This paper presents a new method for impossible differential cryptanalysis of 7-round Advanced Encryption Standard. This attack on the reduced 7-round AES requires about 2{sup}123.5 chosen plaintexts, demands 2{sup}89 words of memory, and performs 2{sup}122 7-round AES encryptions. Furthermore, it is only 2{sup}(-34.5) of the probability to fail to recover the secret key.
展开▼