Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 skin-theme-clientpref-day vector-sticky-header-enabled" lang="de" dir="ltr"><head>
<meta charset="UTF-8">
<title>Advanced Encryption Standard</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://de.wikipedia.org/wiki/Advanced_Encryption_Standard"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.math.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link href="./_mw_/ext.gadget.citeRef.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.defaultPlainlinks.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonHide.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonLayout.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonStyle.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiDarkmode.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiResponsive.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.specialSearch.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Advanced_Encryption_Standard rootpage-Advanced_Encryption_Standard skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">Advanced Encryption Standard</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="de" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="de" dir="ltr"><table class="float-right infobox wikitable" style="font-size:90%; margin-top:0; width:23em;">

<tbody><tr>
<th colspan="2" class="hintergrundfarbe6" style="font-size:105%;">AES
</th></tr>
<tr>
<td colspan="2" style="text-align:center;"><small>Der Substitutionsschritt, einer von 4 Teilschritten pro Runde</small>
</td></tr>
<tr>
<td>Entwickler
</td>
<td><a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a>, <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a>
</td></tr>
<tr>
<td>Veröffentlicht
</td>
<td>1998, Zertifizierung Oktober 2000
</td></tr>
<tr>
<td>Abgeleitet von
</td>
<td>Square
</td></tr>
<tr>
<td>Zertifizierung
</td>
<td><a href="NESSIE" title="NESSIE">NESSIE</a>
</td></tr>
<tr>
<td>Schlüssellänge
</td>
<td>128, 192 oder 256&nbsp;Bit
</td></tr>
<tr>
<td>Blockgröße
</td>
<td>128 Bit<sup id="cite_ref-blocksize_1-0" class="reference"><a href="#cite_note-blocksize-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td>Struktur
</td>
<td><a href="Substitutions-Permutations-Netzwerk" title="Substitutions-Permutations-Netzwerk">Substitutions-Permutations-Netzwerk</a>
</td></tr>
<tr>
<td>Runden
</td>
<td>10, 12 oder 14 (schlüssellängenabhängig)
</td></tr>
<tr>
<th colspan="2" class="hintergrundfarbe6">Beste bekannte Kryptoanalyse
</th></tr>
<tr>
<td colspan="2" style="text-align:center;">Der geheime Schlüssel kann bei AES-128 in 2<sup>126,1</sup> Schritten, bei AES-192 in 2<sup>189,7</sup> Schritten und bei AES-256 in 2<sup>254,4</sup> Schritten gefunden werden.<sup id="cite_ref-biclique_2-0" class="reference"><a href="#cite_note-biclique-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</td></tr></tbody></table>
<p>Der <b>Advanced Encryption Standard</b> (<b>AES</b>) (<span style="font-style:normal;font-weight:normal"><a href="Deutsche_Sprache" title="Deutsche Sprache">deutsch</a></span> <span lang="de-Latn">etwa „fortschrittlicher Verschlüsselungsstandard“</span>) ist eine <a href="Blockverschl%C3%BCsselung" title="Blockverschlüsselung">Blockchiffre</a>, die als Nachfolger des <a href="Data_Encryption_Standard" title="Data Encryption Standard">DES</a> im Oktober 2000 vom <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> (NIST) als US-amerikanischer Standard bekanntgegeben wurde. Der <a href="Algorithmus" title="Algorithmus">Algorithmus</a> wurde von <a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a> und <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a> unter der Bezeichnung <b>Rijndael</b> entwickelt.
</p><p>Es handelt sich um ein <a href="Symmetrisches_Kryptosystem" title="Symmetrisches Kryptosystem">symmetrisches Verschlüsselungsverfahren</a>, d.&nbsp;h. der <a href="Schl%C3%BCssel_(Kryptologie)" title="Schlüssel (Kryptologie)">Schlüssel</a> zum <a href="Verschl%C3%BCsselung" title="Verschlüsselung">Ver-</a> und <a href="Entschl%C3%BCsselung" title="Entschlüsselung">Entschlüsseln</a> ist identisch. Der Rijndael-Algorithmus besitzt variable, voneinander unabhängige Block- und <a href="Schl%C3%BCssell%C3%A4nge" title="Schlüssellänge">Schlüssellängen</a> von 128, 160, 192, 224 oder 256 Bit. Rijndael bietet ein sehr hohes Maß an Sicherheit; erst mehr als zehn Jahre nach seiner Standardisierung wurde der erste theoretisch interessante, praktisch aber nicht relevante Angriff gefunden.
</p><p>AES schränkt die Blocklänge auf 128 Bit und die Wahl der Schlüssellänge auf 128, 192 oder 256 <a href="Bit" title="Bit">Bit</a> ein. Die Bezeichnungen der drei AES-Varianten AES-128, AES-192 und AES-256 beziehen sich jeweils auf die gewählte Schlüssellänge. AES ist frei verfügbar und darf ohne Lizenzgebühren eingesetzt sowie in Soft- und Hardware implementiert werden.
</p><p>Das Verfahren ist pragmatisch sicher; das heißt, es ist kein praktisch durchführbarer <a href="Kryptoanalyse" title="Kryptoanalyse">Angriff</a> bekannt. Es ist jedoch theoretisch <a href="Brechen_(Kryptologie)" title="Brechen (Kryptologie)">gebrochen</a>: die <a href="Entzifferung" title="Entzifferung">Entzifferung</a> ist unter Umständen mit geringerem (aber noch immer unrealistisch hohem) Aufwand möglich als das systematische Durchprobieren aller möglicher Schlüssel. AES-192 und AES-256 sind in den <a href="Vereinigte_Staaten" title="Vereinigte Staaten">USA</a> für staatliche Dokumente mit höchstem <a href="Geheimhaltungsgrad" title="Geheimhaltungsgrad">Geheimhaltungsgrad</a> zugelassen.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>

<div class="mw-heading mw-heading2"><h2 id="Entstehung">Entstehung</h2></div>
<p>Bis zum Einsatz von AES war der <a href="Data_Encryption_Standard" title="Data Encryption Standard">Data Encryption Standard</a> (DES) der am häufigsten genutzte symmetrische Algorithmus zur <a href="Verschl%C3%BCsselung" title="Verschlüsselung">Verschlüsselung</a> von Daten. Spätestens seit den 1990er Jahren galt er mit seiner Schlüssellänge von 56&nbsp;Bit als nicht mehr ausreichend sicher gegen Angriffe mit der <a href="Brute-Force-Methode" title="Brute-Force-Methode">Brute-Force-Methode</a>. Ein neuer, besserer Algorithmus musste gefunden werden.
</p>
<div class="mw-heading mw-heading3"><h3 id="Auswahl_eines_DES-Nachfolgers">Auswahl eines DES-Nachfolgers</h3></div>
<p>Das amerikanische Handelsministerium schrieb die Suche nach einem Nachfolgealgorithmus am 2.&nbsp;Januar 1997 international aus, federführend für die Auswahl war das US-amerikanische <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> in Gaithersburg, Maryland. Nach einer internationalen Konferenz am 15.&nbsp;April 1997 veröffentlichte es am 12.&nbsp;September 1997 die endgültige Ausschreibung. Die Art der Suche sowie die Auswahlkriterien unterschieden sich damit beträchtlich von der hinter verschlossenen Türen erfolgten DES-Entwicklung. Der Sieger der Ausschreibung, der als Advanced Encryption Standard (AES) festgelegt werden sollte, musste folgende Kriterien erfüllen:
</p>
<ul><li>AES muss ein <a href="Symmetrisches_Kryptosystem" title="Symmetrisches Kryptosystem">symmetrischer Algorithmus</a> sein, und zwar eine <a href="Blockchiffre" class="mw-redirect" title="Blockchiffre">Blockchiffre</a>.</li>
<li>AES muss 128 Bit lange Blöcke verwenden (dies wurde erst während der Ausschreibung festgelegt, zu Beginn der Ausschreibung waren auch Blockgrößen von 192 und 256 Bit verlangt, diese wurden nur als mögliche Erweiterungen beibehalten)</li>
<li>AES muss Schlüssel von 128, 192 und 256 Bit Länge einsetzen können.</li>
<li>AES soll gleichermaßen leicht in Hard- und Software zu <a href="Implementierung" title="Implementierung">implementieren</a> sein.</li>
<li>AES soll in <a href="Hardware" title="Hardware">Hardware</a> wie <a href="Software" title="Software">Software</a> eine überdurchschnittliche <a href="Rechenleistung" title="Rechenleistung">Leistung</a> haben.</li>
<li>AES soll allen bekannten Methoden der <a href="Kryptoanalyse" title="Kryptoanalyse">Kryptoanalyse</a> widerstehen können und sich für Implementierungen eignen, die sicher gegen Power- und Timing-Attacken sind.</li>
<li>Speziell für den Einsatz in <a href="Smartcard" class="mw-redirect" title="Smartcard">Smartcards</a> sollen geringe <a href="Ressource" title="Ressource">Ressourcen</a> erforderlich sein (Codelänge, <a href="Speicherbedarf" class="mw-redirect" title="Speicherbedarf">Speicherbedarf</a>).</li>
<li>Der Algorithmus muss frei von <a href="Patent" title="Patent">patentrechtlichen</a> Ansprüchen sein und muss von jedermann unentgeltlich genutzt werden können.</li></ul>
<p>Die Auswahlkriterien wurden in drei Hauptkategorien unterteilt: Sicherheit, Kosten sowie Algorithmus- und Implementierungscharakteristiken. Die Sicherheit war der wichtigste Faktor in der Evaluierung und umfasste die Eigenschaften Widerstandsfähigkeit des Algorithmus gegen Kryptoanalyse, Zufälligkeit des Chiffrats, Stichhaltigkeit der mathematischen Basis sowie die relative Sicherheit im Vergleich zu den anderen Kandidaten.
</p><p>Kosten, der nächste wichtige Faktor, ist im Sinne des Auswahlverfahrens als Überbegriff zu verstehen: Dieser umfasste Lizenzierungsansprüche sowie rechnerische Effizienz auf verschiedenen Plattformen und Speicherverbrauch.
