Cryptanalysis of reduced variants of RIJNDAEL

Rijndael was submitted to the AES selection process, and was later selected as one of the ve nalists from which one will be chosen in the next summer. The best known attack against Rijndael is still the one presented by the designers. In this paper we describe several attacks against reduced variants of Rijndael which improve the best known attack by a factor of 2, and present considerably larger factors for shorter variants. We also show that if only the key scheduling of Rijndael was reversed, the complexity of the best known attack would be reduced by an additional factor of 28.