Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Bent function</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Bent_function"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/ext.math.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Bent_function rootpage-Bent_function skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Bent function</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">


<p>In the <a href="Mathematics" title="Mathematics">mathematical</a> field of <a href="Combinatorics" title="Combinatorics">combinatorics</a>, a <b>bent function</b> is a <a href="Boolean_function" title="Boolean function">Boolean function</a> that is maximally non-linear; it is as different as possible from the set of all <a href="Linear_map" title="Linear map">linear</a> and <a href="Affine_function" class="mw-redirect" title="Affine function">affine functions</a> when measured by <a href="Hamming_distance" title="Hamming distance">Hamming distance</a> between <a href="Truth_table" title="Truth table">truth tables</a>. Concretely, this means the maximum <a href="Correlation_coefficient" title="Correlation coefficient">correlation</a> between the output of the function and a linear function is minimal. In addition, the <a href="Boolean_derivative" class="mw-redirect" title="Boolean derivative">derivatives</a> of a bent function are <a href="Balanced_Boolean_function" title="Balanced Boolean function">balanced</a> Boolean functions, so for any change in the input variables there is a 50 percent chance that the output value will change.
</p><p>The maximal nonlinearity means approximating a bent function by an affine (linear) function is hard, a useful property in the defence against <a href="Linear_cryptanalysis" title="Linear cryptanalysis">linear cryptanalysis</a>. In addition, detecting a change in the output of the function yields no information about what change occurred in the inputs, making the function immune to <a href="Differential_cryptanalysis" title="Differential cryptanalysis">differential cryptanalysis</a>.
</p><p>Bent functions were defined and named in the 1960s by Oscar Rothaus in research not published until 1976.<sup id="cite_ref-rothaus_1-0" class="reference"><a href="#cite_note-rothaus-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> They have been extensively studied for their applications in <a href="Cryptography" title="Cryptography">cryptography</a>, but have also been applied to <a href="Spread_spectrum" title="Spread spectrum">spread spectrum</a>, <a href="Coding_theory" title="Coding theory">coding theory</a>, and <a href="Combinatorial_design" title="Combinatorial design">combinatorial design</a>. The definition can be extended in several ways, leading to different classes of generalized bent functions that share many of the useful properties of the original.
</p><p>It is known that V. A. Eliseev and O. P. Stepchenkov studied bent functions, which they called <i>minimal functions</i>, in the USSR in 1962.<sup id="cite_ref-bent-book_2-0" class="reference"><a href="#cite_note-bent-book-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> However, their results have still not been declassified.
</p><p>Bent functions are also known as <b>perfectly nonlinear</b> (<b>PN</b>) Boolean functions. Certain functions that are as close as possible to perfect nonlinearity (e.g. for functions of an odd number of bits, or vectorial functions) are known as <b>almost perfectly nonlinear</b> (<b>APN</b>).<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Walsh_transform">Walsh transform</h2></div>
<p>Bent functions are defined in terms of the <a href="Walsh_transform" class="mw-redirect" title="Walsh transform">Walsh transform</a>. The Walsh transform of a Boolean function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}</annotation>
</semantics>
</math></span><img src="./f72bcef1f7d9d6fc46aaa37bb2ae2bcd07e9b2e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:12.203ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}" loading="lazy"></span> is the function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}:\mathbb {Z} _{2}^{n}\to \mathbb {Z} }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}:\mathbb {Z} _{2}^{n}\to \mathbb {Z} }</annotation>
</semantics>
</math></span><img src="./8c6b7befe98febdc1c37297ca26287434fd9f7e6.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:11.569ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}:\mathbb {Z} _{2}^{n}\to \mathbb {Z} }" loading="lazy"></span> given by
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)=\sum _{\scriptstyle {x\in \mathbb {Z} _{2}^{n}}}(-1)^{f(x)+a\cdot x},}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<munder>
<mo>∑<!-- ∑ --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="false" scriptlevel="1">
<mrow class="MJX-TeXAtom-ORD">
<mi>x</mi>
<mo>∈<!-- ∈ --></mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
</mrow>
</mstyle>
</mrow>
</munder>
<mo stretchy="false">(</mo>
<mo>−<!-- − --></mo>
<mn>1</mn>
<msup>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>+</mo>
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mi>x</mi>
</mrow>
</msup>
<mo>,</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)=\sum _{\scriptstyle {x\in \mathbb {Z} _{2}^{n}}}(-1)^{f(x)+a\cdot x},}</annotation>
</semantics>
</math></span><img src="./326118f8089440b38a66a530dee45fca991eeb6e.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -3.671ex; width:24.263ex; height:6.176ex;" alt="{\displaystyle {\hat {f}}(a)=\sum _{\scriptstyle {x\in \mathbb {Z} _{2}^{n}}}(-1)^{f(x)+a\cdot x},}" loading="lazy"></span></dd></dl>
<p>where <span class="nowrap"><i>a</i> · <i>x</i> = <i>a</i><sub>1</sub><i>x</i><sub>1</sub> + <i>a</i><sub>2</sub><i>x</i><sub>2</sub> + … + <i>a</i><sub><i>n</i></sub><i>x</i><sub><i>n</i></sub> (mod 2)</span> is the <a href="Dot_product" title="Dot product">dot product</a> in <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span>.<sup id="cite_ref-bool_4-0" class="reference"><a href="#cite_note-bool-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Alternatively, let <span class="nowrap"><i>S</i><sub>0</sub>(<i>a</i>) = { <i>x</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span>&nbsp;: <i>f</i>(<i>x</i>) = <i>a</i> · <i>x</i> }</span> and <span class="nowrap"><i>S</i><sub>1</sub>(<i>a</i>) = { <i>x</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span>&nbsp;: <i>f</i>(<i>x</i>) ≠ <i>a</i> · <i>x</i> }</span>. Then <span class="nowrap">|<span class="nowrap" style="padding-left:0.1em; padding-right:0.1em;"><i>S</i><sub>0</sub>(<i>a</i>)</span>| + |<span class="nowrap" style="padding-left:0.1em; padding-right:0.1em;"><i>S</i><sub>1</sub>(<i>a</i>)</span>| = 2<sup><i>n</i></sup></span> and hence
