1, 2, 1, 0]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 0, 0, 2, 1, 0, 2, 0, 1]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 1, 1, 0, 2, 0, 0, 0, 2]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 1, 1, 0, 0, 2, 0, 2, 0]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.F = [0, 2, 2, 0, 0, 1, 0, 1, 0]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 2, 2, 0, 1, 0, 0, 0, 1]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.F = [0, 1, 1, 1, 2, 2, 1, 2, 2]T

.DG F, f = [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.F = [0, 1, 1, 2, 0, 0, 2, 0, 0]T

.DG F, f = [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.F = [0, 2, 2, 1, 0, 0, 1, 0, 0]T

.DG F, f = [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.F = [0, 2, 2, 2, 1, 1, 2, 1, 1]T

.DG F, f = [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.F = [0, 2, 2, 1, 1, 2, 1, 2, 1]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 1, 1, 2, 1, 2, 2, 2, 1]T

.DG F, f = [0, 0, 0, 0, 1, 2, 0, 2, 1]T

.F = [0, 2, 2, 1, 2, 1, 1, 1, 2]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

.F = [0, 1, 1, 2, 2, 1, 2, 1, 2]T

.DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]T

3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18.

F = [0, 0, 2, 2, 2, 1, 2, 2, 1]T

.

is DV C, f = [6, 6, 6, 4, 4, 5, 3, 4, 5]T .

.

Thus, distribution of values of the VC-Gibbs derivative for this function is .3(1), 4(3), 5(2), 6(3). This function does not have the Gibbs characterization in terms of the VC-Gibbs derivative. Its GF-Gibbs derivative is equal to .0. There are .54 functions with the distribution .(1, 4, 4) whose GF-Gibbs derivative is the zero vector, and their VC-Gibbs derivative is with the following distribution of elements .3(1), 4(4), 5(2), 6(1), 7(1). Example 4.18 For the function . f (x1 , x2 ) = x12 ⊕ x22 with the distribution .(1, 4, 4) and the function vector F = [0, 1, 1, 1, 2, 2, 1, 2, 2]T ,

.

the GF-Gibbs derivative is .0, while the VC-Gibbs derivative is DV C, f = [7, 5, 6, 3, 4, 4, 5, 4, 4]T .

.

116

4 Gibbs Characterization of Ternary Bent Functions

Table 4.17 GF-Gibbs and VC-Gibbs derivatives for functions with the distribution . D = (1, 4, 4) and with the GF-Gibbs derivative equal to .k · φ, .k = 0, 1, 2 .k

GF-Gibbs derivative

VC-Gibbs derivative

.0

T .[0, 0, 0, 0, 0, 0, 0, 0, 0, ]

.3(1), 4(4), 5(2), 6(1), 7(1)

.1

T .[0, 0, 0, 0, 1, 2, 0, 2, 1]

.3(1), 4(3), 5(2), 6(3)

.2

.[0, 0, 0, 0, 2, 1, 0, 1, 2]

T

.3(1), 4(3), 5(2), 6(3)

Therefore, distribution of values of the VC-Gibbs derivative for this function is .3(1), 4(4), 5(2), 6(1), 7(1). For the distribution.(1, 4, 4), there are.162 functions with the GF-Gibbs derivative equal to k · φ, with .54 functions for each value of .k = 0, 1, 2. We computed the VC-Gibbs derivative for each of these subsets of .54 functions for different .k. Table 4.17 shows the distributions of values in VC-Gibbs derivatives for functions with the distribution .(1, 4, 4) and with the GF-Gibbs derivative equal to .k · φ, .k = 0, 1, 2. It can be observed that functions for .k = 1 and .k = 2 have the same distributions of values of the VC-Gibbs derivative. The analysis of functions for .n = 2 can be summarized as follows.

.

Statement 4.4 For .n = 2 there are .486 ternary bent functions out of the total of .19683 functions. There are .324 functions with distribution .(5, 2, 2), and .162 with distribution .(1, 4, 4). 1. There are .108 functions with the GF-Gibbs derivative .0, out of which there are .54 functions for each of these two distributions. 2. There are .189 functions with the GF-Gibbs derivative .1 · φ, out of which .135 functions have the distribution .(5, 2, 2) and .54 with the distribution .(1, 4, 4). 3. There are .189 functions with the GF-Gibbs derivative .2 · φ, out of which there are .135 functions have the distribution .(5, 2, 2) and .54 with the distribution .(1, 4, 4). 4. For functions with the GF-Gibbs derivative .0, and distribution .(5, 2, 2), the VC-Gibbs derivative can have the following values: DV C, f = [3, 4, 4, 4, 5, 5, 6, 6, 6]T ,

.

or in terms of the distribution .3(1), 4(3), 5(2), 6(3). Recall that we consider the absolute values of the VC-Gibbs derivative rounded to integers. 5. For functions with the GF-Gibbs derivative .k · φ, .k = 1, 2, and distribution .(5, 2, 2), the VC-Gibbs derivative can have the following values:

4.8

Gibbs Characterization of Ternary Functions and Distribution of Function Values

117

DV C, f = [0, 1, 2, 3, 4, 5, 6, 7, 8]T ,

.

DV C, f = [1, 1, 2, 4, 4, 5, 7, 7, 8]T , DV C, f = [3, 3, 4, 4, 4, 5, 5, 6, 7]T , or in terms of distributions.0(1), 1(1), 2(1), 3(1), 4(1), 5(1), 6(1), 7(1), 8(1),.1(2), 2(1), 4(2), 5(1), 7(2), 8(1), and .3(2), 4(3), 5(2), 6(1), 7(1). 6. For functions with the GF-Gibbs derivative .0, and distribution .(1, 4, 4), the VC-Gibbs derivative can have the following values: DV C, f = [3, 4, 4, 4, 4, 5, 5, 6, 7]T ,

.

or in terms of distributions .3(1), 4(4), 5(2), 6(1), 7(1). 7. For functions with GF-Gibbs derivative .k · φ, .k = 1, 2, and distribution .(1, 4, 4) the VC-Gibbs derivative can have the following values: DV C, f = [3, 4, 4, 4, 5, 5, 6, 6, 6]T ,

.

or in terms of distributions .3(1), 4(3), 5(2), 6(3). Notice that for the distribution .(5, 2, 2), and the GF-Gibbs derivative .0, the VC-Gibbs derivative is the same as for the distribution .(1, 4, 4) with the GF-Gibbs derivative for .k = 1, 2. Besides bent functions, no other functions for .n = 2 can have the GF-Gibbs or VCGibbs derivatives as specified above. It follows that the Gibbs derivatives can be used to characterize ternary bent functions. Example 4.19 The function with the function vector F = [0, 0, 1, 0, 2, 2, 1, 2, 1]T

.

has the GF-Gibbs derivative equal to .2 · φ; however, it is balanced, and therefore not bent. Its VC-Gibbs derivative is DV C, f = [6, 5, 3, 3, 4, 6, 4, 3, 4]T ,

.

or in terms of appearances .3(3), 4(3), 5(1), 6(2) and also does not belong to the possible values for GF-Gibbs derivative of bent functions. Thus, viewed as a function, the vector of the GF-Gibbs derivative is balanced. Example 4.20 As an illustration of the above statements, Tables 4.18 and 4.19 show .26 bent functions derived from the function . f (x1 , x2 ) = x12 ⊕ x22 , their function vectors, and GF-Gibbs and VC-Gibbs derivatives. The first .9 functions have the zero-valued GF-Gibbs derivative, and all other functions have identical GF-Gibbs derivative which viewed as a

118

4 Gibbs Characterization of Ternary Bent Functions

Table 4.18 Bent functions (1–18) with . D = (1, 4, 4), their GF-Gibbs derivatives (. DG F, f ), and VC-Gibbs (. DV C, f ) derivatives . f , . DG F, f

1.

. x 12



.DG F, f

2.

.x1



.x2



4.

.x1

.2x 1



.DG F, f

6.

.2x 2

.2x 1

.x1

.2x 1

.2x 1 x 2 .DG F, f

11.

.2x 1 x 2 .DG F, f

12.

.2x 1 x 2 .DG F, f

13.

.2x 1 x 2 .DG F, f

14.

.2x 1 x 2 .DG F, f

15.

.2x 1 x 2 .DG F, f

16.

.2x 1 x 2 .DG F, f

17.

.2x 1 x 2 .DG F, f

18.

x12



x22

⊕2

x12



x22

⊕1

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T = [0, 0, 0, 0, 0, 0, 0, 0, 0]T = [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.2x 1 x 2 .DG F, f

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T ⊕ x12 ⊕ 2x22 = [0, 0, 0, 0, 2, 1, 0, 1, 2]T ⊕ x1 ⊕ x12 ⊕ 2x22 ⊕ 2 = [0, 0, 0, 0, 2, 1, 0, 1, 2]T ⊕ x2 ⊕ x12 ⊕ 2x22 ⊕ 1 ⊕ 2x1 ⊕ =

⊕ 2x22

x12

⊕ 2x22 x12

x12 x12

⊕ 2x22

⊕2

⊕ 2x22

⊕2

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

⊕ 2x1 ⊕ 2x2 ⊕ =

⊕1

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

⊕ x1 ⊕ 2x2 ⊕ =

⊕ 2x22

x12

⊕ 2x22

⊕1

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

= [4, 4, 6, 5, 6, 3, 6, 5, 4]T

= [2, 0, 2, 1, 1, 2, 2, 1, 1]T

.DV C, f .F

= [4, 6, 5, 6, 4, 4, 3, 5, 6]T

= [2, 2, 0, 2, 1, 1, 1, 2, 1]T

.DV C, f .F

= [6, 5, 4, 4, 4, 6, 5, 6, 3]T

= [1, 1, 2, 0, 2, 2, 1, 2, 1]T

.DV C, f .F

= [5, 4, 6, 4, 6, 4, 6, 3, 5]T

= [1, 2, 1, 2, 2, 0, 2, 1, 1]T

.DV C, f .F

= [6, 3, 5, 5, 4, 6, 4, 6, 4]T

= [2, 1, 1, 2, 0, 2, 1, 1, 2]T

.DV C, f .F

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

⊕ 2x1 ⊕ x2 ⊕ =

⊕1

= [5, 6, 3, 6, 5, 4, 4, 4, 6]T

= [1, 1, 2, 2, 1, 1, 2, 0, 2]T

.DV C, f .F

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

⊕ x1 ⊕ x2 ⊕ =

⊕2

[0, 0, 0, 0, 2, 1, 0, 1, 2]T

⊕ 2x2 ⊕ =

x12

= [6, 4, 4, 3, 5, 6, 4, 6, 5]T

= [2, 1, 1, 1, 2, 1, 2, 2, 0]T

.DV C, f .F

= [0, 0, 0, 0, 2, 1, 0, 1, 2]T

= [4, 4, 3, 4, 4, 5, 5, 6, 7]T

= [0, 2, 2, 1, 2, 1, 1, 1, 2]T

.DV C, f .F

= [4, 4, 5, 5, 6, 7, 4, 4, 3]T

= [2, 2, 1, 2, 2, 1, 1, 1, 0]T

.DV C, f .F

= [4, 3, 4, 4, 5, 4, 6, 7, 5]T

= [2, 2, 1, 1, 1, 0, 2, 2, 1]T

.DV C, f .F

= [5, 6, 7, 4, 4, 3, 4, 4, 5]T

= [2, 1, 2, 2, 1, 2, 1, 0, 1]T

.DV C, f .F

= [3, 4, 4, 5, 4, 4, 7, 5, 6]T

= [1, 1, 0, 2, 2, 1, 2, 2, 1]T

.DV C, f .F

= [4, 5, 4, 6, 7, 5, 4, 3, 4]T

= [1, 2, 2, 1, 2, 2, 0, 1, 1]T

.DV C, f .F

= [6, 7, 5, 4, 3, 4, 4, 5, 4]T

= [2, 1, 2, 1, 0, 1, 2, 1, 2]T

.DV C, f .F

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T

= [5, 4, 4, 7, 5, 6, 3, 4, 4]T

= [1, 0, 1, 2, 1, 2, 2, 1, 2]T

.DV C, f .F

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T

= [7, 5, 6, 3, 4, 4, 5, 4, 4]T

= [1, 2, 2, 0, 1, 1, 1, 2, 2]T

.DV C, f .F

⊕ 2x2 ⊕ x12 ⊕ x22 ⊕ 2

.DG F, f

10.

⊕1

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T

⊕ 2x2 ⊕ x12 ⊕ x22 ⊕ 2

.DG F, f

9.



x22

= [0, 1, 1, 1, 2, 2, 1, 2, 2]T

.DV C, f .F

⊕ x2 ⊕ x12 ⊕ x22 ⊕ 2

.DG F, f

8.

⊕1

⊕ x12 ⊕ x22 ⊕ 1

.DG F, f

7.

x22

[0, 0, 0, 0, 0, 0, 0, 0, 0]T

⊕ x2 ⊕

.DG F, f

5.

[0, 0, 0, 0, 0, 0, 0, 0, 0]T



=

x12

.DG F, f

.F

=

x12

.DG F, f

3.

.F, . DV C, f

x22

= [4, 6, 4, 6, 3, 5, 5, 4, 6]T

= [1, 2, 1, 1, 1, 2, 0, 2, 2]T

.DV C, f

= [3, 5, 6, 4, 6, 5, 6, 4, 4]T

References

119

Table 4.19 Bent functions (19-27) with . D = (1, 4, 4) and their GF-Gibbs derivatives 19.

.2x 1 x 2

⊕ 2x12 ⊕ x22 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

20.

.2x 1 x 2

⊕ x1 ⊕ 2x12 ⊕ x22 ⊕ 1 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

21.

.2x 1 x 2

⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 2 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

22.

.2x 1 x 2

⊕ 2x1 ⊕ 2x12 ⊕ x22 ⊕ 1 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

23.

.2x 1 x 2

⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 2 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

24.

.2x 1 x 2

⊕ x1 ⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 1 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

25.

.2x 1 x 2

⊕ 2x1 ⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 2 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

26.

.2x 1 x 2

⊕ x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 2 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

27.

.2x 1 x 2

⊕ 2x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 1 T .DG F, f = [0, 0, 0, 0, 2, 1, 0, 1, 2]

.F

= [0, 1, 1, 2, 2, 1, 2, 1, 2]T T .D V C, f = [6, 3, 4, 4, 6, 5, 4, 5, 6] = [1, 2, 2, 1, 1, 0, 2, 1, 2]T T .D V C, f = [5, 6, 4, 3, 4, 6, 6, 5, 4] = [2, 1, 2, 1, 2, 2, 1, 1, 0]T T .D V C, f = [6, 5, 4, 5, 6, 4, 3, 4, 6] = [1, 2, 2, 2, 2, 1, 1, 0, 1]T T .D V C, f = [5, 4, 6, 6, 4, 5, 4, 6, 3] = [2, 2, 1, 1, 0, 1, 1, 2, 2]T T .D V C, f = [6, 4, 5, 4, 6, 3, 5, 4, 6] = [1, 0, 1, 1, 2, 2, 2, 2, 1]T T .D V C, f = [4, 6, 3, 5, 4, 6, 6, 4, 5] = [2, 1, 2, 0, 1, 1, 2, 2, 1]T T .D V C, f = [4, 5, 6, 6, 3, 4, 4, 6, 5] = [2, 2, 1, 2, 1, 2, 0, 1, 1]T T .D V C, f = [4, 6, 5, 4, 5, 6, 6, 3, 4] = [1, 1, 0, 2, 1, 2, 1, 2, 2]T T .D V C, f = [3, 4, 6, 6, 5, 4, 5, 6, 4]

ternary function has the distribution . D = (5, 2, 2). The VC-Gibbs derivatives for the first .9 functions have the distribution of values as .3(1)4(4), 5(2), 6(1), 7(1). The remaining functions have the VC-Gibbs derivative with the distribution .3(1), 4(3), 5(2), 6(2).

References 1. Hurst, S.L.: Logical Processing of Digital Signals. Crane Russak and Edward Arnold, London (1978) 2. Hurst, S.L., Miller, D.M., Muzio, J.C.: Spectral Techniques in Digital Logic. Academic, Bristol (1985) 3. Stankovi´c, R.S. Astola, J.T., Moraga, C.: Representation of Multiple-Valued Logic Functions. Claypool & Morgan Publishers (2012) 4. Stankovi´c, S., Stankovi´c, M., Astola, J.: Representation of multiple-valued functions with flat Vilenkin-Chrestenson spectra by decision diagrams. Mutiple-Valued Logic Soft Comput. 23(5– 6), 485–501 (2014) 5. Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Some spectral invariant operations for functions with disjoint products in the polynomial form. In: Moreno-Diaz, R., Pichler, F., Quesada-Arencibia, A., (eds.), Computer Aided Systems Theory - EUROCAST 2017, 16th International Conference,

120

6.

7.

8. 9. 10.

11.

12.

13. 14.

4 Gibbs Characterization of Ternary Bent Functions Las Palmas de Gran Canaria, Spain, February 19–24, 2017, Revised Selected Papers, LNCS, vol. 10672, 262–269, Part 2. Springer (2017) Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Some spectral invariant operations for multiplevalued functions with homogeneous disjoint products in the polynomial form. In: Proceedings of the 47th International Symposium on Multiple-Valued Logic, Novi Sad, Serbia, May 22–24, 2017, 61–66 (2017) Joyner, D.W.: The strange story of ternary bent functions in 2 variables (2023). https://wdjoyner. wordpress.com/2012/12/29/the-strange-story-of-ternary-bent-functions-in-2-variables/ visited October 10, 2023 Stankovi´c, R.S.: Fast algorithms for the calculation of Gibbs derivatives on finite groups. Approxim. Theory Appl. 7(2), 1–19 (1991) Stankovi´c, R.S., Stankovi´c, M.: Calculation of the Gibbs derivatives on finite Abelian groups through the decision diagrams. Approxim. Theory Its Appl. 14(4), 12–25 (1998) Stankovi´c, R.S., Gaji´c, D.B.: Efficient computation of Gibbs derivatives on finite Abelian groups. In: Dyadic Walsh analysis from 1924 onwards: Walsh-Gibbs-Butzer Dyadic differentiation in science, Vol. 2 Extensions and Generalizations, 211–228. Springer/Atlantis Press, Paris (2015). ISSN 1875-7642 ISSN 2467-9631 (electronic) ISBN 978-94-6239-162-8 ISBN 978-94-6239163-5 (eBook) Stankovi´c, M., Stankovi´c, R.S., Moraga, C., Astola, J.T.: Remarks on Gibbs permutation matrices for ternary bent functions. In: Proceedings of the 52nd International Symposium on Multiplevalued Logic, Matsue, Shimane, Japan, May 22–24, 2023, 70–75 (2023). https://doi.org/10. 1109/ISMVL57333.2023.00024 Stankovi´c, R.S., Stankovi´c, M., Astola, J.T., Moraga, C.: Gibbs characterization of binary and ternary bent functions. In: Proceedings of the 46th International Symposium on Multiple-Valued Logic, Sapporo, Hokkaido, Japan, May 18–20, 2016, 205–210 (2016) Stankovi´c, R.S., Moraga, C., Astola, J.T.: Fourier Analysis on Finite Non-Abelian Groups with Applications in Signal Processing and System Design. Wiley/IEEE Press (2005) Moraga, C., Stankovi´c, M., Stankovi´c, R.S., Stojkovi´c, S.: Contribution to the study of multiplevalued bent functions. In: Proceedings of the 43th International Symposium on Multiple-Valued Logic, Toyama, Japan, May 22–24, 2013, 340–345 (2013)

5

Gibbs Characterization of a Class of Quaternary Bent Functions

As already noticed in previous chapters, there are differences between binary bent functions and bent functions for . p > 2. For example, the binary bent functions are defined as maximally non-linear binary functions. In the case of bent functions for other values of . p, including the case . p = 4 this feature does not necessarily hold. As pointed out in [1] for quaternary functions, and discussed more generally for any . p in [2], there are quaternary bent functions that are not maximally non-linear, and, vice versa, maximally non-linear quaternary functions that are not bent. The differences between binary bent functions and bent functions for other . p > 2 give the motivation to study up to which extent the methods used in the characterization of binary bent functions, and partially extended to the characterization of ternary functions, can be applied to quaternary bent functions. This chapter is devoted to the extension of the Gibbs characterization of bent functions for . p = 2 and . p = 3 to quaternary bent functions, i.e., bent functions for . p = 4 [3, 4]. Recall that by following the approach adopted by many authors, and also assumed in this book, the term quaternary functions means functions defined as . f : Z 4n → Z 4 , where . Z 4 is the ring of non-negative integers smaller than .4. Thus, the functions and their variables can take four different values conveniently identified with the first four non-negative integers n .0, 1, 2, 3. We process them by using the Vilenkin–Chrestenson transform on the group .C 4 after complex encoding of their values .(0, 1, 2, 3) → (1, i, −1, −i). The following example shows a particular case illustrating the differences of quaternary bent functions with respect to binary and ternary bent functions.

© The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_5

121

122

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Example 5.1 For .n = 2, the functions .

f pG F (x1 , x2 ) = x1 x2 , f sG F (x1 , x2 ) = x12 ⊕ x22 ,

with operations of multiplication, exponentiation, and addition in .G F(4), as indicated by the index .G F, are not bent in the sense of the present discussions. This observation can be viewed as follows. The function vectors of . f pG F and . f sG F are F pG F = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 3, 1, 0, 3, 1, 2]T ,

.

FsG F = [0, 1, 3, 2, 1, 0, 2, 3, 3, 2, 0, 1, 2, 3, 1, 0]T . The compositions of function values are .C pG F = (7, 3, 3, 3) and .CsG F = (4, 4, 4, 4). It follows that the function . f pG F does not have the distribution of function values required for bent functions. Further, the function . f sG F is balanced, therefore, it cannot be bent. The same can be concluded from their Vilenkin–Chrestenson spectra. To compute the Vilenkin– Chrestenson transform for . p = 4, we first perform encoding .(0, 1, 2, 3) → (1, i, −1, −i). The Vilenkin–Chrestenson spectra of these functions are S f pG F = [4, 4, 4, 4, 4, 2 − 6i, −4 + 4i, −2 + 2i,

.

4, −4 + 4i, −4i, 0, 4, −2 + 2i, 0, −2 − 2i]T , S fsG F = [0, 0, 0, 0, 0, 4 − 4i, 0, 4 + 4i, 0, 0, 8 − 8i, 0, 0, 4 + 4i, 0, −4 + 4i]T , and since they are not flat, it follows the these functions are not bent in the realms of the ring .(Z 4 , +, ·). Notice that these functions are bent when studied in the realms of the Galois field .G F(4) and related Fourier transform. Consider the functions with the formally identical functional expressions as in Example 5.1, the product of variables, and the sum of squares of variables, but with operations modulo .4. Thus, their function vectors are F p4 = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 0, 2, 0, 3, 2, 1]T ,

.

Fs4 = [0, 1, 0, 1, 1, 2, 1, 2, 0, 1, 0, 1, 1, 2, 1, 2]T . The function . f p4 has the composition .C f p4 = (8, 2, 4, 2), while the function . f s4 does not take the value .3, and has the composition .C fs4 = (4, 8, 4, 0). The corresponding Vilenkin–Chrestenson spectra are S f p4 = [4, 4, 4, 4, 4, −4i, −4, 4i, 4, −4, 4, −4, 4, 4i, −4, −4i]T ,

.

S fs4 = [8i, 0, 8, 0, 0, 0, 0, 0, 8, 0, −8i, 0, 0, 0, 0, 0]T . The function . f p4 is bent since it has the flat spectrum, while . f s4 is not bent and its spectrum is not flat. The function . f s4 is a plateaued function [5].

5 Gibbs Characterization of a Class of Quaternary Bent Functions

123

Consider the function. fr 4 (x1 , x2 ) = x13 ⊕ x23 with operations modulo.4, i.e., moving from . G F(4) to the ring .(Z 4 , +, ·). In the rest of this chapter, we will be working in this ring, as shown by the letter .r in the index, and therefore sums and products or exponentials of variables will always be calculated modulo .4. The function vector is Fr 4 = [0, 1, 0, 3, 1, 2, 1, 0, 0, 1, 0, 3, 3, 0, 3, 2]T ,

.

and the Vilenkin–Chrestenson spectrum is S fr 4 = [4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4, −4, −4, −4, −4, 4]T .

.

It follows that this function is bent. The composition of function values is.C fr 4 = (6, 4, 2, 4). Notice that the sum of elements in .F pG F and .FsG F computed modulo .4 are .2 and .0, respectively. For functions . f p4 and . f s4 the sum of elements in the function vectors is .0. For the function . fr 4 the sum of elements is also .0. This feature will be used later. The Vilenkin–Chrestenson spectrum of . f s4 is not flat, thus, this function is not bent. In function vectors of quaternary bent functions for .n = 1, just two different values are allowed under restriction that a value should appears three times, while the fourth value is different from it. Therefore, the distribution for single variable quaternary bent functions is . D = (0, 0, 1, 3). The observations as these illustrated by Example 5.1 that functions with functional expressions of a form typical for basic binary and ternary bent functions are not bent when operations are in .G F(4) motivated the usage of the Gibbs derivative defined with respect to the Reed–Muller–Fourier transform presented in Sect. 2.6, the RMF-Gibbs derivative, instead of the GF-Gibbs derivative and besides the VC-Gibbs derivative defined with respect to the Vilenkin–Chrestenson transform. Since the Gibbs coefficients in the VC-Gibbs derivatives are complex numbers, the same as the Vilenkin–Chrestenson coefficients, and bentness is determined by referring to their absolute values, we use the absolute values of the VC-Gibbs coefficients rounded to the nearest integers. Therefore, in what follows, whenever we speak of VC-Gibbs derivatives, we mean the rounded absolute values of the VC-Gibbs coefficients. Further, unlike the binary and ternary bent functions, quaternary bent functions are split into two subsets with respect to the sum of values in their function vectors, equivalently, in the vectors of the RMF-Gibbs derivatives, equal to either .0 or .2 modulo .4. This requirement corresponds to the similar requirement for binary bent functions defined in terms of the Hamming weight where also two subsets are distinguished. Recall also that for binary bent functions, the sums of their positive and negative Gibbs coefficients must be mutually equal so that their total sum is .0. For ternary functions, the sum of function values in the function vector of a bent function must be .0 modulo .3. For quaternary bent functions, the sum of function values in the function vector can be either .0, or .2 modulo .4. Each of these subsets of quaternary bent functions can be further

124

5 Gibbs Characterization of a Class of Quaternary Bent Functions

split into classes of functions sharing the same RMF-Gibbs derivative. It is similar when the VC-Gibbs derivative is considered, as it will be discussed below. The class of functions having the sum of function values equal to .0 modulo .4 can be expressed in terms of the Gibbs characterization of single variable quaternary bent functions. Recall that binary and ternary bent functions are characterized in terms of multiples of the eigenfunction of the VC-Gibbs derivative and the GF-Gibbs derivative. The characterization is also done in terms of the distribution of values in the VC-Gibbs derivative. For quaternary bent functions with the sum of values equal to .0, the characterization is done in terms of the eigenfunction of the RMF-Gibbs derivative, its powers and multiples, and also the RMFGibbs derivatives of quaternary bent functions for .n = 1. In the case when the sum of values in the function vector of a quaternary function is .2 modulo .4, such a characterization is still unsolved.

5.1

Quaternary Bent Functions for .n = 1

In this section, we discuss relationships between quaternary bent functions in a single variable and their RMF-Gibbs derivatives and VC-Gibbs derivatives.

5.1.1

Classes of Quaternary Bent Functions for .n = 1 in Terms of the RMF-Gibbs Derivative

Table 5.1 shows all quaternary bent functions for.n = 1, their Vilenkin–Chrestenson spectra, and the RMF-Gibbs derivatives. It should be noticed that some functions are just different encoding of certain others, but they are still viewed as different functions in the same way as in the binary case functions which are complements of each other, i.e., functions with different Hamming weight, are considered as different functions. Recall that in the binary case, there are two possible values for the Hamming weight of bent functions. Since these are even numbers, the sum of function values in the function vector of binary bent functions is .0 modulo .2. It can be observed that the set of .32 quaternary bent functions in a single variable, out of the total of .256 functions for .n = 1, can be split into subsets of functions for which the sum of function values computed modulo .4 is either .0 or .2. The sum of RMF-Gibbs coefficients is also .0 or .2 modulo .4. These values correspond to each other. When the sum of function values is .σ f = 0, the sum of its RMF-Gibbs coefficients is .σ R M F = 0 modulo .4, and the same is for .σ f = 2 and .σ R M F = 2. Each of these two subsets can be further split into two subsets of functions sharing the same RMF-Gibbs derivative. Notice that in this table, the functions . f 1 , . f 5 , . f 9 , . f 13 , . f 17 , . f 21 , . f 25 , . f 29 , where the index of the function corresponds to the row in the table where the function appears, are a kind of basis functions in the sense that the three following functions are derived by adding

5.1

Quaternary Bent Functions for n = 1

125

Table 5.1 Quaternary bent functions for .n = 1 arranged by the RMF-Gibbs derivatives .σ f

.σ D

1.

.F

= [0002]T

.S f

= [2, −2i, 2, 2i]T

.D R M F

= [0002]

.2

.2

2.

.F

= [1113]T

.S f

= [2i, 2, 2i, −2]T

.D R M F

= [0002]T

.2

.2

3.

.D R M F

= [0002]T

.2

.2

4.

.F = [2220]T .F = [3331]T

.D R M F

= [0002]T

.2

.2

5.

.F

.D R M F

= [0002]T

.2

.2

6.

.2

.2

.2

8.

.F

= [3313]T

.2

.2

9.

.F

= [0200]T

.2

.2

10.

.F

= [1311]T

.2

.2

11.

.F

= [2022]T

.2

.2

12.

.2

.2

13.

.F = [3133]T .F = [2000]T

.2

.2

14.

.F

= [0222]T

.2

.2

15.

.F

= [3111]T

.2

.2

16.

.F

= [1333]T

.2

.2

17.

.F

= [0103]T

.0

.0

18.

.0

.0

19.

.F = [1210]T .F = [2321]T

.0

.0

20.

.F

= [3032]T

.0

.0

21.

.F

= [0121]T

.0

.0

22.

.F

= [1232]T

.0

.0

23.

.F

= [2303]T

.0

.0

24.

.0

.0

25.

.F = [3010]T .F = [1012]T

.0

.0

26.

.F

= [2123]T

.0

.0

27.

.F

= [3230]T

.0

.0

28.

.F

= [0301]T

.0

.0

29.

.F

= [0323]T

.0

.0

30.

.0

.0

31.

.F = [1030]T .F = [2101]T

.0

.0

32.

.F

.D R M F = [0002]T .D R M F = [0002]T .D R M F = [0002]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0200]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0121]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T .D R M F = [0323]T

.2

7.

.F = [1131]T .F = [2202]T

.0

.0

.F

.S f

= [0020]T

= [3212]T

.D R M F, f

.S f = [−2, 2i, −2, −2i]T .S f = [−2i, −2i, −2i, 2]T .S f = [2, 2, −2, 2]T .S f = [2i, 2i, −2i, 2i]T .S f = [−2, −2, 2, −2]T .S f = [−2i, −2i, 2i, −2i]T .S f = [2, 2i, 2, −2i]T .S f = [2i, −2, 2i, 2]T .S f = [−2, −2i, −2, 2i]T .S f = [−2i, 2, −2i, −2]T .S f = [2, −2, −2, −2]T .S f = [−2, 2, 2, 2]T .S f = [2i, −2i, −2i, −2i]T .S f = [−2i, 2i, 2i, 2i]T .S f = [2, 2, 2, −2]T .S f = [2i, 2i, 2i, −2i]T .S f = [−2, −2, −2, 2]T .S f = [−2i, −2i, −2i, 2i]T .S f = [2i, 2, −2i, 2]T .S f = [−2, 2i, 2, 2i]T .S f = [−2i, −2, 2i, −2]T .S f = [2, −2i, −2, −2i]T .S f = [2i, −2i, 2i, 2i]T .S f = [−2, 2, −2, −2]T .S f = [−2i, 2i, −2i, −2i]T .S f = [2, −2, 2, 2]T .S f = [−2i, 2, 2i, 2]T .S f = [2, 2i, −2, 2i]T .S f = [2i, −2, −2i, −2]T .S f = [−2, −2i, 2, −2i]T

RM F

126

5 Gibbs Characterization of a Class of Quaternary Bent Functions

the constants .1, 2, 3 to each of these functions. For example, . f 2 = f 1 ⊕ 1, . f 3 = f 1 ⊕ 2, f 4 = f 1 ⊕ 3. Recall that adding a constant to a function is a spectral invariant operation, which in the case of bent functions preserves bentness. The first subset determined with respect to the RMF-Gibbs derivative consists of functions taking three equal values while the fourth value is different. In terms of a distribution, this can be expressed as . D = (0, 0, 1, 3). This is similar to the ternary case for .n = 1, where two function values should be equal and the third is different. For ternary bent functions in a single variable, the sum of the function values modulo .3 is either .1 or .2. For the larger number of variables, the sum of function values of a ternary bent function is .0 computed modulo .3. The other subset are functions having function vectors with two equal values while the third and fourth values are different, which in terms of the distribution is . D = (0, 1, 1, 2). The sum of all elements in the function vector equals .0 modulo .4. The sum of Gibbs-RMF coefficients also equals .0 computed modulo .4. Functions .1, .9, .21, .29 have function vectors equal to the vectors of their RMF-Gibbs derivative, while for functions .4, .10, .11, .12, .14, .16, .21, .29 this equality holds up to the encodings shown in Table 5.2. Table 5.3 shows a classification of quaternary bent functions for .n = 1 in terms of the RMF-Gibbs derivative into four classes. It should be noticed that the RMF-Gibbs derivative for Class.4 is actually the derivative for the class.3 multiplied by.3 modulo.4. It should be also noticed that some functions are just a different encoding of certain others. Also, functions in Classes .1 and .2 with the same RMF-Gibbs derivative could be viewed as shifted versions of other functions, or obtained as different polarity functions . f = g ⊕ k, for .k = 1, 2, 3. For

.

Table 5.2 Example of functions with different encoding in the RMF-Gibbs derivative

.

f

Encoding in .D R M F

2

.2

↔ 0, .0 ↔ 2,

3

.1

↔ 0, .3 ↔ 2,

4

.3

↔ 0, .1 ↔ 2,

10

.2

↔ 0, .0 ↔ 2,

11

.1

↔ 0, .3 ↔ 2,

12

.3

↔ 0, .1 ↔ 2,

22

.1

↔ 0, .2 ↔ 1, .3 ↔ 2,

23

.2

↔ 0, .3 ↔ 1, .0 ↔ 2,

24

.3

↔ 0, .0 ↔ 1, .1 ↔ 2,

30

.1

↔ 0, .0 ↔ 3, .3 ↔ 2,

31

.2

↔ 0, .1 ↔ 3, .0 ↔ 2,

32

.3

↔ 0, .2 ↔ 3, .1 ↔ 2

5.1

Quaternary Bent Functions for n = 1

127

Table 5.3 Classes of quaternary bent functions for .n = 1 in terms of the RMF-Gibbs derivative Class

Derivative

.σ f

.σ(D

1

.D f

= [0002]T

.1

−8

.2

.2

2

.D f

= [0200]T

.9

− 16

.2

.2

3

.D f

= [0121]T

.17

− 24

.0

.0

4

T .D f = [0323]

.25

− 32

.0

.0

Functions

RM F )

example, the function vector for . f 1 is the function vector for . f 2 , . f 3 , and . f 4 in encodings 0 ↔ 2, .0 ↔ 1, .0 ↔ 3.

.

Remark 5.1 For .n = 1, the set of all .32 ternary bent functions can be split into four classes with respect to their RMF-Gibbs derivatives as summarized in Table 5.1. The first two classes correspond to functions for which the sum of function values .σ f as well as of their RMFGibbs coefficients .σ D R M F is .2 modulo .4. The other two classes correspond to functions for which the sum of function values .σ f as well as of their RMF-Gibbs coefficients .σ D R M F is .0 modulo .4. Example 5.2 For .n = 1, . p = 4, the function . f (x) = x 3 ⊕ 3x 2 is bent, since its Vilenkin– Chrestenson spectrum is . S f = [2, 2i, 2, −2i]T . The function vector is .F = [0200]T , and the vector of RMF-Gibbs coefficients is .D R M F = [0200]T . By inspection of Table 5.1, it is as follows. Remark 5.2 A quaternary function for .n = 1 is bent if 1. The sum of elements in both the function vector .F and its RMF-Gibbs derivative . D R M F is equal to .2 modulo .4, where the RMF-Gibbs derivative of . f is equal to either (a) . D R M F = [0002]T or (b) . D R M F = [0200]T . 2. The sum of elements in both the function vector .F and its RMF-Gibbs derivative . D R M F is equal to .0 modulo .4, where the RMF-Gibbs derivative of . f is equal to either (a) . D R M F = [0121]T or (b) . D R M F = [0323]T .

128

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Recall that in the case of ternary functions, a necessary condition for a function to be bent is that the sum of its function values is .0 modulo .3 [4].

5.1.2

Classes of Quaternary Bent Functions for .n = 1 in Terms of the VC-Gibbs Derivative

Table 5.4 shows all .32 quaternary bent functions for .n = 1 and the absolute values of their VC-Gibbs derivatives. These values are computed for function values encoded as in computing the Vilenkin–Chrestenson spectra, i.e., as .(0, 1, 2, 3) → (1, i, −1, −i), and the absolute values are converted into integers by using the function .r ound in Matlab. It can be observed that all quaternary bent functions for .n = 1 have the sum of VC-Gibbs coefficients equal to .2 modulo .4, irrespective of the sum of their function values which could be either .0 or .2 modulo .4. For functions with the sum of function values .0, the VC-Gibbs derivatives are .DV C = [1113]T and shifted versions of it. If the sum of function values is T .0, then the VC-Gibbs derivative is .D V C = [0222] or a shifted version of it. It should be noticed that functions whose function vectors are identical up to the encoding have identical VC-Gibbs derivatives. Therefore, given the VC-Gibbs derivative of a bent function . f , a few other bent functions derived from . f by various encoding of their values have the same VC-Gibbs derivative. Functions whose function vectors are cyclic shifted versions of the function vector of a given bent function . f have the VC-Gibbs derivative which is the shifted version of that for . f . Example 5.3 In Table 5.4, functions in rows .2, .3, .14 are derived from the function in the first row by encodings f1 → f2 0 ↔ 2 f 1 → f 3 0 → 1, 2 → 3 f 1 → f 4 0 → 3, 2 → 1. These function have the same VC-Gibbs derivative. The function in the fifth row is the shifted version of the function in the first row. Its VC-Gibbs derivative is the shifted version of the VC-Gibbs derivative for the function in the first row.

Remark 5.3 A quaternary function for .n = 1 is bent if 1. The sum of elements in the function vector .F as well as the sum of its VC-Gibbs coefficients . DV C is equal to .2 modulo .4. The VC-Gibbs derivative of . f is equal to T .D V C = [1113] or a shifted version of it. 2. The sum of elements in the function vector .F is equal to .0 modulo .4 and the sum of its VC-Gibbs coefficients . DV C is equal to .2 modulo .4. The VC-Gibbs derivative of . f is equal to .DV C = [0222]T or a shifted version of it.

5.1

Quaternary Bent Functions for n = 1

129

Table 5.4 Quaternary bent functions for .n = 1 arranged by the absolute values of the VC-Gibbs derivatives .F

.S f

.D f

.σ f

.σ D

.S f = [2, −2i, 2, 2i]T

.2

.2

.2

3.

.F

.2

.2

4.

.D V C = [1113]T .D V C = [1113]T .D V C = [1113]T .D V C = [1113]T .D V C = [1131]T .D V C = [1131]T .D V C = [1131]T .D V C = [1131]T .D V C = [1311]T .D V C = [1311]T .D V C = [1311]T .D V C = [1311]T .D V C = [3111]T .D V C = [3111]T .D V C = [3111]T .D V C = [3111]T .D V C = [0222]T .D V C = [0222]T .D V C = [0222]T .D V C = [0222]T .D V C = [2022]T .D V C = [2022]T .D V C = [2022]T .D V C = [2022]T .D V C = [2202]T .D V C = [2202]T .D V C = [2202]T .D V C = [2202]T .D V C = [2220]T .D V C = [2220]T .D V C = [2220]T .D V C = [2220]T

.2

2.

.F = [0002]T .F = [2220]T

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

.0

.2

1.

.S f

= [−2, 2i, −2, −2i]T

= [1113]T

.S f

= [2i, 2, 2i, −2]T

.F

= [3331]T

.S f

= [−2i, −2i, −2i, 2]T

5.

.F

= [0020]T

.S f

= [2, 2, −2, 2]T

6.

.F

= [2202]T

.S f

= [−2, −2, 2, −2]T

7.

.F

= [1131]T

.S f

= [2i, 2i, −2i, 2i]T

8.

.F

= [3313]T

.S f

= [−2i, −2i, 2i, −2i]T

9.

.F

= [0200]T

.S f

= [2, 2i, 2, −2i]T

10.

.F

= [2022]T

.S f

= [−2, −2i, −2, 2i]T

11.

.F

= [1311]T

.S f

= [2i, −2, 2i, 2]T

12.

.F

= [3133]T

.S f

= [−2i, 2, −2i, −2]T

13.

.F

= [2000]T

.S f

= [2, −2, −2, −2]T

14.

.F

= [0222]T

.S f

= [−2, 2, 2, 2]T

15.

.F

= [3111]T

.S f

= [2i, −2i, −2i, −2i]T

16.

.F

= [1333]T

.S f

= [−2i, 2i, 2i, 2i]T

17. 18.

.F = [0103]T .F = [1210]T

19.

.F

20.

.S f = [2, 2, 2, −2]T .S f

= [2i, 2i, 2i, −2i]T

= [2321]T

.S f

= [−2, −2, −2, 2]T

.F

= [3032]T

.S f

= [−2i, −2i, −2i, 2i]T

21.

.F

= [0121]T

.S f

= [2i, 2, −2i, 2]T

22.

.F

= [1232]T

.S f

= [−2, 2i, 2, 2i]T

23.

.F

= [2303]T

.S f

= [−2i, −2, 2i, −2]T

24.

.F

= [3010]T

.S f

= [2, −2i, −2, −2i]T

25.

.F

= [1012]T

.S f

= [2i, −2i, 2i, 2i]T

26.

.F

= [2123]T

.S f

= [−2, 2, −2, −2]T

27.

.F

= [3230]T

.S f

= [−2i, 2i, −2i, −2i]T

28.

.F

= [0301]T

.S f

= [2, −2, 2, 2]T

29.

.F

= [0323]T

.S f

= [−2i, 2, 2i, 2]T

30. 31.

.F = [1030]T .F = [2101]T

32.

.F

= [3212]T

.S f = [2, 2i, −2, 2i]T .S f

= [2i, −2, −2i, −2]T

.S f

= [−2, −2i, 2, −2i]T

130

5.2

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Quaternary Bent Functions for .n = 2

Conclusions for single variable quaternary bent functions can be extended to two variable 2 functions. The number of quaternary functions for .n = 2, that is .44 = 4294967296, is so large that it is hard to expect that we can do an exhaustive search and find all of them and select bent functions in a reasonable time. Therefore, we examined subsets of quaternary functions. It is observed that, as in the case of functions for .n = 1, except for bent functions, there are no other functions for which simultaneously the sum of both function values as well as of their RMF-Gibbs coefficients is either .2 or .0 computed modulo .4. Therefore, quaternary bent functions in two variables can be split into two classes with respect to the sum of their function values, respectively the RMF-Gibbs coefficients. The necessary condition for a quaternary function . f to be bent is that either 1. The sum of elements in both the function vector .F and its RMF-Gibbs derivative . D f is equal to .2 computed modulo .4, or 2. The sum of elements in both the function vector .F and its RMF-Gibbs-derivative . D f is equal to .0 computed modulo .4. Remark 5.4 For .n = 2, the set of quaternary bent functions can be split into two disjoint subsets with equal number of elements, i.e., the functions corresponding to the two subsets enumerated above. Both subsets of quaternary bent functions can be further split into classes of functions sharing the same RMF-Gibbs derivative. For functions whose sum of elements modulo .4 is equal to .0, the RMF-Gibbs derivatives can be expressed in terms of the RMF-Gibbs derivatives for single variable quaternary functions. Their RMF-Gibbs derivative is equal to the function .k · φ(2) = kx1 x2 , for .k = 1, 2, 3, and .x1 , x2 ∈ {0, 1, 2, 3}, or functions derived as the Kronecker product of the function .φ(1) for .n = 1, its powers and multiples, as well as the RMF-Gibbs derivatives of quaternary bent functions for .n = 1. We could not find such a simple description of classes of bent functions whose sum of elements modulo .4 is equal to .2. For .n = 1, we consider the functions φ(1) = [0123]T , 3φ(1) = [0321]T , 3φ(1)2 = [0303]T , . 3φ(1)3 = [0301]T , D f1 = [0002]T , D f3 = [0121]T ,

2φ(1) = [0202]T , φ(1)2 = [0101]T , φ(1)3 = [0103]T ,

(5.1)

D f2 = [0200]T , D f4 = [0323]T ,

where powers of .φ(1) are computed componentwise, i.e., as the Hadamard products of φ(1) with itself. These functions are used to describe the RMF-Gibbs derivatives for bent

.

5.2

Quaternary Bent Functions for n = 2

131

functions in two variables whose sum of elements in the function vector and the sum of the RMF-Gibbs coefficients is .0 modulo .4. Notice that 2φ(1)2 = [0202]T = 2φ(1),

.

2φ(1)3 = [0202]T = 2φ(1)2 . Further, consider functions φ(2) = [0000012302020321]T = [0123] ⊗ [0123] = φ(1) ⊗ φ(1),

.

φ(2)2 = [0000010100000101]T = [0101] ⊗ [0101] = φ(1)2 ⊗ φ(1)2 , φ(2)3 = [0000010300000301]T = [0103] ⊗ [0103] = φ(1)3 ⊗ φ(1)3 , 2φ(2) = [0000020200000202]T = [0101] ⊗ [0202] = φ(1)2 ⊗ 2φ(1)2 , = [0202] ⊗ [0303] = 2φ(1)2 ⊗ 3φ(1)2 ,

(5.2)

3φ(2) = [0000032102020123] = [0103] ⊗ [0321] = φ(1) ⊗ 3φ(1), T

3

3φ(2)2 = [0000030300000303]T = [0101] ⊗ [0303] = φ(1)2 ⊗ 3φ(1)2 , 3φ(2)3 = [0000030100000103]T = [0103] ⊗ [0301] = φ(1)3 ⊗ 3φ(1)3 . Notice that with powers computed componentwise 2φ(2)2 = [0000020200000202]T = 2φ(2),

.

