Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -2,7 +2,7 @@
|
||||
|
||||
- AES superseded DES as a standard in 2002
|
||||
|
||||

|
||||

|
||||
|
||||
- Uses rounds of 4 layers and a final round of 3
|
||||
- Bytes are represented as a 4x4 block called the *state*
|
||||
@@ -19,12 +19,12 @@ First row doesn’t move, second row is shifted to the left by 1, the third row
|
||||
|
||||
Then, when the columns are mixed, this means the overall diffusion is extremely good
|
||||
|
||||
The last round doesn’t have a **mix column** step as its reversible and wouldn’t add additional security.
|
||||
The last round doesn’t have a **mix column** step as it's reversible and wouldn’t add additional security.
|
||||
|
||||
#### S-Box
|
||||
|
||||
- The AES s-box is based around the multiplicative inverse of 8-bit values in $GF(2^8)$
|
||||
- This is strongly *non-linear* mapping
|
||||
- This is a strongly *non-linear* mapping
|
||||
|
||||
$$
|
||||
A_i \cdot A_i^{-1} \equiv 1 \space (mod \space P(x)) \\
|
||||
@@ -37,7 +37,7 @@ $$
|
||||

|
||||
|
||||
- Note: 0 maps to 0
|
||||
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
|
||||
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
|
||||
- This destroys any remaining mathematical structure
|
||||
|
||||

|
||||
@@ -46,15 +46,15 @@ Remember an affine transformation is a multiplication and addition by two consta
|
||||
|
||||
##### S-box Properties
|
||||
|
||||
- The s-box simply described, and is bijective, an invertible 1:1 mapping
|
||||
- The s-box is simply described, and is bijective, an invertible 1:1 mapping
|
||||
- It has no fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) = A_i$
|
||||
- i.e. no $A_i$ for which $S(A_i) = A_i$
|
||||
- No inverse fixed points
|
||||
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
|
||||
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
|
||||
- Minimisation of the largest non-trivial correlation between linear combinations of input bits and linear combinations of output bits
|
||||
- 0 is a non-trivial combination
|
||||
- 0 is a non-trivial combination
|
||||
- Minimisation of the largest non-trivial value in the `EXOR` table
|
||||
- This stops differential cryptanalysis
|
||||
- This stops differential cryptanalysis
|
||||
|
||||
#### AES Diffusion
|
||||
|
||||
@@ -86,48 +86,54 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
|
||||
|
||||
- The first round key used is just the key
|
||||
- We then take $W[3]$ and put it through the $g$ function which just permutes it
|
||||
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
|
||||
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
|
||||
- Like for example if we had a bit stream of all 0s
|
||||
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
|
||||
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
|
||||
- Like for example if we had a bit stream of all 0s
|
||||
|
||||
### Implementation
|
||||
|
||||
1. All addition and subtractions are `xor`
|
||||
1. All additions and subtractions are `xor`
|
||||
|
||||
2. Multiply by `01` has no effect
|
||||
2. Multiplying by `01` has no effect
|
||||
|
||||
3. Multiplying by `02` (which is $x$) is simply a left shift followed by modular reduction
|
||||
|
||||
- Left shift multiplies by $x$
|
||||
- Left shift multiplies by $x$
|
||||
|
||||
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
|
||||
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
|
||||
|
||||
- ```java
|
||||
// xtime
|
||||
if ((a & 0x80) > 0) {
|
||||
a = (a << 1) ^ 0x1b;
|
||||
} else {
|
||||
a <<= 1;
|
||||
}
|
||||
```
|
||||
- Example:
|
||||
|
||||
4. Multiply by `03` ($x+1$) is simply `xtime(a) ^ a`
|
||||
```java
|
||||
// xtime
|
||||
if ((a & 0x80) > 0) {
|
||||
a = (a << 1) ^ 0x1b;
|
||||
} else {
|
||||
a <<= 1;
|
||||
}
|
||||
```
|
||||
|
||||
- Inverse multiplications are by `09`, `11`, `13`, `14`. these require either a more general function or lookup tables
|
||||
4. Multiplying by `03` ($x+1$) is simply `xtime(a) ^ a`
|
||||
|
||||
- Inverse multiplications are by `09`, `11`, `13`, `14`. These require either a more general function or lookup tables
|
||||
|
||||
- Consider the sum:
|
||||
|
||||
- $$
|
||||
a = x^6 + x^4 + x^2 + 1 \\
|
||||
b = x^7 + x^4 + x^2 + x \\
|
||||
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
|
||||
$$
|
||||
- Product:
|
||||
|
||||
- $$
|
||||
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
|
||||
$$
|
||||
$$
|
||||
a = x^6 + x^4 + x^2 + 1 \\
|
||||
b = x^7 + x^4 + x^2 + x \\
|
||||
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
|
||||
$$
|
||||
|
||||
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeated multiplying $a$ by $x$.
|
||||
- Repeated multiplication:
|
||||
|
||||
$$
|
||||
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
|
||||
$$
|
||||
|
||||
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeatedly multiplying $a$ by $x$.
|
||||
|
||||
- AES is very **fast in software** and pretty **fast in hardware**
|
||||
|
||||
@@ -135,11 +141,11 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
|
||||
|
||||
- Much of the algorithm can be converted into a series of lookup tables
|
||||
|
||||
- **Trade off** between **speed** and **space**
|
||||
- **Trade-off** between **speed** and **space**
|
||||
|
||||
- There are numerous cache-timing and other attacks possible
|
||||
|
||||
- Implementation must be constant time
|
||||
- CPU instructions help mitigate this
|
||||
- Implementation must be constant time
|
||||
- CPU instructions help mitigate this
|
||||
|
||||
- In general AES is much harder to implement safely than `ChaCha20`
|
||||
Reference in new issue
Block a user