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)=\left|S_{0}(a)\right|-\left|S_{1}(a)\right|=2\left|S_{0}(a)\right|-2^{n}.}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mrow>
<mo>|</mo>
<mrow>
<msub>
<mi>S</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
<mo>|</mo>
</mrow>
<mo>−<!-- − --></mo>
<mrow>
<mo>|</mo>
<mrow>
<msub>
<mi>S</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
<mo>|</mo>
</mrow>
<mo>=</mo>
<mn>2</mn>
<mrow>
<mo>|</mo>
<mrow>
<msub>
<mi>S</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
<mo>|</mo>
</mrow>
<mo>−<!-- − --></mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>.</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)=\left|S_{0}(a)\right|-\left|S_{1}(a)\right|=2\left|S_{0}(a)\right|-2^{n}.}</annotation>
</semantics>
</math></span><img src="./d8b8d86d031813e79c9d907626b3521199916c05.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:41.629ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}(a)=\left|S_{0}(a)\right|-\left|S_{1}(a)\right|=2\left|S_{0}(a)\right|-2^{n}.}" loading="lazy"></span></dd></dl>
<p>For any Boolean function <i>f</i> and <span class="nowrap"><i>a</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span></span>, the transform lies in the range
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle -2^{n}\leq {\hat {f}}(a)\leq 2^{n}.}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo>−<!-- − --></mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>≤<!-- ≤ --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>≤<!-- ≤ --></mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>.</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle -2^{n}\leq {\hat {f}}(a)\leq 2^{n}.}</annotation>
</semantics>
</math></span><img src="./c90bff823cc4abba01cffa87c5e52309e7a54440.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:18.152ex; height:3.343ex;" alt="{\displaystyle -2^{n}\leq {\hat {f}}(a)\leq 2^{n}.}" loading="lazy"></span></dd></dl>
<p>Moreover, the linear function <span class="nowrap"><i>f</i><sub>0</sub>(<i>x</i>) = <i>a</i> · <i>x</i></span> and the affine function <span class="nowrap"><i>f</i><sub>1</sub>(<i>x</i>) = <i>a</i> · <i>x</i> + 1</span> correspond to the two extreme cases, since
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}_{0}(a)=2^{n},~{\hat {f}}_{1}(a)=-2^{n}.}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>,</mo>
<mtext>&nbsp;</mtext>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mo>−<!-- − --></mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>.</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}_{0}(a)=2^{n},~{\hat {f}}_{1}(a)=-2^{n}.}</annotation>
</semantics>
</math></span><img src="./7925cd6bb14bbae136c0ef8410f09665b08679ad.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:26.613ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}_{0}(a)=2^{n},~{\hat {f}}_{1}(a)=-2^{n}.}" loading="lazy"></span></dd></dl>
<p>Thus, for each <span class="nowrap"><i>a</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span></span> the value of <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)}</annotation>
</semantics>
</math></span><img src="./bc9afb498eab2f0fe28cadb753fa5393f3a97260.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:4.738ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}(a)}" loading="lazy"></span> characterizes where the function <i>f</i>(<i>x</i>) lies in the range from <i>f</i><sub>0</sub>(<i>x</i>) to <i>f</i><sub>1</sub>(<i>x</i>).
</p>
<div class="mw-heading mw-heading2"><h2 id="Definition_and_properties">Definition and properties</h2></div>
<p>Rothaus defined a <b>bent function</b> as a Boolean function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}</annotation>
</semantics>
</math></span><img src="./f72bcef1f7d9d6fc46aaa37bb2ae2bcd07e9b2e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:12.203ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}" loading="lazy"></span> whose <a href="Walsh_transform" class="mw-redirect" title="Walsh transform">Walsh transform</a> has constant <a href="Absolute_value" title="Absolute value">absolute value</a>. Bent functions are in a sense equidistant from all the affine functions, so they are equally hard to approximate with any affine function.
</p><p>The simplest examples of bent functions, written in <a href="Algebraic_normal_form" title="Algebraic normal form">algebraic normal form</a>, are <span class="nowrap"><i>F</i>(<i>x</i><sub>1</sub>, <i>x</i><sub>2</sub>) = <i>x</i><sub>1</sub><i>x</i><sub>2</sub></span> and <span class="nowrap"><i>G</i>(<i>x</i><sub>1</sub>, <i>x</i><sub>2</sub>, <i>x</i><sub>3</sub>, <i>x</i><sub>4</sub>) = <i>x</i><sub>1</sub><i>x</i><sub>2</sub> ⊕ <i>x</i><sub>3</sub><i>x</i><sub>4</sub></span>. This pattern continues: <span class="nowrap"><i>x</i><sub>1</sub><i>x</i><sub>2</sub> ⊕ <i>x</i><sub>3</sub><i>x</i><sub>4</sub> ⊕ … ⊕ <i>x</i><sub><i>n</i>−1</sub><i>x</i><sub><i>n</i></sub></span> is a bent function <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}</annotation>
</semantics>
</math></span><img src="./a35bb52b99fde3ae4e8ceff2746aa12ec70204f3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:8.987ex; height:2.843ex;" alt="{\displaystyle \mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}}" loading="lazy"></span> for every even <i>n</i>, but there is a wide variety of other bent functions as <i>n</i> increases.<sup id="cite_ref-nonlin_5-0" class="reference"><a href="#cite_note-nonlin-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> The sequence of values (−1)<sup><i>f</i>(<i>x</i>)</sup>, with <span class="nowrap"><i>x</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span></span> taken in <a href="Lexicographical_order" class="mw-redirect" title="Lexicographical order">lexicographical order</a>, is called a <b>bent sequence</b>; bent functions and bent sequences have equivalent properties. In this ±1 form, the Walsh transform is easily computed as
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)=W\left(2^{n}\right)(-1)^{f(a)},}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mi>W</mi>
<mrow>
<mo>(</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msup>
<mo>)</mo>
</mrow>
<mo stretchy="false">(</mo>
<mo>−<!-- − --></mo>
<mn>1</mn>
<msup>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
</msup>
<mo>,</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)=W\left(2^{n}\right)(-1)^{f(a)},}</annotation>
</semantics>
</math></span><img src="./8cefcb361f0feeedf0d32455866cae929f1b3617.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:23.948ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}(a)=W\left(2^{n}\right)(-1)^{f(a)},}" loading="lazy"></span></dd></dl>
<p>where <i>W</i>(2<sup><i>n</i></sup>) is the natural-ordered <a href="Walsh_matrix" title="Walsh matrix">Walsh matrix</a> and the sequence is treated as a <a href="Column_vector" class="mw-redirect" title="Column vector">column vector</a>.<sup id="cite_ref-dual_6-0" class="reference"><a href="#cite_note-dual-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>Rothaus proved that bent functions exist only for even <i>n</i>, and that for a bent function <i>f</i>, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \left|{\hat {f}}(a)\right|=2^{n/2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow>
<mo>|</mo>
<mrow>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
<mo>|</mo>
</mrow>
<mo>=</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>2</mn>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \left|{\hat {f}}(a)\right|=2^{n/2}}</annotation>
</semantics>
</math></span><img src="./a6d8e06764b3a51787c2602dfa6c10e6386dd513.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.338ex; width:13.155ex; height:3.843ex;" alt="{\displaystyle \left|{\hat {f}}(a)\right|=2^{n/2}}" loading="lazy"></span> for all <span class="nowrap"><i>a</i> ∈ <b>Z</b><span class="nowrap"><span style="display:inline-block;margin-bottom:-0.3em;vertical-align:-0.4em;line-height:1.2em;font-size:80%;text-align:left"><sup style="font-size:inherit;line-height:inherit;vertical-align:baseline"><i>n</i></sup><br><sub style="font-size:inherit;line-height:inherit;vertical-align:baseline">2</sub></span></span></span>.<sup id="cite_ref-bool_4-1" class="reference"><a href="#cite_note-bool-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> In fact, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)=2^{n/2}(-1)^{g(a)}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>2</mn>
</mrow>
</msup>
<mo stretchy="false">(</mo>
<mo>−<!-- − --></mo>
<mn>1</mn>
<msup>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>g</mi>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)=2^{n/2}(-1)^{g(a)}}</annotation>
</semantics>
</math></span><img src="./89b789e783a38c130e1545486f0f9eda6f2ca546.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:19.812ex; height:3.343ex;" alt="{\displaystyle {\hat {f}}(a)=2^{n/2}(-1)^{g(a)}}" loading="lazy"></span>, where <i>g</i> is also bent. In this case, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {g}}(a)=2^{n/2}(-1)^{f(a)}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>g</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>2</mn>
</mrow>
</msup>
<mo stretchy="false">(</mo>
<mo>−<!-- − --></mo>
<mn>1</mn>
<msup>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {g}}(a)=2^{n/2}(-1)^{f(a)}}</annotation>
</semantics>
</math></span><img src="./679a0060f33d8250d8e10b8e649c2855f65dbc34.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:19.459ex; height:3.343ex;" alt="{\displaystyle {\hat {g}}(a)=2^{n/2}(-1)^{f(a)}}" loading="lazy"></span>, so <i>f</i> and <i>g</i> are considered <a href="Duality_(mathematics)" title="Duality (mathematics)">dual</a> functions.<sup id="cite_ref-dual_6-1" class="reference"><a href="#cite_note-dual-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>
</p><p>Every bent function has a <a href="Hamming_weight" title="Hamming weight">Hamming weight</a> (number of times it takes the value 1) of <span class="nowrap">2<sup><i>n</i>−1</sup> ± 2<sup><i>n</i>/2−1</sup></span>, and in fact agrees with any affine function at one of those two numbers of points. So the <i>nonlinearity</i> of <i>f</i> (minimum number of times it equals any affine function) is <span class="nowrap">2<sup><i>n</i>−1</sup> − 2<sup><i>n</i>/2−1</sup></span>, the maximum possible. Conversely, any Boolean function with nonlinearity <span class="nowrap">2<sup><i>n</i>−1</sup> − 2<sup><i>n</i>/2−1</sup></span> is bent.<sup id="cite_ref-bool_4-2" class="reference"><a href="#cite_note-bool-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> The <a href="Degree_of_a_polynomial" title="Degree of a polynomial">degree</a> of <i>f</i> in algebraic normal form (called the <i>nonlinear order</i> of <i>f</i>) is at most <style data-mw-deduplicate="TemplateStyles:r1214402035">
/* start https://en.wikipedia.org/ */


.mw-parser-output .sfrac{white-space:nowrap}.mw-parser-output .sfrac.tion,.mw-parser-output .sfrac .tion{display:inline-block;vertical-align:-0.5em;font-size:85%;text-align:center}.mw-parser-output .sfrac .num{display:block;line-height:1em;margin:0.0em 0.1em;border-bottom:1px solid}.mw-parser-output .sfrac .den{display:block;line-height:1em;margin:0.1em 0.1em}.mw-parser-output .sr-only{border:0;clip:rect(0,0,0,0);clip-path:polygon(0px 0px,0px 0px,0px 0px);height:1px;margin:-1px;overflow:hidden;padding:0;position:absolute;width:1px}


/* end https://en.wikipedia.org/ */
</style><span class="sfrac">⁠<span class="tion"><span class="num"><i>n</i></span><span class="sr-only">/</span><span class="den">2</span></span>⁠</span> (for <span class="nowrap"><i>n</i> &gt; 2</span>).<sup id="cite_ref-nonlin_5-1" class="reference"><a href="#cite_note-nonlin-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>Although bent functions are vanishingly rare among Boolean functions of many variables, they come in many different kinds. There has been detailed research into special classes of bent functions, such as the <a href="Homogeneous_polynomial" title="Homogeneous polynomial">homogeneous</a> ones<sup id="cite_ref-homo_7-0" class="reference"><a href="#cite_note-homo-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> or those arising from a <a href="Monomial" title="Monomial">monomial</a> over a <a href="Finite_field" title="Finite field">finite field</a>,<sup id="cite_ref-mono_8-0" class="reference"><a href="#cite_note-mono-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> but so far the bent functions have defied all attempts at a complete enumeration or classification.
