ConceptioArchivearXiv CS
arXiv CSopen access

On APN Exponents and the Differential and Boomerang Properties of Binomials in Characteristic 3

2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptographycybersecurityprivacysecurity
cryptography, security, privacy, cybersecurity

On APN Exponents and the Differential and Boomerang Properties of Binomials in Characteristic 3

arXiv:2605.23224v1 [cs.IT] 22 May 2026

Namhun Koo1 , Soonhak Kwon2,3 , Minwoo Ko2 , Byunguk Kim2 Email: [email protected], [email protected], [email protected], [email protected] 1 Institute of Basic Science, Sungkyunkwan University, Suwon, Korea 2 Department of Mathematics, Sungkyunkwan University, Suwon, Korea 3 Applied Algebra and Optimization Research Center, Sungkyunkwan University, Suwon, Korea

May 25, 2026 Abstract Recent studies on binomials of the form Fr (x) = xr (1 + χ(x)) over Fpn have shown that these functions can exhibit very low boomerang uniformity. In this paper, we focus on the specific behavior of such binomials in characteristic 3, where instances of extremely low boomerang uniformity—namely 0 or 1—seem to arise more frequently than in other characteristics. First, we provide a systematic analysis of Almost Perfect Nonlinear (APN) power functions in characteristic 3. We present an explicit parametrization of APN exponents arising from the construction of Zha and Wang and demonstrate through numerical results for n ≤ 13 that this generalized framework accounts for several previously known and sporadic APN instances. Building on this classification, we identify and rigorously prove two classes of binomials Fr that are locally-PN and possess the minimum possible boomerang uniformity of 0. These classes involve exponents derived from the n−1 aforementioned APN construction and the differentially 4-uniform exponent r = 2 · 3 2 + 1. Furthermore, we analyze the binomial Fr with r = 3n − 3, proving that it is locally-APN with boomerang uniformity 1 when n ≥ 5 is odd, and completely determine its boomerang spectrum through the evaluation of character sums. Our results clarify and extend existing studies on the cryptographic properties of binomials, providing a systematic characterization of several classes of binomials with very low boomerang uniformity in characteristic 3. Keywords. APN Power Functions, Differential Uniformity, Locally-PN Functions, Boomerang Uniformity, Boomerang Spectrum Mathematics Subject Classification (2020): 94A60, 06E30

1

Introduction

Let p be an odd prime and n a positive integer. We denote by Fpn the finite field with pn elements and by F∗pn = Fpn \ {0} its multiplicative group. Differential and boomerang properties of functions over finite fields play a central role in the design of cryptographic primitives, as they measure resistance to differential and boomerang attacks. In particular, differential uniformity and boomerang uniformity have been extensively studied as fundamental criteria for evaluating the security of S-boxes. Differential uniformity was introduced by Nyberg [16] and is defined as follows. 1

Definition 1.1. Let F : Fpn → Fpn be a function. For a ∈ F∗pn and b ∈ Fpn , define δF (a, b) by the number of solutions of F (x + a) − F (x) = b. Then, the differential uniformity of F is defined by: δF =

max

a∈F∗pn ,b∈Fpn

δF (a, b).

A function F is called perfect nonlinear (PN) if δF = 1, and almost perfect nonlinear (APN) if δF = 2. While differential uniformity captures resistance against differential attacks, it does not fully reflect resistance to more advanced attacks such as boomerang attacks. To address this limitation, the notion of boomerang uniformity was originally introduced for permutations by Cid et al. [3]. This notion was later extended to general (not necessarily bijective) functions by Li et al. [11], leading to the following definition. Definition 1.2. Let F : Fpn → Fpn be a function. For a, b ∈ F∗pn , define βF (a, b) as the number of pairs (x, y) ∈ F2pn satisfying: ( F (x) − F (y) = b, F (x + a) − F (y + a) = b. Then the boomerang uniformity of F is given by: βF = max∗ βF (a, b). a,b∈Fpn

While differential uniformity has been extensively studied for general functions, much of the work on differential spectrum and boomerang uniformity has focused on power functions. Functions of the pn −1 form Fr,u (x) = xr (1 + uχ(x)), where χ(x) = x 2 denotes the quadratic character on Fpn , were first studied in [15, 22], where the case r = pn − 2 was shown to yield APN functions in certain characteristics. These functions have also been investigated in more recent works [13, 17, 19, 20], which study their differential properties in the non-APN cases. In [8,13, 14], particular choices of the n exponent r, such as r = pn − 2, 2, and p 4+1 , were further investigated. These works also considered the case u = 1, leading to functions of the form Fr (x) = xr (1 + χ(x)), which were not treated in the same way in other works [17, 19, 20]. The above results show that the functions Fr can exhibit very low values of max δFr (1, b) and low boomerang uniformity. ∗ b∈Fpn

Motivated by this phenomenon, in our previous work [9] we initiated a systematic study of such functions. It was shown that if r satisfies the condition that the equation (x + 1)r − xr = b has at most one solution with χ(x) = χ(x + 1) = 1 for each b ∈ F∗pn , and if gcd(r, pn − 1) ≤ 2, then the function Fr satisfies n

• δFr = δFr (1, 0) = p 4+1 , • max δFr (1, b) ≤ 2, ∗ b∈Fpn

• βFr ≤ 2. 2

max δFr (1, b) ∗

Spectrum provided

Ref.

p = 3, n odd p > 3, pn ≡ 3 (mod 4) pn ≡ 3 (mod 4) pn ≡ 3 (mod 8) pn ≡ 7 (mod 8) pn ≡ 3 (mod 4), 0 < k < n p = 3, n odd, 0 < k < n pn ≡ 11 (mod 12) pn ≡ 11 (mod 12)

1 1 ≤2 1 2 ≤2 ≤2 2 2

O O X O O X X O O

[13] [13] [14] [8] [8] [9] [9] [9] [9]

p = 3, n odd p = 3, n odd p = 3, n odd, gcd(m, n) = 1 um ≡ 1 (mod n), u even p = 3, n odd, gcd(m, n) = 1 um ≡ 1 (mod n), u odd p = 3, n odd p = 3, n ≥ 5 odd

≤2 ≤2

X X

[9] [9]

1

O

Section 4.1

1

O

Section 4.1

1 ≤2

O X

Section 4.2 Section 5

r

Conditions

pn − 2 pn − 2 2 pn +1 4 pn +1 4 pk + 1 3k +1 2

3 2pn −1 3 n+1 3 2 −1 2 3n+1 −1 8 3um −1 3m +1 1−3(n−u)m 1+3m n−1 2

2·3 +1 n 3 −3

b∈Fpn

Table 1: Differential uniformity and spectrum of Fr

3

r

Conditions

βFr

Spectrum provided

Ref.

pn − 2 pn − 2 2

p = 3, n odd pn ≡ 3 (mod 4), p > 3

0 1 2 0 2 ≤2 ≤2 ≤2 ≤2

O X O X X X X

[13] [13] [14] [8] [8] [9] [9] [9] [9]

≤2 ≤2 1

X X O

[9] [9] [9]

0

-

Section 4.1

0

-

Section 4.1

0 1

O

Section 4.2 Section 5

pn ≡ 3 (mod 4), large pn pn ≡ 3 (mod 8) pn ≡ 7 (mod 8) pn ≡ 3 (mod 4), 0 < k < n p = 3, n odd, 0 < k < n pn ≡ 11 (mod 12) pn ≡ 11 (mod 12)

pn +1 4 pn +1 4 pk + 1 3k +1 2

3 2·pn −1 3 n+1 3 2 −1 2 3n+1 −1 8

2 3um −1 3m +1 1−3(n−u)m 1+3m n−1

2·3 2 +1 3n − 3

p = 3, n odd p = 3, n odd p = 3, n ≥ 3 odd p = 3, n odd, gcd(m, n) = 1 um ≡ 1 (mod n), u even p = 3, n odd, gcd(m, n) = 1 um ≡ 1 (mod n), u odd p = 3, n odd p = 3, n ≥ 5 odd

Table 2: Boomerang uniformity and spectrum of Fr .

4

Moreover, several classes of such exponents r were identified. We refer the reader to [9] or Section 2.3 for further details. Tables 1 and 2 summarize known results on the differential and boomerang properties of the functions Fr , together with the new classes studied in this paper. In particular, in characteristic 3, instances in which the boomerang uniformity is strictly smaller than the bound 2 from [9] appear quite frequently, which motivates a closer investigation. To address this, we investigate exponents r for which Fr attains boomerang uniformity 0 or 1. We perform an exhaustive search for small values of n, and report the results in Section 6. Moreover, we identify two classes of exponents for which Fr has boomerang uniformity 0, namely those arising from APN n−1 exponents in [23] and the class r = 2 · 3 2 + 1, for which xr is known to be differentially 4-uniform (see [5]). We also show that Fr has boomerang uniformity 1 when r = 3n − 3, where xr is APN [6] and its differential spectrum has been studied in [21], and determine its boomerang spectrum. Furthermore, we provide a more detailed analysis of APN exponents from [23]. In particular, we give an explicit parametrization of such exponents (Proposition 3.3) and show that, in characteristic 3, this construction accounts for all APN exponents arising from [23]. Our computational results further indicate that, for n ≤ 13, all APN power functions not listed in Table 1 of [2] are explained by this construction. The rest of this paper is organized as follows. Section 2 contains some preliminaries, including a summary of the main results from our previous work [9] that will be used in later sections, as well as a brief discussion of the differential spectrum of Fr in the locally-PN case, where Fr also has boomerang uniformity 0. In Section 3, we study APN exponents arising from [23]. In Section 4, we present two classes of locally-PN binomials Fr with boomerang uniformity 0. We also show that F3n −3 has boomerang uniformity 1 for n ≥ 5 odd, and explicitly evaluate its boomerang spectrum in Section 5. Section 6 presents our numerical results. Finally, Section 7 concludes the paper.

