{"id":270,"date":"2018-07-23T10:18:59","date_gmt":"2018-07-23T10:18:59","guid":{"rendered":"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/?post_type=chapter&#038;p=270"},"modified":"2018-12-27T11:28:14","modified_gmt":"2018-12-27T11:28:14","slug":"advanced-encryption-standardpart2","status":"publish","type":"chapter","link":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/chapter\/advanced-encryption-standardpart2\/","title":{"rendered":"Advanced Encryption Standard(part2)"},"content":{"raw":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/m4pU7uN5KhQ\" target=\"_blank\" rel=\"noopener\"><img src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a>\r\n<\/span><\/div>\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n&nbsp;\r\n\r\n<strong>Learning Objectives:<\/strong>\r\n<ul>\r\n \t<li>To understand the AES selection process<\/li>\r\n \t<li>To know the details of Rijndael \u2013 the AES cipher<\/li>\r\n \t<li>Discuss about the steps in each round and the key expansion<\/li>\r\n \t<li>To understand the implementation aspects<\/li>\r\n<\/ul>\r\n<strong>2.1 Introduction<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">We have studied AES selection process, key expansion and implementation aspects in last module. This section deals with different operations such as ShiftRows,MixColumns,AddRoundKey in each round of AES in details.<\/p>\r\n&nbsp;\r\n<div>\r\n\r\n<strong>2.2 ShiftRows<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The ShiftRows stage provides a simple \u201cpermutation\u201d of the data, whereas the other steps involve substitutions. Further, since the state is treated as a block of columns, it is this step which provides for diffusion of values between columns. It performs a circular rotate on each row of 0, 1, 2 &amp; 3 places for respective rows. When decrypting it performs the circular shifts in the opposite direction for each row. This row shift moves an individual\u00a0byte from one column to another, which is a linear distance of a multiple of 4 bytes, and ensures that the 4 bytes of one column are spread out to four different columns.<\/p>\r\n\r\n<\/div>\r\n<strong>2.3 ShiftRows Scheme<\/strong>\r\n\r\n&nbsp;\r\n\r\nFigure given below illustrates the Shift Rows permutation.\r\n\r\n<img class=\"alignnone size-full wp-image-271\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16.png\" alt=\"\" width=\"573\" height=\"426\" \/>\r\n\r\n<strong>2.4 MixColumns<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The MixColumns stage is a substitution that makes use of arithmetic over GF(28 ). Each byte of a column is mapped into a new value that is a function of all four bytes in that column. It is designed as a matrix multiplication where each byte is treated as a polynomial in GF(28). The inverse used for decryption involves a different set of constants.<\/p>\r\nEffectively a matrix multiplication in GF(28) using prime poly m(x) =x8+x4+x3+x+1\r\n\r\n<img class=\"alignnone size-full wp-image-272\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17.png\" alt=\"\" width=\"532\" height=\"144\" \/>\r\n\r\n&nbsp;\r\n\r\nThe constants used are based on a linear code with maximal distance between code words\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">\u2013 this gives good mixing of the bytes within each column. Combined with the \u201cshift rows\u201d step provides good avalanche, so that within a few rounds, all output bits depend<\/p>\r\non all input bits.\r\n\r\n&nbsp;\r\n\r\nThe following figure illustrates the Mix Columns transformation.\r\n\r\n<img class=\"alignnone size-full wp-image-273\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18.png\" alt=\"\" width=\"510\" height=\"288\" \/>\r\n<div>\r\n<p style=\"text-align: justify\">In practise, you implement Mix Columns by expressing the transformation on each column as 4 equations (Stallings equation 5.4) to compute the new bytes for that column. This computation only involves shifts, XORs &amp; conditional XORs (for the modulo reduction).<\/p>\r\n&nbsp;\r\n<p style=\"text-align: justify\">The decryption computation requires the use of the inverse of the matrix, which has larger coefficients, and is thus potentially a little harder &amp; slower to implement.<\/p>\r\n\r\n<\/div>\r\n<p style=\"text-align: justify\">The designers &amp; the AES standard provide an alternate characterisation of Mix Columns, which treats each column of State to be a four-term polynomial with coefficients in GF(28). Each column is multiplied by a fixed polynomial a(x) given in Stallings eqn 5.7.<\/p>\r\n&nbsp;\r\n\r\nMixColumn and InvMixColumn is illustrated in the following figure.\r\n\r\n<img class=\"alignnone size-full wp-image-274\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19.png\" alt=\"\" width=\"562\" height=\"221\" \/>\r\n\r\n<strong>2.5 AddRoundKey<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">Lastly is the Add Round Key stage which is a simple bitwise XOR of the current block with a portion of the expanded key. Note this is the only step which makes use of the key and obscures the result, hence MUST be used at start and end of each round, since otherwise could undo effect of other steps. But the other steps provide confusion\/diffusion\/non-linearity. That us you can look at the cipher as a series of XOR with key then scramble\/permute block repeated. This is efficient and highly secure it is believed<\/p>\r\n<img class=\"alignnone size-full wp-image-275\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20.png\" alt=\"\" width=\"550\" height=\"175\" \/>\r\n\r\nThe above figure illustrates the Add Round Key stage, which like Byte Substitution, operates on each byte of state independently.