</p>
<div class="mw-heading mw-heading2"><h2 id="Constructions">Constructions</h2></div>
<p>There are several types of constructions for bent functions.<sup id="cite_ref-bent-book_2-1" class="reference"><a href="#cite_note-bent-book-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p>
<ul><li>Combinatorial constructions: iterative constructions, Maiorana–McFarland construction, partial spreads, Dillon's and Dobbertin's bent functions, minterm bent functions, bent iterative functions</li>
<li>Algebraic constructions: monomial bent functions with exponents of Gold, Dillon, Kasami, Canteaut–Leander and Canteaut–Charpin–Kuyreghyan; Niho bent functions, etc.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Applications">Applications</h2></div>
<p>As early as 1982 it was discovered that <a href="Maximum_length_sequence" title="Maximum length sequence">maximum length sequences</a> based on bent functions have <a href="Cross-correlation" title="Cross-correlation">cross-correlation</a> and <a href="Autocorrelation" title="Autocorrelation">autocorrelation</a> properties rivalling those of the <a href="Gold_code" title="Gold code">Gold codes</a> and <a href="Kasami_code" title="Kasami code">Kasami codes</a> for use in <a href="CDMA" class="mw-redirect" title="CDMA">CDMA</a>.<sup id="cite_ref-seq_9-0" class="reference"><a href="#cite_note-seq-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> These sequences have several applications in <a href="Spread_spectrum" title="Spread spectrum">spread spectrum</a> techniques.
</p><p>The properties of bent functions are naturally of interest in modern digital <a href="Cryptography" title="Cryptography">cryptography</a>, which seeks to obscure relationships between input and output. By 1988 Forré recognized that the Walsh transform of a function can be used to show that it satisfies the <a href="Strict_avalanche_criterion" class="mw-redirect" title="Strict avalanche criterion">strict avalanche criterion</a> (SAC) and higher-order generalizations, and recommended this tool to select candidates for good <a href="S-box" title="S-box">S-boxes</a> achieving near-perfect <a href="Confusion_and_diffusion" title="Confusion and diffusion">diffusion</a>.<sup id="cite_ref-spectral_10-0" class="reference"><a href="#cite_note-spectral-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> Indeed, the functions satisfying the SAC to the highest possible order are always bent.<sup id="cite_ref-sac_11-0" class="reference"><a href="#cite_note-sac-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> Furthermore, the bent functions are as far as possible from having what are called <i>linear structures</i>, nonzero vectors a such that <span class="nowrap"><i>f</i>(<i>x</i> + <i>a</i>) + <i>f</i>(<i>x</i>)</span> is a constant. In the language of <a href="Differential_cryptanalysis" title="Differential cryptanalysis">differential cryptanalysis</a> (introduced after this property was discovered) the <i>derivative</i> of a bent function <i>f</i> at every nonzero point <i>a</i> (that is, <span class="nowrap"><i>f</i><sub><i>a</i></sub>(<i>x</i>) = <i>f</i>(<i>x</i> + <i>a</i>) + <i>f</i>(<i>x</i>))</span> is a <a href="Balanced_Boolean_function" title="Balanced Boolean function"><i>balanced</i> Boolean function</a>, taking on each value exactly half of the time. This property is called <i>perfect nonlinearity</i>.<sup id="cite_ref-nonlin_5-2" class="reference"><a href="#cite_note-nonlin-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>
</p><p>Given such good diffusion properties, apparently perfect resistance to differential cryptanalysis, and resistance by definition to <a href="Linear_cryptanalysis" title="Linear cryptanalysis">linear cryptanalysis</a>, bent functions might at first seem the ideal choice for secure cryptographic functions such as S-boxes. Their fatal flaw is that they fail to be balanced. In particular, an invertible S-box cannot be constructed directly from bent functions, and a <a href="Stream_cipher" title="Stream cipher">stream cipher</a> using a bent combining function is vulnerable to a <a href="Correlation_attack" title="Correlation attack">correlation attack</a>. Instead, one might start with a bent function and randomly complement appropriate values until the result is balanced. The modified function still has high nonlinearity, and as such functions are very rare the process should be much faster than a brute-force search.<sup id="cite_ref-nonlin_5-3" class="reference"><a href="#cite_note-nonlin-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> But functions produced in this way may lose other desirable properties, even failing to satisfy the SAC – so careful testing is necessary.<sup id="cite_ref-sac_11-1" class="reference"><a href="#cite_note-sac-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> A number of cryptographers have worked on techniques for generating balanced functions that preserve as many of the good cryptographic qualities of bent functions as possible.<sup id="cite_ref-nyberg_12-0" class="reference"><a href="#cite_note-nyberg-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-highly_13-0" class="reference"><a href="#cite_note-highly-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-cast_14-0" class="reference"><a href="#cite_note-cast-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p><p>Some of this theoretical research has been incorporated into real cryptographic algorithms. The <i>CAST</i> design procedure, used by <a href="Carlisle_Adams" title="Carlisle Adams">Carlisle Adams</a> and <a href="Stafford_Tavares" title="Stafford Tavares">Stafford Tavares</a> to construct the S-boxes for the <a href="Block_ciphers" class="mw-redirect" title="Block ciphers">block ciphers</a> <a href="CAST-128" title="CAST-128">CAST-128</a> and <a href="CAST-256" title="CAST-256">CAST-256</a>, makes use of bent functions.<sup id="cite_ref-cast_14-1" class="reference"><a href="#cite_note-cast-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> The <a href="Cryptographic_hash_function" title="Cryptographic hash function">cryptographic hash function</a> <a href="HAVAL" title="HAVAL">HAVAL</a> uses Boolean functions built from representatives of all four of the <a href="Equivalence_class" title="Equivalence class">equivalence classes</a> of bent functions on six variables.<sup id="cite_ref-haval_15-0" class="reference"><a href="#cite_note-haval-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup> The stream cipher <a href="Grain_(cipher)" title="Grain (cipher)">Grain</a> uses an <a href="NLFSR" class="mw-redirect" title="NLFSR">NLFSR</a> whose nonlinear feedback polynomial is, by design, the sum of a bent function and a linear function.<sup id="cite_ref-grain_16-0" class="reference"><a href="#cite_note-grain-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Generalizations">Generalizations</h2></div>