2φ(2)3 = [0000020200000202]T = 2φ(2). Functions in (5.1) and (5.2) and the function .φ(2) = x1 x2 can be used to express RMFGibbs-derivatives of bent functions for .n = 2 whose sum of function values is .0 modulo .4. Example 5.4 Table 5.5 shows randomly selected examples of quaternary bent functions for n = 2 and their RMF-Gibbs derivatives expressed in terms of.φ(2) and functions in (5.1) and (5.2). All these functions have different RMF-Gibbs derivatives. The sum of function values is .0 modulo .4, and it is the same for the sum of the Gibbs coefficients in the RMF-Gibbs derivative.

.

Table 5.6 shows the VC-Gibbs derivatives for functions in Table 5.5. Table 5.7 shows the distribution of absolute values of VC-Gibbs coefficients.

132

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Table 5.5 Examples of quaternary bent functions for .n = 2 and their RMF-Gibbs derivatives Function .F1

RMF-Gibbs derivative

= [0000200202020022]T

.

T .F2 = [0000301221030202]

= [0002011222021021]T = [0001211312132012]T

.F5

= [3223200221120202]T

.F6

= [3232311312120220]T

= [0000010102020101]T = [0121] ⊗ [0101] = D f 3 ⊗ φ(1)2

.DR M F .

.F4

= [0000012300000123]T = [0101] ⊗ [0123] = φ(1)2 ⊗ φ(1)

.DR M F .

.F3

= [0000020200000202]T = 2φ(2)

.DR M F

= [0000030300000303]T = 3φ 2 (2)

.DR M F .

= [0000030302020101]T = [0123] ⊗ [0303] = φ(1) ⊗ 3φ(1)2

.DR M F .

= [0000032102020321]T = [0323] ⊗ [0123] = D f 4 ⊗ φ(1)

.DR M F .

Table 5.6 Quaternary bent functions in Table 5.5 and their VC-Gibbs derivatives encoded Function

VC-Gibbs derivative

= [0000200202020022]T

. DV C

= [6, 4, 6, 12, 14, 7, 6, 8, 7, 14, 7, 6, 6, 7, 14, 8]T

T .F2 = [0000301221030202] T .F3 = [0002011222021021] T .F4 = [0001211312132012] T .F5 = [3223200221120202] T .F6 = [3232311312120220]

. DV C

= [8, 6, 4, 10, 11, 6, 9, 5, 16, 5, 7, 9, 10, 10, 4, 11]T

. DV C

= [9, 6, 5, 5, 10, 4, 7, 4, 14, 9, 12, 5, 12, 9, 13, 9]T

. DV C

= [11, 6, 9, 14, 11, 4, 3, 11, 7, 10, 4, 11, 6, 8, 5, 11]T

. DV C

= [12, 8, 11, 10, 10, 10, 6, 6, 9, 4, 7, 3, 15, 7, 11, 4]T

. DV C

= [9, 5, 9, 5, 11, 9, 8, 9, 13, 5, 7, 9, 12, 5, 4, 12]T

.F1

Table 5.7 Distributions of values in VC-Gibbs derivatives of functions in Table 5.6 Function

Distribution of values in VC-Gibbs derivative

1.

4(1),6(5),7(4),8(2),12(1),14(3)

2.

4(2),5(2),6(2),7(1),8(1),9(2),10(3),11(2),16(1)

3.

4(2),5(3),6(1),7(1),9(4),10(1),12(2),13(1),14(1)

4.

3(1),4(2),5(1),6(2),7(1),8(1),9(1),10(1),11(5),14(1)

5.

3(1),4(2),6(2),7(2),8(1),9(1),10(3),11(2),12(1),15(1)

6.

4(1),5(4),7(1),8(1),9(5),11(1),12(2),13(1)

5.2

Quaternary Bent Functions for n = 2

133

Table 5.8 Examples of quaternary bent functions for.n = 2 sharing the same RMF-Gibbs derivatives encoded Function

RMF-Gibbs derivative

T .F = [0303311301010220] T .F = [0303311301012002]

.DR M F

= [0000032102020321]T

.DR M F

= [0000032102020321]T

T .F = [1010311312120220] T .F = [1010311312122002]

.DR M F

= [0000032102020321]T

.DR M F

= [0000032102020321]T

T .F = [2121311301010220] T .F = [2121311301012002]

.DR M F

= [0000032102020321]T

.DR M F

= [0000032102020321]T

T .F = [2310001321121102] T .F = [3232311312120220]

.DR M F

= [0000032102020321]T

.DR M F

= [0000032102020321]T

.DR M F

= [0000032102020321]T

10

T .F = [3232311312122002] T .F = [0000311302020220]

.DR M F

= [0000020200000000]T

11

.F

= [0000311302022002]T

.DR M F

= [0000020200000000]T

12

T .F = [1110311202030221] T .F = [1111311302020220]

.DR M F

= [0000020200000000]T

.DR M F

= [0000020200000000]T

T .F = [1111311302022002] T .F = [2222311302020220]

.DR M F

= [0000020200000000]T

.DR M F

= [0000020200000000]T

T .F = [2222311302022002] T .F = [2333211312021220]

.DR M F

= [0000020200000000]T

.DR M F

= [0000020200000000]T

.DR M F

= [0000020200000000]T

19

T .F = [3101110322120012] T .F = [3333311302020220]

.DR M F

= [0000020200000000]T

20

T .F = [3333311302022002]

.DR M F

= [0000020200000000]T

1 2 3 4 5 6 7 8 9

13 14 15 16 17 18

Example 5.5 Table 5.8 shows examples of bent functions for .n = 2 which have the same RMF-Gibbs derivative. Functions .1 to .9 have the derivative . D R M F = [0000032102020321] = [0323] ⊗ [0123] = D f4 ⊗ φ(1). Functions .10 to .20 have the derivative . D R M F = [0000020200000000] = [0200] ⊗ [0123] = D f 2 ⊗ φ(1). Notice that the sixth function in Table 5.5 has the same RMF-Gibbs derivative as the first .9 functions in this table. Remark 5.5 The set of quaternary bent functions in two variables can be split into disjoint subsets of functions having the same RMF-Gibbs-derivative. For functions whose sum of elements in the function vector is .0, the RMF-Gibbs derivatives can be expressed as the Kronecker product of the RMF-Gibbs derivatives for single variable functions and the function .φ(1) and its powers. For classes containing functions the sum of whose values is .2, we cannot find such a characterization in terms of functions for .n = 1.

134

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Table 5.9 Examples of quaternary bent functions for .n = 2 and absolute values of their VC-Gibbs derivatives Function

VC-Gibbs derivative

.F = [0303311301010220]T .F = [0303311301012002]T

.D V C

= [5, 9, 5, 9, 12, 9, 8, 9, 3, 6, 10, 14, 4, 5, 12, 12]T

.D V C

= [10, 14, 3, 6, 9, 11, 9, 8, 5, 9, 5, 9, 12, 12, 5, 4]T

.F = [1010311312120220]T .F = [1010311312122002]T

.D V C

= [5, 9, 5, 9, 12, 4, 5, 12, 9, 7, 5, 13, 9, 8, 9, 11]T

.D V C

= [9, 7, 5, 13, 12, 5, 4, 12, 5, 9, 5, 9, 8, 9, 11, 9]T

.F = [2121311301010220]T .F = [2121311301012002]T

.D V C

= [9, 5, 9, 5, 5, 4, 12, 12, 6, 3, 1, 10, 9, 11, 9, 8]T

.D V C

= [6, 3, 14, 10, 4, 5, 12, 12, 9, 5, 9, 5, 8, 9, 11, 9]T

.F = [2310001321121102]T .F = [3232311312120220]T

.D V C

= [6, 10, 5, 15, 11, 4, 4, 12, 11, 7, 5, 9, 8, 8, 11, 10]T

.D V C

= [9, 5, 9, 5, 11, 9, 8, 9, 13, 5, 7, 9, 12, 5, 4, 12]T

.F = [3232311312122002]T .F = [0000311302020220]T

.D V C

= [7, 9, 13, 5, 9, 8, 9, 11, 9, 5, 9, 5, 12, 12, 4]T

.D V C

= [4, 8, 4, 8, 11, 4, 8, 12, 4, 7, 11, 15, 4, 8, 12, 11]T

.D V C

= [9, 6, 4, 13, 9, 5, 9, 12, 6, 10, 6, 10, 12, 9, 5, 9]T

12

.F = [0000311302022002]T .F = [1110311202030221]T

.D V C

= [7, 7, 7, 12, 8, 7, 8, 7, 4, 7, 13, 8, 6, 8, 13, 13]T

13

.F

= [1111311302020220]T

.D V C

= [6, 6, 6, 6, 9, 6, 9, 12, 4, 7, 13, 12, 5, 9, 13, 9]T

14

.F = [1111311302022002]T .F = [2222311302020220]T

.D V C

= [10, 3, 6, 12, 8, 4, 8, 14, 8, 8, 8, 8, 12, 8, 8, 8]T

.D V C

= [8, 4, 8, 4, 5, 9, 12, 9, 7, 4, 15, 11, 9, 5, 9, 12]T

.D V C

= [6, 9, 13, 4, 4, 8, 12, 11, 10, 6, 10, 6, 8, 12, 11, 4]T

17

.F = [2222311302022002]T .F = [2333211312021220]T

.D V C

= [6, 7, 7, 7, 9, 8, 12, 9, 8, 4, 13, 13, 7, 3, 8, 13]T

18

.F

= [3101110322120012]T

.D V C

= [13, 5, 8, 13, 8, 4, 8, 14, 7, 7, 6, 7, 12, 8, 7, 8]T

19

.F

= [3333311302020220]T

.D V C

= [6, 6, 6, 6, 8, 8, 12, 8, 7, 4, 12, 13, 8, 4, 8, 14]T

20

.F = [3333311302022002]T

.D V C

= [3, 10, 12, 6, 5, 9, 13, 9, 8, 8, 8, 8, 9, 12, 9, 6]T

1 2 3 4 5 6 7 8 9 10 11

15 16

Table 5.9 shows the absolute values of the VC-Gibbs derivative for functions in Table 5.8. Table 5.10 shows the distribution of absolute values of the VC-Gibbs derivative for functions in Table 5.9. Example 5.6 From Table 5.10, it can be observed that functions . f 1 , . f 2 , . f 5 , and . f 6 have the same distributions of the Gibbs coefficients in the VC-Gibbs derivative as .3(1), 4(1), 5(3), 6(1), 8(1), 9(4), 10(1), 11(1), 12(2), 14(1). Further, functions . f 3 , . f 4 , . f 8 , and . f 9 have the same distribution of these coefficients as .4(1), 5(4), 7(1), 8(1), 9(5), 11(1), 12(2), 13(1). In this example, we discuss the first subset of functions mutually related by the same distribution of values in VC-Gibbs coefficients. Similar conclusions can be derived for the other subset. In the original domain, functions . f 1 and . f 2 have the same distribution of function values as .0(6), 1(4), 2(2), 3(4). They differ just in the permutation of the last four function values. It is the same for functions . f 5 and . f 6 which also have the same distribution of function values as .0(4)1(6)2(4)3(2), but it is different from the distribution of function values in . f 1 and . f 2 . These pairs of functions are not related by encoding. Since there are .6 values .0

5.2

Quaternary Bent Functions for n = 2

135

Table 5.10 Distribution of absolute values of VC-Gibbs derivatives for functions in Table 5.9 Function

Distribution of values in VC-Gibbs derivative

1

.

f1

3(1),4(1),5(3),6(1),8(1),9(4),10(1),11(1),12(2),14(1)

2

.

f2

3(1),4(1),5(3),6(1),8(1),9(4),10(1),11(1),12(2),14(1)

3

.

f3

4(1),5(4),7(1),8(1),9(5),11(1),12(2),13(1)

4

.

f4

4(1),5(4),7(1),8(1),9(5),11(1),12(2),13(1)

5

.

f5

3(1),4(1),5(3),6(1),8(1),9(4),10(1),11(1),12(2),14(1)

6

.

f6

3(1),4(1),5(3),6(1),8(1),9(4),10(1),11(1),12(2),14(1)

7

.

f7

4(2),5(2),6(1),7(1),8(2),9(1),10(2),11(3),12(1),15(1)

8

.

f8

4(1),5(4),7(1),8(1),9(5),11(1),12(2),13(1)

9

.

f9

4(1),5(4),7(1),8(1),9(5),11(1),12(2),13(1)

10

.

f 10

4(5),7(1),8(4),11(3),12(2),15(1)

11

.

f 11

4(1),5(2),6(3),9(5),10(2),12(2),13(1)

12

.

f 12

4(1),6(1),7(6),8(4),12(1),13(3)

13

.

f 13

4(1),5(1),6(5),7(1),9(4),12(2),13(2)

14

.

f 14

3(1),4(1),6(1),8(9),10(1),12(2),14(1)

15

.

f 15

4(3),5(2),7(1),8(2),9(4),11(1),12(2),15(1)

16

.

f 16

4(3),6(3),8(2),9(1),10(2),11(2),12(2),13(1)

17

.

f 17

3(1),4(1),6(1),7(4),8(3),9(2),12(1),13(3)

18

.

f 18

4(1),5(1),6(1),7(4),8(5),12(1),13(2),14(1)

19

.

f 19

4(2),6(4),7(1),8(5),12(2),13(1),14(1)

20

.

f 20

3(1),5(1),6(2),8(4),9(4),10(1),12(2),13(1)

in the distribution for . f 1 and . f 2 and .6 values .1 in the distribution for . f 5 and . f 6 , a single possibility for encoding is .0 ↔ 1. Then, it remains .2 ↔ 3. Such a replacement of values in either . f 1 or . f 2 does not produce . f 4 or . f 5 , since in the obtained function vectors the first element should be .1, while in . f 5 and . f 2 it is .2. In particular, a possible encoding is .0 ↔ 1, and .2 ↔ 3. This encoding applied to . f 1 produces a function . f e whose function vector is .Fe = [1, 2, 1, 2, 2, 0, 0, 2, 1, 0, 1, 0, 1, 3, 3, 1]T , which is bent since its Vilenkin– Chrestenson spectrum is S fe = [4i, −4, 4i, 4i, −4, −4, 4, 4i, 4i, 4, 4i, −4i, −4, 4, 4, −4i]T .

.

The VC-Gibbs derivative is DV C, fe = [5, 13, 9, 7, 9, 11, 9, 8, 5, 9, 5, 9, 5, 12, 12, 4]T .

.

The distribution of the VC-Gibbs coefficients for . f e is the same as for these four functions, i.e., .4(1), 5(4), 7(1), 8(1), 9(5), 11(1), 12(2), 13(1). The RMF-Gibbs derivative of . f e is

136

5 Gibbs Characterization of a Class of Quaternary Bent Functions

D R M F, f e = [0, 0, 0, 0, 0, 1, 2, 3, 0, 2, 0, 2, 0, 1, 2, 3]T ,

.

which, as we can see from Table 5.8, is .3 times the RMF-Gibbs derivative for the considered functions. If in . f 1 we use just .0 ↔ 1 and two other values remain at their present positions, we obtain the function vector F = [1, 3, 1, 3, 3, 0, 0, 3, 1, 0, 1, 0, 1, 2, 2, 1]T ,

.

and the corresponding function is not bent.

5.3

Experiments for Quaternary Bent Functions in .n = 2 Variables

Quaternary bent functions are represented by the RMF-expressions in terms of the following basic functions [ ] [ ] X(2) = 1 x1 x1∗2 x1∗3 ⊗ 1 x2 x2∗2 x2∗3 [ = 1 x2 x2∗2 x2∗3 x1 x1 x2 x1 x2∗2 x1 x2∗3

.

] x1∗2 x1∗2 x2 x1∗2 x2∗2 x1∗2 x2∗3 x1∗3 x1∗3 x2 x1∗3 x2∗2 x1∗3 x2∗3 ,

where the symbol .∗ is used for the Gibbs exponentiation defined in Chap. 1. We allowed that non-zero coefficients are assigned to terms of the power .2 and .3, i.e., to terms as for instance .x1 x2 and .x1∗2 for the second order, and .x1 x2∗2 for the third order. If we count the coefficients in the Hadamard order from .0 to .15, these non-zero coefficients are at the positions.2,.3,.5,.6,.8,.9,.13. By assigning values from.{0, 1, 2, 3}, we found.400 functions with a flat spectrum. For these functions, there are .163 different VC-Gibbs derivatives with rounded absolute values of the coefficients. To each of these functions we can add linear terms, variables .x1 , .2x1 , .3x1 , .x2 , .2x2 , .3x2 , and all their sums, also a constant either .1, .2, or .3. This makes .25.600 bent functions. For these functions, there are .217 different VC-Gibbs derivatives, i.e., with different vectors of rounded absolute values. We repeated the experiment allowing non-zero coefficients assigned to basis functions with powers less than or equal to .4, without linear terms. Included are also positions .7, .10, and .13. There are .1152 quaternary bent functions in two variables, with .386 different VC-Gibbs derivatives. By adding linear terms and constants, there are .1152 × 64 = 73728 functions. For these functions, there are .456 different VC-Gibbs derivatives. We finally allowed non-zero coefficients also at the positions .11 and .14, and produced .2112 bent functions in two variables, with .780 different VC-Gibbs derivatives. After adding linear terms and just the constant .1, there are .33.792 functions with .911 different VC-Gibbs derivatives.

5.3

Experiments for Quaternary Bent Functions in .n = 2 Variables

137

Then, we tried several examples by adding other constants, .2 and .3, and it appears that in this case the VC-Gibbs derivative remains the same. It means that there will be the same number of .911 different VC-Gibbs derivatives for the total of .2112 × 64 = 135.168 functions.

5.4

Binary and Quaternary Bent Functions

Various generalizations of binary bent functions have some applications in both binary- and multiple-valued domain. The generalized Boolean functions having binary variables, but taking four different values, are of a special interest due to simple realizations. In this chapter, we explain how relationships between binary bent functions and generalized Boolean bent functions with quaternary values can be used to construct these functions. More precisely, the generalized Boolean bent functions as defined below are constructed from binary bent functions by using Gibbs permutation matrices. There are generalizations of the concept of bent functions to other domains as the ring of integers modulo .q, . Z q , with the case .q = 4 being especially interesting [6–10] due to some applications to mention just the reduction of the peak-to-power ratio to the lowest possible value in multi-code code-division multiple access systems (MC-CDMA) [11], and the design of vectorized stream cipher systems. The generalizations were done to different algebraic structures as domains for bent functions including Abelian and non-Abelian groups [12–17] with English translation in [18]. Another approach to the generalization of the concept of bentness preserves . Z 2n as the domain for Boolean bent functions but allows the function values to be taken in the ring . Z q of integers smaller than .q, with again the case .q = 4 as the most prominent example [11]. This class of bent functions is the subject of considerations in this section, and we use the relationships between the quaternary and binary valued Boolean bent functions studied in [19]. For detailed discussions of the generalizations of bent functions, we refer to [7, 20–22]. Quaternary functions, i.e., functions taking four different values, can be viewed in two different ways, as either 1. Quaternary .n-variable functions on .C4n or 2. Generalized Boolean functions in .2n variables on .C22n . In the first case, a quaternary function can be written as .g(2x1 + x2 ) = f (x1 , x2 ) where x1 and .x2 are coordinates in the binary representation of elements of the set .{0, 1, 2, 3}. In the second case, . f (x1 , x2 ) = 2g1 (x1 , x2 ) + g2 (x1 , x2 ), which establishes a connection between these two interpretations of functions taking four different values.

.

138

5 Gibbs Characterization of a Class of Quaternary Bent Functions

As pointed in [23], the following statements are equivalent: 1. The generalized Boolean function . f in .2n variables is bent. 2. The Boolean functions .g1 and .g1 + g2 in .2n variables are both bent. Example 5.7 The quaternary function . f specified by the function vector .F = [0323]T is bent since its Vilenkin–Chrestenson spectrum is flat.S f = [−2i, 2, 2i, 2]T . This function can be converted into two binary functions .g1 and .g2 by the binary representation of quaternary values. Thus, the function vectors for these functions are .G1 = [0111] and .G2 = [0101]T . The function.g1 ⊕ g2 is specified by the truth-vector.G1,2 = G1 ⊕ G2 = [0010]T , where the addition is performed componentwise. In the .(0, 1) → (1, −1) encoding, the corresponding function vectors are .G1,e = [1, −1, −1, −1]T and .G1,2,e = [1, 1, −1, 1]T . The functions .g1 and .g1 ⊕ g2 are bent, and can be characterized in terms of the Gibbs derivatives for functions in two binary variables defined with respect to the Walsh transform [3, 24, 25] discussed in Chap. 2. This derivative for .n = 2 is defined by ⎡

⎤ −3 1 2 0 ⎥ 1⎢ ⎢ 1 −3 0 2 ⎥ . .D = ⎣ 2 0 −3 1 ⎦ 2 0 2 1 −3 The Gibbs derivative of these functions is equal to the eigenfunction of the derivative with permuted values and the sign .(−) assigned to the Gibbs coefficients at the positions corresponding to the positions where the functions .g1 and .g1 ⊕ g2 take the value T .−1 in the encoding .(0, 1) → (1, −1). Therefore, .Dg1 = [3, −1, −2, 0] , and .Dg1 +g2 = T [2, 0, −3, 1] . Recall that the zero value can correspond to either .1 or .−1.

5.5

Generalized Four-Valued Bent Functions

In this section, we consider a particular class of the so-called generalized bent functions, which can be viewed as a connection between the binary and quaternary bent functions in the sense that they share the domain with binary and the range with quaternary bent functions. Binary bent functions are a mapping . f : Z 2n → Z 2 , where . Z 2 is the ring of nonnegative integers smaller than.2, and.n is the number of variables. The generalized quaternary bent functions are a mapping . f : Z 2n → Z 4 , where . Z 4 is the ring of non-negative integers smaller than.4. Thus, they are functions in binary variables, but take four values conveniently identified with the integers .0, .1, .2, .3. Besides the academic interest in such mathematical objects, there are some applications of these bent functions making them worth studying. Two such applications are the reduction of the peak-to-power ratio to the lowest possible value in multi-code code-division multiple

5.5

Generalized Four-Valued Bent Functions

139

access systems (MC-CDMA) [16], and the design of vectorized stream cipher systems. For more details on thus generalized bent functions, we refer to [7, 10, 22]. For .q = 4, we assume that . Z 4n = Z 2n × Z 2n . Thus, with .x, y ∈ Z 2n , a generalized Boolean function can be expressed in terms of two Boolean functions .b, c : Z 22n → Z 2 , as . f (x, y) = 2b(x, y) + c(x, y), where .+ denotes the addition in . Z [11]. As for the Boolean functions, a generalized Boolean function is bent iff all its Walsh spectral coefficients have the same absolute value equal to .2n/2 [11, 19]. Recall that in the spectral characterization of bentness, the related Fourier transform is determined by the domain of the variables, not by the function values. Therefore, for both Boolean and generalized Boolean bent functions the Walsh transform is used, while for the functions in quaternary variables the Vilenkin–Chrestenson transform is used [26]. It is assumed that for computing the Walsh spectrum, the function values are encoded by .q-th roots of unity. Therefore, for .q = 2 and .q = 4, we use the encodings .(0, 1) → (1, −1), and .(0, 1, 2, 3, ) → (1, i, −1, −i), respectively. Function vectors after this encoding will be identified by adding an .i to the index of the original function vector. Unlike binary bent functions, in the case of generalized Boolean functions the number of variables .n should not necessarily be even [19]. In [19] is proven a theorem about relationships between the bentness properties of generalized Boolean functions . f and the related component Boolean functions .b and .c in terms of which . f is represented. Theorem 5.1 If a generalized Boolean bent function in .n quaternary variables is represented in terms of two binary valued Boolean functions in .2n binary variables as . f (x, y) = 2b(x, y) + c(x, y), then the Boolean functions .b and .r = b ⊕ c, where .⊕ is the bitwise addition modulo .2, are both bent binary valued Boolean functions. The property stated in this theorem will be used later to generate generalized Boolean bent functions. In what follows, in the case of binary valued Boolean bent functions we simply call them bent functions. The symbol .⊕ will be used both for the operation between two bits and the bitwise operation between two .n-tuples.

5.6

Construction of Generalized Boolean Bent Functions

In this section, we discuss three ways of constructing generalized Boolean bent functions by using permutation matrices assigned to binary valued bent functions through their characterization in terms of Gibbs derivatives.

140

5.6.1

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Straightforward Algorithm

Theorem 5.1 from [19] about the relationship between binary bent functions and generalized Boolean bent functions provides a straightforward way for constructing generalized Boolean bent functions. 1. Select two Boolean bent functions . f 1 and . f 2 . 2. Compute .c = f 1 ⊕ f 2 . 3. Determine a new generalized Boolean bent function as .

f new1 = 2 f 1 + c,

.

f new2 = 2 f 2 + c.

or as

The following example illustrates this procedure. Example 5.8 Given two Boolean functions . f 1 and . f 2 by their function vectors F1 = [0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 1, 1, 0, 1]T ,

.

F2 = [0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 0, 1, 1, 0, 1]T , which are bent, since after encoding .(0, 1) → (1, −1) F1i = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, −1, 1, −1, −1, 1, −1]T ,

.

F2i = [1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, 1, −1, −1, 1, −1]T , their Walsh spectra are computed as S f1 = [4, 4, 4, −4, 4, −4, 4, 4, 4, 4, 4, −4, −4, 4, −4, −4]T ,

.

S f2 = [4, −4, 4, 4, 4, −4, 4, 4, 4, −4, 4, 4, −4, 4, −4, −4]T . We compute c = F1 ⊕ F2

.

= [0, 0, 1, 1, 0, 0, 1, 1, 0, 0, 0, 0, 0, 0, 0, 0]T . A new generalized Boolean bent function is determined as Fnew = 2F1 + c

.

= [0, 0, 1, 3, 0, 0, 1, 3, 0, 0, 2, 0, 2, 2, 0, 2]T ,

5.6

Construction of Generalized Boolean Bent Functions

141

which after encoding becomes Fnewi = [1, 1, i, −i, 1, 1, i, −i, 1, 1, −1, 1, −1, −1, 1, −1]T .

.

Its Walsh spectrum is computed as S fnew = [4, 4i, 4, −4i, 4, −4, 4, 4, 4, 4i, 4, −4i, −4, 4, −4, −4]T ,

.

from where it follows that . f is bent.

5.6.2

Construction by Permutation Matrices

The permutation matrices used to construct binary bent functions as discussed in previous chapters can be equally used for the generalized Boolean functions, since they do not concern the function values, and the domain is the same in both cases. Due to the structure of the Gibbs permutation matrices, when they are applied to the function vector of a bent function, blocks of values will be permuted. The permuted blocks of function values are equal to blocks that would be permuted with some spectral invariant operations. Since these operations preserve the magnitude of the coefficients of the spectrum, the resulting function is bent. Therefore, the following procedure immediately follows. 1. Given is a generalized Boolean bent function . f by its function vector .F. 2. Select a Gibbs permutation matrix for binary bent functions and apply it to .F. The constructed vector is the function vector of another generalized Boolean bent function with the same distribution of function values. This procedure is illustrated by the following example. Example 5.9 Consider the generalized Boolean bent function derived in Example 5.8 specified by the function vector F = [2, 3, 0, 3, 2, 0, 0, 0, 0, 1, 2, 1, 2, 0, 0, 0]T .

.

If we use the permutation matrix ⎡

0 ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢A .p1 = ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎣0 C

0 A 0 0 0 C 0 0

0 0 A 0 0 0 C 0

A 0 0 0 C 0 0 0

0 0 0 B 0 0 0 D

0 B 0 0 0 D 0 0

0 0 B 0 0 0 D 0

⎤ B 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥ D⎥ ⎥ 0⎥ ⎥ 0⎦ 0

142

5 Gibbs Characterization of a Class of Quaternary Bent Functions

whose entries .A, .B, .C, and .D are defined in Sect. 3.4 of Chap. 3, we construct a new generalized Boolean bent function as Fnewper m = [2, 3, 0, 3, 2, 0, 0, 0, 0, 1, 2, 1, 2, 0, 0, 0]T .

.

After encoding, the function vector of . f is Fnewper mi = [−1, −i, 1, −i, −1, 1, 1, 1, 1, i, −1, i, −1, 1, 1, 1]T ,

.

and its Walsh spectrum is S f newper m = [4, −4, −4, −4, −4, 4, 4, 4, −4i, 4i, −4, −4, −4i, 4i, −4, −4]T ,

.

from where it follows that . f is bent. Since we perform just the permutation, it is clear that the distribution of function values remains the same in the initial and the constructed generalized Boolean bent functions.

5.6.3

Construction of Bent Functions by Combination of Permutation Matrices

Another way to perform the same operation as above which, however, permits a generalization of the method for constructing different bent functions can be formulated as follows by referring to the theorem proven in [19]. In order to determine a generalized Boolean bent function, we start from a known generalized Boolean function for .q = 4 whose values .0, 1, 2, 3 are represented in terms of pairs of binary values. The coordinates of these binary representations viewed as functions of .2n variables are the functions .b and .c in . f (x, y) = 2b(x, y) + c(x, y). Then, we perform the following processing: 1. 2. 3. 4. 5.

Represent . f as . f (x, y) = 2b(x, y) + c(x, y). Compute .g(x, y) = b(x, y) ⊕ c(x, y). Permute the functions .b and .g by using the selected permutation matrix. From the permuted functions .b per m and .g per m , compute .cnew = g per m ⊕ b per m . Construct the new function . f = 2b per m + cnew .

This procedure is illustrated by the following example. Example 5.10 Given is a generalized Boolean function . f specified by the function vector F = [0, 1, 0, 3, 0, 1, 3, 0, 1, 0, 2, 1, 3, 2, 3, 0]T .

.

5.6

Construction of Generalized Boolean Bent Functions

143

In the encoding .(0, 1, 2, 3) → (1, i, −1, −i), the function vector is Fi = [1, i, 1, −i, 1, i, −i, 1, i, 1, −1, i, −i, −1, −i, 1]T .

.

This function is a bent function, since its Walsh spectrum in the considered encoding is S f = [4, −4i, 4i, 4, 4i, 4i, 4, −4, 4, 4, 4i, −4i, −4i, 4, −4, −4i]T .

.

The function . f is written as . f = 2b + c, where b = [0, 0, 0, 1, 0, 0, 1, 0, 0, 0, 1, 0, 1, 1, 1, 0]T ,

.

c = [0, 1, 0, 1, 0, 1, 1, 0, 1, 0, 0, 1, 1, 0, 1, 0]T , and, we compute g = b⊕c

.

= [0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 1, 1, 0, 1, 0, 0]T . Both functions .b and .g are bent, which can be verified after encoding by the Walsh transform, since Sb = [4, −4, 4, 4, 4, 4, 4, −4, 4, 4, 4, −4, −4, 4, −4, −4]T ,

.

Sg = [4, 4, −4, 4, −4, −4, 4, −4, 4, 4, −4, 4, 4, 4, −4, 4]T . We perform the permutation of the functions .b and .g by using the permutation matrix .P1 in Example 5.9, in which way we construct the functions b per m1 = [0, 0, 0, 1, 1, 0, 0, 0, 1, 1, 1, 0, 1, 0, 0, 0]T ,

.

g per m1 = [0, 0, 1, 0, 1, 1, 0, 1, 0, 0, 1, 0, 0, 0, 1, 0]T , and compute c1 = g per m1 ⊕ b per m1

.

= [0, 0, 1, 1, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0, 1, 0]T . Therefore, we determine Fnew1 = 2b per m1 + c per m1

.

= [0, 0, 1, 3, 2, 1, 0, 1, 3, 3, 2, 0, 3, 0, 1, 0]T , which is bent since after encoding Fnew1i = [1, 1, i, −i, −1, i, 1, i, −i, −i, −1, 1, −i, 1, i, 1]T ,

.

144

5 Gibbs Characterization of a Class of Quaternary Bent Functions

its Walsh spectrum is S Fnew1 = [4, −4, −4i, −4i, −4i, 4i, 4, 4, 4i, 4, 4i, −4, 4, 4i, 4, −4i]T .

.

If we change the permutation matrix and use the matrix ⎡

B ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 .P2 = ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎣D 0

0 0 B 0 D 0 0 0

0 0 0 C 0 A 0 0

0 C 0 0 0 0 0 A

0 0 A 0 C 0 0 0

A 0 0 0 0 0 C 0

0 D 0 0 0 0 0 B

⎤ 0 0⎥ ⎥ 0⎥ ⎥ ⎥ D⎥ ⎥, 0⎥ ⎥ B⎥ ⎥ 0⎦ 0

we get the functions b per m2 = [0, 0, 1, 1, 1, 0, 1, 0, 0, 0, 0, 0, 0, 1, 1, 0]T ,

.

g per m2 = [1, 1, 0, 0, 0, 0, 0, 0, 0, 1, 0, 1, 0, 1, 1, 0]T , and compute c2 = g per m2 ⊕ b per m2

.

= [1, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 1, 0, 0, 0, 0]T , from where Fnew2 = 2b per m2 + c per m2

.

= [1, 1, 3, 3, 3, 0, 3, 0, 0, 1, 0, 1, 0, 2, 2, 0]T , which is bent since after encoding Fnew2i = [i, i, −i, −i, −i, 1, −i, 1, 1, i, 1, i, 1, −1, −1, 1]T ,

.

its Walsh spectrum is computed as S Fnew2 = [4, −4i, 4i, 4, 4i, 4, 4i, −4, −4i, −4, 4i, −4, −4, 4, 4, 4]T .

.

Notice that these new bent functions . f new1 and . f new2 represented by function vectors Fnew1 and .Fnew2 can be obtained by the application of the permutation matrices directly to the initial bent function . f . This follows from the property that the new functions are defined as the linear combinations of the permuted functions.b and.c and that a bent function remains bent if some affine function is added to it [27].

.

5.6

Construction of Generalized Boolean Bent Functions

145

We can generate two more generalized Boolean bent functions by taking combinations b per m1 and .g per m2 and .b per m2 and .g per m1 to construct two new functions .c and further two new generalized Boolean bent functions . f . Therefore,

.

c3 = b per m1 ⊕ g per m2

.

= [1, 1, 0, 1, 1, 0, 0, 0, 1, 0, 1, 1, 1, 1, 1, 0]T , Fnew3 = 2b per m1 + c3 = [1, 1, 0, 3, 3, 0, 0, 0, 3, 2, 3, 1, 3, 1, 1, 0]T , which after encoding is Fnew3i = [i, i, 1, −i, −i, 1, 1, 1, −i, −1, −i, i, −i, i, i, 1]T ,

.

whose Walsh spectrum is S Fnew3 = [4, −4i, −4, −4i, −4, 4, 4i, 4i, 4, 4i, 4i, −4, 4i, 4i, 4i, −4i]T .

.

Another possibility is to compute .c from .b per m2 and .g per m1 c4 = b per m2 ⊕ g per m1

.

= [0, 0, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0, 0, 1, 0, 0]T , from where Fnew4 = 2b per m2 + c4

.

= [0, 0, 2, 3, 2, 1, 3, 1, 0, 0, 1, 0, 0, 3, 2, 0]T , which after encoding is Fnew4i = [1, 1, −1, −i, −1, i, −i, i, 1, 1, i, 1, 1, −i, −1, 1]T ,

.

whose Walsh spectrum is S Fnew4 = [4, −4, 4, 4, 4, 4i, 4, −4i, −4, −4i, 4i, −4, −4i, 4i, 4, 4]T .

.

The initial function . f has two values .3 and the new generalized Boolean bent functions have four values .3. Therefore, in this way we can produce new generalized Boolean bent functions with different distributions of function values. The following two examples illustrate the application of different Gibbs permutation matrices in the construction of generalized Boolean bent functions.

146

5 Gibbs Characterization of a Class of Quaternary Bent Functions

Example 5.11 Consider a quaternary bent function specified by the function vector F = [0, 1, 2, 3, 1, 3, 1, 3, 2, 1, 0, 3, 3, 3, 3, 3]T .

.

Binary representations of values of .F are Fbin = [00, 01, 10, 11, 01, 11, 01, 11, 10, 01, 00, 11, 11, 11, 11, 11]T .

.

Therefore, we have both coordinates represented as binary functions g1 = [0, 0, 1, 1, 0, 1, 0, 1, 1, 0, 0, 1, 1, 1, 1, 1]T ,

.

g2 = [0, 1, 0, 1, 1, 1, 1, 1, 0, 1, 0, 1, 1, 1, 1, 1]T . Then, we compute r = g 1 ⊕ g2

.

= [0, 1, 1, 0, 1, 0, 1, 0, 1, 1, 0, 0, 0, 0, 0, 0]T . In the .(0, 1) → (1, −1) encoding, we obtain g1i = [1, 1, −1, −1, 1, −1, 1, −1, −1, 1, 1, −1, −1, −1, −1, −1]T ,

.

ri = [1, −1, −1, 1, −1, 1, −1, 1, −1, −1, 1, 1, 1, 1, 1, 1]T . We use a permutation matrix ⎡

0 ⎢A ⎢ ⎢0 ⎢ ⎢ ⎢0 .P3 = ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎣0 C

0 0 0 C 0 A 0 0

0 B 0 0 0 0 0 D

0 0 0 D 0 B 0 0

B 0 0 0 0 0 D 0

0 0 D 0 B 0 0 0

A 0 0 0 0 0 C 0

⎤ 0 0⎥ ⎥ C⎥ ⎥ ⎥ 0⎥ ⎥ A⎥ ⎥ 0⎥ ⎥ 0⎦ 0

and construct g1 per m = [0, 1, 1, 0, 0, 1, 0, 1, 1, 1, 1, 1, 1, 1, 0, 0]T ,

.

which after encoding is g1 per mi = [1, −1, −1, 1, 1, −1, 1, −1, −1, −1, −1, −1, −1, −1, 1, 1]T ,

.

5.6

Construction of Generalized Boolean Bent Functions

and its Walsh spectrum is Sg1 per mi = [−4, 4, −4, 4, −4, −4, 4, 4, 4, 4, 4, 4, 4, −4, −4, 4]T

.

from where it follows that this function is bent. We compute g2 per m = g1 per m ⊕ r per m

.

= [1, 1, 1, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 1, 1, 0]T , and r per m = [1, 0, 0, 1, 0, 0, 1, 1, 0, 0, 0, 0, 1, 0, 1, 0]T ,

.

r per mi = [−1, 1, 1, −1, 1, 1, −1, −1, 1, 1, 1, 1, −1, 1, −1, 1]T , Sr per mi = [4, −4, 4, −4, 4, 4, −4, −4, −4, 4, 4, −4, −4, −4, −4, −4]T . Therefore, the permuted function is f per m = [1, 3, 3, 1, 0, 3, 1, 2, 3, 3, 3, 3, 2, 3, 1, 0]T ,

.

and after encoding, f per mi = [i, −i, −i, i, 1, −i, i, −1, −i, −i, −i, −i, −1, −i, i, 1]T ,

.

its spectrum is computed as S f per mi = [−4i, 4i, −4i, 4i, −4i, −4i, 4i, 4i, 4i, 4, 4, 4i, 4i, −4, −4, 4i]T

.

from which is clear that this function is bent. Example 5.12 Consider the same initial function as in Example 5.9, F = [0, 0, 1, 3, 0, 0, 1, 3, 0, 0, 2, 0, 2, 2, 0, 2]T ,

.

with g1 = [0, 0, 1, 3, 0, 0, 1, 3, 0, 0, 2, 0, 2, 2, 0, 2]T ,

.

g2 = [0, 0, 1, 1, 0, 0, 1, 1, 0, 0, 0, 0, 0, 0, 0, 0]T , however, a different permutation matrix

147

148

5 Gibbs Characterization of a Class of Quaternary Bent Functions



D ⎢0 ⎢ ⎢B ⎢ ⎢ ⎢0 .P4 = ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎣0 0

0 0 0 0 B 0 D 0

0 0 0 0 0 C 0 A

0 A 0 C 0 0 0 0

0 B 0 D 0 0 0 0

0 0 0 0 0 D 0 B

0 0 0 0 A 0 C 0

⎤ C 0⎥ ⎥ A⎥ ⎥ ⎥ 0⎥ ⎥. 0⎥ ⎥ 0⎥ ⎥ 0⎦ 0

By using this matrix, we determine permuted functions g1 per m2 = [0, 0, 0, 1, 0, 1, 0, 0, 1, 1, 1, 0, 0, 1, 0, 0]T ,

.

g1 per m2i = [1, 1, 1, −1, 1, −1, 1, 1, −1, −1, −1, 1, 1, −1, 1, 1]T , r per m2 = [0, 0, 0, 0, 0, 1, 0, 1, 0, 1, 1, 0, 1, 1, 0, 0]T , r per m2i = [1, 1, 1, 1, 1, −1, 1, −1, 1, −1, −1, 1, −1, −1, 1, 1]T , and compute g22 = g1 per m2 ⊕ r per m2

.

= [0, 0, 0, 1, 0, 0, 0, 1, 1, 0, 0, 0, 1, 0, 0, 0]T , which after encoding is g22i = [1, 1, 1, −1, 1, 1, 1, −1, −1, 1, 1, 1, −1, 1, 1, 1]T .

.

With .g1 and .g2 we determine a new function F2 = [0, 0, 0, 3, 0, 2, 0, 1, 3, 2, 2, 0, 1, 2, 0, 0]T .

.

After encoding F2i = [1, 1, 1, −i, 1, −1, 1, i, −i, −1, −1, 1, i, −1, 1, 1]T ,

.

and we compute the Walsh spectrum of . f 2i as S f 2i = [4, 4, −4, 4, −4i, −4i, 4, −4i, 4, 4, 4, −4, 4, 4i, 4i, −4]T ,

.

from where it is clear that this function is bent. For more examples of this kind, we refer to [28].

5.6

Construction of Generalized Boolean Bent Functions

149

References 1. Picek, S., Knezevi´c, K., Mariot, L., Jakobovi´c, D., Leporati, A.: Evolving bent quaternary functions. In: IEEE Congress on Evolutionary Computation (CEC), p. 8. Rio de Janeiro, Brazil (2018). https://doi.org/10.1109/CEC.2018.8477900. 2. Ryabov, V.: Nonlinearity of bent functions over finite fields. In: Proceedings of the 10th Workshop on Current Trends in Cryptology, (CTCrypt 2021), June 1–4, 2021, 210–219. Dorokhovo, Ruza District, Moscow Region, Russia (2021) 3. Stankovi´c, R.S., Astola, J.T., Moraga, C., Stankovi´c, M., Gaji´c, D.: Remarks on characterization of bent functions in terms of Gibbs dyadic derivatives, Eurocast 2015. In: Moreno-Diaz, R., Pichler, F., Quesada-Arencibia, A., (eds.) Computer Aided Systems Theory - EUROCAST 2015, 15th Int. Conf., Las Palmas de Gran Canaria, Spain, February 8–13, 2015, Revised Selected Papers LNCS, vol. 9520, 632–639. Springer (2015) 4. Stankovi´c, R. S., Stankovi´c, M., Astola, J.T., Moraga, C.: Gibbs characterization of binary and ternary bent functions. In: Proceedings of the 46th International Symposium on Multiple-Valued Logic, 205–210. Sapporo, Hokkaido, Japan (2016) 5. Stankovi´c, M., Moraga, C., Stankovi´c, R.S.: Construction of ternary plateaued functions from quadratic forms for ternary bent functions. In: Proceedings of the 51st International Symposium on Multiple-Valued Logic, Nur-Sultatn, Kazakhstan, May 25–27, 1–6 (2021). https://doi.org/10. 1109/ISMVL51352.2021.00010 6. Carlet, C., Ding, C.: Highly non-linear mappings. J. Complexity 20(2–3), 205–244 (2004) 7. Carlet, C., Mesnager, S.: Four decades of research on bent functions. Des. Codes Cryptogr. 78, 5–50 (2016) 8. Hu, H., Feng, D.: On quadratic bent functions in polynomial forms. IEEE Trans. Inform. Theory 53, 2610–2615 (2007) 9. Kumar, P.V., Scholtz, R.A., Welch, L.R.: Generalized bent functions and their properties. J. Combin. Theory Ser. A 40, 90–107 (1985) 10. St˘anic˘a, P., Martinsen, T., Gangopadhyay, S., et al.: Bent and generalized bent Boolean functions. Des. Codes Cryptogr. 69, 77–94 (2013) 11. Schmidt, K.-U.: . Z 4 -valued quadratic forms and quaternary sequence families. IEEE Trans. Inform. Theory 55, 5803–5810 (2009) 12. Logachev, O.A., Salnikov, A.A., Yashchenko, V.V.: Bent functions on a fnte Abelian group. Discrete Math. Appl. 7(6), 547–564 (1997) 13. Poinsot, L.: Bent functions on a finite non-Abelian group. J. Discret. Math. Sci. Cryptogr. 9(2), 349–364 (2006) 14. Poinsot, L.: Non-Abelian bent functions. Cryptogr. Commun. 4, 1–23 (2012) 15. Pott, A.: Nonlinear functions in Abelian groups and relative difference sets. Discrete Appl. Math. 138, 177–193 (2004) 16. Schmidt, K.U.: Quaternary Constant-Amplitude Codes for Multicode CDMA. In: IEEE International Symposium on Information Theory ISIT’2007, Nice, France, June 24-29, 2007 Proceedings 2007, 2781/2785. http://arxiv.org/abs/cs.IT/0611162. IEEE Trans. Inform. Theory 55(4), 1824–1832 (2009) 17. Solodovnikov V.I.: Bent functions from a finite Abelian group into a finite Abelian group. Discretnaya Matematika 12(2), 111–126 (2002). English translation in 18. Solodovnikov, V.I.: Bent functions from a finite Abelian group into a finite Abelian group. Discrete Math. Appl. 14(1), 99–113 (2002) 19. Solé, P., Tokareva, N.N.: On quaternary and binary bent functions. Prikl. Diskr. Mat. Supplement No. 1, 16–18 (2009)

150

5 Gibbs Characterization of a Class of Quaternary Bent Functions

20. Tokareva, N.: Generalizations of bent functions. A survey, translated from Discrete Analysis and Operation Research (Diskretn. Anal. Issled. Oper.) 17(1), 34–64 (2010) 21. Tokareva, N.: Symmetric Cryptography. Novosibirsk State University, Novosibirsk, Russia (2012)978-5-4437-0067-0, 234 p. (in Russian) 22. Tokareva, N.: Bent Functions - Results and Applications to Cryptography. Elsevier (2015) 23. Solé, P., Tokareva, N.: Connections between quaternary and binary bent functions. In: 2011 IEEE International Symposium on Information Theory Proceedings, ISIT 2011. St. Petersburg, Russia, July 31–August 5 (2011) 24. Gibbs, J.E.: Walsh spectrometry a form of spectral analysis well suited to binary digital computation. NPL DES Repts. National Physical Lab, Teddington, Middlesex, England (1967) 25. Gibbs, J.E.: Walsh functions and the Gibbs derivative. NPL DES Memo, vol. 10, pp. ii + 13 (1973) 26. Karpovsky, M.G., Stankovi´c, R.S., Astola, J.T.: Spectral Logic and Its Application in the Design of Digital Devices. Wiley (2008) 27. Cusick, T.W., St˘anic˘a, P.: Cryptographic Boolean Functions and Applications. Academic Press/Elsevier (2009) 28. Stankovi´c, R.S., Stankovi´c, M., Astola, J.T., Moraga, C.: Quaternary generalized Boolean bent functions obtained through permutation of binary Boolean bent functions. In: Proceedings of the 48th International Symposium on Multiple-Valued Logic, Linz, Austria, May 16–18 (2018)

6

Matrix-Valued Binary Bent Functions

In theory and practice of bent functions, the term class is used in a twofold meaning. Most often, it is applied to sets of bent functions generated in a specified manner or by a particular algorithm. In this respect, several classes of bent functions are distinguished [1–3]. In another meaning, the term classes refers to sets of bent functions sharing certain specific properties or are mutually related by some transformations. For example, already Rothaus proved that for .n = 6 there are four classes of bent functions that are affine equivalent, i.e., functions from the same class can be converted to each other by affine transformations [4]. Table 6.1 shows representative functions for these classes [4]. For .n = 8, bent functions of the degree not larger than .3 can be split into .10 affine equivalence classes, the representatives of which are shown in Table 6.2 [2, 5, 6]. Further, these functions are affine equivalent to functions obtained by the Maiorana–McFarland construction method [7, 8]. In [9], it is shown that for .n = 8 there are at least .129 classes of affine equivalent bent functions. Another approach to the classification of bent functions is done in [10, 11] in terms of Walsh spectra of subvectors of length.2k of truth-vectors of bent functions viewed as Boolean functions in .k variables. It is shown that bent functions of .n = 4 variables can be split into .8 classes of the so-called quadrate equivalent functions where the term quadrate refers to bent quadrates defined as square matrices whose rows are the Walsh spectra of subfunctions in .k variables of the considered bent functions. In this chapter, we present an approach proposed initially in [12, 13] to the classification of bent functions with respect to patterns appearing in their truth-vectors or function vectors when encoding .(0, 1) → (1, −1) is used. The approach is based upon the following considerations. Linear functions are sums of Boolean variables. Each variable .xi can be viewed as a function in .n variables, but essentially dependent just on the .i-th variable. Then, it is rep© The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_6

151

152

6 Matrix-Valued Binary Bent Functions

Table 6.1 Representative functions for affine equivalent binary bent functions in .n = 6 variables 1.

