This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| AES competition | |
|---|---|
| Name | Advanced Encryption Standard selection |
| Other names | AES selection |
| Date | 1997–2000 |
| Organiser | National Institute of Standards and Technology |
| Winner | Rijndael |
| Participants | Multiple cryptographers and teams |
| Location | United States (selection process) |
AES competition
The AES competition was a multi-year public selection process run by National Institute of Standards and Technology and informed by United States Department of Commerce and Federal Information Processing Standards activities, initiated after concerns raised by the Data Encryption Standard lifecycle and advances involving Ronald L. Rivest's legacy and debates in cryptographic communities such as those around Whitfield Diffie, Martin Hellman, and discourse at venues like CRYPTO Conference and Eurocrypt. The process solicited submissions from international teams including researchers affiliated with institutions such as University of Luxembourg, Katholieke Universiteit Leuven, and companies including RSA Security, while engaging professional societies like the International Organization for Standardization and events such as SIGCOMM and Usenix Security Symposium.
The initiative followed the expiration and perceived weaknesses of Data Encryption Standard and public concern amplified by analyses at conferences like FSE and publications by researchers in journals associated with Association for Computing Machinery and IEEE. NIST issued a formal call for algorithms to establish a new Federal Information Processing Standards symmetric block cipher, prompting responses from teams connected to Technische Universiteit Eindhoven, University of Leuven, and private entities including Siemens and IBM. Discussions referenced earlier work by figures from MIT and Bell Labs and drew on threat assessments influenced by the rise of projects such as RSA Conference forums and policy debates in Congressional Research Service briefings.
NIST received fifteen first-round submissions from designers with ties to Belgium, Netherlands, Japan, United States, and France, among others, including notable submissions by teams led by Joan Daemen and Vincent Rijmen (Rijndael), Ronald L. Rivest (RC6), M. J. B. Robshaw associates, and designers of Twofish connected to Bruce Schneier and Counterpane Internet Security. Other submitters included authors affiliated with Netscape era researchers, academics from University of Bergen, and cryptographers presenting at Asiacrypt and CHES. Each submission specified block size, key schedule, and operations with implementers referencing platforms from Intel and ARM Holdings and cryptanalytic evaluations appearing in proceedings such as IACR workshops.
NIST published evaluation criteria that emphasized security against attacks demonstrated in literature from IACR, Crypto++ implementations, and analyses by researchers from Queensland University of Technology and University of California, Berkeley, while also valuing performance on platforms produced by Sun Microsystems, Microsoft, and Oracle Corporation. The process included public comment rounds, performance testing on hardware like Pentium and embedded chips from Atmel, and reviews at meetings involving representatives from National Security Agency, European Commission experts, and academic panels chaired by figures associated with Stanford University and University of Cambridge. Criteria balanced resistance to differential and linear cryptanalysis studied by Eli Biham and Adi Shamir, implementation simplicity cited in papers from Niels Ferguson and Ross Anderson, and patent concerns raised by stakeholders including PKWARE and industry consortia.
Five finalists were announced following extensive analysis and public workshops: Rijndael, Twofish, RC6, Serpent, and MARS. Each finalist was analyzed in depth at venues such as Crypto Conference, FSE, and Eurocrypt and by authors from Queen's University Belfast and Ecole Normale Supérieure. After additional scrutiny addressing attack models discussed by Michael Wiener and Paul Kocher, NIST selected Rijndael for standardization; Rijndael's designers, Joan Daemen and Vincent Rijmen, proposed a cipher balancing simplicity and performance on platforms from Intel and ARM. The selection culminated in issuance of the standard as FIPS 197.
The chosen algorithm rapidly became ubiquitous across protocols and products including implementations in TLS, IPsec, Secure Shell, and storage systems by vendors such as Microsoft, Apple Inc., and Google. Academic curricula at institutions like MIT, ETH Zurich, and University of Oxford incorporated AES into courses alongside material by Shamir, Diffie, and Rivest, and research labs at NIST and CNRS extended analysis into modes of operation referenced in ISO/IEC 10116 and IEEE 802.11 standards. Commercial adoption influenced hardware acceleration in processors from Intel Corporation (AES-NI) and cryptographic libraries maintained by projects like OpenSSL and LibreSSL, and motivated further work on authenticated encryption at conferences including NDSS and Usenix.
Since standardization, Rijndael/AES has been the subject of extensive cryptanalysis published in proceedings of IACR, Eurocrypt, and CRYPTO Conference, with researchers from University of Luxembourg, Darmstadt University of Technology, and École Polytechnique reporting reduced-round distinguishers, related-key attacks, and side-channel vulnerabilities studied by Paul Kocher and groups at University of Cambridge. Practical attacks exploiting implementation faults appeared in work tied to DPA research and countermeasures informed by papers from Martijn van Dijk and André Biryukov. National agencies including NSA and academic teams continued to evaluate quantum-era implications of symmetric key sizes in the context of algorithms by Peter Shor and developments in post-quantum cryptography discussed at PQCrypto. Overall, AES remains widely trusted for appropriately sized keys and correctly implemented modes, while the community continues to refine defenses against implementation-level and future theoretical threats.