A new 5-round distinguisher of AES with key whitening is presented by using the properties of its round transformation. Based on this distinguisher, we present new meet-in-the-middle attacks on reduced AES considering the key schedule and the time-memory tradeoff approach. New attacks improve the best known meet-in-the-middle attacks on reduced AES presented at FSE2008. We reduce the time complexity of attacks on 7-round AES-192 and 8-round AES-256 by a factor of at least 2(8). Moreover, the distinguisher can be exploited to develop the attack on 8-round AES-192.
English Abstract:
A new 5-round distinguisher of AES with key whitening is presented by using the properties of its round transformation. Based on this distinguisher, we present new meet-in-the-middle attacks on reduced AES considering the key schedule and the time-memory tradeoff approach. New attacks improve the best known meet-in-the-middle attacks on reduced AES presented at FSE2008. We reduce the time complexity of attacks on 7-round AES-192 and 8-round AES-256 by a factor of at least 2(8). Moreover, the distinguisher can be exploited to develop the attack on 8-round AES-192.