0

In effect the same 128 bit key is XORed at every round and before and after as whitening.

Would it be 2^128?

What are the dangers of such a naive key schedule and does AES suffer from them?

Edit: Fair enough, slide attack is a problem. It doesn't explain however why there is a key schedule instead of round constants.

0 Answers0