<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 vector-feature-night-mode-enabled skin-theme-clientpref-os vector-sticky-header-enabled" lang="fr" dir="ltr"><head>
<meta charset="UTF-8">
<title>Advanced Encryption Standard</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://fr.wikipedia.org/wiki/Advanced_Encryption_Standard"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.math.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.pygments.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Advanced_Encryption_Standard rootpage-Advanced_Encryption_Standard skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span lang="en">Advanced Encryption Standard</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="fr" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="fr" dir="ltr"><p class="mw-empty-elt">
</p>
<div class="infobox_v3 infobox infobox--frwiki noarchive">
<div class="entete" style="background-color: #FEFFAD;">
<div>AES</div>
</div>
<div class="images">
</div>
<table><caption style="background-color:#FEFFAD;">Résumé</caption>
<tbody><tr>
<th scope="row">Concepteur(s)</th>
<td>
<a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a>, <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a></td>
</tr>
<tr>
<th scope="row">Première publication</th>
<td>
<a href="2000" title="2000">2000</a></td>
</tr>
<tr>
<th scope="row">Dérivé de</th>
<td>
<a href="Rijndael" title="Rijndael">Rijndael</a>, <a href="Square_(cryptographie)" title="Square (cryptographie)">Square</a></td>
</tr>
<tr>
<th scope="row">Chiffrement(s) basé(s) sur cet algorithme</th>
<td>
Aucun</td>
</tr>
</tbody></table>
<table><caption style="background-color:#FEFFAD;">Caractéristiques</caption>
<tbody><tr>
<th scope="row"><a href="Taille_de_bloc_(cryptographie)" title="Taille de bloc (cryptographie)">Taille(s) du bloc</a></th>
<td>
128 bits</td>
</tr>
<tr>
<th scope="row">Longueur(s) de la clé</th>
<td>
128, 192, 256 bits</td>
</tr>
<tr>
<th scope="row">Structure</th>
<td>
Réseau de substitution/permutation</td>
</tr>
<tr>
<th scope="row">Nombre de tours</th>
<td>
10,12 ou 14 selon la taille de la clé</td>
</tr>
</tbody></table>
<p class="bloc" style="background-color:#FEFFAD;">Meilleure <a href="Cryptanalyse" title="Cryptanalyse">cryptanalyse</a></p>
<p><small>Une attaque par clé apparentée casse 9 tours de AES-256. Une attaque par texte clair choisi casse 8 tours de AES-192 et 256, ou 7 tours de AES-128 (Ferguson et al, 2000).</small>
</p>
</div>
<p><i><b><span class="lang-en" lang="en">Advanced Encryption Standard</span></b></i> ou <b>AES</b> (<abbr class="abbr" title="littéralement">litt.</abbr> « norme de <a href="Chiffrement" title="Chiffrement">chiffrement</a> avancé »), aussi connu sous le nom de <a href="Rijndael" title="Rijndael">Rijndael</a>, est un <a href="Algorithmique" title="Algorithmique">algorithme</a> de <a href="Chiffrement_sym%C3%A9trique" class="mw-redirect" title="Chiffrement symétrique">chiffrement symétrique</a>. Il remporta en octobre <a href="2000" title="2000">2000</a> le <a href="Concours_AES" class="mw-redirect" title="Concours AES">concours AES</a>, lancé en 1997 par le <a href="NIST" class="mw-redirect" title="NIST">NIST</a> et devint le nouveau <a href="Norme_et_standard_techniques" title="Norme et standard techniques">standard</a> de chiffrement pour les organisations du gouvernement des <a href="%C3%89tats-Unis" title="États-Unis">États-Unis</a>. Il a été approuvé par la <a href="National_Security_Agency" title="National Security Agency">NSA</a> (National Security Agency) dans sa suite B des algorithmes cryptographiques <a href="https://en.wikipedia.org/wiki/NSA_Suite_B_Cryptography" class="extiw external" title="en:NSA Suite B Cryptography"><span class="indicateur-langue" title="Article en anglais : « NSA_Suite_B_Cryptography »">(en)</span></a><sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>.
</p><p>Le système <a href="Cryptographie" title="Cryptographie">cryptographique</a> AES est très fréquemment associé à la sécurisation de l'affichage des pages web ou des échanges de mails à travers l'usage de <a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a>. Son utilisation est extrêmement répandue<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Origine">Origine</h2></div>
<p>Il est issu d'un appel international à candidatures lancé en janvier <a href="1997" title="1997">1997</a> et ayant reçu 15 propositions. Parmi ces 15 algorithmes, 5 furent choisis pour une évaluation plus poussée en avril <a href="1999" title="1999">1999</a> : <a href="MARS_(cryptographie)" title="MARS (cryptographie)">MARS</a>, <a href="RC6" title="RC6">RC6</a>, <a href="Rijndael" title="Rijndael">Rijndael</a>, <a href="Serpent_(cryptographie)" title="Serpent (cryptographie)">Serpent</a>, et <a href="Twofish" title="Twofish">Twofish</a>. A l'issue du processus de sélection, ce fut le candidat <a href="Rijndael" title="Rijndael">Rijndael</a> - du nom de ses deux concepteurs <a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a> et <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a> (tous les deux de nationalité belge) - qui a été choisi<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>. Ces deux experts en cryptographie étaient déjà les auteurs d'un autre algorithme : <a href="Square_(cryptographie)" title="Square (cryptographie)">Square</a>. AES est un <a href="Sous-ensemble" class="mw-redirect" title="Sous-ensemble">sous-ensemble</a> de Rijndael : il ne travaille qu'avec des blocs de 128 bits alors que Rijndael offre des tailles de blocs et de clefs qui sont des multiples de 32 (compris entre 128 et 256 bits).
</p><p>Ce faisant, l'AES remplace le <a href="Data_Encryption_Standard" title="Data Encryption Standard">DES</a> (choisi comme standard dans les <a href="Ann%C3%A9es_1970" title="Années 1970">années 1970</a>) devenu obsolète car il utilise une clef de 56 <a href="Bit_(informatique)" class="mw-redirect" title="Bit (informatique)">bits</a> ; ce qui n'est plus assez robuste. L'AES a été adopté par le <a href="NIST" class="mw-redirect" title="NIST">NIST</a> (National Institute of Standards and Technology) en 2001<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>. Son utilisation ne nécessite que peu de mémoire et - n'étant pas basé sur un <a href="Sch%C3%A9ma_de_Feistel" class="mw-redirect" title="Schéma de Feistel">schéma de Feistel</a> - sa complexité est réduite de même que son implémentation est techniquement aisée.
</p>
<div class="mw-heading mw-heading2"><h2 id="Fonctionnement">Fonctionnement</h2></div>
<p>L'algorithme prend en entrée un bloc de 128 bits (16 <a href="Octet" title="Octet">octets</a>), la clé fait 128, 192 ou 256 bits. Les 16 octets en entrée sont permutés selon une table définie au préalable. Ces octets sont ensuite placés dans une <a href="Matrice_(math%C3%A9matiques)" title="Matrice (mathématiques)">matrice</a> de 4x4 éléments et ses lignes subissent une rotation vers la droite. L'incrément pour la rotation varie selon le numéro de la ligne. Une <a href="Transformation_lin%C3%A9aire" class="mw-redirect" title="Transformation linéaire">transformation linéaire</a> est ensuite appliquée sur la matrice, elle consiste en la multiplication binaire de chaque élément de la matrice avec des <a href="Polyn%C3%B4me" title="Polynôme">polynômes</a> issus d'une matrice auxiliaire, cette multiplication est soumise à des règles spéciales selon GF(2<sup>8</sup>) (<a href="Groupe_de_Galois" title="Groupe de Galois">groupe de Galois</a> ou <a href="Corps_fini" title="Corps fini">corps fini</a>). La transformation linéaire garantit une meilleure <a href="Confusion_et_diffusion" title="Confusion et diffusion">diffusion</a> (propagation des bits dans la structure) sur plusieurs tours.
</p><p>Finalement, un <a href="Fonction_OU_exclusif" title="Fonction OU exclusif">OU exclusif XOR</a> entre la matrice et une autre matrice permet d'obtenir une <a href="Matrice_(math%C3%A9matiques)" title="Matrice (mathématiques)">matrice</a> intermédiaire. Ces différentes opérations sont répétées plusieurs fois et définissent un « tour ». Pour une clé de 128, 192 ou 256, AES nécessite respectivement 10, 12 ou 14 tours.
