[{"data":1,"prerenderedAt":469},["ShallowReactive",2],{"navigation_docs":3,"-ciphers-rijndael":180,"-ciphers-rijndael-surround":464},[4,36],{"title":5,"path":6,"stem":7,"children":8,"icon":35},"Guide","\u002Fguide","1.guide\u002F01.index",[9,11,15,19,23,27,31],{"title":10,"path":6,"stem":7},"Getting Started",{"title":12,"path":13,"stem":14},"Encode and decode","\u002Fguide\u002Ftransform","1.guide\u002F02.transform",{"title":16,"path":17,"stem":18},"Analysis","\u002Fguide\u002Fanalysis","1.guide\u002F03.analysis",{"title":20,"path":21,"stem":22},"CLI","\u002Fguide\u002Fcli","1.guide\u002F04.cli",{"title":24,"path":25,"stem":26},"Agents","\u002Fguide\u002Fagents","1.guide\u002F05.agents",{"title":28,"path":29,"stem":30},"Custom ciphers","\u002Fguide\u002Fcustom","1.guide\u002F06.custom",{"title":32,"path":33,"stem":34},"Playground","\u002Fguide\u002Fplayground","1.guide\u002F07.playground","i-solar-book-2-linear",{"title":37,"path":38,"stem":39,"children":40,"icon":179},"Ciphers","\u002Fciphers","2.ciphers\u002F00.index",[41,43,47,51,55,59,63,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175],{"title":42,"path":38,"stem":39},"Overview",{"title":44,"path":45,"stem":46},"Caesar","\u002Fciphers\u002Fcaesar","2.ciphers\u002F01.caesar",{"title":48,"path":49,"stem":50},"ROT-13","\u002Fciphers\u002Frot13","2.ciphers\u002F02.rot13",{"title":52,"path":53,"stem":54},"ROT-47","\u002Fciphers\u002Frot47","2.ciphers\u002F03.rot47",{"title":56,"path":57,"stem":58},"Atbash","\u002Fciphers\u002Fatbash","2.ciphers\u002F04.atbash",{"title":60,"path":61,"stem":62},"Affine","\u002Fciphers\u002Faffine","2.ciphers\u002F05.affine",{"title":64,"path":65,"stem":66},"Vigenère","\u002Fciphers\u002Fvigenere","2.ciphers\u002F06.vigenere",{"title":68,"path":69,"stem":70},"Trithemius","\u002Fciphers\u002Ftrithemius","2.ciphers\u002F07.trithemius",{"title":72,"path":73,"stem":74},"Alberti","\u002Fciphers\u002Falberti","2.ciphers\u002F08.alberti",{"title":76,"path":77,"stem":78},"Playfair","\u002Fciphers\u002Fplayfair","2.ciphers\u002F09.playfair",{"title":80,"path":81,"stem":82},"Polybius square","\u002Fciphers\u002Fpolybius","2.ciphers\u002F10.polybius",{"title":84,"path":85,"stem":86},"Morse code","\u002Fciphers\u002Fmorse","2.ciphers\u002F11.morse",{"title":88,"path":89,"stem":90},"Bacon's cipher","\u002Fciphers\u002Fbacon","2.ciphers\u002F12.bacon",{"title":92,"path":93,"stem":94},"Tap code","\u002Fciphers\u002Ftap-code","2.ciphers\u002F13.tap-code",{"title":96,"path":97,"stem":98},"ADFGVX","\u002Fciphers\u002Fadfgvx","2.ciphers\u002F14.adfgvx",{"title":100,"path":101,"stem":102},"Bifid","\u002Fciphers\u002Fbifid","2.ciphers\u002F15.bifid",{"title":104,"path":105,"stem":106},"Rail fence","\u002Fciphers\u002Frail-fence","2.ciphers\u002F16.rail-fence",{"title":108,"path":109,"stem":110},"Columnar transposition","\u002Fciphers\u002Fcolumnar","2.ciphers\u002F17.columnar",{"title":112,"path":113,"stem":114},"Enigma M3","\u002Fciphers\u002Fenigma","2.ciphers\u002F18.enigma",{"title":116,"path":117,"stem":118},"Beaufort","\u002Fciphers\u002Fbeaufort","2.ciphers\u002F19.beaufort",{"title":120,"path":121,"stem":122},"Autokey","\u002Fciphers\u002Fautokey","2.ciphers\u002F20.autokey",{"title":124,"path":125,"stem":126},"AES (ECB)","\u002Fciphers\u002Faes","2.ciphers\u002F21.aes",{"title":128,"path":129,"stem":130},"Triple