2

Preliminaries

2.1

Reduction Properties of Fr and Locally-APN Functions

For power functions, the differential equation can be reduced to the case a = 1 by a simple scaling argument. Indeed, if F (x) = xr , multiplying a1r on both sides of b = F (x + a) − F (x) = (x + a)r − xr , we have x r  x r b = + 1 − = (y + 1)r − y r , ar a a x where y = . Hence, we have a   b δF (a, b) = δF 1, r , so δF = max δF (1, b), (1) b∈Fpn a in this case. This reduction property motivates the notion of locally-APN functions, originally introduced for power functions in even characteristic [1] and later extended to odd characteristic in [7], where the condition δF (1, b) ≤ 2 for all b ∈ Fpn \ Fp , (2) was introduced. A further generalization was considered in [8] for functions satisfying δF (a, b) = δF (1, ga (b)) for all b ∈ Fpn , where ga permutes Fpn for each a ∈ F∗pn . 5

(3)

Definition 2.1. Let F be a function on Fpn satisfying (3) for every a ∈ F∗pn . Then, • F is called locally-PN, if δF (1, b) ≤ 1 for all b ∈ Fpn \ Fp . • F is called locally-APN, if δF (1, b) ≤ 2 for all b ∈ Fpn \ Fp . The following lemma shows that Fr,u satisfies (3), and hence the notion of locally-APN functions applies to Fr,u as well. Lemma 2.2. [14, Lemma 11] Let Fr,u (x) = xr (1 + uχ(x)) be defined on Fpn , where r > 1 and u ∈ F∗pn . Let a ∈ F∗pn and b ∈ Fpn . Then, δFr,u (a, b) =

βFr,u (a, b) =

2.2

(  δFr,u 1, abr

if χ(a) = 1, b

δFr,u 1, (−1)r+1 ar (  βFr,u 1, abr  βFr,u

1, (−1)b r ar



if χ(a) = −1, if χ(a) = 1, if χ(a) = −1.

Known Results on Quadratic Character

We denote Sij = {x ∈ Fpn : χ(x) = (−1)i , χ(x + 1) = (−1)j }, where i, j ∈ {0, 1}. The following lemma is well-known and useful for our results. n

n

Lemma 2.3. [4] If pn ≡ 1 (mod 4), then #S00 = p 4−5 and #S01 = #S10 = #S11 = p 4−1 . If n n pn ≡ 3 (mod 4), then #S00 = #S10 = #S11 = p 4−3 and #S01 = p 4+1 . The following three lemmas on the quadratic character are useful for our results. Lemma 2.4. [12, Theorem 5.48] Let f (x) = a2 x2 + a1 x + a0 ∈ Fpn [x] with p odd and a2 ̸= 0. Put d = a21 − 4a0 a2 . Then, ( X −χ(a2 ) if d ̸= 0, χ(f (x)) = n (p − 1)χ(a2 ) if d = 0. x∈F n p

Lemma 2.5. [12, Theorem 5.41] Let η(·) be a multiplicative character of Fpn of order m > 1 and let f ∈ Fpn [x] be a monic polynomial of positive degree that is not m-th power of a polynomial. Let d be the number of distinct roots of f in its splitting field over Fpn . Then for every a ∈ Fpn we have X

√ η(af (x)) ≤ (d − 1) pn .

x∈Fpn

The following lemma is well-known. A simple proof is given in Lemma 2.5 of [9]. n n Lemma 2.6. [12, Exercise 5.59] X Let p ≡ 3 (mod 4) and f be a function on Fp with f (−x) = −f (x) for all x ∈ Fpn . Then, χ(f (x)) = 0. x∈Fpn

6

2.3

Differential and Boomerang Properties of Fr

To compute the differential uniformity of Fr , we count the number of solutions of b = Fr (x + 1) − Fr (x) = (x + 1)r (1 + χ(x + 1)) − xr (1 + χ(x)).

(4)

Let Dij (b) denote the number of solutions of (4) in Sij where i, j ∈ {0, 1}. We summarize the results of [9] on differential properties of Fr in the following theorem. Theorem 2.7. [9, Section 3.1] Let r > 1 be an integer and q = pn ≡ 3 (mod 4). If (x + 1)r − xr = b has at most 1 solution in S00 for all b ∈ F∗pn and gcd(r, q − 1) | 2, then n

• [9, Lemma 3.2] D11 (0) = p 4−3 and D11 (b) = 0 for all b ∈ F∗pn . • [9, Lemma 3.3] D00 (0) = 0, and D00 (b) ≤ 1 for all b ∈ F∗pn . • [9, Lemma 3.4, 3.5] D01 (b) + D10 (b) = 0 for b ∈ {0, 2}, and D01 (b) + D10 (b) ≤ 1 for all b ∈ Fpn \ {0, 2}. • [9, Theorem 3.1] Combining the above results, δFr (1, b) ≤ 2 for all b ∈ F∗pn and δFr = δFr (1, 0) =

pn + 1 , 4

and hence Fr is locally-APN. To compute the boomerang uniformity of Fr , we consider the number of common solutions (x, y) of the following system. ( xr (1 + χ(x)) − y r (1 + χ(y)) = b, (5) (x + 1)r (1 + χ(x + 1)) − (y + 1)r (1 + χ(y + 1)) = b. Let Bijkl (b) denote the number of solutions of (5) in Sij × Skl , where i, j, k, l ∈ {0, 1}. We summarize the results of [9] on boomerang properties of Fr in the following theorem. Theorem 2.8. [9, Section 4.1] Under the same assumptions as in Theorem 2.7, we have 1. [9, Lemma 4.5] B0001 (b) = B0010 (b) = 0 or B0100 (b) = B1000 (b) = 0. 2. [9, Lemma 4.6] B0001 (b), B0010 (b), B0100 (b), B1000 (b) ≤ 1. 3. [9, Theorem 4.1] Let α ∈ S00 be the solution of (x + 1)r − xr = 1 if it exists. Then, B0001 (b) = B0010 (b) = B1000 (b) = 0, and hence βFr (1, ±2αr ) = 1 + B0100 (b) ≤ 2. 4. [9, Theorem 4.1] If b ̸= ±2αr , then βFr (1, b) = B0001 (b) + B0010 (b) + B0100 (b) + B1000 (b) ≤ 2. For any function F satisfying (3), the differential spectrum of F is defined to be the multiset DSF = {ωi : 0 ≤ i ≤ δF }, where ωi = #{b ∈ Fpn : δF (1, b) = i}.

7

The following identity for the differential spectrum is well-known: δF X i=0

ωi =

δF X

i · ωi = pn .

(6)

i=0

It is known that Fr is locally-PN with boomerang uniformity 0 in several cases, such as r = 3n − 2 n for p = 3 [13], and r = p 4+1 for pn ≡ 3 (mod 8) [8]. Motivated by these results, we establish a general condition under which Fr is locally-PN, determine its differential spectrum, and show that its boomerang uniformity is 0. Proposition 2.9. Under the assumptions of Theorem 2.7, suppose that • D00 (2) = 0, • D00 (b) = 1 and D01 (b) + D10 (b) = 1 do not occur simultaneously for all b ∈ F∗pn . n

Then, Fr is locally-PN with δFr = p 4+1 and the differential spectrum of Fr is given by   3pn − 1 pn − 3 , ω1 = , ω pn +1 = 1 . DSFr = ω0 = 4 4 4

(7) n

Proof. If x = 0, −1 in (4), then b = 2, 0, respectively. By Theorem 2.7, we have δFr (1, 0) = p 4+1 , δFr (1, 2) = 1 + D00 (2), and δFr (1, b) ≤ D00 (b) + D01 (b) + D10 (b). for all b ̸= 0, 2. Hence, it suffices to verify the conditions in this proposition to ensure that δFr (1, b) ≤ 1 for all b ∈ F∗pn . n n Applying ω pn +1 = 1 on (6), we have ω1 = 3p 4−1 and ω0 = p 4−3 . 4

Proposition 2.10. Let pn ≡ 3 (mod 4) and gcd(r, pn − 1) ∈ {1, 2}. Then, βFr = 0 if and only if δFr (1, b) ≤ 1 for all b ∈ F∗pn . Proof. Since the argument in the proof of [8, Theorem 16] depends only on the property δFr (1, b) ≤ 1, it can be applied without modification to conclude that βFr = 0. Conversely, suppose on the contrary that δFr (1, b) ≥ 2 for some b ∈ F∗pn . Then, there exist x1 ̸= x2 ∈ Fpn such that Fr (x1 + 1) − Fr (x1 ) = Fr (x2 + 1) − Fr (x2 ) = b. Let c = Fr (x1 ) − Fr (x2 ) = Fr (x1 + 1) − Fr (x2 + 1). • If χ(x1 ) ̸= χ(x2 ), then one of Fr (x1 ) and Fr (x2 ) is zero and the other is nonzero, and hence c ̸= 0. • If χ(x1 ) = χ(x2 ) = −1, then we have Fr (x1 + 1) = Fr (x2 + 1) = b. If χ(x1 + 1) = −1 or χ(x2 +1) = −1, then we obtain b = 0, a contradiction. Hence, we have χ(x1 +1) = χ(x2 +1) = 1. Then, (x1 + 1)r = (x2 + 1)r . – If gcd(r, pn − 1) = 1, then we have x1 = x2 , a contradiction to x1 ̸= x2 . – If gcd(r, pn − 1) = 2, then x1 + 1 = −(x2 + 1), since x1 ̸= x2 . But, we can see that χ(x1 +1) = χ(−(x2 +1)) = −χ(x2 +1), which is a contradiction to χ(x1 +1) = χ(x2 +1) = 1. 8

Hence, this case cannot happen. • Assume that χ(x1 ) = χ(x2 ) = 1. If χ(x1 + 1) = −1 or χ(x2 + 1) = −1 then we can easily see that c ̸= 0. In the case χ(x1 + 1) = χ(x2 + 1) = 1, suppose on the contrary that c = 0. Then, we have xr1 = xr2 . Since gcd(r, pn − 1) ∈ {1, 2} and x1 ̸= x2 , we obtain x1 = −x2 , which contradicts χ(x1 ) = χ(x2 ) = 1. Hence, c ̸= 0. Thus, in every possible case, we have c ̸= 0. Therefore, βFr ≥ βFr (1, c) ≥ 1.