\r\n\r\n<strong>2.6 AES Round<\/strong>\r\n\r\n&nbsp;\r\n\r\nNow view all the internal details of the AES round, showing how each byte of the state is manipulated, as shown in figure below.\r\n\r\n<img class=\"alignnone size-full wp-image-277\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22.png\" alt=\"\" width=\"548\" height=\"402\" \/>\r\n<div>\r\n\r\n<strong>2.7 AES Key Scheduling<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">The AES key expansion algorithm takes as input a 4-word (16-byte) key and produces a linear array of words, providing a 4-word round key for the initial AddRoundKey stage and each of the 10\/12\/14 rounds of the cipher. It involves copying the key into the first group of 4 words, and then constructing subsequent groups of 4 based on the values of the previous &amp; 4th back words. The first word in each group of 4 gets \u201cspecial treatment\u201d\u00a0with rotate + S-box + XOR constant on the previous word before XOR\u2019ing the one from 4 back. In the 256-bit key\/14 round version, there\u2019s also an extra step on the middle word.<\/p>\r\n\r\n<\/div>\r\n<img class=\"alignnone size-full wp-image-278\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23.png\" alt=\"\" width=\"509\" height=\"291\" \/>\r\n\r\nThe above table takes 128-bits (16-bytes) key and expands into array of 44 32-bit words\r\n\r\n&nbsp;\r\n\r\n<strong>2.8 Key Expansion Scheme<\/strong>\r\n\r\n<img class=\"alignnone size-full wp-image-279\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24.png\" alt=\"\" width=\"473\" height=\"366\" \/>\r\n\r\nThe sub keys are generated according to the above figure.\r\n\r\n&nbsp;\r\n\r\n<strong>2.9 Key Expansion submodule<\/strong>\r\n\r\n&nbsp;\r\n\r\n<strong>RotWord <\/strong>performs a one byte circular left shift on a word For example:\r\n\r\n&nbsp;\r\n\r\n<strong>RotWord[b0,b1,b2,b3] = [b1,b2,b3,b0]<\/strong>\r\n\r\n&nbsp;\r\n\r\n<strong>SubWord <\/strong>performs a byte substitution on each byte of input word using the S-box<strong> SubWord(RotWord(temp)) <\/strong>is XORed with RCon[j] \u2013 the round constant\r\n\r\n&nbsp;\r\n\r\n<strong>Round Constant (RCon)<\/strong>\r\n\r\n&nbsp;\r\n\r\nRCON is a word in which the three rightmost bytes are zero. It is different for each round and defined as:\r\n\r\n&nbsp;\r\n\r\nRCon[j] = (RCon[j],0,0,0)\r\n\r\n&nbsp;\r\n\r\nwhere RCon[1] =1 , RCon[j] = 2 * RCon[j-1]\r\n\r\n&nbsp;\r\n\r\nMultiplication is defined over GF(28) but can be implement in Table Lookup given below.\r\n\r\n<img class=\"alignnone size-full wp-image-280\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25.png\" alt=\"\" width=\"410\" height=\"209\" \/>\r\n\r\n<strong>2.1.0 Key Expansion Example (1<\/strong><strong>st<\/strong><strong> Round)<\/strong>\r\n<div>\r\n\r\n&nbsp;\r\n\r\nExample of expansion of a 128-bit cipher key Cipher key\r\n\r\n= 2b7e151628aed2a6abf7158809cf4f3c w0=2b7e1516\r\n\r\nw1=28aed2a6 w2=abf71588 w3=09cf4f3c\r\n\r\n<\/div>\r\n<img class=\"alignnone size-full wp-image-281\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26.png\" alt=\"\" width=\"586\" height=\"301\" \/>\r\n\r\n<strong>2.1.1 AES Security<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">AES was designed after DES. Most of the known attacks on DES were already tested on AES. In terms of security, AES is definitely more secure than DES due to the larger-size key. Numerous tests have failed to do statistical analysis of the ciphertext. There are no differential and linear attacks on AES as yet.<\/p>\r\n&nbsp;\r\n\r\n<strong>2.1.2 Implementation Aspects<\/strong>\r\n\r\n&nbsp;\r\n<p style=\"text-align: justify\">AES can also be very efficiently implemented on an 32-bit processor, by rewriting the stage transformation to use 4 table lookups &amp; 4 XOR\u2019s per column of state. These tables can be computed in advance using the formulae shown in the text, and need 4Kb to store.<\/p>\r\n&nbsp;\r\n\r\nThe developers of Rijndael believe that this compact, efficient implementation was probably one of the most important factors in the selection of Rijndael for AES.\r\n\r\n&nbsp;\r\n<div>\r\n\r\n<strong>Summary<\/strong>\r\n\r\n&nbsp;\r\n\r\nWe have considered:\r\n<ul>\r\n \t<li>The AES selection process<\/li>\r\n \t<li>The details of Rijndael \u2013 the AES cipher<\/li>\r\n \t<li><span style=\"text-align: initial;font-size: 1em\">Looked at the steps in each round in AES <\/span><\/li>\r\n \t<li><span style=\"text-align: initial;font-size: 1em\">The key expansion in AES<\/span><\/li>\r\n \t<li><span style=\"text-align: initial;font-size: 1em\">Implementation aspects of AES<\/span><\/li>\r\n<\/ul>\r\n<table>\r\n<tbody>\r\n<tr>\r\n<td><strong>you can view video on Advanced Encryption Standard(part2)<\/strong><\/td>\r\n<td><a href=\"https:\/\/youtu.be\/m4pU7uN5KhQ\" target=\"_blank\" rel=\"noopener\"><img class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n\r\n<img class=\"alignnone size-full wp-image-282\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27.png\" alt=\"\" width=\"586\" height=\"301\" \/> <img class=\"alignnone size-full wp-image-283\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48.jpg\" alt=\"\" width=\"613\" height=\"392\" \/>\r\n\r\n<\/div>","rendered":"<div><span style=\"float: right\"><a href=\"https:\/\/youtu.be\/m4pU7uN5KhQ\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"epgp books\" width=\"75px\" height=\"75px;\" \/><\/a><br \/>\n<\/span><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Learning Objectives:<\/strong><\/p>\n<ul>\n<li>To understand the AES selection process<\/li>\n<li>To know the details of Rijndael \u2013 the AES cipher<\/li>\n<li>Discuss about the steps in each round and the key expansion<\/li>\n<li>To understand the implementation aspects<\/li>\n<\/ul>\n<p><strong>2.1 Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">We have studied AES selection process, key expansion and implementation aspects in last module. This section deals with different operations such as ShiftRows,MixColumns,AddRoundKey in each round of AES in details.