Transactions on Cryptographic Hardware and Embedded Systems 2026
Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits
README
Artifact for "Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits"
Authors: Giyoon Kim, Seungjun Baek, Yongjin Jeon, Vedad Hadzic, and Jongsung Kim
Paper: https://eprint.iacr.org/2026/726
Overview
This artifact contains executable Python scripts for the optimized S-box circuits reported in the paper. Each script is self-contained and verifies one circuit by reconstructing the full truth table, checking equivalence to the target S-box, and printing the circuit statistics.
No external packages are required.
Relation to the paper
This artifact accompanies the paper "Bitsliced Segment-Based Search Technique for Low-Depth and Hardware-Efficient S-Box Circuits".
It focuses on the generated gate-level S-box circuits and simple verification scripts. The scripts are intended to validate the correctness of the reported circuits and reproduce their circuit metrics, including the number of nonlinear gates, linear gates, NOT gates, and depth-related information encoded in the filenames.
Contents
The artifact includes the following 12 Python files:
AES S-box circuits
00.AES_D14_AD4_NL33_L95_G128.py01.AES_D13_AD3_NL42_L94_G136.py02.AES_D12_AD3_NL42_L107_G149.py
7-bit x^3 circuits
03.7bit_x3_D6_AD1_NL11_L41_G52.py04.7bit_x3_D5_AD1_NL18_L40_G58.py05.7bit_x3_D5_AD1_NL20_L37_G57.py
Dillon 6-bit APN S-box circuits
06.Dillon_D10_AD3_NL12_L39_G51.py07.Dillon_D7_AD2_NL20_L49_G69.py
6-bit x^3 circuits
08.6bit_x3_D6_AD1_NL8_L28_G36.py09.6bit_x3_D5_AD1_NL9_L27_G36.py10.6bit_x3_D4_AD1_NL11_L23_G34.py
Ascon S-box circuit
11.Ascon_D4_AD1_NL5_L11_G16.py
Environment
- Python 3.x
- No external dependencies
How to run
Unzip the artifact and run any script directly with Python.
Example:
python 00.AES_D14_AD4_NL33_L95_G128.py
Each script prints:
Trueif the circuit matches the target S-box,#NLfor nonlinear gates,#Lfor linear gates,#NOTfor explicit NOT gates.
A typical output looks like:
True
#NL: 42 (AND: 0, NAND: 40, OR: 0, NOR: 2)
#L : 94 (XOR: 44, XNOR: 50)
#NOT : 0
To run all files on Linux/macOS:
for f in *.py; do
python "$f"
done
To run all files on Windows PowerShell:
Get-ChildItem *.py | ForEach-Object { python $_.FullName }
Expected results
The first line should always be True.
| File | Expected result summary |
|---|---|
00.AES_D14_AD4_NL33_L95_G128.py |
True, #NL: 33, #L: 95, #NOT: 0 |
01.AES_D13_AD3_NL42_L94_G136.py |
True, #NL: 42, #L: 94, #NOT: 0 |
02.AES_D12_AD3_NL42_L107_G149.py |
True, #NL: 42, #L: 107, #NOT: 0 |
03.7bit_x3_D6_AD1_NL11_L41_G52.py |
True, #NL: 11, #L: 41, #NOT: 0 |
04.7bit_x3_D5_AD1_NL18_L40_G58.py |
True, #NL: 18, #L: 40, #NOT: 9 |
05.7bit_x3_D5_AD1_NL20_L37_G57.py |
True, #NL: 20, #L: 37, #NOT: 4 |
06.Dillon_D10_AD3_NL12_L39_G51.py |
True, #NL: 12, #L: 39, #NOT: 1 |
07.Dillon_D7_AD2_NL20_L49_G69.py |
True, #NL: 20, #L: 49, #NOT: 0 |
08.6bit_x3_D6_AD1_NL8_L28_G36.py |
True, #NL: 8, #L: 28, #NOT: 0 |
09.6bit_x3_D5_AD1_NL9_L27_G36.py |
True, #NL: 9, #L: 27, #NOT: 0 |
10.6bit_x3_D4_AD1_NL11_L23_G34.py |
True, #NL: 11, #L: 23, #NOT: 0 |
11.Ascon_D4_AD1_NL5_L11_G16.py |
True, #NL: 5, #L: 11, #NOT: 3 |
Contact
If any issue arises when running the artifact, please contact the authors.