3

On APN Power Functions from [23] and Their Instances

The following result is a consequence of the analysis in the proof of Theorem 3.1 together with Theorem 4.1 in [23]. We state it explicitly for later use. Theorem 3.1. [23] Assume that (3m + 1)r − 2 = k(3n − 1), where r is even, k is odd, gcd(m, n) = 1.

(8)

• Let b ∈ F3n \ F3 .  m – If χ b3 +1 − 1 = −1, then (x + 1)r − xr = b has exactly two solutions, one in S00 ∪ S11 and the other in S01 ∪ S10 .  m – If χ b3 +1 − 1 = 1, then (x + 1)r − xr = b has no solution in F3n \ {0, −1}. • If b = 0, 1, −1, then (x + 1)r − xr = b has one solution x = 1, 0, −1, respectively. Hence, xr is APN. Note that the differential spectrum of the APN power functions arising from [23] can be derived from Theorem 3.1. However, to the best of our knowledge, this spectrum has not been explicitly stated in the literature. We therefore summarize the corresponding differential spectrum in the following n+1 theorem. We remark that the special case r = 3 4 −1 of this APN class (see Remark 3.10 (ii)) was recently studied in [18], where its differential spectrum was explicitly determined. Theorem 3.2. If (8) holds, then the differential spectrum of F (x) = xr is given by   3n − 3 DSF = ω0 = ω2 = , ω1 = 3 . 2 Proof. From Theorem 3.1, we have   2 δF (1, b) = 1   0

 m if χ b3 +1 − 1 = −1, b ∈ F3n \ F3 , if b ∈ F3 ,  m if χ b3 +1 − 1 = 1, b ∈ F3n \ F3 .

In particular, ω1 = 3. Using δF = 2 and (6), we obtain the desired differential spectrum.

9

We note that condition (8) cannot hold when n is even, as can be seen by considering (8) modulo 4. The following proposition provides a systematic construction of APN power functions arising from the framework of Theorem 3.1 for odd n. In particular, for any integer m with gcd(m, n) = 1, it yields an explicit exponent r such that xr is APN. Proposition 3.3. Let n be odd and gcd(m, n) = 1. Choose an integer u with 1 ≤ u ≤ n − 1 such that um ≡ 1 (mod n). (i) If u is even, then xr , where r=

3um − 1 , 3m + 1

is APN. (ii) If u is odd, then xr , where r=

1 − 3(n−u)m , 1 + 3m

is APN. Here and throughout the paper, exponents are considered modulo 3n − 1. Proof. Let t = um−1 n . (i) Since u is even, r=

3um − 1 = 3m(u−1) − 3m(u−2) + · · · + 3m − 1 ≡ u 3m + 1

(mod 2)

is also even. Moreover, it follows that nt = um − 1 is odd. Thus, t is also odd, and hence k=

3(3tn − 1) = 3(3(t−1)n + 3(t−2)n + · · · + 1) ≡ t 3n − 1

(mod 2)

is also odd. Moreover, we have (3m + 1)r = 3um − 1 = 3tn+1 − 1 = 3(3tn − 1) + 2 = k(3n − 1) + 2. Therefore, (8) holds, and hence xr is APN, by Theorem 3.1. (ii) Since u is odd, r=

1 − 3(n−u)m = 1 − 3m + · · · + 3m(n−u−2) − 3m(n−u−1) ≡ n − u 1 + 3m

(mod 2)

is even. Moreover, it follows that n(m − t) = m(n − u) + 1 is odd. Thus, m − t = m(n−u)+1 is also n odd. Hence, we can see that k=

1 − 3n(m−t) = 1 + 3n + · · · + 3(m−t−1)n ≡ m − t 1 − 3n

(mod 2)

is odd. Let d = 3r. Then, we obtain (3m + 1)d = 3(1 − 3(n−u)m ) = (1 − 3n(m−t) ) + 2 = −k(3n − 1) + 2. Therefore, d satisfies (8), and hence xd is APN, by Theorem 3.1. Therefore, xr is also APN. 10

Proposition 3.3 provides an explicit construction of an even exponent r satisfying (8). The following result shows that such an r is unique up to linear equivalence (or equivalently, up to cyclotomic cosets). Proposition 3.4. Let n be odd. For each m coprime to n, there is a unique even residue r modulo 3n − 1 satisfying (8). Proof. The existence follows from Proposition 3.3. Let A=

3m + 1 , 2

B=

3n − 1 . 2

We first claim that gcd(A, B) = 1. Indeed, if an odd prime ℓ divided both A and B, then 3m ≡ −1

3n ≡ 1

(mod ℓ),

(mod ℓ).

Therefore the order of 3 modulo ℓ divides both 2m and n. Since n is odd and gcd(m, n) = 1, we have gcd(2m, n) = 1, so this order must be 1. But then 3 ≡ 1 (mod ℓ), which contradicts 3m ≡ −1 (mod ℓ). Hence gcd(A, B) = 1. Now let (r1 , k1 ) and (r2 , k2 ) be two solutions of (8) with r1 , r2 even and k1 , k2 odd. Subtracting the two equations gives A(r1 − r2 ) = B(k1 − k2 ). Because gcd(A, B) = 1, it follows that B | (r1 − r2 ). Since B is odd and r1 − r2 is even, we actually have 2B = 3n − 1 | (r1 − r2 ). Thus r1 ≡ r2 (mod 3n − 1). In particular, all even solutions give the same residue class, hence the same cyclotomic coset. Remark 3.5. Our exhaustive computational experiments via SageMath indicate that Proposition 3.3 provides a broad coverage of APN power functions in characteristic 3. More precisely, for n ≤ 13, among the APN power functions found in our experiments, all those not listed in Table 1 of [2] appear to be accounted for by Proposition 3.3. In particular, Table 7 in Section 6 illustrates how the APN exponents arising from this construction explain several such cases, while also serving as a source of functions Fr with boomerang uniformity 0. Remark 3.6. The following observation shows that the cases m and n − m in Proposition 3.3 give rise to linearly equivalent APN power functions, so that these two choices of m should be regarded as equivalent. Let m2 = n − m1 with gcd(m1 , n) = 1, and let ri be the exponent obtained from Proposition 3.3 for m = mi , where i = 1, 2. Let ui be the integer such that 1 ≤ ui ≤ n − 1 and mi ui ≡ 1 (mod n) for i = 1, 2. Since (n − u1 )m2 = (n − u1 )(n − m1 ) ≡ u1 m1 ≡ 1 (mod n), we have u2 = n − u1 . For

11

convenience, we assume that u1 is even; the case where u1 is odd follows similarly. Then u1 (n−m1 ) 1 − 3(n−u2 )m2 m1 (u1 −1) 1 − 3 = 3 · 3m1 (u1 −1) r2 = 3m1 (u1 −1) · m2 1 + 3n−m1  1+3  = 3m1 (u1 −1) 1 − 3n−m1 + 32(n−m1 ) − · · · + 3(u1 −2)(n−m1 ) − 3(u1 −1)(n−m1 )

= 3m1 (u1 −1) − 3n+m1 (u1 −2) + 32n+m1 (u1 −3) − · · · + 3(u1 −2)n+m1 − 3(u1 −1)n ≡ 3m1 (u1 −1) − 3m1 (u1 −2) + 3m1 (u1 −3) − · · · + 3m1 − 1 3u1 m1 − 1 = m1 = r1 . 3 +1

(mod 3n − 1)

Therefore, xr1 and xr2 are linearly equivalent. Hence, it suffices to consider m ≤ n−1 2 when enumerating APN power functions arising from Proposition 3.3. The following proposition reformulates Proposition 3.3 in a more explicit way, implying two families of APN exponents depending on divisibility conditions on n ± 1. Proposition 3.7. Let n be odd. r (i) If m | n + 1 with n+1 m is even and m ̸= 1, then x , where

r=

3n+1 − 1 , 3m + 1

is APN. r (ii) If m | n − 1 with n−1 m is even, then x , where

r=

1 − 3n−1 , 1 + 3m

is APN. Proof. (i) Observe that u = n+1 m is even. Since um = n + 1 ≡ 1 (mod n), Proposition 3.3(i) implies that if 3um − 1 3n+1 − 1 = m , r= m 3 +1 3 +1 then xr is APN. n−1 ′ (ii) Let u′ = n−1 m . Observe that u = n − u = n − m is odd. Since um = n(m − 1) + 1 ≡ 1 (mod n), Proposition 3.3(ii) implies that if ′

r=

1 − 3(n−u)m 1 − 3u m 1 − 3n−1 = = , 1 + 3m 1 + 3m 1 + 3m

then xr is APN. The following APN class obtained in [10] can be recovered as a special case of Proposition 3.7 (i).