.

2.

.

f 6−1 = x1 x2 ⊕ x3 x4 ⊕ x5 x6

3.

f 6−2 = x1 x2 x3 ⊕ x1 x4 ⊕ x2 x5 ⊕ x3 x6 . f 6−3 = x 1 x 2 x 3 ⊕ x 2 x 4 x 5 ⊕ x 1 x 2 ⊕ x 1 x 4 .

4.

.

⊕x2 x6 ⊕ x3 x5 ⊕ x4 x5

f 6−4 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 x6 ⊕ x1 x4 . ⊕x2 x6 ⊕ x3 x4 ⊕ x3 x5 ⊕ x3 x6 ⊕ x4 x5 ⊕ x4 x6

Table 6.2 Representative functions for affine equivalent bent functions of degree .3 in .n = 8 variables 1.

.

f 8−1 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x7 x8

2.

.

f 8−2 = x1 x2 x3 ⊕ x1 x4 ⊕ x2 x5 ⊕ x3 x6 ⊕ x7 x8

3.

.

f 8−3 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 ⊕ x2 x6 ⊕ x1 x7 ⊕ x5 x8

4.

.

f 8−4 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x1 x3 ⊕ x1 x5 ⊕ x2 x6 ⊕ x3 x4 ⊕ x7 x8

5.

.

6.

f 8−5 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 x6 ⊕ x3 x5 ⊕ x2 x6 ⊕ x2 x5 ⊕ x1 x7 ⊕ x4 x8 . f 8−6 = x 1 x 2 x 3 ⊕ x 2 x 4 x 5 ⊕ x 3 x 4 x 6 ⊕ x 3 x 5 ⊕ x 1 x 3 ⊕ x 1 x 4 ⊕ x 2 x 7 ⊕ x 6 x 8

7.

. .

f 8−7 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 x6 ⊕ x3 x5 ⊕ x2 x6 ⊕ x2 x5 ⊕ x1 x2 ⊕ x1 x3 ⊕x1 x4 ⊕ x7 x8

8.

.

f 8−8 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 x6 ⊕ x3 x5 ⊕ x1 x6 ⊕ x2 x7 ⊕ x4 x8

9.

.

f 8−9 = x1 x2 x7 ⊕ x3 x4 x7 ⊕ x5 x6 x7 ⊕ x1 x4 ⊕ x3 x6 ⊕ x2 x5 ⊕ x4 x5 ⊕ x7 x8

10.

. .

f 8−10 = x1 x2 x3 ⊕ x2 x4 x5 ⊕ x3 x4 x6 ⊕ x1 x4 x7 ⊕ x3 x5 ⊕ x2 x7 ⊕ x1 x5 ⊕x1 x6 ⊕ x4 x8

resented by a truth-vector of length .2n consisting of constant .0 and .1 subvectors of length i .2 . In linear functions, the sum of these constant subvectors results in particular patterns in their truth-vectors. Example refex-paterni below illustrates this feature of linear functions. For a given number of variables .n, the set of all linear functions is isomorphic to the set of all Walsh functions of length .2n . Due to this and the orthogonality of the Walsh transform, the Walsh spectra of linear functions have a single non-zero coefficient with the value equal to .2n . The binary .n-tuple expressing the position of the non-zero coefficient in the vector of spectral coefficients has the value .1 at the positions corresponding to the variables involved in the EXOR sum defining the linear function considered. As noticed above, this follows from the isomorphism between the Walsh and linear functions and the orthogonality of the Walsh transform. Bent functions with the given number of non-zero values are mutually related by permutations of elements of their truth-vectors. It is similar in the Walsh spectral domain since bent functions have flat spectra. Walsh spectra of different bent functions are different in the order of spectral coefficients. Recall that after dividing with .2n/2 , the Walsh spectra of

6 Matrix-Valued Binary Bent Functions

153

bent functions define the corresponding dual bent functions. Thus, particular permutations of their values define new bent functions. Binary bent functions are defined as functions at the largest distance from linear functions. They are functions with low autocorrelation and therefore, it could be interesting to ask if there are possible relationships between their values resulting in some patterns in their truth-vectors, and if yes, then would it be possible to classify them by using these patterns? Example 6.1 illustrates this question and its meaning. Example 6.1 For .n = 4, the linear function . fl = x1 ⊕ x2 ⊕ x3 ⊕ x4 has the truth-vector Fl = [0, 1, 1, 0, 1, 0, 0, 1, 1, 0, 0, 1, 0, 1, 1, 0]T ,

.

in which the patterns .[0, 1, 1, 0] and .[1, 0, 0, 1] appear. These patterns, which are complements of each other, are balanced subfunctions in two variables and they repeat such that the entire function is balanced. The function . f = x1 x2 ⊕ x3 x4 is bent and has the truth-vector Fb = [0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0]T ,

.

in which the patterns .[0, 0, 0, 1] and .[1, 1, 1, 0] appear. These patterns, the complements to each other, are unbalanced functions and repeat in such a manner that the entire function is unbalanced as it is required for bent functions. It follows that non-linearity does not mean irregularity in the sense of non-existence of repeating patterns. Recalling these properties of linear but also of bent functions, it is interesting to consider if there can be found some relationships between values a bent function takes, i.e., to find some possible patterns expressing similarity between certain bent functions in the sense that functions are mutually similar if they share identical patterns in their truth-vectors. The relationships between function values can be explored in terms of the Walsh spectra with respect to particular subsets of variables. These spectra can be defined and understood by referring to the Fast Walsh–Hadamard Transform (FWHT) in the following manner. In searching for patterns of length .2k , which means when considering the subset of .k variables, we perform first .n − k steps of the FWHT. The output of these computations can be called the partially computed Walsh spectrum, in short the partial Walsh spectrum, in the sense that not all the steps of FWHT are performed to compute the complete spectrum. The idea is that since the complete spectrum of a bent function is flat, to achieve this flatness, in previous steps of computing certain patterns should appear. Then, bent functions can be classified by referring to the identical patterns in their partial Walsh spectra. Functions sharing the same patterns with permutation of pattern elements allowed belong to the same class. The length of the patterns can be varied and classes of bent functions with respect to patterns of different sizes can be considered. Recall that the degree of a bent function . f is defined as the number of variables in the largest product term in the positive polarity Reed–

154

6 Matrix-Valued Binary Bent Functions

Muller expression for . f . This implies that the Reed–Muller coefficients assigned to product terms larger than the degree must be .0. Since the Reed–Muller coefficients can be viewed as the Walsh coefficients computed after .(0, 1) → (1, −1) encoding and then reduced modulo .2, there is sense to search for patterns in bent functions of the same degree. To redistribute and possibly reduce the computing space and time requirements, as well as to adapt the computation to contemporary hardware oriented toward matrix computations, the computing of partial Walsh spectra can be converted into computation with matrix-valued functions. It means, we first convert a Boolean function into a matrix-valued (mv) function whose function values are .(k × k) matrices and compute its Walsh spectrum obtaining in this way the corresponding matrix-valued (mv) spectrum. Bent functions can be classified in terms of values taken by elements of their matrix-valued Walsh spectra. Functions sharing same patterns, permutations of elements within a pattern and different signs assignments allowed, are considered to be mutually similar.

6.1

Matrix-Valued Functions

A Boolean function in .n variables is specified by the truth-vector of length .2n whose elements are logic values .0 and .1. We use the encoding .(0, 1) → (1, −1), where .1 and .−1 are interpreted as integers. In this encoding, the Boolean function is represented by the .2n length function vector whose elements are integers .1 and .−1. We convert a Boolean function into a matrix-valued function by first splitting its function vector into .r = 2k , .1 < k < n, consecutive subvectors, and then writing these subvectors as rows of a .(2k × 2k ) matrix. The following example illustrates and explains the way of converting a Boolean function into its matrix-valued equivalent. Example 6.2 A Boolean function in four variables has the function vector of .16 elements F = [ f (0), f (1), f (2), f (3), f (4), f (5), f (6), f (7), f (8),

.

f (9), f (10), f (11), f (12), f (13), f (14), f (15)]T , and can be converted into a matrix-valued function.f with.4 elements that are.(2 × 2) matrices as f = [a, b, c, d]T ,

.

where [ a=

.

] [ ] [ ] [ ] f (0) f (1) f (4) f (5) f (8) f (9) f (12) f (13) ,b = ,c = ,d = . f (2) f (3) f (6) f (7) f (10) f (11) f (14) f (15)

6.1

Matrix-Valued Functions

155

Since there are no restrictions to elements of a vector .F whose Walsh spectrum should be computed, they can be matrices. Therefore, the Walsh spectrum of a matrix-valued function is computed in the same way as of a number-valued vector. By comparing mv-spectra of bent functions, they can be split into classes of functions sharing mv-spectra consisting of matrices of the same forms and with elements from the same sets of values. Notice that, as mentioned above, computing the .(2k × 2k ) matrix-valued coefficients actually means performing first .n − k steps of FWHT. For example, for .(2 × 2)-coefficients, we first perform addition and subtraction of function values. f (i) and. f (2n/2 + i) as specified by the basic Walsh transform matrix .W(1). Then, we perform the same computation over the obtained values split into blocks of length .2(n/2) , and the procedure continues until we perform all.n − k steps. Since after.n steps, the values of Walsh coefficients for a bent function have to be.±2n/2 , the values computed in previous steps must satisfy some restrictions, which come from particular distributions of function values bent functions can take. This further reflects into patterns representing rows of matrix-valued coefficients, i.e., their structure. Therefore, by comparing the matrix-valued coefficients, some relationships between bent functions sharing the same patterns in these coefficients, equivalently in their function values, can be observed. Therefore, we split bent functions into classes depending on the structure of their matrix-valued coefficients.

6.1.1

Classification Method

The question and a possible answer of which we are interested in this chapter can be alternatively formulated in the following way. In truth-vectors of linear functions there are patterns that repeat. These are patterns .1, 0, 0, 1 and.0, 1, 1, 0 as illustrated by Example 7.3. Further, linear functions are isomorphic to Walsh functions, i.e., rows of the Walsh matrix, and due to that, their Walsh spectrum has a single non-zero coefficient. For a linear function in terms of all .n variables, this is the coefficient at the position in the spectrum equal to the position of the Walsh function in the transform matrix which the linear function is isomorphic with, and its value is .2n . with the index .2n − 1, starting counting from .0. All other coefficients are .0. If we consider the matrix-valued spectrum of a linear function, except the last mv coefficient, all the coefficients are zero matrices. The last coefficient is a non-zero matrix whose rows are a single pattern with negative signs assigned in different manners. Example 6.3 Consider the linear function in .6 variables f = x1 ⊕ x2 ⊕ x3 ⊕ x4 ⊕ x5 ⊕ x6 . Its truth-vector is

.

F = [0, 1, 1, 0, 1, 0, 0, 1, 1, 0, 0, 1, 0, 1, 1, 0,

.

1, 0, 0, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 1, 1, 0, 0, 1, 0, 1, 1, 0, 0, 1, 1, 0, 1, 0, 0, 1, 0, 1, 1, 0, 1, 0, 0, 1, 1, 0, 0, 1, 0, 1, 1, 0]T .

156

6 Matrix-Valued Binary Bent Functions

When .(0, 1) → (1, −1), the encoded function vector is F = [1, −1, −1, 1, −1, 1, 1, −1, −1, 1, 1, −1, 1, −1, −1, 1,

.

−1, 1, 1, −1, 1, −1, −1, 1, 1, −1, −1, 1, −1, 1, 1, −1, −1, 1, 1, −1, 1, −1, −1, 1, 1, −1, −1, 1, −1, 1, 1, −1, 1, −1, −1, 1, −1, 1, 1, −1, −1, 1, 1, −1, 1, −1, −1, 1]T . The .(4 × 4) matrix-valued function is F[a, b, b, a]T ,

.

where ⎤ ⎡ ⎤ −1 1 1 −1 1 −1 −1 1 ⎢ 1 −1 −1 1 ⎥ ⎢ −1 1 1 −1 ⎥ ⎥ ⎢ ⎥ .a = ⎢ ⎣ −1 1 1 −1 ⎦ , b = ⎣ 1 −1 −1 1 ⎦ . −1 1 1 −1 1 −1 −1 1 ⎡

The .(4 × 4)-spectrum of this function is S f = [c, c, c, d]T ,

.

where ⎡

0 ⎢0 .c = ⎢ ⎣0 0

0 0 0 0

0 0 0 0

⎤ ⎡ ⎤ 4 −4 −4 4 0 ⎥ ⎢ 0⎥ ⎥ , d = ⎢ −4 4 4 −4 ⎥ . ⎣ ⎦ −4 4 4 −4 ⎦ 0 4 −4 −4 4 0

Notice that the fourth coefficient .d is actually the first or fourth matrix .a in the matrixvalued function vector of . f multiplied by .4. The rows of this coefficient are the pattern .4, 4, 4, 4 with two different assignments of negative signs .4, −4, −4, 4 and .−4, 4, 4 − 4. These patterns correspond to patterns .0, 1, 1, 0 and .1, 0, 0, 1 which can be observed in the initial truth-vector. Example 6.4 Consider the bent function in .6 variables . f = x1 x2 ⊕ x3 x4 ⊕ x5 x6 . Its truthvector is F = [0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0,

.

0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 1, 0, 1, 1, 1, 0, 0, 0, 0, 1]T .

6.1

Matrix-Valued Functions

157

When .(0, 1) → (1, −1), the encoded function vector is F = [1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1

.

1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1 1, 1, 1, −1, 1, 1, 1, −1, 1, 1, 1, −1, −1, −1, −1, 1 −1, −1, −1, 1, −1, −1, −1, 1, −1, −1, −1, 1, 1, 1, 1, −1]T . The .(4 × 4) matrix-valued function is F = [a, a, a, b]T ,

.

where ⎤ ⎡ ⎤ −1 −1 −1 1 1 1 1 −1 ⎢ −1 −1 −1 1 ⎥ ⎢ 1 1 1 −1 ⎥ ⎥ ⎢ ⎥ .a = ⎢ ⎣ 1 1 1 −1 ⎦ , b = ⎣ −1 −1 −1 1 ⎦ . 1 1 1 −1 −1 −1 −1 1 ⎡

The .(4 × 4)-spectrum of this function is S f = [c, c, c, d]T ,

.

where ⎤ ⎡ ⎤ −2 −2 −2 2 2 2 2 −2 ⎢ −2 −2 −2 2 ⎥ ⎢ 2 2 2 −2 ⎥ ⎥ ⎢ ⎥ .c = ⎢ ⎣ 2 2 2 −2 ⎦ , d = ⎣ −2 −2 −2 2 ⎦ . 2 2 2 −2 −2 −2 −2 2 ⎡

The pattern is .2, 2, 2, 2, with two different assignments of the sign as .−2, −2, −2, 2 and .2, 2, 2, −2. In bent functions, there cannot be zero-valued coefficients, since the spectrum is flat; however, in matrix-valued coefficients patterns including .0 might appear. When comparing the mv-coefficients of the partial Walsh spectra, where the term partial means that not all the steps of Fast Walsh transform algorithms are implemented, we consider their structure and values of their elements. In this context, structure of a matrix means the number and position of elements with equal values. Table 6.3 shows examples of matrices that are considered to be of equal structure for .(2 × 2)-matrix-valued Walsh spectra. The structure and the values of matrix-valued Walsh coefficients are used as the classification criteria for binary bent functions. Bent functions whose matrix-valued coefficients have matrices of the same structure and with elements from the same set of even integers belonging to the same class. Allowed are permutation of

158

6 Matrix-Valued Binary Bent Functions

Table 6.3 Examples of matrices with the same structure [ [ [ ] ] ] a a a b aa . . . a −b aa ba

[ .

−b a aa

]

1. Matrix-valued coefficients within the matrix-valued function vectors. 2. Rows or columns in matrix-valued coefficients. 3. Elements in rows and columns.

Classes of Binary Bent Functions for .n = 4

6.2

An exhaustive computer check shows that the following statement is true. Statement 6.1 The set of all bent functions in four variables can be split into two subsets 1. The subset . S4 of functions whose .(2 × 2) matrix-valued Walsh coefficients have a single non-zero element equal to .±4. 2. The subset . S2 of functions whose .(2 × 2) matrix-valued Walsh coefficients have three elements equal to .2, while the fourth element is .−2, or vice versa, three elements are .−2 and the fourth is .2. These subsets consist of .384 and .512 bent functions, respectively. The following randomly chosen Examples 6.5 and 6.6 out of all .896 bent functions in four variables illustrate the statement. Example 6.5 The bent function whose truth-vector can be viewed as the binary representation of the integer .64682 has .10 values .1, and it is specified by the function vector F64682 = [1, 0, 0, 1, 0, 1, 0, 1, 0, 0, 1, 1, 1, 1, 1, 1]T ,

.

which in .(0, 1) → (1, −1) encoding is F64682 = [−1, 1, 1, −1, 1, −1, 1, −1, 1, 1, −1, −1, −1, −1, −1, −1]T ,

.

and can be converted into a .(2 × 2) matrix-valued equivalent function as

6.2

Classes of Binary Bent Functions for n = 4

159

f64682 = [a, b, c, d]T ,

.

where [ a=

.

] ] [ ] [ ] [ −1 −1 1 1 1 −1 −1 1 . , d= , c= , b= −1 −1 −1 −1 1 −1 1 −1

We use the following Walsh matrix to compute the matrix-valued Walsh spectrum ⎤ 1 1 1 1 ⎢ 1 −1 1 −1 ⎥ ⎥ .W = ⎢ ⎣ 1 1 −1 −1 ⎦ . 1 −1 −1 1 ⎡

The matrix-valued .(2 × 2)-spectrum of the function .64682 is computed as

S64682

.

⎡ ⎤ ⎡ ⎤ a s0 ⎢ b ⎥ ⎢ s1 ⎥ ⎥ ⎢ ⎥ = W⎢ ⎣ c ⎦ = ⎣ s2 ⎦ . s3 c

Therefore, S64682 = [s0 , s1 , s2 , s3 ]T ,

.

where ] [ 0 0 0 , s1 = a − b + c − d = 0 −4 0 ] [ [ 00 −4 s2 = a + b − c − d = , s3 = a − b − c + d = 40 0 [

s0 = a + b + c + d =

.

] 4 , 0 ] 0 . 0

Example 6.6 The bent function whose truth-vector can be viewed as the binary representation of the integer .39616 has .6 values .1, and it is specified by the function vector F39616 = [1, 0, 0, 1, 1, 0, 1, 0, 1, 1, 0, 0, 0, 0, 0, 0]T ,

.

which in .(0, 1) → (1, −1) encoding is F39616 = [−1, 1, 1, −1, −1, 1, −1, 1, −1, −1, 1, 1, 1, 1, 1, 1]T ,

.

which can be converted into a matrix-valued equivalent function as f39616 = [a, b, c, d]T ,

.

where

160

6 Matrix-Valued Binary Bent Functions

[ a=

.

] [ ] [ ] [ ] −1 1 −1 1 −1 −1 11 , b= , c= , d= . 1 −1 −1 1 1 1 11

The matrix-valued .(2 × 2)-spectrum of the function .39616 computed as shown in Example 6.5 is S39616 = [s0 , s1 , s2 , s3 ]T ,

.

where [

] [ ] −2 2 −2 2 .s0 = a + b + c + d = , s1 = a − b + c − d = , 22 −2 −2 [ ] [ ] −2 −2 2 2 s2 = a + b − c − d = , s3 = a − b − c + d = . 2 −2 2 −2 Examples 6.5 and 6.6 illustrate two possible cases of subsets . S4 and . S2 of bent functions in Statement 6.1. These subsets . S4 and . S2 in Statement 6.1 constitute two classes of bent functions for .n = 4, denoted as .C1 and .C2 . The sum of elements per coefficient is .±4. For functions in .n = 4 variables, there is no sense to consider larger matrix-valued equivalents, since for .(4 × 4), the function maps into a single matrix.

6.3

Classes of Binary Bent Functions for .n = 6

It is hard to perform an exhaustive search for bent functions in six and more variables. Therefore, we are using the following observations. All affine equivalent Boolean functions have Walsh spectra that mutually differ in the permutation of Walsh coefficients. The same applies to their partial spectra, i.e., matrixvalued spectra. Therefore, it is sufficient to compare for possible similarity the matrix-valued spectra of affine equivalence representative functions.

6.3.1

(2 × 2)-spectra for Binary Bent Functions for .n = 6

.

We compute .(2 × 2)-spectra for each of four affine equivalence representative functions in Table 6.1 and notice that three functions . f 6−2 , . f 6−3 , and . f 6−4 have the .(2 × 2)-spectra with the same structure. Further, elements of their matrix-valued coefficients are .0, .4, and .8 with a different assignment of signs and positions in .(2 × 2) matrices. Thus, they belong to the same class. The function. f 6−1 constitutes a separate class, since elements of its matrix-valued coefficients are .±4. Table 6.4 shows values of elements of these spectra. Examples 6.7, 6.8, 6.9, 6.10 show the corresponding matrix-valued spectra.

Classes of Binary Bent Functions for n = 6

6.3

161

Table 6.4 Classes of affine equivalence representative bent functions for .n = 6 with respect to × 2) mv-spectra

.(2

Class

Functions

.C 1

.

.C 2

.

Elements of matrix-valued spectral coefficients .±4

f 6−1

.0, .±4, .±8

f 6−2 . f 6−3 . f 6−4

.0, .±4, .±8 .0, .±4, .±8

Example 6.7 The .(2 × 2) matrix-valued spectrum of . f 6−1 is ] ] [ ] [ ] [ [[ −4 −4 4 4 4 4 4 4 S f6−1 = −4 4 4 −4 4 −4 4 −4 [

.

[

[

4 4 4 −4 4 4 4 −4

−4 −4 −4 4 [

If we use the notation .a4 =

]

[

]

[

][

4 4 4 −4 4 4 4 −4

−4 −4 −4 4

]

[

]

[

][

4 4 4 −4 4 4 4 −4

−4 −4 −4 4

] [

] [

][

−4 −4 −4 4 −4 −4 −4 4

4 4 4 −4

]

]

]] .

] 4 4 , then the spectrum 4 −4

S f6−1 = [a4 , a4 , a4 , −a4 , a4 , a4 , a4 , −a4 , a4 , a4 , a, −a4 − a4 , −a4 , −a4 , a4 ]T .

.

The index .4 in the label of the matrix .a shows that the fourth element has a different sign compared to other three elements in the matrix enumerating them per rows as .1, 2, 3, 4. After encoding .a4 = 0, .−a4 = 1, the spectrum .S f6−1 is identical to the function vector of the function . f (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 .

162

6 Matrix-Valued Binary Bent Functions

Example 6.8 The .(2 × 2) matrix-valued spectrum of . f 6−2 is ] ] [ ][ ] [ [[ 4 −4 00 4 4 80 S f6−2 = 4 4 80 4 −4 00 [

.

[

[

08 00 80 00 08 00

]

][

][

[

44 −4 4

−4 −4 −4 4 −4 −4 4 −4

][

][

][

00 08 00 80 00 08

]

[

]

[

][

−4 4 44

−4 4 −4 −4

4 −4 −4 −4

]

]

]] .

If we introduce the notation as ] ] ] ] [ [ [ [ 80 08 00 00 b2 = b3 = b4 = b1 = 00 00 80 08 ] ] ] ] [ [ [ [ . −4 4 4 −4 44 4 4 a2 = a3 = a4 = , a1 = 44 4 4 −4 4 4 −4 then the spectrum of . f 6−2 can be written as S f6−2 = [b1 , a4 , b3 , a2 , b2 , a3 , b4 , a1 , b1 , −a4 , b3 , −a2 , b2 , −a3 , b4 , −a1 ]T .

.

Example 6.9 The .(2 × 2) matrix-valued spectrum of . f 6−3 is ] ] [ ] [ ] [ [[ −4 4 08 4 −4 80 S f6−3 = 44 00 4 4 00 [

.

[

[

00 80 80 00 00 80

]

][

][

[

4 4 4 −4

−4 4 −4 −4 −4 −4 −4 4

]

][

][

[

00 08

0 0 0 −8 0 −8 0 0

]

[

]

[

][

44 −4 4 44 −4 4

−4 4 44

]

]

]] .

With notation as in Example 6.8, the spectrum .S f6−3 can be written as S f6−3 = [b1 , a2 , b2 , a1 , b3 , a4 , b4 , a3 , b1 , −a2 , −b4 , a3 , b3 , −a4 , −b2 , a1 ]T .

.

6.3

Classes of Binary Bent Functions for n = 6

163

Table 6.5 Examples of randomly generated bent functions in .n = 6 variables 1.

.

2.

.

fr −1 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5

3.

fr −2 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5 ⊕ x2 x4 ⊕ x4 x3 x5 ⊕ x5 . f r −3 = x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 1 x 3 x 5 ⊕ x 2 x 4 ⊕ x 4 x 3 x 5

4.

.

5.

fr −4 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x1 x3 x5 ⊕ x2 x4 ⊕ x4 x3 x5 .⊕x1 x5 ⊕ x4 x5 . f r −5 = 1 ⊕ x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 1 x 3 x 5 ⊕ x 2 x 4 ⊕ x 4 x 3 x 5 .⊕x 1 x 5 ⊕ x 4 x 5

6.

.

fr −6 = x1 x2 ⊕ x3 x4 ⊕ x5 x6 ⊕ x2 x4 x6 . f r −7 = x 1 x 2 ⊕ x 3 x 4 ⊕ x 5 x 6 ⊕ x 2 x 4 x 6 ⊕ x 1 x 3 ⊕ x 3 x 4 x 6 .⊕x 1 ⊕ x 4 x 6

7.

Example 6.10 The .(2 × 2) matrix-valued spectrum of . f 6−4 is [[ ] [ ] [ ] [ ] 44 80 4 4 08 S f6−4 = −4 4 00 4 −4 00 [

.

[

[

4 −4 4 4 4 −4 4 4

−4 −4 −4 4

]

][

]

[

00 08

0 0 0 −8 [

08 00

]

[

]

[

][

−4 4 44 44 −4 4

4 −4 −4 −4

]

[

] [

][

00 80

−8 0 00

00 80

]

]

]] .

The spectrum .S f6−4 can be written as S f6−4 = [a3 , b1 , a4 , b2 , a2 , b4 , a1 , b3 , a2 , −b4 , a3 , −b1 , −a4 , b2 , −a1 , b3 ]T .

.

From Examples 6.7 to 6.10, it is clear that affine equivalence representative functions can be split into two classes as in Table 6.4. We randomly generated .7 bent functions by modifying a starting bent function by adding new terms and computing their .(2 × 2) spectra to check if there are some similarities among them allowing to somehow classify them. Table 6.5 shows the considered functions where the starting function is . fr −1 . Their .(2 × 2) spectra are the following

164

6 Matrix-Valued Binary Bent Functions

[[ S fr −1 = [

.

[

[

[[

[

[

[

[[ S fr −3 = [

.

[

[

4 4 4 −4 4 4 4 −4

−4 −4 −4 4

S fr −2 =

.

4 4 4 −4

4 −4 4 4 4 −4 4 4 4 −4 4 4 4 −4 4 4

4 4 4 −4 4 4 4 −4 4 4 4 −4

−4 4 −4 −4

]

[

]

[

]

[

][

[

]

[

][

4 4 4 −4

4 −4 4 4 4 4 4 −4

−4 4 −4 −4 −4 4 −4 −4

]

[

]

[

]

[

][

4 −4 4 4

−4 4 −4 −4

]

][

4 4 4 −4

4 4 4 −4 4 −4 4 4 4 4 4 −4

−4 −4 −4 4

]

[

]

[

]

[

][

][

][

][

][

4 4 4 −4

4 −4 4 4 4 −4 4 4 4 −4 4 4 4 4 4 −4

[

]

[

]

4 4 4 −4

−4 −4 −4 4

]

][

4 4 4 −4

] [

] [

][

[

]

[

]

[

][

4 4 4 −4 4 4 4 −4

4 −4 4 4

−4 −4 −4 4 −4 4 −4 −4 −4 −4 −4 4

4 −4 4 4

]

−4 −4 −4 4 [

] [

−4 −4 −4 4 −4 4 −4 −4

]

[

]

[

]

][

]

]

]] .

−4 4 −4 −4

−4 4 −4 −4

]

]

]

]

]] .

−4 −4 −4 4 −4 4 −4 −4 [

4 4 4 −4

−4 −4 −4 4

]

]

]

]] .

6.3

Classes of Binary Bent Functions for n = 6

[[ S fr −4 = [

.

[

[

4 −4 4 4 4 4 4 −4

−4 −4 −4 4

[[ S fr −5 = [

.

4 4 4 −4

[

]

[

]

[

][

−4 4 −4 −4 −4 −4 −4 4

[[ S fr −6 = [

[

[

[

−4 −4 −4 4

[

.

]

4 4 4 −4

4 4 4 −4 4 4 4 −4 4 4 4 −4

−4 −4 −4 4

4 4 4 −4 4 4 4 −4 4 4 4 −4

−4 4 −4 −4

][

][

][

]

]

[

]

[

][

]

−4 −4 −4 4 −4 −4 −4 4 −4 −4 −4 4 [

]

[

]

[

]

[

][

165

4 −4 4 4

4 4 4 −4 4 4 4 −4 4 4 4 −4

−4 −4 −4 4

4 4 4 −4 4 −4 4 4

−4 −4 −4 4 [

][

][

]

4 4 4 −4

]

[

]

4 4 4 −4

−4 −4 −4 4

[

]

[

]

[

4 4 4 −4 4 4 4 −4 44 −4 4

−4 −4 4 −4

−4 −4 −4 4 −4 −4 −4 4 [

][

−4 4 −4 −4

]

][

[

−4 −4 −4 4

[

][

]

4 4 4 −4

−4 4 −4 −4

]

[

]

[

] [

][

] [

] [

] [

][

4 4 4 −4

−4 −4 −4 4

]

]

]

]

]]

−4 −4 −4 4 −4 −4 −4 4 −4 −4 4 −4

44 −4 4

]

]] .

4 4 4 −4

4 −4 4 4

]

. ]

]

]

]] .

166

6 Matrix-Valued Binary Bent Functions

Table 6.6 Spectra of randomly generated bent functions in .n = 6 variables in Table 6.5 1.

.S fr −1

= [a4 , a4 , a4 , −a4 , a4 , a2 , a4 , −a2 , a4 , a4 , a4 , −a4 , −a4 , −a2 , −a4 , a2 ]T

2.

.S fr −2

= [a2 , a2 , a2 , −a2 , a2 , a4 , a2 , −a4 , a2 , −a2 , a2 , −a2 , a2 , −a2 , a4 , −a2 ]T

3.

.S fr −3

= [a4 , a4 , a4 , −a4 , a4 , a2 , a4 , −a2 , a4 , a4 , −a4 , a4 , −a2 , −a4 , a2 , −a4 ]T

4.

.S fr −4

= [a4 , a4 , a4 , −a4 , a2 , a4 , a2 , −a4 , a4 , a4 , −a4 , a4 , −a4 , −a2 , a4 , −a2 ]T

5.

.S f

= [−a4 , −a4 , −a4 , a4 , −a2 , −a4 , −a2 , a4 , −a4 , −a4 , a4 , −a4 , a4 , a2 , −a4 , a2 ]T

6.

.S fr −6

= [a4 , a4 , a4 , −a4 , a4 , a4 , a4 , −a4 , a4 , a4 , a3 , −a3 , −a4 , −a4 , −a3 , a3 ]T

7.

.S fr −7

= [a4 , a4 , a4 , −a4 , −a4 , a4 , −a4 , −a4 , a4 , a4 , a3 , −a3 , a3 , −a3 , a4 , a3 ]T

r −5

[[ S fr −7 = [

.

4 4 4 −4

−4 −4 −4 4 [

[

4 4 4 −4 44 −4 4

]

[

]

[

]

[

][

4 4 4 −4 4 4 4 −4 4 4 4 −4

−4 −4 4 −4

]

][

[

4 4 4 −4

−4 −4 −4 4

]

[

]

[

44 −4 4 4 4 4 −4

] [

] [

] [

][

−4 −4 −4 4 −4 −4 −4 4 −4 −4 4 −4

4 4 4 −4

]

]

]

]] .

Table 6.6 shows spectra of these randomly generated bent functions in terms of notation in the above examples. Since these functions are derived by spectral invariant operations from the same function. f 6−1 in Example 6.7, they all have the spectra consisting of submatrices of the same form and therefore belong to the same class to which this initial function belongs.

6.3.2

(4 × 4)-spectra for Binary Bent Functions for .n = 6

.

In this section, we compare.(4 × 4)-spectra for four affine representative functions for.n = 6. The .(4 × 4)-spectrum for the function . f 6−1 consists of patterns .±(2, 2, 2, −2). The sum per rows is .±4 and the total sum is .16. The spectra for functions . f 6−2 , . f 6−3 , and . f 6−4 consists of patterns .(4, 0, 2, 2) and .(0, 0, 2, 2) with permuted elements and different signs assigned to them. For . f 6−2 and . f 6−3 the sum per rows is either .±8 or .0 and the total sum is .32. The sum per rows for . f 6−4 is equal to .±4 and the total sum is .20. Due to the appearance of the same patterns, three functions. f 6−2 ,. f 6−3 , and. f 6−4 belong to the same class. Examples 6.11, 6.12, 6.13, 6.14 show the .(4 × 4)-spectra of these functions.

6.3

Classes of Binary Bent Functions for n = 6

167

Example 6.11 The .(4 × 4)-spectrum for . f 6−1 is .S f6−1 = [s0 , s0 , s0 , −s0 ]T , where ⎤ 2 2 2 −2 ⎢ 2 2 2 −2 ⎥ ⎥ .s0 = ⎢ ⎣ 2 2 2 −2 ⎦ . −2 −2 −2 2 ⎡

The sum of elements per coefficient is .±8. Example 6.12 The .(4 × 4)-spectrum for . f 6−2 is .S f6−2 = [s0 , s1 , s2 , s3 ]T , where ⎡

⎤ ⎤ ⎡ 0 2 2 0 0 2 −2 ⎥ ⎢ 0 −2 −2 ⎥ ⎥ , s1 = ⎢ 0 0 −2 2 ⎥ , ⎦ ⎣ 0 2 −2 4 0 2 2⎦ 0 −2 2 4 0 −2 −2



⎡ ⎤ ⎤ 4 2 2 0 0 −2 2 ⎢ ⎥ 4 −2 −2 ⎥ ⎥ , s3 = ⎢ 0 0 2 −2 ⎥ . ⎣ ⎦ 0 −2 2 0 4 2 2⎦ 0 2 −2 0 4 −2 −2

4 ⎢4 s0 = ⎢ ⎣0 0 .

0 ⎢0 s2 = ⎢ ⎣0 0

The sum of elements per coefficient is .8. Example 6.13 The .(4 × 4)-spectrum for . f 6−3 is .S f6−3 = [s0 , s1 , s2 , s3 ]T , where ⎡

⎡ ⎤ 2 2 4 0 2 −2 0 ⎢ 2 −2 0 0 ⎥ ⎢2 2 4 ⎢ ⎥ s0 = ⎢ ⎣ 2 2 −4 0 ⎦ , s1 = ⎣ 2 −2 0 2 −2 0 0 2 2 −4 .



2 2 0 ⎢ −2 2 0 s2 = ⎢ ⎣ 2 −2 0 −2 −2 0

⎡ ⎤ 4 −2 2 ⎢ 2 2 0⎥ ⎥ , s3 = ⎢ ⎣ −2 −2 0⎦ 4 2 −2

0 0 0 0

⎤ 0 0⎥ ⎥, 0⎦ 0 ⎤ 0 4⎥ ⎥. 4⎦ 0

The sum of elements per coefficient is .8. Example 6.14 The .(4 × 4)-spectrum for . f 6−4 is .S f6−4 = [s0 , s1 , s2 , s3 ]T , where

168

6 Matrix-Valued Binary Bent Functions

Table 6.7 Classes of affine equivalence representative bent functions for .n = 6 with respect to × 4) mv-spectra

.(4

Class

Functions

.C 1

.

.C 2

.

f 6−1

f 6−2 . f 6−3 . f 6−4

Sum of elements per coefficient

.±2

.±8

.0, .±2, .±4

.±8

.0, .±2, .±4

.±8

.0, .±2, .±4

.±8



⎤ ⎤ ⎡ 0 2 −2 0 0 2 2 ⎥ ⎢ 0 −2 −2 ⎥ ⎥ , s1 = ⎢ 4 0 −2 2 ⎥ , ⎦ ⎣ 0 −2 2 0 0 −2 −2 ⎦ 0 2 2 4 0 2 −2



⎡ ⎤ ⎤ 4 2 −2 0 0 −2 −2 ⎢ ⎥ 0 2 2⎥ ⎥ , s3 = ⎢ 0 −4 −2 2 ⎥ . ⎣ 0 −4 2 −2 ⎦ 0 −2 −2 ⎦ 4 −2 2 0 0 2 2

4 ⎢0 s0 = ⎢ ⎣4 0 .

Elements of spectral coefficients

0 ⎢0 s2 = ⎢ ⎣0 0

The sum of elements per coefficient is .±8. Table 6.7 summarizes these observations for classes of affine representative functions for n = 6. We now consider spectra of random generated functions for .n = 6. We randomly select a function, and then construct new bent functions by performing spectral invariant operations.

.

Example 6.15 For the first random generated function . f r6−1 , the .(4 × 4)-spectrum is T .Sr6−1 = [s0 , s1 , s0 , −s1 ] , where ⎡

⎡ ⎤ ⎤ 2 2 2 −2 2 2 2 −2 ⎢ 2 2 2 −2 ⎥ ⎢ 2 2 2 −2 ⎥ ⎢ ⎥ ⎥ . s0 = ⎢ ⎣ 2 2 2 −2 ⎦ , s1 = ⎣ 2 2 −2 2 ⎦ . −2 −2 −2 2 −2 −2 2 −2 Therefore, this function is similar to the function . f 6−1 and belongs to its class. Example 6.16 The random generated function . f r6−2 has the .(4 × 4)-spectrum as .Sr6−2 = [s0 , s1 , s2 , s3 ]T where

6.4

Classes for Binary Bent Functions for n = 8

169



⎡ ⎤ ⎤ 2 2 2 −2 2 2 2 −2 ⎢ 2 2 2 −2 ⎥ ⎢ 2 2 2 −2 ⎥ ⎢ ⎥ ⎥ s0 = ⎢ ⎣ −2 −2 −2 2 ⎦ , s1 = ⎣ −2 −2 2 −2 ⎦ , 2 2 2 −2 2 2 −2 2 .



⎡ ⎤ ⎤ 2 −2 2 2 −2 2 −2 −2 ⎢ 2 −2 2 2 ⎥ ⎢ −2 2 −2 −2 ⎥ ⎢ ⎥ ⎥ s2 = ⎢ ⎣ −2 2 −2 −2 ⎦ , s3 = ⎣ 2 −2 −2 −2 ⎦ . 2 −2 2 2 −2 2 2 2

From the similarity of.(4 × 4)-spectra, this function belongs to the same class as the functions from which it is derived. It is the same with other randomly generated functions that we consider. This statement holds generally.

6.4

Classes for Binary Bent Functions for .n = 8

We determine mv-spectra for .10 affine equivalent representative functions for .n = 8 in Table 6.2 and compare patterns of values in rows and columns of the matrix-valued coefficients.

6.4.1

(2 × 2)-spectra for Functions in .n = 8 Variables

.

It can be observed that .(2 × 2)-spectra of some of these functions have identical elements. In that respect two classes can be differentiated, each class containing.5 representative functions as in Table 6.8. As examples, we show .(2 × 2)-spectra for the first, second, third, and the .10-th affine equivalent representative functions in Examples 6.17, 6.18, 6.19, and 6.20. The spectra of other functions are calculated in the same way and led to identical conclusions. [ The ]spectra of functions . f 8−1 , . f 8−2 , . f 8−4 , . f 8−7 , . f 8−9 consist of the submatrix .a = 8 8 and its variants with four different positions of the negative element .−8 as well as 8 −8 [ ] −8 −8 . their negated counterparts, i.e., .−a = −8 8 The spectra of . f 8−3 , . f 8−5 , . f 8−6 , . f 8−8 , . f 8−10 consist of two types of submatrices including submatrices [appearing ] in [spectra ] of functions . f 8−1 , . f 8−2 , . f 8−4 , . f 8−7 , . f 8−9 . These 8 8 16 0 and . and their variants with the values .−8 and .16 at four submatrices are . 8 −8 00 different positions, as well as these submatrices with negative values. The sum of elements per coefficients is .±16.

170

6 Matrix-Valued Binary Bent Functions

Table 6.8 Classes of bent functions for .n = 8 with respect to .(2 × 2) mv-spectra Class

Functions

1

.

f 8−1 , . f 8−2 , . f 8−4 , . f 8−7 , . f 8−9

.±8

Elements of spectral coefficients

2

.

f 8−3 , . f 8−5 , . f 8−6 , . f 8−8 , . f 8−10

.0, .±8, .±16

Example 6.17 The .(2 × 2)-spectrum of the function . f 8−1 is s f8−1 = [a, a, a, −a, a, a, a, −a, a, a, a, −a, −a, −a, −a, a,

.

a, a, a, −a, a, a, a, −a, a, a, a, −a, −a, −a, −a, a, a, a, a, −a, a, a, a, −a, a, a, a, −a, −a, −a, −a, a, −a, −a, −a, a, −a, −a, −a, a, −a, −a, −a, a, a, a, a, −a]T , ] [ 8 8 where .a = . There are .36 equal to .a while the remaining .28 take value .−a. 8 −8 Example 6.18 The .(2 × 2)-spectrum of the function . f 8−2 is s f8−2 = [a, a, a, a, a, a, a, a, a, −a, a, −a, a, −a, a, a,

.

a, a, −a, −a, a, a, −a, a, a, −a, −a, a, a, −a, −a, −a, a, a, a, a, −a, −a, −a, a, a, −a, a, −a, −a, a, −a, −a, a, a, −a, −a, −a, −a, a, −a, a, −a, −a, a, −a, a, a, a]T , [

] 8 8 . There are .36 values .a and .28 values .−a. Thus, spectra for . f 8−1 and 8 −8 differ in the position of negative signs.

where .a = .

f 8−2

Example 6.19 The .(2 × 2)-spectrum of the function . f 8−3 is s f8−3 = [A, H, C, F, A, G, C, E, A, F, C, H, −A, −E, −C, −G,

.

A, −H, C, −F, A, −G, C, −E, A, −F, C, −H, −A, E, −C, G, B, G, D, E, B, H, D, F, B, E, D, G, −B, −F, −D, −H, B, −G, D, −E, B, −H, D, −F, B, −E, D, −G, −B, F, −D, H]T , where the submatrices are specified in Table 6.9. Each submatrix appears .8 times. Four submatrices .A, .B, .C, .D appear .6 times with the sign .+ and two times with the sign .−. The other matrices, .E, .F, .G, .H, appear four times with the sign .+ and four times with the sign .−.

Classes for Binary Bent Functions for n = 8

6.4

171

Table 6.9 Submatrices in .(2 × 2)-spectra for functions in the second class in Table 6.8 [ [ [ [ ] ] ] ] 16 0 0 16 00 0 0 .A = .B = .C = .D = 00 0 0 16 0 0 16 [ .E

=

−8 8 88

[

] .F

=

] 8 −8 . 8 8

[ .G

=

88 −8 8

[

] .H

=

] 8 8 . 8 −8

Example 6.20 The .(2 × 2)-spectrum of the function . f 8−10 is s f8−10 = [A, G, F, A, C, E, H, C, H, −D, −C, F, F, −B, −A, H,

.

