By Hans Dobbertin, Vincent Rijmen, Aleksandra Sowa,

ISBN-10: 3540265570

ISBN-13: 9783540265573

This ebook const?tutes the completely refereed postproceedings of the 4th foreign convention at the complex Encryption commonplace, AES 2004, held in Bonn, Germany in could 2004.

The 10 revised complete papers offered including an introductory survey and four invited papers by way of major researchers have been conscientiously chosen in the course of rounds of reviewing and development. The papers are geared up in topical sections on cryptanalytic assaults and similar subject matters, algebraic assaults and similar effects, implementations, and different subject matters. All in all, the papers represent a most modern review of the cutting-edge of knowledge encryption utilizing the complex Encryption normal AES, the de facto international commonplace for info encryption.

Additional info for Advanced Encryption Standard – AES: 4th International Conference, AES 2004, Bonn, Germany, May 10-12, 2004, Revised Selected and Invited Papers

Sample text

E. during the treatment of only one byte. This experience demonstrates that AES on smart cards must now be implemented not only with SPA/DPA countermeasures but also with DFA countermeasures. 7 Conclusion Although DFA on the DES is a well-known attack, it is impossible to directly apply Biham and Shamir’s attack to the AES as the latter does not have the Feistel Structure. This paper extends the operative ﬁeld of diﬀerential fault attacks by describing how to perform two diﬀerent DFA attacks on the AES.

Minier The complexity of the secund step is about 2144 operations less expensive than AES executions. Its probability of success is about 1/2. This attack provides 20 bytes of information on the last and penultimate key values. 4 How to Improve this Attack Using the Lucks’ Property of the Key Schedule for a 192 Bits Key We can improve, by using the particular property of the key schedule described by S. Lucks in [Luc00], the complexity of the attack by a little factor in the case of a key length equal to 192 bits.

4 We adopt this approach. Because of the complexities introduced by most key schedules, the values relevant to linear and diﬀerential cryptanalysis are rarely calculated for the true distribution of subkeys—this remains an interesting and largely unexplored area of study. 2 Linear and Diﬀerential Cryptanalysis Linear and diﬀerential cryptanalysis are generally considered to be the most powerful attacks on block ciphers. Linear cryptanalysis, due to Matsui [16], is a known-plaintext attack that exploits the existence of relatively large expected 4 Some authors use AES* to denote the AES modiﬁed by this assumption.

