Recent attacks on AES (
see here and
here) have shown weaknessesn in the AES key schedule. In short, they managed to recover the key of an 256-bit AES with a complexity of 2
119 and 192-bit AES with complexity 2
176. If this results holds, AES-256 is not better then AES-128. For the time being, there are no practical implications, as all three algorithms still can be considered practically secure.
No comments:
Post a Comment