[Cryptech Tech] AES core(s) and use case?

Joachim Strömbergson joachim at secworks.se
Fri Feb 21 22:07:20 UTC 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Aloha!

Rob Austein wrote:
> At Fri, 21 Feb 2014 21:59:18 +0100, Joachim Strömbergson wrote:
>> I meant to say that what was said was that AES-128 is the
>> important version.
> 
> I believe that's correct, but I'm mostly just repeating what Steve 
> Bellovin told me.  If I recall the story correctly, there are some 
> theoretical weaknesses in the key schedule for AES-256.  Not 
> immediately clear there are practical attacks, but, as I understand 
> it, because of this, there is some reason to suspect that AES-128
> may be safer than AES-256 in spite of their respective nominal
> strengths.

There is an attack from 2009 on reduces round AES-256 (and AES-192) that
utilize that fact that the key expansion for these modes are partially
reused.

What do we know about requirements from use cases?

- -- 
Med vänlig hälsning, Yours

Joachim Strömbergson - Alltid i harmonisk svängning.
========================================================================
 Joachim Strömbergson          Secworks AB          joachim at secworks.se
========================================================================
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.22 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCAAGBQJTB84YAAoJEF3cfFQkIuyNvoYP/iDQMxtzIhVL7/j+Ct5Mh5lW
OgNHD39IDZIEbvb1qeI/F9e5KgaBo7U4NtB3T8NUtAPuf9vQAUlRcg/QR3VGetyU
lHpsh9z3+DWL8h+Ei3Hp66FNWlHJCrg/qnC0Ept3HlHXl6H9XLZhtElAEv1AuMCn
dRsO7SN2jg8mxokjDOFfQn69TGV7zR3VPwC7D8xvMK9eqKjVJzZteg3zl4oc2HOA
UGYEkvmPMwWf6MxAmmBLjdC0qTroAYKIA+aMW5e3CZr+z02GjuPpl+pgCQxDpaQe
jpTh9k9O76yw1WWFzuK4VKYmJhUuAtVSS/bMFYN/g2cK0NurSucSRs3QTS2MrvcI
Q6zIMF7jBt1jfH8ZoXa26EWDgLT58up9nCRyM8dezD7xQM3Pc8exn7+7ADwSgJf6
bEyYdMHNrhMwOKdH5K5boBc+D4qZzWqoTcTpRv7H7qwa8bDrXjkobHlY/Zg0pQ1N
iKq8/z95JSTh+D0Wh44m9LkXTQ2KJSujYk8sKccaltm0wbBjinXlzK5dXIT/2+Ef
7bZvtw4UMozJTnIXrZQygMJ1VW3++DJvOoQNU0d6z/dIw1TKrK7PQy2kc+c0Zs1A
fmwtw6eHGebZr/StKUKCcIUggMS2ekfvMcMwCyQ4JdUGCc2vo93apIXVnFYHpnG2
KtGVKX4WzKd/fmISsfdX
=TjL2
-----END PGP SIGNATURE-----



More information about the Tech mailing list