Classifying bent functions by their Cayley graphs
Paul Leopardi ∗ 11 December 2018
Abstract In 1999 Bernasconi and Codenotti noted that the Cayley graph of a bent function is strongly regular. This paper describes the con- cept of extended Cayley equivalence of bent functions, discusses some connections between bent functions, designs, and codes, and explores the relationship between extended Cayley equivalence and extended affine equivalence. SageMath scripts and CoCalc worksheets are used to compute and display some of these relationships, for bent functions up to dimension 8.
1 Introduction
Binary bent functions are important combinatorial objects. Besides the well-known application of bent functions and their generalizations to cryp- tography [2][65, 4.1-4.6], bent functions have well-studied connections to Hadamard difference sets [21], symmetric designs with the symmetric dif- ference property [22, 33], projective two-weight codes [11, 23] and strongly regular graphs. In two papers, Bernasconi and Codenotti [3], and then Bernasconi, Co- denotti and Vanderkam [4] explored some of the connections between bent arXiv:1705.04507v6 [math.CO] 12 Dec 2018 functions and strongly regular graphs. While these papers established that the Cayley graph of a binary bent function (whose value at 0 is 0) is a strongly regular graph with certain parameters, they leave open the question of which strongly regular graphs with these parameters are so obtained.
∗University of Melbourne; Australian Government – Bureau of Meteorology mailto: [email protected]
1 In a recent paper [44], the author found an example of two infinite series of bent functions whose Cayley graphs have the same strongly regular pa- rameters at each dimension, but are not isomorphic if the dimension is 8 or more. Kantor, in 1983 [34], showed that the numbers of non-isomorphic projec- tive linear two weight codes with certain parameters, Hadamard difference sets, and symmetric designs with certain properties, grow at least expo- nentially with dimension. This result suggests that the number of strongly regular graphs obtained as Cayley graphs of bent functions also increases at least exponentially with dimension. A 2003 paper by Cameron [12] considers random strongly regular graphs with given parameters, and outlines some prerequisites for a theory of random strongly regular graphs, including that “the number of non-isomorphic graphs is superexponential in the number of vertices.” The goal of the current paper is to further explore the connections between bent functions, their Cayley graphs, and related combinatorial objects, and in particular to examine the relationship between various equivalence classes of bent functions, in particular, the relationship between the extended affine equivalence classes and equivalence classes defined by isomorphism of Cayley graphs. As well as a theoretical study of bent functions of all dimensions, a computational study is conducted into bent functions of dimension at most 8, using SageMath [63] and CoCalc [58]. The methodology for this study is modelled on experimental mathematics. As stated by Borwein and Devlin [5, pp. 4-5]: What makes experimental mathematics different (as an enter- prise) from the classical conception and practice of mathematics is that the experimental process is regarded not as a precursor to a proof, to be relegated to private notebooks and perhaps stud- ied for historical purposes only after a proof has been obtained. Rather, experimentation is viewed as a significant part of math- ematics in its own right, to be published, considered by others, and (of particular importance) contributing to our overall math- ematical knowledge. The theoretical results listed this paper serve a few purposes. First, in order to classify bent functions by their Cayley graphs, it helps to understand the relationship between Cayley equivalence and other concepts of equiva- lence of bent functions, especially if this helps to cut down the search space needed for the classification. A similar consideration applies to the duals of bent functions. Second, some of the empirical observations made in the classification of bent functions in small dimensions can be explained by these
2 theoretical results. Third, these theoretical results can improve our under- standing of the relationships between bent functions, projective two-weight codes, strongly regular graphs, and symmetric block designs with the sym- metric difference property. In what follows, known results with references are presented as propositions, or sometimes as remarks; and results where the statement or the proof seems to be missing or obscure within the existing literature are presented as lemmas or theorems, with proofs. This paper makes no pretence at being an exhaustive survey, neither should it be construed that the lemmas and theorems listed here make any claim to originality. Even given the current excellent electronic search capa- bilities available, it would be folly to do so given the extensive literature that has been generated on the study of bent functions since the 1960s. Some recent surveys include books by Cusick and Stanica [19], Mesnager [50] and Tokareva [65], and the article by Carlet and Mesnager [16]. The remainder of the paper is organized as follows. Section2 covers the concepts, definitions and known results used later in the paper. Section3 dis- cusses the relationship between bent functions and strongly regular graphs. Section4 introduces various concepts of equivalence of bent functions. Sec- tion5 discusses the relationship between bent functions and block designs. Section6 describes the SageMath and CoCalc code that has been used to obtain the computational results of this paper. Section7 puts the results of this paper in the context of questions that are still open. The appendices contain the proof of one of the properties of quadratic bent functions, and list some of the properties of the equivalence classes of bent functions for dimension up to 8.
