Weak-Key Distinguishers for AES

Grassi, Lorenzo
Leander, Gregor
Rechberger, Christian
Tezcan, Cihangir
Wiemer, Friedrich
In this paper, we analyze the security of AES in the case in which the whitening key is a weak key.
27th International Conference on Selected Areas in Cryptography (SAC)


In this paper, we analyze the security of AES in the case in which the whitening key is a weak key.After a systematization of the classes of weak-keys of AES, we perform an extensive analysis of weak-key distinguishers (in the single-key setting) for AES instantiated with the original key-schedule and with the new key-schedule proposed at ToSC/FSE’18. As one of the main results, we show that (almost) all the secret-key distinguishers for round-reduced AES currently present in the literature can be set up fo...