Da eines der wichtigsten Ziele, die das NIST ausgearbeitet hatte, die weltweite Verbreitung auf lizenzfreier Basis war und dass AES von jedermann unentgeltlich genutzt werden kann, wurden öffentliche Kommentare und Anregungen zu Lizenzansprüchen und diesbezügliche potenzielle Konflikte spezifisch gesucht.
</p><p>Die Anforderung der Geschwindigkeit des Algorithmus auf diversen Plattformen wurde in drei zusätzliche Ziele unterteilt:
</p>
<ul><li>Die rechnerische Geschwindigkeit mit 128-Bit-Schlüsseln.</li>
<li>Die rechnerische Geschwindigkeit mit 192-Bit- und 256-Bit-Schlüsseln sowie die rechnerische Geschwindigkeit verschiedener Hardware-Implementierungen. Der Speicherverbrauch und die Grenzen von Software-Implementierungen der Kandidaten waren weitere wichtige Aspekte.</li>
<li>Das dritte Ziel, die Algorithmus- und Implementierungscharakteristiken, beinhalteten die Flexibilität, die Eignung für Soft- und Hardware-Implementierungen und die Einfachheit des Algorithmus.</li></ul>
<p>Unter Flexibilität verstand man die Eigenschaften, dass AES die Schlüssel- und Blockgröße über dem Minimum unterstützen musste und dass er in verschiedenen Typen von Umgebungen sowie zusätzlich als <a href="Stromchiffre" class="mw-redirect" title="Stromchiffre">Stromchiffre</a> und <a href="Kryptologische_Hashfunktion" class="mw-redirect" title="Kryptologische Hashfunktion">kryptologische Hashfunktion</a> sicher und effizient zu implementieren war.
</p><p>Die Ausschreibung führte bis zum Abgabeschluss am 15. Juni 1998 zu fünfzehn Vorschlägen aus aller Welt. Diese wurden in der AES-Konferenz vom 20. bis 22. August 1998 in <a href="Ventura_(Kalifornien)" title="Ventura (Kalifornien)">Ventura (Kalifornien)</a> vorgestellt, öffentlich diskutiert und auf die Erfüllung der genannten Kriterien geprüft. Die AES-Konferenz vom 22. und 23. April 1999 in Rom führte zu einer ersten Diskussion der Ergebnisse und Empfehlungen, welche der fünfzehn Algorithmen weiter betrachtet werden sollten. Die fünf besten Kandidaten (<a href="MARS_(Verschl%C3%BCsselung)" title="MARS (Verschlüsselung)">MARS</a>, <a href="RC6" title="RC6">RC6</a>, Rijndael, <a href="Serpent_(Verschl%C3%BCsselung)" title="Serpent (Verschlüsselung)">Serpent</a>, <a href="Twofish" title="Twofish">Twofish</a>) kamen in die nächste Runde.
</p><p>Alle fünf Kandidaten erfüllen die oben genannten Forderungen, daher wurden weitere Kriterien hinzugezogen. Es folgte eine Überprüfung der Algorithmen auf theoretische Schwachstellen, durch die der Algorithmus möglicherweise zu einem späteren Zeitpunkt durch technischen Fortschritt unsicher werden kann. So konnten zum damaligen Stand technisch nicht realisierbare Vorgehensweisen in einigen Jahren anwendbar sein, ein solches Risiko sollte minimiert werden. Die Staffelung der Kandidaten nach <a href="Ressource" title="Ressource">Ressourcenverbrauch</a> und <a href="Rechenleistung" title="Rechenleistung">Leistung</a> war eindeutiger. Der Rijndael-Algorithmus hatte sich in <a href="Hardware" title="Hardware">Hardware</a>- und <a href="Software" title="Software">Software</a>-<a href="Implementierung" title="Implementierung">Implementierung</a> als überdurchschnittlich schnell herausgestellt. Die anderen Kandidaten haben jeweils in unterschiedlichen Bereichen kleinere Schwächen.
</p><p>Im Mai des Jahres 2000 wurden die Analysen und öffentlichen Diskussionen abgeschlossen und am 2.&nbsp;Oktober 2000 der Sieger schließlich bekannt gegeben: der belgische Algorithmus Rijndael. Rijndael überzeugte durch seine Einfachheit (die Referenz-Implementierung umfasst weniger als 500 Zeilen <a href="C_(Programmiersprache)" title="C (Programmiersprache)">C-Code</a>), Sicherheit und Geschwindigkeit, weshalb sich die USA trotz Sicherheitsbedenken für einen europäischen Algorithmus entschieden.
</p><p>Der Auswahlprozess faszinierte weltweit viele Kryptographen insbesondere durch seine offene Gestaltung. Bis heute wird dieser Wettbewerb als vorbildlich angesehen.
</p>
<div class="mw-heading mw-heading2"><h2 id="Arbeitsweise">Arbeitsweise</h2></div>
<p>Rijndael ist eine als <a href="Substitutions-Permutations-Netzwerk" title="Substitutions-Permutations-Netzwerk">Substitutions-Permutations-Netzwerk</a> entworfene <a href="Blockverschl%C3%BCsselung" title="Blockverschlüsselung">Blockchiffre</a>. Bei Rijndael können Blocklänge und Schlüssellänge unabhängig voneinander die Werte 128, 160, 192, 224 oder 256 Bits erhalten, während bei AES die Blockgröße auf 128 Bit festgelegt ist und die Schlüsselgröße 128, 192 oder 256 Bit betragen kann.
</p><p>Rijndael ist eine <a href="Iteration" title="Iteration">iterierte</a> Blockchiffre, d.&nbsp;h. der Block wird in mehreren aufeinanderfolgenden Runden verschlüsselt, die bis auf die verwendeten Rundenschlüssel gleich sind. Für jede Runde wird ein anderer Rundenschlüssel aus dem Originalschlüssel berechnet (Schlüsselexpansion). Die Anzahl <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle R}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>R</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle R}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/4b0bfb3769bf24d80e15374dc37b0441e2616e33.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.764ex; height:2.176ex;" alt="{\displaystyle R}" loading="lazy"></span> der Runden variiert und ist vom Maximum der Blockgröße <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f11423fbb2e967f986e36804a8ae4271734917c3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.998ex; height:2.176ex;" alt="{\displaystyle b}" loading="lazy"></span> und der Schlüssellänge <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle k}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>k</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle k}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/c3c9a2c7b599b37105512c5d570edc034056dd40.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.211ex; height:2.176ex;" alt="{\displaystyle k}" loading="lazy"></span> abhängig (beim AES also nur von der Schlüssellänge):
</p>
<table class="wikitable" style="text-align:center;">
<caption>Anzahl der Runden bei Rijndael
</caption>
<tbody><tr>
<th class="hintergrundfarbe6">max(b, k)
</th>
<th>128
</th>
<th>160
</th>
<th>192
</th>
<th>224
</th>
<th>256
</th></tr>
<tr>
<th class="hintergrundfarbe6">Rundenzahl R
</th>
<td>10
</td>
<td>11
</td>
<td>12
</td>
<td>13
</td>
<td>14
</td></tr></tbody></table>
<p>Der Datenblock, der ver- oder entschlüsselt werden soll, wird zunächst in eine zweidimensionale <a href="Tabelle" title="Tabelle">Tabelle</a> geschrieben, deren Zellen ein <a href="Byte" title="Byte">Byte</a> groß sind und die vier Zeilen und je nach Blockgröße 4 bis 8 Spalten hat.
</p>
<div class="mw-heading mw-heading3"><h3 id="Ablauf">Ablauf</h3></div>
<ul><li>Schlüsselexpansion</li>
<li>AddRoundKey(Rundenschlüssel[0])</li>
<li><i>Verschlüsselungsrunden r = 1 bis R-1:</i>
<ul><li>SubBytes()</li>
<li>ShiftRows()</li>
<li>MixColumns()</li>
<li>AddRoundKey(Rundenschlüssel[r])</li></ul></li>
<li><i>Schlussrunde:</i>
<ul><li>SubBytes()</li>
<li>ShiftRows()</li>
<li>AddRoundKey(Rundenschlüssel[R])</li></ul></li></ul>
<div class="mw-heading mw-heading3"><h3 id="S-Box">S-Box</h3></div>
<p>Rijndael verwendet eine <a href="S-Box" title="S-Box">S-Box</a>, um bei der Operation <i>SubBytes()</i> jedes Byte des Datenblocks durch ein anderes zu ersetzen, und sie wird auch bei der Schlüsselexpansion eingesetzt. Eine S-Box (Substitutionsbox) dient zur <a href="Monoalphabetische_Substitution" title="Monoalphabetische Substitution">monoalphabetischen Verschlüsselung</a>. Sie bewirkt vor allem die Verwischung der Beziehung zwischen Klar- und Geheimtext, was in der kryptologischen Fachsprache <a href="Konfusion_(Kryptologie)" title="Konfusion (Kryptologie)">Konfusion</a> genannt wird, kann aber auch zur Umsetzung des <a href="Claude_Elwood_Shannon" class="mw-redirect" title="Claude Elwood Shannon">Shannon’schen</a> Prinzips der <a href="Diffusion_(Kryptologie)" title="Diffusion (Kryptologie)">Diffusion</a> beitragen.