2 Preliminaries
This section presents some of the key concepts used in the remainder of the paper. We first examine Boolean functions, then define bent Boolean functions, and finally explore the relationships between bent functions and Hamming weights.
2.1 Boolean functions
Here and in the remainder of the paper, F2 denotes the field of two elements, also known as GF (2). Models of F2 include integer arithmetic modulo 2 (Z/2Z also known as Z2) and Boolean algebra with “exclusive or” as addition and “and” as multiplication.
3 Boolean functions and Reed-Muller codes. Any Boolean function f : n F2 → F2 can be represented as a reduced polynomial in at most n variables over F2 [51, 55][21, Ch. III, Section 2]. This is called the algebraic normal form of f [57, Chapter 5]. Example. In Sage, using sage.crypto.boolean_function, define: from sage.crypto.boolean_function import BooleanFunction f = BooleanFunction([1,1,1,0]) a = f.algebraic_normal_form()
2 The algebraic normal form of the Boolean function f on F2 with variables x0 and x1 and truth table [1, 1, 1, 0] (in lexicographic order) is then a = x0x1 +1 [64, Boolean Functions]. Definition 1. [51][45, Ch. 13, Section 3] [62, 10.5.2] The Reed-Muller code n RM(r, n) consists of those Boolean functions f : F2 → F2 whose algebraic normal form has degree r. Remark. Some texts use the notation R(r, n) or RM(r, 2n) for RM(r, n). Each Reed-Muller code RM(r, n) is a linear subspace of the vector space n of Boolean functions f : F2 → F2. The Reed-Muller code RM(1, n) consists of the 2n+1 affine functions n f(x) = hc, xi + δ for c ∈ F2 , δ ∈ F2 [45, Ch 14, Section 3] [62, 10.5.2].
Bent Boolean functions. Bent Boolean functions can be defined in a number of equivalent ways. The definition used here involves the Walsh Hadamard Transform. Definition 2. [21, Ch. III, Section 2] [45, Ch. 2, Section 3] The Walsh n Hadamard transform of a Boolean function f : F2 → F2 is
X f(y)+hx,yi Wf (x) := (−1) n y∈F2 where
n−1 X hx, yi := xiyi. i=0 Example. Using sage.crypto.boolean_function in Sage, define: from sage.crypto.boolean_function import BooleanFunction f = BooleanFunction([1,1,1,0]) w = f.walsh_hadamard_transform()
4 2 The Walsh Hadamard transform of the Boolean function f on F2 is then w = (−2, −2, −2, 2) as a truth table in lexicographic order [64, Boolean Func- tions].
Remarks.
1. In versions of Sage before 8.2 the walsh_hadamard_transform method has an incorrect sign [Sage trac ticket #23931].
n 2. For Boolean functions f : F2n → F2, where F2n is the finite field on 2 elements, the trace form [29, 3.1] is used to define the Walsh Hadamard transform.
2m Definition 3. A Boolean function f : F2 → F2 is bent if and only if its Walsh Hadamard transform has constant absolute value 2m [21, p. 74] [55, p. 300].
Example. The Boolean function f in the previous example is bent, since its Walsh Hadamard transform has constant absolute value 2.
The remainder of this paper refers to bent Boolean functions simply as bent functions. Remarks.
1. Bent functions can also be characterized as those Boolean functions whose Hamming distance from any affine Boolean function is the max- imum possible [45, Ch. 14 Theorem 6] [49, Theorem 3.3].
2. The property of being a bent function is invariant with respect to the non-degenerate symmetric bilinear form used to define the Walsh Hada- mard transform. That is, for a non-degenerate symmetric bilinear form n×n hx, Syi, where S is a non-degenerate symmetric matrix in F2 , and a Boolean function f : F2n → F2, the Walsh Hadamard transform
X f(y)+hx,Syi W [S]f (x) := (−1) n y∈F2 has constant absolute value 2m if and only if f is bent as per Definition 2m 3[24]. In this sense, given an isomorphism between F2 and F22m 2m as vector spaces over F2, the definition of a bent function on F2 is equivalent to the definition on F22m .
5 n 3. The fact that any symmetric matrix S on F2 can be factorized S = LT L, with the shape of L depending on the rank of S [39] leads to the existence of a basis of F2n for which the trace form is diagonal. 2m This yields an explicit isomorphism between F2 and F22m as vector spaces over F2 for which the two equivalent definitions of bent function coincide [53, p. 860].
The characterization of bent functions given by Definition3 immediately implies the existence of dual functions:
2m Definition 4. For a bent function f : F2 → F2, the function fe, defined by
fe(x) −m (−1) := 2 Wf (x) is called the dual of f [15].
2m Remark 1. The function fe is also a bent function on F2 [45, p. 427] [55, p. 301].