G, C, B, G, E, A, D, E, B, −H, −G, D, D, −F, −E, B, H, −B, A, −F, F, −D, C, −H, A, E, −H, −A, C, G, −F, −C, B, −F, E, −D, D, −H, G, −B, G, A, −D, −G, E, C, −B, −E]T , where the submatrices are specified in Table 6.9. As in Example 6.19, the appearance of these matrices is the same; there are four submatrices .A, .C, .E, .G which appear .6 times with the sign .+ and two times with the sign .−, and other submatrices .B, .D, .F, .H appear four times with .+ and .−.

6.4.2

(4 × 4)-spectra for Functions in .n = 8 Variables

.

In this section, we discuss .(4 × 4)-spectra for .10 affine equivalent representative functions for .n = 8 in Table 6.2. It can be observed that rows of matrix-valued coefficients consist of patterns shown in Table 6.10, with allowed permutations of their elements and signs assigned such that the sum of elements per rows is either .±8 or .16. The second column shows functions in whose spectra the corresponding patterns appear. Different functions are obtained by different permutations of elements of a pattern and sign assignments. For an explanation of this classification, consider the following properties of .(4 × 4)spectra for functions in Class .1. The spectrum of . f 8−1 consists of the pattern .[4, 4, 4, 4] with differently assigned negative signs as shown in Example 6.21. For other three functions in this class, the coefficients consist of this pattern and the pattern .[8, 0, 0, 0] with shifted element .8 with either the positive or negative sign. The function . f 8−1 can possibly constitute a separate class, and it should be noticed that its coefficients have the same form as the non-zero coefficient in linear functions in the sense that all the elements have the same absolute value. The non-linearity of bent functions implies that there cannot exist zero-valued matrix coefficients.

172

6 Matrix-Valued Binary Bent Functions

Table 6.10 Patterns in matrix-valued coefficients of .(4 × 4)-spectra for affine equivalence representative functions for .n = 8 Class

Pattern

Functions

1

.[4, 4, 4, 4]

.

f 8−1 , . f 8−2 , . f 8−4 , . f 8−7 , . f 8−9

2

.[8, 0, 0, 0]

.

f 8−2 , . f 8−4 , . f 8−7 , . f 8−9

3

.[8, 0, 4, 4]

.

f 8−3 , . f 8−4 , . f 8−5 , . f 8−6 , . f 8−8 , . f 8−10

4

.[4, 4, 0, 0]

.

f 8−3 , . f 8−4 , . f 8−5 , . f 8−6 , . f 8−8 , . f 8−10

5

.[12, 0, 0, 4]

.

f 8−5 , . f 8−8 , . f 8−10

6

.[4, 8, 8, 4]

.

f 8−5 , . f 8−10

We can observe that functions which belong to the same class with respect to .(2 × 2)spectra stay in the same class with respect to .(4 × 4)-spectra, which can be viewed as a kind of consistency. Further, with .(4 × 4)-spectra we can observe stronger similarities between certain functions in the same class. We assume that the similarity is stronger if two functions belong to a larger number of classes. For example, . f 8−5 and . f 8−10 belong to Classes .3, .4, .5, .6 and are strongly similar in that respect, since they share four different patterns in their spectra. There is no similarity between these two functions and functions in Classes .1 and .2, since there no common terms as row in their matrix-valued coefficients. From Table 6.2, it can be observed that these two functions share the following product terms .x1 x2 x3 , .x2 x4 x5 , .x3 x4 x6 , .x3 x5 , .x4 x8 . There are no common terms with . f 8−1 , and it is a single common term .x1 x2 x3 with . f 8−2 . It should be however noticed that similarity in terms of .(4 × 4)-spectra discussed here does not reduce to sharing the common terms. For example, functions . f 8−5 , . f 8−6 , . f 8−7 , . f 8−8 , and . f 8−10 all share at least five common terms, but belong to different classes in the sense we are discussing here. Similarly, the function . f 8−9 has a single common term with functions in Class .1 to which it belongs. Example 6.21 The elements of .(4 × 4) coefficients for the function . f 8−1 are .±4 and all the rows of these coefficients consist of patterns .(4, 4, 4, −4) and .(−4, −4, −4, 4). The spectrum is S f8−1 = [X3 , X3 , X3 , −X3 , X3 , X3 , X3 , −X3 ,

.

X3 , X3 , X3 , −X3 , −X3 , −X3 , −X3 , X3 ]T , where ⎤ 4 4 4 −4 ⎢ 4 4 4 −4 ⎥ ⎥ .X3 = ⎢ ⎣ 4 4 4 −4 ⎦ . −4 −4 −4 4 ⎡

6.4

Classes for Binary Bent Functions for n = 8

173

If we use encoding .(X3 , −X3 ) → (0, 1), then .S f8−1 equals the function vector of the function . f (x1 , x2 , x3 4) = x1 x2 ⊕ x3 x4 . The index .3 in .X3 denotes that in this matrix the sign of the third column is the opposite to the sign of other columns with counting starting from .0. We will further use the same notation convention for columns in matrix-valued coefficients. We can observe that the functions differ by permutation of columns in matrix-valued coefficients and permutation of these coefficients in the matrix-valued spectra. Functions whose spectra consist of the same matrices ignoring these permutations and sign assignments belong to the same class. Example 6.22 The spectrum of function . f 8−2 consists of two types of matrices .Xi and Yi , where the index .i points to the column which has the sign or both the sign and values different from other columns. In this case,

.

⎤ −4 4 4 4 ⎢ −4 4 4 4 ⎥ ⎥ .X0 = ⎢ ⎣ −4 4 4 4 ⎦ , 4 −4 −4 −4 ⎡

and ⎤ 4 −4 4 4 ⎢ 4 −4 4 4 ⎥ ⎥ .X1 = ⎢ ⎣ 4 −4 4 4 ⎦ . −4 4 −4 −4 ⎡

The matrices.X2 and.X3 are defined in the same way, the column with three negative elements is shifted at the positions .2 and .3, respectively. The other matrices are ⎡ ⎤ 8 0 0 0 ⎢ 8 0 0 0⎥ ⎥ .Y0 = ⎢ ⎣ 8 0 0 0⎦, −8 0 0 0 and ⎡

0 8 ⎢0 8 .Y1 = ⎢ ⎣0 8 0 −8

0 0 0 0

⎤ 0 0⎥ ⎥, 0⎦ 0

and in the same way for .Y2 and .Y3 , i.e., the column with three negative elements is shifted at the positions .2 and .3, respectively.

174

6 Matrix-Valued Binary Bent Functions

With this notation, the .(4 × 4)-spectrum of . f 8−2 is S f8−2 = [Y0 , X3 , Y1 , X2 , Y2 , X1 , Y3 , X0 ,

.

Y0 , −X3 , Y1 , −X2 , Y2 , −X1 , Y3 , −X0 ]T . Example 6.23 The .(4 × 4)-spectrum of . f 8−3 consists of two types of matrices .Q and .R, however, in some cases with both rows and columns permuted. We denote these permutations of columns and rows by indices at the right and the left side of the label for the matrix. For the given matrix .Q with rows and columns labeled by .0, 1, 2, 3, the label .3201Q1032 means the matrix obtained by ordering rows of .Q as .(0123) → (3201), and then reordering columns of thus produced matrix as .(0123) → (1032). This index label is omitted if the order of rows or columns is unchanged. The .(4 × 4)-spectrum of . f 8−3 is S f8−3 = [R0123 , Q0123 , R0132 , −Q0132 , R1032 ,

.

Q1032 , R1023 , −Q1032 , 3201 R0132 , 3201 Q0132 , 3201 R0123 , 3201 (−Q0132 ), 2301 R1032 , 3201 Q1032 , T 2301 R1023 , 3201 (−Q1032 )] ,

where ⎡

R0123

.

8 ⎢8 =⎢ ⎣0 0

⎤ 0 4 4 0 −4 −4 ⎥ ⎥, 0 4 −4 ⎦ 0 −4 4

and ⎡

Q0123

.

⎤ 4 4 8 0 ⎢ 4 4 −8 0 ⎥ ⎥ =⎢ ⎣ 4 −4 0 0 ⎦ . 4 −4 0 0

Example 6.24 The .(4 × 4)-spectrum for . f 8−4 is s f8−4 = [Y0 , X1 , Y0 , −X1 , Y1 , X0 , Y1 , −X0 ,

.

Y2 , X3 , Y3 , −X2 , Y3 , X2 , Y2 , −X3 ]T , where the matrices .X0 and .Y0 are as in Example 6.22. Since functions . f 8−2 and . f 8−4 share the same submatrices, with permuted columns and rows as well as their position in the spectrum, they belong to the same class.

6.4

Classes for Binary Bent Functions for n = 8

175

Example 6.25 The .(4 × 4)-spectrum for . f 8−5 is S f8−5 = [V0123 , 1023 V, U0123 , 1032 U0123 , D0123 , D1032 ,

.

K0123 , K1032 , V3102 , V3210 , U2301 , U3210 , U2301 , D3210 , K2103 , K1230 ]T , where ⎤ ⎡ 12 0 0 4 4 0 8 ⎢ 0 4 −4 0 ⎥ ⎢ 0 −4 −4 ⎥ ⎢ =⎢ ⎣ 4 0 0 −4 ⎦ , U0123 = ⎣ −4 0 0 0 −4 4 0 0 4 −4 ⎡

V0123

.

⎤ 4 8⎥ ⎥, 4⎦ 0

and ⎤ −4 8 8 4 ⎢ 0 −4 4 0 ⎥ ⎥ =⎢ ⎣ 4 0 0 −4 ⎦ . 0 −4 4 0 ⎡

K0123

.

Example 6.26 The .(4 × 4)-spectrum for . f 8−6 is s f8−6 = [R0312 , Q1203 , R1203 , Q0312 , 3201 R0123 , 3201 Q1230 , 2301 R1203 ,

.

3201 Q0312 , R0213 , 3201 A2301 , R1302 , A0123 , E0123 , A2301 , T 2301 E2301 , 2301 A0123 ] ,

where .R01234 and .Q0123 are as in Example 6.23, ⎡

R0123

.

8 ⎢8 =⎢ ⎣0 0

⎡ ⎤ ⎤ 0 4 4 4 4 8 0 ⎢ ⎥ 0 −4 −4 ⎥ ⎥ , Q0123 = ⎢ 4 4 −8 0 ⎥ , ⎣ ⎦ 0 4 −4 4 −4 0 0 ⎦ 0 −4 4 4 −4 0 0

and ⎡

A0123

.

⎡ ⎤ ⎤ −4 −8 4 0 0 4 0 4 ⎢ −4 8 4 0 ⎥ ⎢ ⎥ ⎥ , E0123 = ⎢ 0 −4 0 −4 ⎥ . =⎢ ⎣ −4 0 −4 0 ⎦ ⎣ 8 4 0 −4 ⎦ −4 0 −4 0 8 −4 0 4

Recall that indices on the left and the right side of the label of a matrix show reordering of rows and columns in the initial matrix, respectively.

176

6 Matrix-Valued Binary Bent Functions

Example 6.27 The .(4 × 4)-spectrum for . f 8−7 is S f8−7 = [Y0 , X0 , Y2 , X2 , Y3 , X3 , Y1 ,

.

X1 , Y0 , −X3 , Y3 , −X3 , Y1 , −X1 , Y2 , −X2 ]T , where .X0 , .X1 , .X2 , .X3 , .Y0 , .Y1 , .Y2 , .Y3 are as in Example 6.22. Example 6.28 The .(4 × 4)-spectrum for . f 8−8 is S f8−8 = [A0123 , A1032 , B0123 , B1032 , A2301 ,

.

A3210 , B2301 , B3210 , C0123 , C1032 , D0123 , D1032 , C2301 , C3210 , D2301 , D3210 ]T , where ⎤ ⎤ ⎡ 12 0 0 −4 4 0 8 4 ⎢ 0 4 4 0⎥ ⎢ 0 −4 4 0 ⎥ ⎥ ⎥ ⎢ =⎢ ⎣ 4 0 0 4 ⎦ , B0123 = ⎣ −4 0 8 −4 ⎦ , 0 −4 −4 0 0 4 −4 0 ⎡

A0123

.

and ⎡

C0123

.

4 ⎢ 0 =⎢ ⎣ −4 0

⎤ ⎡ 8 0 4 −4 8 0 ⎢ 0 −4 4 4 −4 0 ⎥ ⎥ , D0123 = ⎢ ⎣ 4 0 0 0 0 4⎦ 4 4 −8 0 −4 −4

⎤ 4 8⎥ ⎥. 4⎦ 0

Example 6.29 The .(4 × 4)-spectrum for . f 8−9 is S f8−9 = [N0123 , N0312 , N1023 , N3012 , N2301 , N2103 ,

.

0132 N3120 , M0123 , N0132 , −M3120 , N1032 ,

L0123 , L0213 , 0132 M0132 , 0132 L0321 , 0132 N2130 ]T , where ⎤ ⎤ ⎡ 8 0 0 0 0 0 0 8 ⎢ 8 0 0 0⎥ ⎢ 0 0 0 8⎥ ⎥ ⎥ ⎢ =⎢ ⎣ 4 4 4 −4 ⎦ , M0123 = ⎣ 4 4 4 −4 ⎦ , −4 −4 −4 4 −4 −4 −4 4 ⎡

N0123

.

and

6.4

Classes for Binary Bent Functions for n = 8

177

⎤ 0 −8 0 0 ⎢ 0 −8 0 0 ⎥ ⎥ =⎢ ⎣ −4 4 4 4 ⎦ . 4 −4 −4 −4 ⎡

L0123

.

Example 6.30 The .(4 × 4)-spectrum for . f 8−10 is S f8−10 = [J0123 , J1032 , Q0123 , Q1032 , R0123 , R1032 ,

.

Q0123 , Q1032 , E0123 , E1032 , A0123 , A1032 , B0123 , B1032 , C0123 , C1032 ]T , where ⎤ ⎡ 12 0 0 4 4 0 0 ⎢ 0 4 −4 0 ⎥ ⎢ 0 −4 4 ⎥ ⎢ =⎢ ⎣ 0 −4 4 0 ⎦ , Q0123 = ⎣ 0 4 4 4 0 0 −4 −4 0 −8 ⎡

J0123

.

⎤ 4 8⎥ ⎥, 0⎦ 4

and ⎤ ⎤ ⎡ 4 0 0 4 4 8 0 −4 ⎢ 0 −4 4 −8 ⎥ ⎢ 0 4 4 0⎥ ⎥ ⎥ ⎢ =⎢ ⎣ 8 4 −4 0 ⎦ , E0123 = ⎣ 0 4 −4 8 ⎦ , 4 0 0 4 −4 0 0 −4 ⎡

R0123

.

and ⎡

A0123

.

⎡ ⎤ ⎤ −4 8 8 4 −4 0 0 4 ⎢ 0 −4 4 0 ⎥ ⎢ 0 4 −4 0 ⎥ ⎢ ⎥ ⎥ =⎢ ⎣ 0 −4 4 0 ⎦ , B0123 = ⎣ 8 4 4 0 ⎦ , 4 0 0 −4 −4 8 0 −4

and ⎡

C0123

.

⎤ 4 0 8 −4 ⎢ 0 −4 −4 0 ⎥ ⎥ =⎢ ⎣ 0 4 4 0⎦. −4 0 8 4

Notice that in .(4 × 4) spectra of .10 affine representative functions, there are actually four essentially mutually different matrices by their structure, .X, .Y, .R, .V. After a corresponding assignment of element values, all other matrices can be derived from them by allowing the permutation of columns and rows as well as permutation of elements in rows and columns. In all these matrices, the signs .+ and .− are assigned such that the sum of elements per

178

6 Matrix-Valued Binary Bent Functions

Table 6.11 Classes of .10 affine equivalence representative functions with respect to .(4 × 4)-partial spectra Class

Functions

mv-coefficients

1

.

f 8−1

.X

2

.

f 8−2 , . f 8−4 , . f 8−7

.X, .Y

3

.

f 8−3 , . f 8−6 , . f 8−9

.R

4

.

f 8−5 , . f 8−8 , . f 8−10

.V, .R

coefficients is .16. Taking this into account, and since in searching for similarity, we refer to the structure of matrix-valued coefficients, not in values of their elements, it follows that these .10 affine equivalence representative functions can be split into four classes as shown in Table 6.11. Functions sharing the related .(4 × 4) matrix-valued coefficients belong to the same class. The term related means that these matrix-valued coefficients share the same structure, and differ in the encoding of elements and the allowed permutations of rows, columns, and their elements, as well as sign assignments.

References 1. Cusick, T.W., St˘anic˘a, P.: Cryptographic Boolean Functions and Applications. Academic Press/Elsevier (2009) 2. Tokareva, N.: Symmetric Cryptography. Novosibirsk State University, Novosibirsk, Russia (2012) 978-5-4437-0067-0, 234 pages. (in Russian) 3. Tokareva, N.: Bent Functions—Results and Applications to Cryptography. Elsevier (2015) 4. Rothaus, O.: On bent functions. J. Combin. Theory. Ser. A 20(3), 300–305 (1976) 5. Braeken, A.: Cryptographic properties of Boolean functions and Sboxes, Ph.D. thesis, Katholieke University, Leuven, Belgium (2006) 6. Hou, X.D.: .q-ary bent functions constructed from chain rings. Finite Fields Appl. 4(1), 55–61 (1998) 7. Maiorana, J.A.: A class of bent functions, R41 Technical paper, Aug. 1970 8. McFarland, R.L.: A family of difference sets in non-cyclic groups. J. Combin. Theory. Ser. A. 15(1), 1–10 (1973) 9. Yang, M., Meng, Q., Zhang H.: Evolutionary design of trace form bent functions. Cryptology ePrint Archive, Report 2005/322 10. Agievich, S.V.: On the representation of bent functions by bent rectangles. In: Fifth International Petrozavodsk Conference on Probabilistic Methods in Discrete Mathematics, Petrozavodsk, Russia, 1–6 June 2000, Proceedings of the Boston VSP, pp. 121–135 (2000). http://arxiv.org/abs/ math/0502087 11. Agievich, S.V.: Bent Rectangles, NATO Advanced Study Institute on Boolean Functions in Cryptology and Information Security, Zvenigorod, Russia, 8–18 Sept. 2007, Proceedings of the Netherlands, pp. 3–22. IOS Press (2008)

References

179

12. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola. J.: Remarks on similarities among ternary bent functions. In: Proceedings of the 49th International Symposium on Multiple-Valued Logic, Fredericton, Canada, pp. 79–84, 21–23 May 2019 13. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Remarks on Similarities Between Bent Functions, Binary and Ternary Cases, Res. Rept. (2018). available from the authors upon request

7

Matrix-Valued Ternary Bent Functions

In this chapter, we extend the approach to the classification of binary bent functions through matrix-valued spectra to ternary bent functions.

7.1

Matrix-Valued Equivalents of Bent Functions

For ternary functions, the function vector is of length .3n and the used encoding for its elements is .(0, 1, 2) → (1, e1 , e2 ) in order that their values correspond with the values of basis functions in the Vilenkin–Chrestenson transform. The function vector in this encoding is split into subvectors of length .3k , .1 < k < 3n , which are written as rows of .(3k × 3k ) matrices. In this way, the function vector is converted into the corresponding matrix-valued vector whose elements are .(3k × 3k ) matrices. The following example illustrates and explains the way of converting a ternary function into its matrix-valued equivalent. It is similar as in the case of binary functions. Example 7.1 A ternary function in three variables has the function vector of .27 elements F = [ f (0), f (1), f (2), f (3), f (4), f (5), f (6), f (7), f (8),

.

f (9), f (10), f (11), f (12), f (13), f (14), f (15), f (16), f (17), f (18), f (19), f (20), f (21), f (22), f (23), f (24), f (25), f (26)]T ,

© The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_7

181

182

7 Matrix-Valued Ternary Bent Functions

and can be converted into a matrix-valued function.f with.3 elements that are.(3 × 3) matrices such as f = [a1 , a2 , a3 ]T ,

.

where ⎡

⎤ f (0) f (1) f (2) .a1 = ⎣ f (3) f (4) f (5) ⎦ , f (6) f (7) f (8) ⎡ ⎤ f (9) f (10) f (11) a2 = ⎣ f (12) f (13) f (14) ⎦ , f (15) f (16) f (17) ⎡ ⎤ f (18) f (19) f (20) a3 = ⎣ f (21) f (22) f (23) ⎦ . f (24) f (25) f (26) As in the case of the Walsh transform, in the Vilenkin–Chrestenson transforms there are no restrictions to elements of the function vector .F the spectrum of which should be computed. Thus, they can be matrices and we compute the matrix-valued (mv) Vilenkin–Chrestenson spectra of matrix-valued ternary functions as in the case of number-valued vectors. By comparing mv-spectra of bent functions, they can be split into classes of functions sharing mv-spectra consisting of matrices whose rows are patterns identical up to the permutation and sign changes. Functions belonging to the same class are considered to be similar to each other.

7.1.1

Similarity of Ternary Bent Functions

The following example illustrates the notion of similarity between bent functions as it is understood in the present book by referring to the proposed classification. Example 7.2 Consider two ternary bent functions . f 1 and . f 2 in three variables specified by the function vectors F1 = [1, 1, 0, 0, 0, 2, 1, 1, 0, 1, 2, 2, 0, 1, 1, 1, 2, 2, 1, 0, 1, 0, 2, 0, 1, 0, 1]T ,

.

F2 = [2, 1, 2, 1, 0, 1, 2, 1, 2, 0, 0, 2, 2, 2, 1, 0, 0, 2, 1, 2, 2, 0, 1, 1, 1, 2, 2]T . We write the matrix-valued equivalents of these functions as follows:

7.1

Matrix-Valued Equivalents of Bent Functions

⎡⎡

1 .f1 = ⎣⎣ 0 1 ⎡⎡ 2 ⎣ ⎣ f2 = 1 2

⎤ ⎡ 0 1 2⎦,⎣0 0 1 ⎤ ⎡ 12 0 ⎣ ⎦ 01 , 2 12 0 1 0 1

⎤ ⎡ 2 1 1⎦,⎣0 2 1 ⎤ ⎡ 02 1 ⎣ ⎦ 21 , 0 02 1 2 1 2

183

⎤⎤ 1 0 ⎦⎦ , 1 ⎤⎤ 22 1 1 ⎦⎦ . 22

0 2 0

We perform encoding of patterns appearing in these matrix-valued functions as .110 = a, 002 = b, .122 = c, and recall that in the analysis of patterns in the present considerations permutation of their elements is allowed. In this encoding, the function vectors for considered functions can be written as

.

F1 = [aba|cac|aba]T = [AC A]T ,

.

F2 = [cac|bcb|cac]T = [C BC]T , where.aba = A,.bcb = B,.cac = C. It can be observed that these functions have the function vectors of the same structure, meaning that two identical subvectors are separated by the third subvector, .aba, .cac, .bcb, then . AC A and .C BC. These subvectors appear as permuted versions, for example, .110, .011, and .101 are considered as equivalent subvectors. Therefore, functions that have the same structure belong to the same class, as it will be discussed below. This example suggests the following definition of similarity of ternary functions that are equivalents of the corresponding definitions in the binary case. Definition 7.1 Two ternary functions . f 1 and . f 2 are similar to each other if in their function vectors there are patterns of length .3k , .1 < k < ˪n/2˩, identical up to the permutation and sign changes of their elements. In the classification proposed in [1, 11], bent functions similar in the above sense belong to the same class.

7.1.2

Matrix-Valued Vilenkin–Chrestenson Coefficients of Linear Ternary Functions

The question and a possible answer to which we are interested in this chapter can be alternatively formulated in the following way. In truth-vectors of linear binary functions, there are patterns that repeat. For example, these are patterns .1, 0, 0, 1 and .0, 1, 1, 0 as it can be easily seen for example in the linear binary functions .x1 ⊕ x2 ⊕ x3 ⊕ x4 , and . x 1 ⊕ x 2 ⊕ x 3 ⊕ x 4 ⊕ x 5 ⊕ x 6 . It is the same for linear ternary functions as is illustrated by Example 7.3 below. Further, linear ternary functions are isomorphic to Vilenkin–Chrestenson

184

7 Matrix-Valued Ternary Bent Functions

functions, i.e., rows of the Vilenkin–Chrestenson matrix, and due to that, their Vilenkin– Chrestenson spectrum has a single non-zero coefficient. For a linear function in terms of all .n variables, this is the coefficient with the index .3n − 1, starting counting from .0. All other coefficients are .0. If we consider the matrix-valued coefficients, the last coefficient is a non-zero matrix consisting of a single pattern with negative signs assigned in different manners. Example 7.3 Consider the ternary linear function in three variables .

f = 2x1 ⊕ x2 ⊕ 2x3 .

Its function vector is F = [0, 2, 1, 1, 0, 2, 2, 1, 0, 2, 1, 0, 0, 2, 1, 1, 0, 2, 1, 0, 2, 2, 1, 0, 0, 2, 1]T .

.

The .(3 × 3) matrix-valued function is ⎤⎤ ⎤ ⎡ ⎤ ⎡ 102 210 021 .f = ⎣ ⎣ 1 0 2 ⎦ , ⎣ 0 2 1 ⎦ , ⎣ 2 1 0 ⎦ ⎦ . 021 102 210 ⎡⎡

The .(3 × 3)-absolute-valued spectrum of this function is ⎡⎡

⎤ ⎡ ⎤ ⎡ ⎤⎤ 000 000 111 .s f = ⎣ ⎣ 0 0 0 ⎦ , ⎣ 0 0 0 ⎦ , ⎣ 1 1 1 ⎦ ⎦ . 000 000 111 In this chapter, we try to find answers to the following questions. Can we possibly observe some patterns in highly non-linear functions as bent functions? Since bent functions are functions with low autocorrelation, what are possible relationships between their particular values, or value of their matrix-valued coefficients?

7.2

Classification Approach for Ternary Bent Functions

The same as in the case of binary bent functions, it is hard to observe patterns and possible regularities in function vectors of bent functions in either original, Vilenkin–Chrestenson spectral, or autocorrelation domain. For these reasons, we are looking for patterns and regularities in matrix-valued spectral coefficients, the computing of which as noticed above is equivalent to performing steps of the Fast Vilenkin–Chrestenson Transform (FVCT) algorithm. A rationale for this way of classifying bent functions is the same as for the binary bent functions and can be summarized in the following observations.

7.2

Classification Approach for Ternary Bent Functions

185

In the .i-th step of computing .(3 × 3)-coefficients of ternary functions, we perform operations specified by the basic Vilenkin–Chrestenson matrix .V(1) over the function values at the positions at the mutual distance of .3n−i , .i = 1, . . . , n. Therefore, in the .i-th step computations are performed over values within blocks of length .3n−i . The procedure continues until we perform the first .n − k steps to compute the .(k × k) matrix-valued spectra. Since after .n steps, the absolute values of Vilenkin–Chrestenson coefficients for a bent function have to be.3n/2 , the values computed in previous steps must satisfy some restrictions, which can be fulfilled just if the function takes particular combinations of function values. We are looking for such combinations within the first .n − k steps of the fast Vilenkin– Chrestenson transform applied to matrix-valued functions. Therefore, these distributions reflect into patterns representing rows of matrix-valued Vilenkin–Chrestenson coefficients, i.e., in their structure. Under the term structure of matrix-valued coefficients, we mean appearance of patterns equivalent under permutation and sign changes of their elements as well as permutation of patterns within a coefficient, and permutation of coefficients in the matrix-valued Vilenkin–Chrestenson spectra. Thus, by comparing the matrix-valued coefficients, some relationships among bent functions sharing the same patterns in these coefficients, equivalently among subsets of their function values, can be observed. Therefore, we split bent functions into classes depending on the relationships among elements of their matrix-valued coefficients. These relationships can be conveniently expressed in terms of compositions introduced in Sect. 1.9 defined as follows [1]. Definition 7.2 Consider a vector .γ = [γ1 , γ2 , . . . , γn ], whose elements .γi , .i = 1, . . . , n, are taken from a set .β = {β1 , β2 , . . . , βm }. Denote by .Ci (γ) the number of elements .γ j of .γ that are equal to .βi , i.e., Ci (γ) = { j|1 ≤ j ≤ n, γ j = βi }.

.

Then, .C(γ) = [C1 (γ), C2 (γ), . . . , Cm (γ)] is called the composition of .γ. Example 7.4 Let .β = {0, 1, 2}, .γ = (0, 1, 1, 2) and .α = (0, 0, 0, 1). Then, .C(γ) = (1, 2, 1), .C(α) = (3, 1, 0). ) .γ of length .n and the set .β of size .m, the number of compositions is ( For a vector n+m−1 . [2]. m−1 Given is a matrix-valued spectrum with .3n−2k matrix-valued .(3k × 3k ) spectral coefficients. Each row of a matrix-valued spectral coefficient has a unique composition. Then, the column formed from the row compositions has a unique column composition (of row compositions). This composition is called the second order composition.

186

7 Matrix-Valued Ternary Bent Functions

Definition 7.3 (Similarity of matrix-valued coefficients) The matrix-valued spectral coefficients are similar if they have the same second order composition. Definition 7.4 (Similarity of matrix-valued spectra) Two matrix-valued spectra are similar if they have the same composition of second order compositions. The following example illustrates how the concept of compositions reduces the number of possible classes of functions derived from an analysis of their function vectors, in a similar way as the concept of the flat spectrum reduces the number of possible spectral values. Notice that for binary vectors, the concept of composition coincides with the Hamming weight. Example 7.5 Consider a ternary function in .8 variables. Its function vector is of length 8 .3 = 6561. We split it into consecutive subvectors of length .9 and arrange them as a vector of length .81 whose elements are .(9 × 9) matrices .R(k), .k = 1, 2, . . . 81. Denote the .l-th row of the .k-th matrix .R(k) as .rk,l , .1 ≤ k ≤ 81, .1 ≤ l ≤ 8. We form the composition .Crk,l of the row .rk,l . ( ) 9+3−1 = 55. Then, we The number of possible distinct row compositions is . 3−1 replace each .(9 × 9) matrix by the column vector consisting of their row compositions of this column vector and call it matrix column composition. The number of distinct ( row ) 9 + 54 ≈ 2.3 · 1010 . matrix row column compositions is . 54 Finally, we consider the composition of the .81 matrix row column compositions. Their number is ⎛( ) ⎞ 63 + 80 ⎜ 54 ⎟ ⎟ ≈ 10720 . .⎜ ( ⎝ 63 ) ⎠ −1 54 8

The number of all ternary functions in eight variables is .33 which is over .103000 . Therefore, the reduction is quite large. Definition 7.5 Two ternary bent functions belong to the same class if their matrix-valued spectra are similar to each other.

7.3

Classes of Ternary Bent Functions for .n = 3 and .n = 4

In this section, we determine classes of ternary bent functions for .n = 3 of the degrees .3 and 4, and of the degree.3 for.n = 4. The classes are determined by referring to the matrix-valued spectra of the considered functions.

.

7.3

Classes of Ternary Bent Functions for n = 3 and n = 4

7.3.1

187

(3 × 3)-spectra for Ternary Bent Functions of the Degree .3 for .n = 3

.

As already discussed, the degree of a binary bent function is defined as the maximal number of variables in the product terms in its algebraic normal form, i.e., positive polarity Reed– Muller expression [3, 4]. Binary bent functions have degree restricted to .n/2 of variables. Therefore, the search space for bent functions in the Reed–Muller domain is considerably reduced if restricted to functions having non-zero coefficients in the algebraic normal form corresponding to the product with the allowed number of variables [5]. The corresponding restriction of the degree applies to ternary bent functions with respect to the generalized Reed–Muller expressions. As shown in [6], the maximal degree of a . p-ary bent function + 1, which in the case . p = 3 and .n = 3 is .4. The maximal degree of is .deg( f ) = ( p−1)n 2 , which for . p = 3 and .n = 3 is .3 weakly regular ternary bent functions is .deg( f ) = ( p−1)n 2 [6]. We followed the approach used by Rothaus in [7] for binary bent functions, and worked first with functions of the degree up to .3. We analyzed and determined the classes for all .341.172 ternary bent functions of degree up to .3 for .n = 3 by using the above observation to restrict the search space for bent functions in the Reed–Muller domain for ternary functions. We consider just functions having non-zero Reed–Muller coefficients at the positions corresponding to product terms with no more variables than the degree of ternary bent functions. Further, since adding an affine function to a bent function produces another bent function, it is sufficient to allow non-zero coefficients just to quadratic and ternary terms in the algebraic normal form. In the case . p = 3, .n = 3, this means .13 possible positions, .6 and .7 positions corresponding to quadratic and ternary terms, respectively. In this way we generated .4.212 ternary bent functions of the degree up to .3. Then, to each of the produced bent functions any combination of variables and the constant.1 can be added, which means another .81 possible bent functions. Therefore, for .n = 3 there are in total .4.212 × 81 = 341.172 ternary bent functions of the degree up to .3. The total number of ternary bent functions of the degree up to .4 generated in this way is .155.844 × 81 = 12.623.364 functions. For determining the classes of ternary bent functions, we used the property that adding a variable to a function changes the phase and not the value of the complex-valued Vilenkin–Chrestenson coefficients. Since we are working with absolute values of Vilenkin– Chrestenson spectra, it follows that bent functions and functions derived from them by adding the variables have the same absolute-valued spectra. From the classification point of view, it means that they belong to the same class.

188

7 Matrix-Valued Ternary Bent Functions

Table 7.1 Initial ternary bent functions used in experiments and the number of bent functions produced from them by spectral invariant operations 1 2 3

Functions

Number of bent functions

2 .x ⊕ x2 x3 1 2 2 2 .x ⊕ x ⊕ x 1 2 3 2 .x1 x3 ⊕ x 2

14518 13127 12181

Example 7.6 Consider the functions r = x32 ⊕ 2x22 ⊕ 2x1 x3 ⊕ x1 x32 ⊕ 2x1 x2 x3 ⊕ x1 x22 ⊕ 2x12 x3 ⊕ 2x12 x2 ,

.

s = r ⊕ x2 ⊕ x3 = x32 ⊕ 2x22 ⊕ 2x1 x3 ⊕ x1 x32 ⊕ 2x1 x2 x3 ⊕ x1 x22 ⊕ 2x12 x3 ⊕ 2x12 x2 ⊕ x2 ⊕ x3 . A computation of .(3 × 3) matrix-valued absolute-valued Vilenkin–Chrestenson spectra shows ⎤⎤T ⎤ ⎡ ⎤ ⎡ 022 022 322 .Sr = Ss = ⎣⎣ 2 2 0 ⎦ , ⎣ 2 2 3 ⎦ , ⎣ 2 2 0 ⎦⎦ . 232 202 202 ⎡⎡

The explanation is that, as mentioned above, adding a variable to a function changes the phase and not the absolute value of Vilenkin–Chrestenson coefficients. Due to this observation, it is sufficient to determine matrix-valued absolute-valued Vilenkin–Chrestenson spectra of .4.212 ternary bent functions. By analysis of these matrixvalued spectra, we discovered that there are five different classes. Table 7.2 shows these classes containing .96228, .8748, .26244, .52488, and .157464 functions, respectively. Then, we determined three sets of ternary bent functions by the application of spectral invariant operations to three randomly chosen ternary bent functions. Table 7.1 shows these initial bent functions and the number of distinct ternary bent functions produced from them by spectral invariant operations. All these functions are used in the experiments. By computing absolute-valued spectra, generated bent functions are classified each in a particular class out of the five classes in Table 7.2. It is interesting to observe that linear ternary functions have a single non-zero matrixvalued coefficient, and it is a .(3 × 3) matrix with all elements equal to .1. The difference among different linear functions is in the position of this coefficient in the spectrum, and different linear functions can have the same non-zero matrix-valued coefficient. Notice that in this approach, the same as in [8], allowed are permutations of both rows and columns, as well as permutations of elements in rows and columns. Further, the order of coefficients in the matrix-valued Vilenkin–Chrestenson spectrum is also permuted. Due

7.3

Classes of Ternary Bent Functions for n = 3 and n = 4

189

Table 7.2 Absolute-valued Vilenkin–Chrestenson coefficients for ternary bent functions for .n = 3 of degree .3 Class 1

2

3

4

5

Pattern ⎡ ⎤ 222 ⎢ ⎥ .⎣ 2 2 2 ⎦ 222 ⎡ ⎤ 333 ⎢ ⎥ .⎣ 0 0 0 ⎦ 000 ⎡ ⎤ 300 ⎢ ⎥ .⎣ 3 0 0 ⎦ 300 ⎡ ⎤ 300 ⎢ ⎥ .⎣ 2 2 2 ⎦ 222 ⎡ ⎤ 322 ⎢ ⎥ .⎣ 2 2 0 ⎦ 202



⎤ 22 ⎥ 2 2⎦ 22 ⎤ 00 ⎥ 3 3⎦ 00 ⎤ 30 ⎥ 3 0⎦ 30 ⎤ 03 ⎥ 2 2⎦ 22 ⎤ 22 ⎥ 2 3⎦ 02



⎤ 00 ⎥ 0 3⎦ 30 ⎤ 03 ⎥ 0 0⎦ 30

2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 3 0 ⎡ 0 ⎢ .⎣ 0 0 ⎡ 0 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 2 2



⎤ 22 ⎥ 2 2⎦ 22 ⎤ 00 ⎥ 0 0⎦ 33 ⎤ 03 ⎥ 0 3⎦ 03 ⎤ 30 ⎥ 2 2⎦ 22 ⎤ 22 ⎥ 2 0⎦ 32



⎤ 03 ⎥ 3 0⎦ 00 ⎤ 30 ⎥ 0 3⎦ 00

2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 0 3 ⎡ 0 ⎢ .⎣ 0 0 ⎡ 0 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 2 2

Table 7.3 Subclasses in Class .3 in Table 7.2 Class 1

2

Pattern ⎡ ⎤ 030 ⎢ ⎥ .⎣ 3 0 0 ⎦ 003 ⎤ ⎡ 300 ⎥ ⎢ .⎣ 0 3 0 ⎦ 003

3 ⎢ .⎣ 0 0 ⎡ 0 ⎢ .⎣ 3 0

0 ⎢ .⎣ 0 3 ⎡ 0 ⎢ .⎣ 0 3

to that, each class can be split into subclasses. For instance, Table 7.3 shows two subclasses in Class .3. Example 7.7 The functions . f c1 , . f c2 , . f c3 , . f c4 , and . f c5 belong respectively to Classes .1, .2, 3, .4, and .5 in Table 7.2.

.

190

7 Matrix-Valued Ternary Bent Functions

Fc1 = [0, 0, 0, 1, 2, 0, 1, 0, 2, 1, 1, 1, 1, 2, 0, 0, 2, 1, 1, 1, 1, 0, 1, 2, 1, 0, 2]T ,

.

Fc2 = [1, 2, 2, 1, 0, 1, 0, 0, 2, 0, 1, 1, 2, 1, 2, 0, 0, 2, 2, 0, 0, 0, 2, 0, 0, 0, 2]T , Fc3 = [2, 2, 1, 1, 0, 1, 1, 2, 2, 2, 0, 0, 2, 2, 1, 0, 2, 0, 2, 1, 2, 0, 1, 1, 2, 2, 1]T , Fc4 = [1, 1, 0, 0, 1, 1, 0, 2, 0, 1, 0, 1, 1, 1, 0, 2, 0, 0, 1, 2, 2, 2, 1, 2, 1, 1, 0]T , Fc5 = [2, 1, 2, 1, 0, 1, 2, 1, 2, 0, 0, 2, 2, 2, 1, 0, 0, 2, 1, 2, 2, 0, 1, 1, 1, 2, 2]T . The matrix-valued absolute-valued spectra of these functions are ⎡⎡ S f c1 =

.

S f c2 =

S f c3 =

S f c4 =

S f c5 =

S f c6 =

2 ⎣⎣ 2 2 ⎡⎡ 0 ⎣⎣ 0 3 ⎡⎡ 3 ⎣⎣ 0 0 ⎡⎡ 0 ⎣⎣ 0 0 ⎡⎡ 3 ⎣⎣ 3 3 ⎡⎡ 0 ⎣⎣ 0 0

⎤ ⎡ ⎤ ⎡ ⎤⎤ 22 222 222 2 2 ⎦ , ⎣ 2 2 2 ⎦ , ⎣ 2 2 2 ⎦⎦ , 22 222 222 ⎤ ⎡ ⎤ ⎡ ⎤⎤ 00 000 333 0 0 ⎦ , ⎣ 3 3 3 ⎦ , ⎣ 0 0 0 ⎦⎦ , 33 000 000 ⎤ ⎡ ⎤ ⎡ ⎤⎤ 00 030 003 0 3 ⎦ , ⎣ 3 0 0 ⎦ , ⎣ 0 3 0 ⎦⎦ , 30 003 300 ⎤ ⎡ ⎤ ⎡ ⎤⎤ 03 300 030 0 3 ⎦ , ⎣ 3 0 0 ⎦ , ⎣ 0 3 0 ⎦⎦ , 03 300 030 ⎤ ⎡ ⎤ ⎡ ⎤⎤ 00 030 003 0 0 ⎦ , ⎣ 0 3 0 ⎦ , ⎣ 0 0 3 ⎦⎦ , 00 030 003 ⎤ ⎡ ⎤ ⎡ ⎤⎤ 03 300 030 0 3 ⎦ , ⎣ 3 0 0 ⎦ , ⎣ 0 3 0 ⎦⎦ . 03 300 030

For simplicity, in what follows, matrix-valued absolute-valued coefficients will be mentioned just as absolute-valued coefficients. Example 7.8 Both functions . f 1 and . f 2 in Example 7.2 belong to Class .3, since their absolute-valued spectra are ⎡⎡

S f1

.

S f2

3 = ⎣⎣ 3 3 ⎡⎡ 0 = ⎣⎣ 0 0

⎤ ⎡ 0 0 0⎦,⎣0 0 0 ⎤ ⎡ 3 03 0 3⎦,⎣3 3 03

0 0 0

⎤ ⎡ 0 0 0⎦,⎣0 0 0 ⎤ ⎡ 0 00 0 0⎦,⎣0 0 00 3 3 3

⎤⎤ T 3 3 ⎦⎦ , 3 ⎤⎤ T 30 3 0 ⎦⎦ . 30

0 0 0

7.3

Classes of Ternary Bent Functions for n = 3 and n = 4

191

The following example illustrates the appearance of patterns in the value vectors for randomly selected functions in the same class. Example 7.9 We randomly selected two ternary functions. f 3 and. f 4 from Class.5 and wrote their value vector as matrix-valued equivalents as ⎡⎡

0 .f3 = ⎣⎣ 1 1 ⎡⎡ 0 f4 = ⎣⎣ 2 2

⎤ ⎡ 00 0 1 1⎦,⎣1 11 1 ⎤ ⎡ 12 2 1 0⎦,⎣1 22 1

⎤ ⎡ 12 0 2 0⎦,⎣1 20 1 ⎤ ⎡ 22 1 2 0⎦,⎣0 02 0

⎤⎤ 21 0 2 ⎦⎦ , 02 ⎤⎤ 02 0 0 ⎦⎦ . 12

In . f 3 , there are two times the pattern .1, 1, 1 to which in . f 4 corresponds .2, 2, 2. Recall that .2 = −1 modulo .3, therefore, the pattern .2, 2, 2 is actually the pattern .1, 1, 1 with a negative sign of its elements. The patterns .0, 0, 0 and .0, 1, 2 appear two and six times in both functions, respectively. Example 7.10 We randomly selected two ternary functions . f 5 and . f 6 from Class .1 and wrote their truth-vector as matrix-valued equivalents as ⎡⎡

0 .f5 = ⎣⎣ 1 1 ⎡⎡ 0 f6 = ⎣⎣ 2 2

7.3.2

⎤ ⎡ 1 00 1 1⎦,⎣0 1 11 ⎤ ⎡ 00 0 2 2⎦,⎣0 22 1

⎤ ⎡ 1 02 2 1⎦,⎣1 0 02 ⎤ ⎡ 12 1 1 2⎦,⎣2 20 1

⎤⎤ 20 2 0 ⎦⎦ , 12 ⎤⎤ 02 1 0 ⎦⎦ . 02

(3 × 3)-spectra for Ternary Bent Functions of the Degree .4 for n=3

. .

Increased degree implies a larger number of bent functions and then also the enlarged number of classes the same as, for example, in the classification of affine equivalent bent functions mentioned above. Table 7.4 shows new classes of ternary bent functions in .n = 3 variables of degree .4. Notice that the matrix-valued coefficients in Class .3 in this table are related by the composition to the coefficients in Class .5 in Table 7.2. Example 7.11 The following functions belong to the classes in Table 7.4. The following bent function of degree .4 belongs to Class 1 in Table 7.4.

192

7 Matrix-Valued Ternary Bent Functions

Table 7.4 Additional absolute-valued Vilenkin–Chrestenson coefficients for ternary bent functions for .n = 3 of degree .4 Class 1

2

3

4

5

6

Pattern ⎡ ⎤ 200 ⎢ ⎥ .⎣ 2 3 0 ⎦ 203 ⎡ ⎤ 300 ⎢ ⎥ .⎣ 3 0 0 ⎦ 222 ⎡ ⎤ 320 ⎢ ⎥ .⎣ 2 2 2 ⎦ 202 ⎡ ⎤ 222 ⎢ ⎥ .⎣ 2 3 0 ⎦ 202 ⎡ ⎤ 323 ⎢ ⎥ .⎣ 0 0 2 ⎦ 200 ⎡ ⎤ 320 ⎢ ⎥ .⎣ 0 2 3 ⎦ 020



2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 0 2 ⎡ 0 ⎢ .⎣ 2 2 ⎡ 2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 3 2 ⎡ 0 ⎢ .⎣ 3 0

⎤ 33 ⎥ 0 0⎦ 00 ⎤ 30 ⎥ 3 0⎦ 22 ⎤ 23 ⎥ 2 2⎦ 02 ⎤ 22 ⎥ 0 3⎦ 02 ⎤ 20 ⎥ 3 2⎦ 00 ⎤ 20 ⎥ 2 0⎦ 23



2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 0 2 ⎡ 0 ⎢ .⎣ 2 2 ⎡ 2 ⎢ .⎣ 2 2 ⎡ 0 ⎢ .⎣ 0 2 ⎡ 0 ⎢ .⎣ 0 3

⎤ 00 ⎥ 0 3⎦ 30 ⎤ 03 ⎥ 0 3⎦ 22 ⎤ 20 ⎥ 2 2⎦ 32 ⎤ 22 ⎥ 0 0⎦ 32 ⎤ 20 ⎥ 0 2⎦ 33 ⎤ 23 ⎥ 2 0⎦ 20

Fnova−1 = [0, 2, 2, 1, 1, 2, 1, 2, 1, 2, 0, 0, 0, 1, 1, 0, 1, 1, 2, 1, 1, 0, 1, 0, 0, 0, 1]T ,

.

