Reference : Cryptanalysis of the Full AES Using GPU-Like Special-Purpose Hardware
Scientific journals : Article
Engineering, computing & technology : Computer science
http://hdl.handle.net/10993/17086
Cryptanalysis of the Full AES Using GPU-Like Special-Purpose Hardware
English
Biryukov, Alex mailto [University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) >]
Groszschädl, Johann mailto [University of Luxembourg > Faculty of Science, Technology and Communication (FSTC) > Computer Science and Communications Research Unit (CSC) >]
Apr-2012
Fundamenta Informaticae
IOS Press
114
3-4
221-237
Yes (verified by ORBilu)
International
0169-2968
1875-8681
[en] Advanced Enryption Standard ; Cryptanalysis ; Cryptanalytic Hardware ; Graphics Processing Unit ; Energy Evaluation
[en] The block cipher Rijndael has undergone more than ten years of extensive cryptanalysis since its submission as a candidate for the Advanced Encryption Standard (AES) in April 1998. To date, most of the publicly-known cryptanalytic results are based on reduced-round variants of the AES (respectively Rijndael) algorithm. Among the few exceptions that target the full AES are the Related-Key Cryptanalysis (RKC) introduced at ASIACRYPT 2009 and attacks exploiting Time-Memory-Key (TMK) trade-offs such as demonstrated at SAC 2005. However, all these attacks are generally considered infeasible in practice due to their high complexity (i.e. 2^99.5 AES operations for RKC, 2^80 for TMK). In this paper, we evaluate the cost of cryptanalytic attacks on the full AES when using special-purpose hardware in the form of multi-core AES processors that are designed in a similar way as modern Graphics Processing Units (GPUs) such as the NVIDIA GT200b. Using today's VLSI technology would allow for the implementation of a GPU-like processor reaching a throughput of up to 10^12 AES operations per second. An organization able to spend one trillion US$ for designing and building a supercomputer based on such processors could theoretically break the full AES in a time frame of as little as one year when using RKC, or in merely one month when performing a TMK attack. We also analyze different time-cost trade-offs and assess the implications of progress in VLSI technology under the assumption that Moore's law will continue to hold for the next ten years. These assessments raise some concerns about the long-term security of the AES.
http://hdl.handle.net/10993/17086
10.3233/FI-2012-626
http://iospress.metapress.com/content/b16256871m6vg867/

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
FI2012.pdfPublisher postprint157.27 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.