作者: Jorge Nakahara , Daniel Santana de Freitas , Raphael C. -W. Phan
DOI: 10.1007/11554868_20
关键词:
摘要: This paper presents the first security evaluation of Rijndael cipher with block sizes larger than 128 bits. We describe new higher-order multiset distinguishers for such large-block instances Rijndael. Both and AES were designed to resist differential linear cryptanalysis, which is indicated by number active S-boxes (minimum 25 4-round AES) best distinguishers, probability correlation values are estimated as 2−150 2−75. All these variants have been formally defined their designers extensions AES. 5-round 160 up 256-bit blocks, all holding certainty, many more S-boxes.