Security Evaluation of AES


It was proven that there exists no 5-round impossible differential path of AES without taking the details of Sbox into account [SLG+16a], and the first 5 round integrals of AES was discovered in [SLG+16a].

The first preimage attack against 8-round AES hashing modes was found in [BDG+21].