</p>
<div class="mw-heading mw-heading3"><h3 id="Différence_entre_Rijndael_et_AES"><span id="Diff.C3.A9rence_entre_Rijndael_et_AES"></span>Différence entre Rijndael et AES</h3></div>
<p>La seule différence entre AES et Rijndael est l'ensemble des longueurs de bloc et la taille de clé. Rijndael est un bloc de chiffrement avec une longueur de bloc et une longueur de la clé variables. La longueur du bloc et la longueur de la clé peuvent être spécifiées indépendamment comme tout multiple de 32 bits, avec un minimum de 128 bits et un maximum de 256 bits. Il serait possible de définir des versions de Rijndael avec la longueur du bloc ou la longueur de la clé, mais il ne semble pas que cela soit nécessaire actuellement<sup id="cite_ref-:0_5-0" class="reference"><a href="#cite_note-:0-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>.
</p><p>L'AES fixe la longueur de bloc à 128 bits et prend en charge les longueurs de clé de 128, 192 ou 256 bits seulement. Les longueurs de bloc et de clé supplémentaires dans Rijndael ne sont pas évaluées dans le cadre du processus de sélection de l'AES, et par conséquent ils ne sont pas adoptés dans la norme FIPS actuelle<sup id="cite_ref-:0_5-1" class="reference"><a href="#cite_note-:0-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading3"><h3 id="Algorithme">Algorithme</h3></div><p>
Algorithme haut niveau pour le chiffrement avec Rijndael<sup id="cite_ref-:0_5-2" class="reference"><a href="#cite_note-:0-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>:</p><div class="mw-highlight mw-highlight-lang-vbnet mw-content-ltr" dir="ltr"><pre><span></span><span class="n">procedure</span><span class="w"> </span><span class="n">Rijndael</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">Cipherkey</span><span class="p">)</span>
<span class="w"> </span><span class="n">KeyExpansion</span><span class="p">(</span><span class="n">CipherKey</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="p">)</span>
<span class="w"> </span><span class="n">AddRoundKey</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="mi">0</span><span class="o">]</span><span class="p">)</span>
<span class="w"> </span><span class="k">for</span><span class="w"> </span><span class="n">i</span><span class="w"> </span><span class="o">=</span><span class="w"> </span><span class="mi">1</span><span class="w"> </span><span class="k">to</span><span class="w"> </span><span class="n">Nr</span><span class="w"> </span><span class="err">−</span><span class="w"> </span><span class="mi">1</span><span class="w"> </span><span class="k">do</span>
<span class="w"> </span><span class="n">Round</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">i</span><span class="o">]</span><span class="p">)</span>
<span class="w"> </span><span class="k">end</span><span class="w"> </span><span class="k">for</span>
<span class="w"> </span><span class="n">FinalRound</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">Nr</span><span class="o">]</span><span class="p">)</span>
<span class="k">end</span><span class="w"> </span><span class="n">procedure</span>
</pre></div><p>Les tours de transformation de Rijndael<sup id="cite_ref-:0_5-3" class="reference"><a href="#cite_note-:0-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup>:</p><div class="mw-highlight mw-highlight-lang-vbnet mw-content-ltr" dir="ltr"><pre><span></span><span class="n">procedure</span><span class="w"> </span><span class="n">Round</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">i</span><span class="o">]</span><span class="p">)</span>
<span class="w"> </span><span class="n">SubBytes</span><span class="p">(</span><span class="n">State</span><span class="p">)</span><span class="err">;</span>
<span class="w"> </span><span class="n">ShiftRows</span><span class="p">(</span><span class="n">State</span><span class="p">)</span><span class="err">;</span>
<span class="w"> </span><span class="n">MixColumns</span><span class="p">(</span><span class="n">State</span><span class="p">)</span><span class="err">;</span>
<span class="w"> </span><span class="n">AddRoundKey</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">i</span><span class="o">]</span><span class="p">)</span><span class="err">;</span>
<span class="k">end</span><span class="w"> </span><span class="n">procedure</span>
<span class="n">procedure</span><span class="w"> </span><span class="n">FinalRound</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">Nr</span><span class="o">]</span><span class="p">)</span>
<span class="w"> </span><span class="n">SubBytes</span><span class="p">(</span><span class="n">State</span><span class="p">)</span><span class="err">;</span>
<span class="w"> </span><span class="n">ShiftRows</span><span class="p">(</span><span class="n">State</span><span class="p">)</span><span class="err">;</span>
<span class="w"> </span><span class="n">AddRoundKey</span><span class="p">(</span><span class="n">State</span><span class="p">,</span><span class="n">ExpandedKey</span><span class="o">[</span><span class="n">Nr</span><span class="o">]</span><span class="p">)</span><span class="err">;</span>
<span class="k">end</span><span class="w"> </span><span class="n">procedure</span>
</pre></div>
<div class="mw-heading mw-heading2"><h2 id="Chiffrement">Chiffrement</h2></div>
<p>L'AES est un algorithme de chiffrement symétrique, et c'est un chiffrement par blocs.
Il chiffre un message de 128 bits pour produire un chiffré de 128 bits également.
La clé utilisée peut varier en taille : elle peut être de 128 bits, 192 bits ou 256 bits.
La représentation du message bloqué se fait sous la forme d'un tableau 4x4, soit 16 cases, chacune représentant un octet, pour un total de 128 bits. Le chiffrement AES est constitué de plusieurs tours. Ce nombre de tours varie selon la taille de la clé initiale : pour une clé de 128 bits, le nombre de tours est de 10 ; pour une clé de 192 bits, il est de 12 tours ; et pour une clé de 256 bits, il est de 14 tours.
</p><p>Pour chaque tour, une clé sera générée à partir de la clé initiale en utilisant un algorithme d'expansion de clé. Ces clés sont appelées round keys, et chacune est de taille 128 bits, quelle que soit la taille de la clé initiale.
</p><p>Chaque tour est divisé en 4 étapes : substitution des octets, shift rows, mix columns et add round key, sauf pour le dernier tour, qui n'inclut pas l'étape mix columns.
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading3"><h3 id="Substitution_des_octets">Substitution des octets</h3></div>
<p>Chaque octet dans le message représenté par un bloc 4x4 sera remplacé par un autre octet en utilisant une table de substitution 16x16 (boite S)
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading3"><h3 id="Shift_rows">Shift rows</h3></div>
<p>Pour la première ligne, il n'y a pas de changements. Pour la deuxième ligne, les éléments sont décalés chacun d'un pas vers la gauche, pour la troisième ligne, de 2 pas vers la gauche, et pour la quatrième ligne, de 3 pas vers la gauche.
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading3"><h3 id="Mix_columns">Mix columns</h3></div>
<p>Chaque colonne sera multipliée par la matrice 4x4 fixe suivante :
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading3"><h3 id="Add_round_key">Add round key</h3></div>
<p>Le message en bloc sera XORé avec la round key.
</p><p>La round key est formée de 4 mots, et chaque mot sera XORé avec une colonne du message.
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading3"><h3 id="Algorithme_d'expansion_des_clés"><span id="Algorithme_d.27expansion_des_cl.C3.A9s"></span>Algorithme d'expansion des clés</h3></div>
<p>Division de la clé initiale
</p><p>La clé initiale (128, 192 ou 256 bits) est divisée en mots, chacun contenant 4 octets :
</p><p>AES-128 : 16 octets (4 mots).
</p><p>AES-192 : 24 octets (6 mots).
</p><p>AES-256 : 32 octets (8 mots).
</p><p>Exemple avec une clé AES-128 (128 bits) : 2b7e151628aed2a6abf7158809cf4f3c
</p><p>W0 =2b7e1516
</p><p>W1 =28aed2a6
</p><p>W2 =abf71588
</p><p>W3 =09cf4f3c
</p><p>Nombre de mots pour la clé étendue
</p><p>Le nombre de mots nécessaires pour la clé étendue est donné par :
</p><p>Nb de mots = 4 × (Nb de tours + 1)
Le facteur 4 correspond au nombre de mots de 4 octets d'un bloc (128 bits).
</p><p>AES ne traite que des blocs de 128 bits, donc il y a 4 mots par bloc.
</p><p>Ainsi :
</p><p>Pour AES-128, on a besoin de 44 mots.
</p><p>Pour AES-192, on a besoin de 52 mots.
</p><p>Pour AES-256, on a besoin de 60 mots.
</p><p>Calcul des mots pour les clés de ronde
</p><p>La clé de ronde suivante est composée des mots
</p><p>W4 ,W5 ,W6 ,W7 .
</p><p>W4=W0⊕core(W3)
</p><p>W5=W4⊕W1
</p><p>W6=W5⊕W2
</p><p>W7=W6⊕W3
</p><p>Note : La fonction core applique des transformations spécifiques (substitution et rotation) à un mot.
</p><p>On répète ce processus jusqu'à obtenir tous les mots nécessaires pour générer les clés de toutes les rondes.
</p>
<div class="clear" style="clear:both;"></div>
<hr>
<div class="mw-heading mw-heading2"><h2 id="Déchiffrement"><span id="D.C3.A9chiffrement"></span>Déchiffrement</h2></div>
<p>Dans le déchiffrement, on applique le même mécanisme que lors du chiffrement, mais dans l'ordre inverse. Cela signifie :
AddRoundKey en premier.
</p><p>Pour chaque tour :
</p>
<ul><li>Inverse ShiftRows (décalage inverse des lignes).</li>
<li>Inverse SubBytes (substitution inverse des octets).</li>
<li>AddRoundKey.</li>
<li>Inverse MixColumns (sauf lors du dernier tour).</li></ul>
<p>Lors du dernier tour, l'étape Inverse MixColumns est omise, et le déchiffrement se termine avec AddRoundKey.
</p>
<div class="mw-heading mw-heading2"><h2 id="Attaques_sur_le_système_cryptographique_AES"><span id="Attaques_sur_le_syst.C3.A8me_cryptographique_AES"></span>Attaques sur le système cryptographique AES</h2></div>
<p>L'AES n'a pour l'instant pas été cassé, même théoriquement, au sens où il n'existe pas d'attaque significativement plus efficace que la <a href="Attaque_par_force_brute" title="Attaque par force brute">recherche exhaustive</a> quand le chiffrement est correctement utilisé. Le système AES est largement considéré comme l'un des algorithmes de chiffrement les plus sécurisés disponibles. Cependant, comme tout système cryptographique, il est constamment soumis à des analyses et des attaques pour tester sa robustesse.
</p><p>Il est important de noter que, malgré ces attaques, l'AES reste un algorithme très robuste. Il est largement utilisé dans de nombreuses applications sécurisées. Les attaques mentionnées sont souvent théoriques ou nécessitent des conditions très spécifiques pour être réalisées avec succès.
</p><p><a href="Rijndael" title="Rijndael">Rijndael</a> a été conçu de façon à résister aux méthodes classiques en particulier la <a href="Cryptanalyse_lin%C3%A9aire" title="Cryptanalyse linéaire">cryptanalyse linéaire</a> et la <a href="Cryptanalyse_diff%C3%A9rentielle" title="Cryptanalyse différentielle">cryptanalyse différentielle</a>. Le nombre de tours de l'AES est calculé en fonction de la taille de la clef pour que chacune de ces deux attaques (linéaire et différentielle) ne soit pas plus efficace qu'une attaque par force brute.
</p>
<div class="mw-heading mw-heading3"><h3 id="Attaques_sur_des_versions_simplifiées"><span id="Attaques_sur_des_versions_simplifi.C3.A9es"></span>Attaques sur des versions simplifiées</h3></div>
<p>Des attaques existent sur des versions simplifiées d'AES. <a href="Niels_Ferguson" title="Niels Ferguson">Niels Ferguson</a> et son équipe ont proposé en 2000 une attaque sur une version à 7 tours de l'AES 128 <a href="Bit_(informatique)" class="mw-redirect" title="Bit (informatique)">bits</a>. Une attaque similaire casse un AES de 192 ou 256 bits contenant 8 tours. Un AES de 256 bits peut être cassé s'il est réduit à 9 tours avec une contrainte supplémentaire. En effet, cette dernière attaque repose sur le principe des « related-keys » (clés apparentées). Dans une telle attaque, la clé demeure secrète mais l'attaquant peut spécifier des transformations sur la clé et chiffrer des textes à sa guise. Il peut donc légèrement modifier la clé et regarder comment la sortie de l'AES se comporte.
</p>
<div class="mw-heading mw-heading3"><h3 id="Attaques_sur_la_version_complète"><span id="Attaques_sur_la_version_compl.C3.A8te"></span>Attaques sur la version complète</h3></div>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_force_brute">Attaques par force brute</h4></div>
<p>La simplicité algébrique de l'AES a été mise en avant, par exemple en 2001 par <a href="Niels_Ferguson" title="Niels Ferguson">Niels Ferguson</a>, comme une potentielle faiblesse<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>. Elle n'a cependant pu être exploitée jusqu'à présent. En 2002 <a href="Nicolas_Courtois" title="Nicolas Courtois">Nicolas Courtois</a> et <a href="Josef_Pieprzyk" title="Josef Pieprzyk">Josef Pieprzyk</a> avaient présenté une attaque algébrique théorique : l'<a href="Attaque_XSL" title="Attaque XSL">attaque XSL</a>, dont ils estimaient qu'elle était plus efficace que l'<a href="Attaque_par_force_brute" title="Attaque par force brute">attaque par force brute</a>, mais cela a été infirmé par des travaux ultérieurs<sup id="cite_ref-7" class="reference"><a href="#cite_note-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>.
</p><p>En 2011, des chercheurs de <a href="Microsoft" title="Microsoft">Microsoft</a> publient une attaque sur la version complète d'AES<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>. Cette attaque permet de trouver la clef d'AES-128 en <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2^{126,1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>126</mn>
<mo>,</mo>
<mn>1</mn>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2^{126,1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/44d0611a26595efdfebccdda31442e40a0bb4f33.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:5.14ex; height:2.676ex;" alt="{\displaystyle 2^{126,1}}" loading="lazy"></span> opérations (contre <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2^{128}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>128</mn>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2^{128}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/759062fdace390ded4a751eeff7689d2883995cd.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:3.861ex; height:2.676ex;" alt="{\displaystyle 2^{128}}" loading="lazy"></span> pour une attaque par force brute, soit presque 4 fois plus rapide que cette dernière). La même attaque s'applique à une version simplifiée (à 8 tours) d'AES-128, réduisant la complexité de l'attaque à <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2^{124,9}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>124</mn>
<mo>,</mo>
<mn>9</mn>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2^{124,9}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a7084ce06f17160abf19b586c7c2d9009538f4e0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:5.14ex; height:2.676ex;" alt="{\displaystyle 2^{124,9}}" loading="lazy"></span>. Cette attaque, fondée sur une amélioration de l'<a href="Cryptanalyse#Attaque_par_rencontre_au_milieu" title="Cryptanalyse">attaque par rencontre au milieu</a>, reste impraticable.
</p>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_canal_auxiliaire">Attaques par canal auxiliaire</h4></div>
<p>Les <a href="Attaques_par_canal_auxiliaire" class="mw-redirect" title="Attaques par canal auxiliaire">attaques par canal auxiliaire</a> exploitent des informations supplémentaires obtenues à partir de l'implémentation physique de l'algorithme, comme la consommation d'énergie, le temps de calcul, ou les émissions électromagnétiques. Les attaques par analyse de la <a href="Analyse_de_consommation" title="Analyse de consommation">consommation d'énergie</a> et les attaques par analyse des émissions électromagnétiques sont des exemples courant :
</p>
<ul><li>Differential Power Analysis (DPA) : introduite par <a href="Paul_Kocher" title="Paul Kocher">Paul Kocher</a>, Joshua Jaffe, et Benjamin Jun en 1999. Cette méthode a été largement étudiée et améliorée depuis<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>;</li>
<li>Electromagnetic Analysis (EMA) : les attaques par analyse des émissions électromagnétiques ont également été explorées dans les années 2000 et continuent d'être un sujet de recherche actif<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>.</li></ul>
<p>En mars 2016, Ashokkumar C., Ravi Prakash Giri et Bernard Menezes ont présenté une attaque par canal auxiliaire sur les implémentations AES qui peut récupérer la clé AES complète de 128 bits en seulement 6-7 blocs de texte en clair/chiffré, ce qui constitue une amélioration substantielle par rapport aux travaux précédents qui nécessitent entre 100 et un million de calculs de déchiffrement. L'attaque proposée nécessite des privilèges utilisateur standards et les algorithmes de récupération de clé s'exécutent en moins d'une minute<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>.
</p><p>Pour se protéger face à ce type d'attaques, un <a href="Jeu_d'instructions_AES" title="Jeu d'instructions AES">jeu d'instructions AES</a> est intégré au cœur de l'architecture des microprocesseurs modernes.
</p>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_fautes">Attaques par fautes</h4></div>
<p>Les <a href="Attaque_par_faute" title="Attaque par faute">attaques par fautes</a> introduisent des erreurs dans le processus de chiffrement ou de déchiffrement pour obtenir des informations sur la clé secrète. Par exemple, en injectant des fautes dans les registres de l'algorithme, un attaquant peut observer les différences dans les sorties et en déduire des informations sur la clé<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_cryptanalyse">Attaques par cryptanalyse</h4></div>
<p>Bien que l'AES soit conçu pour résister à de nombreuses formes de <a href="Cryptanalyse" title="Cryptanalyse">cryptanalyse</a>, des recherches continuent à explorer de nouvelles méthodes pour trouver des faiblesses. Par exemple, des attaques basées sur des techniques de cryptanalyse linéaire et différentielle ont été proposées, mais elles ne sont généralement pas pratiques pour des clés de taille standard (128, 192, ou 256 bits).
</p><p>Ces techniques ont été développées dans les années 1990 par des chercheurs comme <a href="Mitsuru_Matsui" title="Mitsuru Matsui">Mitsuru Matsui</a> (cryptanalyse linéaire) et <a href="Eli_Biham" title="Eli Biham">Eli Biham</a> et <a href="Adi_Shamir" title="Adi Shamir">Adi Shamir</a> (cryptanalyse différentielle). Bien que l'AES soit conçu pour résister à ces attaques, des variantes et des améliorations continuent d'être étudiées.
</p>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_calcul_quantique">Attaques par calcul quantique</h4></div>
<p>Bien que les ordinateurs quantiques ne soient pas encore disponibles à grande échelle, des algorithmes quantiques comme l'<a href="Algorithme_de_Grover" title="Algorithme de Grover">algorithme de Grover</a> pourraient théoriquement réduire la sécurité de l'AES en permettant une recherche plus efficace de la clé. Cependant, même avec des ordinateurs quantiques, l'AES reste relativement sécurisé en raison de sa grande taille de clé. En effet, l'AES-256 est considéré comme résistant aux attaques quantiques<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>.
</p><p>L'algorithme de Grover, qui pourrait réduire la sécurité de l'AES<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup>, a été proposé par <a href="Lov_Grover" title="Lov Grover">Lov Grover</a> en 1996. Cependant, les implications pratiques de cette attaque dépendent de l'avancement des <a href="Informatique_quantique" title="Informatique quantique">technologies quantiques</a>, qui est encore en cours de développement.
</p>
<div class="mw-heading mw-heading4"><h4 id="Attaques_par_implémentation"><span id="Attaques_par_impl.C3.A9mentation"></span>Attaques par implémentation</h4></div>
<p>Des vulnérabilités peuvent également être introduites par des erreurs dans l'implémentation de l'algorithme AES<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup>. Des bugs dans le code ou des failles dans les bibliothèques cryptographiques peuvent être exploités par des attaquants. Les vulnérabilités d'implémentation peuvent être découvertes à tout moment et sont souvent spécifiques à des bibliothèques ou des logiciels particuliers. Par exemple, des failles dans des bibliothèques cryptographiques comme <a href="OpenSSL" title="OpenSSL">OpenSSL</a> ont été découvertes et corrigées au fil des ans.
</p><p>En <time class="nowrap" datetime="2005-04" data-sort-value="2005-04">avril 2005</time>, <a href="Daniel_J._Bernstein" title="Daniel J. Bernstein">Daniel J. Bernstein</a> a publié une <a href="Attaque_temporelle" title="Attaque temporelle">attaque temporelle</a> utilisée pour casser une clé AES sur un serveur spécifique tournant avec <a href="OpenSSL" title="OpenSSL">OpenSSL</a>.
</p><p>En <time class="nowrap" datetime="2010-11" data-sort-value="2010-11">novembre 2010</time>, Endre Bangerter, David Gullasch et Stephan Krenn ont publié un article décrivant la récupération d'une clé secrète AES-128 quasiment en temps réel qui fonctionne sur certaines implémentations. Comme les précédentes attaques de ce type, elle nécessite de lancer un programme sur la machine qui effectue le chiffrement.
</p>
<div class="mw-heading mw-heading3"><h3 id="Recommandations_de_la_NSA">Recommandations de la NSA</h3></div>
<p>Le gouvernement américain a annoncé en <a href="Juin_2003" title="Juin 2003">juin 2003</a> à propos de l'algorithme AES (suivant une analyse de la <a href="National_Security_Agency" title="National Security Agency">NSA</a>) :
</p>
<blockquote>
<p>« L'architecture et la longueur de toutes les tailles de clés de l'algorithme AES (128, 192 et 256) sont suffisantes pour protéger des documents classifiés jusqu'au niveau « SECRET ». Le niveau « TOP SECRET » nécessite des clés de 192 ou 256 bits. L'implémentation de l'AES dans des produits destinés à la protection des systèmes et/ou documents liés à la sécurité nationale doit faire l'objet d'une analyse et d'une certification par la NSA avant leur acquisition et leur utilisation »
</p>
</blockquote><p style="margin:-0.7em 0 0.3em 6em">— paragraphe (6) de la dépêche originale<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup></p>
<div class="mw-heading mw-heading2"><h2 id="Performances">Performances</h2></div>
<p>Lors de la sélection d'un nouveau standard de chiffrement, le <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">NIST</a> a évalué les performances de nombreux algorithmes<sup id="cite_ref-:1_19-0" class="reference"><a href="#cite_note-:1-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>.
</p><p>Une étude comparative détaillée a été conduite concernant les performances des candidats à l'AES sur diverses plateformes, notamment les <a href="Processeur" title="Processeur">CPU</a> 32 bits, 64 bits, les cartes à puce 8 bits et le matériel dédié. Les algorithmes ont été évalués en termes de vitesse de chiffrement, de temps de configuration des clés, de consommation de <a href="M%C3%A9moire_vive" title="Mémoire vive">RAM</a> et de ROM, ainsi que de leur capacité à être parallélisés et utilisés comme fonctions de hachage. Choisir un seul algorithme pour toutes les applications a été difficile pour répondre au besoin de standardisation. L'AES tel que connu aujourd'hui, dérivé de Rijndael, a été retenu parmi les candidats au regard de ses performances et de son coût d'implémentation<sup id="cite_ref-:1_19-1" class="reference"><a href="#cite_note-:1-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>.
</p><p>Les <a href="Jeu_d'instructions_AES" title="Jeu d'instructions AES">instructions AES</a> d'Intel offrent des performances significativement améliorées pour le chiffrement et le déchiffrement des données par rapport aux implémentations logicielles traditionnelles basées sur des tables de recherche. Ces instructions permettent une exécution en temps indépendant des données et sans utilisation de tables, ce qui aide à éliminer les principales attaques par chronométrage et basées sur le cache qui menacent les implémentations logicielles d'AES. De plus, elles simplifient la mise en œuvre d'AES avec une taille de code réduite, diminuant ainsi le risque d'introduction accidentelle de <a href="Vuln%C3%A9rabilit%C3%A9_(informatique)" title="Vulnérabilité (informatique)">failles de sécurité</a>, comme les fuites par canaux latéraux difficiles à détecter. Les instructions AES sont conçues pour fonctionner efficacement sur diverses plateformes et pour différentes applications, y compris le chiffrement en temps réel de <a href="Streaming" title="Streaming">flux vidéo</a> et audio, les <a href="Carte_%C3%A0_puce" title="Carte à puce">cartes à puce</a>, les <a href="Syst%C3%A8me_embarqu%C3%A9" title="Système embarqué">systèmes embarqués</a>, et les applications nécessitant une agilité de clé élevée comme <a href="IPsec" title="IPsec">IPsec</a><sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading2"><h2 id="Mieux_connaître_l'AES"><span id="Mieux_conna.C3.AEtre_l.27AES"></span>Mieux connaître l'AES</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Solution_éducative"><span id="Solution_.C3.A9ducative"></span>Solution éducative</h3></div>
<p>De nombreuses ressources sont disponibles en ligne pour en apprendre davantage sur ce système cryptographique. Le projet éducatif <a href="CrypTool" title="CrypTool">CrypTool</a> offre un support visuel pas-à-pas<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup> et un autre avec animation interactive<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> qui permettent à chacun d'approfondir sa connaissance du fonctionnement interne de l'AES.
</p>
<div class="mw-heading mw-heading3"><h3 id="Exemple_d'implémentation_simple_avec_Python"><span id="Exemple_d.27impl.C3.A9mentation_simple_avec_Python"></span>Exemple d'implémentation simple avec Python</h3></div>
<p>Ci-dessous, un exemple d'implémentation d'AES avec le <a href="Mode_op%C3%A9ratoire_(cryptographie)" class="mw-redirect" title="Mode opératoire (cryptographie)">mode opératoire</a> Cipher Block Chaining (CBC) est proposé. Ce bloc de code <a href="Python_(langage)" title="Python (langage)">Python</a> présente AES et fonctionne avec un <a href="Vecteur_d'initialisation" title="Vecteur d'initialisation">vecteur d'initialisation</a> et une <a href="Cl%C3%A9_de_chiffrement" title="Clé de chiffrement">clé de chiffrement</a> fixes. Il offre une fonctionnalité de chiffrement et de déchiffrement pour un fichier d'entrée <<i>input_file</i>> passé en argument et une sortie donnée pour <<i>output_file</i>>.
</p><p>
En <a href="Interface_en_ligne_de_commande" title="Interface en ligne de commande">ligne de commande</a> sur un ordinateur disposant de Python version 3 installé ainsi que de la <a href="Biblioth%C3%A8que_logicielle" title="Bibliothèque logicielle">bibliothèque logicielle</a> <code>pycryptodome</code> il s'utilise comme suit pour le chiffrement d'un <a href="Fichier_texte" title="Fichier texte">fichier texte</a> dans la mesure où le code est enregistré sous <code>aes_cbc_file.py</code> : <code>python3 aes_cbc_file.py encrypt mon_texte_clair.txt mon_fichier_chiffre</code></p><div class="mw-highlight mw-highlight-lang-python3 mw-content-ltr mw-highlight-lines" dir="ltr"><pre><span></span><span class="linenos" data-line="1"></span><span class="kn">import</span><span class="w"> </span><span class="nn">sys</span>
<span class="linenos" data-line="2"></span><span class="kn">from</span><span class="w"> </span><span class="nn">Crypto.Cipher</span><span class="w"> </span><span class="kn">import</span> <span class="n">AES</span>
<span class="linenos" data-line="3"></span><span class="kn">from</span><span class="w"> </span><span class="nn">Crypto.Util.Padding</span><span class="w"> </span><span class="kn">import</span> <span class="n">pad</span><span class="p">,</span> <span class="n">unpad</span>
<span class="linenos" data-line="4"></span><span class="kn">import</span><span class="w"> </span><span class="nn">base64</span>
<span class="linenos" data-line="5"></span>
<span class="linenos" data-line="6"></span><span class="c1"># Fixed key and IV</span>
<span class="linenos" data-line="7"></span><span class="n">FIXED_KEY</span> <span class="o">=</span> <span class="sa">b</span><span class="s1">'fixedkey1234567890123456'</span> <span class="c1"># 256-bit key (32 bytes)</span>
<span class="linenos" data-line="8"></span><span class="n">FIXED_IV</span> <span class="o">=</span> <span class="sa">b</span><span class="s1">'fixediv012345678'</span> <span class="c1"># 128-bit IV (16 bytes)</span>
<span class="linenos" data-line="9"></span>
<span class="linenos" data-line="10"></span><span class="k">def</span><span class="w"> </span><span class="nf">encrypt</span><span class="p">(</span><span class="n">plaintext</span><span class="p">):</span>
<span class="linenos" data-line="11"></span> <span class="n">cipher</span> <span class="o">=</span> <span class="n">AES</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="n">FIXED_KEY</span><span class="p">,</span> <span class="n">AES</span><span class="o">.</span><span class="n">MODE_CBC</span><span class="p">,</span> <span class="n">FIXED_IV</span><span class="p">)</span>
<span class="linenos" data-line="12"></span> <span class="n">ciphertext</span> <span class="o">=</span> <span class="n">cipher</span><span class="o">.</span><span class="n">encrypt</span><span class="p">(</span><span class="n">pad</span><span class="p">(</span><span class="n">plaintext</span><span class="p">,</span> <span class="n">AES</span><span class="o">.</span><span class="n">block_size</span><span class="p">))</span>
<span class="linenos" data-line="13"></span> <span class="k">return</span> <span class="n">base64</span><span class="o">.</span><span class="n">b64encode</span><span class="p">(</span><span class="n">ciphertext</span><span class="p">)</span>
<span class="linenos" data-line="14"></span>
<span class="linenos" data-line="15"></span><span class="k">def</span><span class="w"> </span><span class="nf">decrypt</span><span class="p">(</span><span class="n">ciphertext</span><span class="p">):</span>
<span class="linenos" data-line="16"></span> <span class="n">ciphertext</span> <span class="o">=</span> <span class="n">base64</span><span class="o">.</span><span class="n">b64decode</span><span class="p">(</span><span class="n">ciphertext</span><span class="p">)</span>
<span class="linenos" data-line="17"></span> <span class="n">cipher</span> <span class="o">=</span> <span class="n">AES</span><span class="o">.</span><span class="n">new</span><span class="p">(</span><span class="n">FIXED_KEY</span><span class="p">,</span> <span class="n">AES</span><span class="o">.</span><span class="n">MODE_CBC</span><span class="p">,</span> <span class="n">FIXED_IV</span><span class="p">)</span>
<span class="linenos" data-line="18"></span> <span class="n">plaintext</span> <span class="o">=</span> <span class="n">unpad</span><span class="p">(</span><span class="n">cipher</span><span class="o">.</span><span class="n">decrypt</span><span class="p">(</span><span class="n">ciphertext</span><span class="p">),</span> <span class="n">AES</span><span class="o">.</span><span class="n">block_size</span><span class="p">)</span>
<span class="linenos" data-line="19"></span> <span class="k">return</span> <span class="n">plaintext</span>
<span class="linenos" data-line="20"></span>
<span class="linenos" data-line="21"></span><span class="k">def</span><span class="w"> </span><span class="nf">main</span><span class="p">():</span>
<span class="linenos" data-line="22"></span> <span class="k">if</span> <span class="nb">len</span><span class="p">(</span><span class="n">sys</span><span class="o">.</span><span class="n">argv</span><span class="p">)</span> <span class="o"><</span> <span class="mi">4</span><span class="p">:</span>
<span class="linenos" data-line="23"></span> <span class="nb">print</span><span class="p">(</span><span class="s2">"Usage: python aes_cbc_file.py <encrypt|decrypt> <input_file> <output_file>"</span><span class="p">)</span>
<span class="linenos" data-line="24"></span> <span class="n">sys</span><span class="o">.</span><span class="n">exit</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
<span class="linenos" data-line="25"></span>
<span class="linenos" data-line="26"></span> <span class="n">action</span> <span class="o">=</span> <span class="n">sys</span><span class="o">.</span><span class="n">argv</span><span class="p">[</span><span class="mi">1</span><span class="p">]</span>
<span class="linenos" data-line="27"></span> <span class="n">input_file</span> <span class="o">=</span> <span class="n">sys</span><span class="o">.</span><span class="n">argv</span><span class="p">[</span><span class="mi">2</span><span class="p">]</span>
<span class="linenos" data-line="28"></span> <span class="n">output_file</span> <span class="o">=</span> <span class="n">sys</span><span class="o">.</span><span class="n">argv</span><span class="p">[</span><span class="mi">3</span><span class="p">]</span>
<span class="linenos" data-line="29"></span>
<span class="linenos" data-line="30"></span> <span class="k">try</span><span class="p">:</span>
<span class="linenos" data-line="31"></span> <span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="n">input_file</span><span class="p">,</span> <span class="s1">'rb'</span><span class="p">)</span> <span class="k">as</span> <span class="n">f</span><span class="p">:</span>
<span class="linenos" data-line="32"></span> <span class="n">data</span> <span class="o">=</span> <span class="n">f</span><span class="o">.</span><span class="n">read</span><span class="p">()</span>
<span class="linenos" data-line="33"></span> <span class="k">except</span> <span class="ne">FileNotFoundError</span><span class="p">:</span>
<span class="linenos" data-line="34"></span> <span class="nb">print</span><span class="p">(</span><span class="sa">f</span><span class="s2">"File </span><span class="si">{</span><span class="n">input_file</span><span class="si">}</span><span class="s2"> not found."</span><span class="p">)</span>
<span class="linenos" data-line="35"></span> <span class="n">sys</span><span class="o">.</span><span class="n">exit</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
<span class="linenos" data-line="36"></span>
<span class="linenos" data-line="37"></span> <span class="k">if</span> <span class="n">action</span> <span class="o">==</span> <span class="s2">"encrypt"</span><span class="p">:</span>
<span class="linenos" data-line="38"></span> <span class="n">encrypted_data</span> <span class="o">=</span> <span class="n">encrypt</span><span class="p">(</span><span class="n">data</span><span class="p">)</span>
<span class="linenos" data-line="39"></span> <span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="n">output_file</span><span class="p">,</span> <span class="s1">'wb'</span><span class="p">)</span> <span class="k">as</span> <span class="n">f</span><span class="p">:</span>
<span class="linenos" data-line="40"></span> <span class="n">f</span><span class="o">.</span><span class="n">write</span><span class="p">(</span><span class="n">encrypted_data</span><span class="p">)</span>
<span class="linenos" data-line="41"></span> <span class="nb">print</span><span class="p">(</span><span class="sa">f</span><span class="s2">"Encrypted data written to </span><span class="si">{</span><span class="n">output_file</span><span class="si">}</span><span class="s2">"</span><span class="p">)</span>
<span class="linenos" data-line="42"></span> <span class="k">elif</span> <span class="n">action</span> <span class="o">==</span> <span class="s2">"decrypt"</span><span class="p">:</span>
<span class="linenos" data-line="43"></span> <span class="n">decrypted_data</span> <span class="o">=</span> <span class="n">decrypt</span><span class="p">(</span><span class="n">data</span><span class="p">)</span>
<span class="linenos" data-line="44"></span> <span class="k">with</span> <span class="nb">open</span><span class="p">(</span><span class="n">output_file</span><span class="p">,</span> <span class="s1">'wb'</span><span class="p">)</span> <span class="k">as</span> <span class="n">f</span><span class="p">:</span>
<span class="linenos" data-line="45"></span> <span class="n">f</span><span class="o">.</span><span class="n">write</span><span class="p">(</span><span class="n">decrypted_data</span><span class="p">)</span>
<span class="linenos" data-line="46"></span> <span class="nb">print</span><span class="p">(</span><span class="sa">f</span><span class="s2">"Decrypted data written to </span><span class="si">{</span><span class="n">output_file</span><span class="si">}</span><span class="s2">"</span><span class="p">)</span>
<span class="linenos" data-line="47"></span> <span class="k">else</span><span class="p">:</span>
<span class="linenos" data-line="48"></span> <span class="nb">print</span><span class="p">(</span><span class="s2">"Invalid action. Use 'encrypt' or 'decrypt'."</span><span class="p">)</span>
<span class="linenos" data-line="49"></span> <span class="n">sys</span><span class="o">.</span><span class="n">exit</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
<span class="linenos" data-line="50"></span>
<span class="linenos" data-line="51"></span><span class="k">if</span> <span class="vm">__name__</span> <span class="o">==</span> <span class="s2">"__main__"</span><span class="p">:</span>
<span class="linenos" data-line="52"></span> <span class="n">main</span><span class="p">()</span>
</pre></div>
<div class="mw-heading mw-heading2"><h2 id="Notes_et_références"><span id="Notes_et_r.C3.A9f.C3.A9rences"></span>Notes et références</h2></div>
<div style="font-size:85%; padding-left:1.6em; margin:0.3em 0;"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Cet article est partiellement ou en totalité issu de l’article de Wikipédia en anglais intitulé <span class="">« <a class="external text" href="https://en.wikipedia.org/wiki/Advanced_Encryption_Standard?oldid=689607309">Advanced Encryption Standard</a> » <small>(<a class="external text" href="https://en.wikipedia.org/wiki/Advanced_Encryption_Standard?action=history">voir la liste des auteurs</a>)</small></span>.</div>
<div class="references-small decimal" style=""><div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><a href="#cite_ref-1">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> « <a rel="nofollow" class="external text" href="http://www.nsa.gov/ia/programs/suiteb_cryptography/"><cite style="font-style:normal;" lang="en">Suite B Cryptography</cite></a> »</span></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><a href="#cite_ref-2">↑</a> </span><span class="reference-text"><span class="ouvrage" id="2020"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> « <a rel="nofollow" class="external text" href="https://luxsci.com/blog/256-bit-aes-encryption-for-ssl-and-tls-maximal-security.html"><cite style="font-style:normal;" lang="en">Enhanced Security: AES-256 Encryption for SSL and TLS</cite></a> », sur <span class="italique">LuxSci</span>, <time class="nowrap" datetime="2020-12-01" data-sort-value="2020-12-01"><abbr class="abbr" title="premier">1<sup>er</sup></abbr> décembre 2020</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2024-11-21" data-sort-value="2024-11-21">21 novembre 2024</time>)</small></span></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><a href="#cite_ref-3">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Nechvatal2000"><span class="ouvrage" id="James_Nechvatal2000"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> James Nechvatal, Elaine Barker, Lawrence Bassham, William Burr, Morris Dworkin, James Foti, Edward Roback, « <a rel="nofollow" class="external text" href="http://csrc.nist.gov/archive/aes/round2/r2report.pdf"><cite style="font-style:normal;" lang="en">Report on the Development of the Advanced Encryption Standard (AES)</cite></a> », sur <span class="italique">csrc.nist.gov</span>, <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a>, <time class="nowrap" datetime="2000-10-02" data-sort-value="2000-10-02">2 octobre 2000</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2009-06-08" data-sort-value="2009-06-08">8 juin 2009</time>)</small></span></span></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><a href="#cite_ref-4">↑</a> </span><span class="reference-text"><span class="ouvrage" id="NIST2001"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> NIST, « <cite style="font-style:normal" lang="en">Advanced Encryption Standard (AES)</cite> », <i><span class="lang-en" lang="en">Federal Information Processing Standards Publication</span></i>, <time>2001</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.197-upd1.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Advanced+Encryption+Standard+%28AES%29&rft.jtitle=Federal+Information+Processing+Standards+Publication&rft.au=NIST&rft.date=2001&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span>
</li>
<li id="cite_note-:0-5"><span class="reference-text"><span class="ouvrage" id="Daemen2020"><span class="ouvrage" id="Joan_Daemen2020">Joan <span class="nom_auteur">Daemen</span>, <cite class="italique">The design of Rijndael : the Advanced Encryption Standard (AES)</cite>, <time>2020</time> <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-3-662-60769-5</span> et <span class="nowrap">3-662-60769-7</span>, <a href="Online_Computer_Library_Center" title="Online Computer Library Center">OCLC</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://worldcat.org/fr/title/1155884098">1155884098</a></span>, <a rel="nofollow" class="external text" href="https://www.worldcat.org/oclc/1155884098">lire en ligne</a>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=book&rft.btitle=The+design+of+Rijndael+%3A+the+Advanced+Encryption+Standard+%28AES%29&rft.aulast=Daemen&rft.aufirst=Joan&rft.date=2020&rft.isbn=978-3-662-60769-5&rft_id=info%3Aoclcnum%2F1155884098&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><a href="#cite_ref-6">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Niels Ferguson, Richard Schroeppel et Doug Whiting <span class="citation">« A Simple Algebraic Representation of Rijndael »</span> (<time>2001</time>) <br>— <span class="ouvrage"><cite style="font-style:normal">« <i>(ibid.)</i> »</cite>, dans Serge Vaudenay et Amr M. Youssef (éds.), <cite class="italique">Selected Areas in Cryptography</cite>, Springer Berlin Heidelberg, <abbr class="abbr" title="collection">coll.</abbr> « Lecture Notes in Computer Science » <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-3-540-45537-0</span>)</small>, <abbr class="abbr" title="pages">p.</abbr> <span class="nowrap">103–111</span><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=bookitem&rft.btitle=Selected+Areas+in+Cryptography&rft.atitle=%27%27%28ibid.%29%27%27&rft.pub=Springer+Berlin+Heidelberg&rft.pages=103%E2%80%93111&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-7"><span class="mw-cite-backlink"><a href="#cite_ref-7">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Cid,_G._Leurent2005"><span class="ouvrage" id="C._Cid,_G._Leurent2005"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> C. Cid, G. Leurent, « <cite style="font-style:normal" lang="en">An Analysis of the XSL Algorithm</cite> », <i><span class="lang-en" lang="en">LNCS</span></i>, <abbr class="abbr" title="volume">vol.</abbr> 3788, <time>2005</time>, <abbr class="abbr" title="pages">p.</abbr> <span class="nowrap">333–335</span> <small style="line-height:1em;">(<a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1007/11593447">10.1007/11593447</a></span>, <a rel="nofollow" class="external text" href="http://www.isg.rhul.ac.uk/~ccid/publications/XSL_AC05.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=An+Analysis+of+the+XSL+Algorithm&rft.jtitle=LNCS&rft.au=C.+Cid%2C+G.+Leurent&rft.date=2005&rft.volume=3788&rft.pages=333%E2%80%93335&rft_id=info%3Adoi%2F10.1007%2F11593447&rft_id=http%3A%2F%2Fwww.isg.rhul.ac.uk%2F~ccid%2Fpublications%2FXSL_AC05.pdf&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a> </span><span class="reference-text"><span class="ouvrage" id="BogdanovKhovratovichRechberger2011"><span class="ouvrage" id="Andrey_BogdanovDmitry_KhovratovichChristian_Rechberger2011"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Andrey <span class="nom_auteur">Bogdanov</span>, Dmitry <span class="nom_auteur">Khovratovich</span> et Christian <span class="nom_auteur">Rechberger</span>, « <cite style="font-style:normal" lang="en">Biclique Cryptanalysis of the Full AES</cite> », <i><span class="lang-en" lang="en">Advances in Cryptology – ASIACRYPT 2011</span></i>, Springer, <time>2011</time>, <abbr class="abbr" title="pages">p.