Paper 2026/2304

Gram Moments and Pairwise Mixing of AES

Chongxu Ren, Tsinghua University
Hongbo Yu, Tsinghua University
Abstract

We prove that $4k+4$ rounds of AES with independent uniform round keys are $2^{-14-61k}$-close to pairwise independent, improving on Hurst's announced bound of $2^{-3.82-48.03k}$. Here, closeness is measured by the total variation distance between the outputs on any two distinct plaintexts and those of a uniform random permutation, with the round keys sampled once and retained across evaluations. Consequently, 12, 16, and 20 rounds suffice for statistical accuracy $2^{-128}$, $2^{-192}$, and $2^{-256}$, respectively. Our bound also holds for the complete view of any algorithm making at most two adaptive classical forward queries. We develop a general bound for local difference channels acting on additive MDS codes, expressed through the second moment of a Gram matrix. This bound controls the dependencies created by diffusion and refines the activity-space analysis of previous work. Combining the resulting contraction estimate with a sharper analysis of the initial difference distributions yields the stated mixing bound.

Metadata
Available format(s)
PDF
Category
Secret-key cryptography
Publication info
Preprint.
Keywords
AESPairwise independenceGram matricesMDS codesSpectral analysis
Contact author(s)
rcx23 @ mails tsinghua edu cn
yuhongbo @ tsinghua edu cn
History
2026-10-04: approved
2026-10-01: received
See all versions
Short URL
https://ia.cr/2026/2304
License
Creative Commons Attribution-NonCommercial-ShareAlike
CC BY-NC-SA

BibTeX

@misc{cryptoeprint:2026/2304,
      author = {Chongxu Ren and Hongbo Yu},
      title = {Gram Moments and Pairwise Mixing of {AES}},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/2304},
      year = {2026},
      url = {https://eprint.iacr.org/2026/2304}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.