12

Corollary 3.8. [10] Let n ≡ −1 (mod 2ℓ ) and m = n+1 where ℓ is a positive integer. Then, the 2ℓ function xr , where 3n+1 − 1 3n+1 − 1 , r= m = n+1 3 +1 3 2ℓ + 1 is APN. ℓ Proof. Since n = 2ℓ m − 1, we have m | n + 1 and n+1 m = 2 is even. If m ̸= 1, then the result follows n+1 from Proposition 3.7(i). If m = 1, then r = 3 4 −1 , which is the known APN exponent from [6]; see also Remark 3.10 (ii).

By symmetry, one may also consider the case where n−1 m is a power of 2. This leads to the following APN class. where ℓ is a positive integer. Then the function Corollary 3.9. Let n ≡ 1 (mod 2ℓ ) and m = n−1 2ℓ r x , where 1 − 3n−1 1 − 3n−1 r= = n−1 , 1 + 3m 1 + 3 2ℓ is APN. ℓ Proof. Since n = 2ℓ m + 1, we have m | n − 1 and n−1 m = 2 is even. Thus the result follows from Proposition 3.7(ii). n+1

Remark 3.10. (i) It is easy to see that if ℓ = 1 in Corollary 3.8, we obtain r = 3 2 − 1 which is a known APN exponent from [6]. Moreover, taking ℓ = 1 in Corollary 3.9 yields n−1

n−1

n−1

n+1

r = 1 − 3 2 ≡ 3n − 3 2 = 3 2 (3 2 − 1)

(mod 3n − 1),

which is equivalent to the same class. (ii) Taking m = 1 in Proposition 3.7 (ii) gives 3r ≡ 3r + (3n − 1) =

3n+1 − 1 4

(mod 3n − 1),

which is also a known APN exponent from [6]. (iii) Outside of these cases, the construction in Corollary 3.9 produces new instances starting from n = 9.

4

Locally-PN Binomials with Boomerang Uniformity 0

In this section we introduce two classes of locally-PN binomials Fr with boomerang uniformity 0, using Proposition 2.9 and Proposition 2.10.

13

4.1

The APN-exponent class arising from (8)

In this subsection, we show that the corresponding function Fr is locally-PN with boomerang uniformity 0, where r is an APN exponent arising from [23] satisfying (8). Such exponents were discussed n+1 in Section 3. We remark that, for the associated function Fr , the case m = 1 (i.e., r = 3 4 −1 ) was already studied in [8]. By Theorem 3.1, it remains to verify the second condition of Proposition 2.9. We consider the number of solutions of the following equation for every b ∈ F∗3n . (x + 1)r (1 + χ(x + 1)) − xr (1 + χ(x)) = b

(9)

Lemma 4.1. Assume that (8) holds. If b ∈ F∗3n , then  3m +1  D01 (b) = 1 ⇔ χ(b) = 1, χ b 2 + 1 = −1,   3m +1 m 2 + (−1) = (−1)m . D10 (b) = 1 ⇔ χ(b) = −1, χ b Proof. If x ∈ S01 , then (9) leads to xr = b. m

Since χ(x) = 1, we have χ(b) = χ (xr ) = 1. Raising both sides of the above equation to the 3 2+1 -th power implies 3m +1 2

m

= xr(3 +1) = x

k(3n −1) +1 2

= χ(xk ) · x = x,  3m +1  since χ(x) = 1. Hence, χ(x + 1) = −1 if and only if χ b 2 + 1 = −1. Hence, D01 (b) = 1 if and   3m +1 only if χ(b) = 1 and χ b 2 + 1 = −1. If x ∈ S10 , then (9) leads to (x + 1)r = −b. b

Since χ(x + 1) = 1, we have χ(b) = χ (−(x + 1)r ) = −1. Raising both sides of the above equation to m the 3 2+1 -th power implies (−b)

3m +1 2

= (x + 1)

k(3n −1) +1 2

= x + 1,   3m +1 since χ(x + 1) = 1. Hence, χ(x) = −1 if and only if χ (−b) 2 − 1 = −1, or equivalently  3m +1  χ b 2 + (−1)m = (−1)m . Theorem 4.2. Assume that (8) holds. Then, Fr is locally-PN with the differential uniformity δFr = δFr (1, 0) =

3n + 1 , 4

and the differential spectrum is given in (7). Moreover, Fr has boomerang uniformity 0. Proof. As mentioned in the beginning of this subsection, it suffices to prove that if D00 (b) = 1 then D01 (b) = 0 and D10 (b) = 0 for every b ∈ F∗3n . Suppose that (9) has a solution x = x0 , where x0 ∈ S00 . Then,  r r r r −b = (x0 + 1)r − xr0 = (x0 + 1) 2 − x02 (x0 + 1) 2 + x02 . 14

r

r

r

r

Let t = (x0 + 1) 2 − x02 . Then, − bt = (x0 + 1) 2 + x02 , and hence r

(x0 + 1) 2 =

r b b − t, x02 = + t. t t

Raising (3m + 1)-th power on the second equation, we have 

b +t t

because x0 ∈ S00 . Similarly,

3m +1

(3m +1)r 2

= x0

k(3n −1) +1 2

= x0

= χ(xk0 ) · x0 = x0 ,

3m +1 b = x0 + 1. Thus, t −t

3m +1  3m +1 b b 1= −t +t − t t   3m +1   3m +1 m m b3 b b3 b 3m −1 3m +1 3m −1 3m +1 − 3m −1 − bt +t − 3m +1 + 3m −1 + bt +t = t3m +1 t t t     m m 3m −1 3m −1 b3 −1 b3 −1 m m = b t3 −1 + 3m −1 = b t3 −1 + 3m −1 + b 2 − b 2 t t ! m 2 3 −1 3m −1 3m +1 b 2 2 =b t − 3m −1 (10) −b 2 t 2 !2 3m −1 3m −1 3m +1 b 2 (11) = b t 2 + 3m −1 +b 2 . t 2  3m +1   3m +1  (10) and (11) imply χ(b) = χ b 2 + 1 and χ(b) ̸= χ b 2 − 1 , respectively. By Lemma 4.1, we obtain D01 (b) = 0 and D10 (b) = 0. This completes the proof by Propositions 2.9 and 2.10. 

4.2

n−1

The case r = 2 · 3 2 + 1

In this section, we study differential and boomerang properties of F2·3ℓ +1 on F3n , when n is odd and ℓ = n−1 2 . First, we extract several auxiliary results from [5], which arise in the derivation of the ℓ differential spectrum of the power function x2·3 +1 , and present them as a lemma for later use. Lemma 4.3. [5] Let n be odd and ℓ

g(x) = (x − 1)2·3 +1 − (x + 1)2·3 +1 where ℓ = n−1 2 . Let S = {x ∈ F∗3n : χ(x2 − 1) = −1}, S ′ = {x ∈ F∗3n : χ(x2 − 1) = 1}, ℓ+1

P = {x ∈ F3n : χ(x3−2·3

ℓ+1

− 1) = 1}, P ′ = {x ∈ F3n : χ(x3−2·3

− 1) = −1}.

Then, 1. If x ∈ S, then g(x) ∈ P . If x ∈ S ′ , then g(x) ∈ P ′ . If x ∈ F3 , then g(x) = 1. 15

2. The restriction of g to S maps 4-to-1, and the restriction of g to S ′ maps 2-to-1. To study differential properties of Fr , we count the number of solutions of the following equation for every b ∈ F∗3n . n−1

n−1

(x + 1)2·3 2 +1 (1 + χ(x + 1)) − x2·3 2 +1 (1 + χ(x)) = b

(12)

Lemma 4.4. Let  n be odd and ℓ = n−1 2 . Then, D00 (b) ≤ 1. Moreover, D00 (b) = 1 if and only if   ℓ+1 χ b b2·3 −3 + 1 = 1. Proof. If (12) has a solution in S00 , then it is also a solution of ℓ

−b = (x + 1)2·3 +1 − x2·3 +1 = g(x − 1)

(13)

where g is given in Lemma 4.3. Observe that x − 1 ∈ S ′ if and only if χ(x)χ(x + 1) = 1. Hence, by Lemma 4.3, −b ∈ P ′ , and hence        ℓ+1  ℓ+1 ℓ+1 ℓ+1 −1 = χ (−b)3−2·3 − 1 = −χ b3−2·3 + 1 = −χ b3−2·3 χ b2·3 −3 + 1  ℓ+1  = −χ(b)χ b2·3 −3 + 1 , as desired.   ℓ+1  Conversely, if χ b b2·3 −3 + 1 = 1, then −b ∈ P ′ . By Lemma 4.3, (13) has two solutions x1 , x2 such that χ(x1 (x1 + 1)) = χ(x2 (x2 + 1)) = 1. Moreover, since r = 2 · 3ℓ + 1 is odd, if x = x1 is a solution of (13), then x = −x1 − 1 is also a solution of (13). Thus, we can see that x2 = −x1 − 1. Observe that if x1 ∈ S00 then χ(x2 ) = χ(−(x1 + 1)) = −1 and χ(x2 + 1) = χ(−x1 ) = −1, so x2 ∈ S11 . Therefore, we conclude that (13) has exactly one solution in S00 and hence D00 (b) = 1. ∗ Lemma 4.5. Let n be odd and ℓ = n−1 2 . If b ∈ F3n , then  ℓ+1  D01 (b) = 1 ⇔ χ(b) = 1, χ b2·3 −3 + 1 = −1,  ℓ+1  D10 (b) = 1 ⇔ χ(b) = −1, χ b2·3 −3 + 1 = 1.

