CCZ-Equivalence and Enumeration of Triprojective APN Functions
Fuzhou University Zhicheng College
cs.CR
Submitted: 2026-08-12
Updated: 2026-09-23
Comments: 13 pages. Ancillary files contain exact code and regression tests for the finite n=9 computation in Proposition 18. Submitted to IEEE Transactions on Information Theory
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Importance score: 75/100
The gist: This paper classifies binary-linear two-term Frobenius-linearized operators of the form L(Y) = AY σ + BY on K3, where K is a finite extension of F2 and σ is a fixed nontrivial Frobenius
Terminology
Summary
This paper classifies binary-linear two-term Frobenius-linearized operators of the form L(Y) = AY σ + BY on K3, where K is a finite extension of F2 and σ is a fixed nontrivial Frobenius automorphism of K with fixed field F2. The central result is a normal-form classification: under the assumptions that both coefficient matrices A and B have K-rank two and the full binary-linear operator has a one-dimensional kernel over F2, every such operator is, up to invertible K-linear changes of input and output coordinates, equivalent to the single canonical model N σ(α, β, γ) = (α σ + α, β σ, γ). Conversely, every left-right K-linear transform of N σ has coefficient-rank pair (2,2) and binary nullity one, so the rank condition together with the binary kernel condition characterizes a single left-right equivalence class of two-term Frobenius-linearized operators for this fixed σ.
The proof constructs the coordinate frames from the two coefficient-kernel directions and the binary kernel. If X generates the binary kernel, R generates ker K B, and S σ generates ker K A, then X, R, S are forced to be a K-basis. Their images produce a second K-basis, giving matrices E, J ∈ GL(3,K) such that J−1 ∘ L ∘ E = N σ. The first row of J−1 is exactly the unique nonzero trace-adjoint normal to the binary image of L, and its pairing with the first output-frame vector is one in K. This provides the bridge between the two geometries: the binary image remains the trace hyperplane Z: Tr(n T Z) = 0, while the same vector n defines the K-linear covector Z ↦ n T Z and hence a point [n] of the dual K-projective plane.
For pure σ-quadratic almost perfect nonlinear (APN) maps F: K3 → K3, polarization has the form (1) in every direction and the two coefficient halves both evaluate to F(X) at the derivative direction. Therefore, if F is APN and every nonzero derivative has coefficient-rank pair (2,2), the normal form identifies the orthoderivative by the exact field identity π F(X) T F(X) = 1 in K. When m is odd, its trace is one, which places F(X) outside the binary derivative image, yields a direct permutation proof, and combines with pure semiquadratic homogeneity and the standard odd-dimensional orthoderivative bijection to give [X] ↦ [π F(X)] as a bijection from PG(2,K) to its dual plane. The paper proves that π F(λX) = λ(−(σ+1)) π F(X) for λ ∈ K*, X ≠ 0, and that the map Φ F: PG(2,K) → PG(2,K)* defined by [X] ↦ [π F(X)] is a bijection when m is odd, using the fact that gcd(2 k + 1, 2 m − 1) = 1.
Two APN constructions show that the operator class has content beyond a single family. The triprojective family of Göloğlu and Kölsch is pure σ-quadratic and realizes the full pure specialization. Explicit adjugate factorizations verify the rank-(2,2) condition: adj(A X) = S σ l A T and adj(B X) = Rl B T. Additional family-specific contractions give det J X = (det E X)(σ+1) and all three rows of J X−1, including the explicit formula π F(X) T = (P X × Q X) T / Δ X(σ+1). The root-free hypothesis on the admissibility polynomial p(T) = aT(σ2+σ+1) + bT(σ+1) + cT + 1 is shown to be equivalent to Δ X ≠ 0 for every X ≠ 0.
By contrast, the Li–Zhou–Li–Qu cubic norm-twist construction arises from a different extension-field mechanism. Its derivative again has coefficient-rank pair (2,2) and hence the same abstract normal form, but its first output-frame vector is b(HX, X) rather than F(X). Consequently, the theorem yields π F(X) T b(HX, X) = 1, not automatically π F(X) T F(X) = 1. The second realization therefore separates the general operator theorem from the stronger pure-map corollary instead of merely duplicating it. Admissible parameters for the relevant norm-twist subfamily exist in every stated extension degree by the work of Bartoli, Calderini, Polverino, and Zullo.
The coefficient-rank hypothesis is also a genuine structural separator, not an automatic consequence of the APN property. In the natural cubic-extension presentation of a Gold map G(z) = z(2 t+1), both derivative coefficient operators are invertible, giving rank pair (3,3) rather than (2,2). Thus the two positive realizations and the Gold boundary place the normal-form theorem inside a proper representation-dependent subclass of quadratic APN constructions.
On the Fourier side, no new abstract support mechanism is claimed. The classical derivative-incidence theory already determines when a Walsh coefficient can be nonzero and gives the known almost-bent amplitude in odd dimension. What the normal form contributes is the exact extension-field label of the relevant binary trace hyperplane: for the pure class the component indexed by π F(X) has radical F2X, and W F(U, π F(X)) ≠ 0 if and only if Tr(U T X) = 1. Whenever nonzero, W F(U, π F(X)) = 2((3m+1)/2).
The paper also includes a finite machine-assisted result in Appendix A: at m = 3 (binary dimension n = 9), every admissible triprojective parameter instance over F83 is binary EA-inequivalent, and hence CCZ-inequivalent, to every admissible Li–Zhou–Li–Qu norm-twist parameter instance over F512. The computation exhausts 292 triprojective instances and 5292 norm-twist instances, producing disjoint sets of orthoderivative differential spectra. This finite result is stated with its explicit quantifier and no conclusion for m > 3 is claimed.
The contributions are organized in three layers: (1) general theory classifying all operators AY σ + BY on K3 with coefficient-rank pair (2,2) and binary nullity one up to left-right K-linear equivalence, identifying the first dual coordinate as the exactly normalized trace-adjoint normal; (2) APN consequences and realizations, giving the exact normalization π F(X) T F(X) = 1, odd-degree permutation behavior, and an orthoderivative dual-coordinate bijection for pure σ-quadratic APN maps, with the Göloğlu–Kölsch and Li–Zhou–Li–Qu constructions realizing the general theorem through two distinct algebraic mechanisms; (3) sharper specialization and boundaries, including explicit adjugates, the determinant identity, a complete dual frame, extension-field labels for known radical/Walsh relations, and the Gold full-rank scope separator.
Improvements for AI systems
Improvements to AI Systems Based on This Paper:
- Algebraic Normal-Form Classifier for Linearized Operators
-
Improvement: Train a model to detect when a given binary-linear two-term Frobenius-linearized operator (e.g., L(Y)=AY sigma+BY on K cubed) satisfies the rank-(2,2) and binary-nullity-one conditions, then automatically output its unique canonical form N sigma(alpha, beta, gamma).
-
Capability: The AI can reduce any such operator to its normal form via explicit left-right K-linear transformations, enabling fast equivalence checks and structural analysis in coding theory and cryptography.
- Automated APN Map Verification and Normalization
-
Improvement: Implement a symbolic engine that, given a pure sigma-quadratic APN map F, verifies the coefficient-rank pair (2,2) for all nonzero derivatives and then computes the exact orthoderivative identity pi F(X) T F(X)=1.
-
Capability: The AI can certify APN-ness, produce the dual-coordinate bijection [X] [pi F(X)] for odd m, and directly prove permutation properties without manual case analysis.
- Construction-Specific Adjugate and Determinant Computation
-
Improvement: Use the paper’s explicit adjugate factorizations (e.g., adj(A X)=S sigma A T) to build a tool that automatically derives determinant identities like J X = (E X) sigma+1 for any candidate APN family.
-
Capability: The AI can validate new APN constructions by checking rank conditions and computing full dual frames, accelerating discovery of new families.
- Equivalence and Inequivalence Testing via Orthoderivative Spectra
-
Improvement: Leverage the finite machine-assisted result (Appendix A) to train a classifier that distinguishes binary EA/CCZ-inequivalent APN instances by comparing orthoderivative differential spectra.
-
Capability: The AI can exhaustively test parameter instances (e.g., triprojective vs. norm-twist) for inequivalence in higher dimensions, extending the m=3 result to larger fields.
- Walsh Coefficient Prediction with Exact Trace-Hyperplane Labels
-
Improvement: Integrate the normal-form-derived trace hyperplane Z: Tr(n T Z)=0 to predict nonzero Walsh coefficients and their amplitudes (W F(U, pi F(X))=2(3m+1)/2) for pure APN maps.
-
Capability: The AI can compute exact Fourier spectra for APN functions, identifying which components have radical F 2 X and providing precise nonlinearity bounds.
- Boundary Detection for Representation-Dependent Subclasses
-
Improvement: Train a model to recognize when an APN map (e.g., Gold) falls outside the rank-(2,2) class (e.g., rank-(3,3)), using the paper’s separator theorem.
-
Capability: The AI can classify quadratic APN constructions by their operator rank structure, guiding selection of representations that admit normal-form simplifications.
- Automated Proof Generation for Field-Theoretic Identities
-
Improvement: Use the paper’s derivations (e.g., pi F(lambda X)= lambda-(sigma+1) pi F(X)) to build a theorem prover that generates rigorous proofs for new APN maps’ bijectivity and dual-coordinate behavior.
-
Capability: The AI can produce human-checkable proofs for permutation properties and orthoderivative bijections in odd-dimensional extensions of F 2.
- Parameter Admissibility Checker for APN Families
-
Improvement: Implement the paper’s equivalence between the root-free admissibility polynomial p(T) and X not equal to 0 to create a fast filter for valid parameters in triprojective and norm-twist constructions.
-
Capability: The AI can instantly reject invalid parameter sets and enumerate admissible ones for any extension degree, streamlining search in APN design.
Sources
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs