New Integral Distinguisher for Rijndael-256

Yuechuan Wei and Bing Sun and Chao Li

Abstract: The known 3-round distinguisher of Rijndael-256 is byte- oriented and 2^8 plaintexts are needed to distinguish 3-round Rijndael from a random permutation. In this paper, we consider the influence of the order of the plaintexts and present a new 3-round distinguisher which only needs 32 plaintexts.

Category / Keywords: secret-key cryptography / block cipher, integral attack, Rijndael-256

Date: received 13 Nov 2009, last revised 17 Nov 2009