  ℓ+1  Moreover, D01 (b) + D10 (b) = 1 if and only if χ b b2·3 −3 + 1 = −1. Proof. If x ∈ S01 , then (12) leads to ℓ

x2·3 +1 = b   ℓ Since χ(x) = 1, we have χ(b) = χ x2·3 +1 = 1. Raising both sides of the above equation to the (2 · 3ℓ − 1)-th power implies ℓ

n−1 −1

b2·3 −1 = x4·3 

3

n

n−1

= x(3 −1)+3

n−1

= x3

,

 ℓ+1  . Hence, χ(x + 1) = −1 if and only if χ b2·3 −3 + 1 = −1.  ℓ+1  2·3 −3 Hence, D01 (b) = 1 if and only if χ(b) = 1 and χ b + 1 = −1. The proof of the characterization of D10 (b) is analogous, and we omit it here. The final statement follows immediately from these two equivalences. ℓ

and hence x = b2·3 −1

ℓ+1 −3

= b2·3

16

Theorem 4.6. Let n be odd and ℓ = n−1 2 . Then, F2·3ℓ +1 is locally-PN with the differential uniformity δF2·3ℓ +1 = δF2·3ℓ +1 (1, 0) =

3n + 1 , 4

and the differential spectrum is given in (7). Moreover, F2·3ℓ +1 has boomerang uniformity 0. Proof. We apply Proposition 2.9. Since 3n − 1 = (2 · 3ℓ + 1)(2 · 3ℓ − 1) − 3n−1 , we obtain gcd(2 · 3ℓ + 1, 3n − 1) = 1. Next, by Lemmas 4.4 and 4.5, D00 (b) ≤ 1 for all b ∈ F∗3n , and the conditions D00 (b) = 1 and D01 (b) + D10 (b) = 1 do not occur simultaneously for any b ∈ F3n \ {0, 2}. Now, it remains to show that D00 (2) = D00 (−1) = 0. Substituting b = −1 into (13), we obtain g(x − 1) = 1. By Lemma 4.3, all solutions of g(x − 1) = 1 lie in F3 . Since S00 ∩ F3 = ∅, it follows that D00 (−1) = 0.

5

Differential and Boomerang Properties of Fr with r = 3n − 3

In this section, we study differential and boomerang properties of F3n −3 on F3n , when n is odd. In the following theorem, we show that F3n −3 is locally-APN, using Theorem 2.7. n

Theorem 5.1. Let n ≥ 3 be odd. Then, δF3n −3 (1, b) ≤ 2 for all b ∈ F∗3n and δF3n −3 (1, 0) = 3 4+1 . Therefore, F3n −3 is locally-APN. Proof. By Theorem 2.7, it suffices to show that n

n

(x + 1)3 −3 − x3 −3 = −b.

(14)

has at most one solution in S00 . Suppose that x ̸∈ {0, −1}. Then, we have x2 −(x+1)2 = −bx2 (x+1)2 , or equivalently 1 1 x4 − x3 + x2 + x − = 0. b b Applying x = y + 1 in the above equation, we have y 4 + y 2 − uy + 1 = 0,

(15)

where u = − 1b . If (15) has two or more solutions, g(y) = y 4 + y 2 − uy + 1 = (y 2 + cy + d)(y 2 − cy + d−1 ) for some c, d ∈ F∗3n . Then,

( d + d−1 = c2 + 1,  c d − d−1 = u

The first equation in (16) leads to d2 + 1 = d(c2 + 1) d2 + 2d(c2 + 1) + 1 = 0 d2 + 2d(c2 + 1) + c4 − c2 + 1 = c4 − c2 2 d + (c2 + 1) = c2 (c2 − 1). 17

(16)

If c2 = 0 or c2 = 1, then the above equation implies d = −(c2 +1) which leads to d−1 = (c2 +1)−d = d and hence u = 0, a contradiction. Hence, c2 (c2 − 1) ̸= 0 and χ(c2 − 1) = 1. Furthermore, we have   3n +1 3n +1 2 d = −(c2 + 1) + ϵc(c2 − 1) 4 = c − ϵ(c2 − 1) 4 (17) where ϵ ∈ {±1} will be determined later. Then, u=c d−d

−1



2

2

= c −(c + 1) + ϵc(c − 1)

3n +1 4

−(c2 + 1) + ϵc(c2 − 1) ! n 2 + 1) − ϵc(c2 − 1) 3 4+1 3n +1 −(c = c −(c2 + 1) + ϵc(c2 − 1) 4 − (c2 + 1)2 − c2 (c2 − 1) = −ϵc2 (c2 − 1)

3n +1 4

!

1 3n +1 4

.

Furthermore, we have   3n +1 3n +1 = −(c2 − 1) − ϵc(c2 − 1) 4 c2 − d = c2 − −(c2 + 1) + ϵc(c2 − 1) 4   3n +1 3n +1 = (c2 − 1) 4 2cϵ − (c2 − 1) 4 . Similarly, we obtain c2 − d−1 = −(c2 − 1)

3n +1 4



2cϵ + (c2 − 1)

3n +1 4



.

If ϵ = χ(c + 1) = χ(c − 1), then c2 − d = (c2 − 1)

3n +1 4



(c + 1)

3n +1 4

+ (c − 1)

3n +1 4

2

is a square, and c2 − d−1 = −(c2 − 1)

3n +1 4



(c + 1)

3n +1 4

− (c − 1)

3n +1 4

2

is not a square. Hence, g(y) = 0 has two solutions satisfying y 2 + cy + d = 0. Let y1 and y2 be two solutions of y 2 + cy + d = 0. Then, x1 = y1 + 1 and x2 = y2 + 1 are two solutions of (14), and x1 x2 (x1 + 1)(x2 + 1) = (y1 + 1)(y2 + 1)(y1 − 1)(y2 − 1) = (y12 − 1)(y22 − 1) = y12 y22 − (y12 + y22 ) + 1 = (y1 y2 )2 − (y1 + y2 )2 − y1 y2 + 1 = d2 − c2 − d + 1 = (d + 1)2 − c2   3n +1 2 3n +1 = −c2 + ϵc(c2 − 1) 4 − c2 = c4 + c2 (c2 − 1) + ϵc3 (c2 − 1) 4 − c2     3n +1 3n +1 3n +1 = −c2 c2 − 1 − ϵc(c2 − 1) 4 = −c2 (c2 − 1) 4 2ϵc + (c2 − 1) 4   3n +1 3n +1 3n +1 2 = −c2 (c2 − 1) 4 (c + 1) 4 + (c − 1) 4 . Hence, we have χ (x1 (x1 + 1)) χ (x2 (x2 + 1)) = χ (x1 x2 (x1 + 1)(x2 + 1)) = −1, and hence satisfying both χ (x1 (x1 + 1)) = 1 and χ (x2 (x2 + 1)) = 1 is impossible. Therefore, (14) has at most one solution in S00 . The proof for the case −ϵ = χ(c + 1) = χ(c − 1) is very similar to the above case, and we omit it here. 18

Next, we study the boomerang properties of F3n −3 . In the following lemma, we give necessary and sufficient conditions for each Bijkl (b) to be equal to 1. Lemma 5.2. Let p = 3, n ≥ 3 be odd, r = 3n − 3 and b ∈ F∗3n . Then, • B0001 (b) = 1 if and only if  3n +1   3n +1   3n +1  3n4+1 3n +1 3n +1 χ(b) = −1, χ b 4 + 1 = χ b 4 + b = 1, χ b 4 b 4 +b − (b 4 + 1)

! = 1. (18)

• B0010 (b) = 1 if and only if  3n +1   3n +1   3n +1  3n4+1 3n +1 3n +1 + (b 4 − 1) χ(b) = χ b 4 − 1 = χ b 4 − b = −1, χ b 4 b 4 −b

! = 1. (19)

• B0100 (b) = 1 if and only if  3n +1   3n +1   3n4+1  3n +1 3n +1 3n +1 4 4 4 4 b +b =χ b − 1 = −1, χ b +b + (b 4 − 1) χ(b) = 1, χ b

! = 1. (20)

• B1000 (b) = 1 if and only if  3n +1   3n +1   3n +1  3n4+1 3n +1 3n +1 χ(b) = χ b 4 + 1 = χ b 4 − b = 1, χ b 4 b 4 −b − (b 4 + 1)

! = 1. (21)

Proof. If there is a solution (x, y) ∈ S00 × S01 in (5) with r = 3n − 3, then (5) reduces to ( n n x3 −3 − y 3 −3 = −b, n (x + 1)3 −3 = −b.

(22)

1 n Raising both sides of the second equation in (22) to the 3 4+1 -th power yields x + 1 = − 3n +1 and b n4 3 +1 4 1 b +1 n χ(b) = −1, since 3 4+1 is odd when n is odd and χ(x + 1) = 1. Then, x = − 3n +1 − 1 = − , 3n +1 4 4 b b 3n +1 3n +1 b 4 +1 hence χ(x) = 1 leads to χ(b 4 + 1) = 1. Substitute x = − into the first equation in (22), 3n +1 b 4 we obtain  3n +1 2 !2 3n +1 4 −b + b b + 1 b 4 n n y 3 −3 = x3 −3 + b = − 3n +1 +b=  3n +1 2 b 4 +1 b 4 +1  3n +1   3n +1  3n +1 −b + b b 2 − b 4 + 1 b b 4 +b =− = − n  3n +1 2 2 . 3 +1 b 4 +1 b 4 +1

19

Hence, the above equation implies 3n +1

b 4 +1 y=−  3n +1 .  3n +1 3n +1 4 b 4 b 4 +b When χ(b) = −1 and χ(b −1 is equivalent to

3n +1 4

 3n +1  + 1) = 1, χ(y) = 1 leads to χ b 4 + b = 1. Furthermore, χ(y + 1) =

χ b

3n +1 4

 3n +1  3n4+1 3n +1 4 − (b 4 + 1) b +b

! = 1.

The proofs for the other cases are very similar, and we omit here. The following two lemmas are useful for our results. Lemma 5.3. Let n be odd. Then, X

χ(x4 + x3 − 1) = −1.

x∈F3n

Proof. Let y = x1 where x ∈ F∗3n . Then, we obtain X

4

3



χ x + x − 1 = −1 +

X

4

3

χ x + x − 1 = −1 +

x∈F∗3n

x∈F3n

= −1 +

X y∈F∗3n

X



 χ

y∈F∗3n

 χ

1 + y − y4 y4

 = −2 −

X

1 1 + 3 −1 4 y y

 χ y4 − y − 1 .

y∈F3n

If we set z = x + 1, then X X X    χ x4 + x 3 − 1 = χ z 4 − z − 1 = −2 − χ z4 + z3 − 1 , x∈F3n

z∈F3n

z∈F3n

which completes the proof. Lemma 5.4. Let n be odd. Then, X X χ(x(x2 + 1))χ(x4 + x3 − 1) + χ(x4 − 1)χ(x4 + x3 − 1) = −1. x∈F3n

x∈F3n

Proof. Let y = x − 1 and A=

X

 χ(x2 + 1)χ(x4 + x3 − 1) χ(x) + χ(x2 − 1) .

x∈F3n

Then, A=

X

 χ(y 2 − y − 1)χ(y 4 − y 3 + y + 1) χ(y + 1) + χ(y 2 − y) .

y∈F3n

20



If z = y1 , then A=

X

χ(y 2 − y − 1)χ(y 4 − y 3 + y + 1) χ(y + 1) + χ(y 2 − y)



y∈F3n

X

= −1 +

χ(y 2 − y − 1)χ(y 4 − y 3 + y + 1) χ(y + 1) + χ(y 2 − y)



y∈F∗3n



X

= −1 +

χ

z∈F∗3n

X

= −1 −

       1 1 1 1 1 1 1 1 − −1 χ − + +1 χ +1 +χ − z2 z z4 z3 z z z2 z

    χ z 2 + z − 1 χ z 4 + z 3 − z + 1 χ z 2 + z + χ (1 − z)

z∈F∗3n

X

= −2 −

    χ z 2 + z − 1 χ z 4 + z 3 − z + 1 χ z 2 + z + χ (1 − z) .

z∈F3n

If we set w = −z + 1, then X     A = −2 − χ w2 + 1 χ w4 + w3 − 1 χ w2 − 1 + χ (w) = −2 − A, w∈F3n

which completes the proof. Applying Lemma 2.2, the boomerang spectrum of F is defined to be the multiset BSF = {νi : 0 ≤ i ≤ βF }, where νi = #{b ∈ F∗pn : βF (1, b) = i}. The following identity for the boomerang spectrum is well-known: βF X

νi = q − 1.

(23)

i=0

Theorem 5.5. If n ≥ 3 odd, the boomerang spectrum of F3n −3 is given by    1 n+1 1 n BSF3n −3 = ν0 = 3 − 5 − 2Γ1 − Γ2 , ν1 = (3 + 1 + 2Γ1 + Γ2 ) , 4 4 where Γ1 =

X

X   χ(u(u2 + 1))χ u4 + u3 − 1 , Γ2 = χ(u(1 − u2 ))χ u4 + u3 − 1 .

u∈F3n

u∈F3n

Moreover, ν1 > 0 and hence βF3n −3 = 1, when n ≥ 5. Proof. We first show that βF3n −3 ≤ 1. By Theorem 2.8, it suffices to prove that (18) and (19) do not hold simultaneously, and that (20) and (21) do not hold simultaneously. Suppose that (18) and (19) occur simultaneously. Then, χ(b) = −1. Moreover,  3n +1   3n +1   3n +1  −1 = χ b 4 + 1 χ b 4 − 1 = χ b 2 − 1 = χ(−b − 1), 21

and hence χ(b + 1) = 1. Then,  3n +1   3n +1   3n +1  −1 = χ b 4 + b χ b 4 − b = χ b 2 − b2 = χ(−b − b2 ) = −χ(b)χ(b + 1) = 1, a contradiction. The argument for (20) and (21) is analogous and hence omitted. Next, we compute ν1 . (18) and (19) are identical after replacing b in (20) and (21) by −b, respectively. Hence, ν1 equals twice the number of b ∈ F∗3n satisfying (18) or (19). Let A1 be the number of b ∈ F∗3n satisfying (18). Then,   3n +1    3n +1   3n +1  3n +1 1 X (1 − χ(b)) 1 + χ b 4 + 1 1+χ b 4 A1 = 1+χ b 4 +b b 4 +b 16

3n +1 4

− (b

!

3n +1 4

+ 1)

b∈F3n

1 = 8

X 

 3n +1    3n +1   3n +1  3n4+1 3n +1 3n +1 − (b 4 + 1) 1+χ b 4 +1 1+χ b 4 +b b 4 +b 1+χ b 4

χ(b)=−1 3n +1 4

. Then, b = −y 2 when χ(b) = −1, and hence      3n +1 1 X 2 2 4 A1 = (1 + χ(y + 1)) 1 + χ y − y 1+χ y y−y − (y + 1) 16

Let y = b

y∈F3n

=

 1 X (1 + χ(y + 1)) 1 + χ y − y 2 16 y∈F3n

    3n +1 1 X (1 + χ(y + 1)) 1 + χ y − y 2 χ y y − y 2 4 − (y + 1) 16 y∈F3n     3n +1 1 n 1 X 2 2 4 − (y + 1) , (1 + χ(y + 1)) 1 + χ y − y χ y y−y = (3 + 1) + 16 16

+

y∈F3n

by Lemmas 2.4 and 2.6. Let t = y + 1. Then, X

(1 + χ(y + 1)) 1 + χ y − y

2



 χ y y−y

2

 3n +1 4

 − (y + 1)

y∈F3n

=

X

(1 + χ(t)) 1 + χ 1 − t

2



   3n +1 2 4 χ (t − 1) 1 − t −t

t∈F3n

= −4 +

X

(1 + χ(t)) 1 + χ 1 − t

t∈F3n \F3

22

2



 χ (t − 1) 1 − t

2

 3n +1 4

 −t

(24)

!! .

u Let t = 1+u 2 . Then,

X

(1 + χ(t)) 1 + χ 1 − t

2



   3n +1 2 4 χ (t − 1) 1 − t −t

t∈F3n \F3

          3n2+1 2 2 2 2 u (1 − u ) (u + 1) 1−u u  1 1+χ 1+χ χ − − = 2 2 2 2 2 2 u +1 (1 + u ) 1+u 1+u 1 + u2 u∈F3n \F3     1 X (u + 1)2 (1 − u2 )χ(1 − u4 ) + u(1 + u2 ) 2 4 2 = 1 + χ u(u + 1) 1 + χ (1 − u ) χ − 2 (1 + u2 )2 u∈F3n \F3 X   1 + χ u(u2 + 1) χ (u + 1)3 (1 − u)χ(1 − u4 ) + u(u2 + 1) =− X

u∈F3n \F3

=

X

1 + χ u(u2 + 1)



u∈F3n \F3 χ(1−u4 )=1

=

X

X

 χ u4 + u3 − 1 −

1 + χ u(u2 + 1)



 χ u4 − u − 1

u∈F3n \F3 χ(1−u4 )=−1

(1 + χ(1 − u4 )) 1 + χ u(u2 + 1)



χ u4 + u3 − 1



u∈F3n \F3

where the last equality is from X   1 + χ u(u2 + 1) χ u4 − u − 1 = − u∈F3n \F3 χ(1−u4 )=−1

X

1 + χ s(s2 + 1)



χ s4 + s3 − 1

s∈F3n \F3 χ(1−s4 )=1

when s = u1 . Hence, by Lemma 5.3 and Lemma 5.4     n +1 X 3   1  n A1 = 3 +1+ (1 + χ(y + 1)) 1 + χ y − y 2 χ y y − y 2 4 − (y + 1)  16 y∈F3n     n +1 X 3   1  n = 3 −3+ (1 + χ(t)) 1 + χ 1 − t2 χ (t − 1) 1 − t2 4 − t  16 t∈F3n \F3   X   1  n = 3 −3+ (1 + χ(1 − u4 )) 1 + χ u(u2 + 1) χ u4 + u3 − 1  16 u∈F3n \F3   X   1  n = 3 +1+ (1 + χ(1 − u4 )) 1 + χ u(u2 + 1) χ u4 + u3 − 1  16 u∈F3n

=

1 n (3 + 1 + 2Γ1 + Γ2 ) 16

23



Let A2 be the number of b ∈ F∗3n satisfying (19). Then,   3n +1    3n +1   3n +1  3n +1 1 X (1 − χ(b)) 1 − χ b 4 − 1 1+χ b 4 A2 = 1−χ b 4 −b b 4 −b 16

3n +1 4

+ (b

!