</p><p>Die S-Box von Rijndael ist nach Kriterien konstruiert, die die Anfälligkeit für die Methoden der linearen und der differentiellen Kryptoanalyse sowie für algebraische Attacken minimieren sollen. Sie besteht aus 256 Bytes, die erzeugt werden, indem jedes Byte außer der Null, aufgefasst als Vertreter des <a href="Endlicher_K%C3%B6rper" title="Endlicher Körper">endlichen Körpers</a> <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \mathbb {F} _{2^{8}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">F</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>8</mn>
</mrow>
</msup>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \mathbb {F} _{2^{8}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a294571cba95908afeea64b9c0528f082721dfae.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:3.306ex; height:2.843ex;" alt="{\displaystyle \mathbb {F} _{2^{8}}}" loading="lazy"></span>, durch sein multiplikatives Inverses ersetzt wird, worauf noch eine affine Transformation erfolgt.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Es ist
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle S(x)={\overline {x}}\oplus ({\overline {x}}\lll 1)\oplus ({\overline {x}}\lll 2)\oplus ({\overline {x}}\lll 3)\oplus ({\overline {x}}\lll 4)\oplus (63)_{\text{hex}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>S</mi>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo>⋘<!-- ⋘ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo>⋘<!-- ⋘ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo>⋘<!-- ⋘ --></mo>
<mn>3</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo>⋘<!-- ⋘ --></mo>
<mn>4</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mn>63</mn>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext>hex</mtext>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle S(x)={\overline {x}}\oplus ({\overline {x}}\lll 1)\oplus ({\overline {x}}\lll 2)\oplus ({\overline {x}}\lll 3)\oplus ({\overline {x}}\lll 4)\oplus (63)_{\text{hex}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/ca87175074cfa36858ad2759651eb32551d2b403.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:65.477ex; height:2.843ex;" alt="{\displaystyle S(x)={\overline {x}}\oplus ({\overline {x}}\lll 1)\oplus ({\overline {x}}\lll 2)\oplus ({\overline {x}}\lll 3)\oplus ({\overline {x}}\lll 4)\oplus (63)_{\text{hex}}}" loading="lazy"></span>.</dd></dl>
<p>Dabei steht <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\overline {x}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\overline {x}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/9fa4039bbc2a0048c3a3c02e5fd24390cab0dc97.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.445ex; height:2.343ex;" alt="{\displaystyle {\overline {x}}}" loading="lazy"></span> für das multiplikative Inverse von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/87f9e315fd7e2ba406057a97300593c4802b53e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\displaystyle x}" loading="lazy"></span> in <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \mathbb {F} _{2^{8}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">F</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>8</mn>
</mrow>
</msup>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \mathbb {F} _{2^{8}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a294571cba95908afeea64b9c0528f082721dfae.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:3.306ex; height:2.843ex;" alt="{\displaystyle \mathbb {F} _{2^{8}}}" loading="lazy"></span>, oder für 0, falls <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x=0}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
<mo>=</mo>
<mn>0</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x=0}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/953917eaf52f2e1baad54c8c9e3d6f9bb3710cdc.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:5.591ex; height:2.176ex;" alt="{\displaystyle x=0}" loading="lazy"></span>. <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b\lll n}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
<mo>⋘<!-- ⋘ --></mo>
<mi>n</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b\lll n}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/fab27fe2615c9728f521d303a5b2452b3a983713.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:6.78ex; height:2.176ex;" alt="{\displaystyle b\lll n}" loading="lazy"></span> bezeichnet die <a href="Bitweiser_Operator#Zyklische_Verschiebung" title="Bitweiser Operator">Linksrotation</a> des Bytes <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f11423fbb2e967f986e36804a8ae4271734917c3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.998ex; height:2.176ex;" alt="{\displaystyle b}" loading="lazy"></span> um <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle n}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>n</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle n}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a601995d55609f2d9f5e233e36fbe9ea26011b3b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.395ex; height:1.676ex;" alt="{\displaystyle n}" loading="lazy"></span> Bitpositionen und <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \oplus }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo>⊕<!-- ⊕ --></mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \oplus }</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8b16e2bdaefee9eed86d866e6eba3ac47c710f60.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.505ex; width:1.808ex; height:2.176ex;" alt="{\displaystyle \oplus }" loading="lazy"></span> das <a href="Bitweiser_Operator#XOR" title="Bitweiser Operator">bitweise XOR</a>.
</p><p>Die Werte der S-Box und der zum Entschlüsseln benötigten inversen S-Box können entweder für jedes substituierte Byte erneut (dynamisch) berechnet werden, um Speicher zu sparen, oder vorberechnet und in einem <a href="Feld_(Datentyp)" class="mw-redirect" title="Feld (Datentyp)">Array</a> gespeichert werden.
</p>
<div class="mw-heading mw-heading3"><h3 id="Schlüsselexpansion"><span id="Schl.C3.BCsselexpansion"></span>Schlüsselexpansion</h3></div>

<p>Zunächst müssen aus dem Schlüssel <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle R+1}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>R</mi>
<mo>+</mo>
<mn>1</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle R+1}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/6fdbc7768520d4183c66f1a404a0b3ab651dc14b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.505ex; width:5.767ex; height:2.343ex;" alt="{\displaystyle R+1}" loading="lazy"></span> Teilschlüssel (auch Rundenschlüssel genannt) erzeugt werden, die jeweils die gleiche Größe wie ein Datenblock haben. Somit muss der Benutzerschlüssel auf die Länge <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b\cdot (R+1)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
<mo>⋅<!-- ⋅ --></mo>
<mo stretchy="false">(</mo>
<mi>R</mi>
<mo>+</mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b\cdot (R+1)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/43a9836c1f3f26460d1d3a3ab67d5900c598ad27.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:10.253ex; height:2.843ex;" alt="{\displaystyle b\cdot (R+1)}" loading="lazy"></span> expandiert werden, wobei <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f11423fbb2e967f986e36804a8ae4271734917c3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.998ex; height:2.176ex;" alt="{\displaystyle b}" loading="lazy"></span> die Blockgröße in Bit angibt. Der Schlüssel wird in eine zweidimensionale Tabelle mit vier Zeilen und Zellen der Größe 1 Byte abgebildet. Fasst man jede Spalte als 32-bit-Wort auf, ergibt das ein eindimensionales <a href="Feld_(Datentyp)" class="mw-redirect" title="Feld (Datentyp)">Array</a> mit <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b/32\cdot (R+1)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>32</mn>
<mo>⋅<!-- ⋅ --></mo>
<mo stretchy="false">(</mo>
<mi>R</mi>
<mo>+</mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b/32\cdot (R+1)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/854a0f88af589ba7722d5f87d1695ddcbb4072d0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:13.74ex; height:2.843ex;" alt="{\displaystyle b/32\cdot (R+1)}" loading="lazy"></span> Elementen.
</p><p>Sei <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle N=k/32}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>N</mi>
<mo>=</mo>
<mi>k</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>32</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle N=k/32}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8fc6f9907e80a995e6ea6c8326fd9670c374faee.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:9.861ex; height:2.843ex;" alt="{\displaystyle N=k/32}" loading="lazy"></span> die Länge des Benutzerschlüssels in Wörtern. Dieser wird zunächst in die ersten Wörter <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{0},\cdots ,W_{N-1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>,</mo>
<mo>⋯<!-- ⋯ --></mo>
<mo>,</mo>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>N</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{0},\cdots ,W_{N-1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/09c65831c3a57241e68541ff28184ef114e7b914.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:14.412ex; height:2.509ex;" alt="{\displaystyle W_{0},\cdots ,W_{N-1}}" loading="lazy"></span> des Arrays eingetragen. Dann werden in einer <a href="Iteration" title="Iteration">Iteration</a> die weiteren Wörter <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{i}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{i}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/7301a4cfd04d4f5db4549fdf23746a0d2ce9f387.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:2.993ex; height:2.509ex;" alt="{\displaystyle W_{i}}" loading="lazy"></span> jeweils durch <a href="Bitweiser_Operator#XOR" title="Bitweiser Operator">bitweises XOR</a> von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{i-1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{i-1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/9e761621dd4980708abf259717f50a9607afb9f5.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:5.094ex; height:2.509ex;" alt="{\displaystyle W_{i-1}}" loading="lazy"></span> und <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{i-N}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mi>N</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{i-N}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/901e1c9364011cbac357b7f1b4527ebd975323de.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:5.731ex; height:2.509ex;" alt="{\displaystyle W_{i-N}}" loading="lazy"></span> berechnet. Für jedes <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle N}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>N</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle N}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f5e3890c981ae85503089652feb48b191b57aae3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.064ex; height:2.176ex;" alt="{\displaystyle N}" loading="lazy"></span>-te Wort wird <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{i-1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{i-1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/9e761621dd4980708abf259717f50a9607afb9f5.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:5.094ex; height:2.509ex;" alt="{\displaystyle W_{i-1}}" loading="lazy"></span> zuvor rotiert, byteweise substituiert und mit einer von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle i}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>i</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle i}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/add78d8608ad86e54951b8c8bd6c8d8416533d20.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:0.802ex; height:2.176ex;" alt="{\displaystyle i}" loading="lazy"></span> abhängigen Konstanten verknüpft. Falls <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle N>6}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>N</mi>
<mo>&gt;</mo>
<mn>6</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle N&gt;6}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/3c27ef60d32f88f950cdbfd083a1ad76ac13d20a.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:6.325ex; height:2.176ex;" alt="{\displaystyle N>6}" loading="lazy"></span> ist, wird dazwischen alle <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle N}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>N</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle N}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f5e3890c981ae85503089652feb48b191b57aae3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.064ex; height:2.176ex;" alt="{\displaystyle N}" loading="lazy"></span> Wörter noch eine weitere Substitution ausgeführt.
