Jonathan Komada Eriksen

@jonathan.isogeny.club

Post-doc at COSIC, probably more known for dubious rhymes than research.

Excited to share that I've been awarded a Veni grant from the NWO! This grant allows me the freedom to explore research of my own choosing, and to achieve faster, better, and simpler post-quantum cryptography using deep mathematical insight. More info: www.ru.nl/en/about-us/...

Veni grants for eight Radboud researchers | Radboud University

The Dutch Research Council (NWO) has awarded a Veni grant to eight young researchers of the Radboud University and Radboudumc.

ru.nl

This summer has been a dream come true. That is worth celebrating. In life, its easy to get lost in working for you own personal goals. But, I can 100% say that this feeling of love, hope and togetherness surpasses the joy I could EVER feel over any personal achievement ❤️

BildBildBildBild

The paper shows how to find affine maps agreeing with an S-box on as many as possible inputs. Look for presentation at #Eurocrypt 2026 today! The code is already available. Also check out a vide-coded interactive tool, it's fun to play with: affine.group/pages/greedy...

Greedy Extension (DDT) Algorithm

affine.group

ePrint Updates@eprint.ing.bot · 3mo ago

Algorithmic Toolkit for Linearization of S-boxes (Alex Biryukov, Philip Tureček, Aleksei Udovenko) ia.cr/2026/913

Abstract. Linearization is a cryptanalysis technique in which a nonlinear function (an S-box) is represented by an affine mapping on a certain subset of inputs. Its variants were applied to analyze Keccak, LowMC, RAIN and AIM. In these primitives, the S-boxes are either very small (up to 5 bits) or are very specific monomial functions over a binary field. Linearization of arbitrary S-boxes was never practically explored due to the lack of theoretic, algorithmic, and cryptanalytic understanding.

For the first time, we develop an algorithmic toolkit which allows one to compute strong linearizations of S-boxes, when they exist. For up to n = 8 bits, our algorithms are able to find provably the best possible approximations, while for larger S-boxes it is feasible to obtain good approximations together with meaningful upper bounds. We apply our algorithms to a variety of S-boxes from existing primitives, to monomial functions, to so-called APN functions, and to 16-bit Super-Sboxes. We obtain interesting results raising many new open questions and open up new research directions, as well as a foundation for developing cryptanalytic attacks.

To advance the cryptanalytic utility of linearization, we study and solve the problem of covering an S-box with multiple approximations. As an application, we derive a generic linearization approach for the CICO problem (constrained-input-constrained-output) over SPN-based permutations (Substitution-Permutation Networks) with general linear layers. This is the first such general cryptanalysis based on the existence of a strong linearization of the S-box.

By the way as you know lately I have been thinking about cubical structures in terms of derived quadratic forms, and although a bit conceptual it is *amazing* for having a better understanding of what we can do with them. For instance the monodromy leak can be explained in a paragraph: