Feasible Attack on the 13-round AES-256.
Alex Biryukov, Dmitry Khovratovich · 2010
Abstract. In this note we present the first attack with feasible com-plexity on the 13-round AES-256. The attack runs in the related-subkey scenario with four related keys, in 276 time, data, and memory. 1