</p><p>Für <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle i=N,\ldots ,b/32\cdot (R+1)-1}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>i</mi>
<mo>=</mo>
<mi>N</mi>
<mo>,</mo>
<mo>…<!-- … --></mo>
<mo>,</mo>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mn>32</mn>
<mo>⋅<!-- ⋅ --></mo>
<mo stretchy="false">(</mo>
<mi>R</mi>
<mo>+</mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle i=N,\ldots ,b/32\cdot (R+1)-1}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/aadbc4f8b52730fd4579bc31dee4c2b20de6e3bb.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:28.886ex; height:2.843ex;" alt="{\displaystyle i=N,\ldots ,b/32\cdot (R+1)-1}" loading="lazy"></span>:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle W_{i}={\begin{cases}W_{i-N}\oplus \operatorname {S} (W_{i-1}\lll 8)\oplus C_{i/N-1}&amp;{\text{wenn }}i\equiv 0{\pmod {N}}\\W_{i-N}\oplus \operatorname {S} (W_{i-1})&amp;{\text{wenn }}N>6{\text{ und }}i\equiv 4{\pmod {N}}\\W_{i-N}\oplus W_{i-1}&amp;{\text{sonst}}\\\end{cases}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
</mrow>
</msub>
<mo>=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>{</mo>
<mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false">
<mtr>
<mtd>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mi>N</mi>
</mrow>
</msub>
<mo>⊕<!-- ⊕ --></mo>
<mi mathvariant="normal">S</mi>
<mo>⁡<!-- ⁡ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
<mo>⋘<!-- ⋘ --></mo>
<mn>8</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<msub>
<mi>C</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo>/</mo>
</mrow>
<mi>N</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>wenn&nbsp;</mtext>
</mrow>
<mi>i</mi>
<mo>≡<!-- ≡ --></mo>
<mn>0</mn>
<mrow class="MJX-TeXAtom-ORD">
<mspace width="0.444em"></mspace>
<mo stretchy="false">(</mo>
<mi>mod</mi>
<mspace width="0.333em"></mspace>
<mi>N</mi>
<mo stretchy="false">)</mo>
</mrow>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mi>N</mi>
</mrow>
</msub>
<mo>⊕<!-- ⊕ --></mo>
<mi mathvariant="normal">S</mi>
<mo>⁡<!-- ⁡ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
<mo stretchy="false">)</mo>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>wenn&nbsp;</mtext>
</mrow>
<mi>N</mi>
<mo>&gt;</mo>
<mn>6</mn>
<mrow class="MJX-TeXAtom-ORD">
<mtext>&nbsp;und&nbsp;</mtext>
</mrow>
<mi>i</mi>
<mo>≡<!-- ≡ --></mo>
<mn>4</mn>
<mrow class="MJX-TeXAtom-ORD">
<mspace width="0.444em"></mspace>
<mo stretchy="false">(</mo>
<mi>mod</mi>
<mspace width="0.333em"></mspace>
<mi>N</mi>
<mo stretchy="false">)</mo>
</mrow>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mi>N</mi>
</mrow>
</msub>
<mo>⊕<!-- ⊕ --></mo>
<msub>
<mi>W</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>i</mi>
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msub>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>sonst</mtext>
</mrow>
</mtd>
</mtr>
</mtable>
<mo fence="true" stretchy="true" symmetric="true"></mo>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle W_{i}={\begin{cases}W_{i-N}\oplus \operatorname {S} (W_{i-1}\lll 8)\oplus C_{i/N-1}&amp;{\text{wenn }}i\equiv 0{\pmod {N}}\\W_{i-N}\oplus \operatorname {S} (W_{i-1})&amp;{\text{wenn }}N&gt;6{\text{ und }}i\equiv 4{\pmod {N}}\\W_{i-N}\oplus W_{i-1}&amp;{\text{sonst}}\\\end{cases}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/30e2d0fdba047dcbf9f8c2408d601cb49f0fac29.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -3.838ex; width:75.993ex; height:8.843ex;" alt="{\displaystyle W_{i}={\begin{cases}W_{i-N}\oplus \operatorname {S} (W_{i-1}\lll 8)\oplus C_{i/N-1}&amp;{\text{wenn }}i\equiv 0{\pmod {N}}\\W_{i-N}\oplus \operatorname {S} (W_{i-1})&amp;{\text{wenn }}N>6{\text{ und }}i\equiv 4{\pmod {N}}\\W_{i-N}\oplus W_{i-1}&amp;{\text{sonst}}\\\end{cases}}}" loading="lazy"></span></dd></dl>
<p><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {S} (x)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi mathvariant="normal">S</mi>
<mo>⁡<!-- ⁡ --></mo>
<mo stretchy="false">(</mo>
<mi>x</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {S} (x)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/faddb38cd3818df16e8e470958a159760256e8d4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:4.431ex; height:2.843ex;" alt="{\displaystyle \operatorname {S} (x)}" loading="lazy"></span> bezeichnet die Substitution jedes Bytes in <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/87f9e315fd7e2ba406057a97300593c4802b53e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\displaystyle x}" loading="lazy"></span> durch die gleiche S-Box, die auch beim Verschlüsseln eines Datenblocks eingesetzt wird. <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x\lll 8}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
<mo>⋘<!-- ⋘ --></mo>
<mn>8</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x\lll 8}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/dfb32c586e5a2cd8f352590f5ae7546c80183a70.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:6.88ex; height:2.176ex;" alt="{\displaystyle x\lll 8}" loading="lazy"></span> ist die <a href="Bitweiser_Operator#Zyklische_Verschiebung" title="Bitweiser Operator">Rotation</a> von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/87f9e315fd7e2ba406057a97300593c4802b53e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\displaystyle x}" loading="lazy"></span> um 8 Bitpositionen nach links. Die Konstanten <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle C_{j}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>C</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>j</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle C_{j}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/4598eb9b4e1c079e0973de79383fc6f898744e18.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:2.572ex; height:2.843ex;" alt="{\displaystyle C_{j}}" loading="lazy"></span> werden gebildet, indem <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2^{j}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mi>j</mi>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2^{j}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/d333722497d28dd4f7d38c2c2e4b4dbac3cb2abe.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.072ex; height:2.676ex;" alt="{\displaystyle 2^{j}}" loading="lazy"></span>, berechnet im Körper <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \mathbb {F} _{2^{8}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mrow class="MJX-TeXAtom-ORD">
<mi mathvariant="double-struck">F</mi>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>8</mn>
</mrow>
</msup>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \mathbb {F} _{2^{8}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a294571cba95908afeea64b9c0528f082721dfae.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:3.306ex; height:2.843ex;" alt="{\displaystyle \mathbb {F} _{2^{8}}}" loading="lazy"></span>, in das höchste Byte von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle C_{j}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>C</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>j</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle C_{j}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/4598eb9b4e1c079e0973de79383fc6f898744e18.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:2.572ex; height:2.843ex;" alt="{\displaystyle C_{j}}" loading="lazy"></span> eingetragen wird, während die übrigen Bytes 0 sind.
</p>
<div class="mw-heading mw-heading3"><h3 id="AddRoundKey">AddRoundKey</h3></div>

<p>Vor der ersten und nach jeder Verschlüsselungsrunde wird der Datenblock mit einem der Rundenschlüssel XOR-verknüpft. Dies ist die einzige Funktion in AES, in die der Benutzerschlüssel eingeht.
</p>
<div class="mw-heading mw-heading3"><h3 id="SubBytes">SubBytes</h3></div>
<p>Im ersten Schritt jeder Runde wird jedes Byte <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle B}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>B</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle B}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/47136aad860d145f75f3eed3022df827cee94d7a.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.764ex; height:2.176ex;" alt="{\displaystyle B}" loading="lazy"></span> im Block durch den Eintrag <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle S(B)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>S</mi>
<mo stretchy="false">(</mo>
<mi>B</mi>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle S(B)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/bc20d6c8e443fb2a2e32a85a4b4fdd0702ee7c74.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:5.073ex; height:2.843ex;" alt="{\displaystyle S(B)}" loading="lazy"></span> der S-Box ersetzt. Somit werden die Daten byteweise <a href="Monoalphabetische_Substitution" title="Monoalphabetische Substitution">monoalphabetisch</a> verschlüsselt.
</p>
<div class="mw-heading mw-heading3"><h3 id="ShiftRows">ShiftRows</h3></div>

<p>Wie oben erwähnt, liegt ein Block in Form einer zweidimensionalen Tabelle mit vier Zeilen vor. In diesem zweiten Schritt jeder Runde werden die Zeilen um eine bestimmte Anzahl von Spalten nach links verschoben. Überlaufende Zellen werden von rechts fortgesetzt. Die Anzahl der Verschiebungen ist zeilen- und blocklängenabhängig:
</p>
<table class="wikitable" style="text-align:center;">

<tbody><tr class="hintergrundfarbe6">
<th><i>r</i>
</th>
<th><i>b</i>=128
</th>
<th><i>b</i>=160
</th>
<th><i>b</i>=192
</th>
<th><i>b</i>=224
</th>
<th><i>b</i>=256
</th></tr>
<tr>
<th class="hintergrundfarbe6">Zeile 1
</th>
<td><b>0</b>
</td>
<td>0
</td>
<td>0
</td>
<td>0
</td>
<td>0
</td></tr>
<tr>
<th class="hintergrundfarbe6">Zeile 2
</th>
<td><b>1</b>
</td>
<td>1
</td>
<td>1
</td>
<td>1
</td>
<td>1
</td></tr>
<tr>
<th class="hintergrundfarbe6">Zeile 3
</th>
<td><b>2</b>
</td>
<td>2
</td>
<td>2
</td>
<td>2
</td>
<td>3
</td></tr>
<tr>
<th class="hintergrundfarbe6">Zeile 4
</th>
<td><b>3</b>
</td>
<td>3
</td>
<td>3
</td>
<td>4
</td>
<td>4
</td></tr></tbody></table>
<p>Je nach Blocklänge <i>b</i> und Zeile in der Datentabelle wird die Zeile um 1 bis 4 Spalten verschoben.<br>Für den AES sind nur die fett markierten Werte relevant.