3n +1 4

− 1)

b∈F3n

1 = 8

X 

   3n +1   3n +1  3n4+1  3n +1 3n +1 3n +1 1+χ b 4 1−χ b 4 −b b 4 −b + (b 4 − 1) 1−χ b 4 −1

χ(b)=−1 3n +1 4

. Then b = −y 2 when χ(b) = −1 and hence     3n +1  1 X 2 2 4 A2 = 1+χ y y+y (1 − χ(y − 1)) 1 − χ y + y + (y − 1) 16 y∈F3n      3n +1 1 X 2 2 4 − (t + 1) = A1 , (1 − χ(−t − 1)) 1 − χ t − t 1 + χ −t t − t = 16

Let y = b

y∈F3n

where t = −y, and by (24). Therefore, we finally obtain that 1 ν1 = 4A1 = (3n + 1 + 2Γ1 + Γ2 ). 4 Applying (23), we get the desired boomerang spectrum. √ √ n By Lemma 2.5, we have |Γ1 | ≤ 6 3 and |Γ2 | ≤ 6 3n . Hence,  n 1 n 1 n (3 + 1 − 2|Γ1 | − |Γ2 |) ≥ 3 − 18 · 3 2 + 1 . 4 4   n A direct computation using SageMath shows that 14 3n − 18 · 3 2 ≥ 1 if 3n ≥ 330 ≈ 35.28 . We confirm that βF3n −3 = 0 when n = 3, and βF3n −3 = 1 when n = 5. ν1 ≥

Table 3 shows the boomerang spectrum of F3n −3 given in Theorem 5.5 for 3 ≤ n ≤ 15 using SageMath. We also verified via SageMath that the results of Theorem 5.5 are correct, when 3 ≤ n ≤ 9.

n

Γ1

Γ2

BSF3n −3

3 5 7 9 11 13 15

−2 −22 250 142 −1586 570 −6262

−24 40 112 48 792 −104 −1184

{v0 = 26, v1 = 0} {v0 = 182, v1 = 60} {v0 = 1486, v1 = 700} {v0 = 14678, v1 = 5004} {v0 = 133454, v1 = 43692} {v0 = 1195482, v1 = 398840} {v0 = 10765106, v1 = 3583800}

Table 3: Boomerang spectrum BSF3n −3 when n is odd, 3 ≤ n ≤ 15.

24

!! .

6

Numerical Results in Characteristic 3

In Section 2.3, we presented the results of [9], which characterize power functions Fr with boomerang uniformity at most 2. However, as observed in [8, 9, 13], functions Fr with smaller boomerang uniformity, namely 0 or 1, appear more frequently in the case p = 3 than for other characteristics. Several of the experimentally observed cases are theoretically explained in the present paper. Motivated by this phenomenon, we conducted a computational study of exponents r for which Fr has boomerang uniformity 0 or 1 when p = 3. Analogously to the classification of APN power functions in [6], we summarize the exponents r for which Fr has boomerang uniformity 0 in Table 4, and Fr has boomerang uniformity 1 in Table 5. In contrast to the case of boomerang uniformity 0, determining whether βFr = 1 requires computing the full BCT, which is computationally much more demanding. Therefore, Table 5 is restricted to n ≤ 7. i It is easy to see that if ri = rpi and Li (x) = xp where 0 < i < n, then i

i

i

(Fr ◦ Li )(x) = (xp )r (1 + χ(xp )) = xrp (1 + χ(x)) = Fri (x), and hence Fri is linearly equivalent to Fr . Moreover, it is obvious that Fr = Fr+ pn −1 . Therefore, in 2

n

the tables of this section, we describe cyclotomic cosets modulo p 2−1 of each class. max δFr (1, b)

Algebraic Degree

(7, 8, 11)

1

4

12

(12, 10, 4)

1

5

[8], Sec. 4.1, 4.2 [13]

5

19 26 61 120

(19, 57, 50, 29, 87) (26, 78, 113, 97, 49) (61, 62, 65, 74, 101) (120, 118, 112, 94, 40)

1 1 1 1

6 6 6 9

Sec. 4.2 Sec. 4.1 [8] [13]

7

55 80 547 656 1092

(55, 165, 495, 392, 83, 249, 747) (80, 240, 720, 1067, 1015, 859, 391) (547, 548, 551, 560, 587, 668, 911) (656, 875, 439, 224, 672, 923, 583) (1092, 1090, 1084, 1066, 1012, 850, 364)

1 1 1 1 1

8 8 8 8 13

Sec. 4.2 Sec. 4.1 [8] Sec. 4.1 [13]

9

163 242 4921 9185 9840

(163, 489, 1467, 4401, 3362, 245, 735, 2205, 6615) (242, 726, 2178, 6534, 9761, 9601, 9121, 7681, 3361) (4921, 4922, 4925, 4934, 4961, 5042, 5285, 6014, 8201) (9185, 7873, 3937, 1970, 5910, 7889, 3985, 2114, 6342) (9840, 9838, 9832, 9814, 9760, 9598, 9112, 7654, 3280)

1 1 1 1 1

10 10 10 10 17

Sec. 4.2 Sec. 4.1 [8] Sec. 4.1 [13]

n

3

r

Cyclotomic Cosets

7

b∈F∗3n

Ref.

Table 4: Fr with boomerang uniformity 0 on F3n when n ≤ 9. For n = 11, 13, due to computational limitations, we instead searched for exponents r with max δFr (1, b) = 1, which is described in Table 6. Our computational results, obtained while con∗

b∈F3n

structing Tables 4 and 5, suggest that, for n ≤ 9, the condition δFr (1, b) ≤ 1 for all b ∈ F∗3n is a 25

max δFr (1, b) ∗

Algebraic Degree

Ref.

(2, 6, 5)

2

3

[9]

2 8 10 13 16 20 31 67 76

(2, 6, 18, 54, 41) (8, 24, 72, 95, 43) (10, 30, 90, 28, 84) (13, 39, 117, 109, 85) (16, 48, 23, 69, 86) (20, 60, 59, 56, 47) (31, 93, 37, 111, 91) (67, 80, 119, 115, 103) (76, 107, 79, 116, 106)

2 2 2 2 3 2 2 2 2

5 5 7 8 5 5 8 8 7

[9]

2 5 107 169 182 1091

(2, 6, 18, 54, 162, 486, 365) (5, 15, 45, 135, 405, 122, 366) (107, 321, 963, 703, 1016, 862, 400) (169, 507, 428, 191, 573, 626, 785) (182, 546, 545, 542, 533, 506, 425) (1091, 1087, 1075, 1039, 931, 607, 728)

2 2 2 3 2 2

7 6 7 8 7 12

n

r

Cyclotomic Cosets

3

2

5

7

b∈F3n

Sec. 5 [9]

Sec. 5

Table 5: Fr with boomerang uniformity 1 on F3n when n ≤ 7. necessary and sufficient condition for Fr to have boomerang uniformity 0, even without the assumption gcd(r, pn − 1) ∈ {1, 2} in Proposition 2.10. Therefore, we also expect that Table 6 provides a complete list of exponents r such that Fr has boomerang uniformity 0 when n = 11, 13. Finally, we remark that we have completed rigorous proofs for all functions identified with boomerang uniformity 0 in our computational results. Table 7 provides a detailed correspondence between the exponents r identified in our numerical search and the theoretical APN classes analyzed in Section 3. This table serves not only to categorize the binomials Fr with boomerang uniformity 0 as discussed in Section 4.1, but also to validate the effectiveness of our generalized parametrization for APN power functions in Section 3. Notably, for larger fields such as n = 11 and n = 13, several exponents are not covered by the more specific constructions in Corollaries 3.8 and 3.9, yet they are successfully accounted for by the broader framework of Proposition 3.3. For example, when n = 11, the exponent r = 74891 arises from Proposition 3.3(ii) with (m, u, n) = (4, 3, 11), which yields r=

7

1 − 3(n−u)m 1 − 332 3n − 1 = = −22597807181120 ≡ 163464 = 74891 + m 4 1+3 1+3 2

(mod 3n − 1).

Conclusion

In this paper, we investigated differential and boomerang properties of binomial functions of the form Fr (x) = xr (1 + χ(x)) over finite fields of characteristic 3. Our main focus was on identifying exponents r for which Fr exhibits very low boomerang uniformity. We showed that Fr attains boomerang 26

n

r 487 728

11 18980 44287 53144 74891 88572 1459 2186 13

398581 408302 490058 744017 778181 797160

Cyclotomic Cosets (487, 1461, 4383, 13149, 39447, 29768, 731, 2193, 6579, 19737, 59211) (728, 2184, 6552, 19656, 58968, 88331, 87847, 86395, 82039, 68971, 29767) (18980, 56940, 82247, 69595, 31639, 6344, 19032, 57096, 82715, 70999, 35851) (44287, 44288, 44291, 44300, 44327, 44408, 44651, 45380, 47567, 54128, 73811) (53144, 70859, 35431, 17720, 53160, 70907, 35575, 18152, 54456, 74795, 47239) (74891, 47527, 54008, 73451, 43207, 41048, 34571, 15140, 45420, 47687, 54488) (88572, 88570, 88564, 88546, 88492, 88330, 87844, 86386, 82012, 68890, 29524) (1459, 4377, 13131, 39393, 118179, 354537, 266450, 2189, 6567, 19701, 59103, 177309, 531927) (2186, 6558, 19674, 59022, 177066, 531198, 796433, 794977, 790609, 777505, 738193, 620257, 266449) (398581, 398582, 398585, 398594, 398621, 398702, 398945, 399674, 401861, 408422, 428105, 487154, 664301) (408302, 427745, 486074, 661061, 388861, 369422, 311105, 136154, 408462, 428225, 487514, 665381, 401821) (490058, 673013, 424717, 476990, 633809, 307105, 124154, 372462, 320225, 163514, 490542, 674465, 429073) (744017, 637729, 318865, 159434, 478302, 637745, 318913, 159578, 478734, 639041, 322801, 171242, 513726) (778181, 740221, 626341, 284701, 56942, 170826, 512478, 740273, 626497, 285169, 58346, 175038, 525114) (797160, 797158, 797152, 797134, 797080, 796918, 796432, 794974, 790600, 777478, 738112, 620014, 265720)

Algebraic Degree

Ref.

