IP Library Granted Patent US 12,627,468
Granted Patent B2
US 12,627,468 · App. 18/533,853 · Granted May 12, 2026

Systems and methods for providing substitution boxes

Inventors: Michael Kurdziel (Rochester, NY); Steven Farris (Webster, NY); Alan Kaminsky (Rochester, NY); Peter Bajorski (Fairport, NY); Payton Burak (Jamison, PA); Marcin Lukowiak (Rochester, NY); Stanislaw Radziszowski (West Henrietta, NY)
Assignee: L3Harris Global Communications, Inc.
H04L9/0631G06F1/03G06F17/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,468
App. No.
18/533,853
Granted
May 12, 2026
Kind
B2
Abstract

Systems and methods for providing an S-box. The methods comprise: implementing a plurality of layers on a field programmable gate array, wherein each of the layers comprises a substitution sublayer and a mixing sublayer. The substitution sublayer comprises a plurality of μ-boxes that are each configured to perform a different randomly chosen non-linear bijective mapping from GF(2 4 ) to GF(2 4 ). The mixing sublayer is configured to (i) compute a plurality of product terms each representing a product of an element of a maximum distance separable matrix M and an output from one of the plurality of μ-boxes, and (ii) compute a plurality of column vector elements each comprising a sum of respective ones of the plurality of product terms.

Claims (32)

1 . A method for providing and using a cryptographic algorithm with an S-box, comprising:

providing an electronic device with the cryptographic algorithm by implementing a plurality of layers of the S-box on a field programmable gate array of the electronic device, each of the layers comprises a substitution sublayer and a mixing sublayer;

using input data as an index for a lookup table implementing the S-box in the field programmable gate array to obtain a data item;

using the data item to obtain encrypted data; and

communicating the encrypted data in a message sent from the electronic device;

wherein the substitution sublayer comprises a plurality of μ-boxes that are each configured to perform a different randomly chosen non-linear bijective mapping from GF(2 4 ) to GF(2 4 ); and

wherein the mixing sublayer is configured to (i) compute a plurality of product terms each representing a product of an element of a maximum distance separable matrix M and an output from one of the plurality of μ-boxes, and (ii) compute a plurality of column vector elements each comprising a sum of respective ones of the plurality of product terms.

2 . The method according to claim 1 , wherein the S-box is configured to meet the following requirements: no fixed points where S(x)=x; and no opposite fixed points where S(x)=bitwise complement of x.

3 . The method according to claim 1 , wherein each of said μ-boxes is configured to meet the following requirements: no fixed points where μ(x)=x; no opposite fixed points where μ(x)=bitwise complement of x; maximum differential probability of 4/16 or smaller; and maximum absolute linear bias of 4/16 or smaller.

4 . The method according to claim 1 , wherein the plurality of μ-boxes comprises four or more μ-boxes with a 4-bit input and a 4-bit output.

5 . The method according to claim 1 , wherein the plurality of μ-boxes are each implemented via at least four look-up tables of the field programmable gate array.

6 . The method according to claim 1 , wherein the plurality of layers comprises four or more layers.

7 . The method according to claim 1 , wherein the plurality of product terms are computed by product operators that are each implemented via at least two lookup tables of the field programmable gate array.

8 . The method according to claim 7 , wherein each of the product operators is implemented via four or more lookup tables of the field programmable gate array.

9 . The method according to claim 1 , wherein each element of the maximum distance separable matrix M, the output of each of said μ-boxes, and each of said column vector elements comprises an element in a finite field GF(2 4 )/ƒ(x), wherein ƒ(x) is a degree-4 irreducible polynomial.

10 . The method according to claim 9 , further comprising performing a plurality of rounds of the mixing sublayer using a different randomly chosen maximum distance separable matrix and a different randomly chosen irreducible polynomial.

11 . A system, comprising:

a field programmable gate array comprising lookup tables implementing at least a portion of an encryption algorithm with an S-box;

the S-box configured to map input data to output data and comprising a plurality of layers implemented in the field programmable gate array, each of the layers comprises a substitution sublayer and a mixing sublayer; and

a communication device configured to communicate encrypted data in a message;

wherein the field programmable gate array uses the input data as an index for at least one of the lookup tables to retrieve a data item and uses the data item to obtain encrypted data;

wherein the substitution sublayer comprises a plurality of μ-boxes that are each configured to perform a different randomly chosen non-linear bijective mapping from GF(2 4 ) to GF(2 4 ); and

wherein the mixing sublayer is configured to (i) compute a plurality of product terms each representing a product of an element of a maximum distance separable matrix M and an output from one of the plurality of μ-boxes, and (ii) compute a plurality of column vector elements each comprising a sum of respective ones of the plurality of product terms.

12 . The system according to claim 11 , wherein the S-box is configured to meet the following requirements: no fixed points where S(x)=x; and no opposite fixed points where S(x)=bitwise complement of x.

13 . The system according to claim 11 , wherein each of said μ-boxes is configured to meet the following requirements: no fixed points where μ(x)=x; no opposite fixed points where μ(x)=bitwise complement of x; maximum differential probability of 4/16 or smaller; and maximum absolute linear bias of 4/16 or smaller.

14 . The system according to claim 11 , wherein the plurality of μ-boxes comprises four or more μ-boxes with a 4-bit input and a 4-bit output.

15 . The system according to claim 11 , wherein the plurality of μ-boxes are each implemented via at least four look-up tables of the field programmable gate array.

16 . The system according to claim 11 , wherein the plurality of layers comprises four or more layers.

17 . The system according to claim 11 , wherein the plurality of product terms are computed by product operators that are each implemented via at least two lookup tables of the field programmable gate array.

18 . The system according to claim 17 , wherein each of the product operators is implemented via four or more lookup tables of the field programmable gate array.

19 . The system according to claim 11 , wherein each element of the maximum distance separable matrix M, the output of each of said μ-boxes, and each of said column vector elements comprises an element in a finite field GF(2 4 )/ƒ(x), wherein ƒ(x) is a degree-4 irreducible polynomial.

20 . The system according to claim 19 , wherein each of a plurality of rounds of the mixing sublayer uses a different randomly chosen maximum distance separable matrix and a different randomly chosen irreducible polynomial.

Assignments (2)
CHANGE OF NAME Recorded Sep 16, 2024
From: HARRIS GLOBAL COMMUNICATIONS, INC.
To: L3HARRIS GLOBAL COMMUNICATIONS, INC.
Reel/Frame 068962/0871 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2023
From: KURDZIEL, MIKE; FARRIS, STEVEN M.; BURAK, PAYTON; LUKOWIAK, MARCIN; KAMINSKY, ALAN; RADZISZOWSKI, STANISLAW P.; BAJORSKI, PETER
To: HARRIS GLOBAL COMMUNICATIONS, INC.
Reel/Frame 065837/0268 →
Continuity (1)
Related Publication 20250192984A1 · Jun 12, 2025
References Cited (19)
US 10666437B2 · Kurdziel · 2020 [cited by examiner]
US 20140198913A1 · Rose · 2014 [cited by examiner]
US 20160269175A1 · Cammarota · 2016 [cited by examiner]
Anandakumar et al., “A Very Compact FPGA Implementation of LED and PHOTON,” Advances in Visual Computing: 16th International Symposium, ISVC 2021, Virtual Event, Oct. 4-6, 2021, Proceedings, Part II; (Lecture Notes in C… [cited by applicant]
Avanzi, “A Salad of Block Ciphers: The State of the Art in Block Ciphers and their Analysis,” IACR, International Association for Cryptologic Research, vol. 20161228, 296 pages (2016). [cited by applicant]
Bogdanov and Shibutani, “Generalized Feistel networks revisited,” Des. Codes Cryptogr., 66, pp. 75-97 (2013). [cited by applicant]
Bajorski et al., “Array-Based Statistical Analysis of the MK-3 Authenticated Encryption Scheme,” MILCOM 2018—2018 IEEE Military Communications Conference (MILCOM), Los Angeles, CA, USA, pp. 1-9 (2018). [cited by applicant]
Bajorski et al., “Customization Modes for the Harris MK-3 Authenticated Encryption Algorithm,” MILCOM 2018—2018 IEEE Military Communications Conference (MILCOM), Los Angeles, CA, USA, pp. 1-5 (2018). [cited by applicant]
Bajorski et al., “Statistical Analysis of the MK-3 Customizable Authenticated Encryption,” MILCOM 2022 Track 3—Cyber Security and Trusted Computing, pp. 974-979 (2022). [cited by applicant]
Fitzgerald et al., “FPGA-Based, Multi-Processor HW-SW System for Single-Chip Crypto Applications,” Proc. IEEE, Mil. Comm. Conf., Oct. 2010, 6 pages. [cited by applicant]
Kelly et al., “Customizable Sponge-Based Authenticated Encryption Using 16-bit S-boxes,” MILCOM 2015—2015 IEEE Military Communications Conference, Tampa, FL, USA, pp. 43-48 (2015). [cited by applicant]
Matsui, “Linear Cryptanalysis Method for DES Cipher,” T. Helleseth (Ed.): Advances in Cryptology—EUROCRYPT '93, LNCS 765, pp. 386-397, (1994). [cited by applicant]
Mishra et al., “Efficient hardware mapping of Boolean substitution boxes based on functional decomposition for RFID and ISM band IoT applications,” INTEGRATION, the VLSI journal 92, pp. 38-47 (2023). [cited by applicant]
Prathiba et al., “Hardware footprints of S-box in lightweight symmetric block ciphers for IoT and CPS information security systems,” Integration, the VLSI Journal 69, pp. 266-278 (2019). [cited by applicant]
Rashidi, “Compact and efficient structure of 8-bit S-box for lightweight cryptography,” INTEGRATION, the VLSI journal 76, pp. 172-182 (2021). [cited by applicant]
Sawada et al., “Logic Synthesis for Look-Up Table based FPGAs using Functional Decomposition and Support Minimization,” Proceedings of IEEE International Conference on Computer Aided Design (ICCAD), San Jose, CA, USA, p… [cited by applicant]
Werner et al., “Fully Parallel Implementation of the MK-3 Authenticated Encryption Algorithm on FPGA,” New York Cyber Security and Engineering Technology Association (NYSETA) Conf., Rochester, NY, Oct. 2015, 7 pages. [cited by applicant]
Werner et al., “Implementing Authenticated Encryption Algorithm MK-3 on FPGA,” Milcom 2016 Track 3—Cyber Security and Trusted Computing, pp. 1-6 (2016). [cited by applicant]
Youssef et al., “On the Design of Linear Transformations for Substitution Permutation Encryption Networks,” Fourth Annual Workshop on Selected Areas in Cryptography (SAC '97), pp. 40-48 (1997). [cited by applicant]