DES (ECB)","\u002Fciphers\u002Ftriple-des","2.ciphers\u002F22.triple-des",{"title":132,"path":133,"stem":134},"AES (LRW)","\u002Fciphers\u002Faes-lrw","2.ciphers\u002F23.aes-lrw",{"title":136,"path":137,"stem":138},"AES (CBC)","\u002Fciphers\u002Faes-cbc","2.ciphers\u002F24.aes-cbc",{"title":140,"path":141,"stem":142},"AES (CFB)","\u002Fciphers\u002Faes-cfb","2.ciphers\u002F25.aes-cfb",{"title":144,"path":145,"stem":146},"AES (CTR)","\u002Fciphers\u002Faes-ctr","2.ciphers\u002F26.aes-ctr",{"title":148,"path":149,"stem":150},"AES (CCM)","\u002Fciphers\u002Faes-ccm","2.ciphers\u002F27.aes-ccm",{"title":152,"path":153,"stem":154},"AES (OFB)","\u002Fciphers\u002Faes-ofb","2.ciphers\u002F28.aes-ofb",{"title":156,"path":157,"stem":158},"AES (OCB)","\u002Fciphers\u002Faes-ocb","2.ciphers\u002F29.aes-ocb",{"title":160,"path":161,"stem":162},"Triple DES (CBC)","\u002Fciphers\u002Ftriple-des-cbc","2.ciphers\u002F30.triple-des-cbc",{"title":164,"path":165,"stem":166},"Rijndael (ECB)","\u002Fciphers\u002Frijndael","2.ciphers\u002F31.rijndael",{"title":168,"path":169,"stem":170},"AES (XTS)","\u002Fciphers\u002Faes-xts","2.ciphers\u002F32.aes-xts",{"title":172,"path":173,"stem":174},"AES (CBC-MAC)","\u002Fciphers\u002Faes-cbc-mac","2.ciphers\u002F33.aes-cbc-mac",{"title":176,"path":177,"stem":178},"Blowfish (ECB)","\u002Fciphers\u002Fblowfish","2.ciphers\u002F34.blowfish","i-solar-library-linear",{"id":181,"title":164,"body":182,"description":457,"extension":458,"links":459,"meta":460,"navigation":461,"path":165,"seo":462,"stem":166,"__hash__":463},"docs\u002F2.ciphers\u002F31.rijndael.md",{"type":183,"value":184,"toc":453},"minimark",[185,189,198,204,368,383,388,391,404,407,411,426,433,449],[186,187],"cipher-facts",{"name":188},"rijndael",[190,191,192,193,197],"p",{},"AES is a subset. Daemen and Rijmen sent NIST a cipher whose block and key could each be 128, 160, 192, 224 or 256 bits. NIST kept the 128-bit block and three of the keys and called that AES. Everything else stayed Rijndael, and it didn't go away. PHP's old mcrypt called the 256-bit block ",[194,195,196],"code",{},"MCRYPT_RIJNDAEL_256",", which is not AES-256, whatever the name suggests.",[190,199,200,203],{},[194,201,202],{},"blockSize"," is in bits, 128, 160, 192, 224 or 256, default 128. The key is 32, 40, 48, 56 or 64 hex digits, so the 160 and 224-bit keys AES never took work here too. The mode is ECB. Text goes in as UTF-8 with PKCS#7 padding up to a whole block, and the ciphertext comes out as lowercase hex.",[205,206,211],"pre",{"className":207,"code":208,"language":209,"meta":210,"style":210},"language-ts shiki shiki-themes github-light github-light poimandres","const rijndael = create(\"rijndael\");\nconst key = \"2b7e151628aed2a6abf7158809cf4f3c762e7160f38b4da56a784d9045190cfe\";\nrijndael.encode(\"ATTACK AT DAWN\", { key, blockSize: 256 }).text;\n\u002F\u002F \"4e0085db1697ce5f34911401d53bc05637a158856ca148bb212050ebfd20d208\"\nrijndael.decode(\"4e0085db1697ce5f34911401d53bc05637a158856ca148bb212050ebfd20d208\", { key, blockSize: 256 }).text;\n\u002F\u002F \"ATTACK AT DAWN\"\n","ts","",[194,212,213,249,270,318,325,362],{"__ignoreMap":210},[214,215,218,222,226,229,233,237,241,244,246],"span",{"class":216,"line":217},"line",1,[214,219,221],{"class":220},"s1TYA","const",[214,223,225],{"class":224},"saoiD"," rijndael",[214,227,228],{"class":220}," =",[214,230,232],{"class":231},"sULi6"," create",[214,234,236],{"class":235},"sKlNE","(",[214,238,240],{"class":239},"scVjq","\"",[214,242,188],{"class":243},"sQ7BG",[214,245,240],{"class":239},[214,247,248],{"class":235},");\n",[214,250,252,254,257,259,262,265,267],{"class":216,"line":251},2,[214,253,221],{"class":220},[214,255,256],{"class":224}," key",[214,258,228],{"class":220},[214,260,261],{"class":239}," \"",[214,263,264],{"class":243},"2b7e151628aed2a6abf7158809cf4f3c762e7160f38b4da56a784d9045190cfe",[214,266,240],{"class":239},[214,268,269],{"class":235},";\n",[214,271,273,276,279,282,284,286,289,291,294,296,299,303,306,310,313,316],{"class":216,"line":272},3,[214,274,188],{"class":275},"spVlQ",[214,277,278],{"class":235},".",[214,280,281],{"class":231},"encode",[214,283,236],{"class":235},[214,285,240],{"class":239},[214,287,288],{"class":243},"ATTACK AT DAWN",[214,290,240],{"class":239},[214,292,293],{"class":235},", {",[214,295,256],{"class":275},[214,297,298],{"class":235},",",[214,300,302],{"class":301},"snHMy"," blockSize",[214,304,305],{"class":235},":",[214,307,309],{"class":308},"siHFe"," 256",[214,311,312],{"class":235}," }).",[214,314,315],{"class":275},"text",[214,317,269],{"class":235},[214,319,321],{"class":216,"line":320},4,[214,322,324],{"class":323},"sjhu3","\u002F\u002F \"4e0085db1697ce5f34911401d53bc05637a158856ca148bb212050ebfd20d208\"\n",[214,326,328,330,332,335,337,339,342,344,346,348,350,352,354,356,358,360],{"class":216,"line":327},5,[214,329,188],{"class":275},[214,331,278],{"class":235},[214,333,334],{"class":231},"decode",[214,336,236],{"class":235},[214,338,240],{"class":239},[214,340,341],{"class":243},"4e0085db1697ce5f34911401d53bc05637a158856ca148bb212050ebfd20d208",[214,343,240],{"class":239},[214,345,293],{"class":235},[214,347,256],{"class":275},[214,349,298],{"class":235},[214,351,302],{"class":301},[214,353,305],{"class":235},[214,355,309],{"class":308},[214,357,312],{"class":235},[214,359,315],{"class":275},[214,361,269],{"class":235},[214,363,365],{"class":216,"line":364},6,[214,366,367],{"class":323},"\u002F\u002F \"ATTACK AT DAWN\"\n",[190,369,370,371,373,374,377,378,382],{},"Leave ",[194,372,202],{}," out and you get AES. The same key gives ",[194,375,376],{},"bb1b417494158895d7224a297dac330f"," here and in ",[379,380,381],"a",{"href":125},"AES",", because it's the same function.",[384,385,387],"h2",{"id":386},"what-changes-with-the-block","What changes with the block",[190,389,390],{},"The state stops being a 4×4 square and gets five to eight columns. Three things follow from that, all from the Rijndael proposal:",[392,393,394,398,401],"ul",{},[395,396,397],"li",{},"More rounds. The count is the larger of the key and block length in 32-bit words, plus six. So a 128-bit key on a 256-bit block runs 14 rounds, not 10.",[395,399,400],{},"More round key. Every round needs a key as wide as the block, and the key schedule simply keeps going until there's enough.",[395,402,403],{},"Different row shifts. Rows 1 to 3 move by 1, 2 and 3 bytes up to six columns, by 1, 2 and 4 at seven, and by 1, 3 and 4 at eight.",[190,405,406],{},"S-box and MixColumns stay the same. Each column still gets mixed on its own, there are just more of them.",[384,408,410],{"id":409},"checking-it","Checking