New Representations of the AES Key Schedule
Gaëtan Leurent, Clara Pernot
摘要
In this paper we present a new representation of the AES key schedule, with some implications to the security of AES-based schemes. In particular, we show that the AES-128 key schedule can be split into four independent parallel computations operating on 32 bits chunks, up to linear transformation. Surprisingly, this property has not been described in the literature after more than 20 years of analysis of AES. We show two consequences of our new representation, improving previous cryptanalysis results of AES-based schemes. First, we observe that iterating an odd number of key schedule rounds results in a function with short cycles. This explains an observation of Khairallah on mixFeed, a second-round candidate in the NIST lightweight competition. Our analysis actually shows that his forgery attack on mixFeed succeeds with probability 0.44 (with data complexity 220GB), breaking the scheme in practice. The same observation also leads to a novel attack on ALE, another AES-based AEAD scheme. Our new representation also gives efficient ways to combine information from the first subkeys and information from the last subkeys, in order to reconstruct the corresponding master keys. In particular we improve previous impossible differential attacks against AES-128.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
相关 Paper
- Differential Meet-In-The-Middle CryptanalysisChristina Boura, Nicolas David, Patrick Derbez, Gregor Leander 等CRYPTO 2023 · 被引用 24 次
- Twin Column Parity Mixers and Gaston - A New Mixing Layer and PermutationSolane El Hirch, Joan Daemen, Raghvendra Rohit, Rusydi H. MakarimCRYPTO 2023 · 被引用 2 次
- New Slide Attacks on Almost Self-similar CiphersOrr Dunkelman, Nathan Keller, Noam Lasry, Adi ShamirEUROCRYPT 2020 · 被引用 4 次
- Cryptanalysis Results on Spook - Bringing Full-Round Shadow-512 to the LightPatrick Derbez, Paul Huynh, Virginie Lallemand, María Naya-Plasencia 等CRYPTO 2020 · 被引用 3 次
- Circuit Bootstrapping: Faster and SmallerRuida Wang, Yundi Wen, Zhihao Li, Xianhui Lu 等EUROCRYPT 2024 · 被引用 25 次