Fnova−2 = [0, 0, 0, 1, 1, 1, 1, 1, 1, 0, 1, 2, 1, 2, 0, 0, 1, 2, 0, 2, 1, 1, 0, 2, 0, 2, 1]T , Fnova−3 = [0, 2, 2, 1, 1, 2, 1, 2, 1, 0, 2, 0, 0, 2, 0, 2, 1, 2, 0, 0, 1, 0, 2, 2, 2, 0, 2]T , Fnova−4 = [0, 0, 0, 0, 1, 2, 0, 2, 1, 2, 2, 2, 2, 1, 0, 0, 1, 2, 2, 2, 0, 2, 1, 1, 2, 0, 2]T , Fnova−5 = [0, 2, 2, 0, 0, 1, 0, 1, 0, 0, 2, 2, 1, 1, 2, 2, 0, 2, 0, 0, 2, 2, 2, 1, 2, 2, 1]T , Fnova−6 = [0, 0, 0, 2, 2, 0, 2, 1, 2, 0, 2, 2, 0, 2, 0, 1, 2, 0, 0, 0, 1, 1, 1, 0, 0, 2, 1]T . Their Reed–Muller spectra confirming that they have degree .4 are R fnova−1 = [0, 0, 2, 0, 1, 0, 1, 0, 0, 0, 0, 1, 0, 2, 0, 0, 0, 0, 2, 0, 1, 0, 0, 0, 0, 0, 0]T ,

.

R fnova−2 = [0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 2, 0, 0, 1, 0, 0]T , R fnova−3 = [0, 0, 2, 0, 1, 0, 1, 0, 0, 0, 0, 1, 0, 2, 0, 0, 0, 0, 0, 1, 1, 2, 0, 0, 0, 0, 0]T , R fnova−4 = [0, 0, 0, 0, 1, 0, 0, 0, 0, 0, 1, 2, 2, 0, 0, 1, 0, 0, 2, 2, 1, 2, 1, 0, 1, 0, 0]T , R fnova−5 = [0, 0, 2, 0, 1, 0, 0, 0, 0, 0, 2, 2, 2, 2, 0, 2, 0, 0, 0, 1, 1, 2, 1, 0, 1, 0, 0]T , R fnova−6 = [0, 0, 0, 0, 0, 2, 2, 1, 0, 0, 1, 0, 1, 0, 0, 0, 0, 0, 0, 2, 2, 0, 0, 0, 0, 0, 0]T .

7.3

Classes of Ternary Bent Functions for n = 3 and n = 4

7.3.3

193

(3 × 3)-spectra for Ternary Functions for .n = 4

.

We generated different ternary bent functions in four variables by the application of spectral invariant operations to the initial function . f = x1 x2 ⊕ x3 x4 and determined their absolutevalued spectra. The number of obtained distinct bent functions is determined by the used spectral invariant operations and the order of their applications. We removed identical functions produced by different combinations of spectral invariant operations and different order of their applications. In this way, we produced .8580 distinct ternary bent functions in four variables and used them in the considerations presented below. For .n = 4, the matrix-valued Vilenkin–Chrestenson spectra consist of .9 coefficients which are .(3 × 3) matrices. By inspection of spectra of these .8580 functions discovered are five classes of bent functions with spectral coefficients corresponding to the coefficients in Table 7.2, however, with their matrix elements determined by .9 instead of .3 different compositions. Further, due to the larger normalization factor in the Vilenkin–Chrestenson transform, the values of matrix elements are divided by .3 and rounded to the nearest integer. For .n = 4, and .(3 × 3) matrices, compared with the case .n = 3, we should perform two more steps to get the final spectrum of bent functions which should be flat. Due to this, there is another combination of values in absolute-valued .(3 × 3)-spectra leading to the flat spectrum with Vilenkin–Chrestenson coefficients whose absolute values are .32 = 9. This absolute-valued mv spectrum consists of .9 coefficients which are .(3 × 3) matrices with a single non-zero element the position of which is different in each matrix. These spectra constitute the .6-th class of ternary bent functions for .n = 4, which is illustrated by Example 7.13. Such matrix-valued coefficients are of the form ⎡

⎤ r 00 .R = ⎣ 0 0 0 ⎦ , 000 where the position of the single non-zero element .r is different in each matrix. Example 7.12 We generated .37908 distinct ternary bent functions with quadratic terms in their arithmetic normal form by using spectral invariant operations. Table 7.5 shows the number of bent functions per class for the .6 above-mentioned classes for these quadratic ternary bent functions in four variables.

Example 7.13 The ternary function of degree .3 in four variables specified by the function vector

194

7 Matrix-Valued Ternary Bent Functions

Table 7.5 Number of functions per class for considered quadratic ternary bent functions in four variables Class

1

2

3

4

5

6

.#

26244

2592

2592

2592

2592

1296

f

F = [0, 0, 0, 2, 1, 0, 2, 0, 1, 0, 2, 1, 0, 1, 2, 1,

.

1, 1, 0, 1, 2, 1, 1, 1, 0, 2, 1, 0, 2, 1, 2, 0, 1, 2, 2, 2, 0, 1, 2, 0, 0, 0, 1, 0, 2, 0, 0, 0, 1, 0, 2, 0, 1, 2, 0, 1, 2, 2, 2, 2, 2, 1, 0, 0, 0, 0, 0, 2, 1, 1, 2, 0, 0, 2, 1, 1, 2, 0, 0, 0, 0]T has the .(3 × 3)-absolute-valued spectrum of .9 coefficients which are .(3 × 3) matrices .qa = [qi, j ], .a = 0, 1, . . . , 8, .i, j ∈ {0, 1, 2} in which the non-zero element .9 is at the positions .q0 = [q0,0 ], .q1 = [q1,0 ], .q2 = [q2,0 ], .q3 = [q2,2 ], .q4 = [q0,2 ], .q5 = [q1,2 ], .q6 = [q1,1 ], .q7 = [q2,1 ], and .q8 = [q0,1 ]. Therefore, S f = [q0 , q1 , q2 , q3 , q4 , q5 , q6 , q7 , q8 ]T ,

.

where ⎤ ⎤ ⎤ ⎡ ⎡ 900 000 000 q0 = ⎣ 0 0 0 ⎦ , q1 = ⎣ 9 0 0 ⎦ , q2 = ⎣ 0 0 0 ⎦ 000 000 900 ⎡



⎡ ⎡ ⎤ ⎤ ⎤ 000 009 000 . q3 = ⎣ 0 0 0 ⎦ , q4 = ⎣ 0 0 0 ⎦ , q5 = ⎣ 0 0 9 ⎦ , 009 000 000 ⎡

⎡ ⎡ ⎤ ⎤ ⎤ 000 000 090 q6 = ⎣ 0 9 0 ⎦ , q7 = ⎣ 0 0 0 ⎦ , q8 = ⎣ 0 0 0 ⎦ . 000 090 000 This function belongs to Class .6, which is the additional class for functions in four variables of degree .3 compared to the classes in Table 7.2 for ternary functions of degree .3 in three variables.

7.3

Classes of Ternary Bent Functions for n = 3 and n = 4

7.3.4

195

Ternary Linear Functions and Ternary Bent Functions

Ternary linear functions are defined as the sum of all possible combinations of variables with constants.1 and.2 as coefficients in these linear combinations. There are.3n linear functions in n .n variables, and we denote them and their function vectors by.li and.Li ,.i = 0, 1, . . . , 3 − 1, respectively. We denote by .Ln the set of all linear functions for a given .n. The first function in .Ln , i.e., .l0 is the constant function whose values can be either .0, .1, or .2, and we will use the notation .l0,0 , .l0,1 , and .l0,2 to differentiate these possible constant functions. The set .Ln of linear functions is isomorphic to the set of .3n Vilenkin–Chrestenson functions representing the rows of the Vilenkin–Chrestenson matrix for the given.n. Since the Vilenkin– Chrestenson functions are usually written in the Hadamard ordering to provide Kronecker product representable Vilenkin–Chrestenson transform matrix, we keep the same initial ordering for linear functions in .Ln . Ternary variables viewed as functions in .n variables, where just a single variable is essential, are balanced functions. It follows that linear functions as their linear combinations are also balanced functions. Thus, their distribution is . D = (3n−1 , 3n−1 , 3n−1 ). Table 7.6 shows distributions of function values for ternary linear functions for .n = 1, 2, 3, 4, 5, 6, 7, 8. It becomes apparent that the coefficients of . Dl,k = 3(k−1) . Example 7.14 Table 7.7 shows functional expressions and function vectors for linear ternary functions in two variables in the Hadamard ordering. In the context of linear functions, we also use the constant functions .l0,1 = 1 and .l0,2 = 2, whose function vectors are respectively .L0,1 = [1, 1, 1, 1, 1, 1, 1, 1, 1]T and .L0,2 = [2, 2, 2, 2, 2, 2, 2, 2, 2]T . It is interesting to observe that linear functions have a single non-zero .(k × k) matrixvalued coefficient, the rows of which are patterns of.k values.1. This resembles the coefficients in Class.1 as shown by Example 7.3. The same is true for other linear functions in both binary and ternary cases. Table 7.6 Distribution of function values for ternary linear functions for .n = 1, 2, 3, 4, 5, 6, 7, 8

.n

Distribution

1

. Dl,1

= (1, 1, 1)

2

. Dl,2

= (3, 3, 3)

3

. Dl,3

= (9, 9, 9)

4

. Dl,4

= (27, 27, 27)

5

. Dl,5

= (81, 81, 81)

6

. Dl,6

= (243, 243, 243)

7

. Dl,7

= (729, 729, 729)

8

. Dl,8

= (2187, 2187, 2187)

196

7 Matrix-Valued Ternary Bent Functions

Table 7.7 Ternary linear functions for .n = 2 Function .l 0,0

Function vector

=0

.F0

= [0, 0, 0, 0, 0, 0, 0, 0, 0]T

.l 1

= x2

.F1

= [0, 1, 2, 0, 1, 2, 0, 1, 2]T

.l 2

= 2x2

.F2

= [0, 2, 1, 0, 2, 1, 0, 2, 1]T

.l 3

= x1

.F3

= [0, 0, 0, 1, 1, 1, 2, 2, 2]T

.F4

= [0, 1, 2, 1, 2, 0, 2, 0, 1]T

.F5

= [0, 2, 1, 1, 0, 2, 2, 1, 0]T

= x1 ⊕ x2 .l 5 = x 1 ⊕ 2x 2 .l 4

.l 6

= 2x1

.F6

= [0, 0, 0, 2, 2, 2, 1, 1, 1]T

.l 7

= 2x1 ⊕ x2

.F7

= [0, 1, 2, 2, 0, 1, 1, 2, 0]T

.l 8

= 2x1 ⊕ 2x2

.F8

= [0, 2, 1, 2, 1, 0, 1, 0, 2]T

Non-linearity of bent functions requires that no zero-valued coefficients could appear, otherwise the function would be isomorphic to a Walsh, respectively Vilenkin–Chrestenson function, that are isomorphic to linear functions. At the same time, there are bent functions all whose .(k × k)-spectral coefficients are matrices consisting of rows that are the same pattern with different permutations or its elements and sign changes to ensure non-singularity of matrix-valued coefficients. The question is Can we speak about highly non-linear functions as bent functions which have absolutevalued spectra as in Class.1 that are more similar to linear functions than other bent functions whose coefficients have rows consisting of different patterns? It should be noticed that in the spectral domain patterns do not consist of successive elements in the function vector, but of the values at the positions from where fast algorithm for the Vilenkin–Chrestenson transform fetches data for computations in the corresponding steps of the algorithm.

7.4

Construction of Ternary Bent Functions from Ternary Linear Functions

The characteristics of linear functions and bent functions discussed in the previous section lead to a possibly contra-intuitive idea of constructing bent functions from linear functions which is expressed in [9]. The following example taken from [9] explains the basic idea on the example of binary bent functions. Example 7.15 The function vector of the basic binary bent function in four variable . f = x1 x2 ⊕ x3 x4 is F = [0, 0, 0, 1|0, 0, 0, 1|0, 0, 0, 1|1, 1, 1, 0]T ,

.

7.4

Construction of Ternary Bent Functions from Ternary Linear Functions

197

and it can be noticed that this is an unbalanced function as every other bent function, and that two distinct subvectors in .F, .F1 = [0, 0, 0, 1]T and its complement .F2 = [1, 1, 1, 0]T are also unbalanced as bent functions in two variables. Therefore, the function vector .F can be viewed as a concatenation of function vectors of bent functions in two variables . f 1 = x1 x2 and . f 2 = 1 ⊕ x1 x2 . Thus, F = [F1 , F1 , F1 , F2 ]T .

.

If we permute the variables .x2 ↔ x3 , the constructed function is . fl = x1 x3 ⊕ x2 x4 , and it is bent since any permutation of variables is a spectral invariant operation meaning that the absolute values of spectral coefficients, in this case the Walsh coefficients, are unchanged. Thus, the flat spectrum of . f is converted into the flat spectrum of . fl . The function vector .F of . f is converted into the function vector .Fl of . fl Fl = [0, 0, 0, 0|0, 1, 0, 1|0, 0, 1, 1|0, 1, 1, 0]T ,

.

the subvectors of which are balanced and linear functions .l0 = 0, .l1 = x2 , .l2 = x1 , .l3 = x1 ⊕ x2 . Thus, the function vector of this bent function .Fl in four variables is constructed by concatenating function vectors of linear functions in two variables including the constant function all whose elements are .0. If the constant .0 is replaced by .1, we get another bent function in four variables with the function vector Fl,1 = [1, 1, 1, 1|0, 1, 0, 1|0, 0, 1, 1|0, 1, 1, 0]T ,

.

and the functional expression as .

fl,1 = 1 ⊕ x2 ⊕ x2 x4 ⊕ x1 ⊕ x1 x3 ⊕ x1 x2 .

In constructing a ternary bent function from ternary linear functions, we differentiate the cases of functions with primary and secondary distributions discussed in Chap. 1, Sect. 1.9. As explained in [9], the bent functions with the secondary distribution cannot be constructed from linear functions. It is however shown that these functions can be constructed by using such functions in smaller number of variables applying the algorithm presented below to construct bent functions with the primary distribution from linear functions. For the functions with primary distribution, we first discuss construction of the basic ternary bent function . f p whose functional expression is the sum of disjoint pairs of variables in an even number of variables. We assume that given are the set .Ln of all linear functions in .n variables, these functions are ordered in the Hadamard order as discussed above and the constant function .l0,0 , as well as the constant functions .l0,1 , and .l0,2 . It is assumed that all linear and constant functions are specified by their function vectors.

198

7 Matrix-Valued Ternary Bent Functions

As presented in [9], the basic ternary bent function . f p in .2n variables . f p (2n) is constructed by concatenating the function vectors of linear functions in .Ln . Thus, F p (2n) = [Ln ]T = [L0 |L1 | · · · |Ln ]T .

.

In the case of an odd number of variables, the functional expression of . f p contains the square of a variable, while all other variables are involved in pairs of disjoint variables. Then, the basic ternary bent function in .2n + 1 variables . f p (2n + 1) is constructed by concatenating the function vectors of linear functions in.Ln three times by adding the constant .1 to the function vectors in the last two repetitions. The reason for repeating the concatenation three times and adding the constant .1 to these two parts is the following. A ternary variable 2 2 T . x i has the function vector .Xi = [0, 1, 2] , and the function vector of the square . x is .X = i i T [0, 1, 1] . Therefore, we follow this pattern since in the functional expression for a ternary function each variable .xi is represented as .Xi (1) = [1, xi , xi2 ] and the functional expression is defined as the Kronecker product of such representations of variables for .i = 0, 1, . . . , n [10]. Since for an odd number of variables, the square of a variable is added to the sum of disjoint pairs of variables, the function vector of a basic ternary bent function in an odd number of variables is constructed as F p (2n + 1) = [Ln |Ln ⊕ 1|Ln ⊕ 1]T

.

= [L0 |L1 | · · · |Ln |L0 ⊕ 1|L1 ⊕ 1| · · · |Ln ⊕ 1| L0 ⊕ 1|L1 ⊕ 1| · · · |Ln ⊕ 1]T , where .1 denotes the vector of length .3n all whose elements are .1. This method for constructing basic bent functions . f p for different number of variables from linear functions can be used to construct many other bent functions by manipulating subvectors corresponding to linear functions involved in the construction procedure. The possible operations which can be performed over these subvectors are the following: 1. Change the order of linear functions in .Ln from the Hadamard order to any other order. 2. Use the constants .0, .1, or .2, i.e., the constant functions .l0,0 , .l0,1 , .l0,2 . 3. Add the constant .1 or .2 to any linear function in .Ln . The adding of constants to a subset or all linear functions in .Ln is included. As discussed in Sect. 1.9, for .n even and .n / = 0 modulo .4, the sum of squares of variables can be viewed as another basic bent function, as for example for .n = 2, 6, 10, 14. These functions, however, cannot be generated by concatenating linear functions. In this case, we use functions of a smaller number of variables represented by the sum of squares of variables. We concatenate the function vectors of these functions in the same manner as when generating bent functions in an odd number of variables from linear functions. Therefore, the sum of squares function in.n variables is repeated three times and in the last two repetitions the constant .1 is added. The reason for using this principle of concatenation is that for an

7.4

Construction of Ternary Bent Functions from Ternary Linear Functions

199

Table 7.8 Basic bent functions for .n = 1 in terms of square of the variable Function

Function vector

f 0 = x12 2 . f1 = x ⊕ 1 1

.F0 (1)

= [0, 1, 1]T

.F1 (1)

= [1, 2, 2]T

2 . f2 = x ⊕ 2 1

.F2 (1)

= [2, 0, 0]T

.

odd number of variables, we add the square of a variable to the sum of disjoint products of variables. In the same way, we add the square of a variable to a function . f s in .n variables to get the function . f s in .(n + 1) variables. The function vector of a bent function . f s in .(n + 1) variables which is represented by the 2 is obtained as sum of squares of variables . f (x1 , x2 , . . . , xn+1 ) = x12 ⊕ x22 ⊕ · · · ⊕ xn+1 F(n+1) = [Fn |Fn ⊕ 1|Fn ⊕ 1]T ,

.

where .Fn is the function vector of the function in .n variables . f (x1 , x2 , . . . , xn ) = x12 ⊕ x22 ⊕ · · · ⊕ xn2 . Example 7.16 Table 7.8 shows the basic bent functions of a single variable whose functional expressions are squares of the variable. These functions can be concatenated as follows to construct the bent function in two variables with the secondary distribution .(1, 4, 4) as Fs (2) = [F0 (1)|F1 (1)|F1 (1)]T

.

= [0, 1, 1|1, 2, 2|1, 2, 2]T . The corresponding functional expression is . f (2) = x12 ⊕ x22 . The basic function in three variables . f s (3) = x12 ⊕ x22 ⊕ x32 is constructed as Fs (3) = [F(2)|F(2) ⊕ 1|F(2) ⊕ 1]T ,

.

= [F0 (1), F1 (1), F1 (1)|F1 (1), F2 (1), F2 (1), |F1 (1), F2 (1), F2 (1)]T , = [0, 1, 1, 1, 2, 2, 1, 2, 2, |1, 2, 2, 2, 0, 0, 2, 0, 0, |1, 2, 2, 2, 0, 0, 2, 0, 0]T . In the same way, the basic bent function in four variables . f s (4) = x12 ⊕ x22 ⊕ x32 ⊕ x42 is constructed as

200

7 Matrix-Valued Ternary Bent Functions

Fs (4) = [F(3)|F(3) ⊕ 1|F(3) ⊕ 1]T ,

.

= [F0 (1), F1 (1), F1 (1), F1 (1), F2 (1), F2 (1), F1 (1), F2 (1), F2 (1), | F1 (1), F2 (1), F2 (1), F2 (1), F0 (1), F0 (1), F2 (1), F0 (1), F0 (1), | F1 (1), F2 (1), F2 (1), F2 (1), F0 (1), F0 (1), F2 (1), F0 (1), F0 (1)]T , = [0, 1, 1, 1, 2, 2, 1, 2, 2, |1, 2, 2, 2, 0, 0, 2, 0, 0, |1, 2, 2, 2, 0, 0, 2, 0, 0, | 1, 2, 2, 2, 0, 0, 2, 0, 0, |2, 0, 0, 0, 1, 1, 0, 1, 1, |2, 0, 0, 0, 1, 1, 0, 1, 1, | 1, 2, 2, 2, 0, 0, 2, 0, 0, |2, 0, 0, 0, 1, 1, 0, 1, 1, |2, 0, 0, 0, 1, 1, 0, 1, 1]T . Different bent functions can be constructed by the following modification of the above basic method: 1. Select the constant either .l0,0 , .l0,1 , or .l0,2 . 2. Reorder the linear functions in an arbitrary order. 3. Add a constant .1 or .2 to all or any subset of linear functions. The following examples in [9] illustrate these possibilities to construct different bent functions from linear functions. Example 7.17 Consider a ternary function . f p whose function vector is obtained by concatenating function vectors of ternary linear functions F p = [l0,0 , l1 , l2 , l3 , l4 , l5 , l6 , l7 , l8 ]T .

.

Thus, F = [0, 0, 0, 0, 0, 0, 0, 0, 0, |1, 2, 0, 1, 2, 0, 1, 2, |0, 2, 1, 0, 2, 1, 0, 2, 1, |

.

0, 0, 0, 1, 1, 1, 2, 2, 2, |0, 1, 2, 1, 2, 0, 2, 0, 1, |0, 2, 1, 1, 0, 2, 2, 1, 0, | 0, 0, 0, 2, 2, 2, 1, 1, 1, |0, 1, 2, 2, 0, 1, 1, 2, 0, |0, 2, 1, 2, 1, 0, 1, 0, 2]T . This function is bent with the absolute values of Vilenkin–Chrestenson coefficients equal to .9 and its functional expression is .

f = x1 x3 ⊕ x2 x4 .

The following example illustrates the case when linear functions in .L4 are randomly permuted. Example 7.18 Consider a function . f 1 whose function vector .F1 is the permuted vector .F0 , i.e., we permuted linear functions in .L2 as

7.4

Construction of Ternary Bent Functions from Ternary Linear Functions

201

F1 = [l0,0 , l1 , l5 , l3 , l4 , l7 , l6 , l2 , l8 ]T .

.

The function vector of the constructed function is obtained by substituting the function vectors of linear functions as F1 = [0, 0, 0, 0, 0, 0, 0, 0, 0, |0, 1, 2, 0, 1, 2, 0, 1, 2, |0, 2, 1, 1, 0, 2, 2, 1, 0, |

.

0, 0, 0, 1, 1, 1, 2, 2, 2, |0, 1, 2, 1, 2, 0, 2, 0, 1, |0, 1, 2, 2, 0, 1, 1, 2, 0, | 0, 0, 0, 2, 2, 2, 1, 1, 1, |0, 2, 1, 0, 2, 1, 0, 2, 1, |0, 2, 1, 2, 1, 0, 1, 0, 2]T , and the functional expression is .

f 1 = x2 x4 ⊕ x2 x3 ⊕ 2x22 x3 ⊕ x1 x3 ⊕ x1 x2 x3 ⊕ x1 x22 x4 ⊕2x12 x2 x4 ⊕ 2x12 x2 x3 .

The constructed function is bent. It is interesting to observe that this function . f 1 has the degree four, while the basic ternary function with the same distribution but for different order of variables . f = x1 x2 ⊕ x3 x4 , as well as the function . f = x1 x3 ⊕ x2 x4 for the Hadamard ordering of linear functions, is of the degree two. Consider a function with reordered function vector consisting of linear functions as F2 = [l6 , l7 , l8 , l0,0 , l1 , l2 , l3 , l4 , l5 ]T .

.

For this function the complete function vector is F2 = [0, 0, 0, 2, 2, 2, 1, 1, 1, |0, 1, 2, 2, 0, 1, 1, 2, 0, |0, 2, 1, 2, 1, 0, 1, 0, 2, |

.

0, 0, 0, 0, 0, 0, 0, 0, 0, |0, 1, 2, 0, 1, 2, 0, 1, 2|0, 2, 1, 0, 2, 1, 0, 2, 1, | 0, 0, 0, 1, 1, 1, 2, 2, 2, |0, 1, 2, 1, 2, 0, 2, 0, 1, |0, 2, 1, 1, 0, 2, 2, 1, 0]T . This function is bent and its functional expression is .

f 2 = x2 x4 ⊕ x1 x3 ⊕ 2x3 .

The permutation to convert.F into.F1 corresponds to the FFT-like permutation matrix with the basic matrix .X(1) at the first position in the Kronecker product .P(2) = X(1) ⊗ I(1) applied to the vector of elements of .L2 , meaning that this is the spectral invariant operation .x1 = x1 ⊕ 2. It is clear that .F2 can be alternatively obtained from .F1 by the FFT-like permutation matrix .P(4) = X(1) ⊗ I(1) ⊗ I(1) ⊗ I(1). This follows from the property that . f 2 can be expressed by a sum-of-product expression with linear functions as co-factors [10]. Adding a constant to some linear functions that are concatenated preserves bentness.

202

7 Matrix-Valued Ternary Bent Functions

Example 7.19 Consider a vector. F whose elements are function vectors of linear functions F = [l0 , l1 , l2 , l3 , l4 , l5 , l6 , l6 , l8 ]T .

.

We add the constants .1 and .2 to linear functions . f 6 , f 7 , f 8 and . f 3 , f 4 , f 5 , respectively. Thus, F1 = [ f 0 , f 1 , f 2 , 2 ⊕ f 3 , 2 ⊕ f 4 , 2 ⊕ f 5 , 1 ⊕ f 6 , 1 ⊕ f 7 , 1 ⊕ f 8 ] T .

.

The complete function vector is F1 = [0, 0, 0, 0, 0, 0, 0, 0, 0, |0, 1, 2, 0, 1, 2, 0, 1, 2, |0, 2, 1, 0, 2, 1, 0, 2, 1, |

.

2, 2, 2, 0, 0, 0, 1, 1, 1, |2, 0, 1, 0, 1, 2, 1, 2, 0, |2, 1, 0, 0, 2, 1, 1, 0, 2, | 1, 1, 1, 0, 0, 0, 2, 2, 2, |1, 2, 0, 0, 1, 2, 2, 0, 1, |1, 0, 2, 0, 2, 1, 2, 1, 0]T . Thus, the constructed function is bent and its functional expression is .

f 1 = x2 x4 ⊕ 2x1 ⊕ x1 x3 .

The application of constant functions .l0,1 and .l0,2 instead of .l0,0 is illustrated by the following examples. Example 7.20 Consider a function with the function vector obtained by concatenating function vectors of linear functions with .l0,1 , F1 = [l0,1 , l1 , l2 , l3 , l4 , l5 , l6 , l7 , l8 ]T .

.

The complete function vector of the constructed function is F = [1, 1, 1, 1, 1, 1, 1, 1, 1, |0, 1, 2, 0, 1, 2, 0, 1, 2, |0, 2, 1, 0, 2, 1, 0, 2, 1, |

.

0, 0, 0, 1, 1, 1, 2, 2, 2, |0, 1, 2, 1, 2, 0, 2, 0, 1, |0, 2, 1, 1, 0, 2, 2, 1, 0, | 0, 0, 0, 2, 2, 2, 1, 1, 1, |0, 1, 2, 2, 0, 1, 1, 2, 0, |0, 2, 1, 2, 1, 0, 1, 0, 2]T . The function expression for . f is .

f = 1 ⊕ x2 x4 ⊕ 2x22 ⊕ x1 x3 ⊕ 2x12 ⊕ x12 x22 .

Example 7.21 In this case we use the linear functions with .l0,2 F1 = [l0,2 , l1 , l2 , l3 , l4 , l5 , l6 , l7 , l8 ]T .

.

Therefore,

7.4

Construction of Ternary Bent Functions from Ternary Linear Functions

203

F = [2, 2, 2, 2, 2, 2, 2, 2, 2, |0, 1, 2, 0, 1, 2, 0, 1, 2, |0, 2, 1, 0, 2, 1, 0, 2, 1, |

.

0, 0, 0, 1, 1, 1, 2, 2, 2, |0, 1, 2, 1, 2, 0, 2, 0, 1, |0, 2, 1, 1, 0, 2, 2, 1, 0| 0, 0, 0, 2, 2, 2, 1, 1, 1, |0, 1, 2, 2, 0, 1, 1, 2, 0, |0, 2, 1, 2, 1, 0, 1, 0, 2]T . The corresponding functional expression is .

f = 2 ⊕ x2 x4 ⊕ x22 ⊕ x1 x3 ⊕ x12 ⊕ 2x12 x22 .

Adding a constant to a linear function is another operation that preserves bentness. Example 7.22 Consider the case when the constant .2 is added to all linear functions. The function vector is F1 = [l0 ⊕ 2, l1 ⊕ 2, l2 ⊕ 2, l3 ⊕ 2, l4 ⊕ 2, l5 ⊕ 2, l6 ⊕ 2, l7 ⊕ 2, l8 ⊕ 2]T .

.

Thus, F = [2, 2, 2, 2, 2, 2, 2, 2, 2, |2, 0, 1, 2, 0, 1, 2, 0, 1, |2, 1, 0, 2, 1, 0, 2, 1, 0, |

.

2, 2, 2, 0, 0, 0, 1, 1, 1, |2, 0, 1, 0, 1, 2, 1, 2, 0, |2, 1, 0, 0, 2, 1, 1, 0, 2| 2, 2, 2, 1, 1, 1, 0, 0, 0, |2, 0, 1, 1, 2, 0, 0, 1, 2, |2, 1, 0, 1, 0, 2, 0, 2, 1]T , and the functional expression is .

f = 2 ⊕ x2 x4 ⊕ x1 x3 ,

i.e., the effect is as adding the constant .2 to the function . f . The following example illustrates that the bentness is preserved also in the case when constants are arbitrarily added to certain linear functions. Example 7.23 Consider the function vector F = [l0,2 , l1 , l2 ⊕ 2, l3 ⊕ 1, l4 , l5 ⊕ 2, l6 ⊕ 2, l7 ⊕ 1, l8 ⊕ 2]T .

.

Thus, F = [2, 2, 2, 2, 2, 2, 2, 2, 2, |0, 1, 2, 0, 1, 2, 0, 1, 2, |1, 0, 2, 1, 0, 2, 1, 0, 2, |

.

1, 1, 1, 2, 2, 2, 0, 0, 0, |0, 1, 2, 1, 2, 0, 2, 0, 1, |2, 1, 0, 0, 2, 1, 1, 0, 2, | 2, 2, 2, 1, 1, 1, 0, 0, 0, |1, 2, 0, 0, 1, 2, 2, 0, 1, |2, 1, 0, 1, 0, 2, 0, 2, 1]T .

204

7 Matrix-Valued Ternary Bent Functions

This function is bent and its functional expression is .

f = 2 ⊕ x2 ⊕ x2 x4 ⊕ x1 ⊕ x1 x3 ⊕ 2x1 x2 ⊕ x12 ⊕ x12 x2 ⊕ 2x12 x22 .

References 1. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.: Remarks on similarities among ternary bent functions. In: Proceedings of the 49th International Symposium on Multiple-Valued Logic, Fredericton, Canada, 79–84, 21–23 May 2019 2. Sytankovi´c, R.S., Astola, J., Egiazarian, K.: Remarks on symmetric binary and multiple-valued functions. In: Proceedings of the 6th International Workshop on Boolean Problems, Technische Universität Bergakademie Freiberg, 83–87 (2004). ISBN 3-86012-233-9 3. Cusick, T.W., St˘anic˘a, P.: Cryptographic Boolean Functions and Applications. Academic Press/Elsevier (2009) 4. Sasao, T.: Switching Theory for Logic Synthesis. Kluwer Academic Publishers (1999) 5. Radmanovi´c, M., Stankovi´c, R.S.: Construction of subsets of bent functions satisfying restrictions in the Reed-Muller domain. Facta Universitatis. Ser. Electron. Energ. 31(2), 207–222 (2018) 6. Hou, X.D.: .q-ary bent functions constructed from chain rings. Finite Fields Appl. 4(1), 55–61 (1998) 7. Rothaus, O.: On bent functions. J. Combin. Theory. Ser. A 20(3), 300–305 (1976) 8. Agievich, S.V.: On the representation of bent functions by bent rectangles. In: Fifth International Petrozavodsk Conference on Probabilistic Methods in Discrete Mathematics, Petrozavodsk, Russia, 1–6 June 2000, Proceedings of the Boston VSP, 121–135 (2000). http://arxiv.org/abs/math/ 0502087 9. Stankovi´c, M., Stankovi´c, R.S., Moraga, C., Astola, J.T.: Construction of ternary bent functions from ternary linear functions. In: Proceedings of the 52nd International Symposium on Multiplevalued Logic, Dallas, TX, USA, 18–20 May 2022, 50–55. https://doi.org/10.1109/ISMVL52857. 2022.00015 10. Stankovi´c, R.S., Astola, J.T., Moraga, C.: Representation of Multiple-Valued Logic Functions. Claypool & Morgan Publishers (2012) 11. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Remarks on Similarities Between Bent Functions, Binary and Ternary Cases, Res. Rept. (2018). Available from the authors upon request

8

Construction of Bent Functions by FFT-like Permutation Matrices

In this chapter, we first present a particular class of permutation matrices introduced in [1, 2] as FFT-like permutation matrices, since they are derived from a particular factorization of Discrete Fourier Transform (DFT) matrices leading to the Fast Fourier Transform (FFT) as a fast algorithm to compute the DFT spectra [3]. These permutation matrices can be efficiently used to construct bent functions by modifying given bent functions. This statement follows from the observation that spectral invariant operations, which preserve bentness, perform particular precisely specified permutations of subsets of spectral coefficients. These permutations in spectral domain can be equivalently expressed as permutations over function values involved in computing the corresponding spectral coefficients. The function values used to compute a spectral coefficient are uniquely determined by the positions from which the data are fetched in steps of FFT algorithms for the Walsh and the Vilenkin–Chrestenson transforms, respectively, for binary- and multiple-valued functions. The efficiency of the procedure is borrowed from the FFT. A restriction is that by permutations from the given bent function with a number of non-zero values and the composition for binary- and multiplevalued functions, respectively, we can construct many other bent functions, but with the same number of non-zero values for binary and the same composition for the multiple-valued cases. Some other bent functions with a different number of non-zero values for binary and the compositions for multiple-valued cases can be constructed by encoding. The presentation in this chapter is given for binary and ternary bent functions by referring to definitions and examples presented in [4]; see also the extended version [1, 5], respectively. It is obvious that the same approach works for any . p and .n, and the limitations come from the available space and time computing resources.

© The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_8

205

206

8.1

8 Construction of Bent Functions by FFT-like Permutation Matrices

FFT-like Permutation Matrices for Binary Bent Functions

The set of all binary bent functions in a given number of variables can be split into two subsets with respect to the two possible numbers of non-zero values in their truth-vectors. Functions in a subset are mutually related by permutations, since they have an equal number of non-zero elements. There are many permutation matrices that can be used to convert a given binary bent function into another binary bent function with the same number of non-zero values. Some of these permutation matrices have a structure that corresponds to the structure of sparse factor matrices describing steps in the Good–Thomas decomposition [6–8] of the Cooley–Tukey Fast Fourier transform (FFT) [3]. We define two basic matrices [ ] [ ] 01 10 .P(1) = , I(1) = . 10 01 By using these basic matrices, we define .(2n × 2n ) permutation matrices with respect to the .i-th variable in a function in .n variables as { n Θ P(1), j = i, .Pi (n) = Dj, Dj = I(1), otherwise. j=1

There can be observed a strong resemblance in the structure of this matrix .Pi (n) to the factor matrices .Ci (n) in FFT, which gives a justification for the term FFT-like permutation matrix for .Pi (n). This resemblance consists in the replacement of the basic transform matrix .W(1) by the basic permutation matrix .P(1). From the definition of the spectral invariant operation of polarization of a variable .xi → xi ⊕ 1 by referring to its expression in the spectral domain, it follows that it is performed by application of the permutation matrix .Pi to the truth-vector .F of a given function . f . A recursive application of the permutation matrices assigned to different variables will produce various bent functions. Notice that the recursive application of permutation matrices .Pi and .P j assigned to the variables . x i and . x j , respectively, is equivalent to the multiplication with a permutation matrix .Pi, j obtained as the product of the corresponding permutation matrices assigned to variables. From the properties of the Kronecker product and matrices involved, the same permutation matrices can be derived by using simultaneously the matrix .P(1) at two or more positions. Therefore, the permutation matrix .Pi1 ,i2 ,...,ik performing polarization of .k variables .x j1 , x j2 , . . . , x jk in a function in .n variables is obviously Pi1 ,i2 ,...in (n) =

n Θ

.

j=1

{ Dj, Dj =

P(1), j1 = i 1 , j2 = i 2 , . . . , jk = i k I(1), otherwise.

8.2

Permutation Matrices for Disjoint Spectral Translation

207

Example 8.1 illustrates construction of bent functions from the given bent function by using these FFT-like permutation matrices which perform polarization, in the binary case, negation of variables. Example 8.1 Consider the function whose functional expression is .

f (x1 , x2 , x3 , x4 ) = x2 ⊕ x3 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4 .

Its truth-vector is F = [0, 1, 1, 1, 1, 1, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0]T .

.

The Walsh spectrum after encoding .(0, 1) → (1, −1) is computed as S f = [−4, 4, 4, 4, −4, 4, 4, 4, −4, 4, −4, −4, 4, −4, 4, 4]T .

.

Consider the following randomly selected cases: 1. The matrix .P(1) at two different positions in the Kronecker product, 2. Two matrices .P(1) simultaneously at two different positions, 3. Three matrices .P(1) simultaneously at three different positions. Table 8.1 shows these particular examples. Figure 8.1 shows the flow-graph for computing with permutation matrices .P2 and .P4 where .P2 = I(1) ⊗ P(1) ⊗ I(1) and .P4 = I(1) ⊗ I(1) ⊗ P(1). The black lines correspond to the flow-graph of the FWT, while thicker green lines over them show the performed permutations. Figures 8.2 and 8.3 show the flow-graphs for computing with permutation matrices .Q1 and .Q2 , while Figs. 8.6 and 8.9 show computing with .R1 and .R4 , defined in cases 3, 4, 5, and 6, in Table 8.1, respectively (Figs. 8.4, 8.5, 8.7, 8.8, and 8.10).

8.2

Permutation Matrices for Disjoint Spectral Translation

In the previous section, we discuss FFT-like permutation matrices performing negation of variables allowing simultaneous negation of subsets of variables. In this section, we discuss FFT-like permutation matrices performing the disjoint spectral translation [ ] .xi → xi ⊕ [ xk . ]In ab a0 and .T(1) = . that order, we consider two symbolic .(2 × 2) matrices .L(1) = ba 0b A .(2n × 2n ) auxiliary symbolic matrix is defined as

208

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.1 Spectral invariant operations, permutation matrices, truth-vectors of produced functions, their Walsh spectra, and functional expressions for produced bent functions from the function . f in Example 8.1 Case 1

.x2

→ x2 ⊕ 1

.P2

= I(1) ⊗ P(1) ⊗ I(1) ⊗ I(1)

.F2

= P2 F = [1, 1, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0, 0, 1, 1, 1]T

.S f

Case 2

= 1 ⊕ x1 ⊕ x2 ⊕ x3 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4

.x4 .P4

→ x4 ⊕ 1 = I(1) ⊗ I(1) ⊗ I(1) ⊗ P(1)

.F4

= P4 F = [1, 0, 1, 1, 1, 1, 1, 0, 1, 0, 1, 1, 0, 0, 0, 1]T

.S f

Case 3

= 1 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4

.x2

→ x2 ⊕ 1 after (.x1 → x1 ⊕ 1)

.Q1

= P(1) ⊗ P(1) ⊗ I(1) ⊗ I(1)

.F5

= Q1 F = [0, 0, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1, 0, 1, 1, 1]T = [−4, 4, 4, 4, 4, −4, −4, −4, 4, −4, 4, 4, 4, −4, 4, 4]T

5

. f5

= x1 ⊕ x3 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4

.x3

→ x3 ⊕ 1 after (.x2 → x2 ⊕ 1)

.Q2

= I(1) ⊗ P(1) ⊗ P(1) ⊗ I(1)

.F6

= Q2 F = [0, 1, 1, 1, 1, 1, 0, 1, 1, 0, 0, 0, 1, 1, 0, 1]T

.S f

= [−4, 4, −4, −4, 4, −4, 4, 4, −4, 4, 4, 4, −4, 4, 4, 4]T

6

= x1 ⊕ x2 ⊕ x3 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ X 3 x4

. f6

Case 5

= [−4, −4, 4, −4, −4, −4, 4, −4, −4, −4, −4, 4, 4, 4, 4, −4]T

4

. f4

.S f

Case 4

= [−4, 4, 4, 4, 4, −4, −4, −4, −4, 4, −4, −4, −4, 4, −4, −4]T

2

. f2

→ x3 ⊕ 1 after (.x2 → x2 ⊕ 1) to (.x1 → x1 ⊕ 1) .R1 = P(1) ⊗ P(1) ⊗ P(1) ⊗ I(1) .x3

= R1 F = [1, 0, 0, 0, 1, 1, 0, 1, 0, 1, 1, 1, 1, 1, 0, 1]T

.F11 .S f

11

. f 11

Case 6

= [−4, 4, −4, −4, 4, −4, 4, 4, 4, −4, −4, −4, 4, −4, −4, −4]T

= 1 ⊕ x1 ⊕ x3 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4

.x4

→ x4 ⊕ 1 after (.x3 → x3 ⊕ 1) to (.x2 → x2 ⊕ 1)

.R4

= I(1) ⊗ P(1) ⊗ P(1) ⊗ P(1) = R4 F = [1, 0, 1, 1, 1, 1, 1, 0, 0, 1, 0, 0, 1, 1, 1, 0]T

.F14 .S f

14

. f 14

= [−4, −4, −4, 4, 4, 4, 4, −4, −4, −4, 4, −4, −4, −4, 4, −4]T

= 1 ⊕ x2 ⊕ x4 ⊕ x1 x2 ⊕ x2 x4 ⊕ x3 x4

⎧ ⎨ L(1), j = i, .Ai,k (n) = A j , A j = T(1), j = k, ⎩ j=1 I(1), otherwise. n Θ

The permutation matrix .Qi,k (n) is defined as a matrix derived from .Ai,k (n) by replacement of symbols .a 2 and .b2 by .1, while symbols with mixed letters .ab and .ba are replaced by .0.

8.2

Permutation Matrices for Disjoint Spectral Translation

Fig. 8.1 Flow-graph for computing with .P2 and .P4

209

f(0)

f(4)

f(0)

f(1)

f(1)

f(5)

f(1)

f(0)

f(2)

f(6)

f(2)

f(3)

f(3)

f(7)

f(3)

f(2)

f(4)

f(0)

f(4)

f(5)

f(5)

f(1)

f(5)

f(4)

f(6)

f(2)

f(6)

f(7)

f(7)

f(3)

f(7)

f(6)

f(8)

f(12)

f(8)

f(9)

f(9)

f(13)

f(9)

f(8)

f(10)

f(14)

f(10)

f(11)

f(11)

f(15)

f(11)

f(10)

f(12)

f(8)

f(12)

f(13)

f(13)

f(9)

f(13)

f(12)

f(14)

f(10)

f(14)

f(15)

f(15)

f(11)

f(15)

f(14)

P4

P2 Fig. 8.2 Flow-graph for computing with .Q1

f(0)

f(8)

f(12)

f(1)

f(9)

f(13)

f(2)

f(10)

f(14)

f(3)

f(11)

f(15)

f(4)

f(12)

f(8)

f(5)

f(13)

f(9)

f(6)

f(14)

f(10)

f(7)

f(15)

f(11)

f(8)

f(0)

f(4)

f(9)

f(1)

f(5)

f(10)

f(2)

f(6)

f(11)

f(3)

f(7)

f(12)

f(4)

f(0)

f(13)

f(5)

f(1)

f(14)

f(6)

f(2)

f(15)

f(7)

f(3)

Q1

210 Fig. 8.3 Flow-graph for computing with .Q2

8 Construction of Bent Functions by FFT-like Permutation Matrices f(0)

f(4)

f(6)

f(1)

f(5)

f(7)

f(2)

f(6)

f(4)

f(3)

f(7)

f(5)

f(4)

f(0)

f(2)

f(5)

f(1)

f(3)

f(6)

f(2)

f(0)

f(7)

f(3)

f(1)

f(8)

f(12)

f(14)

f(9)

f(13)

f(15)

f(10)

f(14)

f(12)

f(11)

f(15)

f(13)

f(12)

f(8)

f(10)

f(13)

f(9)

f(11)

f(14)

f(10)

f(8)

f(15)

f(11)

f(9)

Q2 Fig. 8.4 Flow-graph for computing with .Q3

f (0)

f(2)

f (3)

f (1)

f(3)

f (2)

f (2)

f(0)

f (1)

f (3)

f(1)

f (0)

f (4)

f(6)

f (7)

f (5)

f(7)

f (6)

f (6)

f(4)

f (5)

f (7)

f(5)

f (4)

f (8)

f(10)

f (11)

f (9)

f(11)

f (10)

f (10)

f(8)

f (9)

f (11)

f(9)

f (8)

f (12)

f(14)

f (15)

f (13)

f(15)

f (14)

f (14)

f(12)

f (13)

f (15)

f(13)

f (12)

Q3

8.2

Permutation Matrices for Disjoint Spectral Translation

Fig. 8.5 Flow-graph for computing with .Q4

211

f(0)

f(8)

f(10)

f(1)

f(9)

f(11)

f(2)

f(10)

f(8)

f(3)

f(11)

f(9)

f(4)

f(12)

f(14)

f(5)

f(13)

f(15)

f(6)

f(14)

f(12)

f(7)

f(15)

f(13)

f(8)

f(0)

f(2)

f(9)

f(1)

f(3)

f(10)

f(2)

f(0)

f(11)

f(3)

f(1)

f(12)

f(4)

f(6)

f(13)

f(5)

f(7)

f(14)

f(6)

f(4)

f(15)

f(7)

f(5)

Q4

Again, from the definition of spectral invariant operations in the spectral domain, it follows that the permutation matrix .Qi,k (n) performs the substitution of a variable .xi by .xi ⊕ xk . Example 8.2 illustrates the application of this permutation matrix. The following example illustrates the construction of a bent function by the application of the permutation matrix corresponding to the spectral invariant operation called the disjoint translation .xi → xi ⊕ xk [9]. Example 8.2 We determine a symbolic matrix as A1,2 = L(1) ⊗ T(1) ⊗ I(1) ⊗ I(1).

.