<p>More than 25 different generalizations of bent functions are described in Tokareva's 2015 monograph.<sup id="cite_ref-bent-book_2-2" class="reference"><a href="#cite_note-bent-book-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> There are algebraic generalizations (<i>q</i>-valued bent functions, <i>p</i>-ary bent functions, bent functions over a finite field, generalized Boolean bent functions of Schmidt, bent functions from a finite Abelian group into the set of complex numbers on the unit circle, bent functions from a finite Abelian group into a finite Abelian group, non-Abelian bent functions, vectorial G-bent functions, multidimensional bent functions on a finite Abelian group), combinatorial generalizations (symmetric bent functions, homogeneous bent functions, rotation symmetric bent functions, normal bent functions, self-dual and anti-self-dual bent functions, partially defined bent functions, plateaued functions, Z-bent functions and quantum bent functions) and cryptographic generalizations (semi-bent functions, balanced bent functions, partially bent functions, hyper-bent functions, bent functions of higher order, <i>k</i>-bent functions).
</p><p>The most common class of <i>generalized bent functions</i> is the <a href="Modular_arithmetic" title="Modular arithmetic">mod <i>m</i></a> type, <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}</annotation>
</semantics>
</math></span><img src="./7b1675883dc864fcda4cc16acfc39c35cde2ca9f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:13.281ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}" loading="lazy"></span> such that
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\hat {f}}(a)=\sum _{x\in \mathbb {Z} _{m}^{n}}e^{{\frac {2\pi i}{m}}(f(x)-a\cdot x)}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<munder>
<mo>∑<!-- ∑ --></mo>
<mrow class="MJX-TeXAtom-ORD">
<mi>x</mi>
<mo>∈<!-- ∈ --></mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
</mrow>
</munder>
<msup>
<mi>e</mi>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mfrac>
<mrow>
<mn>2</mn>
<mi>π<!-- π --></mi>
<mi>i</mi>
</mrow>
<mi>m</mi>
</mfrac>
</mrow>
<mo stretchy="false">(</mo>
<mi>f</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>−<!-- − --></mo>
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\hat {f}}(a)=\sum _{x\in \mathbb {Z} _{m}^{n}}e^{{\frac {2\pi i}{m}}(f(x)-a\cdot x)}}</annotation>
</semantics>
</math></span><img src="./724f8f37b2657807ae827b5815dde2882e04d4fe.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -3.505ex; width:24.685ex; height:6.509ex;" alt="{\displaystyle {\hat {f}}(a)=\sum _{x\in \mathbb {Z} _{m}^{n}}e^{{\frac {2\pi i}{m}}(f(x)-a\cdot x)}}" loading="lazy"></span></dd></dl>
<p>has constant absolute value <i>m</i><sup><i>n</i>/2</sup>. Perfect nonlinear functions <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}</annotation>
</semantics>
</math></span><img src="./7b1675883dc864fcda4cc16acfc39c35cde2ca9f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:13.281ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}" loading="lazy"></span>, those such that for all nonzero <i>a</i>, <span class="nowrap"><i>f</i>(<i>x</i> + <i>a</i>) − <i>f</i>(<i>a</i>)</span> takes on each value <span class="nowrap"><i>m</i><sup><i>n</i>−1</sup></span> times, are generalized bent. If <i>m</i> is <a href="Prime_number" title="Prime number">prime</a>, the converse is true. In most cases only prime <i>m</i> are considered. For odd prime <i>m</i>, there are generalized bent functions for every positive <i>n</i>, even and odd. They have many of the same good cryptographic properties as the binary bent functions.<sup id="cite_ref-nyberg2_17-0" class="reference"><a href="#cite_note-nyberg2-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-gbf2_18-0" class="reference"><a href="#cite_note-gbf2-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p><b>Semi-bent functions</b> are an odd-order counterpart to bent functions. A semi-bent function is <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>m</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}</annotation>
</semantics>
</math></span><img src="./7b1675883dc864fcda4cc16acfc39c35cde2ca9f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:13.281ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{m}^{n}\to \mathbb {Z} _{m}}" loading="lazy"></span> with <i>n</i> odd, such that <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \left|{\hat {f}}\right|}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow>
<mo>|</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>f</mi>
<mo stretchy="false">^<!-- ^ --></mo>
</mover>
</mrow>
</mrow>
<mo>|</mo>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \left|{\hat {f}}\right|}</annotation>
</semantics>
</math></span><img src="./8850d90414a5f27caf916f61d1bb50efc62989ad.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.338ex; width:2.993ex; height:3.843ex;" alt="{\displaystyle \left|{\hat {f}}\right|}" loading="lazy"></span> takes only the values 0 and <i>m</i><sup>(<i>n</i>+1)/2</sup>. They also have good cryptographic characteristics, and some of them are balanced, taking on all possible values equally often.<sup id="cite_ref-semi_19-0" class="reference"><a href="#cite_note-semi-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>The <b>partially bent functions</b> form a large class defined by a condition on the Walsh transform and autocorrelation functions. All affine and bent functions are partially bent. This is in turn a proper subclass of the <i>plateaued functions</i>.<sup id="cite_ref-plat_20-0" class="reference"><a href="#cite_note-plat-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p><p>The idea behind the <b>hyper-bent functions</b> is to maximize the minimum distance to <i>all</i> Boolean functions coming from <a href="Bijection" title="Bijection">bijective</a> monomials on the finite field GF(2<sup><i>n</i></sup>), not just the affine functions. For these functions this distance is constant, which may make them resistant to an <a href="Interpolation_attack" title="Interpolation attack">interpolation attack</a>.
</p><p>Other related names have been given to cryptographically important classes of functions <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}^{n}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>f</mi>
<mo>:</mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
<mo stretchy="false">→<!-- → --></mo>
<msubsup>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">Z</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mi>n</mi>
</mrow>
</msubsup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}^{n}}</annotation>
</semantics>
</math></span><img src="./017a45a556874f7e20867bf0a7adc6818cd18ee0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:12.367ex; height:2.843ex;" alt="{\displaystyle f:\mathbb {Z} _{2}^{n}\to \mathbb {Z} _{2}^{n}}" loading="lazy"></span>, such as <b>almost bent functions</b> and <b>crooked functions</b>. While not bent functions themselves (these are not even Boolean functions), they are closely related to the bent functions and have good nonlinearity properties.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Correlation_immunity" title="Correlation immunity">Correlation immunity</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist reflist-columns references-column-width reflist-columns-2">
<ol class="references">
<li id="cite_note-rothaus-1"><span class="mw-cite-backlink"><b><a href="#cite_ref-rothaus_1-0">^</a></b></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><cite id="CITEREFO._S._Rothaus1976" class="citation journal cs1">O. S. Rothaus (May 1976). <a rel="nofollow" class="external text" href="https://doi.org/10.1016%2F0097-3165%2876%2990024-8">"On "Bent" Functions"</a>. <i>Journal of Combinatorial Theory, Series A</i>. <b>20</b> (3): <span class="nowrap">300–</span>305. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1016%2F0097-3165%2876%2990024-8">10.1016/0097-3165(76)90024-8</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0097-3165">0097-3165</a>.</cite></span>
</li>
<li id="cite_note-bent-book-2"><span class="mw-cite-backlink">^ <a href="#cite_ref-bent-book_2-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-bent-book_2-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-bent-book_2-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFN._Tokareva2015" class="citation book cs1">N. Tokareva (2015). <i>Bent functions: results and applications to cryptography</i>. Academic Press. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9780128023181</bdi>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFBlondeauNyberg2015" class="citation journal cs1">Blondeau; Nyberg (2015-03-01). <a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.ffa.2014.10.007">"Perfect nonlinear functions and cryptography"</a>. <i>Finite Fields and Their Applications</i>. <b>32</b>: <span class="nowrap">120–</span>147. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.ffa.2014.10.007">10.1016/j.ffa.2014.10.007</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1071-5797">1071-5797</a>.</cite></span>
</li>
<li id="cite_note-bool-4"><span class="mw-cite-backlink">^ <a href="#cite_ref-bool_4-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-bool_4-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-bool_4-2"><sup><i><b>c</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFC._QuJ._SeberryT._Xia2001" class="citation web cs1">C. Qu; <a href="Jennifer_Seberry" title="Jennifer Seberry">J. Seberry</a>; T. Xia (29 December 2001). <a rel="nofollow" class="external text" href="http://citeseer.ist.psu.edu/old/700097.html">"Boolean Functions in Cryptography"</a><span class="reference-accessdate">. Retrieved <span class="nowrap">14 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-nonlin-5"><span class="mw-cite-backlink">^ <a href="#cite_ref-nonlin_5-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-nonlin_5-1"><sup><i><b>b</b></i></sup></a> <a href="#cite_ref-nonlin_5-2"><sup><i><b>c</b></i></sup></a> <a href="#cite_ref-nonlin_5-3"><sup><i><b>d</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFW._MeierO._Staffelbach1989" class="citation conference cs1">W. Meier; O. Staffelbach (April 1989). <i>Nonlinearity Criteria for Cryptographic Functions</i>. <a href="Eurocrypt" class="mw-redirect" title="Eurocrypt">Eurocrypt</a> '89. pp.&nbsp;<span class="nowrap">549–</span>562.</cite></span>
</li>
<li id="cite_note-dual-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-dual_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-dual_6-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFC._CarletL.E._DanielsenM.G._ParkerP._Solé2008" class="citation conference cs1">C. Carlet; L.E. Danielsen; M.G. Parker; P. Solé (19 May 2008). <a rel="nofollow" class="external text" href="http://www.ii.uib.no/~matthew/bfcasdb.pdf"><i>Self Dual Bent Functions</i></a> <span class="cs1-format">(PDF)</span>. Fourth International Workshop on Boolean Functions: Cryptography and Applications (BFCA '08)<span class="reference-accessdate">. Retrieved <span class="nowrap">21 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-homo-7"><span class="mw-cite-backlink"><b><a href="#cite_ref-homo_7-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFT._XiaJ._SeberryJ._PieprzykC._Charnes2004" class="citation journal cs1">T. Xia; J. Seberry; <a href="Josef_Pieprzyk" title="Josef Pieprzyk">J. Pieprzyk</a>; C. Charnes (June 2004). <a rel="nofollow" class="external text" href="http://ro.uow.edu.au/infopapers/291/">"Homogeneous bent functions of degree n in 2n variables do not exist for n &gt; 3"</a>. <i>Discrete Applied Mathematics</i>. <b>142</b> (<span class="nowrap">1–</span>3): <span class="nowrap">127–</span>132. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.dam.2004.02.006">10.1016/j.dam.2004.02.006</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0166-218X">0166-218X</a><span class="reference-accessdate">. Retrieved <span class="nowrap">21 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-mono-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-mono_8-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFA._CanteautP._CharpinG._Kyureghyan2008" class="citation journal cs1"><a href="Anne_Canteaut" title="Anne Canteaut">A. Canteaut</a>; P. Charpin; G. Kyureghyan (January 2008). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110721001849/http://www-roc.inria.fr/secret/Anne.Canteaut/Publications/CanChaKuy07.pdf">"A new class of monomial bent functions"</a> <span class="cs1-format">(PDF)</span>. <i>Finite Fields and Their Applications</i>. <b>14</b> (1): <span class="nowrap">221–</span>241. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1016%2Fj.ffa.2007.02.004">10.1016/j.ffa.2007.02.004</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1071-5797">1071-5797</a>. Archived from <a rel="nofollow" class="external text" href="http://www-roc.inria.fr/secret/Anne.Canteaut/Publications/CanChaKuy07.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 21 July 2011<span class="reference-accessdate">. Retrieved <span class="nowrap">21 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-seq-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-seq_9-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJ._OlsenR._ScholtzL._Welch1982" class="citation journal cs1 cs1-prop-long-vol">J. Olsen; R. Scholtz; L. Welch (November 1982). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20110722055600/http://www.costasarrays.org/costasrefs/b2hd-olsen82bent-function.html">"Bent-Function Sequences"</a>. <i><a href="IEEE_Transactions_on_Information_Theory" title="IEEE Transactions on Information Theory">IEEE Transactions on Information Theory</a></i>. IT-28 (6): <span class="nowrap">858–</span>864. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2Ftit.1982.1056589">10.1109/tit.1982.1056589</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0018-9448">0018-9448</a>. Archived from <a rel="nofollow" class="external text" href="http://www.costasarrays.org/costasrefs/b2hd-olsen82bent-function.html">the original</a> on 22 July 2011<span class="reference-accessdate">. Retrieved <span class="nowrap">24 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-spectral-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-spectral_10-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFR._Forré1988" class="citation conference cs1">R. Forré (August 1988). <i>The Strict Avalanche Criterion: Spectral Properties of Boolean Functions and an Extended Definition</i>. <a href="CRYPTO" class="mw-redirect" title="CRYPTO">CRYPTO</a> '88. pp.&nbsp;<span class="nowrap">450–</span>468.</cite></span>
</li>
<li id="cite_note-sac-11"><span class="mw-cite-backlink">^ <a href="#cite_ref-sac_11-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-sac_11-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFC._AdamsS._Tavares1990" class="citation book cs1"><a href="Carlisle_Adams" title="Carlisle Adams">C. Adams</a>; <a href="Stafford_Tavares" title="Stafford Tavares">S. Tavares</a> (January 1990). <i>The Use of Bent Sequences to Achieve Higher-Order Strict Avalanche Criterion in S-box Design</i>. Technical Report TR 90-013. <a href="Queen's_University_at_Kingston" title="Queen's University at Kingston">Queen's University</a>. <a href="CiteSeerX_(identifier)" class="mw-redirect" title="CiteSeerX (identifier)">CiteSeerX</a>&nbsp;<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.41.8374">10.1.1.41.8374</a></span>.</cite></span>
</li>
<li id="cite_note-nyberg-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-nyberg_12-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFK._Nyberg1991" class="citation conference cs1"><a href="Kaisa_Nyberg" title="Kaisa Nyberg">K. Nyberg</a> (April 1991). <i>Perfect nonlinear S-boxes</i>. Eurocrypt '91. pp.&nbsp;<span class="nowrap">378–</span>386.</cite></span>
</li>
<li id="cite_note-highly-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-highly_13-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFJ._SeberryX._Zhang1992" class="citation conference cs1">J. Seberry; X. Zhang (December 1992). <i>Highly Nonlinear 0–1 Balanced Boolean Functions Satisfying Strict Avalanche Criterion</i>. <a href="AUSCRYPT" class="mw-redirect" title="AUSCRYPT">AUSCRYPT</a> '92. pp.&nbsp;<span class="nowrap">143–</span>155. <a href="CiteSeerX_(identifier)" class="mw-redirect" title="CiteSeerX (identifier)">CiteSeerX</a>&nbsp;<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.57.4992">10.1.1.57.4992</a></span>.</cite></span>
</li>
<li id="cite_note-cast-14"><span class="mw-cite-backlink">^ <a href="#cite_ref-cast_14-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-cast_14-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFC._Adams1997" class="citation journal cs1">C. Adams (November 1997). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20081026081723/http://jya.com/cast.html">"Constructing Symmetric Ciphers Using the CAST Design Procedure"</a>. <i>Designs, Codes and Cryptography</i>. <b>12</b> (3): <span class="nowrap">283–</span>316. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1023%2FA%3A1008229029587">10.1023/A:1008229029587</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0925-1022">0925-1022</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:14365543">14365543</a>. Archived from <a rel="nofollow" class="external text" href="http://jya.com/cast.html">the original</a> on 26 October 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">20 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-haval-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-haval_15-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFY._ZhengJ._PieprzykJ._Seberry1992" class="citation conference cs1"><a href="Yuliang_Zheng" title="Yuliang Zheng">Y. Zheng</a>; J. Pieprzyk; J. Seberry (December 1992). <a rel="nofollow" class="external text" href="http://works.bepress.com/jseberry/192/"><i>HAVAL – a one-way hashing algorithm with variable length of output</i></a>. AUSCRYPT '92. pp.&nbsp;<span class="nowrap">83–</span>104<span class="reference-accessdate">. Retrieved <span class="nowrap">20 June</span> 2015</span>.</cite></span>