</p>
<div class="mw-heading mw-heading3"><h3 id="MixColumns">MixColumns</h3></div>
<div class="hauptartikel" role="navigation"><span class="hauptartikel-pfeil" title="siehe" aria-hidden="true" role="presentation">→&nbsp;</span><i><span class="hauptartikel-text">Hauptartikel</span>: <a href="Rijndael_MixColumns" title="Rijndael MixColumns">Rijndael MixColumns</a></i></div>

<p>Als dritte Operation jeder Runde außer der Schlussrunde werden die Daten innerhalb der Spalten vermischt. Zur Berechnung eines Bytes <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b_{j}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>j</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b_{j}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/fa56eff4488494085785b7b0d6e2069bd45a3ce5.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:1.907ex; height:2.843ex;" alt="{\displaystyle b_{j}}" loading="lazy"></span> der neuen Spalte wird jedes Byte <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle a_{j}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>j</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle a_{j}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/d0096fb78d6843c9fb67a840dc796b61ad93eec2.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:2.14ex; height:2.343ex;" alt="{\displaystyle a_{j}}" loading="lazy"></span> der alten mit einer Konstanten (1, 2 oder 3) multipliziert. Dies geschieht modulo des <a href="Irreduzibles_Polynom" title="Irreduzibles Polynom">irreduziblen Polynoms</a> <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x^{8}+x^{4}+x^{3}+x+1}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>8</mn>
</mrow>
</msup>
<mo>+</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>4</mn>
</mrow>
</msup>
<mo>+</mo>
<msup>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msup>
<mo>+</mo>
<mi>x</mi>
<mo>+</mo>
<mn>1</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x^{8}+x^{4}+x^{3}+x+1}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/657ccba0967614d3c63fdb74a86c5eff0b85a2c7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.505ex; width:21.005ex; height:2.843ex;" alt="{\displaystyle x^{8}+x^{4}+x^{3}+x+1}" loading="lazy"></span> im <a href="Galois-K%C3%B6rper" class="mw-redirect" title="Galois-Körper">Galois-Körper</a> <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle GF(2^{8})}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>G</mi>
<mi>F</mi>
<mo stretchy="false">(</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>8</mn>
</mrow>
</msup>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle GF(2^{8})}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/249fe8b7753a547eb2437f80d47848678c96d1a5.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:7.593ex; height:3.176ex;" alt="{\displaystyle GF(2^{8})}" loading="lazy"></span>. Dann werden die Ergebnisse <a href="Kontravalenz" title="Kontravalenz">XOR</a>-verknüpft:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b_{0}=(a_{0}\cdot 2)\oplus (a_{1}\cdot 3)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 1)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>=</mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>3</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b_{0}=(a_{0}\cdot 2)\oplus (a_{1}\cdot 3)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 1)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/9c05b23efab9e3c8b97f23032b387b046e36a2f9.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:41.411ex; height:2.843ex;" alt="{\displaystyle b_{0}=(a_{0}\cdot 2)\oplus (a_{1}\cdot 3)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 1)}" loading="lazy"></span></dd>
<dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b_{1}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 2)\oplus (a_{2}\cdot 3)\oplus (a_{3}\cdot 1)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>=</mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>3</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b_{1}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 2)\oplus (a_{2}\cdot 3)\oplus (a_{3}\cdot 1)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a384b87c359923560474b78e858eff222ede6327.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:41.411ex; height:2.843ex;" alt="{\displaystyle b_{1}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 2)\oplus (a_{2}\cdot 3)\oplus (a_{3}\cdot 1)}" loading="lazy"></span></dd>
<dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b_{2}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 2)\oplus (a_{3}\cdot 3)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>=</mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>3</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b_{2}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 2)\oplus (a_{3}\cdot 3)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/c6bab7472927af59d09e5dfe6ead53f8dff501a7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:41.411ex; height:2.843ex;" alt="{\displaystyle b_{2}=(a_{0}\cdot 1)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 2)\oplus (a_{3}\cdot 3)}" loading="lazy"></span></dd>
<dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle b_{3}=(a_{0}\cdot 3)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 2)}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>=</mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>3</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle b_{3}=(a_{0}\cdot 3)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 2)}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/5cc6e5dae38c837826eb87b54dfd72b73231b0a7.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:41.411ex; height:2.843ex;" alt="{\displaystyle b_{3}=(a_{0}\cdot 3)\oplus (a_{1}\cdot 1)\oplus (a_{2}\cdot 1)\oplus (a_{3}\cdot 2)}" loading="lazy"></span></dd></dl>
<p>In Matrixschreibweise:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\begin{pmatrix}b_{0}\\b_{1}\\b_{2}\\b_{3}\end{pmatrix}}={\begin{pmatrix}2&amp;3&amp;1&amp;1\\1&amp;2&amp;3&amp;1\\1&amp;1&amp;2&amp;3\\3&amp;1&amp;1&amp;2\end{pmatrix}}{\begin{pmatrix}a_{0}\\a_{1}\\a_{2}\\a_{3}\end{pmatrix}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>(</mo>
<mtable rowspacing="4pt" columnspacing="1em">
<mtr>
<mtd>
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>b</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mtd>
</mtr>
</mtable>
<mo>)</mo>
</mrow>
</mrow>
<mo>=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>(</mo>
<mtable rowspacing="4pt" columnspacing="1em">
<mtr>
<mtd>
<mn>2</mn>
</mtd>
<mtd>
<mn>3</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
</mtr>
<mtr>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>2</mn>
</mtd>
<mtd>
<mn>3</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
</mtr>
<mtr>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>2</mn>
</mtd>
<mtd>
<mn>3</mn>
</mtd>
</mtr>
<mtr>
<mtd>
<mn>3</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>1</mn>
</mtd>
<mtd>
<mn>2</mn>
</mtd>
</mtr>
</mtable>
<mo>)</mo>
</mrow>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>(</mo>
<mtable rowspacing="4pt" columnspacing="1em">
<mtr>
<mtd>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>0</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mtd>
</mtr>
<mtr>
<mtd>
<msub>
<mi>a</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mtd>
</mtr>
</mtable>
<mo>)</mo>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\begin{pmatrix}b_{0}\\b_{1}\\b_{2}\\b_{3}\end{pmatrix}}={\begin{pmatrix}2&amp;3&amp;1&amp;1\\1&amp;2&amp;3&amp;1\\1&amp;1&amp;2&amp;3\\3&amp;1&amp;1&amp;2\end{pmatrix}}{\begin{pmatrix}a_{0}\\a_{1}\\a_{2}\\a_{3}\end{pmatrix}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/b3a8536a588363245f9f0a7a52078e2a25efa3e9.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -5.671ex; width:33.507ex; height:12.509ex;" alt="{\displaystyle {\begin{pmatrix}b_{0}\\b_{1}\\b_{2}\\b_{3}\end{pmatrix}}={\begin{pmatrix}2&amp;3&amp;1&amp;1\\1&amp;2&amp;3&amp;1\\1&amp;1&amp;2&amp;3\\3&amp;1&amp;1&amp;2\end{pmatrix}}{\begin{pmatrix}a_{0}\\a_{1}\\a_{2}\\a_{3}\end{pmatrix}}}" loading="lazy"></span></dd></dl>
<p>Nach den Rechengesetzen in diesem Galois-Körper gilt für die Multiplikation:
</p>
<ul><li><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle a\cdot 1=a}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mn>1</mn>
<mo>=</mo>
<mi>a</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle a\cdot 1=a}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f3e5c8aeb598f9dadf4767a03328e05849f37035.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:8.4ex; height:2.176ex;" alt="{\displaystyle a\cdot 1=a}" loading="lazy"></span></li>
<li><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle a\cdot 2={\begin{cases}2a&amp;{\text{wenn }}a<2^{7}\\2a\oplus (11{\text{b}})_{\text{hex}}&amp;{\text{wenn }}a\geq 2^{7}\end{cases}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo>=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mrow>
<mo>{</mo>
<mtable columnalign="left left" rowspacing=".2em" columnspacing="1em" displaystyle="false">
<mtr>
<mtd>
<mn>2</mn>
<mi>a</mi>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>wenn&nbsp;</mtext>
</mrow>
<mi>a</mi>
<mo>&lt;</mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>7</mn>
</mrow>
</msup>
</mtd>
</mtr>
<mtr>
<mtd>
<mn>2</mn>
<mi>a</mi>
<mo>⊕<!-- ⊕ --></mo>
<mo stretchy="false">(</mo>
<mn>11</mn>
<mrow class="MJX-TeXAtom-ORD">
<mtext>b</mtext>
</mrow>
<msub>
<mo stretchy="false">)</mo>
<mrow class="MJX-TeXAtom-ORD">
<mtext>hex</mtext>
</mrow>
</msub>
</mtd>
<mtd>
<mrow class="MJX-TeXAtom-ORD">
<mtext>wenn&nbsp;</mtext>
</mrow>
<mi>a</mi>
<mo>≥<!-- ≥ --></mo>
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>7</mn>
</mrow>
</msup>
</mtd>
</mtr>
</mtable>
<mo fence="true" stretchy="true" symmetric="true"></mo>
</mrow>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle a\cdot 2={\begin{cases}2a&amp;{\text{wenn }}a&lt;2^{7}\\2a\oplus (11{\text{b}})_{\text{hex}}&amp;{\text{wenn }}a\geq 2^{7}\end{cases}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/ff3e0880e63aa090bc6e12bf6a0beff538d8a16c.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -2.505ex; width:37.812ex; height:6.176ex;" alt="{\displaystyle a\cdot 2={\begin{cases}2a&amp;{\text{wenn }}a<2^{7}\\2a\oplus (11{\text{b}})_{\text{hex}}&amp;{\text{wenn }}a\geq 2^{7}\end{cases}}}" loading="lazy"></span></li>
<li><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle a\cdot 3=(a\cdot 2)\oplus a}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mn>3</mn>
<mo>=</mo>
<mo stretchy="false">(</mo>
<mi>a</mi>
<mo>⋅<!-- ⋅ --></mo>
<mn>2</mn>
<mo stretchy="false">)</mo>
<mo>⊕<!-- ⊕ --></mo>
<mi>a</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle a\cdot 3=(a\cdot 2)\oplus a}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/7447bb56e3b485b776536bcff8b0aa71b194832f.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:17.121ex; height:2.843ex;" alt="{\displaystyle a\cdot 3=(a\cdot 2)\oplus a}" loading="lazy"></span></li></ul>
<p>Dabei bezeichnet <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2a}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mn>2</mn>
<mi>a</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2a}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/d325c24be7d760207674a169b078892bdd5cbc76.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.392ex; height:2.176ex;" alt="{\displaystyle 2a}" loading="lazy"></span> die normale Multiplikation von <i>a</i> mit 2 und <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \oplus }">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo>⊕<!-- ⊕ --></mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \oplus }</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8b16e2bdaefee9eed86d866e6eba3ac47c710f60.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.505ex; width:1.808ex; height:2.176ex;" alt="{\displaystyle \oplus }" loading="lazy"></span> die bitweise XOR-Verknüpfung.
</p>
<div class="mw-heading mw-heading3"><h3 id="Entschlüsselung"><span id="Entschl.C3.BCsselung"></span>Entschlüsselung</h3></div>
<p>Bei der <a href="Entschl%C3%BCsselung#Entschlüsselung_in_der_Kryptologie" title="Entschlüsselung">Entschlüsselung</a> von Daten wird genau rückwärts vorgegangen. Die Daten werden zunächst wieder in zweidimensionale Tabellen gelesen und die Rundenschlüssel generiert. Allerdings wird nun mit der Schlussrunde angefangen und alle Funktionen in jeder Runde in der umgekehrten Reihenfolge aufgerufen. Durch die vielen <a href="Kontravalenz" title="Kontravalenz">XOR-Verknüpfungen</a> unterscheiden sich die meisten Funktionen zum Entschlüsseln nicht von denen zum Verschlüsseln. Jedoch muss eine andere S-Box genutzt werden (die sich aus der originalen S-Box berechnen lässt) und die Zeilenverschiebungen erfolgen in die andere Richtung.
</p>
<div class="mw-heading mw-heading2"><h2 id="Anwendung">Anwendung</h2></div>
<p>AES wird u.&nbsp;a. vom Verschlüsselungsstandard <a href="IEEE_802.11i" title="IEEE 802.11i">IEEE 802.11i</a> für <a href="Wireless_Local_Area_Network" title="Wireless Local Area Network">Wireless LAN</a> und seinem <a href="Wi-Fi" title="Wi-Fi">Wi-Fi</a>-Äquivalent <a href="WPA2" title="WPA2">WPA2</a>, bei IEEE 802.16&nbsp;m (<a href="WiMAX" title="WiMAX">WiMAX</a>), für <a href="Powerline_Communication" title="Powerline Communication">Powerline-Netzwerkverkehr</a> ab der Version <a href="HomePlug_AV" title="HomePlug AV">HomePlug AV</a> sowie bei <a href="Secure_Shell" title="Secure Shell">SSH</a> und bei <a href="IPsec" title="IPsec">IPsec</a> genutzt. Auch in der <a href="IP-Telefonie" title="IP-Telefonie">IP-Telefonie</a> kommt AES sowohl in offenen Protokollen wie <a href="Secure_Real-Time_Transport_Protocol" title="Secure Real-Time Transport Protocol">SRTP</a> als auch proprietären Systemen wie <a href="Skype" title="Skype">Skype</a><sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> zum Einsatz. Mac OS X benutzt AES als Standardverschlüsselungsmethode für Disk-Images, außerdem verwendet der Dienst <i><a href="FileVault" title="FileVault">FileVault</a></i> AES. Ebenso verwendet die transparente Verschlüsselung <a href="Encrypting_File_System" title="Encrypting File System">EFS</a> in Windows XP ab SP 1 diese Methode. Zudem wird der Algorithmus zur Verschlüsselung diverser komprimierter Dateiarchive verwendet, z.&nbsp;B. bei <a href="7-Zip" title="7-Zip">7-Zip</a> und <a href="RAR_(Dateiformat)" title="RAR (Dateiformat)">RAR</a>. In <a href="Pretty_Good_Privacy" title="Pretty Good Privacy">PGP</a> und <a href="GNU_Privacy_Guard" title="GNU Privacy Guard">GnuPG</a> findet AES ebenfalls einen großen Anwendungsbereich. Der <a href="Linear_Tape_Open" title="Linear Tape Open">Linear Tape Open</a> Standard spezifiziert eine Schnittstelle für AES-Verschlüsselung durch das Bandlaufwerk ab LTO-4 und ermöglicht so Bandkompression bei gleichzeitiger Verschlüsselung.
</p><p>AES gehört zu den vom Projekt <a href="NESSIE" title="NESSIE">NESSIE</a> empfohlenen kryptografischen Algorithmen und ist Teil der <a href="NSA_Suite_B_Cryptography" title="NSA Suite B Cryptography">Suite B</a> der NSA.
</p><p>Der AES-Algorithmus wird inzwischen in etlichen CPUs von Intel oder AMD durch die Befehlssatzerweiterung <a href="AES-NI" title="AES-NI">AES-NI</a> unterstützt, wodurch das Verschlüsseln 5-mal und das Entschlüsseln 25-mal schneller als mit nicht spezialisierten Maschinenbefehlen erfolgt.<sup id="cite_ref-6" class="reference"><a href="#cite_note-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Damit ist AES auch für mobile Anwendungen Akku-schonend benutzbar und für den Masseneinsatz geeignet. Programmier-Softwarebibliotheken wie zum Beispiel <a href="OpenSSL" title="OpenSSL">OpenSSL</a> erkennen und nutzen die Hardware-AES-Implementierung und greifen nur wenn nötig auf langsamere Softwareimplementierung zurück.
</p><p>AES-verschlüsselte Kommunikation wird auch zur Verschlüsselung der Datenübertragung zwischen elektronischen Identitätsdokumenten und Inspektionsgeräten verwendet, zum Beispiel bei neueren Reisepässen oder dem Deutschen <a href="Personalausweis_(Deutschland)" title="Personalausweis (Deutschland)">Personalausweis</a>. So wird das Abhören dieser Kommunikation verhindert. Hier erfolgt die Berechnung meist in dedizierten Koprozessoren für DES und AES, sowohl erheblich schneller als auch sicherer als in einer Allzweck-CPU möglich.
</p><p>Da AES eine Blockverschlüsselung ist, sollte ein <a href="Betriebsmodus_(Kryptographie)" title="Betriebsmodus (Kryptographie)">Betriebsmodus</a> verwendet werden um die Blöcke zu verketten. Dadurch wird die Sicherheit weiter erhöht.
</p>
<div class="mw-heading mw-heading2"><h2 id="Schwächen_und_Angriffe"><span id="Schw.C3.A4chen_und_Angriffe"></span>Schwächen und Angriffe</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Kritikpunkte">Kritikpunkte</h3></div>
<p>Rijndael überzeugte im AES-Wettbewerb durch seine mathematisch elegante und einfache Struktur sowie durch seine Effizienz. Allerdings sahen manche Kryptographen gerade darin ein Problem:
</p>
<ul><li>Die S-Boxen lassen sich algebraisch einfach beschreiben, und sie sind die einzige nichtlineare Komponente der Chiffre. Dadurch lässt sich der gesamte Algorithmus als Gleichungssystem beschreiben.<sup id="cite_ref-ferguson_7-0" class="reference"><a href="#cite_note-ferguson-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup></li>
<li>Durch die einfache Schlüsseleinteilung würden mit einem beliebigen Rundenschlüssel auch 128 Bit des Verfahrensschlüssels <a href="Kompromittierung_(Kryptologie)" title="Kompromittierung (Kryptologie)">kompromittiert</a>.</li></ul>
<p>Ein weiterer Kritikpunkt war die relativ geringe Sicherheitsmarge, die nach damaligem Stand der Analyse nur drei (bei 128 Bit Schlüssellänge) bis fünf Runden (bei 256 Bit Schlüssellänge) betrug.<sup id="cite_ref-ferguson_7-1" class="reference"><a href="#cite_note-ferguson-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Biclique-Angriff">Biclique-Angriff</h3></div>
<p>Auf der Rump-Session der Konferenz CRYPTO im August 2011 stellten die Kryptologen Andrey Bogdanov, Dmitry Khovratovich und Christian Rechberger den ersten Angriff auf den vollen AES-Algorithmus vor.<sup id="cite_ref-biclique_2-1" class="reference"><a href="#cite_note-biclique-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup> Dieser Angriff ist bei den verschiedenen Schlüssellängen im Schnitt etwa um den Faktor 4 schneller als ein <a href="Brute-Force-Methode" title="Brute-Force-Methode">vollständiges Durchsuchen</a> des <a href="Schl%C3%BCsselraum_(Kryptologie)" title="Schlüsselraum (Kryptologie)">Schlüsselraumes</a>. Damit zeigt er die prinzipielle Angreifbarkeit von AES, ist aber für die praktische Sicherheit nicht relevant. Der Angriff berechnet den geheimen Schlüssel von AES-128 in 2<sup>126,1</sup> Schritten. Bei AES-192 werden 2<sup>189,7</sup> Schritte, bei AES-256 2<sup>254,4</sup> Schritte benötigt.
</p>
<div class="mw-heading mw-heading3"><h3 id="XSL-Angriff">XSL-Angriff</h3></div>
<p>2002 wurde von Courtois und Pieprzyk ein theoretischer Angriff namens XSL (für eXtended Sparse Linearization) gegen Serpent und Rijndael vorgestellt (siehe <a href="Serpent_(Verschl%C3%BCsselung)#Angriff" title="Serpent (Verschlüsselung)">Serpent</a>). Mit dem XSL-Angriff ist nach Angabe der Autoren eine <a href="Komplexit%C3%A4t_(Informatik)" title="Komplexität (Informatik)">Komplexität</a> im Bereich von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 2^{100}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msup>
<mn>2</mn>
<mrow class="MJX-TeXAtom-ORD">
<mn>100</mn>
</mrow>
</msup>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 2^{100}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8ccbe1f7fda633830ccc9c2dc0d4685b1cf3833e.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:3.861ex; height:2.676ex;" alt="{\displaystyle 2^{100}}" loading="lazy"></span> Operationen erreichbar. XSL ist die Weiterentwicklung einer heuristischen Technik namens XL (für eXtended Linearization), mit der es manchmal gelingt, große nichtlineare Gleichungssysteme effizient zu lösen. XL wurde ursprünglich zur Analyse von Public-Key-Verfahren entwickelt. Der Einsatz im Kontext von symmetrischen Kryptosystemen ist eine Innovation von Courtois und Pieprzyk. Grob kann die Technik und ihre Anwendung auf symmetrische Kryptosysteme wie folgt beschrieben werden:
</p><p>Die Blockchiffre wird als überspezifiziertes System quadratischer Gleichungen in GF(2) beschrieben. Überspezifiziert bedeutet, dass es mehr Gleichungen als Variablen gibt. Variablen und Konstanten können nur die Werte 0 und 1 annehmen. Die Addition entspricht dem logischen eXklusiv-OdeR (XOR), die Multiplikation dem logischen UND. Eine solche Gleichung könnte wie folgt aussehen:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x_{1}+x_{2}\cdot x_{3}+x_{2}\cdot x_{4}\equiv 1\mod 2}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>+</mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo>+</mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>4</mn>
</mrow>
</msub>
<mo>≡<!-- ≡ --></mo>
<mn>1</mn>
<mspace width="1em"></mspace>
<mi>mod</mi>
<mspace width="thinmathspace"></mspace>
<mspace width="thinmathspace"></mspace>
<mn>2</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x_{1}+x_{2}\cdot x_{3}+x_{2}\cdot x_{4}\equiv 1\mod 2}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/0fe8431e536ee6fffd851244a95d186d795527c8.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:34.644ex; height:2.509ex;" alt="{\displaystyle x_{1}+x_{2}\cdot x_{3}+x_{2}\cdot x_{4}\equiv 1\mod 2}" loading="lazy"></span></dd></dl>
<p>Diese Gleichung besteht aus einem linearen Term (der Variablen <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x_{1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x_{1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/a8788bf85d532fa88d1fb25eff6ae382a601c308.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:2.384ex; height:2.009ex;" alt="{\displaystyle x_{1}}" loading="lazy"></span>), zwei quadratischen Termen (<span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x_{2}\cdot x_{3}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x_{2}\cdot x_{3}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/88a18ac9a1d9d29443e4a3cba032924d81330245.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:6.447ex; height:2.009ex;" alt="{\displaystyle x_{2}\cdot x_{3}}" loading="lazy"></span> und <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x_{2}\cdot x_{4}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>⋅<!-- ⋅ --></mo>
<msub>
<mi>x</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>4</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x_{2}\cdot x_{4}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/256d75ddbb6742cbfe80b1609bf30a813a7fcb40.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:6.447ex; height:2.009ex;" alt="{\displaystyle x_{2}\cdot x_{4}}" loading="lazy"></span>) und einem konstanten Term (<span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle 1}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mn>1</mn>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle 1}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/92d98b82a3778f043108d4e20960a9193df57cbf.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.162ex; height:2.176ex;" alt="{\displaystyle 1}" loading="lazy"></span>).
</p><p>Einige Wissenschaftler zweifeln die Korrektheit der Abschätzungen von Courtois und Pieprzyk an:
</p>
<div class="Vorlage_Zitat" style="margin:1em 40px;">
<div style="margin:1em 0;"><blockquote lang="en" style="margin:0;">
<p>“I believe that the Courtois-Pieprzyk work is flawed. They overcount the number of linearly independent equations. The result is that they do not in fact have enough linear equations to solve the system, and the method does not break Rijndael … The method has some merit, and is worth investigating, but it does not break Rijndael as it stands.”
</p>
</blockquote>
<blockquote style="margin:.5em 0 0 0;" lang="de-Latn">
<p>„Ich glaube, dass die Arbeit von Courtois und Pieprzyk fehlerhaft ist; sie schätzen die Anzahl der linear unabhängigen Gleichungen zu hoch ein. Das Resultat ist, dass sie in Wirklichkeit nicht genug lineare Gleichungen erhalten, um das System zu lösen, und die Methode somit Rijndael nicht bricht […] Die Methode besitzt ihre Vorzüge und ist es wert, weiter untersucht zu werden, allerdings bricht sie in ihrer aktuellen Form Rijndael nicht.“
</p>
</blockquote></div><div class="cite" style="margin:-1em 0 1em 1em;">– <style data-mw-deduplicate="TemplateStyles:r261921330">
/* start https://de.wikipedia.org/ */


.mw-parser-output .Person{font-variant:small-caps}


/* end https://de.wikipedia.org/ */
</style><span class="Person h-card"><a href="Don_Coppersmith" title="Don Coppersmith">Don Coppersmith</a></span><sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup></div></div>
<p>Diese Art von System kann typischerweise sehr groß werden, im Falle der 128-Bit-AES-Variante wächst es auf 8000 quadratische Gleichungen mit 1600 Variablen an, womit der XSL-Angriff in der Praxis nicht anwendbar ist.
Das Lösen von Systemen quadratischer Gleichungen ist ein <a href="NP-Schwere" title="NP-Schwere">NP-schweres</a> Problem mit verschiedenen Anwendungsfeldern in der Kryptographie.
</p>
<div class="mw-heading mw-heading3"><h3 id="Weitere_Angriffe">Weitere Angriffe</h3></div>
<p>Kurz vor der Bekanntgabe des AES-Wettbewerbs stellten verschiedene Autoren eine einfache algebraische Darstellung von AES als <a href="Kettenbruch" title="Kettenbruch">Kettenbruch</a> vor. Dies könnte für erfolgreiche Angriffe genutzt werden. Hierzu gibt es einen Videovortrag von <a href="Niels_Ferguson" title="Niels Ferguson">Niels Ferguson</a> auf der HAL 2001.<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>
</p><p>Im Jahr 2003 entdeckten Sean Murphy und Matt Robshaw eine alternative Beschreibung des AES, indem sie diesen in eine Blockchiffre namens BES einbetteten, welche anstatt auf Datenbits auf Datenblöcken von 128 Bytes arbeitet. Die Anwendung des XSL-Algorithmus auf BES reduziert dessen Komplexität auf 2<sup>100</sup>, wenn die Kryptoanalyse von Courtois und Pieprzyk korrekt ist.
</p><p>Im Mai 2005 veröffentlichte <a href="Daniel_J._Bernstein" title="Daniel J. Bernstein">Daniel Bernstein</a> einen Artikel über eine unerwartet einfache <a href="Seitenkanalattacke#Rechenzeitangriff_(Timing_Attack)" title="Seitenkanalattacke">Timing-Attacke</a><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> (eine Art der <a href="Seitenkanalattacke" title="Seitenkanalattacke">Seitenkanalattacke</a>) auf den Advanced Encryption Standard.
</p><p>Die Forscher Alex Biryukov und Dmitry Khovratovich veröffentlichten Mitte des Jahres 2009 einen Angriff mit verwandtem Schlüssel<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup> auf die AES-Varianten mit 192 und 256 Bit Schlüssellänge. Dabei nutzten sie Schwächen in der Schlüsselexpansion aus und konnten eine Komplexität von 2<sup>119</sup> erreichen. Damit ist die AES-Variante mit 256 Bit Schlüssellänge formal schwächer als die Variante mit 128 Bit Schlüssellänge.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> Ende 2009 wurde mit einer Verbesserung des Angriffs eine Komplexität von nur noch 2<sup>99,5</sup> erreicht.<sup id="cite_ref-BK09_13-0" class="reference"><a href="#cite_note-BK09-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> Für die Praxis hat dieser Angriff jedoch wenig Relevanz, denn AES bleibt weiterhin praktisch berechnungssicher.<sup id="cite_ref-BK09_13-1" class="reference"><a href="#cite_note-BK09-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p><p>Im März 2012 wurde bekannt, dass die NSA in ihrem neuen <a href="Utah_Data_Center" title="Utah Data Center">Utah Data Center</a> neben dem Speichern großer Teile der gesamten Internetkommunikation auch mit enormen Rechenressourcen am Brechen von AES arbeitet.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup> Die Eröffnung des Rechenzentrums läuft schrittweise seit September 2013.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p><p>Craig Ramsay &amp; Jasper Lohuis, als Forscherteam der beiden Unternehmen Fox-IT und Riscure, beschreiben 2017 einen Angriff, bei dem sie die von der CPU abgestrahlten Funksignale zur Entschlüsselung verwenden.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Damit ließe sich der AES-Schlüssel in maximal fünf Minuten ermitteln, wenn Sniffer und angegriffene CPU etwa 1 Meter entfernt voneinander stehen. Bei 30 Zentimeter Distanz schrumpfe die Zeit auf etwa 50 Sekunden.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> Man muss aber beachten, dass dies ein Angriff auf eine einzelne Implementierung des Algorithmus auf einer bestimmten CPU ist, nicht auf den Algorithmus an sich. Ein solcher Angriff ist nur unter sehr speziellen Bedingungen durchführbar und kann nicht unbedingt verallgemeinert werden.
