Linearity of the AES Key Schedule
The AES key schedule can almost be described as collection of 32 linear feedback shift registers LFSRs, working in parallel. This implies that for related keys, i.e., pairs of unknown keys with known differences, one can in part predict the differences of the individual round keys. Such a property has been used (but not explained in detail) by Ferguson et al.  for a related key attack on a 9-round variant of the AES (with 256-bit keys). In the current paper, we study the propagation of (known) key differences in the key schedule for all three key sizes of the AES.
Unable to display preview. Download preview PDF.
- 1.Nicolas Courtois, Private CommunicationGoogle Scholar