Mobius Bridges for the Invert-and-Affine S-box Class, with the Four ARIA Instantiations

No attack complexities for ARIA are claimed.

Bilar, Daniyel Yaacov · 2026-08-03 · v1.0.5 · publication/preprint · cc-by-4.0

DOI (concept, always latest): https://doi.org/10.5281/zenodo.21705468
This PDF (version v1.0.5): https://doi.org/10.5281/zenodo.21765164
Download PDF (Zenodo): open
ARIA published maps verified: A, B with a=0x63, b=0xE2 (0/64770 per Table 1 row)
Lean (v1.0.5): class bridge (Thm 3.1), fingerprint corollary (Cor 3.2), bad-index set (§5)
Code / Lean / verifier: github.com/chokmah-me/aria-moebius (release v1.0.4)
Software DOI: 10.5281/zenodo.23215647 (concept …939)
Software catalog: aria-moebius verifier page
OSF mirror: https://osf.io/wy8db/
Sketchnote for Möbius Bridges v1.0.5: invert-and-affine class form, four ARIA maps, bad indices at L1 inverse of 0, Lean spine plus Python oracle, no attack complexities claimed

Sketchnote for paper v1.0.5 (CC BY 4.0). Full-size PNG.

Abstract

The Mobius Bridge of Nasr and Carlini removes one guessed key byte from meet-in-the-middle attacks on 7-round AES by constructing a fingerprint invariant under the group action that survives the S-box. Their derivation is written for the AES S-box (field inversion followed by a GF(2)-affine map). This note shows the construction is not specific to that shape. For any S-box of the form S = L2 ∘ Frobj ∘ inv ∘ L1, with L1 and L2 GF(2)-affine bijections and Frob the squaring map, the same reciprocal-and-reparametrize step yields an affine bridge identity in which both parameters are raised to the 2j power and the multiplier remains the square of the translation. The Frobenius exponent is the only degree of freedom. AES instantiates j = 0 with L1 = id. ARIA instantiates four distinct members (S1, S2, S1−1, S2−1 at exponents 0, 3, 0, 5), each with its own offline multiset. A consequence that does not appear in the AES case: bad indices where inv(0) = 0 breaks the identity move with L1, sitting at L1−1(0) rather than at 0; for ARIA's inverse S-boxes these are the affine constants, so the published bad-index treatment does not port unchanged. Bridge identities are verified exhaustively over GF(28). Theorem 3.1, Corollary 3.2, and the Section 5 bad-index set are formalized in Lean 4. No attack complexities for ARIA are claimed.

Keywords

ARIA · block cipher · meet-in-the-middle · Mobius Bridge · GF(2^8) · Frobenius · Lean 4 · S-box · cryptanalysis · formal verification · invert-and-affine · class bridge · fingerprint invariance

← All research