CRYPTOGRAPHY
Symmetric Key Encryption
Ciphers
ADVANCED ENCRYPTION STANDARD
• The more popular and widely adopted symmetric
encryption algorithm likely to be encountered
nowadays is the Advanced Encryption Standard (AES).
• It is found at least six time faster than triple DES.
• A replacement for DES was needed as its key size was
too small.
• With increasing computing power, it was considered
vulnerable against exhaustive key search attack.
• Triple DES was designed to overcome this drawback
but it was found slow.
THE FEATURES OF AES
• Symmetric key symmetric block cipher
• Block size = 128 bits
• 128-bit data, 128/192/256-bit keys
• Stronger and faster than Triple-DES
• Provide full specification and design details
• Software implementable in C and Java
OPERATION OF AES
• AES is an iterative rather than Feistel cipher.
• It is based on ‘substitution–permutation network.
• It comprises of a series of linked operations, some of
which involve replacing inputs by specific outputs
(substitutions) and others involve shuffling bits around
(permutations).
CONT.
• Interestingly, AES performs all its computations on bytes rather
than bits.
• Hence, AES treats the 128 bits of a plaintext block as 16 bytes.
• These 16 bytes are arranged in four columns and four rows for
processing as a matrix .
• Unlike DES, the number of rounds in AES is variable and depends
on the length of the key.
• AES uses 10 rounds for 128-bit keys, 12 rounds for 192-bit
keys and 14 rounds for 256-bit keys.
• Each of these rounds uses a different 128-bit round key, which is
calculated from the original AES key.
Each block represents
1-byte
S0,0 S0,1 S0,2 S0,3
S1,0 S1,1 S1,2 S1,3
[W0, W1, W2, W3]
S2,0 S2,1 S2,2 S2,3
S3,0 S3,1 S3,2 S3,3
Key Size= 128-Bits or 4 Words
K0 K4 K8 K12
Key Expansion
Algorithm
K1 K5 K9 K13 K0 K1 K2 … K41 K42 K43
K2 K6 K10 K14 44 Words
K3 K7 K11 K15
ENCRYPTION PROCESS
XOR Operation
4 words will be used
as subkeys
STRUCTURE OF EACH ROUND
TRANSFORMATION
• There are four types of transformation
– Substitution
– Permutation
– Mixing
– Key-adding
CONT.
Byte Substitution (SubBytes)
• The 16 input bytes are substituted by looking up a fixed table (S-
box) given in design.
• The result is in a matrix of four rows and four columns.
S-BOX
Only one table is used for the transformation of the bytes, which
means if two bytes are same then the transformation will also be
the same.
SHIFT-ROWS/PERMUTATION
• Each of the four rows of the matrix is shifted to the
left.
• Any entries that ‘fall off’ are re-inserted on the right
side of row.
MIX COLUMNS
• Each column of four bytes is now transformed using a special mathematical
function.
• This function takes as input the four bytes of one column and outputs four
completely new bytes, which replace the original column.
• The result is another new matrix consisting of 16 new bytes.
• It should be noted that this step is not performed in the last round.
ADD ROUND KEY
• The 16 bytes of the matrix are now considered as 128 bits and
are XORed to the 128 bits of the round key.
• If this is the last round then the output is the cipher-text.
• Otherwise, the resulting 128 bits are interpreted as 16 bytes and
we begin another similar round.