2.2 Weights and weight classes Definition 5. The Hamming weight of a Boolean function is the cardinality n of its support [45, p. 8]. For f on F2
n supp (f) := {x ∈ F2 | f(x) = 1}, wt (f) := |supp (f)| . The remainder of this paper refers to Hamming weights simply as weights. Since a bent function of a given dimension can have only one of two weights, the weights can be used to define equivalence classes of bent func- tions here called weight classes.
2m Definition 6. A bent function f on F2 has weight [21, Theorem 6.2.10] wt (f) = 22m−1 − 2m−1 (weight class number wc (f) = 0), or wt (f) = 22m−1 + 2m−1 (weight class number wc (f) = 1).
Weight classes and dual bent functions. We now note a connection between weight classes and dual bent functions that makes it a little easier to reason about dual bent functions. The following lemma expresses the dual bent function in terms of weight classes. (See also MacWilliams and Sloane [45, p. 414].)
6 2m 2m Lemma 1. For a bent function f : F2 → F2, and x ∈ F2 ,
fe(x) = wc (y 7→ f(y) + hx, yi) .
The proof of Lemma1 relies on the following lemma about weight classes.
2m Lemma 2. For a bent function f : F2 → F2, wc (f) = 2−m wt (f) − 2m−1 + 2−1, so that
wt (f) = 2m wc (f) + 22m−1 − 2m−1.
Proof. If wt (f) = 22m−1 − 2m−1 then
2−m wt (f) − 2m−1 + 2−1 = 2−m(22m−1 − 2m−1) − 2m−1 + 2−1 = 0.
If wt (f) = 22m−1 + 2m−1 then
2−m wt (f) − 2m−1 + 2−1 = 2−m(22m−1 + 2m−1) − 2m−1 + 2−1 = 1.
Proof of Lemma1. Let h(y) := y 7→ f(y) + hx, yi. Then X (−1)fe(x) = 2−m (−1)f(y)+hx,yi 2m y∈F2 −m X X = 2 1 − 1 f(y)+hx,yi=0 f(y)+hx,yi=1 = 2−m 22m − 2 wt (h) = 2m − 21−m wt (h) = 2m − 21−m(2m wc (h) + 22m−1 − 2m−1) = 1 − 2 wc (h) = (−1)wc(h), where we have used Lemma2.
3 Bent functions and strongly regular graphs
This section defines the Cayley graph of a Boolean function, and explores the relationships between bent functions, projective two-weight codes, and strongly regular graphs.
7 3.1 The Cayley graph of a Bent function The Cayley graph of a bent function f with f(0) = 0 is defined in terms of the Cayley graph for a general Boolean function with f with f(0) = 0.
The Cayley graph of a Boolean function.
2m Definition 7. For a Boolean function f : F2 → F2, with f(0) = 0 we consider the simple undirected Cayley graph Cay (f)[3, 3.1] where the vertex 2m 2m set V (Cay (f)) = F2 and for i, j ∈ F2 , the edge (i, j) is in the edge set E(Cay (f)) if and only if f(i + j) = 1. Note especially that in contrast with the paper of Bernasconi and Code- notti [3], this paper defines Cayley graphs only for Boolean functions f with f(0) = 0, since the use of Definition7 with a function f for which f(0) = 1 would result in a graph with loops rather than a simple graph.
Bent functions and strongly regular graphs. We repeat below in Proposition1 the result of Bernasconi and Codenotti [3] that the Cayley graph of a bent function is strongly regular. The following definition is used to fix the notation used in this paper. Definition 8. A simple graph Γ of order v is strongly regular [6,9, 59] with parameters (v, k, λ, µ) if • each vertex has degree k,
• each adjacent pair of vertices has λ common neighbours, and
• each nonadjacent pair of vertices has µ common neighbours. The following proposition summarizes some of the well-known properties of the Cayley graphs of bent functions.
2m Proposition 1. The Cayley graph Cay (f) of a bent function f on F2 with f(0) = 0 is a strongly regular graph with λ = µ [3, Lemma 12]. 2m In addition, any Boolean function f on F2 with f(0) = 0, whose Cayley graph Cay (f) is a strongly regular graph with λ = µ is a bent function [4, Theorem 3] [61, Theorem 3.1]. 2m For a bent function f on F2 , the parameters of Cay (f) as a strongly regular graph are [21, Theorem 6.2.10] [28, Theorem 3.2]
(v, k, λ, µ) =(4m, 22m−1 − 2m−1, 22m−2 − 2m−1, 22m−2 − 2m−1) or (4m, 22m−1 + 2m−1, 22m−2 + 2m−1, 22m−2 + 2m−1).
8 3.2 Bent functions, linear codes and strongly regular graphs Another well known way to obtain a strongly regular graph from a bent function is via a projective two-weight code. This is done via the following definitions.
