Xian Mo Zhang*, Yuliang Zheng, Hideki Imai

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

14 Citations (Scopus)


Due to the success of differential and linear attacks on a large number of encryption algorithms, it is important to investigate relationships among various cryptographic, including differential and linear, characteristics of an S-box (substitution box). After discussing a precise relationship among three tables, namely the difference, auto-correlation and correlation immunity distribution tables, of an S-box, we develop a number of results on various properties of S-boxes. More specifically, we show (1) close connections among three indicators of S-boxes, (2) a tight lower bound on the sum of elements in the leftmost column of its differential distribution table, (3) a non-trivial and tight lower bound on the differential uniformity of an S-box, and (4) two upper bounds on the nonlinearity of S-boxes (one for a general, not necessarily regular, S-box and the other for a regular S-box).

Original languageEnglish
Pages (from-to)45-63
Number of pages19
JournalDesigns, Codes and Cryptography
Issue number1
Publication statusPublished - Jan 2000


  • Boolean Functions
  • Cryptography
  • Differential attack
  • Linear attack
  • Nonlinearity
  • S-boxes


Dive into the research topics of 'Relating'. Together they form a unique fingerprint.

Cite this