</li>
<li id="cite_note-grain-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-grain_16-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFHellJohanssonMaximovMeier2006" class="citation conference cs1">Hell, Martin; Johansson, Thomas; Maximov, Alexander; Meier, Willi (2006). <a rel="nofollow" class="external text" href="https://www.ecrypt.eu.org/stream/p2ciphers/grain/Grain128_p2.pdf">"A Stream Cipher Proposal: Grain-128"</a> <span class="cs1-format">(PDF)</span>. <i>Proceedings 2006 IEEE International Symposium on Information Theory, ISIT 2006, The Westin Seattle, Seattle, Washington, USA, July 9–14, 2006</i>. IEEE. pp.&nbsp;<span class="nowrap">1614–</span>1618. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1109%2FISIT.2006.261549">10.1109/ISIT.2006.261549</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>1-4244-0505-X</bdi>.</cite></span>
</li>
<li id="cite_note-nyberg2-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-nyberg2_17-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFK._Nyberg1990" class="citation conference cs1">K. Nyberg (May 1990). <i>Constructions of bent functions and difference sets</i>. Eurocrypt '90. pp.&nbsp;<span class="nowrap">151–</span>160.</cite></span>
</li>
<li id="cite_note-gbf2-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-gbf2_18-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFShashi_Kant_PandeyB.K._Dass2017" class="citation journal cs1">Shashi Kant Pandey; B.K. Dass (September 2017). "On Walsh Spectrum of Cryptographic Boolean Function". <i>Defence Science Journal</i>. <b>67</b> (5): <span class="nowrap">536–</span>541. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.14429%2Fdsj.67.10638">10.14429/dsj.67.10638</a> (inactive 1 July 2025). <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0011-748X">0011-748X</a>.</cite><span class="cs1-maint citation-comment"><code class="cs1-code">{{cite journal}}</code>: CS1 maint: DOI inactive as of July 2025 (link)</span></span>
</li>
<li id="cite_note-semi-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-semi_19-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFK._KhooG._GongD._Stinson2006" class="citation journal cs1">K. Khoo; G. Gong; <a href="Doug_Stinson" title="Doug Stinson">D. Stinson</a> (February 2006). <a rel="nofollow" class="external text" href="http://www.cacr.math.uwaterloo.ca/~dstinson/papers/dcc-final.ps">"A new characterization of semi-bent and bent functions on finite fields"</a> <span class="cs1-format">(<a href="PostScript" title="PostScript">PostScript</a>)</span>. <i>Designs, Codes and Cryptography</i>. <b>38</b> (2): <span class="nowrap">279–</span>295. <a href="CiteSeerX_(identifier)" class="mw-redirect" title="CiteSeerX (identifier)">CiteSeerX</a>&nbsp;<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.10.6303">10.1.1.10.6303</a></span>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2Fs10623-005-6345-x">10.1007/s10623-005-6345-x</a>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/0925-1022">0925-1022</a>. <a href="S2CID_(identifier)" class="mw-redirect" title="S2CID (identifier)">S2CID</a>&nbsp;<a rel="nofollow" class="external text" href="https://api.semanticscholar.org/CorpusID:10572850">10572850</a><span class="reference-accessdate">. Retrieved <span class="nowrap">24 September</span> 2009</span>.</cite></span>
</li>
<li id="cite_note-plat-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-plat_20-0">^</a></b></span> <span class="reference-text"><cite id="CITEREFY._ZhengX._Zhang1999" class="citation conference cs1">Y. Zheng; X. Zhang (November 1999). <a rel="nofollow" class="external text" href="http://citeseer.ist.psu.edu/old/291018.html"><i>Plateaued Functions</i></a>. Second International Conference on Information and Communication Security (ICICS '99). pp.&nbsp;<span class="nowrap">284–</span>300<span class="reference-accessdate">. Retrieved <span class="nowrap">24 September</span> 2009</span>.</cite></span>
</li>
</ol></div>
<div class="mw-heading mw-heading2"><h2 id="Further_reading">Further reading</h2></div>
<ul><li><cite id="CITEREFC._Carlet1993" class="citation conference cs1">C. Carlet (May 1993). <i>Two New Classes of Bent Functions</i>. Eurocrypt '93. pp.&nbsp;<span class="nowrap">77–</span>101.</cite></li>
<li><cite id="CITEREFJ._SeberryX._Zhang1994" class="citation journal cs1">J. Seberry; X. Zhang (March 1994). "Constructions of Bent Functions from Two Known Bent Functions". <i>Australasian Journal of Combinatorics</i>. <b>9</b>: <span class="nowrap">21–</span>35. <a href="CiteSeerX_(identifier)" class="mw-redirect" title="CiteSeerX (identifier)">CiteSeerX</a>&nbsp;<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.55.531">10.1.1.55.531</a></span>. <a href="ISSN_(identifier)" class="mw-redirect" title="ISSN (identifier)">ISSN</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/issn/1034-4942">1034-4942</a>.</cite></li>
<li><cite id="CITEREFColbournDinitz2006" class="citation book cs1"><a href="Charles_Colbourn" title="Charles Colbourn">Colbourn, Charles J.</a>; <a href="Jeff_Dinitz" title="Jeff Dinitz">Dinitz, Jeffrey H.</a> (2006). <a rel="nofollow" class="external text" href="https://archive.org/details/handbookofcombin0000unse/page/337"><i>Handbook of Combinatorial Designs</i></a> (2nd&nbsp;ed.). <a href="CRC_Press" title="CRC Press">CRC Press</a>. pp.&nbsp;<a rel="nofollow" class="external text" href="https://archive.org/details/handbookofcombin0000unse/page/337">337–339</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-1-58488-506-1</bdi>.</cite></li>
<li><cite id="CITEREFCusickStanica2009" class="citation book cs1">Cusick, T.W.; Stanica, P. (2009). <i>Cryptographic Boolean Functions and Applications</i>. Academic Press. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>9780123748904</bdi>.</cite></li></ul></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-07-11" href="https://en.wikipedia.org/wiki/?title=Bent_function&amp;oldid=1300019363">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>