12

Sec. 4.2

12

Sec. 4.1

12

Sec. 4.1

12

[8]

12

Sec. 4.1

12

Sec. 4.1

21

[13]

14

Sec. 4.2

14

Sec. 4.1

14

[8]

14

Sec. 4.1

14

Sec. 4.1

14

Sec. 4.1

14

Sec. 4.1

25

[13]

Table 6: Fr with max δFr (1, b) = 1 when n = 11, 13. ∗ b∈F3n

27

n

r

Source

5 7 7 9 9 11 11 11 11 13 13 13 13 13

26 80 656 242 9185 728 18980 53144 74891 2186 408302 490058 744017 778181

Remark 3.10 (i) Remark 3.10 (i) ℓ = 2 in Corollary 3.8 Remark 3.10 (i) ℓ = 2 in Corollary 3.9 Remark 3.10 (i) ℓ = 2 in Corollary 3.8 m = 2, u = 6 in Proposition 3.3 (i) m = 4, u = 3 in Proposition 3.3 (ii) Remark 3.10 (i) m = 4, u = 10 in Proposition 3.3 (i) m = 5, u = 8 in Proposition 3.3 (i) m = 2, u = 7 in Proposition 3.3 (ii) ℓ = 2 in Corollary 3.9

Table 7: Exponents r yielding binomials Fr with boomerang uniformity 0 in Section 4.1, together with their realization within APN exponent constructions described in Section 3. uniformity 0 for two classes of exponents, namely those arising from APN exponents in [23] and n−1 the class r = 2 · 3 2 + 1. We also proved that Fr has boomerang uniformity 1 when r = 3n − 3 for n ≥ 5 odd, and determined its boomerang spectrum. These results demonstrate that, in characteristic 3, the boomerang uniformity of Fr can be strictly smaller than the general bound obtained in [9]. In addition, we provided a detailed analysis of APN exponents from [23]. We established an explicit parametrization of such exponents (Proposition 3.3) and showed that, in characteristic 3, this construction accounts for all APN exponents arising from [23]. Our computational results further indicate that, for n ≤ 13, all APN power functions not listed in Table 1 of [2] can be explained by this parametrization. Moreover, our numerical results suggest that, in characteristic 3, the condition for a binomial Fr to be locally-PN is both necessary and sufficient for it to have boomerang uniformity 0. Finally, we conducted an exhaustive search for small values of n, which supports our theoretical findings and illustrates the distribution of exponents yielding low boomerang uniformity. The results of this paper suggest several directions for future research. First, our numerical results indicate that the locally-PN property appears to be closely related to boomerang uniformity 0 for binomials Fr . Establishing a precise equivalence between these two properties remains an interesting open problem. Second, while our exhaustive search identifies all exponents r yielding boomerang uniformity 0 or 1 for small values of n, several cases with boomerang uniformity 1 appearing in Table 5 are not yet explained by infinite classes. Extending these sporadic examples to infinite families would be a natural continuation of this work. Acknowledgments: This work was supported by the National Research Foundation of Korea (NRF) grant funded by the Korea government (MSIT) (No. RS-2021-NR061794). Soonhak Kwon was supported by Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Education (No. RS-2019-NR040081). 28

References t

[1] C. Blondeau, A. Canteaut and P. Charpin, “Differential Properties of x 7→ x2 −1 ,” IEEE Trans. Inf. Theory, vol. 57, no. 12, pp.8127-8137, Dec. 2011. DOI : 10.1109/TIT.2011.2169129 [2] L. Budaghyan and M. Pal, “Arithmetization-oriented APN permutations,” Des. Codes Cryptogr., vol. 93, no. 4, pp.1067-1088, Apr. 2025. DOI : 10.1007/s10623-024-01487-7 [3] C. Cid, T. Huang, T. Peyrin, Y. Sasaki and L. Song, “Boomerang connectivity table: A new cryptanalysis tool,” EUROCRYPT 2018, Lect. Notes Comput. Sci. 10821, pp.683–714, Mar. 2018. DOI : 10.1007/978-3-319-78375-8 22 [4] L. E. Dickson, “Cyclotomy, Higher Congruences, and Waring’s Problem,” Amer. J. Math., vol. 57, no. 2, pp. 391-424, Apr. 1935. DOI : 10.2307/2371217 [5] H. Dobbertin, T. Helleseth, V. Kumar, and H. Martinsen, “Ternary m-Sequences with ThreeValued Cross-Correlation Function: New Decimations of Welch and Niho Type,” IEEE Trans. Inf. Theory, vol. 47, no. 4, pp. 1473-1481, May 2001. DOI : 10.1109/18.923728 [6] T. Helleseth, C. Rong, and D. Sandberg, “New Families of Almost Perfect Nonlinear Power Mappings,” IEEE Trans. Inf. Theory, vol. 45, no. 2, pp. 475-485, Mar. 1999. DOI : 10.1109/18.748997 [7] Z. Hu, N. Li, L. Xu, X. Zeng and X. Tang, “The differential spectrum and boomerang spectrum of a class of locally-APN functions,” Des. Codes Cryptogr., vol. 91, no. 5, pp.1695-1711, 2023. DOI : 10.1007/s10623-022-01161-w [8] N. Koo and S. Kwon, “On Differential and Boomerang Properties of a Class of Binomials over Finite Fields of Odd Characteristic,” IEEE Trans. Inf. Theory, vol. 72, no. 3, pp.1928–1942, Mar. 2026. DOI : 10.1109/TIT.2026.3657603 [9] N. Koo, S. Kwon, M. Ko, and B. Kim, “Locally-APN Binomials with Low Boomerang Uniformity in Odd Characteristic,” under revision for Finite Fields and Their Applications, preprint available at https://arxiv.org/abs/2512.17603. [10] E. Leducq, “New families of APN functions in characteristic 3 or 5,” in Arithmetic, Geometry, Cryptography and Coding Theory, Contemporary Mathematics, vol. 574, pp.115-123, AMS, 2012. DOI : 10.1090/conm/574/11419 [11] K. Li, L. Qu, B. Sun, and C. Li, “New results about the boomerang uniformity of permutation polynomials,” IEEE Trans. Inf. Theory, vol. 65, no. 11, pp.7542–7553, Nov. 2019. DOI : 10.1109/TIT.2019.2918531 [12] R. Lidl and H. Niederreiter, Finite fields. Cambridge university press, 1997. [13] C. Lyu, X. Wang, and D. Zheng, “A further study on the Ness-Helleseth function,” Finite Fields Appl. vol. 98, Sep. 2024, Art. no. 102453. DOI : 10.1016/j.ffa.2024.102453 [14] S. Mesnager and H. Wu, “The Differential and Boomerang Properties of a Class of Binomials,” IEEE Trans. Inf. Theory, vol. 71, no. 6, pp. 4854-4871, Jun. 2025. DOI : 10.1109/TIT.2025.3550851 29

[15] G. J. Ness and T. Helleseth, “A New Family of Ternary Almost Perfect Nonlinear Mappings,” IEEE Trans. Inf. Theory, vol. 53, no. 7, pp.2581-2586, Jul. 2007. DOI : 10.1109/TIT.2007.899508 [16] K. Nyberg, “Differentially uniform mappings for cryptography,” EUROCRYPT ’93, Lect. Notes Comput. Sci. vol. 765, pp. 55-64, 1994. DOI : 10.1007/3-540-48285-7 6 [17] K. Ren, M. Xiong, and H. Yan, “A note on the differential spectrum of the Ness-Helleseth function,” Adv. Math. Commun., vol. 22, pp. 106-131, Jun. 2026. DOI : 10.3934/amc.2026002 [18] Y. Xia, F. Bao, S. Chen and T. Helleseth, “A direct method for calculating the differential spectrum of an APN power mapping,” Cryptogr. Commun., vol. 18, no. 1, pp.27-44, Jan. 2026. DOI : 10.1007/s12095-024-00764-5 [19] Y. Xia, F. Bao, S. Chen, C. Li and T. Helleseth, “More Differential Properties of the NessHelleseth Function,” IEEE Trans. Inf. Theory, vol. 70, no. 8, pp.6076-6090, Aug. 2024. DOI : 10.1109/TIT.2024.3408882 [20] Y. Xia, C. Li, F. Bao, S. Chen and T. Helleseth, “Further investigation on differential properties of the generalized Ness-Helleseth function,” Des. Codes Cryptogr., vol. 93, no. 6, pp.1549-1573, Jun. 2025. DOI : 10.1007/s10623-024-01525-4 [21] Y. Xia, X. Zhang, C. Lin and T. Helleseth, “The differential spectrum of a ternary power mapping,” Finite Fields Appl. vol. 64, 2020, Art. no. 101660. DOI : 10.1016/j.ffa.2020.101660 [22] X. Zeng, L. Hu, Y. Yang and W. Jiang, “On the Inequivalence of Ness-Helleseth APN Functions,” IACR Cryptol. ePrint Arch., 2007. 2007/379, 2007. [23] Z. Zha and X. Wang, “Power functions with low uniformity on odd characteristic finite fields,” Sci. China Math., vol. 53, no. 8, pp.1931-1940, Aug. 2010. DOI : 10.1007/s11425-010-3149-x.

30

Record · ID 222552 · SHA-256 c3f92532db5e9359
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.