International Association for Cryptologic Research

International Association
for Cryptologic Research

Transactions on Cryptographic Hardware and Embedded Systems 2026

Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits


README

Artifact for "Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits"

Authors: Giyoon Kim, Seungjun Baek, Yongjin Jeon, Vedad Hadzic, and Jongsung Kim

Paper: https://eprint.iacr.org/2026/726


Overview

This artifact contains executable Python scripts for the optimized S-box circuits reported in the paper. Each script is self-contained and verifies one circuit by reconstructing the full truth table, checking equivalence to the target S-box, and printing the circuit statistics.

No external packages are required.


Relation to the paper

This artifact accompanies the paper "Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits".

It focuses on the generated gate-level S-box circuits and simple verification scripts. The scripts are intended to validate the correctness of the reported circuits and reproduce their circuit metrics, including the number of nonlinear gates, linear gates, NOT gates, and depth-related information encoded in the filenames.


Contents

The artifact includes the following 12 Python files:

AES S-box circuits

7-bit x^3 circuits

Dillon 6-bit APN S-box circuits

6-bit x^3 circuits

Ascon S-box circuit


Environment


How to run

Unzip the artifact and run any script directly with Python.

Example:

python 00.AES_D14_AD4_NL33_L95_G128.py

Each script prints:

A typical output looks like:

True
#NL:     42  (AND: 0, NAND: 40, OR: 0, NOR: 2)
#L :     94  (XOR: 44, XNOR: 50)
#NOT :   0

To run all files on Linux/macOS:

for f in *.py; do
    python "$f"
done

To run all files on Windows PowerShell:

Get-ChildItem *.py | ForEach-Object { python $_.FullName }

Expected results

The first line should always be True.

File Expected result summary
00.AES_D14_AD4_NL33_L95_G128.py True, #NL: 33, #L: 95, #NOT: 0
01.AES_D13_AD3_NL42_L94_G136.py True, #NL: 42, #L: 94, #NOT: 0
02.AES_D12_AD3_NL42_L107_G149.py True, #NL: 42, #L: 107, #NOT: 0
03.7bit_x3_D6_AD1_NL11_L41_G52.py True, #NL: 11, #L: 41, #NOT: 0
04.7bit_x3_D5_AD1_NL18_L40_G58.py True, #NL: 18, #L: 40, #NOT: 9
05.7bit_x3_D5_AD1_NL20_L37_G57.py True, #NL: 20, #L: 37, #NOT: 4
06.Dillon_D10_AD3_NL12_L39_G51.py True, #NL: 12, #L: 39, #NOT: 1
07.Dillon_D7_AD2_NL20_L49_G69.py True, #NL: 20, #L: 49, #NOT: 0
08.6bit_x3_D6_AD1_NL8_L28_G36.py True, #NL: 8, #L: 28, #NOT: 0
09.6bit_x3_D5_AD1_NL9_L27_G36.py True, #NL: 9, #L: 27, #NOT: 0
10.6bit_x3_D4_AD1_NL11_L23_G34.py True, #NL: 11, #L: 23, #NOT: 0
11.Ascon_D4_AD1_NL5_L11_G16.py True, #NL: 5, #L: 11, #NOT: 3

Contact

If any issue arises when running the artifact, please contact the authors.