After performing a symbolic computation and replacement of elements .a 2 and .b2 by .1 and all other elements by .0, we get the permutation matrix which can be written in a condensed form as ⎡

Q1,2

.

I(2) ⎢ 0(2) =⎢ ⎣ 0(2) 0(2)

0(2) 0(2) 0(2) I(2)

0(2) 0(2) I(2) 0(2)

⎤ 0(2) I(2) ⎥ ⎥, 0(2) ⎦ 0(2)

212

8 Construction of Bent Functions by FFT-like Permutation Matrices f(0)

f(8)

f(12)

f(14)

f(1)

f(9)

f(13)

f(15)

f(2)

f(10)

f(14)

f(12)

f(3)

f(11)

f(15)

f(13)

f(4)

f(12)

f(8)

f(10)

f(5)

f(13)

f(9)

f(11)

f(6)

f(14)

f(10)

f(8)

f(7)

f(15)

f(11)

f(9)

f(8)

f(0)

f(4)

f(6)

f(9)

f(1)

f(5)

f(7)

f(10)

f(2)

f(6)

f(4)

f(11)

f(3)

f(7)

f(5)

f(12)

f(4)

f(0)

f(2)

f(13)

f(5)

f(1)

f(3)

f(14)

f(6)

f(2)

f(0)

f(15)

f(7)

f(3)

f(1)

R1 Fig. 8.6 Flow-graph for computing with .R1

where .I(2) and .0(2) are the .(4 × 4) identity and the zero matrices. Figure 8.11 shows the flow-graph for computing with this matrix .Q1,2 . The matrix .Q1,2 applied to the truth-vector .F of the initial function in Example 8.1 produces the truth-vector .F1,2 of a function . f 1,2 (x1 , x2 , x3 , x4 ) as F1,2 = [0, 1, 1, 1, 0, 0, 1, 0, 0, 1, 1, 1, 1, 1, 0, 1]T .

.

Its Walsh spectrum is S f1,2 = [−4, 4, 4, 4, −4, 4, 4, 4, 4, −4, 4, 4, −4, 4, −4, −4]T ,

.

which shows that it is bent, and the functional expression is .

f 1,2 (x1 , x2 , x3 , x4 ) = x3 ⊕ x4 ⊕ x3 x4 ⊕ x2 x4 ⊕ x1 x2 .

The same function can be derived from . f by the substitution .x1 → x1 ⊕ x2 . Example 8.3 Define a symbolic matrix with the opposite order of symbolic matrices .L(1) and .T(1), compared to their order in Example 8.2 A2,1 = T(1) ⊗ L(1) ⊗ I(1) ⊗ I(1).

.

8.2

Permutation Matrices for Disjoint Spectral Translation

213

f(0)

f(8)

f(12)

f(13)

f(1)

f(9)

f(13)

f(12)

f(2)

f(10)

f(14)

f(15)

f(3)

f(11)

f(15)

f(14)

f(4)

f(12)

f(8)

f(9)

f(5)

f(13)

f(9)

f(8)

f(6)

f(14)

f(10)

f(11)

f(7)

f(15)

f(11)

f(10)

f(8)

f(0)

f(4)

f(5)

f(9)

f(1)

f(5)

f(4)

f(10)

f(2)

f(6)

f(7)

f(11)

f(3)

f(7)

f(6)

f(12)

f(4)

f(0)

f(1)

f(13)

f(5)

f(1)

f(0)

f(14)

f(6)

f(2)

f(3)

f(15)

f(7)

f(3)

f(2)

R2 Fig. 8.7 Flow-graph for computing with .R2

After symbolic calculation and replacement of symbolic elements as specified above, we produce a permutation matrix which can be written as ⎡

Q2,1

.

I(2) ⎢ 0(2) =⎢ ⎣ 0(2) 0(2)

0(2) I(2) 0(2) 0(2)

0(2) 0(2) 0(2) I(2)

⎤ 0(2) 0(2) ⎥ ⎥. I(2) ⎦ 0(2)

Figure 8.12 shows the flow-graph for computing with this matrix .Q2,1 . When .Q2,1 is applied to the function vector of . f in Example 8.1, another bent function is constructed with the function vector F2,1 = [0, 1, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 0, 1, 1, 1]T ,

.

the Walsh spectrum S f2,1 = [−4, 4, 4, 4, 4, −4, 4, 4, −4, 4, −4, −4, −4, 4, 4, 4]T .

.

The function expression is

214

8 Construction of Bent Functions by FFT-like Permutation Matrices f(0)

f(8)

f(10)

f(11)

f(1)

f(9)

f(11)

f(10)

f(2)

f(10)

f(8)

f(9)

f(3)

f(11)

f(9)

f(8)

f(4)

f(12)

f(14)

f(15)

f(5)

f(13)

f(15)

f(14)

f(6)

f(14)

f(12)

f(13)

f(7)

f(15)

f(13)

f(12)

f(8)

f(0)

f(2)

f(3)

f(9)

f(1)

f(3)

f(2)

f(10)

f(2)

f(0)

f(1)

f(11)

f(3)

f(1)

f(0)

f(12)

f(4)

f(6)

f(7)

f(13)

f(5)

f(7)

f(6)

f(14)

f(6)

f(4)

f(5)

f(15)

f(7)

f(5)

f(4)

R3 Fig. 8.8 Flow-graph for computing with .R3

.

f 1,3 (x1 , x2 , x3 , x4 ) = x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x1 x4 ⊕ x1 x2 .

The same function can be derived from the initial function by the substitution.x2 → x2 ⊕ x1 . Example 8.4 Consider the matrix A2,4 = I(1) ⊗ L(1) ⊗ I(1) ⊗ T(1).

.

After symbolic computation and replacement of elements by .0 and .1, we get the permutation matrix ⎡ ⎤ ⎤ ⎤ ⎡ ⎡ CD 0 0 1000 0000 ⎢D C 0 0 ⎥ ⎢0 0 0 0⎥ ⎢0 1 0 0⎥ ⎥ ⎥ ⎥ ⎢ ⎢ .Q2,4 = ⎢ ⎣ 0 0 C D⎦, C = ⎣0 0 1 0⎦, D = ⎣0 0 0 0⎦. 0 0 DC

0000

0001

This matrix converts the function vector of the initial function from Example 8.1 into the function vector F2,4 = [0, 1, 1, 1, 1, 1, 0, 1, 0, 0, 1, 0, 0, 1, 1, 1]T ,

.

8.2

Permutation Matrices for Disjoint Spectral Translation

215

f(0)

f(4)

f(6)

f(7)

f(1)

f(5)

f(7)

f(6)

f(2)

f(6)

f(4)

f(5)

f(3)

f(7)

f(5)

f(4)

f(4)

f(0)

f(2)

f(3)

f(5)

f(1)

f(3)

f(2)

f(6)

f(2)

f(0)

f(1)

f(7)

f(3)

f(1)

f(0)

f(8)

f(12)

f(14)

f(15)

f(9)

f(13)

f(15)

f(14)

f(10)

f(14)

f(12)

f(13)

f(11)

f(15)

f(13)

f(12)

f(12)

f(8)

f(10)

f(11)

f(13)

f(9)

f(11)

f(10)

f(14)

f(10)

f(8)

f(9)

f(15)

f(11)

f(9)

f(8)

R4 Fig. 8.9 Flow-graph for computing with .R4

the Walsh spectrum S f2,4 = [−4, 4, 4, 4, 4, −4, 4, 4, −4, 4, −4, −4, −4, 4, 4, 4]T .

.

The function expression is .

f 1,3 (x1 , x2 , x3 , x4 ) = x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x1 x4 ⊕ x1 x2 .

The same function can be constructed by the substitution .x2 → x2 ⊕ x4 . Figure 8.13 shows the flow-graph for computing with this matrix .Q2,4 . Example 8.5 Consider the matrix A4,2 = I(1) ⊗ T(1) ⊗ I(1) ⊗ L(1).

.

After symbolic computation and replacement of elements by .0 and .1, we get the permutation matrix

216

8 Construction of Bent Functions by FFT-like Permutation Matrices

f(0)

f(8)

f(12)

f(14)

f(15)

f(1)

f(9)

f(13)

f(15)

f(14)

f(2)

f(10)

f(14)

f(12)

f(13)

f(3)

f(11)

f(15)

f(13)

f(12)

f(4)

f(12)

f(8)

f(10)

f(11)

f(5)

f(13)

f(9)

f(11)

f(10)

f(6)

f(14)

f(10)

f(8)

f(9)

f(7)

f(15)

f(11)

f(9)

f(8)

f(8)

f(0)

f(4)

f(6)

f(7)

f(9)

f(1)

f(5)

f(7)

f(6)

f(10)

f(2)

f(6)

f(4)

f(5)

f(11)

f(3)

f(7)

f(5)

f(4)

f(12)

f(4)

f(0)

f(2)

f(3)

f(13)

f(5)

f(1)

f(3)

f(2)

f(14)

f(6)

f(2)

f(0)

f(1)

f(15)

f(7)

f(3)

f(1)

f(0)

R5 Fig. 8.10 Flow-graph for computing with .R5



Q4,2

.

I(2) ⎢ 0(2) =⎢ ⎣ 0(2) 0(2)

0(2) C(2) 0(2) 0(2)

0(2) 0(2) I(2) 0(2)

⎡ ⎤ 0 0(2) ⎢ ⎥ 0(2) ⎥ 1 , C(2) = ⎢ ⎣0 0(2) ⎦ C(2) 0

1 0 0 0

0 0 0 1

⎤ 0 0⎥ ⎥. 1⎦ 0

This matrix converts the function vector of the initial function from Example 8.1 into the function vector F2,4 = [0, 1, 1, 1, 1, 1, 1, 0, 0, 1, 1, 1, 0, 0, 0, 1]T ,

.

the Walsh spectrum S f2,4 = [−4, 4, 4, 4, −4, 4, 4, 4, −4, −4, −4, 4, 4, 4, 4, −4]T .

.

The function expression is .

f 1,3 (x1 , x2 , x3 , x4 ) = x4 ⊕ x3 ⊕ x3 x4 ⊕ x2 ⊕ x2 x4 ⊕ x2 x3 ⊕ x1 x2 .

8.2

Permutation Matrices for Disjoint Spectral Translation

217

Fig. 8.11 Flow-graph for computing with .Q1,2

f(0)

f(0)

f(1)

f(1)

f(2)

f(2)

f(3)

f(3)

f(4)

f(12)

f(5)

f(13)

f(6)

f(14)

f(7)

f(15)

f(8)

f(8)

f(9)

f(9)

f(10)

f(10)

f(11)

f(11)

f(12)

f(4)

f(13)

f(5)

f(14)

f(6)

f(15)

f(7)

Q1,2

The same function can be constructed by the substitution .x4 → x4 ⊕ x2 . Figure 8.14 shows the flow-graph for computing with this matrix .Q4,2 .

Example 8.6 Consider a matrix obtained as the product of two permutation matrices performing disjoint spectral translation with respect to two different variables, .Q1,4 and .Q2,3 , thus, Q1,4,2,3 = Q1,4 · Q2,3 .

.

It can be written in condensed notation as ⎡ A(2) ⎢ B(2) .Q1,4,2,3 = ⎢ ⎣ C(2) D(2) where

B(2) A(2) D(2) C(2)

C(2) D(2) A(2) B(2)

⎤ D(2) C(2) ⎥ ⎥, B(2) ⎦ A(2)

218

8 Construction of Bent Functions by FFT-like Permutation Matrices

Fig. 8.12 Flow-graph for computing with .Q2,1

f (0)

f(0)

f (1)

f(1)

f (2)

f(2)

f (3)

f(3)

f (4)

f(4)

f (5)

f(5)

f (6)

f(6)

f (7)

f(7)

f (8)

f(12)

f (9)

f(13)

f (10)

f(14)

f (11)

f(15)

f (12)

f(8)

f (13)

f(9)

f (14)

f(10)

f (15)

f(11)

Q2,1

⎤ ⎡ ⎤ 0000 1000 ⎢0 0 0 0⎥ ⎢0 0 0 0⎥ ⎥ ⎢ ⎥ .A(2) = ⎢ ⎣ 0 0 0 0 ⎦ , B(2) = ⎣ 0 0 1 0 ⎦ , 0000 0000 ⎤ ⎡ ⎤ ⎡ 0000 0000 ⎢0 0 0 0⎥ ⎢0 1 0 0⎥ ⎥ ⎢ ⎥ C(2) = ⎢ ⎣ 0 0 0 0 ⎦ , D(2) = ⎣ 0 0 0 0 ⎦ . 0001 0000 ⎡

Figure 8.15 shows the flow-graph for computing with this matrix. The application of this matrix to the initial function . f in Example 8.1 produces a function specified by the truth-vector as F1,4,2,3 = [0, 1, 0, 0, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 1, 1]T ,

.

and with the Walsh spectrum S f 1,4,2,3 = [−4, 4, 4, 4, 4, 4, −4, 4, 4, −4, −4, −4, 4, 4, −4, 4]T .

.

8.3

Construction of Binary Bent Functions by FFT-like Permutation Matrices

Fig. 8.13 Flow-graph for computing with .Q2,4

219

f(0)

f(0)

f(1)

f(5)

f(2)

f(2)

f(3)

f(7)

f(4)

f(4)

f(5)

f(1)

f(6)

f(6)

f(7)

f(3)

f(8)

f(8)

f(9)

f(13)

f(10)

f(10)

f(11)

f(15)

f(12)

f(12)

f(13)

f(9)

f(14)

f(14)

f(15)

f(11)

Q2,4

The functional expression for this function is .

f 1,4,2,3 (x1 , x2 , x3 , x4 ) = x4 ⊕ x3 x4 ⊕ x2 ⊕ x1 x3 ⊕ x1 x2 .

The same function can be obtained by the spectral invariant operation .x2 → x2 ⊕ x3 followed by .x1 → x1 ⊕ x4 .

8.3

Construction of Binary Bent Functions by FFT-like Permutation Matrices

From the proposed approach illustrated by Examples 8.1 and 8.2, 8.3, 8.4, 8.5, and 8.6, an algorithm for constructing bent functions with selected number of variables and specified number of non-zero values in the function vector can be directly formulated. Determine a library.L of FFT-like permutation matrices for specified values of the number of variables .n.

220

8 Construction of Bent Functions by FFT-like Permutation Matrices

Fig. 8.14 Flow-graph for computing with .Q4,2

f(0)

f(0)

f(1)

f(1)

f(2)

f(2)

f(3)

f(3)

f(4)

f(5)

f(5)

f(4)

f(6)

f(7)

f(7)

f(6)

f(8)

f(8)

f(9)

f(9)

f(10)

f(10)

f(11)

f(11)

f(12)

f(13)

f(13)

f(12)

f(14)

f(15)

f(15)

f(14)

Q4,2

Algorithm 8.1 (FFT-permutation matrices)

1. 2. 3. 4.

Given is an arbitrary bent function . f with the selected number of non-zero values. Apply an FFT-like permutation matrix to . f and write the result in a list. Repeat Step .2 for different permutation matrices from .L. Check if each of the produced bent functions is already contained in the list. If .Y es skip it and return to Step .2.

Basic properties of the proposed method and the related algorithm are the following. First, the method is derived by referring to spectral invariant operations which provides a guarantee that the produced functions are bent. Therefore, there is no need to check them for bentness which simplifies the construction procedure. A direct implementation of spectral invariant operations requires computing the Walsh spectrum, performing spectral invariant operations over subsets of spectral coefficients, and finally computing the inverse Walsh transform to determine the function constructed in this way. An alternative is to deal with functional expressions and perform symbolic computations. In the proposed algorithm, the permutations are performed in the original domain; thus, computing the Walsh spectrum and

8.4

Gibbs Matrices and FFT-like Permutation Matrices for Binary Functions

Fig. 8.15 Flow-graph for computing with .Q1,4,2,3

221

f(0)

f(0)

f(0)

f(1)

f(9)

f(9)

f(2)

f(2)

f(6)

f(3)

f(11)

f(15)

f(4)

f(4)

f(4)

f(5)

f(13)

f(13)

f(6)

f(6)

f(2)

f(7)

f(15)

f(11)

f(8)

f(8)

f(8)

f(9)

f(1)

f(1)

f(10)

f(10)

f(14)

f(11)

f(3)

f(7)

f(12)

f(12)

f(12)

f(13)

f(5)

f(5)

f(14)

f(14)

f(10)

f(15)

f(7)

f(3)

Q1,4

Q2,3 Q1,4,2,3

the inverse transform is not required. The algorithm is fast, since the permutation matrices are derived from the factor matrices in fast computing algorithms and express a regular Kronecker product structure. Therefore, implementation of such matrices is fast.

8.4

Gibbs Matrices and FFT-like Permutation Matrices for Binary Functions

The Gibbs matrices and FFT-like permutation matrices are distinct subsets of .(2n × 2n ) permutation matrices. The common characteristic is that they both have a block structure consisting of .(2 × 2) submatrices, but these submatrices are different. In the Gibbs matrices, the submatrices have a single non-zero element, while in FFT-like permutation matrices two non-zero elements appear. Therefore, in this case .(2 × 2) identity matrices are included. Since FFT-like permutation matrices are defined in terms of the Kronecker product, the basic .(2 × 2) submatrices are combined into larger submatrices.

222

8 Construction of Bent Functions by FFT-like Permutation Matrices

Due to their block structure, both the Gibbs and FFT-like permutation matrices perform permutation over subvectors as well as permutation of elements in the subvectors of the function vectors of bent functions in such a manner that bentness is preserved. In terms of spectral invariant operations, which are necessary for preserving bentness, these matrices perform different spectral invariant operations. Gibbs permutation matrices actually perform two spectral invariant operations, permutation of variables, and negation of variables. The FFT-like permutation matrices do not perform permutation of variables, and depending on the way how they are defined perform either negation or spectral translation of variables. Thus, the application of these matrices to a given bent function produces other bent functions. Depending on the structure of subvectors in the initial bent function, the application of either Gibbs or FFT-like permutation matrices may result in functions identical to the initial functions to which the matrices are applied, or different matrices might produce the same resulting functions. It is also possible that particular Gibbs and FFT-like matrices applied to the same initial bent function produce identical functions. The following example illustrates some of such situations. Example 8.7 Given are a Gibbs and an FFT-like permutation matrix, .PGibbs and .P F F T , for functions in four variables as ⎡

PGibbs

.

and

1 ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 =⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎣0 0

0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0

0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0

0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0

0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0

0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0

0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0

⎤ 0 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 1⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥, 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎦ 0

8.4

Gibbs Matrices and FFT-like Permutation Matrices for Binary Functions



PF F T

.

1 ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 =⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎣0 0

0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0

0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0

223

⎤ 0 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥. 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 1⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎦ 0

It can be noticed that the Gibbs permutation matrix consists of .(2 × 2) submatrices with a single .1 element, while in FFT-like permutation matrices the submatrices have two non-zero elements. Further, the FFT-like permutation matrix can be written as.P F F T = P2 · P1 where ⎤ ⎡ 1000000000000000 ⎢0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0⎥ .P1 = ⎢ ⎥, ⎢0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0⎥ ⎥ ⎢ ⎣0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0⎦ 0000000000010000 and

224

8 Construction of Bent Functions by FFT-like Permutation Matrices



1 ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 .P2 = ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ ⎢0 ⎢ ⎣0 0

0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0

0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0

⎤ 0 0⎥ ⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥ ⎥. 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 1⎥ ⎥ 0⎦ 0

Matrices .P1 and .P2 perform the spectral invariant operations .x2 = x2 ⊕ x3 and .x3 = x3 ⊕ x2 , respectively. The application of the matrices .PGibbs and .P F F T to the bent function . f specified by the functional expression .

f = x1 x2 ⊕ x3 x4 ⊕ x2 x4 ,

and the function vector F = [0, 0, 1, 0, 1, 0, 0, 0, 0, 0, 1, 1, 0, 1, 1]T

.

produces the same bent function . f 1 whose function vector is F1 = [0, 0, 0, 0, 0, 1, 0, 1, 0, 0, 1, 1, 0, 1, 1, 0]T

.

and the functional expression is .

f 1 = x1 x3 ⊕ x2 x4 .

The application of these permutation matrices to the bent function . f 2 specified by the functional expression .

f 2 = x1 x2 ⊕ x3 x4 ⊕ x4 ,

and the function vector F2 = [0, 1, 0, 0, 0, 1, 0, 0, 0, 1, 0, 0, 1, 0, 1, 1]T

.

8.5

FFT-like Permutation Matrices for Ternary Bent Functions

225

results in two distinct bent functions . f 3 and . f 4 specified as .

f 3 = x1 x2 ⊕ x3 x4 ⊕ x2 ⊕ x3 ,

with the function vector F3 = [0, 0, 1, 0, 1, 1, 0, 1, 0, 0, 1, 0, 0, 0, 1, 0]T

.

and .

f 4 = x1 x3 ⊕ x2 x4 ⊕ x3 x4 ⊕ x4 ,

with the function vector F4 = [0, 1, 0, 0, 0, 0, 0, 1, 0, 1, 1, 1, 0, 0, 1, 0]T .

.

8.5

FFT-like Permutation Matrices for Ternary Bent Functions

In this section, we discuss FFT-like permutation matrices for constructing ternary bent functions. The basic idea is the same as in the binary case. The difference is that here 2 . x · x / = x, but . x · x = x , and therefore we have to deal with squares of variables. Further, there are ternary bent functions for both even and odd number of variables. As in the binary case, we define permutation matrices acting in the original domain, i.e., we permute function values. Since bentness should be preserved, it follows that these permutations must correspond to certain permutations in the spectral domain which are determined by the spectral invariant operations for ternary functions. Therefore, the permutations in the original domain should be related to function values used in computing the spectral coefficients which can be permuted in the spectral domain by spectral invariant operations. FFT algorithm for computing the spectral coefficients determines function values involved in computing each spectral coefficient. In this way, FFT actually determines the function values that can be permuted while preserving bentness. In other words, FFT determines the structure of the related permutation matrices, which are then called the FFT-like permutation matrices for ternary functions. The essence of FFT is that computing spectral coefficients of a function in .n variables is performed in .n steps. In each step computing is performed with respect to a variable. Therefore, the steps are described by Kronecker product representable matrices in which the basic spectral transform matrix at the .i-th position performs computing of the transform with respect to the .i-th variable, while the other variables remain unprocessed, which is expressed by the identity matrices at all other positions. The basic spectral transform matrix is actually the transform matrix for functions in a single variable. In the case of permutation matrices, the basic spectral transform matrix is replaced by the basic permutation matrix, i.e., the permutation matrix for functions in a single variable.

226

8 Construction of Bent Functions by FFT-like Permutation Matrices

In the case of ternary bent functions, we consider the following basic permutation matrices ⎡ ⎡ ⎤ ⎤ 010 100 Q 1 = ⎣ 1 0 0 ⎦ , Q2 = ⎣ 0 0 1 ⎦ , 001 010 . (8.1) ⎡ ⎡ ⎤ ⎤ 001 001 X1 = ⎣ 1 0 0 ⎦ , N1 = ⎣ 0 1 0 ⎦ . 010 100 Notice that except .X1 , the other three matrices are self-transpose. Thus, by taking into account also ⎡ ⎤ 010 T .X1 = ⎣ 0 0 1 ⎦ , (8.2) 100 we actually have five basic permutation matrices. By adding the.(3 × 3) identity matrix.I(1), we have the set of permutation matrices corresponding to all six possible permutations in a three-element set. The relationship of these matrices and ternary bent functions goes through the bent functions in a single variable. Table 8.2 shows .18 ternary bent functions in a single variable represented by the function vectors split into .6 classes by the compositions. In this table, the function . f 1 in the class .c1 has the function expression . f 1 = x 2 . The other two functions in .c1 are obtained by the cyclic shift of elements in the function vector. These three functions have the same composition which shows that the values .0, .1, and .2, appear .1, .2, and .0 times. In the rightmost column of this table, functions in other classes are expressed in terms of functions in .c1 . Functions from a class can be converted into functions in other five classes by encoding as specified in Table 8.3. Functions within a class are mutually related by permutations since they have the same compositions, and the selected permutation matrices perform the conversion of functions to each other as specified in Table 8.4. For a given bent function with a particular distribution of values, the addition of terms as specified in Tables 8.12, 8.13, and 8.14 produces another bent function with the same distribution of function values. Therefore, these two functions differ in permutation of elements of their function vectors. In other words, the addition of terms to . f 1 and . f 2 , respectively, which can be seen in the left part of these tables, can be expressed by permutation matrices shown in the right part. In terms of functional expressions, multiplication of function vectors by the permutation matrices results in adding particular terms to functional expressions of the processed functions. These are terms which are allowed to be added to a bent function and preserve its

8.5

FFT-like Permutation Matrices for Ternary Bent Functions

227

Table 8.2 Classes of ternary bent functions for .n = 1 Class

Functions f1 , . f2 , . f3

Composition

Relationship

.c1

[0,1,1], [1,0,1], [1,1,0]

(1,2,0)

.c1

= x 2 , cyclic shift

.c2

[0,2,2], [2,0,2], [2,2,0]

(1,0,2)

.c2

= 2c1

.c3

[1,0,0], [0,1,0], [0,0,1]

(2,1,0)

.c3

= 2c1 ⊕ 1

.c4

[2,0,0], [0,2,0], [0,0,2]

(2,0,1)

.c4

= c1 ⊕ 2

.c5

[2,1,1], [1,2,1], [1,1,2]

(0,2,1)

.c5

= 2c1 ⊕ 2

.c6

[1,2,2], [2,1,2], [2,2,1]

(0,1,2)

.c6

= c1 ⊕ 1

.

Table 8.3 Relationships between classes of single variable ternary functions by encoding Classes

Encoding

.c1

and .c2

.1

↔2

.c1

and .c3

.0

↔1

.c1

and .c4

.0

→ 2 and .1 → 0 and .2 → 1

.c1

and .c5

.0

↔2

.c1

and .c6

.0

→ 1 and .1 → 2 and .2 → 0

Table 8.4 Conversion between the elements of a class Matrix

Functions

.Q1

.

f1 → f2

.Q2

.

f2 → f3

.X1

.

T .X 1

f1 → f2 , . f2 → f3 . f1 → f3 , . f3 → f2

.N1

.

f1 → f3

bentness. Which terms can be added to the functional expression of a particular bent function depends on the terms already appearing in the functional expression of the function considered. For example, if in the functional expression for the initial function there is the term 2 . x i x k , the spectral invariant operation . x i → x i ⊕ x k produces the terms . x i x k ⊕ x . In this k sense, multiplication of the function vector by the FFT-like permutation matrix performing this spectral invariant operation can be interpreted in terms of the functional expressions as adding the square term .xk2 . If this term will explicitly appear in the functional expression for the constructed function depends on the other product terms. For instance, if in the functional expression of the initial function there is a term .2xi2 , by adding the term .xi2 both these terms will be canceled since computation is modulo .3.

228

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.5 Correspondence between the basic permutation matrices and spectral invariant operation → k1 xi ⊕ k2 , .k1 ∈ {1, 2}, .k2 ∈ {0, 1, 2}

.xi

.M

.k1 , k2

Substitution

T .X 1

1, 1

.xi

→ xi ⊕ 1

.X1

1, 2

.xi

→ xi ⊕ 2

.Q2

2, 0

.xi

→ 2xi

.Q1

2, 1

.xi

→ 2xi ⊕ 1

.N1

2, 2

.xi

→ 2xi ⊕ 2

In what follows, we consider different FFT-like permutation matrices which perform permutation of function values corresponding to certain spectral invariant operations for ternary functions, i.e., certain permutations in the spectral domain.

8.5.1

Kronecker Product Representable Matrices

In this section, we consider Kronecker product representable permutation matrices in terms of the basic permutation matrices .Q1 , .Q2 , .X1 , .X1T , .N1 in a way corresponding to the Kronecker product representation of steps of FFT for computing the Vilenkin–Chrestenson transform for ternary functions. As in the case of steps of FFT, the position of the basic permutation matrix in the Kronecker product determines which variable will be processed. Therefore, these permutation matrices can be expressed as Pi =

n Θ

.

r =1

{ Mr , Mr =

M, for r = i, I(1), for r / = i,

(8.3)

where .M ∈ {X1 , X1T , Q1 , Q2 , N1 }. The reason for studying such permutation matrices is that they are related with the spectral invariant operation polarization of variables which in the ternary case is defined as .xi → k1 xi ⊕ k2 , where .k1 ∈ {1, 2}, and .k2 ∈ {0, 1, 2}. The values for .k1 and .k2 depend on the selected basic FFT-like permutation matrix. Table 8.5 shows the correspondence between permutation matrices and constants .k1 and .k2 in the substitution rules. The following examples illustrate the application of the Kronecker representable FFT-like permutation matrices defined in this way. Example 8.8 Consider the basic bent function in two variables. f 1 = x1 x2 . The polarization of the variable .x2 as .x2 → x2 ⊕ 1, i.e., with .k1 = k2 = 1 converts . f 1 into . f 2 = x1 x2 ⊕ x1 . This expression can be understood as adding a linear term to the initial function, which preserves its bentness.

8.5

FFT-like Permutation Matrices for Ternary Bent Functions

229

In terms of permutation matrices, this substitution can be performed as follows. From Table 8.5, we see that the matrix .X1T corresponds to these values of .k1 and .k2 , and since .x2 is processed, it should appear at the second position in the Kronecker product. Therefore, this substitution can be expressed as multiplication of the function vector .F1 of . f 1 by the permutation matrix P1 = I(1) ⊗ X1T ,

.

where .I(1) is the .(3 × 3) identity matrix and .X1T as defined in (8.2). The function . f 1 = x2 x2 has the function vector Fx1 x2 = [0, 0, 0, 0, 1, 2, 0, 2, 1]T ,

.

while the variable .x1 is represented by the function vector x1 = [0, 0, 0, 1, 1, 1, 2, 2, 2]T .

.

Therefore, the function vector for . f = x1 x2 ⊕ x1 is determined as Fx1 x2 ⊕x1 = Fx1 x2 ⊕ x1 = [0, 0, 0, 1, 2, 0, 2, 1, 0]T .

.

The same vector can be obtained as F = P1 Fx1 x2 = (I(1) ⊗ X1T )Fx1 x2 ⎡ ⎤ ⎡ ⎤ 010000000 0 ⎢0 0 1 0 0 0 0 0 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢0⎥ ⎢ ⎥ ⎢1 0 0 0 0 0 0 0 0⎥ ⎢ 0⎥ ⎥ ⎢ ⎥ ⎢ ⎢ ⎢0 0 0 0 1 0 0 0 0⎥ ⎢0⎥ ⎢ ⎥ ⎢ ⎥ ⎥ · ⎢1⎥ =⎢ 0 0 1 0 0 0 0 0 0 ⎥ ⎢ ⎥ ⎥ ⎢0 0 0 1 0 0 0 0 0⎥ ⎢ 2⎥ ⎢ ⎥ ⎢ ⎥ ⎢ ⎢ ⎥ 0⎥ ⎢0 0 0 0 0 0 0 1 0⎥ ⎢ ⎥ ⎢ ⎢ ⎥ ⎣0 0 0 0 0 0 0 0 1⎦ ⎣2⎦ 1 000000100 [ ]T = 0, 0, 0, 1, 2, 0, 2, 1, 0 .

.

Example 8.9 The function . f 2 = x1 x2 ⊕ x2 is derived from . f 1 = x1 x2 by the substitution x1 → x1 ⊕ 1. It has the function vector

.

F = [0, 1, 2, 0, 2, 1, 0, 0, 0]T .

.

The same function vector can be obtained from the function vector of the function. f 1 = x1 x2 by multiplying it with the permutation matrix

230

8 Construction of Bent Functions by FFT-like Permutation Matrices

P2 = X1T ⊗ I(1) ⎤ ⎡ ⎤ ⎡ 000100000 0 ⎢0 0 0 0 1 0 0 0 0⎥ ⎢ ⎥ ⎥ ⎢0⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 1 0 0 0⎥ ⎢ 0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 1 0 0⎥ ⎢ 0⎥ ⎥ ⎥ ⎢ ⎢ ⎢ ⎥ ⎥ ⎢ = ⎢0 0 0 0 0 0 0 1 0⎥ · ⎢1⎥ ⎥ ⎢0 0 0 0 0 0 0 0 1⎥ ⎢ 2⎥ ⎥ ⎢ ⎢ ⎥ ⎥ ⎢ ⎢ 0⎥ ⎢1 0 0 0 0 0 0 0 0⎥ ⎢ ⎥ ⎢ ⎥ ⎢ ⎣0 1 0 0 0 0 0 0 0⎦ ⎣2⎦ 1 001000000 [ ]T = 0, 1, 2, 0, 2, 1, 0, 0, 0 .

.

Example 8.10 In the case of function . f 1 = x12 ⊕ x22 , the substitutions .x1 → x1 ⊕ 1 and 2 2 . x 2 → x 2 ⊕ 1 lead to the functions whose functional expressions are . f 2 = x ⊕ x ⊕ 2x 1 ⊕ 1 2 2 2 1 and . f 2 = x1 ⊕ x2 ⊕ 2x2 ⊕ 1, respectively. The function vectors of these functions are obtained by the multiplication of the function vector .F1 for . f 1 by the permutation matrices .P1 and .P2 in Examples 8.8 and 8.9, respectively.

8.6

Computation with Permutation Matrices

Figures 8.16, 8.17, 8.18, 8.19, and 8.20 show flow-graphs of algorithms for performing permutations defined by the matrices .Q1 ⊗ I(1), .I(1) ⊗ Q1 , .Q2 ⊗ I(1), .I(1) ⊗ Q2 , .X1 ⊗ I(1), .I(1) ⊗ X1 , .X1T ⊗ I(1), .I(1) ⊗ X1T , .N ⊗ I(1), .I(1) ⊗ N1 . In order to justify the term FFT-like permutation matrices, the flow-graph for permutations is shown by the thicker green lines over the black lines in the flow-graph for the transform. Recall that in the flowgraph of the FFT for the Vilenkin–Chrestenson transform of ternary functions, the weights at the edges are elements of the Vilenkin–Chrestenson matrices .1, .e1 , and .e2 . When the basic transform matrix is replaced by the basic permutation matrices, the weights at the edges are either .0 or .1. Therefore, in the flow-graph, the edges with the weight .0 do no appear.

8.7

Extensions to Functions in Arbitrary Number of Variables

Considerations and related conclusions derived in the previous section on the example of ternary bent functions in two variables can be extended to functions in an arbitrary number of variables in the same way as this is done in the case of FFT-like algorithms. It means just the extension of the number of terms in the Kronecker product expression as it is written in (8.3).

8.7

Extensions to Functions in Arbitrary Number of Variables

Fig. 8.16 Flow-graphs for the permutation matrices .Q1 ⊗ I(1) and .I(1) ⊗ Q1

231

f(0)

f(3)

f(0)

f(1)

f(1)

f(4)

f(1)

f(0)

f(2)

f(5)

f(2)

f(2)

f(3)

f(0)

f(3)

f(4)

f(4)

f(1)

f(4)

f(3)

f(5)

f(2)

f(5)

f(5)

f(6)

f(6)

f(6)

f(7)

f(7)

f(7)

f(7)

f(6)

f(8)

f(8)

f(8)

f(8) Q1 I(1)

Q1 I(1)

Fig. 8.17 Flow-graphs for the permutation matrices .Q2 ⊗ I(1) and .I(1) ⊗ Q2

f(0)

f(0)

f(0)

f(0)

f(1)

f(1)

f(1)

f(2)

f(2)

f(2)

f(2)

f(1)

f(3)

f(6)

f(3)

f(3)

f(4)

f(7)

f(4)

f(5)

f(5)

f(8)

f(5)

f(4)

f(6)

f(3)

f(6)

f(6)

f(7)

f(4)

f(7)

f(8)

f(8)

f(5)

f(8)

f(7) I(1) Q2

Q2 I(1)

Fig. 8.18 Flow-graphs for the permutation matrices .X1 ⊗ I(1) and .I(1) ⊗ X1

f(0)

f(6)

f(0)

f(2)

f(1)

f(7)

f(1)

f(0)

f(2)

f(8)

f(2)

f(1)

f(3)

f(0)

f(3)

f(5)

f(4)

f(1)

f(4)

f(3)

f(5)

f(2)

f(5)

f(4)

f(6)

f(3)

f(6)

f(8)

f(7)

f(4)

f(7)

f(6)

f(8)

f(5)

f(8)

f(7)

X1 I(1)

I(1) X1

232

8 Construction of Bent Functions by FFT-like Permutation Matrices

Fig. 8.19 Flow-graphs for the permutation matrices T T .X ⊗ I(1) and .I(1) ⊗ X 1 1

f(0)

f(3)

f(0)

f(1)

f(1)

f(4)

f(1)

f(2)

f(2)

f(5)

f(2)

f(0)

f(3)

f(6)

f(3)

f(4)

f(4)

f(7)

f(4)

f(5)

f(5)

f(8)

f(5)

f(3)

f(6)

f(0)

f(6)

f(7)

f(7)

f(1)

f(7)

f(8)

f(2)

f(8)

f(8) X

T 1

Fig. 8.20 Flow-graphs for the permutation matrices .N1 ⊗ I(1) and .I(1) ⊗ N1

f(6) I(1) X

I(1)

T 1

f(0)

f(6)

f(0)

f(2)

f(1)

f(7)

f(1)

f(1)

f(2)

f(8)

f(2)

f(0)

f(3)

f(3)

f(3)

f(5)

f(4)

f(4)

f(4)

f(4)

f(5)

f(5)

f(5)

f(3)

f(6)

f(0)

f(6)

f(8)

f(7)

f(1)

f(7)

f(7)

f(8)

f(2)

f(8)

f(6)

N1 I(1)

I(1) N1

Example 8.11 Consider the function . f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 witch is a basic ternary bent function in three variables. Its function vector is F = [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 2, 0, 0, 1, 2, 2]T .

.

The permutation matrix .P1 = X1T ⊗ I(1) ⊗ I(1) converts this function vector into the function vector F1 = P1 · F

.

= [0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 2, 0, 0, 1, 2, 2, 0, 1, 1, 0, 1, 1, 0, 1, 1]T . The functional expression for the function . f 1 for this function vector is .

f 1 (x1 , x2 , x3 ) = x1 x2 ⊕ x32 ⊕ x2 ,

8.7

Extensions to Functions in Arbitrary Number of Variables

233

Table 8.6 Function vectors and functional expressions for bent functions constructed by the Kronecker product representable FFT-like permutation matrices from the function . f in Example 8.11, 2 . f = x1 x2 ⊕ x 3 1

.P2

= I(1) ⊗ X1 ⊗ I(1), .x2 → x2 ⊕ 2

.F2

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0, 0, 1, 1, 1, 2, 2, 1, 2, 2, 0, 1, 1, 2, 0, 0]T

. f 2 (x 1 , x 2 , x 3 )

2

.P3

= I(1) ⊗ I(1) ⊗ Q2 , .x3 → 2x3

.F3

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 2, 0, 0, 1, 2, 2]T

. f 3 (x 1 , x 2 , x 3 )

3

= x1 x2 ⊕ x32

.P4

= Q1 ⊗ I(1) ⊗ I(1), .x1 → 2x1 ⊕ 1

.F4

= [0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0, 1, 2, 2]T

. f 4 (x 1 , x 2 , x 3 )

4

= x1 x2 ⊕ 2x1 ⊕ x32

= 2x1 x2 ⊕ x2 ⊕ x32

.P5

= I(1) ⊗ I(1) ⊗ N1 , .x3 → 2x3 ⊕ 2

.F5

= [1, 1, 0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 1, 0, 0, 0, 2, 2, 2, 1]T

. f 5 (x 1 , x 2 , x 3 )

= 1 ⊕ 2x3 ⊕ x32 ⊕ x1 x2

which is the function constructed by the spectral invariant operation .x1 → x1 ⊕ 1. Example 8.12 Table 8.6 shows function vectors and functional expressions for bent functions produced by the application of different Kronecker product representable FFT-like permutation matrices to the function . f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 in Example 8.11, as well as the corresponding spectral invariant operations. The following examples illustrate simultaneous application of two or more basic permutation matrices. Example 8.13 Consider a permutation matrix defined as P6 = P1 · P5

.

= (X1T ⊗ I(1) ⊗ I(1)) · (I(1) ⊗ I(1) ⊗ N1 ) = X1T ⊗ I(1) ⊗ N1 . The application of this matrix to the function . f in Example 8.11 results in the function . f 6 whose function vector is F6 = P6 · F

.

= [1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 1, 0, 0, 0, 2, 2, 2, 1, 1, 1, 0, 1, 1, 0, 1, 1, 0]T , and the corresponding functional expression is .

f 6 (x1 , x2 , x3 ) = 1 ⊕ 2x3 ⊕ x32 ⊕ x2 ⊕ x1 x2 .

234

8 Construction of Bent Functions by FFT-like Permutation Matrices

This functional expression is derived by the application of two spectral invariant operations corresponding to matrices .P1 and .P5 , thus, .x1 → x1 ⊕ 1 and .x3 → 2x3 ⊕ 2. Example 8.14 Let .P7 = P1 · P2 · P3 . From the definitions of .P1 , .P2 , and .P3 P7 = (X1T ⊗ I(1) ⊗ I(1)) · (I(1) ⊗ X1 ⊗ I(1)) · (I(1) ⊗ I(1) ⊗ Q2 )

.

= X1T ⊗ X1 ⊗ Q2 . The function . f 7 has the function vector .F7 = P7 · F, i.e., F7 = [2, 0, 0, 0, 1, 1, 1, 2, 2, 1, 2, 2, 0, 1, 1, 2, 0, 0, 0, 1, 1, 0, 1, 1, 0, 1, 1]T ,

.

and its functional expression is .

f 7 (x1 , x2 , x3 ) = 2 ⊕ x32 ⊕ x2 ⊕ 2x1 ⊕ x1 x2

which is produced from the functional expression for . f by the spectral invariant operations . x 1 → x 1 ⊕ 1, . x 2 → x 2 ⊕ 2, and . x 3 → 2x 3 .

8.7.1

Permutation Matrices for Disjoint Spectral Translation

In the Boolean domain, substitution of a variable by the sum of this variable and another variable, i.e., .xi → xi ⊕ x j is a spectral invariant operation usually called the disjoint spectral translation [9, 10]. This operation is efficiently used in many applications intended toward simplification of representations and implementations of Boolean functions already from the initial ideas in 1963 [11], to the more recent applications [12–15] as well as the references therein. The related procedure is called the linear transformation or simply linearization of Boolean functions and if repeatedly applied results in the substitution . x i → x i ⊕ x j ⊕ · · · ⊕ xr . The generalization to ternary functions is straightforward by allowing three-valued coefficients in the linear combination of variables. Thus, the corresponding substitution of a variable .xi is defined as .xi → k1 xi ⊕ k2 x j for .k1 , k2 ∈ {1, 2}. As in the binary case, permutation matrices to perform this spectral invariant operation are determined in terms of auxiliary symbolic matrices. We first use the symbolic Kronecker product representable matrix defined as Qi, j =

n Θ

.

r =1

where

Mr ,

8.7

Extensions to Functions in Arbitrary Number of Variables

235

⎧ ⎨ Ak1 , if r = i, .Mr = B , if r = j, ⎩ k2 I(1), otherwise, where ⎡

⎡ ⎤ ⎤ abc abc .A1 = ⎣ c a b ⎦ , A2 = ⎣ b c a ⎦ , bc a c ab and ⎡

⎡ ⎤ ⎤ a00 a00 .B1 = ⎣ 0 b 0 ⎦ , B2 = ⎣ 0 c 0 ⎦ , 00c 00b i.e., .B1 = diag(a, b, c) and .B2 = diag(a, c, b). After the computation with symbolic matrices is performed, the squared terms are replaced by .1 and terms consisting of product of symbols by .0. Formally, this replacement of symbols can be expressed as .

z · 1 = z,

z · 0 = 0, { 0 for z 1 / = z 2 z1 · z2 = 1 for z 1 = z 2 , for .z, z 1 , z 2 ∈ {a, b, c}. The following examples illustrate implementation of the disjoint spectral translation for ternary functions in terms of permutation matrices. Example 8.15 We define a symbolic matrix as.Q1 = A1 ⊗ I(1) ⊗ B1 , which after performing computing and replacement of squared and product terms with .0 and .1, respectively, results in a permutation matrix.Q1 . An application of this matrix to.F in Example 8.11 results in another bent function with the function vector G1 = Q1 · F

.

= [0, 1, 1, 0, 2, 0, 0, 0, 2, 0, 1, 1, 1, 0, 1, 2, 2, 1, 0, 1, 1, 2, 1, 2, 1, 1, 0]T , and the functional expression g1 (x1 , x2 , x3 ) = x32 ⊕ x2 x3 ⊕ x1 x2

.

corresponding to the spectral invariant operation .x1 → x1 ⊕ x3 over . f .

236

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.7 Function vectors .Gi and functional expressions .gi for bent functions produced by the auxiliary symbolic Kronecker product representable FFT-like permutation matrices from the function 2 . f = x 1 x 2 ⊕ x in Example 8.11 3 1

.Q1

= A1 ⊗ I(1) ⊗ B1 , .x1 → x1 ⊕ x3

.G2

= [0, 1, 1, 0, 2, 0, 0, 0, 2, 0, 1, 1, 1, 0, 1, 2, 2, 1, 0, 1, 1, 2, 1, 2, 1, 1, 0]T

.g1 (x 1 , x 2 , x 3 )

2

= B1 ⊗ I(1) ⊗ A1 , .x3 → x1 ⊕ x3

.G2

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 0, 1, 0, 2, 0, 2, 1, 2]T

.g2 (x 1 , x 2 , x 3 )

3

= A1 ⊗ I(1) ⊗ B2 , .x1 → x1 ⊕ 2x3

.G3

= [0, 1, 1, 0, 0, 2, 0, 2, 0, 0, 1, 1, 1, 1, 0, 2, 1, 2, 0, 1, 1, 2, 2, 1, 1, 0, 1]T = B2 ⊗ I(1) ⊗ A1 , .x3 → 2x1 ⊕ x3

.G4

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 2, 0, 1, 1, 0, 0, 0, 2, 2, 2, 1]T = A2 ⊗ I(1) ⊗ B1 , .x1 → 2x1 ⊕ x3

.G5

= [0, 1, 1, 0, 2, 0, 0, 0, 2, 0, 1, 1, 2, 1, 2, 1, 1, 0, 0, 1, 1, 1, 0, 1, 2, 2, 1]T = B1 ⊗ I(1) ⊗ A2 , .x3 → x1 ⊕ 2x3

.G6

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 2, 0, 1, 1, 0, 0, 0, 2, 2, 2, 1]T = A2 ⊗ I(1) ⊗ B2 , .x1 → 2x1 ⊕ 2x3

.G7

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 2, 0, 1, 1, 0, 0, 0, 2, 2, 2, 1]T = B2 ⊗ I(1) ⊗ A2 , .x3 → 2x1 ⊕ 2x3

.G8

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 0, 1, 0, 2, 0, 2, 1, 2]T = x32 ⊕ 2x1 x3 ⊕ x1 x2 ⊕ x12

.Q9

= Q1 · Q5 , .x1 → 2x1 ⊕ x3 , .x1 → x1 ⊕ x3

.G9

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0, 1, 2, 2, 0, 1, 1, 1, 2, 2, 2, 0, 0]T

.g9 (x 1 , x 2 , x 3 )

10

= x32 ⊕ x1 x3 ⊕ x1 x2 ⊕ x12

.Q8

.g8 (x 1 , x 2 , x 3 )

9

= x32 ⊕ x1 x3 ⊕ x1 x2 ⊕ x12

.Q7

.g7 (x 1 , x 2 , x 3 )

8

= x32 ⊕ x2 x3 ⊕ 2x1 x2

.Q6

.g6 (x 1 , x 2 , x 3 )

7

= x32 ⊕ x1 x3 ⊕ x1 x2 ⊕ x12

.Q5

.g5 (x 1 , x 2 , x 3 )

6

= x32 ⊕ 2x2 x3 ⊕ x1 x2

.Q4

.g4 (x 1 , x 2 , x 3 )

5

= x32 ⊕ 2x1 x3 ⊕ x1 x2 ⊕ x12

.Q3

.g3 (x 1 , x 2 , x 3 )

4

= x32 ⊕ x2 x3 ⊕ x1 x2

.Q2

.Q10 .H1

= x32 ⊕ 2x1 x2

= Q1 · P5 · Q4 , .x3 → 2x1 ⊕ x3 , .x3 → 2x3 ⊕ 2, .x1 → x1 ⊕ x3

= [1, 0, 1, 1, 1, 0, 1, 2, 2, 1, 1, 0, 2, 0, 0, 0, 2, 0, 0, 1, 1, 2, 1, 2, 1, 1, 0]T

.h 1 (x 1 , x 2 , x 3 )

= 1 ⊕ x3 ⊕ x32 ⊕ x2 x3 ⊕ 2x1 ⊕ x1 x3 ⊕ x1 x2 ⊕ x12

Example 8.16 Table 8.7 shows function vectors .G and functional expressions for bent functions produced by the application of symbolic Kronecker product representable FFTlike permutation matrices, as well as the corresponding spectral invariant operations.

8.7

Extensions to Functions in Arbitrary Number of Variables

8.7.2

237

Permutation Matrices for Permutation of Variables

Permutation of variables is a spectral invariant operation and can be performed by the permutation matrices defined as follows. For permuting two variables .xi and .x j we define the symbolic matrix ⎧ n ⎨ S, for k = i, Θ .R = Mk , Mk = ST , for k = j, ⎩ k=1 I(1), otherwise, ⎡

⎤ ab c where .S = ⎣ d e f ⎦. gh i After replacing the squared terms by .1 and all other terms which are products of symbols by .0, as formally defined above, the corresponding permutation matrix is constructed. Example 8.17 Consider the following matrix for .n = 3 S2,3 = I(1) ⊗ S ⊗ ST ⎡ ⎤ ⎡ ⎤ ab c a d g = I(1) ⊗ ⎣ d e f ⎦ ⊗ ⎣ b e h ⎦ . gh i c f i

.

After symbolic computing and replacing the terms, we get ⎡

Q S2,3

.

1 ⎢0 ⎢ ⎢0 ⎡ ⎤ ⎢ ⎢0 100 ⎢ ⎢ = ⎣0 1 0⎦ ⊗ ⎢0 ⎢ ⎢0 001 ⎢ ⎢0 ⎢ ⎣0 0

0 0 0 1 0 0 0 0 0

0 0 0 0 0 0 1 0 0

0 1 0 0 0 0 0 0 0

0 0 0 0 1 0 0 0 0

0 0 0 0 0 0 0 1 0

0 0 1 0 0 1 0 0 0

0 0 0 0 0 0 0 0 0

⎤ 0 0⎥ ⎥ 0⎥ ⎥ 0⎥ ⎥ ⎥ 0⎥. ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎦ 1

If .F is the function vector of the function . f (x1 , x2 , x3 ) = x1 x2 ⊗ x32 and Fs = Q S2,3 · F,

.

then the function vector .Fs of the function . f s (x1 , x2 , x3 ) = x1 x3 ⊗ x22 is constructed.

238

8.7.3

8 Construction of Bent Functions by FFT-like Permutation Matrices

Block Diagonal Permutation Matrices

In this section, we consider matrices of the block diagonal structure that are typical for the .n-th step in the Cooley–Tukey FFT algorithms. We assume that these matrices can be applied to ternary bent functions whose functional expressions are the sum of disjoint pairs of variables. The term .xi2 is included when the number of variables .n is odd. As noticed before, any of the variables can be taken as a square, and just for convenience we usually use either the first or the last variable, .x1 or .xn . The reason for the restriction to these functional expressions is that block diagonal matrices permute function values within subvectors of length .3r , .r = 1, 2, . . . , n − 1, in the function vector. Their application to functions determined by functional expressions of other forms might, but also might not, produce another bent function due to the substitution of variables to which the used matrices correspond. The following example explains the way in which the sizes of blocks within the block diagonal permutation matrices are determined. Example 8.18 For .n = 3, the function vector has the length .33 = 27, and can be split into subvectors of length .3 or .9. Therefore, possible blocks in a block diagonal matrix are of dimensions .(3 × 3) or .(9 × 9). Since we work with the basic permutation matrices, the blocks are .(3 × 3), with the exception that when the identity matrices are at neighboring positions, the resulting blocks are of larger dimensions, since identity matrices are diagonal matrices. The following example illustrates the basic idea behind the block diagonal permutation matrices and their applications. Example 8.19 Given are the function . f (x1 , x2 ) = x1 x2 and its function vector .Fx1 x2 = [0, 0, 0, 0, 1, 2, 0, 2, 1]T . Consider a permutation matrix defined as P1,2 = diag(I(1), X1T , X1 ).

.

The function vector of the term .x12 viewed as a function in two variables is Fx 2 = [0, 0, 0, 1, 1, 1, 1, 1, 1]T ,

.

1

and the function vector of . f = x1 x2 ⊕ x12 is Fx1 x2 ⊕x 2 = Fx1 x2 ⊕ Fx 2 = [0, 0, 0, 1, 2, 0, 1, 0, 2]T .

.

1

1

The same vector can be obtained by multiplying the function vector .F of the function f = x1 x2 with the permutation matrix

.

8.7

Extensions to Functions in Arbitrary Number of Variables

239

P1,2 = Diag(I(1), X1T , X1 ),

.

since ⎤ ⎡ ⎤ 0 100000000 ⎢0 1 0 0 0 0 0 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 1 0 0 0 0 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 1 0 0 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ = ⎢0 0 0 0 0 1 0 0 0⎥ · ⎢1⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 1 0 0 0 0 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 1⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎣0 0 0 0 0 0 1 0 0⎦ ⎣2⎦ 1 000000010 [ ]T = 0, 0, 0, 1, 2, 0, 1, 0, 2 . ⎡

P1,2 · Fx1 x2

.

The function . f = x1 x2 ⊕ x12 is obtained from . f = x1 x2 by the spectral invariant operation .x2 → x2 ⊕ x1 . Therefore, the application of the block diagonal permutation matrix .P1,2 to the considered function produces the same result as this substitution of variable . x 2 . Consider now the substitution .x1 → x1 ⊕ x2 . The corresponding function constructed from . f = x1 x2 is . f = x1 x2 ⊕ x22 whose function vector is .F = [0, 1, 1, 0, 2, 0, 0, 0, 2]T . The same function can be constructed by various permutation matrices, and among them the permutation matrix determined as ⎤ ⎡ ⎤ 0 100000000 ⎢0 0 0 0 1 0 0 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 0 0 1⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 1 0 0 0 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ ⎥ ⎢ = ⎢0 0 0 0 0 0 0 1 0⎥ · ⎢1⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 1 0 0 0 0 0 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎢0 0 0 0 0 0 1 0 0⎥ ⎢0⎥ ⎥ ⎢ ⎥ ⎢ ⎣0 1 0 0 0 0 0 0 0⎦ ⎣2⎦ 1 000001000 [ ]T = 0, 1, 1, 0, 2, 0, 0, 0, 2 . ⎡

P2,2 · Fx1 x2

.

The matrix .P2,2 is not a block diagonal matrix, and the conclusion is that there is the requirement that the index .i of the substituted variable .xi must be greater than the index . j of the squared variable .x j to be added. The requirement .i > j comes from the block diagonal structure of the permutation matrices. The case .i < j results in the matrices that we call the shift-based matrices which are discussed below. The matrix .P2,2 has the structure of such matrices. This topic is discussed further in Example 8.22. Figure 8.21 shows the flow-graph of the fast algorithm for permutations by the matrices .P1,2 and .P2,2 which is defined below in Example 8.22.

240

8 Construction of Bent Functions by FFT-like Permutation Matrices

Fig. 8.21 Flow-graphs for the permutation matrices .P1,2 and .P2,2

f(0)

f(0)

f(0)

f(0)

f(1)

f(1)

f(1)

f(4)

f(2)

f(2)

f(2)

f(8)

f(3)

f(4)

f(3)

f(3)

f(4)

f(5)

f(4)

f(7)

f(5)

f(3)

f(5)

f(2)

f(6)

f(8)

f(6)

f(6)

f(7)

f(6)

f(7)

f(1)

f(7)

f(8)

f(5)

f(8) P1,2= diag(I(1),X

T 1

1

P2,2

In what follows, we consider a particular type of block diagonal matrices that are used to perform the substitution .xi → k1 xi ⊕ k2 x 2j where .k1 , k2 ∈ {1, 2} under the condition that .i > j. We consider block diagonal permutation matrices for functions in .n variables performing transformation over two variables .i and . j defined as Pi, j (n) = diag (I(n − j), M(n − j), M(n − j)) ,

.

where M(n − j) =

n− j Θ

.

Mr ,

r =1

where { Mr =

.

M, for j = i, I(1), for j / = i,

where .M ∈ {X1 , X1T , Q1 , N1 }, and .I(0) = 1. Therefore, the request is that the last two matrices are identical, and the variables .xi and .x j involved in transformation satisfy the requirement .i > j. Thus, the defined block diagonal matrices perform the substitution .xi → k1 xi ⊕ k2 x j . Depending on the selected matrix .M, the substitution of variables for different combinations of possible values for .k1 and .k2 is performed. Table 8.8 shows assignment of matrices .M to substitutions for different combinations of .k 1 and .k 2 . The following examples illustrate the application of such defined diagonal block matrices to construct other ternary bent functions in three and four variables.

8.7

Extensions to Functions in Arbitrary Number of Variables

241

Table 8.8 Substitutions performed by block diagonal matrices based on basic permutation matrices .k1 , k2

Replacement

.X

T 1

.1, 1

.xi

.X1

.1, 2

.Q1

.2, 1

.N1

.2, 2

.M

→ xi ⊕ xk2 2 . x i → x i ⊕ 2x k → 2xi ⊕ xk2 2 . x i → 2x i ⊕ 2x k .xi

Example 8.20 For .n = 3, consider the permutation matrix V1 = diag(I(2), I(1) ⊗ X1T , I(1) ⊗ X1T ).

.

The application of this matrix to the function vector .F of the function . f = x1 x2 ⊕ x32 results in T1 = V1 · F

.

= [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 1, 0, 0, 0, 2, 2, 2, 1]T . The corresponding functional expression is t1 (x1 , x2 , x3 ) = x32 ⊕ x1 x2 ⊕ x12 ⊕ 2x12 x3 ,

.

which is obtained by the substitution .x3 → x3 ⊕ x12 in the starting function . f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 . It is interesting to observe that the degree of the initial function is .2 while that of the constructed function is.3. It follows that block diagonal matrices with an appropriate selection of basic permutation matrices and variables to which they will be applied can be used to increase the degree of bent functions. Example 8.21 Table 8.9 shows function vectors and functional expressions for bent functions in .n = 3 variables produced by the application of block diagonal FFT-like permutation matrices to the function . f = x1 x2 ⊕ x32 , as well as the corresponding spectral invariant operations.

8.7.4

Block Diagonal Permutation Matrices for .n = 4

Table 8.10 shows the block diagonal permutation matrices performing the substitution of the form .xi → k1 xi ⊕ k2 x 2j , .i > j, when applied to ternary bent function . f = x1 x2 ⊕ x3 x4 . The extension to other values of .n is straightforward.

242

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.9 Function vectors and functional expressions for bent functions produced by the block diagonal FFT-like permutation matrices from the function . f = x1 x2 ⊕ x32 in Example 8.11 1

2

3

4

5

6

7

7

9

10

11

12

13

.V2 = diag(I(2), X1T ⊗ I(1), X1T ⊗ I(1)), . x 2 → x 2 ⊕ x 12 .T2 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 2, 0, 0, 1, 2, 2, 0, 1, 1]T .t2 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 1 x 2 ⊕ x 1 .V3 = I(1) ⊗ diag(I(1), X1T , X1T ), . x 3 → x 3 ⊕ x 22 .T3 = [0, 1, 1, 1, 1, 0, 1, 1, 0, 0, 1, 1, 2, 2, 1, 0, 0, 2, 0, 1, 1, 0, 0, 2, 2, 2, 1]T .t3 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 22 x 3 ⊕ x 22 ⊕ x 1 x 2 .V4 = diag(I(2), I(1) ⊗ X1 , I(1) ⊗ X1 ), . x 3 → x 3 ⊕ 2x 12 .T4 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 2, 0, 1, 0, 1, 0, 2, 0, 2, 1, 2]T .t4 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 1 x 2 ⊕ x 3 x 12 ⊕ x 12 .V5 = diag(I(2), X1 ⊗ I(1), X1 ⊗ I(1)), . x 2 → x 3 ⊕ 2x 12 .T5 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0, 0, 1, 1, 1, 2, 2, 1, 2, 2, 0, 1, 1, 2, 0, 0]T .t5 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 1 ⊕ x 1 x 2 .V6 = I(1) ⊗ diag(I(1), X1 , X1 ), . x 3 → x 3 ⊕ 2x 22 .T6 = [0, 1, 1, 1, 0, 1, 1, 0, 1, 0, 1, 1, 2, 1, 2, 0, 2, 0, 0, 1, 1, 0, 2, 0, 2, 1, 2]T .t6 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 3 x 22 ⊕ x 22 ⊕ x 1 x 2 .V7 = diag(I(2), I(1) ⊗ Q1 , I(1) ⊗ Q1 , . x 3 → 2x 3 ⊕ x 12 .T7 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 0, 1, 2, 1, 2, 0, 2, 0, 1, 0, 1, 0, 2, 0, 2, 1, 2]T .t7 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 12 x 3 ⊕ x 12 ⊕ x 1 x 2 .V8 = diag(I(2), Q1 ⊗ I(1), Q1 ⊗ I(1), . x 2 → 2x 2 ⊕ x 12 .T8 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 2, 2, 0, 1, 1, 2, 0, 0, 2, 0, 0, 0, 1, 1, 1, 2, 2]T .t8 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 1 ⊕ 2x 1 x 2 .V9 = I(1) ⊗ diag(I(1), Q1T , Q1T ), . x 3 → 2x 3 ⊕ x 22 .T9 = [0, 1, 1, 1, 0, 1, 1, 0, 1, 0, 1, 1, 2, 1, 2, 0, 2, 0, 0, 1, 1, 0, 2, 0, 2, 1, 2]T .t9 (x 1 , x 2 , x 3 ) = x 32 ⊕ x 3 x 22 ⊕ x 22 ⊕ x 1 x 2 .V10 = diag(I(2), I(1) ⊗ N1 , I(1) ⊗ N1 ), . x 3 → 2x 3 ⊕ 2x 12 .T10 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 1, 0, 2, 2, 1, 0, 0, 2, 1, 1, 0, 0, 0, 2, 2, 2, 1]T .t10 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 3 x 12 ⊕ x 12 ⊕ x 1 x 2 .V11 = diag(I(2), N1 ⊗ I(1), N1 ⊗ I(1)), . x 2 → 2x 2 ⊕ 2x 12 .T11 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0, 1, 2, 2, 0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1]T .t11 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 1 ⊕ 2x 1 x 2 .V12 = I(1) ⊗ diag(I(1), N1 , N1 ), . x 3 → 2x 3 ⊕ 2x 22 .T12 = [0, 1, 1, 1, 1, 0, 1, 1, 0, 0, 1, 1, 2, 2, 1, 0, 0, 2, 0, 1, 1, 0, 0, 2, 2, 2, 1]T .t12 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 3 x 22 ⊕ x 22 ⊕ x 1 x 2 .V13 = diag(I(2), X1 ⊗ X1 , X1 ⊗ X1 ), . x 2 → x 2 ⊕ 2x 12 and . x 3 → x 3 ⊕ 2x 12 .T13 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 2, 0, 1, 0, 1, 2, 1, 2, 2, 1, 2, 1, 0, 1, 0, 2, 0]T .t13 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 1 ⊕ x 1 x 2 ⊕ x 12 x 3 ⊕ x 12 .V14 = diag(I(2), X1 ⊗ Q1 , X1 ⊗ Q1 ), . x 2 → x 2 ⊕ 2x 12 and . x 3 → 2x 3 ⊕ x 12 .T14 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 2, 0, 1, 0, 1, 2, 1, 2, 2, 1, 2, 1, 0, 1, 0, 2, 0]T .t14 (x 1 , x 2 , x 3 ) = x 32 ⊕ 2x 1 ⊕ x 1 x 2 ⊕ x 12 ⊕ x 12 x 3

8.7

Extensions to Functions in Arbitrary Number of Variables

243

Table 8.10 Diagonal permutation matrices for .n = 4 and related substitution rules Permutation matrix .P4,1

=

.P4,1

=

.P4,1 .P4,1

Substitution rule

diag(I(3), I(2) ⊗ X1T , I(2) ⊗ X1T ) diag(I(3), I(2) ⊗ X1T , I(2) ⊗ X1T )

.x4

= x4 ⊕ x12

.x4

= x4 ⊕ 2x12

= diag(I(2) ⊗ Q2 , I(2) ⊗ Q1 , I(2) ⊗ Q1 )

.x4

= 2x4 ⊕ x12

= diag(I(2) ⊗ Q2 , I(2) ⊗ N1 , I(2) ⊗ N1 )

.x4

= 2x4 ⊕ 2x12

.x3

= x3 ⊕ x12

diag(I(3), I(1) ⊗ X1T

.P3,1

=

.P3,1

= diag(I(3), I(1) ⊗ X1 ⊗ I(1), I(1) ⊗ X1 ⊗ I(1))

.x3

= x3 ⊕ 2x12

.P3,1

= diag(I(1) ⊗ Q2 ⊗ I(1), I(1) ⊗ Q1 ⊗ I(1), I(1) ⊗ Q1 ⊗ I(1))

.x3

= 2x3 ⊕ x12

.P3,1

= diag(I(1) ⊗ Q2 ⊗ I(1), I(1) ⊗ N1 ⊗ I(1), I(1) ⊗ N1 ⊗ I(1))

.x3

= 2x3 ⊕ 2x12

.P2,1

=

.x2

= x2 ⊕ x12

.P2,1

= diag(I(3), X1 ⊗ I(2), X1 ⊗ I(2)

.x2

= x2 ⊕ 2x12

.P2,1

= diag(Q2 ⊗ I(2), Q1 ⊗ I(2), Q1 ⊗ I(2)

.x2

= 2x2 ⊕ 2x12

.P2,1

= diag(Q2 ⊗ I(2), N1 ⊗ I(2), N1 ⊗ I(2)

.x2

= 2x2 ⊕ 2x12

.x4

= x4 ⊕ x22

diag(I(3), X1T

⊗ I(1), I(1) ⊗ X1T

⊗ I(2), X1T

⊗ I(1))

⊗ I(2)

.P4,2

=

.P4,2

= I(1) ⊗ diag(I(2), I(1) ⊗ X1 , I(1) ⊗ X1 )

.x4

= x4 ⊕ 2x22

.P4,2

= I(1) ⊗ diag(I(1) ⊗ Q2 , I(1) ⊗ Q1 , I(1) ⊗ Q1 )

.x4

= 2x4 ⊕ x22

.P4,2

= I(1) ⊗ diag(I(1) ⊗ Q2 , I(1) ⊗ N1 , I(1) ⊗ N1 )

.x4

= 2x4 ⊕ 2x22

.P3,2

= I(1) ⊗ diag(I(2), X1T ⊗ I(1), X1T ⊗ I(1))

.x3

= x3 ⊕ x22

.P3,2

= I(1) ⊗ diag(I(2), X1 ⊗ I(1), X1 ⊗ I(1))

.x3

= x3 ⊕ 2x22

.P3,2

= I(1) ⊗ diag(Q2 ⊗ I(1), Q1 ⊗ I(1), Q1 ⊗ I(1))

.x3

= 2x3 ⊕ x22

.P3,2

= I(1) ⊗ diag(Q2 ⊗ I(1), N1 ⊗ I(1), N1 ⊗ I(1))

.x3

= 2x3 ⊕ 2x22

.P4,3

= I(2) ⊗ diag(I(1), X1T , X1T

.x4

= x4 ⊕ x32

.P4,3

= I(2) ⊗ diag(I(1), X1 , X1

.x4

= x4 ⊕ 2x32

.P4,3

= I(2) ⊗ diag(Q2 , Q1 , Q1

.x4

= 2x4 ⊕ x32

.P4,3

= I(2) ⊗ diag(Q2 , N1 , N1

.x4

= 2x4 ⊕ 2x32

8.7.5

I(1) ⊗ diag(I(2), I(1) ⊗ X1T , I(1) ⊗ X1T )

Shift-Based Permutation Matrices

The shift-based permutation matrices concern the case of spectral invariant operation .xi → xi ⊕ x j , for .i < j. Introduction of these permutation matrices in the construction of bent functions by permutation matrices is based on the following considerations. It should be noticed that the basic permutation matrix .X1 performs the cyclic shift. This observation is important since the next permutation matrix .P2,2 describing the addition of the term .x22 to the basic bent function . f = x1 x2 is determined in terms of the cyclic shift of elements of submatrices in the block structure of this permutation matrix. Example 8.22 Consider the basic bent function in two variables. f = x1 x2 . The substitution of variable .x1 → x1 ⊕ x2 results in the function . f = x1 x2 ⊕ x22 , which can be interpreted as adding the term .x22 while preserving bentness. In terms of function vectors, this example can be discussed as follows.

244

8 Construction of Bent Functions by FFT-like Permutation Matrices

The function . f = x22 has the function vector F2x2 = [0, 1, 1, 0, 1, 1, 0, 1, 1]T .

.

When added to the function vector of the basic bent function . f = x1 x2 , which is Fx1 x2 = [0, 0, 0, 0, 1, 2, 0, 2, 1]T ,

.

the function vector of the constructed bent function .x1 x2 ⊕ x22 is obtained as Fx1 x2 ⊕x 2 = [0, 1, 1, 0, 2, 0, 0, 0, 2]T .

.

2

The same function vector can be obtained by the multiplication of .Fx1 x2 by the permutation matrix .P2,2 as Fx1 x2 ⊕x 2 = P2,2 · Fx1 x2 2 ⎡ 10000 ⎢0 0 0 0 1 ⎢ ⎢0 0 0 0 0 ⎢ ⎢0 0 0 1 0 ⎢ ⎢ = ⎢0 0 0 0 0 ⎢ ⎢0 0 1 0 0 ⎢ ⎢0 0 0 0 0 ⎢ ⎣0 1 0 0 0 00000

.

0 0 0 0 0 0 0 0 1

0 0 0 0 0 0 1 0 0

0 0 0 0 1 0 0 0 0

⎤ ⎡ ⎤ 0 0 ⎢0⎥ 0⎥ ⎥ ⎢ ⎥ ⎢ ⎥ 1⎥ ⎥ ⎢0⎥ ⎥ ⎥ 0⎥ ⎢ ⎢0⎥ ]T ⎥ ⎢ ⎥ [ 0 ⎥ · ⎢ 1 ⎥ = 0, 1, 1, 0, 2, 0, 0, 0, 2 . ⎥ ⎢ ⎥ 0⎥ ⎢2⎥ ⎥ ⎢ ⎥ ⎢ ⎥ 0⎥ ⎥ ⎢0⎥ 0⎦ ⎣2⎦ 0

1

It follows that the matrix .P2,2 performs the spectral invariant operation .x1 → x1 ⊕ x2 . Figure 8.21 shows the flow-graph of the fast algorithm for permutations by the matrices .P1,2 in Example 8.19 above, and .P2,2 . Matrix .P2,2 describing the addition of .x22 to .x1 x2 can be split into .(3 × 3) submatrices. They are arranged as blocks of three submatrices in three rows. In the first row of submatrices, the first submatrix has .1 as the first element in the first row. Then, the next submatrix has .1 as the second element in the second row. The third submatrix has .1 as the third element in the third row. In the second row of submatrices, the same pattern repeats but shifted cyclically for a single place to the right. In the third row of submatrices, the pattern repeats but with a shift for two places. If we define the .(3 × 3) auxiliary matrices with a single non-zero element as ⎡ ⎡ ⎤ ⎡ ⎤ ⎤ 100 000 000 .R = ⎣ 0 0 0 ⎦ , V = ⎣ 0 1 0 ⎦ , E = ⎣ 0 0 0 ⎦ , 000 000 001

8.7

Extensions to Functions in Arbitrary Number of Variables

245

then, the matrix .P2,2 can be written as ⎡

P2,2

.

⎤ RVE = ⎣E R V⎦, VER

and if the matrix .P2,2 is split into .(3 × 3) blocks, it can be observed that the same shift-based structure repeats over blocks .R, .V, and .E. In a formal way, this matrix can be determined by using symbolic matrices as follows. Consider the sequence of symbols . S = {a, b, c}, and define .(3 × 3) matrices .A = diag(a, b, c) and .B whose rows are cyclically shifted sequence .(a, b, c) as ⎡

⎤ ⎡ ⎤ a00 abc .A = ⎣ 0 b 0 ⎦ , B = ⎣c a b⎦. 00c bca The Kronecker products of these symbolic matrices .(A ⊗ B) and .(B ⊗ A) followed by the replacement of the squared terms by .1 and all other product terms with mixed symbols by .0 result in the matrices .P1,2 and .P2,2 . Resemblance to matrices describing steps of the Cooley–Tukey FFT-like algorithms illustrated by Example 1.3 is easy to notice, especially in the case of permutation matrices describing addition of variables. The difference is that instead of using in FFT the basic transform matrices for .n = 1, here we use the .(3 × 3) permutation matrices. The matrices determining addition of squares of variables resemble reordering matrices appearing between steps of certain other FFT algorithms, as, for example, the Winograd FFT (WFTA), Prime Factors Algorithms, and related. For more information, we refer to [16–18]. As in the case of previously considered Kronecker representable permutation matrices, these block diagonal matrices perform particular permutations of spectral coefficients without changing their values. It follows that they perform spectral invariant operations. We can conclude which operations are representable by the shift-based matrices by comparing functional expressions of functions derived by permutations with these matrices and functions obtained by spectral invariant operations. Considering operations performed by Kronecker product representable permutation matrices is certainly avoided. In this way, it is easy to observe that shift-based matrices under consideration perform the spectral invariant operation of substitution of a variable .xi → xi ⊕ kx j ⊕ c, where .k ∈ {1, 2}, and .c ∈ {0, 1, 2}, assuming that the matrices .A and .B are at the . j-th and the .i-th position in the Kronecker product, while the identity matrix .I(1) is at all other positions. The values of .k and .c are determined by the permutation of elements .a, b, c at the main diagonal .d of the matrix .A as summarized in Table 8.11.

246

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.11 Substitution rules corresponding to the shift-based FFT-like permutation matrices .d

.k

.c

Substitution rule

.a, b, c

.2

.0

.xi

→ 2x j

.a, c, b

.1

.0

.xi

→ xj

.b, a, c

.1

.2

.xi

.b, c, a

.2

.2

→ xj ⊕ 2 . x i → 2x j ⊕ 2

.c, a, b

.1

.1

.xi

.c, b, a

.2

.1

8.8

→ xj ⊕ 1 . x i → 2x j ⊕ 1

Construction of Ternary Bent Functions by FFT-like Permutation Matrices

The FFT-like permutation matrices applied to the basic bent functions produce other bent functions. Therefore, they can be used to construct ternary bent functions. In this section, we discuss construction of ternary bent functions in two variables, and generalizations are straightforward as discussed in the next section and illustrated by examples. Taken from [2], Table 8.12 and its continuation Table 8.13 show .54 functions having the distribution .(5, 2, 2) derived from the basic function . f 1 = x1 x2 by possible combinations of FFT-like permutation matrices. Table 8.14 shows .27 functions derived from the basic function . f 2 = x12 ⊕ x22 as a representative of bent function sharing the distribution .(1, 4, 4). In these tables, .P1 = I(1) ⊗ X1T , .P2 = X1T ⊗ I(1), .P1,2 = diag(I(1), X1T , X1 ), and .P2,2 is defined in Example 8.22. As discussed above, the matrices .P1,2 and .P2,2 can be defined in terms of particular symbolic matrices. The following example illustrates construction of bent functions by using products of permutation matrices. Example 8.23 Consider the bent function . f = x1 x2 ⊕ x1 ⊕ x12 , whose function vector is T .F = [0, 0, 0, 2, 0, 1, 0, 2, 1] . This vector can be obtained by multiplying the function vector for. f = x1 x2 with the permutation matrix obtained as the product of the permutation matrices for adding .x1 and .x12

8.8

Construction of Ternary Bent Functions by FFT-like Permutation Matrices

Table 8.12 Bent functions (1–27) with distribution .(5, 2, 2) .F

= x1 x2

.(5, 2, 2)

.F

= x1 x2 ⊕ x1

.P1

.F

= x1 x2 ⊕ x2

.P2

.F

= x1 x2 ⊕ 2x1

.P1 P1

.F

= x1 x2 ⊕ 2x2

.P2 P2

.F

= x1 x2 ⊕ x1 ⊕ x2 ⊕ 1

.P1 P2

.F

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ 2

.P1 P1 P2

.F

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2

.P1 P2 P2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ 1

.P1 P1 P2 P2

.F

= x1 x2 ⊕ (x1 )2

.P1,2

.F

= x1 x2 ⊕ x1 ⊕ (x1 )2

.P1 P1,2

.F

= x1 x2 ⊕ x2 ⊕ (x1 )2 ⊕ 2

.P1 P2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ (x1 )2

.P1 P1 P1,2

.F

= x1 x2 ⊕ 2x2 ⊕ (x1 )2 ⊕ 2

.P1 P1 P2 P2 P1,2

.F

= x1 x2 ⊕ x1 ⊕ x2 ⊕ (x1 )2

.P1 P1 P2 P2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ (x1 )2 ⊕ 1

.P2 P1,2

.F

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ (x1 )2 ⊕ 1

.P2 P2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ (x1 )2

.P1 P2 P2 P1,2

.F

= x1 x2 ⊕ (x2 )2

.P2,2

.F

= x1 x2 ⊕ x1 ⊕ (x2 )2 ⊕ 2

.P1 P2 P2,2

.F

= x1 x2 ⊕ x2 ⊕ (x2 )2

.P2 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ (x2 )2 ⊕ 2

.P1 P1 P2 P2 P2,2

.F

= x1 x2 ⊕ 2x2 ⊕ (x2 )2

.P2 P2 P2,2

.F

= x1 x2 ⊕ x1 ⊕ x2 ⊕ (x2 )2

.P1 P2 P2 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ (x2 )2 ⊕ 1

.P1 P1 P2,2

.F

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ (x2 )2 ⊕ 1

.P1 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ (x2 )2

.P1 P1 P2 P2,2

P = P1 · P1,2

.

= Diag(X1T , X1 , I(1)) ⎤ ⎡ 010000000 ⎢0 0 1 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢1 0 0 0 0 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 1 0 0 0⎥ ⎥ ⎢ ⎥ ⎢ = ⎢0 0 0 1 0 0 0 0 0⎥. ⎥ ⎢ ⎢0 0 0 0 1 0 0 0 0⎥ ⎥ ⎢ ⎢0 0 0 0 0 0 1 0 0⎥ ⎥ ⎢ ⎣0 0 0 0 0 0 0 1 0⎦ 000000001

247

248

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.13 Bent functions (28–54) with distribution .(5, 2, 2) .F

= x1 x2 ⊕ 2(x1 )2

.P1,2 P1,2

.F

= x1 x2 ⊕ x1 ⊕ 2x12

.P1 P1,2 P1,2

.F

= x1 x2 ⊕ x2 ⊕ 2x12 ⊕ 1

.P1 P1 P2 P1,2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x12

.P1 P1 P1,2 P1,2

.F

= x1 x2 ⊕ 2x2 ⊕ 2x12 ⊕ 1

.P1 P2 P2 P1,2 P1,2

.F

= x1 x2 ⊕ x1 ⊕ x2 ⊕ 2x12 ⊕ 2

.P2 P1,2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ 2x12

.P1 P2 P1,2 P1,2

.F

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2x12

.P1 P1 P2 P2 P1,2 P1,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ 2x12 ⊕ 2

.P2 P2 P1,2 P1,2

.F

= x1 x2 ⊕ 2x22

.P2,2 P2,2

.F

= x1 x2 ⊕ x1 ⊕ 2x22 ⊕ 1

.P1 P2 P2 P2,2 P2,2

.F

= x1 x2 ⊕ x2 ⊕ 2x22

.P2 P2,2 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x22 ⊕ 1

.P1 P1 P2 P2,2 P2,2

.F

= x1 x2 ⊕ 2x2 ⊕ 2x22

.P2 P2 P2,2 P2,2

.F

= x1 x2 ⊕ x1 ⊕ x2 ⊕ 2x22 ⊕ 2

.P1 P2,2 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ x2 ⊕ 2x22

.P1 P1 P2 P2 P2,2 P2,2

.F

= x1 x2 ⊕ x1 ⊕ 2x2 ⊕ 2(x2 )2

.P1 P2 P2,2 P2,2

.F

= x1 x2 ⊕ 2x1 ⊕ 2x2 ⊕ 2x22 ⊕ 2

.P1 P1 P2,2 P2,2

.F

= 2x12 ⊕ x22

.P1,2 P2,2

.F

= x1 ⊕ 2x12 ⊕ x22 ⊕ 2

.P2 P1,2 P2,2

.F

= x2 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P1 P1,2 P2,2

.F

= x1 ⊕ x2 ⊕ 2x12 ⊕ x22

.P1 P1 P2 P1,2 P2,2

.F

= 2x1 ⊕ 2x12 ⊕ x22 ⊕ 2

.P2 P2 P1,2 P2,2

.F

= 2x2 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P1,2 P2,2

.F

= 2x1 ⊕ x2 ⊕ 2x12 ⊕ x22

.P1 P1 P2 P2 P1,2 P2,2

.F

= x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22

.P1 P2 P1,2 P2,2

.F

= 2x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22

.P1 P2 P2 P1,2 P2,2

Notice that in the cases of products of permutation matrices, different combinations of FFT-like permutation matrices such as factor matrices can produce identical results. This comes from the property that different spectral invariant operations can be applied in a different order. An algorithm to generate ternary bent functions in two variables by permutation matrices can be formulated as follows. Denote by. f 1 and. f 2 the functions whose functional expressions are the sum of disjoint pairs of variables and the sum of squares of variables, respectively.

8.8

Construction of Ternary Bent Functions by FFT-like Permutation Matrices

249

Table 8.14 Bent functions with distribution .(1, 4, 4) . x 12

⊕ x22

.(1, 4, 4)

.x1

⊕ x12 ⊕ x22 ⊕ 1

.P2 P2

.x2

⊕ x12 ⊕ x22 ⊕ 1

.P1 P1

.x1

⊕ x2 ⊕ x12 ⊕ x22 ⊕ 2

.P1 P1 P2 P2

.2x 1

⊕ x12 ⊕ x22 ⊕ 1

.P2

.2x 2

⊕ x12 ⊕ x22 ⊕ 1

.P1

.2x 1

⊕ x2 ⊕ x12 ⊕ x22 ⊕ 2

.P1 P1 P2

⊕ 2x2 ⊕ x12 ⊕ x22 ⊕ 2

.P1 P2 P2

.x1

.2x 1

⊕ 2x2 ⊕ x12 ⊕ x22 ⊕ 2

.P1 P2

.2x 1 x 2

⊕ x12 ⊕ 2x22

.P2,2

.2x 1 x 2

⊕ x1 ⊕ x12 ⊕ 2x22 ⊕ 2

.P1 P2 P2,2

.2x 1 x 2

⊕ x2 ⊕ x12 ⊕ 2x22 ⊕ 1

.P1 P1 P2 P2,2

.2x 1 x 2

⊕ 2x1 ⊕ x12 ⊕ 2x22 ⊕ 2

.P1 P1 P2 P2,2

.2x 1 x 2

⊕ 2x2 ⊕ x12 ⊕ 2x22 ⊕ 1

.P1 P2 P2 P2,2

.2x 1 x 2

⊕ x1 ⊕ x2 ⊕ x12 ⊕ 2x22 ⊕ 1

.P2 P2 P2,2

.2x 1 x 2

⊕ 2x1 ⊕ x2 ⊕ x12 ⊕ 2x22 ⊕ 2

.P1 P2,2

.2x 1 x 2

⊕ x1 ⊕ 2x2 ⊕ x12 ⊕ 2x22 ⊕ 2

.P1 P1 P2,2

.2x 1 x 2

⊕ 2x1 ⊕ 2x2 ⊕ x12 ⊕ 2x22 ⊕ 1

.P2 P2,2

.2x 1 x 2

⊕ 2x12 ⊕ x22

.P1,2

.2x 1 x 2

⊕ x1 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P2 P2 P1,2

.2x 1 x 2

⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 2

.P1 P2 P1,2

.2x 1 x 2

⊕ 2x1 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P1 P2 P1,2

.2x 1 x 2

⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 2

.P1 P1 P2 P2 P1,2

.2x 1 x 2

⊕ x1 ⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P1 P1,2

.2x 1 x 2

⊕ 2x1 ⊕ x2 ⊕ 2x12 ⊕ x22 ⊕ 2

.P2 P2 P1,2

.2x 1 x 2

⊕ x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 2

.P2 P1,2

.2x 1 x 2

⊕ 2x1 ⊕ 2x2 ⊕ 2x12 ⊕ x22 ⊕ 1

.P1 P1,2

Algorithm 8.2 (Permuting matrices) 1. Select the distribution . D1 or . D2 . 2. Select the basis function . f 1 or . f 2 . 3. Apply to the function vector of the selected function the permutation matrices corresponding to terms that are allowed to be added while preserving bentness. 4. Perform an encoding of the function values. With respect to Step .3 of the above algorithm, notice that for all included permutation matrices .P3 = I(2), where .I(2) is a .(9 × 9) identity matrix, which preserves that the same matrix can be applied no more than two times. That is the maximal number of applications of a matrix in the above tables.

250

8 Construction of Bent Functions by FFT-like Permutation Matrices

Recall that in the case of binary bent functions, studied are permutations with the property P2 = I due to which they are called involutions [19, 20]. In the generalization of the method to functions with more than two variables, basic bent functions to which permutation matrices are applied should be selected such that their degree is equal to the degree of functions to be produced.

.

8.9

Generalizations

The methods for constructing bent functions by FFT-like permutation matrices discussed in the previous sections can be generalized to functions in any number of variables. It should be taken into account that the permutation matrices can construct functions with the same compositions. In the case of ternary functions, it should be recalled that for the number of variables .n = 2, 6, 10, 14, there are functions with two possible compositions. Functions with the same composition can be constructed by FFT-like permutation matrices. Therefore, the set of all ternary bent functions for a given number of variables can be split into .6 classes corresponding to six possible permutations of three-valued sets. The functions in a class share the same composition and can be converted to each other by permutation matrices. Functions from a class can be converted into functions in another class, i.e., with another composition by encoding. The corresponding permutation matrices can be derived by referring to the structure of the matrices describing steps of Cooley–Tukey FFT. These matrices have the Kronecker product structure, and the matrix describing the .i-th step has the basic transform matrix at the .i-th position, while at all other positions are the identity matrices. The main idea in deriving FFT-like permutation matrices for any number of variables is to replace the basic transform matrix at the .i-th position in the Kronecker product by some of the basic permutation matrices in (8.1). We define different FFT-like permutation matrices by referring to matrices describing steps in Cooley–Tukey FFT and replacing the basic transform matrices by the basic permutation matrices. Consider the matrix .Q1 , and define three FFT-like permutation matrices as R1 = Q(1) ⊗ I1 ⊗ I(1),

.

R2 = I1 ⊗ Q(1) ⊗ I(1), R3 = I(1) ⊗ I(1) ⊗ Q1 . Again, the resemblance with FFT is that the basic transform matrix is replaced by the basic permutation matrix. It is also possible to simultaneously apply the same or different basic permutation matrices as component matrices in the Kronecker product of .n matrices. In this way, a number of different FFT-like permutation matrices is defined.

8.9

Generalizations

251

Table 8.15 Functions obtained from .q1 by permutation matrices .R1 , .R2 , .R3 Function

Matrix

.x1 x2

⊕ (x3 )2 ⊕ x1

.R1

.x1 x2

⊕ (x3 )2 ⊕ x2

.R2

.x1 x2

⊕ (x3 )2 ⊕ 2x3 ⊕ 1

.R3

These matrices add the linear terms .x1 , .x2 , .2x3 ⊕ 1, respectively, to the function .q1 = x1 x2 ⊕ x32 . These terms determine the indices in the matrices considered (Table 8.15). The function . f = x1 x2 ⊕ x32 ⊕ x3 is also bent; however, its function vector is F = [0, 2, 0, 0, 2, 0, 0, 2, 0, 0, 2, 0, 1, 0, 1, 2, 1, 2, 0, 2, 0, 2, 1, 2, 1, 0, 1]T .

.

We see that this is a different composition .(12, 6, 9); therefore, it belongs to a different class and cannot be obtained by a permutation of function values in .q1 = x1 x2 ⊕ x32 , but by encoding. The matrices for adding quadratic terms are constructed as R1 = A ⊗ B ⊗ I(1), R4 = B ⊗ A ⊗ I(1),

.

R2 = A ⊗ I(1) ⊗ B, R5 = B ⊗ I(1) ⊗ A, R3 = I(1) ⊗ A ⊗ B, R6 = I(1) ⊗ B ⊗ A, followed by the replacement of their elements by .1 and .0 as specified in Sect. 8.7.5. Depending on the functions to which they are applied, .q1 or .q2 , these matrices add terms 2 2 2 . x , . x , and . x possibly combined with variables. In all the cases, coefficients in the added 1 2 3 terms can be either .1 or .2, which increases the number of new bent functions that can be constructed. Table 8.16 shows ternary bent functions derived from the function .q1 = x1 x2 ⊕ x32 with the composition .(9, 12, 6). Table 8.17 shows bent functions derived from the function .q2 = x12 ⊕ x22 ⊕ x32 with the composition .(9, 6, 12). The matrix which expresses adding the term of order three .x12 x3 to the function .q1 = x1 x2 ⊕ x32 is defined as P3 = diag(I(1) ⊗ I(1), X1 ⊗ X1 , X1T ⊗ X1 ).

.

The structure of this matrix is typical for the .(n − 1)-th step in Cooley–Tukey FFT algorithms. The function vector of . f = x1 x2 ⊕ x32 ⊕ x12 x3 is F3 = [0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 2, 0, 1, 0, 1, 2, 1, 2, 0, 2, 0, 2, 1, 2, 1, 0, 1]T .

.

252

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.16 Construction of ternary bent functions by permutation matrices from .q1 with the composition .(9, 12, 6) Function

Permutation matrices

. x 1 x 2 ⊕ x 2 ⊕ (x 1 )2 3

.P1,2

⊗ I(1)

.[0, 1, 1, 0, 1, 1, 0, 1, 1, 1, 2, 2, 2, 0, 0, 0, 1, 1, 1, 2,

2, 0, 1, 1, 2, 0, 0]T

.x1 x2

⊕ x32 ⊕ x22 ⊕ 2x2 x3

.I(1) ⊗ P1,2

.[0, 1, 1, 1, 1, 0, 1, 0, 1, 0, 1, 1, 2, 2, 1, 0,

2, 0, 0, 1, 1, 0, 0, 2, 2, 1, 2]T

.x1 x2

⊕ x32 ⊕ x22

.P2,2

⊗ I(1)

.[0, 1, 1, 1, 2, 2, 1, 2, 2, 0, 1, 1, 2, 0, 0, 0,

1, 1, 0, 1, 1, 0, 1, 1, 2, 0, 0]T

.x1 x2

⊕ x32 ⊕ x1 x3

.I(1) ⊗ P2,2

.[0, 1, 1, 0, 1, 1, 0, 1, 1, 0, 2, 0, 1, 0, 1,

2, 1, 2, 0, 0, 2, 2, 2, 1, 1, 1, 0]T

Table 8.17 Construction of ternary bent functions by permutation matrices from .q2 with the composition .(9, 6, 12) Function

Permutation matrices

.2x 2 ⊕ x 2 ⊕ x 2 ⊕ 2x 1 x 2 1 2 3

.P1,2

⊗ I(1)

.[0, 1, 1, 1, 2, 2, 1, 2, 2, 2, 0, 0, 2, 0, 0, 1, 2, 2,

2, 0, 0, 1, 2, 2, 2, 0, 0]T

.x 2

2 2 1 ⊕ 2x 2 ⊕ x 3 ⊕ 2x 2 x 3

.I(1) ⊗ P1,2

.[0, 1, 1, 2, 2, 1, 2, 1, 2, 1, 2, 2, 0, 0, 2, 0, 2, 0,

1, 2, 2, 0, 0, 2, 0, 2, 0]T

.x 2

2 2 1 ⊕ 2x 2 ⊕ x 3 ⊕ 2x 1 x 2

.P2,2

⊗ I(1)

.[0, 1, 1, 2, 0, 0, 2, 0, 0, 1, 2, 2, 2, 0, 0, 1, 2, 2,

1, 2, 2, 1, 2, 2, 2, 0, 0]T

.x 2

2 2 1 ⊕ x 2 ⊕ 2x 3 ⊕ 2x 2 x 3

.I(1) ⊗ P2,2

.[0, 2, 2, 1, 2, 1, 1, 1, 2, 1, 0, 0, 2, 0, 2, 2, 2, 0, 1,

0, 0, 2, 0, 2, 2, 2, 0]T

The composition is .(9, 12, 6). The same function vector can be obtained as F3 = P3 Fx1 x2 ⊕x 2 .