</p>
<div class="mw-heading mw-heading2"><h2 id="Literatur">Literatur</h2></div>
<ul><li><a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a>, <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a>: <i>The Design of Rijndael. AES: The Advanced Encryption Standard</i>. Springer, Berlin u.&nbsp;a. 2020, ISBN 978-3-662-60769-5<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup> (<i>Information Security and Cryptography</i>), (englisch).</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Weblinks">Weblinks</h2></div>
<ul><li>Offizielle Spezifikation des AES vom NIST, <a href="https://doi.org/10.6028/NIST.FIPS.197" class="extiw external" title="doi:10.6028/NIST.FIPS.197">doi:10.6028/NIST.FIPS.197</a></li>
<li><a rel="nofollow" class="external text" href="https://repges.net/AES-Kandidaten/aes-kandidaten.html">Beschreibung der AES-Kandidaten (Finalisten) von Markus Repges</a></li>
<li><a rel="nofollow" class="external text" href="https://csrc.nist.gov/projects/cryptographic-standards-and-guidelines/archived-crypto-projects/aes-development">NIST, Report on the Development of the Advanced Encryption Standard (AES), 2. Oktober 2000</a> (PDF; 383&nbsp;kB)</li>
<li><a rel="nofollow" class="external text" href="https://formaestudio.com/rijndaelinspector/archivos/Rijndael_Animation_v4_eng.swf">Animation von AES in Englisch</a> – AES mit Flash erklärt und animiert (Flash-Animation by Enrique Zabala / Universität ORT / Montevideo / Uruguay). Verfügbar auch in Deutsch als <a rel="nofollow" class="external text" href="https://www.formaestudio.com/rijndaelinspector/archivos/Rijndael_Animation_v4_ger.zip">ZIP-Datei</a>. Diese Animation ist (in Deutsch, Englisch und Spanisch) auch Teil von <a href="CrypTool" title="CrypTool">CrypTool 1</a>, Menü Einzelverfahren -&gt; Visualisierung von Algorithmen -&gt; AES.</li>
<li><a rel="nofollow" class="external text" href="https://codeplanet.eu/tutorials/cpp/51-advanced-encryption-standard.html">AES Artikel</a> – Sehr detaillierte deutsche Erklärung des AES mitsamt Rechenbeispielen und Implementierung in der Programmiersprache C</li>
<li>codeproject.com: <style data-mw-deduplicate="TemplateStyles:r261891140">
/* start https://de.wikipedia.org/ */


.mw-parser-output .webarchiv-memento a{color:inherit}


/* end https://de.wikipedia.org/ */
</style><a rel="nofollow" class="external text" href="https://web.archive.org/web/20161204100516/https://www.codeproject.com/KB/security/BlockCiphers.aspx">Encrypt Data using Symmetric Encryption with Crypto++</a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> vom 4. Dezember 2016 im <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>)</li>
<li><a href="Tim_Wambach" title="Tim Wambach">Tim Wambach</a>: <a rel="nofollow" class="external text" href="https://infsec.de/aes-in-excel/">AES Demo in Excel</a> Implementierung und Demonstration der Verarbeitungsschritte in Excel.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Einzelnachweise">Einzelnachweise</h2></div>
<ol class="references">
<li id="cite_note-blocksize-1"><span class="mw-cite-backlink"><a href="#cite_ref-blocksize_1-0">↑</a></span> <span class="reference-text">Im Rijndael-Algorithmus werden Blockgrößen von 128, 160, 192, 224, und 256 Bits unterstützt, im AES-Standard wird aber nur eine 128-bit Blockgröße spezifiziert.</span>
</li>
<li id="cite_note-biclique-2"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-biclique_2-0">a</a></sup> <sup><a href="#cite_ref-biclique_2-1">b</a></sup></span> <span class="reference-text">Andrey Bogdanov, Dmitry Khovratovich, Christian Rechberger: <cite style="font-style:italic">Biclique Cryptanalysis of the Full AES</cite>. In: <cite style="font-style:italic">ASIACRYPT 2011</cite> (=&nbsp;<cite style="font-style:italic"><a href="Lecture_Notes_in_Computer_Science" title="Lecture Notes in Computer Science">Lecture Notes in Computer Science</a></cite>). <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em">&nbsp;</span>7073</span>. Springer, 2011, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>344–371</span> (<a rel="nofollow" class="external text" href="http://research.microsoft.com/en-us/projects/cryptanalysis/aesbc.pdf">microsoft.com</a> [PDF; abgerufen am 29.&nbsp;November 2012]).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Advanced+Encryption+Standard&amp;rft.atitle=Biclique+Cryptanalysis+of+the+Full+AES&amp;rft.au=Andrey+Bogdanov%2C+Dmitry+Khovratovich%2C+Christian+Rechberger&amp;rft.btitle=ASIACRYPT+2011&amp;rft.date=2011&amp;rft.genre=book&amp;rft.pages=344-371&amp;rft.pub=Springer&amp;rft.series=Lecture+Notes+in+Computer+Science&amp;rft.volume=7073" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><a href="#cite_ref-3">↑</a></span> <span class="reference-text">Committee on National Security Systems: <cite style="font-style:italic">CNSS Policy No. 15, Fact Sheet No. 1</cite>. 2003, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>2</span> (<a rel="nofollow" class="external text" href="http://csrc.nist.gov/groups/ST/toolkit/documents/aes/CNSS15FS.pdf">nist.gov</a> [PDF]).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Advanced+Encryption+Standard&amp;rft.au=Committee+on+National+Security+Systems&amp;rft.btitle=CNSS+Policy+No.+15%2C+Fact+Sheet+No.+1&amp;rft.date=2003&amp;rft.genre=book&amp;rft.pages=2" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><a href="#cite_ref-4">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.samiam.org/rijndael.html">Beschreibung des AES von Sam Trenholme (englisch)</a></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><a href="#cite_ref-5">↑</a></span> <span class="reference-text">Tom Berson: <i><a rel="nofollow" class="external text" href="https://web.archive.org/web/20051025042834/http://www.skype.com/security/files/2005-031%20security%20evaluation.pdf">Skype Security Evaluation</a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> vom 25. Oktober 2005 im </i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a><i>)</i> auf skype.com mit <a rel="nofollow" class="external text" href="http://www.anagram.com/berson/skyeval.sig">Signatur</a>, 18. Oktober 2005, englisch, <a href="Portable_Document_Format" title="Portable Document Format">PDF</a></span>
</li>
<li id="cite_note-6"><span class="mw-cite-backlink"><a href="#cite_ref-6">↑</a></span> <span class="reference-text">Oliver Lau (2013): „Spezialkommando. Schnelle AES-Chiffres mit Intrinsics“ in: c’t 2013, Heft 14, Seiten 174–177. Zitierte Aussage siehe Seite 176 und 177.</span>
</li>
<li id="cite_note-ferguson-7"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-ferguson_7-0">a</a></sup> <sup><a href="#cite_ref-ferguson_7-1">b</a></sup></span> <span class="reference-text"><a href="Niels_Ferguson" title="Niels Ferguson">Niels Ferguson</a>, <a href="Bruce_Schneier" title="Bruce Schneier">Bruce Schneier</a>: <cite style="font-style:italic">Practical Cryptography</cite>. Wiley Publishing, Indianapolis 2003, ISBN 978-0-471-22357-3, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em">&nbsp;</span>56</span>.<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Advanced+Encryption+Standard&amp;rft.au=Niels+Ferguson%2C+Bruce+Schneier&amp;rft.btitle=Practical+Cryptography&amp;rft.date=2003&amp;rft.genre=book&amp;rft.isbn=9780471223573&amp;rft.pages=56&amp;rft.place=Indianapolis&amp;rft.pub=Wiley+Publishing" style="display:none">&nbsp;</span></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.schneier.com/crypto-gram-0210.html#8">Comments from Readers</a></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://mirror.selfnet.de/CCC/events/hal2001/video/hal2001_cryptoanalis_of_rijndael_48.mp4"><i>Cryptoanalis of Rijndael.</i></a> (MP4; 284 MB) In: <i>selfnet.de.</i><span class="Abrufdatum"> Abgerufen am 30.&nbsp;August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Fde.wikipedia.org%3AAdvanced+Encryption+Standard&amp;rft.title=Cryptoanalis+of+Rijndael&amp;rft.description=Cryptoanalis+of+Rijndael&amp;rft.identifier=https%3A%2F%2Fmirror.selfnet.de%2FCCC%2Fevents%2Fhal2001%2Fvideo%2Fhal2001_cryptoanalis_of_rijndael_48.mp4&amp;rft.language=en">&nbsp;</span></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://cr.yp.to/antiforgery/cachetiming-20050414.pdf">Cache-timing attacks on AES (PDF-Version; 426&nbsp;kB)</a></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><a href="#cite_ref-11">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.cryptolux.org/images/1/1a/Aes-192-256.pdf">Related-key Cryptanalysis of the Full AES-192 and AES-256</a> (PDF; 354&nbsp;kB)</span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><a href="#cite_ref-12">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20131113115057/https://cryptolux.org/index.php/FAQ_on_the_attacks">FAQ zum Angriff</a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> vom 13. November 2013 im <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>)</span>
</li>
<li id="cite_note-BK09-13"><span class="mw-cite-backlink">↑ <sup><a href="#cite_ref-BK09_13-0">a</a></sup> <sup><a href="#cite_ref-BK09_13-1">b</a></sup></span> <span class="reference-text">Biryukov, Alex; Khovratovich, Dmitry: <a rel="nofollow" class="external text" href="http://eprint.iacr.org/2009/317">„Related-key Cryptanalysis of the Full AES-192 and AES-256“</a>, (4. Dezember 2009)</span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><a href="#cite_ref-14">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/">The NSA Is Building the Country’s Biggest Spy Center (Watch What You Say)</a></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><a href="#cite_ref-15">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://www.heise.de/newsticker/meldung/Bericht-Groesstes-NSA-Rechenzentrum-laeuft-sich-warm-1969289.html">Bericht: Größtes NSA-Rechenzentrum läuft sich warm</a></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><a href="#cite_ref-16">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.finalcrypt.org/docs/tempest_attacks_against_aes.pdf"><i>TEMPEST attacks against AES.</i></a> (PDF; 2,1 MB) In: <i>FinalCrypt.</i><span class="Abrufdatum"> Abgerufen am 30.&nbsp;August 2023</span> (englisch).</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Fde.wikipedia.org%3AAdvanced+Encryption+Standard&amp;rft.title=TEMPEST+attacks+against+AES&amp;rft.description=TEMPEST+attacks+against+AES&amp;rft.identifier=https%3A%2F%2Fwww.finalcrypt.org%2Fdocs%2Ftempest_attacks_against_aes.pdf&amp;rft.language=en">&nbsp;</span></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><a href="#cite_ref-17">↑</a></span> <span class="reference-text"><span class="cite">Dusan Zivadinovic: <a rel="nofollow" class="external text" href="https://www.heise.de/newsticker/meldung/AES-Schluessel-stehlen-Van-Eck-Phreaking-fuer-200-Euro-3772462.html"><i>AES-Schlüssel stehlen: Van-Eck-Phreaking für 200 Euro.</i></a><span class="Abrufdatum"> Abgerufen am 18.&nbsp;September 2017</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Fde.wikipedia.org%3AAdvanced+Encryption+Standard&amp;rft.title=AES-Schl%C3%BCssel+stehlen%3A+Van-Eck-Phreaking+f%C3%BCr+200+Euro&amp;rft.description=AES-Schl%C3%BCssel+stehlen%3A+Van-Eck-Phreaking+f%C3%BCr+200+Euro&amp;rft.identifier=https%3A%2F%2Fwww.heise.de%2Fnewsticker%2Fmeldung%2FAES-Schluessel-stehlen-Van-Eck-Phreaking-fuer-200-Euro-3772462.html&amp;rft.creator=Dusan+Zivadinovic">&nbsp;</span></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><a href="#cite_ref-18">↑</a></span> <span class="reference-text"><cite style="font-style:italic">The Design of Rijndael</cite>. <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1007/978-3-662-60769-5">10.1007/978-3-662-60769-5</a></span> (<a rel="nofollow" class="external text" href="https://link.springer.com/book/10.1007/978-3-662-60769-5">springer.com</a> [abgerufen am 9.&nbsp;Februar 2023]).<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&amp;rfr_id=info:sid/de.wikipedia.org:Advanced+Encryption+Standard&amp;rft.btitle=The+Design+of+Rijndael&amp;rft.doi=10.1007%2F978-3-662-60769-5&amp;rft.genre=book" style="display:none">&nbsp;</span></span>
</li>
</ol></div><!--htdig_noindex--><div><div class="zim-footer">
Dieser Artikel wurde von <a class="external text" title="Zuletzt bearbeitet am 2025-08-23" href="https://de.wikipedia.org/wiki/?title=Advanced_Encryption_Standard&amp;oldid=259117652">Wikipedia</a> herausgegeben. Der Text ist unter <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.de">Creative Commons Attribution-Share Alike 4.0</a> verfügbar, sofern nicht anders angegeben. Für die Mediendateien können zusätzliche Bedingungen gelten.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>

</body></html>