Projective two-weight binary codes. Definition 9. [7, 11, 20, 23, 66] A two-weight binary code with parameters [n, k, d] is a k dimensional n subspace of F2 with minimum Hamming distance d, such that the set of Hamming weights of the non-zero vectors has size 2. Bouyukliev, Fack, Willems and Winne [7, p. 60] define projective codes as follows. “A generator matrix G of a linear code [n, k] code C is any matrix of rank k (over F2) with rows from C. . . . A linear [n, k] code is called projective if no two columns of a generator matrix G are linearly dependent, i.e., if the columns of G are pairwise different points in a projective (k −1)-dimensional space.” A projective two-weight binary code with parameters [n, k, d] is thus a two-weight binary code with these parameters which is also projective as an [n, k] linear code.
Remark 2. In the case of F2, no two columns of the generator matrix of a projective code are equal.
From bent function to strongly regular graph via a projective two- weight code. There is a standard construction for obtaining a projective two-weight code from a bent function in such a way that the code can be used to define a strongly regular graph. This method is equivalent to the following definition. Definition 10. [23]. See also [11, Definition 2A] 2m 2m×v Let v = 2 , and let X be the matrix in F2 whose columns are the v 2m 2m elements of F2 in lexicographic order. For a Boolean function f : F2 → F2, 2m×n let n = wt (f), and let Y be the matrix in F2 whose columns are the n elements of supp (f) in lexicographic order. That is,
Yi,j = (yj)i, for i ∈ {0, . . . , v − 1}, j ∈ {0, . . . , n − 1},
2m with yj ∈ F2 being an element of supp (f). n The linear code C(f) ⊂ F2 is then given by the span of the 2m rows of n Y within F2 , considered as row vectors.
9 Example. In Sage, using sage.crypto.boolean_function and boolean_cayley_graphs.boolean_linear_code, define: from sage.crypto.boolean_function import BooleanFunction from boolean_cayley_graphs.boolean_linear_code import ( boolean_linear_code) f = BooleanFunction([0,1,0,0,0,1,0,0,1,0,0,0,0,0,1,1]) dim = f.nvariables() Cf = boolean_linear_code(dim, f)
4 The linear code Cf := C(f) of the Boolean function f on F2 then has the following generator matrix in echelon form: 1 0 0 0 1 0 1 0 0 0 . 0 0 1 0 0 0 0 0 1 1 [42][64, Boolean Functions]. Remarks. 1. The linear span of the rows of Y is given by the set of rows of the matrix M := XT Y, where 2m×v X ∈ F2 2m is the matrix whose columns are all v elements of F2 in lexicographic v×n order. Thus M ∈ F2 . 2. Definition 10 is not identical to the generic construction described by Ding [23, Section III] since that definition is for subsets D ⊂ Fv, and uses the trace form, but for the case where D is the support of a Boolean function f : Fv → F2, the two definitions are equivalent. If the bilinear form hx, yi = xT y is replaced in the previous remark by a non-degenerate symmetric bilinear form hx, Syi = xT Sy, where S is a 2m×2m non-degenerate symmetric matrix in F2 , then this would produce the same linear code, since the matrix S, being invertible, produces a 2m T T bijection on F2 and therefore the matrix X S differs from X only by a permutation of rows. Thus by similar arguments to those in Remarks 2 and 3 following Def- inition3, the generic construction described by Ding [23, Section III] is in this case equivalent to Definition 10.
10 When f is a bent function, the linear code C(f) described by Definition 10 has the following properties.
Proposition 2. [23, Corollary 10] 2m For a bent function f : F2 → F2, the linear code C(f) is a projective two-weight binary code, with ( n = wt (f) = 22m−2 − 2m−2, k = 2m if wc (f) = 0. n = wt (f) = 22m−2 + 2m−2, k = 2m if wc (f) = 1.
The possible weights of non-zero code words are: ( 22m−2, 22m−2 − 2m−1 if wc (f) = 0. 22m−2, 22m−2 + 2m−1 if wc (f) = 1.
Proof. We examine Wf , the Walsh Hadamard transform of f.
X hx,yi+f(y) X hx,yi X hx,yi Wf (x) = (−1) = (−1) − 2 (−1) . 2m 2m y∈F2 y∈F2 f(y)=1 But ( X 4m (x = 0) (−1)hx,yi = 2m 0 otherwise, y∈F2 as per the Sylvester Hadamard matrices. So, for x 6= 0,
X hx,yi Wf (x) = −2 (−1) , f(y)=1 so
X hx,yi X (−1) = wt (f) − 2 1 = −Wf (x)/2. f(y)=1 f(y)=1 hx,yi=1
But X 1 = wt xT Y , f(y)=1 hx,yi=1
11 the weight of the code word of C(f) corresponding to x. So