Schneier spoke some days ago about a “non brute force attack” against AES algorithm.
The paper is “Related-key Cryptanalysis of the Full AES-192 and AES-256“:
Abstract. In this paper we present two related-key attacks on the full AES. For AES-256 we show the first key recovery attack that works for all the keys and has complexity 2119, while the recent attack by Biryukov-Khovratovich-Nikolic works for a weak key class and has higher complexity. The second attack is the first cryptanalysis of the full AES-192. Both our attacks are boomerang attacks, which are based on the recent idea of finding local collisions in block ciphers and enhanced with the boomerang switching techniques to gain free rounds in the middle.
The authors spoke about a possible reduction of complexity from 2119 to about 2110.5
The attack is, and probably forever will be, theoretical. But remember: attacks always get better, they never get worse. Others will continue to improve on these numbers. While there’s no reason to panic, no reason to stop using AES, no reason to insist that NIST choose another encryption standard, this will certainly be a problem for some of the AES-based SHA-3 candidate hash functions.
We meditate about that



2 Responses to “AES – Cryptanalysis season is started”
[...] di una password cifrata in un qualsiasi algoritmo in mancanza di weakness specifiche (es. WEP e/o AES) può risultare un’attività tediosa e priva di soddisfazioni [...]
[...] 30th, 2009Andrea L. Two weeks ago, we post and article about a “possible” vulnerability in AES algorithm. We have say something like WOW! The cryptanalysis season is [...]