This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

+44 -38
View File
@@ -2,7 +2,7 @@
- AES superseded DES as a standard in 2002
![1646490755.png](img/1646490755.png)
![1646490755.png](img/1646490755.png)
- Uses rounds of 4 layers and a final round of 3
- Bytes are represented as a 4x4 block called the *state*
@@ -19,12 +19,12 @@ First row doesn’t move, second row is shifted to the left by 1, the third row
Then, when the columns are mixed, this means the overall diffusion is extremely good
The last round doesn’t have a **mix column** step as its reversible and wouldn’t add additional security.
The last round doesn’t have a **mix column** step as it's reversible and wouldn’t add additional security.
#### S-Box
- The AES s-box is based around the multiplicative inverse of 8-bit values in $GF(2^8)$
- This is strongly *non-linear* mapping
- This is a strongly *non-linear* mapping
$$
A_i \cdot A_i^{-1} \equiv 1 \space (mod \space P(x)) \\
@@ -37,7 +37,7 @@ $$
![1646491900.png](img/1646491900.png)
- Note: 0 maps to 0
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
- The inverses $B'_i$ then undergo an **affine transformation** to produce the final s-box
- This destroys any remaining mathematical structure
![1646491995.png](img/1646491995.png)
@@ -46,15 +46,15 @@ Remember an affine transformation is a multiplication and addition by two consta
##### S-box Properties
- The s-box simply described, and is bijective, an invertible 1:1 mapping
- The s-box is simply described, and is bijective, an invertible 1:1 mapping
- It has no fixed points
- i.e. no $A_i$ for which $S(A_i) = A_i$
- i.e. no $A_i$ for which $S(A_i) = A_i$
- No inverse fixed points
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
- i.e. no $A_i$ for which $S(A_i) \oplus A_i = FF$
- Minimisation of the largest non-trivial correlation between linear combinations of input bits and linear combinations of output bits
- 0 is a non-trivial combination
- 0 is a non-trivial combination
- Minimisation of the largest non-trivial value in the `EXOR` table
- This stops differential cryptanalysis
- This stops differential cryptanalysis
#### AES Diffusion
@@ -86,48 +86,54 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
- The first round key used is just the key
- We then take $W[3]$ and put it through the $g$ function which just permutes it
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
- Like for example if we had a bit stream of all 0s
- $g$ takes the word, shifts it one to the right and then passes it through the s-boxes
- We then `xor` it with $RC[i]$ which is just a constant value to ensure *something* changes
- Like for example if we had a bit stream of all 0s
### Implementation
1. All addition and subtractions are `xor`
1. All additions and subtractions are `xor`
2. Multiply by `01` has no effect
2. Multiplying by `01` has no effect
3. Multiplying by `02` (which is $x$) is simply a left shift followed by modular reduction
- Left shift multiplies by $x$
- Left shift multiplies by $x$
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
- If the original $x^7$ bit was set, then we must `xor` with `0x1B`
- ```java
// xtime
if ((a & 0x80) > 0) {
a = (a << 1) ^ 0x1b;
} else {
a <<= 1;
}
```
- Example:
4. Multiply by `03` ($x+1$) is simply `xtime(a) ^ a`
```java
// xtime
if ((a & 0x80) > 0) {
a = (a << 1) ^ 0x1b;
} else {
a <<= 1;
}
```
- Inverse multiplications are by `09`, `11`, `13`, `14`. these require either a more general function or lookup tables
4. Multiplying by `03` ($x+1$) is simply `xtime(a) ^ a`
- Inverse multiplications are by `09`, `11`, `13`, `14`. These require either a more general function or lookup tables
- Consider the sum:
- $$
a = x^6 + x^4 + x^2 + 1 \\
b = x^7 + x^4 + x^2 + x \\
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
$$
- Product:
- $$
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
$$
$$
a = x^6 + x^4 + x^2 + 1 \\
b = x^7 + x^4 + x^2 + x \\
\therefore a\cdot b = a\cdot x^7 + a\cdot x^4 + a\cdot x^2 + a\cdot x
$$
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeated multiplying $a$ by $x$.
- Repeated multiplication:
$$
a\curvearrowright a\cdot x \curvearrowright a\cdot x^2 \curvearrowright a\cdot x^3 \curvearrowright a\cdot x^4 \curvearrowright a\cdot x^5
$$
- Here in $a\cdot b$, $a$ is just being multiplied by various powers of $x$. This can be easily calculated by repeatedly multiplying $a$ by $x$.
- AES is very **fast in software** and pretty **fast in hardware**
@@ -135,11 +141,11 @@ When multiplying by $x$, there’s a shortcut we can implement. We can set the e
- Much of the algorithm can be converted into a series of lookup tables
- **Trade off** between **speed** and **space**
- **Trade-off** between **speed** and **space**
- There are numerous cache-timing and other attacks possible
- Implementation must be constant time
- CPU instructions help mitigate this
- Implementation must be constant time
- CPU instructions help mitigate this
- In general AES is much harder to implement safely than `ChaCha20`