Full-Cycle 8 × 8 S-Box from Bijective Trims of a 9D APN Permutation with Coordinate-Optimized DSAC and BIC
Rida Samee, Abdul Ghafoor, Maemoona Kayani, Ayesha Khalid, Muhammad Tayyab AliThis paper presents an 8×8 S-box construction based on bijective trims of the compositional inverse of a nine-dimensional quadratic APN permutation. An exhaustive evaluation of 1,566,726 parameter combinations yields 3066 bijective trims, all with differential uniformity 4, vectorial nonlinearity 112, maximum linear bias 2−4 and Boolean algebraic degree 5. The selected representative S-box exhibits desirable cryptographic and structural properties, including algebraic immunity 4, full-cycle permutation behavior, absence of fixed and opposite fixed points, and practical implementation feasibility. A randomized linear-conjugation search enables the selection of a coordinate-optimized representation with lower DSAC and BIC than the canonical AES byte mapping under the adopted measures. In the matched one-million-matrix control, however, 22,911 AES conjugates (2.2911%) and only one conjugate (0.0001%) of the fixed retained trim satisfied both selected thresholds, so the experiment does not establish an advantage over AES under the same coordinate-optimization search. The selected S-box achieves a single cycle of length 256, mean SAC of 128.125, DSAC of 392, BIC of 0.129412, and maximum differential probability 2−6. Compared with the AES S-box, the selected S* matches its differential uniformity, vectorial nonlinearity, and maximum linear bias, while its Boolean algebraic degree is 5, compared with 7 for AES, and its boomerang uniformity is 18 compared with 6 for AES. For direct construction-based software evaluation, the proposed S* required approximately 2.06 times the execution time of the AES direct-arithmetic implementation on the tested platform, reflecting an implementation-specific trade-off for on-the-fly computation.