</abbr> <span class="nowrap">344–371</span> <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-3-642-25385-0</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1007/978-3-642-25385-0_19">10.1007/978-3-642-25385-0_19</a></span>, <a rel="nofollow" class="external text" href="https://link.springer.com/chapter/10.1007/978-3-642-25385-0_19">lire en ligne</a>, consulté le <time class="nowrap" datetime="2025-09-18" data-sort-value="2025-09-18">18 septembre 2025</time>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Biclique+Cryptanalysis+of+the+Full+AES&rft.jtitle=Advances+in+Cryptology+%E2%80%93+ASIACRYPT+2011&rft.aulast=Bogdanov&rft.aufirst=Andrey&rft.au=Khovratovich%2C+Dmitry&rft.au=Rechberger%2C+Christian&rft.date=2011&rft.pages=344%E2%80%93371&rft.isbn=978-3-642-25385-0&rft_id=info%3Adoi%2F10.1007%2F978-3-642-25385-0_19&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a> </span><span class="reference-text">Bossuet, Lilian. « Approche didactique pour l’enseignement de l’attaque DPA ciblant l’algorithme de chiffrement AES ». Journal sur l’enseignement des sciences et technologies de l’information et des systèmes 11 (2012): 4-. Web.</span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a> </span><span class="reference-text"><span class="ouvrage" id="ZhangJiaZhuZhang2023"><span class="ouvrage" id="Cheng_ZhangYunhui_JiaLibin_ZhuZhipeng_Zhang2023">Cheng <span class="nom_auteur">Zhang</span>, Yunhui <span class="nom_auteur">Jia</span>, Libin <span class="nom_auteur">Zhu</span> et Zhipeng <span class="nom_auteur">Zhang</span>, « <cite style="font-style:normal">Research on Simple Power Consumption Based on AES Algorithm</cite> », <i>IEEE</i>, <time>2023</time>, <abbr class="abbr" title="pages">p.</abbr> <span class="nowrap">1883–1886</span> <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-1-6654-6253-2</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1109/EEBDA56825.2023.10090666">10.1109/EEBDA56825.2023.10090666</a></span>, <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/10090666/">lire en ligne</a>, consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Research+on+Simple+Power+Consumption+Based+on+AES+Algorithm&rft.jtitle=IEEE&rft.aulast=Zhang&rft.aufirst=Cheng&rft.au=Jia%2C+Yunhui&rft.au=Zhu%2C+Libin&rft.au=Zhang%2C+Zhipeng&rft.date=2023&rft.pages=1883%E2%80%931886&rft.isbn=978-1-6654-6253-2&rft_id=info%3Adoi%2F10.1109%2FEEBDA56825.2023.10090666&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><a href="#cite_ref-11">↑</a> </span><span class="reference-text"><span class="ouvrage" id="TehranipoorNalla_AnandakumarFarahmandi2023"><span class="ouvrage" id="Mark_TehranipoorN._Nalla_AnandakumarFarimah_Farahmandi2023"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> Mark <span class="nom_auteur">Tehranipoor</span>, N. <span class="nom_auteur">Nalla Anandakumar</span> et Farimah <span class="nom_auteur">Farahmandi</span>, <cite style="font-style:normal" lang="en">« EM Side-Channel Attack on AES »</cite>, dans <cite class="italique" lang="en">Hardware Security Training, Hands-on!</cite>, Springer International Publishing, <time>2023</time>, 163–181 <abbr class="abbr" title="pages">p.</abbr> <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-3-031-31033-1</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1007/978-3-031-31034-8_9">10.1007/978-3-031-31034-8_9</a></span>, <a rel="nofollow" class="external text" href="https://link.springer.com/10.1007/978-3-031-31034-8_9">lire en ligne</a>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rft.genre=bookitem&rft.btitle=Hardware+Security+Training%2C+Hands-on%21&rft.atitle=EM+Side-Channel+Attack+on+AES&rft.pub=Springer+International+Publishing&rft.aulast=Tehranipoor&rft.aufirst=Mark&rft.au=Nalla+Anandakumar%2C+N.&rft.au=Farahmandi%2C+Farimah&rft.date=2023&rft.tpages=163%E2%80%93181&rft.isbn=978-3-031-31033-1&rft_id=info%3Adoi%2F10.1007%2F978-3-031-31034-8_9&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><a href="#cite_ref-12">↑</a> </span><span class="reference-text"><span class="ouvrage" id="AshokkumarGiriMenezes2016"><span class="ouvrage" id="C._AshokkumarRavi_Prakash_GiriBernard_Menezes2016">C. <span class="nom_auteur">Ashokkumar</span>, Ravi Prakash <span class="nom_auteur">Giri</span> et Bernard <span class="nom_auteur">Menezes</span>, « <cite style="font-style:normal">Highly Efficient Algorithms for AES Key Retrieval in Cache Access Attacks</cite> », <i>IEEE</i>, <time>2016</time>, <abbr class="abbr" title="pages">p.</abbr> <span class="nowrap">261–275</span> <small style="line-height:1em;">(<a href="International_Standard_Book_Number" title="International Standard Book Number">ISBN</a> <span class="nowrap">978-1-5090-1751-5</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1109/EuroSP.2016.29">10.1109/EuroSP.2016.29</a></span>, <a rel="nofollow" class="external text" href="https://ieeexplore.ieee.org/document/7467359/">lire en ligne</a>, consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Highly+Efficient+Algorithms+for+AES+Key+Retrieval+in+Cache+Access+Attacks&rft.jtitle=IEEE&rft.aulast=Ashokkumar&rft.aufirst=C.&rft.au=Giri%2C+Ravi+Prakash&rft.au=Menezes%2C+Bernard&rft.date=2016&rft.pages=261%E2%80%93275&rft.isbn=978-1-5090-1751-5&rft_id=info%3Adoi%2F10.1109%2FEuroSP.2016.29&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><a href="#cite_ref-13">↑</a> </span><span class="reference-text"><span class="ouvrage" id="LASHERMES2018"><span class="ouvrage" id="Ronan_LASHERMES2018">Ronan LASHERMES, « <cite style="font-style:normal">Attaques par fautes</cite> », <i>MISC</i>, <abbr class="abbr" title="numéro">n<sup>o</sup></abbr> 96, <time>2018</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://ronan.lashermes.0nline.fr/papers/MISC96.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Attaques+par+fautes&rft.jtitle=MISC&rft.issue=96&rft.aulast=LASHERMES&rft.aufirst=Ronan&rft.date=2018&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><a href="#cite_ref-14">↑</a> </span><span class="reference-text">Xavier Bonnetain, María Naya-Plasencia, André Schrottenloher. Quantum Security Analysis of AES. IACR Transactions on Symmetric Cryptology, 2019, 2019 (2), pp.55-93. ff10.13154/tosc.v2019.i2.55- 93ff. ffhal-02397049f</span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><a href="#cite_ref-15">↑</a> </span><span class="reference-text"><span class="ouvrage" id="KaramlouSimonKatabarwaScholten2021"><span class="ouvrage" id="Amir_H._KaramlouWilliam_A._SimonAmara_KatabarwaTravis_L._Scholten2021">Amir H. <span class="nom_auteur">Karamlou</span>, William A. <span class="nom_auteur">Simon</span>, Amara <span class="nom_auteur">Katabarwa</span> et Travis L. <span class="nom_auteur">Scholten</span>, « <cite style="font-style:normal">Analyzing the performance of variational quantum factoring on a superconducting quantum processor</cite> », <i>npj Quantum Information</i>, <abbr class="abbr" title="volume">vol.</abbr> 7, <abbr class="abbr" title="numéro">n<sup>o</sup></abbr> 1, <time class="nowrap" datetime="2021-10-28" data-sort-value="2021-10-28">28 octobre 2021</time> <small style="line-height:1em;">(<a href="International_Standard_Serial_Number" title="International Standard Serial Number">ISSN</a> <span class=" noarchive"><a rel="nofollow" class="external text" href="https://portal.issn.org/resource/issn/2056-6387">2056-6387</a></span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">DOI</a> <span class=" noarchive nowrap"><a rel="nofollow" class="external text" href="https://dx.doi.org/10.1038/s41534-021-00478-z">10.1038/s41534-021-00478-z</a></span>, <a rel="nofollow" class="external text" href="https://dx.doi.org/10.1038/s41534-021-00478-z">lire en ligne</a>, consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Analyzing+the+performance+of+variational+quantum+factoring+on+a+superconducting+quantum+processor&rft.jtitle=npj+Quantum+Information&rft.issue=1&rft.aulast=Karamlou&rft.aufirst=Amir+H.&rft.au=Simon%2C+William+A.&rft.au=Katabarwa%2C+Amara&rft.au=Scholten%2C+Travis+L.&rft.date=2021-10-28&rft.volume=7&rft.issn=2056-6387&rft_id=info%3Adoi%2F10.1038%2Fs41534-021-00478-z&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><a href="#cite_ref-16">↑</a> </span><span class="reference-text"><span class="ouvrage" id="BURNEL2024"><span class="ouvrage" id="Florian_BURNEL2024">Florian <span class="nom_auteur">BURNEL</span>, « <a rel="nofollow" class="external text" href="https://www.it-connect.fr/des-chercheurs-cassent-cle-rsa-de-22-bits-ordinateur-quantique/"><cite style="font-style:normal;">Des chercheurs chinois cassent le RSA avec un ordinateur quantique</cite></a> », sur <span class="italique">www.it-connect.fr</span>, <time class="nowrap" datetime="2024-10-16" data-sort-value="2024-10-16">16 octobre 2024</time> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small></span></span></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><a href="#cite_ref-17">↑</a> </span><span class="reference-text"><span class="ouvrage">« <a rel="nofollow" class="external text" href="https://connect.ed-diamond.com/MISC/misc-085/implementation-d-aes-la-nitroglycerine"><cite style="font-style:normal;">Implémentation d'AES : la nitroglycérine | Connect - Editions Diamond</cite></a> », sur <span class="italique">connect.ed-diamond.com</span> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small></span></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><a href="#cite_ref-18">↑</a> </span><span class="reference-text"><a rel="nofollow" class="external free" href="https://web.archive.org/web/20070927035010/http://www.cnss.gov/Assets/pdf/cnssp_15_fs.pdf">https://web.archive.org/web/20070927035010/http://www.cnss.gov/Assets/pdf/cnssp_15_fs.pdf</a></span>
