Question: Alice designs a double-AES cipher. Given the plaintext M, she uses the first key K1 (256 bits) to AES-encrypt M to obtain ciphertext C1, then
Alice designs a double-AES cipher. Given the plaintext M, she uses the first key K1 (256 bits) to AES-encrypt M to obtain ciphertext C1, then uses the second key K2 (256 bits) to AES-encrypt C1 to obtain the final ciphertext C2. Does this mean that Alices design has a key strength of 512 bits? Is Alices design vulnerable to meet-in-the-middle? Detail your answers.
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