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>2.2 ShiftRows<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The ShiftRows stage provides a simple \u201cpermutation\u201d of the data, whereas the other steps involve substitutions. Further, since the state is treated as a block of columns, it is this step which provides for diffusion of values between columns. It performs a circular rotate on each row of 0, 1, 2 &amp; 3 places for respective rows. When decrypting it performs the circular shifts in the opposite direction for each row. This row shift moves an individual\u00a0byte from one column to another, which is a linear distance of a multiple of 4 bytes, and ensures that the 4 bytes of one column are spread out to four different columns.<\/p>\n<\/div>\n<p><strong>2.3 ShiftRows Scheme<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Figure given below illustrates the Shift Rows permutation.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-271\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16.png\" alt=\"\" width=\"573\" height=\"426\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16.png 573w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16-300x223.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16-65x48.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16-225x167.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-16-350x260.png 350w\" sizes=\"auto, (max-width: 573px) 100vw, 573px\" \/><\/p>\n<p><strong>2.4 MixColumns<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The MixColumns stage is a substitution that makes use of arithmetic over GF(28 ). Each byte of a column is mapped into a new value that is a function of all four bytes in that column. It is designed as a matrix multiplication where each byte is treated as a polynomial in GF(28). The inverse used for decryption involves a different set of constants.<\/p>\n<p>Effectively a matrix multiplication in GF(28) using prime poly m(x) =x8+x4+x3+x+1<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-272\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17.png\" alt=\"\" width=\"532\" height=\"144\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17.png 532w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17-300x81.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17-65x18.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17-225x61.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-17-350x95.png 350w\" sizes=\"auto, (max-width: 532px) 100vw, 532px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>The constants used are based on a linear code with maximal distance between code words<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">\u2013 this gives good mixing of the bytes within each column. Combined with the \u201cshift rows\u201d step provides good avalanche, so that within a few rounds, all output bits depend<\/p>\n<p>on all input bits.<\/p>\n<p>&nbsp;<\/p>\n<p>The following figure illustrates the Mix Columns transformation.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-273\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18.png\" alt=\"\" width=\"510\" height=\"288\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18.png 510w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18-300x169.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18-65x37.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18-225x127.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-18-350x198.png 350w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/p>\n<div>\n<p style=\"text-align: justify\">In practise, you implement Mix Columns by expressing the transformation on each column as 4 equations (Stallings equation 5.4) to compute the new bytes for that column. This computation only involves shifts, XORs &amp; conditional XORs (for the modulo reduction).<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The decryption computation requires the use of the inverse of the matrix, which has larger coefficients, and is thus potentially a little harder &amp; slower to implement.<\/p>\n<\/div>\n<p style=\"text-align: justify\">The designers &amp; the AES standard provide an alternate characterisation of Mix Columns, which treats each column of State to be a four-term polynomial with coefficients in GF(28). Each column is multiplied by a fixed polynomial a(x) given in Stallings eqn 5.7.<\/p>\n<p>&nbsp;<\/p>\n<p>MixColumn and InvMixColumn is illustrated in the following figure.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-274\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19.png\" alt=\"\" width=\"562\" height=\"221\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19.png 562w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19-300x118.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19-65x26.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19-225x88.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-19-350x138.png 350w\" sizes=\"auto, (max-width: 562px) 100vw, 562px\" \/><\/p>\n<p><strong>2.5 AddRoundKey<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">Lastly is the Add Round Key stage which is a simple bitwise XOR of the current block with a portion of the expanded key. Note this is the only step which makes use of the key and obscures the result, hence MUST be used at start and end of each round, since otherwise could undo effect of other steps. But the other steps provide confusion\/diffusion\/non-linearity. That us you can look at the cipher as a series of XOR with key then scramble\/permute block repeated. This is efficient and highly secure it is believed<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-275\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20.png\" alt=\"\" width=\"550\" height=\"175\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20.png 550w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20-300x95.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20-65x21.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20-225x72.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-20-350x111.png 350w\" sizes=\"auto, (max-width: 550px) 100vw, 550px\" \/><\/p>\n<p>The above figure illustrates the Add Round Key stage, which like Byte Substitution, operates on each byte of state independently.<\/p>\n<p><strong>2.6 AES Round<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>Now view all the internal details of the AES round, showing how each byte of the state is manipulated, as shown in figure below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-277\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22.png\" alt=\"\" width=\"548\" height=\"402\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22.png 548w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22-300x220.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22-65x48.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22-225x165.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-22-350x257.png 350w\" sizes=\"auto, (max-width: 548px) 100vw, 548px\" \/><\/p>\n<div>\n<p><strong>2.7 AES Key Scheduling<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">The AES key expansion algorithm takes as input a 4-word (16-byte) key and produces a linear array of words, providing a 4-word round key for the initial AddRoundKey stage and each of the 10\/12\/14 rounds of the cipher. It involves copying the key into the first group of 4 words, and then constructing subsequent groups of 4 based on the values of the previous &amp; 4th back words. The first word in each group of 4 gets \u201cspecial treatment\u201d\u00a0with rotate + S-box + XOR constant on the previous word before XOR\u2019ing the one from 4 back. In the 256-bit key\/14 round version, there\u2019s also an extra step on the middle word.<\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-278\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23.png\" alt=\"\" width=\"509\" height=\"291\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23.png 509w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23-300x172.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23-65x37.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23-225x129.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-23-350x200.png 350w\" sizes=\"auto, (max-width: 509px) 100vw, 509px\" \/><\/p>\n<p>The above table takes 128-bits (16-bytes) key and expands into array of 44 32-bit words<\/p>\n<p>&nbsp;<\/p>\n<p><strong>2.8 Key Expansion Scheme<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-279\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24.png\" alt=\"\" width=\"473\" height=\"366\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24.png 473w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24-300x232.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24-65x50.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24-225x174.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-24-350x271.png 350w\" sizes=\"auto, (max-width: 473px) 100vw, 473px\" \/><\/p>\n<p>The sub keys are generated according to the above figure.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>2.9 Key Expansion submodule<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>RotWord <\/strong>performs a one byte circular left shift on a word For example:<\/p>\n<p>&nbsp;<\/p>\n<p><strong>RotWord[b0,b1,b2,b3] = [b1,b2,b3,b0]<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><strong>SubWord <\/strong>performs a byte substitution on each byte of input word using the S-box<strong> SubWord(RotWord(temp)) <\/strong>is XORed with RCon[j] \u2013 the round constant<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Round Constant (RCon)<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>RCON is a word in which the three rightmost bytes are zero. It is different for each round and defined as:<\/p>\n<p>&nbsp;<\/p>\n<p>RCon[j] = (RCon[j],0,0,0)<\/p>\n<p>&nbsp;<\/p>\n<p>where RCon[1] =1 , RCon[j] = 2 * RCon[j-1]<\/p>\n<p>&nbsp;<\/p>\n<p>Multiplication is defined over GF(28) but can be implement in Table Lookup given below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-280\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25.png\" alt=\"\" width=\"410\" height=\"209\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25.png 410w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25-300x153.