Skip to main navigation Skip to search Skip to main content

Improved meet-in-the-middle attack on 10 rounds of the AES-256 block cipher

  • Jiqiang Lu*
  • , Wenchang Zhou
  • *Corresponding author for this work
  • State Key Laboratory of Cryptology
  • Beihang University

Research output: Contribution to journalArticlepeer-review

Abstract

Meet-in-the-middle (MitM) attack method has led to the best currently published cryptanalytic results on the AES block cipher in the single-key attack scenario, except biclique attack. Particularly, for AES with a 256-bit key (AES-256), Li and Jin published a MitM attack on 10-round AES-256 in 2016, which has a data complexity of 2111 chosen plaintexts, a memory complexity of 2215.2 bytes and a time complexity of 2253 10-round AES-256 encryptions under so-called weak-key approach. In this paper, we observe that the memory complexity of Li and Jin’s attack should be 2217.4 bytes, then we show that three other byte key relations can be used to further reduce the memory complexity in Li and Jin’s attack by decomposing Li and Jin’s big precomputational table into two smaller ones and using MixColumns’ property to connect the two smaller tables in online key-recovery phase, which produces a 10-round AES-256 attack with a memory complexity of 2189 bytes and a time complexity of 2255 10-round AES encryptions, and finally we exploit a different 6-round MitM distinguisher to mount a 10-round AES-256 attack with a data complexity of 2105 chosen plaintexts, a memory complexity of 2189 bytes and a time complexity of 2253.2 10-round AES encryptions. Our final attack has a much smaller data and memory complexity and a marginally larger time complexity than Li and Jin’s attack.

Original languageEnglish
Pages (from-to)957-973
Number of pages17
JournalDesigns, Codes, and Cryptography
Volume92
Issue number4
DOIs
StatePublished - Apr 2024

Keywords

  • 94A60
  • AES
  • Block cipher
  • Cryptology
  • Differential cryptanalysis
  • Meet-in-the-middle attack

Fingerprint

Dive into the research topics of 'Improved meet-in-the-middle attack on 10 rounds of the AES-256 block cipher'. Together they form a unique fingerprint.

Cite this