.

3

8.9.1

Permutation of Subvectors

In [2] is proposed another approach for constructing ternary bent functions with selected distribution and degree. The basic idea is to split the function vector into subvectors, and

8.9

Generalizations

253

then permute these subvectors as well as elements in them to construct other bent functions. This can be performed by the following algorithm. Algorithm 8.3 (Permuting subvectors) 1. Given are a bent function . f with the distribution . D and the degree .deg( f ). 2. Split the function vector .F of . f into subvectors of length .3k , .1 ≤ k ≤ n − 1. 3. Perform encoding of subvectors and construct a new function vector .Fe whose elements are symbols assigned to the subvectors. 4. Apply an FFT-like permutation matrix .R to .Fe and produce a new bent function . f e . 5. Apply the FFT-like permutation matrix .R to the subvectors and produce another bent function . f e,R . Conversion of performing permutations over subvectors instead over the complete function vector is aimed at making the procedure convenient for implementation on parallel hardware structures. It should be noticed that the choice of the parameter .k determines which step of the FFT-like permutation algorithm is actually performed. This at the same time defines in terms of which variable the spectral invariant operation corresponding to the matrix .R is performed. The choice of the matrix used to perform the permutation determines which spectral invariant operation is performed. Therefore, in this algorithm there is a possibility to select both spectral invariant operations to be performed and variables to which these operations are applied. Different spectral invariant operations can be performed on the selected variables or subsets of variables. Example 8.24 The ternary function in three variables .

f (x1 , x2 , x3 ) = x1 x2 ⊕ x32 ⊕ x22 x32

is a bent function of degree .4. Its function vector is F = [0, 1, 1, 0, 2, 2, 0, 2, 2, 0, 1, 1, 1, 0, 0, 2, 1, 1, 0, 1, 1, 2, 1, 1, 1, 0, 0]T .

.

The distribution of function values is .(9, 12, 6). We split this function vector into three subvectors of .9 elements as K0 = [0, 1, 1, 0, 2, 2, 0, 2, 2]T ,

.

K1 = [0, 1, 1, 1, 0, 0, 2, 1, 1]T , K2 = [0, 1, 1, 2, 1, 1, 1, 0, 0]T . With this notation, it is F = [K0 , K1 , K2 ]T .

.

254

8 Construction of Bent Functions by FFT-like Permutation Matrices

Table 8.18 Spectral invariant operations performed by the basic permutation matrices Matrix

Reordering

.Q1

.F Q 1

= [K1 , K0 , K2 ]T

.x1

→ 2x1 ⊕ 1

.Q2

.F Q 2

.x1

→ 2x1

.X1

.F X 1

T .X 1

.F

.N1

.F N1

= [K0 , K2 , K1 ]T = [K2 , K0 , K1 ]T = [K1 , K2 , K0 ]T = [K2 , K1 , K0 ]T

X 1T

Substitution

→ x1 ⊕ 2 .x1 → x1 ⊕ 1 .x1

.x1

→ 2x1 ⊕ 2

The application of . Q 1 converts .F into F Q 1 = [K1 , K0 , K2 ]T ,

.

which is F Q 1 = [0, 1, 1, 1, 0, 0, 2, 1, 1, 0, 1, 1, 0, 2, 2, 0, 2, 2, 0, 1, 1, 2, 1, 1, 1, 0, 0]T .

.

The corresponding function expression is .

f (x1 , x2 , x3 ) Q 1 = x32 ⊕ x2 ⊕ x22 x32 ⊕ 2x1 x2 ,

and it can obtained by the spectral invariant operation .x1 → 2x1 ⊕ 1. Thus, the matrix .Q1 applied to subvectors of length .9 performs this spectral invariant operation as the example illustrates. The constructed function is bent, and to the initial function the terms .x2 and .x1 x2 are added. Table 8.18 shows the reordering of subvectors produced by the application of matrices.Q1 , T .Q2 , .X1 , .X , and .N1 , the functional expressions of resulting functions, and the corresponding 1 spectral invariant operations. Table 8.19 shows the functions obtained by the application of these permutation matrices.

Table 8.19 Bent functions constructed by the basic permutation matrices from the function . f in Example 8.24 Matrix

Function

.Q1

.

.Q2

f (x1 , x2 , x3 ) Q 1 = x32 ⊕ x2 ⊕ x22 x32 ⊕ 2x1 x2 2 2 2 . f (x 1 , x 2 , x 3 ) Q 2 = x ⊕ x x ⊕ 2x 1 x 2 3 2 3

.X1

.

T .X 1

f (x1 , x2 , x3 ) X 1 = x32 ⊕ 2x2 ⊕ x22 x32 ⊕ x1 x2 2 2 2 . f (x 1 , x 2 , x 3 ) T = x ⊕ x 2 ⊕ x x ⊕ x 1 x 2 3 2 3 X

.N1

.

1

f (x1 , x2 , x3 ) N1 = x32 ⊕ 2x2 ⊕ x22 x32 ⊕ 2x1 x2

8.10

Gibbs and FFT-like Permutation Matrices for Ternary Functions

255

From the structure of FFT-like algorithms for the Vilenkin–Chrestenson transform of ternary functions, it is easy to see that the application of the considered .(3 × 3) matrices to subvectors of length .9 is equivalent to multiplication of .F with the matrix M ⊗ I(1) ⊗ I(1)

.

where .M is any of the considered matrices. In other words, it is equivalent to performing the permutation corresponding to the first step of the FFT-like algorithm. Due to this, the performed spectral invariant operations are with respect to the first variable .x1 . Performing the permutations corresponding to the .i-th step results in the spectral invariant operations with respect to the .i-th variable .xi , .i ∈ {1, 2, . . . , n}. When to the function is obtained by the application of .Q(2), we apply the same transformation to subvectors of length .9, and we get the function . f Q 2 with the function vector F Q 2 = [0, 1, 1, 0, 2, 2, 0, 2, 2, 0, 1, 1, 2, 1, 1, 1, 0, 0, 0, 1, 1, 1, 0, 0, 2, 1, 1]T ,

.

and the functional expression as .

f Q 2 = x32 ⊕ x22 x32 ⊕ 2x1 x2

which is bent and it is obtained by the successive application of the spectral invariant operations .x1 → x1 ⊕ 2 and .x2 → x2 ⊕ 2. Compared to the initial function, the term .x1 x2 is added.

8.10

Gibbs and FFT-like Permutation Matrices for Ternary Functions

It is important to notice a difference between the FFT-like permutation matrices for constructing ternary bent functions [1] and the Gibbs permutation matrices defined above. The essential difference is that compared to FFT-like permutation matrices, the Gibbs permutation matrices perform different spectral invariant operations as it can be seen from Tables 4.11 and 8.18. A Gibbs permutation matrix performs at the same time a pair of spectral invariant operations, permutation of variables followed by the polarization of variables. An FFT-like permutation matrix performs either polarization of variables or disjoint spectral translation, but not both at the same time. If we want to perform a pair of these spectral invariant operations by FFT-like permutation matrices, we have to make a combination of the basic FFT-like permutation matrices in the Kronecker product defining the corresponding FFT-like permutation matrix. The FFT-like permutation matrices in any case do not perform permutation of variables. Therefore, the sets of these two types of permutation matrices for a given .n neither overlap nor intersect, but rather complement each other in the sense that they enrich the set of spectral invariant operations performable by the permutation matrices.

256

8 Construction of Bent Functions by FFT-like Permutation Matrices

References 1. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of ternary bent functions by FFT-like permutation algorithms. In: Proceedings of The 50th International Symposium on Multiple-Valued Logic, Miyazaki, Japan, 9–11 Nov. 2020 2. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of ternary bent functions by FFT-like permutation algorithms. IEICE Trans. Inf. Syst. E104-D(8), 1092–1102 (2021) 3. Cooley, J.W., Tukey, J.W.: An algorithms for the machine calculation of complex Fourier series. Math. Comput. 19, 297–301 (1965) 4. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of binary bent functions by FFT-like permutation algorithms. In: Proceedings of the 14th International Workshop on Boolean Problems, Bremen, Germany, 24–25 Sept. 2020 5. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of binary bent functions by FFT-like permutation algorithms. In: Drechsler, R., Grosse, D., (eds.), Recent Findings in Boolean Techniques, Selected Papers from the 14th International Workshop on Boolean Problems, 105– 124. Springer (2021). ISBN 978-3-030-68070-1, eBook ISBN 978-3-030-68071-8 6. Good, I.J.: The interaction algorithm and practical Fourier analysis. J. Roy. Statist. Soc. Ser. B 20, 361–372. Addendum 22(1960), 372–375 (1958) 7. Good, I.J.: The relationship between two fast Fourier transforms. IEEE Trans. Comput. C-20, 310–317 (1971) 8. Thomas, L.H.: Using a computer to solve problems in physics. In: Application of Digital Computers, Boston, MA, Ginn (1963) 9. Hurst, S.L.: Logical Processing of Digital Signals. Crane Russak and Edward Arnold, London, Basel (1978) 10. Hurst, S.L., Miller, D.M., Muzio, J.C.: Spectral Techniques in Digital Logic. Academic Press, Bristol (1985) 11. Nechiporuk, E.I.: On the synthesis of gate networks. Problemy Kibernetiki, No. 9 (1963) (in Russian) 12. Astola, J., Astola, P., Stankovi´c, R.S., Tabus, I.: An algebraic approach to reducing the number of variables of incompletely defined discrete functions. In: Proceedings of the 46th International Symposium on Multiple-Valued Logic, Sapporo, Japan, May 17–19, 107–112 (2016) 13. Astola, H., Stankovi´c, R.S., Astola, J.T.: Index generation functions based on linear and polynomial transformations. In: Proceedings of the 46th International Symposium on Multiple-Valued Logic, Sapporo, Japan, 102–106, 17–19 May 2016 14. Astola, J.T., Astola, P., Stankovi´c, R.S., Tabus, I.: Algebraic and combinatorial methods for reducing the number of variables of partially defined discrete functions. In: Proceedings of the 47th International Symposium on Multiple-Valued Logic, 22–24, Novi Sad, Serbia, May 2017, 167–172 15. Sasao, T.: Index Generation Functions. Morgan and Calypool Publishers (2019) 16. Karpovsky, M.G., Stankovi´c, R.S., Astola, J.T.: Spectral Logic and Its Application in the Design of Digital Devices. Wiley (2008) 17. Nussbaumer, H.J.: Fast Fourier Transform and Convolution Algorithms. Springer, Berlin (1981) 18. Stoji´c, M.R., Stankovi´c, M.S. Stankovi´c, R.S.: Discrete Transforms in Applications. In: knjiga, N., Belgrade, 1st edn. 1983, Nauka, B. 2nd edn. 1993, 245 pages. ISBN 86-7621-019 (in Serbian). 1st and 2dn eds. 1983, 1993, Nauka, B., 245 pages, ISBN 86-7621-019 (in Serbian). Nauka, B. 1993, ISBN 86-7621-019 (in Serbian) 19. Luo, G., Cao, X., Mesnager, S.: Several new classes of self-dual bent functions derived from involutions. In: Cryptography and Communications, Published online 17 May 2019, Springer

References

257

Science+Business Media, LLC, part of Springer Nature 2019, 13 pages. https://doi.org/10.1007/ s12095-019-00371-917, May 2019, https://doi.org/10.1007/s12095-019-00371-9 20. Mesnager, S.: On constructions of bent functions from involutions. In: Proceedings of International Symposium on Information Theory (ISIT), Barcelona, Spain, 110–114, 10–15 July 2016

9

Construction of Ternary Bent Functions From Matrix Representations

Functions in a large number of variables necessarily require large function vectors to be represented. For a . p-valued function, such a vector of length . p n can be split into subvectors of equal size . p n−k for various values of .k which can be arranged as either rows or columns of a matrix. Sometimes, such matrices can be viewed as a more suitable data structure for manipulating and computing with given functions. Another possibility is to convert a number-valued function vector into a shorter matrix-valued vector as discussed in Chaps. 6 and 7. In this chapter, we discuss how such data structures can be used to construct other bent functions by manipulating the given functions.

9.1

Matrix Representations of Ternary Bent Functions

Transposition of a matrix means permuting of its row and column indices. If the matrix is built from the function vector of a bent function, then the transposition induces a permutation of the arguments of the function, which is a spectral invariant operation and ensures that bentness is preserved. From there, the following procedure immediately follows. For a ternary bent function, we represent the number of variables as .n = k + r where k r .k = 1, 2, . . . , (n − 1), and .r = n − k. Then, we rewrite its function vector .F as .(3 × 3 ) k matrices .Q for different values of .k by writing subvectors of length .3 as rows of .Q. If we take the transpose matrix of .Q for a value of .k, and concatenate its rows, the obtained function is also bent. The reason is that the transposition corresponds to the permutation of variables defined as the cyclic shift for .(n − k) positions to the left. Example 9.1 Consider a ternary function of .n = 3 variables. For simplicity, we write just indices of elements in its function vector © The Author(s), under exclusive license to Springer Nature Switzerland AG 2024 R. S. Stankovi´c et al., Bent Functions and Permutation Methods, Synthesis Lectures on Engineering, Science, and Technology, https://doi.org/10.1007/978-3-031-50650-5_9

259

260

9 Construction of Ternary Bent Functions From Matrix Representations

F = [0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15,

.

16, 1, 18, 19, 20, 21, 22, 23, 24, 25, 26]T . We write this function vector as a .(9 × 3) matrix ⎡

0 ⎢ 3 ⎢ ⎢ 6 ⎢ ⎢ 9 ⎢ ⎢ . ⎢ 12 ⎢ ⎢ 15 ⎢ ⎢ 18 ⎢ ⎣ 21 24

1 4 7 10 13 16 19 22 25

⎤ 2 5 ⎥ ⎥ 8 ⎥ ⎥ 11 ⎥ ⎥ ⎥ 14 ⎥ . ⎥ 17 ⎥ ⎥ 20 ⎥ ⎥ 23 ⎦ 26

The transpose .(3 × 9) matrix is ⎡

⎤ 0 3 6 9 12 15 18 21 24 . ⎣ 1 4 7 10 13 16 19 22 25 ⎦ . 2 5 8 11 14 17 20 23 26 By concatenating the rows of this matrix, we obtain the function vector Fnew = [0, 3, 6, 9, 12, 15, 18, 21, 24, 1, 4, 7, 10, 13, 16, 19,

.

22, 25, 2, 5, 8, 11, 14, 17, 20, 23, 26]T . This is the vector which corresponds to the permutation of variables .x1 x2 x3 → x2 x3 x1 . If we first convert .F into a .(3 × 9) matrix, ⎡

⎤ 0 1 2 3 4 5 6 7 8 . ⎣ 9 10 11 12 13 14 15 16 17 ⎦ 18 19 20 21 22 23 24 25 26 the transposition of it will produce the .(9 × 3) matrix ⎡

0 ⎢1 ⎢ ⎢2 ⎢ ⎢3 ⎢ ⎢ .⎢4 ⎢ ⎢5 ⎢ ⎢6 ⎢ ⎣7 8

9 10 11 12 13 14 15 16 17

⎤ 18 19 ⎥ ⎥ 20 ⎥ ⎥ 21 ⎥ ⎥ ⎥ 22 ⎥ . ⎥ 23 ⎥ ⎥ 24 ⎥ ⎥ 25 ⎦ 26

9.1

Matrix Representations of Ternary Bent Functions

261

Concatenation of rows of this matrix produces the vector Fnew = [0, 9, 18, 1, 10, 19, 2, 11, 20, 3, 12, 21, 4, 13, 22, 5,

.

14, 23, 6, 15, 24, 7, 16, 25, 8, 17, 26]T , which corresponds to the permutation of variables .x1 x2 x3 → x3 x1 x2 . It follows that we obtain other bent functions for different values of .k. The dimensions of rows and columns can be mutually exchanged which produces further possibilities for other bent functions. The method can be applied to bent functions in any number of variables and independently of their degree. Example 9.2 Consider the bent function in four variables of degree four . f = x1 x3 ⊕ x2 x4 ⊕ x22 x32 ⊕ x4 . Its function vector is F = [0, 1, 2, 0, 1, 2, 0, 1, 2|0, 2, 1, 1, 0, 2, 1, 0, 2|0, 0, 0, 1, 1, 1, 1, 1, 1|

.

0, 1, 2, 1, 2, 0, 2, 0, 1|0, 2, 1, 2, 1, 0, 0, 2, 1|0, 0, 0, 2, 2, 2, 0, 0, 0| 0, 1, 2, 2, 0, 1, 1, 2, 0|0, 2, 1, 0, 2, 1, 2, 1, 0|0, 0, 0, 0, 0, 0, 2, 2, 2]T . For .k = 2, it is .r = 2 and we convert this function into the .(32 × 32 ) matrix ⎡

0 ⎢0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎢ .Q = ⎢ 0 ⎢ ⎢0 ⎢ ⎢0 ⎢ ⎣0 0

1 2 0 1 2 0 1 2 0

2 1 0 2 1 0 2 1 0

0 1 1 1 2 2 2 0 0

1 0 1 2 1 2 0 2 0

2 2 1 0 0 2 1 1 0

0 1 1 2 0 0 1 2 2

1 0 1 0 2 0 2 1 2

⎤ 2 2⎥ ⎥ 1⎥ ⎥ 1⎥ ⎥ ⎥ 1⎥. ⎥ 0⎥ ⎥ 0⎥ ⎥ 0⎦ 2

We write the transpose of this matrix, and by concatenating the rows of .QT , we obtain the function vector F1 = [0, 0, 0, 0, 0, 0, 0, 0, 0|1, 2, 0, 1, 2, 0, 1, 2, 0|2, 1, 0, 2, 1, 0, 2, 1, 0|

.

0, 1, 1, 1, 2, 2, 2, 0, 0|1, 0, 1, 2, 1, 2, 0, 2, 0|2, 2, 1, 0, 0, 2, 1, 1, 0| 0, 1, 1, 2, 0, 0, 1, 2, 2|1, 0, 1, 0, 2, 0, 2, 1, 2|2, 2, 1, 1, 0, 0, 0, 0, 2]T of the function .

f 1 = x1 x3 ⊕ x2 x4 ⊕ x12 x42 ⊕ x2 ,

262

9 Construction of Ternary Bent Functions From Matrix Representations

which is also bent. This function corresponds to the cyclic shift of variables in . f for .r = 2 places to the left. Thus, .x1 , x2 , x3 , x4 → x3 , x4 , x1 , x2 . If the initial function . f is converted into a .(27 × 3) matrix, and its transpose determined, the produced bent function has the functional expression as .

f 2 = x32 x2 ⊕ x2 x4 ⊕ x1 ⊕ x1 x3 .

This function corresponds to the shift of variables in . f for .r = 1 places to the left. Thus, x1 , x2 , x3 , x4 → x2 , x3 , x4 , x1 . The matrix .(3 × 27) produces the function with the functional expression

.

.

f 3 = x3 ⊕ x2 x4 ⊕ x1 x3 ⊕ x12 x22 .

This function corresponds to the shift of variables in . f for .r = 3 places to the left. Thus, x1 , x2 , x3 , x4 → x4 , x1 , x2 , x3 .

.

For further examples, we refer to [1]. Example 9.3 Consider the function in .6 variables .

f = x1 x6 ⊕ x2 x4 ⊕ x3 x5 ⊕ x12 x42 x5 ⊕ x3 .

It is clear that this function is of degree .5 as determined by the product term .x12 x42 x5 , and by computing its Vilenkin–Chrestenson spectrum, after its complex encoding, it can be determined that it is bent. The function vector is of length .36 = 729, and can be converted into matrices of the dimensions .(27 × 27), .(9 × 81), .(3 × 243), .(81 × 9), .(243 × 3). After transposition and re-converting into function vectors, these matrices produce, respectively, five bent functions as in Table 9.1. These functions correspond to the cyclic shift of variables for .r = n − k places to the left. Therefore, the cyclic shift is for .3, 4, 5, 2, 1 places to the left. There are .3n linear ternary functions to which any of two constants .1 and .2 can be added to get affine ternary functions. We can add .3n+1 = 37 affine functions in .6 variables to any of these bent functions and in this way obtain more bent functions [2]. The following examples borrowed from [1] illustrate that depending on the initial bent function, the number of produced bent functions is not necessarily equal to the number of possible matrices of different dimensions to be transposed. In certain cases, transposition of matrices of different dimensions might produce the same bent functions or functions equal to the initial functions.

9.1

Matrix Representations of Ternary Bent Functions

263

Table 9.1 Matrices of different dimensions and corresponding bent functions by their transposition Matrix

Function

.(9

× 81)

f 1 = x6 ⊕ x3 x4 ⊕ x2 x6 ⊕ x1 x5 ⊕ x12 x2 x42 2 2 . f 2 = x4 x5 ⊕ x2 x6 ⊕ x x3 x ⊕ x1 ⊕ x1 x3 2 5

.(3

× 243)

.

.(27

.(81

× 27)

.

f 3 = x5 x6 ⊕ x22 x3 x62 ⊕ x2 ⊕ x2 x4 ⊕ x1 x3 2 2 . f 4 = x5 ⊕ x4 x6 ⊕ x2 x3 ⊕ x1 x5 ⊕ x1 x x 3 6

× 9)

.(243

× 3)

.

f 5 = x4 ⊕ x4 x6 ⊕ x3 x5 ⊕ x22 x52 x6 ⊕ x1 x2

Example 9.4 Consider the function represented as a sum of disjoint product of variables .

f = x1 x2 ⊕ x3 x4 ⊕ x5 x6 .

This function is often considered as the basic bent function in .6 variables for the distribution . D = (225, 252, 252). The conversion into a .(27 × 27) matrix and transposition of it produces .

f new,27 = x4 x5 ⊕ x2 x3 ⊕ x1 x6 .

The .(9 × 81) matrix after transposition produces the initial function . f . The .(3 × 243) matrix after transposition produces the function equal to that obtained from the .(27 × 27) matrix. Example 9.5 [1] The function represented by the sum of squares of variables .

f = x12 ⊕ x22 ⊕ x32 ⊕ x42 ⊕ x52 ⊕ x62 ,

is often considered as the basic bent function in .6 variables for the distribution . D = (261, 234, 234). Any of the three possible matrices after transposition produces the initial function . f . This is due to the fact that . f is symmetric. The above examples actually present a procedure for constructing bent functions by manipulating a given bent function which can be formalized into an algorithm as follows [1]. Algorithm 9.1 (Constructing bent functions by transposition)

1. Given is a ternary bent function in .n variables specified as a function vector .F of length n .3 . 2. Split .F into subvectors of length .3k , for .k = 1, 2, . . . , (n − 1).

264

3. 4. 5. 6.

9 Construction of Ternary Bent Functions From Matrix Representations

Write the subvectors in Step .2 as rows of a .(3k × 3n−k ) matrix .Q. Determine .QT , the transpose of .Q. Concatenate rows of .QT to produce the function vector of a bent function . f new . Check if the constructed function already exists in the list of obtained functions for different parameters .k and .r . If .Y es, return to Step .2, if . N o add . f new to the list, and then return to Step .2.

As noticed above, in certain cases, depending on the patterns in the function vector of the initial function, the functions produced by the transposition for certain choices of .k and .r might be identical to either the initial function or to the functions obtained for different choices of the parameters, as can be seen in Examples 9.4 and 9.5. In such cases, another approach presented in the next section based on matrix-valued equivalents of bent functions can be tried. Transposition of matrices is an operation widely used in many computing and related application-oriented algorithms, and its implementation is well studied including hardware realizations. For an example of such circuits for transposition of matrices, we refer to Example .6.14 in [3]. The algorithm presented above immediately implies a challenging task of designing hardware for construction of ternary bent functions. If based on this algorithm, the required hardware reduces to a circuit performing the transposition of matrices. The circuit should be a reconfigurable circuit in order to accommodate different choices for the parameters .k and .r .

9.2

Construction of Ternary Bent Functions from Matrix-Valued Ternary Bent Functions

In this section, we use the matrix-valued equivalents of bent functions discussed in Chap. 7 as a basis to construct bent functions from the given bent functions. We split the function vector into subvectors of length .3k , for .k = 1, 2, . . . , [(n − 1)/2], where .[a] is the smallest integer greater or equal to .a, and write them as .(3k × 3k ) matrices. In this way, the function vector .F of length .3n is converted into a matrix-valued equivalent function vector of .r = 3n−2k elements. A function vector is reconstructed from the matrixvalued equivalent by concatenating the rows of its elements starting from the first element and by processing elements successively. It means that we first concatenate the rows of the first element, then the rows of the second element, and continue in the same way. Table 9.2 shows the possible dimensions and the number of matrix-valued elements for .n = 2, 3, 4, 5, 6, 7, 8. For simplicity, the considerations and examples in this section are given for .k = 1, i.e., the matrix-valued elements of function vectors are .(3 × 3) matrices. All the statements and observations are valid for other possible decompositions.

9.2

Construction of Ternary Bent Functions from Matrix …

265

Table 9.2 Possible decompositions of function vectors into matrix-valued elements .n

.2

.3

.4

.5

.6

.7

.8

.k

.1

.1

.1, 2

.1, 2

.1, 2, 3

.1, 2, 3

.1, 2, 3, 4

.r

.1

.3

.9, 1

.27, 3

.81, 9, 1

.243, 27, 3

.739, 81, 9, 1

Remark 9.1 For a matrix-valued equivalent of a bent function for all the choices of parameters .k and .r , the determinant of matrix-valued elements is equal to .0. Example 9.6 Consider function . f a (x1 , x2 , x3 , x4 ) = x1 x2 ⊕ x3 x4 ⊕ x12 x42 whose function vector is Fa = [0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1, |

.

0, 1, 1, 0, 2, 0, 0, 0, 2, |1, 2, 2, 1, 0, 1, 1, 1, 0, |2, 0, 0, 2, 1, 2, 2, 2, 1, | 0, 1, 1, 0, 2, 0, 0, 0, 2, |2, 0, 0, 2, 1, 2, 2, 2, 1, |1, 2, 2, 1, 0, 1, 1, 1, 0]T . We write its function vector into the form of a vector of .9 elements whose entries are (3 × 3) matrices obtained by arranging triples of successive elements into rows of these matrices. Thus, this function is represented as

.

Fa = [a0 , a1 , a2 , a3 , a4 , a5 , a6 , a7 , a8 ]T ,

.

where ⎡

0 .a0 = ⎣ 0 0 ⎡ 0 a3 = ⎣ 0 0 ⎡ 0 a6 = ⎣ 0 0

0 1 2 1 2 0 1 2 0

⎡ ⎡ ⎤ ⎤ ⎤ 0 000 000 2 ⎦ , a1 = ⎣ 0 1 2 ⎦ , a2 = ⎣ 0 1 2 ⎦ , 1 021 021 ⎡ ⎡ ⎤ ⎤ ⎤ 1 122 200 0 ⎦ , a4 = ⎣ 1 0 1 ⎦ , a5 = ⎣ 2 1 2 ⎦ , 2 110 221 ⎤ ⎤ ⎤ ⎡ ⎡ 1 200 122 0 ⎦ , a7 = ⎣ 2 1 2 ⎦ , a8 = ⎣ 1 0 1 ⎦ . 2 221 110

We determine a matrix-valued function with elements obtained as .vi = Q1 ai , where .Q1 is the basic permutation matrix. Therefore, Fv = [v0 , v1 , v2 , v3 , v4 , v5 , v6 , v7 , v8 ]T ,

.

where

266

9 Construction of Ternary Bent Functions From Matrix Representations



0 .v0 = ⎣ 0 0 ⎡ 0 ⎣ v3 = 0 0 ⎡ 0 v6 = ⎣ 0 0

1 0 2 2 1 0 2 1 0

⎡ ⎡ ⎤ ⎤ ⎤ 2 012 012 0 ⎦ , v1 = ⎣ 0 0 0 ⎦ , v2 = ⎣ 0 0 0 ⎦ , 1 021 021 ⎡ ⎡ ⎤ ⎤ ⎤ 0 101 212 1 ⎦ , v4 = ⎣ 1 2 2 ⎦ , v5 = ⎣ 2 0 0 ⎦ , 2 110 221 ⎡ ⎡ ⎤ ⎤ ⎤ 0 212 101 1 ⎦ , v7 = ⎣ 2 0 0 ⎦ , v8 = ⎣ 1 2 2 ⎦ . 2 221 110

This matrix-valued function defines, after concatenating the rows of matrix-valued elements, a function . f v with the function vector Fv = [0, 1, 2, 0, 0, 0, 0, 2, 1|0, 1, 2, 0, 0, 0, 0, 2, 1|0, 1, 2, 0, 0, 0, 0, 2, 1|

.

0, 2, 0, 0, 1, 1, 0, 0, 2|1, 0, 1, 1, 2, 2, 1, 1, 0|2, 1, 2, 2, 0, 0, 2, 2, 1| 0, 2, 0, 0, 1, 1, 0, 0, 2|2, 1, 2, 2, 0, 0, 2, 2, 1|1, 0, 1, 1, 2, 2, 1, 1, 0]T , and whose functional expression is .

f v = f a (x1 , x2 , x3 , x4 ) ⊕ x4 ⊕ x3 x4 = x4 ⊕ 2x3 x4 ⊕ x1 x2 ⊕ x12 x42 .

This function is bent, and it is interesting to observe that bentness is preserved although a quadratic term is added besides the linear term. We now construct another function . f s the elements of which are obtained from the corresponding coefficients in the initial function as .si = Q2 ai , Therefore, Fs = [s0 , s1 , s2 , s3 , s4 , s5 , s6 , s7 , s8 ]T ,

.

where ⎡

0 .s0 = ⎣ 0 0 ⎡ 0 s3 = ⎣ 0 0 ⎡ 0 s6 = ⎣ 0 0

⎤ ⎤ ⎤ ⎡ ⎡ 00 000 000 2 1 ⎦ , s1 = ⎣ 0 2 1 ⎦ , s2 = ⎣ 0 2 1 ⎦ , 12 012 012 ⎤ ⎤ ⎤ ⎡ ⎡ 11 122 200 0 2 ⎦ , s4 = ⎣ 1 1 0 ⎦ , s5 = ⎣ 2 2 1 ⎦ , 20 101 212 ⎤ ⎤ ⎤ ⎡ ⎡ 11 200 122 0 2 ⎦ , s7 = ⎣ 2 2 1 ⎦ , s8 = ⎣ 1 1 0 ⎦ . 20 212 101

From matrix-valued coefficients, we derive the function vector of another bent function whose function vector is

9.2

Construction of Ternary Bent Functions from Matrix …

267

Fs = [0, 0, 0, 0, 2, 1, 0, 1, 2, |0, 0, 0, 0, 2, 1, 0, 1, 2, |0, 0, 0, 0, 2, 1, 0, 1, 2|

.

0, 1, 1, 0, 0, 2, 0, 2, 0, |1, 2, 2, 1, 1, 0, 1, 0, 1, |2, 0, 0, 2, 2, 1, 2, 1, 2| 0, 1, 1, 0, 0, 2, 0, 2, 0, |2, 0, 0, 2, 2, 1, 2, 1, 2, |1, 2, 2, 1, 1, 0, 1, 0, 1]T . This function is bent which can be seen from its Vilenkin–Chrestenson spectrum, and its functional expression is .

f s = f a (x1 , x2 , x3 , x4 ) ⊕ x3 x4 = 2x3 x4 ⊕ x1 x2 ⊕ x12 x42 .

In this case, the term .x3 x4 is added. Example 9.7 In the present example, we first label elements of the matrix-valued function derived from the initial function by .0, 1, 2, 3, 4, 5, 6, 7, 8 and obtain a function vector .Fe = [0, 1, 2, 3, 4, 5, 6, 7, 8]T . We permute it by the permutation matrix.Px,i = X1 ⊗ I(1) defined in (8.1) [4] and produce a function vector .Fe = [6, 7, 8, 0, 1, 2, 3, 4, 5]T . The replacement of entries in this vector by the corresponding matrix-valued elements of .Fa produces the matrix-valued function as follows: Fw = [w0 , w1 , w2 , w3 , w4 , w5 , w6 , w7 , w8 ]T ,

.

where ⎡

0 .w0 = ⎣ 0 0 ⎡ 0 w3 = ⎣ 0 0 ⎡ 0 w6 = ⎣ 0 0

⎡ ⎡ ⎤ ⎤ ⎤ 11 122 200 2 0 ⎦ , w1 = ⎣ 1 0 1 ⎦ , w2 = ⎣ 2 1 2 ⎦ , 02 110 221 ⎡ ⎡ ⎤ ⎤ ⎤ 00 000 000 1 2 ⎦ , w4 = ⎣ 0 1 2 ⎦ , w5 = ⎣ 0 1 2 ⎦ , 21 021 021 ⎡ ⎡ ⎤ ⎤ ⎤ 11 200 122 2 0 ⎦ , w7 = ⎣ 2 1 2 ⎦ , w8 = ⎣ 1 0 1 ⎦ . 02 221 110

Conversion into a function vector produces a function that is bent and its function vector is Fw = [0, 1, 1, 0, 2, 0, 0, 0, 2, |1, 2, 2, 1, 0, 1, 1, 1, 0, |2, 0, 0, 2, 1, 2, 2, 2, 1|

.

0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1, | 0, 1, 1, 0, 2, 0, 0, 0, 2, |2, 0, 0, 2, 1, 2, 2, 2, 1|1, 2, 2, 1, 0, 1, 1, 1, 0]T . This function is bent and has the functional expression as .

f w = x42 ⊕ x3 x4 ⊕ x2 ⊕ x1 x42 ⊕ 2x1 x2 ⊕ x12 x42 .

268

9 Construction of Ternary Bent Functions From Matrix Representations

If the encoded function vector .Fe is reordered by the permutation .Pi,x = I(1) ⊗ Q1 , we get the function vector .Fd = [2, 0, 1, 5, 3, 4, 8, 6, 7]T . The replacement of entries by the matrix-valued elements of .Fa produces Fd = [d0 , d1 , d2 , d3 , d4 , d5 , d6 , d7 , d8 ]T ,

.

where ⎡

0 .d0 = ⎣ 0 0 ⎡ 1 d3 = ⎣ 1 1 ⎡ 2 d6 = ⎣ 2 2

⎡ ⎡ ⎤ ⎤ ⎤ 00 000 000 1 2 ⎦ , d1 = ⎣ 0 1 2 ⎦ , d2 = ⎣ 0 1 2 ⎦ , 21 021 021 ⎤ ⎡ ⎤ ⎡ ⎤ 22 011 200 0 1 ⎦ , d4 = ⎣ 0 2 0 ⎦ , d5 = ⎣ 2 1 2 ⎦ , 10 002 221 ⎤ ⎤ ⎤ ⎡ ⎡ 00 011 122 1 2 ⎦ , d7 = ⎣ 0 2 0 ⎦ , d8 = ⎣ 1 0 1 ⎦ . 21 002 110

Conversion into a function vector produces Fd = [0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1, |0, 0, 0, 0, 1, 2, 0, 2, 1|

.

1, 2, 2, 1, 0, 1, 1, 1, 0, |0, 1, 1, 0, 2, 0, 0, 0, 2, |2, 0, 0, 2, 1, 2, 2, 2, 1| 2, 0, 0, 2, 1, 2, 2, 2, 1|0, 1, 1, 0, 2, 0, 0, 2, 0, |1, 2, 2, 1, 0, 1, 1, 1, 0]T . This is a function which is bent and has the functional expression as .

f d = f a (x1 , x2 , x3 , x4 ) ⊕ x1 ⊕ x1 x2 = x3 x4 ⊕ x1 ⊕ 2x1 x2 ⊕ x12 x42 .

If the entries of.Fd = [2, 0, 1, 5, 3, 4, 8, 6, 7]T are replaced by the matrix-valued elements of .Fv , thus, by elements of .Fa permuted by .Q1 , we get Fh = [h0 , h1 , h2 , h3 , h4 , h5 , h6 , h7 , h8 ]T ,

.

where ⎡

0 .h0 = ⎣ 0 0 ⎡ 1 ⎣ h3 = 1 1 ⎡ 2 h6 = ⎣ 2 2

1 0 2 0 2 1 1 0 2

⎡ ⎡ ⎤ ⎤ ⎤ 2 012 012 0 ⎦ , h1 = ⎣ 0 0 0 ⎦ , h2 = ⎣ 0 0 0 ⎦ , 1 021 021 ⎤ ⎡ ⎤ ⎡ ⎤ 1 020 212 2 ⎦ , h4 = ⎣ 0 1 1 ⎦ , h5 = ⎣ 2 0 0 ⎦ , 0 002 221 ⎡ ⎡ ⎤ ⎤ ⎤ 2 020 101 0 ⎦ , h7 = ⎣ 0 1 1 ⎦ , h8 = ⎣ 1 2 2 ⎦ . 1 002 110

9.2

Construction of Ternary Bent Functions from Matrix …

269

Conversion into a function vector produces Fh = [0, 1, 2, 0, 0, 0, 0, 2, 1, |0, 1, 2, 0, 0, 0, 0, 2, 1, |0, 1, 2, 0, 0, 0, 0, 2, 1, |

.

1, 0, 1, 1, 2, 2, 1, 1, 0, |0, 2, 0, 0, 1, 1, 0, 0, 2, |2, 1, 2, 2, 0, 0, 2, 2, 1, | 2, 1, 2, 2, 0, 0, 2, 2, 1, |0, 2, 0, 0, 1, 1, 0, 0, 2, |1, 0, 1, 1, 2, 2, 1, 1, 0]T . This function is bent and has the functional expression .

f h = f a (x1 , x2 , x3 , x4 ) ⊕ x1 x2 ⊕ x3 x4 ⊕ x1 ⊕ x4 ⊕ x1 = 2x3 x4 ⊕ x1 ⊕ 2x1 x2 ⊕ x22 x42 .

This function is bent and two quadratic terms are added besides two linear terms. Example 9.8 [1] Consider the function . f squar e = x12 ⊕ x22 ⊕ x32 ⊕ x42 . Its function vector is Fsquar e = [0, 1, 1, 1, 2, 2, 1, 2, 2|1, 2, 2, 2, 0, 0, 2, 0, 0|1, 2, 2, 2, 0, 0, 2, 0, 0|

.

1, 2, 2, 2, 0, 0, 2, 0, 0|2, 0, 0, 0, 1, 1, 0, 1, 1|2, 0, 0, 0, 1, 1, 0, 1, 1| 1, 2, 2, 2, 0, 0, 2, 0, 0|2, 0, 0, 0, 1, 1, 0, 1, 1|2, 0, 0, 0, 1, 1, 0, 1, 1]T . The corresponding matrix-valued function is Fsquar e = [r0 , r1 , r2 , r3 , r4 , r5 , r6 , r7 , r8 ]T ,

.

where ⎡

0 .r0 = ⎣ 1 1 ⎡ 1 r3 = ⎣ 2 2 ⎡ 1 r6 = ⎣ 2 2

1 2 2 2 0 0 2 0 0

⎡ ⎡ ⎤ ⎤ ⎤ 1 122 122 2 ⎦ , r1 = ⎣ 2 0 0 ⎦ , r2 = ⎣ 2 0 0 ⎦ , 2 200 200 ⎡ ⎡ ⎤ ⎤ ⎤ 2 200 200 0 ⎦ , r4 = ⎣ 0 1 1 ⎦ , r5 = ⎣ 0 1 1 ⎦ , 0 011 011 ⎡ ⎡ ⎤ ⎤ ⎤ 2 200 200 0 ⎦ , r7 = ⎣ 0 1 1 ⎦ , r8 = ⎣ 0 1 1 ⎦ . 0 011 011

We first perform the encoding of matrix-valued elements of .Fsquar e as .Fe,squar e = [0, 1, 2, 3, 4, 5, 6, 7, 8]T . Then, we apply the FFT-like permutation matrix .Qi,x T = I(1) ⊗ X1T . The reordered function is .Fe,squar e,new = [1, 2, 0, 4, 5, 3, 7, 8, 6]T . We re-assign the matrix-valued elements to the reordered function as ]T [ Fe,squar e,new = y0 , y1 , y2 , y3 , y4 , y5 , y6 , y7 , y8 ,

.

270

9 Construction of Ternary Bent Functions From Matrix Representations

where ⎡

1 .y0 = ⎣ 2 2 ⎡ 2 y3 = ⎣ 0 0 ⎡ 2 y6 = ⎣ 0 0

⎡ ⎡ ⎤ ⎤ ⎤ 22 122 011 0 0 ⎦ , y1 = ⎣ 2 0 0 ⎦ , y2 = ⎣ 1 2 2 ⎦ , 00 200 122 ⎡ ⎡ ⎤ ⎤ ⎤ 00 200 122 1 1 ⎦ , y4 = ⎣ 0 1 1 ⎦ , y5 = ⎣ 2 0 0 ⎦ , 11 011 200 ⎡ ⎡ ⎤ ⎤ ⎤ 00 200 122 1 1 ⎦ , y7 = ⎣ 0 1 1 ⎦ , y8 = ⎣ 2 0 0 ⎦ . 11 011 200

When converted into a vector, we obtain the function vector Fsquar e = [1, 2, 2, 2, 0, 0, 2, 0, 0|1, 2, 2, 2, 0, 0, 2, 0, 0|0, 1, 1, 1, 2, 2, 1, 2, 2|

.

2, 0, 0, 0, 1, 1, 0, 1, 1|2, 0, 0, 0, 1, 1, 0, 1, 1|1, 2, 2, 2, 0, 0, 2, 0, 0| 2, 0, 0, 0, 1, 1, 0, 1, 1, 2, 0, 0, 0, 1, 1, 0, 1, 1|1, 2, 2, 2, 0, 0, 2, 0, 0]T of a bent function whose functional expression is .

f = 1 ⊕ 2x2 ⊕ x12 ⊕ x22 ⊕ x32 ⊕ x42 .

If we permute the matrix-valued elements in the reordered vector .Fe,squar e,new by any of the elementary permutation matrices, some other bent functions are constructed. For example, by .Q1 , we obtain another bent function whose matrix-valued function vector is ]T [ Fsquar e,new, per muted = g0 , g1 , g2 , g3 , g4 , g5 , g6 , g7 , g8 ,

.

where ⎡

2 .g0 = ⎣ 1 2 ⎡ 0 g3 = ⎣ 2 0 ⎡ 0 ⎣ g6 = 2 0

⎡ ⎡ ⎤ ⎤ ⎤ 00 200 122 2 2 ⎦ , g1 = ⎣ 1 2 2 ⎦ , g2 = ⎣ 0 1 1 ⎦ , 00 200 122 ⎡ ⎡ ⎤ ⎤ ⎤ 11 011 200 0 0 ⎦ , g4 = ⎣ 2 0 0 ⎦ , g5 = ⎣ 1 2 2 ⎦ , 11 011 200 ⎡ ⎡ ⎤ ⎤ ⎤ 11 011 200 0 0 ⎦ , g7 = ⎣ 2 0 0 ⎦ , g8 = ⎣ 1 2 2 ⎦ . 11 011 200

When expanded, we obtain the function vector of a bent function whose function vector is

9.2

Construction of Ternary Bent Functions from Matrix …

271

Fsquar e = [2, 0, 0, 1, 2, 2, 2, 0, 0, |2, 0, 0, 1, 2, 2, 2, 0, 0, |1, 2, 2, 0, 1, 1, 1, 2, 2, |

.

0, 1, 1, 2, 0, 0, 0, 1, 1, |0, 1, 1, 2, 0, 0, 0, 1, 1, |2, 0, 0, 1, 2, 2, 2, 0, 0, | 0, 1, 1, 2, 0, 0, 0, 1, 1, |0, 1, 1, 2, 0, 0, 0, 1, 1, |2, 0, 0, 1, 2, 2, 2, 0, 0]T and the corresponding functional expression is .

f = 2 ⊕ 2x2 ⊕ x3 ⊕ x12 ⊕ x22 ⊕ x32 ⊕ x42 .

This example illustrates that unlike Algorithm 9.1, the method based on matrix-valued equivalents produces different bent functions also in the case of functions represented by the sum of squares of variables. The permutation of matrix-valued elements can be performed by any of the basic transform matrices in Eq. (8.1). Moreover, splitting into matrix-valued coefficients of different dimensions can be done, and in this case, FFT-like permutation matrices of the corresponding dimensions are used. In this way, certain other bent functions are obtained for different dimensions of matrix-valued coefficients. The procedure presented in the above examples, can be summarized in the following algorithm [1]. Algorithm 9.2 (Construction from matrix-valued functions)

1. Given is a ternary bent function in .n variables by its function vector .F of length .3n . 2. Split.F into subvectors of length.3k , for.k = 1, 2, . . . , [n/2], and write as a matrix-valued equivalent .Fmv with .r = 3n−2k elements which are .(3k × 3k ) matrices. 3. Do encoding of elements of .Fmv by integers .0, 1, . . . , r − 1 and produce .Fmv,e . 4. Permute the encoded vector .Fmv,e by an .(r × r ) FFT-like permutation matrix .P, i.e., by .P(n − 2k). 5. Re-assign to elements of .Fmv,e the corresponding matrix-valued elements of .Fmv . 6. Concatenate the rows of matrix-valued elements of .Fmv,e into the function vector of a bent function . f new . 7. Permute each matrix-valued element of.Fmv by the same.(3k × 3k ) FFT-like permutation matrix. 8. Repeat Steps .5, .6, and .7. 9. Repeat Step .4 for a different permutation matrix, and then repeat Steps .5, .6, and .7. The procedures based on matrix representations of bent functions can be useful when considering practical implementation of construction procedures for bent functions in either software or hardware, since the resources tailored for efficient matrix computations can be exploited, or they can lead to specialized ASICs circuits.

272

9 Construction of Ternary Bent Functions From Matrix Representations

References 1. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Remarks on particular properties of ternary bent functions and construction algorithms. In: Proceedings of the 51th International Symposium on Multiple-valued Logic, Nur-Sultan, Kazakhstan, May 25–27, 7–12 (2021). https:// doi.org/10.1109/ISMVL51352.2021.00011. 2. Tokareva, N.: Bent Functions - Results and Applications to Cryptography. Elsevier (2015) 3. Astola, J.T., Stankovi´c, R.S.: Fundamentals of Switching Theory and Logic Design. Springer (2006) 4. Stankovi´c, R.S., Stankovi´c, M., Moraga, C., Astola, J.T.: Construction of ternary bent functions by FFT-like permutation algorithms. In: Proceedings of the 50th International Symposium on Multiple-Valued Logic, Miyazaki, Japan, November 9–11, 2020