This publication constítutes the completely refereed postproceedings of the 4th overseas convention at the complicated Encryption average, AES 2004, held in Bonn, Germany in may possibly 2004. the ten revised complete papers offered including an introductory survey and four invited papers through best researchers have been rigorously chosen in the course of rounds of reviewing and development. The papers are geared up in topical sections on cryptanalytic assaults and comparable issues, algebraic assaults and similar effects, implementations, and different themes. All in all, the papers represent a latest evaluation of the state-of-the-art of knowledge encryption utilizing the complex Encryption average AES, the de facto global normal for information encryption.

Contained in the proof of Theorem 1 in [23]. Remark 5. Clearly if wt(γa ) + wt(γb ) = Bl , then Wl [γa , γb ] ≤ (2n − 1). Further, the values χ(w,i) and υ (w,j) depend only on γa and γb , not on the speciﬁc values of a and b. Lemma 4. Given a, b ∈ {0, 1}N \ 0 that satisfy wt(γa ) + wt(γb ) > Bl , let W = Wl [γa , γb ], f = wt(γa ), = wt(γb ), and let χ(w,i) , υ (w,j) be deﬁned as above. Consider the vectors Vw in (10). Select any (f + −Bl ) vector positions, and ﬁx a value in {0, 1}n \ 0 for each position.

R. Anderson and M. Kuhn. Low cost attacks on tamper resistant devices. In B. Christianson, B. Crispo, T. Mark, A. Lomas, and M. Roe, editors, 5th Security Protocols Workshop, volume 1361 of Lecture Notes in Computer Science, pages 125–136. Springer-Verlag, 1997. 3. I. Biehl, B. Meyer, and V. M¨ uller. Diﬀerential Fault Analysis on Elliptic Curve Cryptosystems. In M. Bellare, editor, Advances in Cryptology – CRYPTO 2000, volume 1880 of Lecture Notes in Computer Science, pages 131–146. SpringerVerlag, 2000.

255} which satisfy the equation Ck ⊕ Dk = SubByte(x) ⊕ SubByte(x ⊕ ej ) (15) We obtain Kj9 and Kj9 ⊕ ej as solutions to (15). So, if we obtain another faulty ciphertext with a fault ej (ej = ej ) which occurs on the same byte j of K 9 , we obtain Kj9 and Kj9 ⊕ ej as solutions. This allows us to deduce the value of Kj9 because it is the only value that appears in both solution. 9 9 to K15 ) of the With this attack, we obtain the values of the last 4 bytes (K12 9 round key K with 32 faulty ciphertexts on average.