it",[190,412,413,414,417,418,421,422,425],{},"OpenSSL has no Rijndael beyond AES. The block function is tested against Brian Gladman's known answer tests for all 25 block and key lengths, the files ",[194,415,416],{},"ecbnt44.txt"," to ",[194,419,420],{},"ecbnt88.txt",". The padded text vectors match ",[194,423,424],{},"py3rijndael",", which is a separate implementation but only knows 128, 192 and 256-bit blocks and keys.",[190,427,428,429,432],{},"Watch the padding if the ciphertext came from mcrypt. mcrypt filled the last block with zero bytes, not PKCS#7, so its output fails the padding check here. You get a ",[194,430,431],{},"CipherError",", not text with zeros at the end.",[190,434,435,436,438,439,442,443,445,446,448],{},"A key or ",[194,437,202],{}," Rijndael doesn't have is an ",[194,440,441],{},"InvalidOptionError",". A ciphertext that isn't whole blocks of the length you asked for is a ",[194,444,431],{},", which also catches an AES ciphertext handed to a 256-bit block. Like ",[379,447,381],{"href":125}," this is plain TypeScript for learning and puzzles, not constant time, and ECB shows every repeated block.",[450,451,452],"style",{},"html pre.shiki code .s1TYA, html code.shiki .s1TYA{--shiki-light:#D73A49;--shiki-default:#D73A49;--shiki-dark:#91B4D5}html pre.shiki code .saoiD, html code.shiki .saoiD{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#E4F0FB}html pre.shiki code .sULi6, html code.shiki .sULi6{--shiki-light:#6F42C1;--shiki-default:#6F42C1;--shiki-dark:#E4F0FBD0}html pre.shiki code .sKlNE, html code.shiki .sKlNE{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#A6ACCD}html pre.shiki code .scVjq, html code.shiki .scVjq{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#A6ACCD}html pre.shiki code .sQ7BG, html code.shiki .sQ7BG{--shiki-light:#032F62;--shiki-default:#032F62;--shiki-dark:#5DE4C7}html pre.shiki code .spVlQ, html code.shiki .spVlQ{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#E4F0FB}html pre.shiki code .snHMy, html code.shiki .snHMy{--shiki-light:#24292E;--shiki-default:#24292E;--shiki-dark:#ADD7FF}html pre.shiki code .siHFe, html code.shiki .siHFe{--shiki-light:#005CC5;--shiki-default:#005CC5;--shiki-dark:#5DE4C7}html pre.shiki code .sjhu3, html code.shiki .sjhu3{--shiki-light:#6A737D;--shiki-light-font-style:inherit;--shiki-default:#6A737D;--shiki-default-font-style:inherit;--shiki-dark:#767C9DB0;--shiki-dark-font-style:italic}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":210,"searchDepth":251,"depth":251,"links":454},[455,456],{"id":386,"depth":251,"text":387},{"id":409,"depth":251,"text":410},"The cipher AES was cut from, with the wider blocks it lost on the way. Block and key each 128 to 256 bits, UTF-8 text in, hex out.","md",null,{},true,{"title":164,"description":457},"19p3po1wpalDvyYDZwO-Gmo8tB0JDSyMSuz6FrYb5iM",[465,467],{"title":160,"path":161,"stem":162,"description":466,"children":-1},"Triple DES with the blocks chained. Every 8-byte block is mixed with the ciphertext before it, so equal blocks stop looking equal. UTF-8 text in, hex out.",{"title":168,"path":169,"stem":170,"description":468,"children":-1},"The disk mode that replaced LRW. Every block masked by its sector and its position, a short last block steals from the one before, and nothing is padded. UTF-8 text in, hex out.",1790291185353]