Distinguisher and Related-Key Attack on the Full AES-256

Executive Summary

This paper constructs a chosen-key distinguisher and a related-key attack on the full 256-bit key AES. It define a notion of differential q-multicollision and show that for AES-256 q-multicollisions can be constructed in time q 267 and with negligible memory, while it prove that the same task for an ideal cipher of the same block size would require at least time.