</li>
<li id="cite_note-:1-19"><span class="reference-text"><span class="ouvrage" id="Bruce_et_al.1999"><span class="ouvrage" id="SCHNEIER,_Bruce_et_al.1999"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> SCHNEIER, Bruce et al., « <cite style="font-style:normal" lang="en">Performance Comparison of the AES Submissions</cite> », <i><span class="lang-en" lang="en">NIST</span></i>, <time>1999</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://www.schneier.com/wp-content/uploads/2016/02/paper-aes-performance.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Performance+Comparison+of+the+AES+Submissions&rft.jtitle=NIST&rft.au=SCHNEIER%2C+Bruce+et+al.&rft.date=1999&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><a href="#cite_ref-20">↑</a> </span><span class="reference-text"><span class="ouvrage" id="Bruce_et_al.1999"><span class="ouvrage" id="SCHEIER,_Bruce_et_al.1999"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> SCHEIER, Bruce et al., « <cite style="font-style:normal" lang="en">AES performance comparison</cite> », <i><span class="lang-en" lang="en">NIST</span></i>, <time>1999</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://csrc.nist.rip/encryption/aes/round1/conf2/Schneier.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=AES+performance+comparison&rft.jtitle=NIST&rft.au=SCHEIER%2C+Bruce+et+al.&rft.date=1999&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><a href="#cite_ref-21">↑</a> </span><span class="reference-text"><span class="ouvrage" id="2010"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> « <cite style="font-style:normal" lang="en">Intel® Advanced Encryption Standard (AES) New Instructions Set</cite> », <i><span class="lang-en" lang="en">INTEL</span></i>, <time>2010</time> <small style="line-height:1em;">(<a rel="nofollow" class="external text" href="https://www.intel.com/content/dam/doc/white-paper/advanced-encryption-standard-new-instructions-set-paper.pdf">lire en ligne</a> <abbr class="abbr indicateur-format format-pdf" title="Document au format Portable Document Format (PDF) d'Adobe">[PDF]</abbr>)</small><span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rft.genre=article&rft.atitle=Intel%C2%AE+Advanced+Encryption+Standard+%28AES%29+New+Instructions+Set&rft.jtitle=INTEL&rft.date=2010&rfr_id=info%3Asid%2Ffr.wikipedia.org%3AAdvanced+Encryption+Standard"></span></span></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><a href="#cite_ref-22">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> « <a rel="nofollow" class="external text" href="https://legacy.cryptool.org/en/cto/aes-step-by-step"><cite style="font-style:normal;" lang="en">CrypTool Portal</cite></a> », sur <span class="italique">CrypTool Portal</span> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small></span></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><a href="#cite_ref-23">↑</a> </span><span class="reference-text"><span class="ouvrage"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> « <a rel="nofollow" class="external text" href="https://legacy.cryptool.org/en/cto/aes-animation"><cite style="font-style:normal;" lang="en">CrypTool Portal</cite></a> », sur <span class="italique">CrypTool Portal</span> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2024-11-20" data-sort-value="2024-11-20">20 novembre 2024</time>)</small></span></span>
</li>
</ol></div>
</div>
<div class="mw-heading mw-heading2"><h2 id="Annexes">Annexes</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Articles_connexes">Articles connexes</h3></div>
<ul><li><a href="Cryptographie_sym%C3%A9trique" title="Cryptographie symétrique">Cryptographie symétrique</a></li>
<li><a href="Data_Encryption_Standard" title="Data Encryption Standard">DES</a></li>
<li><a href="Mode_d'op%C3%A9ration_(cryptographie)" title="Mode d'opération (cryptographie)">Mode d'opération (cryptographie)</a></li>
<li><a href="Projet_NESSIE" class="mw-redirect" title="Projet NESSIE">Projet NESSIE</a></li>
<li><a href="Rijndael" title="Rijndael">Rijndael</a></li>
<li><a href="Triple_DES" title="Triple DES">Triple DES</a></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Liens_externes">Liens externes</h3></div>
<ul><li><abbr class="abbr indicateur-langue" title="Langue : français">(fr)</abbr> <span class="noarchive">« <a rel="nofollow" class="external text" href="https://web.archive.org/web/20090220151705/http://crypto.freezee.org">Adaptation française du document du NIST</a> »</span> <small>(version du <time class="nowrap" datetime="2009-02-20" data-sort-value="2009-02-20">20 février 2009</time> sur <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>)</small></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://doi.org/10.6028/NIST.FIPS.197">Federal Information Processing Standards Publication 197 November 26, 2001 Announcing the ADVANCED ENCRYPTION STANDARD (AES</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://embeddedsw.net/Cipher_Reference_Home.html">code de référence</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage"><span class="noarchive">« <a rel="nofollow" class="external text" href="http://www.esat.kuleuven.ac.be/~rijmen/rijndael/"><cite style="font-style:normal; color:var(--color-link-red, #d73333);">Site officiel de Rijndael</cite></a> »<sup class="">(<a rel="nofollow" class="external text" href="https://web.archive.org/web/*/http://www.esat.kuleuven.ac.be/~rijmen/rijndael/">Archive.org</a> • <a rel="nofollow" class="external text" href="https://archive.wikiwix.com/cache/?url=http://www.esat.kuleuven.ac.be/~rijmen/rijndael/">Wikiwix</a> • <a rel="nofollow" class="external text" href="https://archive.is/http://www.esat.kuleuven.ac.be/~rijmen/rijndael/">Archive.is</a> • <a rel="nofollow" class="external text" href="https://webcache.googleusercontent.com/search?hl=fr&q=cache:http://www.esat.kuleuven.ac.be/~rijmen/rijndael/">Google</a> • Que faire ?)</sup></span></span> (lien mort) *<a rel="nofollow" class="external text" href="https://web.archive.org/web/*/http://homes.esat.kuleuven.be/~rijmen/rijndael/">lien vers archive.org</a>*</li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://www.cryptosystem.net/aes/">Présentation de l'attaque XSL</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://www.schneier.com/crypto-gram-0210.html#2">L'avis des experts sur l'attaque XSL</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://citeseer.ist.psu.edu/koeune99timing.html">« A timing attack against Rijndael » (1999) - Francois Koeune, Jean-Jacques Quisquater</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://www.dsprelated.com/showmessage/26345/1.php">AES timing attacks - discussion sur comp.dsp</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="http://csrc.nist.gov/archive/aes/round2/r2report.pdf">Report of the Development of the Advanced Encryption Standard (AES)</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : français">(fr)</abbr> <a rel="nofollow" class="external text" href="https://connect.ed-diamond.com/MISC/MISCHS-005/De-l-esperance-de-vie-d-un-algorithme-symetrique-ou-l-AES-dix-ans-apres">AES Esperance de vie d'un algoritme</a></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://aesencryptiondecryption.tool-kit.dev/">outil aes</a></li></ul>
<div class="navbox-container" style="clear:both;">
</div>
<ul id="bandeau-portail" class="bandeau-portail"><li><span class="bandeau-portail-element"><span class="bandeau-portail-icone"><span class="noviewer" typeof="mw:File"></span></span> <span class="bandeau-portail-texte">Portail de la cryptologie</span> </span></li> </ul></div><!--htdig_noindex--><div><div class="zim-footer">
Cet article est issu de <a class="external text" title="Dernière modification le 2025-09-25" href="https://fr.wikipedia.org/wiki/?title=Advanced_Encryption_Standard&oldid=229258700">Wikipédia</a>. Sauf mention contraire, le texte est disponible sous <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.fr">Creative Commons Attribution-Share Alike 4.0</a>. Des conditions supplémentaires peuvent s’appliquer aux fichiers multimédias.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>
</body></html>