Add the rest of university notes
This commit is contained in:
366 files changed
+9844
-110
No files matched your search
@@ -0,0 +1,145 @@
|
||||
# Advanced Encryption Standard (AES)
|
||||
|
||||
- AES superseded DES as a standard in 2002
|
||||
|
||||

|
||||
|
||||
- Uses rounds of 4 layers and a final round of 3
|
||||
- Bytes are represented as a 4x4 block called the *state*
|
||||
|
||||

|
||||
|
||||
**Sub-Bytes** - similar to s-boxes in DES
|
||||
|
||||
**Shift Rows** - diffusion and permutation round
|
||||
|
||||

|
||||
|
||||
First row doesn’t move, second row is shifted to the left by 1, the third row is shifted two places to the left etc
|
||||
|
||||
Then, when the columns are mixed, this means the overall diffusion is extremely good
|
||||
|
||||
The last round doesn’t have a **mix column** step as its reversible and wouldn’t add additional security.
|
||||
|
||||
#### S-Box
|
||||
|
||||
- The AES s-box is based around the multiplicative inverse of 8-bit values in $GF(2^8)$
|
||||
- This is strongly *non-linear* mapping
|
||||
|
||||
$$
|
||||
A_i \cdot A_i^{-1} \equiv 1 \space (mod \space P(x)) \\
|
||||
B'_i = \begin{cases}
|
||||
0 \quad\quad\quad i=0 \\
|
||||
A_i^{-1} \quad\space\space\space i > 0
|
||||
\end{cases}
|
||||
$$
|
||||
|
||||

|
||||
|
||||
- Note: 0 maps to 0
|
||||
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
|
||||
- This destroys any remaining mathematical structure
|
||||
|
||||

|
||||
|
||||
Remember an affine transformation is a multiplication and addition by two constants (think of the affine cipher)
|
||||
|
||||
##### S-box Properties
|
||||
|
||||
- The s-box simply described, and is bijective, an invertible 1:1 mapping
|
||||
- It has no fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) = A_i$
|
||||
- No inverse fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
|
||||
- Minimisation of the largest non-trivial correlation between linear combinations of input bits and linear combinations of output bits
|
||||
- 0 is a non-trivial combination
|
||||
- Minimisation of the largest non-trivial value in the `EXOR` table
|
||||
- This stops differential cryptanalysis
|
||||
|
||||
#### AES Diffusion
|
||||
|
||||
Diffusion in AES consists of two layers:
|
||||
|
||||
1. Shift rows
|
||||
2. Mix columns
|
||||
|
||||
Shift rows simply moves bytes around the block
|
||||
|
||||

|
||||
|
||||
##### Mix Columns
|
||||
|
||||
- Performs a linear mixing of bytes within each column
|
||||
- All the input bytes in a column influence all the output bytes
|
||||
|
||||

|
||||
|
||||
- Multiplying by `01` does not change the result
|
||||
|
||||
When multiplying by $x$, there’s a shortcut we can implement. We can set the equation equal to 0, and `xor` by $x^4 - x^3 - x - 1$
|
||||
|
||||

|
||||
|
||||
### Key Schedule
|
||||
|
||||

|
||||
|
||||
- The first round key used is just the key
|
||||
- We then take $W[3]$ and put it through the $g$ function which just permutes it
|
||||
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
|
||||
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
|
||||
- Like for example if we had a bit stream of all 0s
|
||||
|
||||
### Implementation
|
||||
|
||||
1. All addition and subtractions are `xor`
|
||||
|
||||
2. Multiply by `01` has no effect
|
||||
|
||||
3. Multiplying by `02` (which is $x$) is simply a left shift followed by modular reduction
|
||||
|
||||
- Left shift multiplies by $x$
|
||||
|
||||
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
|
||||
|
||||
- ```java
|
||||
// xtime
|
||||
if ((a & 0x80) > 0) {
|
||||
a = (a << 1) ^ 0x1b;
|
||||
} else {
|
||||
a <<= 1;
|
||||
}
|
||||
```
|
||||
|
||||
4. Multiply by `03` ($x+1$) is simply `xtime(a) ^ a`
|
||||
|
||||
- Inverse multiplications are by `09`, `11`, `13`, `14`. these require either a more general function or lookup tables
|
||||
|
||||
- Consider the sum:
|
||||
|
||||
- $$
|
||||
a = x^6 + x^4 + x^2 + 1 \\
|
||||
b = x^7 + x^4 + x^2 + x \\
|
||||
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
|
||||
$$
|
||||
|
||||
- $$
|
||||
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
|
||||
$$
|
||||
|
||||
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeated multiplying $a$ by $x$.
|
||||
|
||||
- AES is very **fast in software** and pretty **fast in hardware**
|
||||
|
||||
- CPU instructions in AES-NI make AES much faster
|
||||
|
||||
- Much of the algorithm can be converted into a series of lookup tables
|
||||
|
||||
- **Trade off** between **speed** and **space**
|
||||
|
||||
- There are numerous cache-timing and other attacks possible
|
||||
|
||||
- Implementation must be constant time
|
||||
- CPU instructions help mitigate this
|
||||
|
||||
- In general AES is much harder to implement safely than `ChaCha20`
|
||||
Reference in new issue
Block a user