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25-65x33.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25-225x115.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-25-350x178.png 350w\" sizes=\"auto, (max-width: 410px) 100vw, 410px\" \/><\/p>\n<p><strong>2.1.0 Key Expansion Example (1<\/strong><strong>st<\/strong><strong> Round)<\/strong><\/p>\n<div>\n<p>&nbsp;<\/p>\n<p>Example of expansion of a 128-bit cipher key Cipher key<\/p>\n<p>= 2b7e151628aed2a6abf7158809cf4f3c w0=2b7e1516<\/p>\n<p>w1=28aed2a6 w2=abf71588 w3=09cf4f3c<\/p>\n<\/div>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-281\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26.png\" alt=\"\" width=\"586\" height=\"301\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26.png 586w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26-300x154.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26-65x33.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26-225x116.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-26-350x180.png 350w\" sizes=\"auto, (max-width: 586px) 100vw, 586px\" \/><\/p>\n<p><strong>2.1.1 AES Security<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">AES was designed after DES. Most of the known attacks on DES were already tested on AES. In terms of security, AES is definitely more secure than DES due to the larger-size key. Numerous tests have failed to do statistical analysis of the ciphertext. There are no differential and linear attacks on AES as yet.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>2.1.2 Implementation Aspects<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: justify\">AES can also be very efficiently implemented on an 32-bit processor, by rewriting the stage transformation to use 4 table lookups &amp; 4 XOR\u2019s per column of state. These tables can be computed in advance using the formulae shown in the text, and need 4Kb to store.<\/p>\n<p>&nbsp;<\/p>\n<p>The developers of Rijndael believe that this compact, efficient implementation was probably one of the most important factors in the selection of Rijndael for AES.<\/p>\n<p>&nbsp;<\/p>\n<div>\n<p><strong>Summary<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>We have considered:<\/p>\n<ul>\n<li>The AES selection process<\/li>\n<li>The details of Rijndael \u2013 the AES cipher<\/li>\n<li><span style=\"text-align: initial;font-size: 1em\">Looked at the steps in each round in AES <\/span><\/li>\n<li><span style=\"text-align: initial;font-size: 1em\">The key expansion in AES<\/span><\/li>\n<li><span style=\"text-align: initial;font-size: 1em\">Implementation aspects of AES<\/span><\/li>\n<\/ul>\n<table>\n<tbody>\n<tr>\n<td><strong>you can view video on Advanced Encryption Standard(part2)<\/strong><\/td>\n<td><a href=\"https:\/\/youtu.be\/m4pU7uN5KhQ\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-120\" src=\"http:\/\/epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/2018\/11\/download.png\" alt=\"\" width=\"36\" height=\"36\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-282\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27.png\" alt=\"\" width=\"586\" height=\"301\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27.png 586w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27-300x154.png 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27-65x33.png 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27-225x116.png 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/2-27-350x180.png 350w\" sizes=\"auto, (max-width: 586px) 100vw, 586px\" \/> <img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-283\" src=\"http:\/\/csp11.epgpbooks.inflibnet.ac.in\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48.jpg\" alt=\"\" width=\"613\" height=\"392\" srcset=\"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48.jpg 613w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48-300x192.jpg 300w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48-65x42.jpg 65w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48-225x144.jpg 225w, https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-content\/uploads\/sites\/55\/2018\/07\/Capture-48-350x224.jpg 350w\" sizes=\"auto, (max-width: 613px) 100vw, 613px\" \/><\/p>\n<\/div>\n","protected":false},"author":3,"menu_order":19,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-270","chapter","type-chapter","status-publish","hentry"],"part":3,"_links":{"self":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/users\/3"}],"version-history":[{"count":4,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/270\/revisions"}],"predecessor-version":[{"id":572,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/270\/revisions\/572"}],"part":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/parts\/3"}],"metadata":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapters\/270\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/media?parent=270"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/pressbooks\/v2\/chapter-type?post=270"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/contributor?post=270"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/ebooks.inflibnet.ac.in\/csp11\/wp-json\/wp\/v2\/license?post=270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}