
RIJNDAEL 
W 
Block size (bits) 
128, 160, 192, 224, or 256 
always 512 
Number of rounds 
10, 11, 12, 13, or 14 
always 10 
Key schedule 
dedicated a priori algorithm 
the round function itself 
GF(2^{8}) reduction polynomial 
x^{8} + x^{4} + x^{3} + x + 1 (0x11B) 
x^{8} + x^{4} + x^{3} + x^{2} + 1 (0x11D) 
Origin of the Sbox 
mapping u → u^{1} over GF(2^{8}), plus affine transform 
recursive structure (see below) 
Origin of the round constants 
polynomials x^{i} over GF(2^{8}) 
successive entries of the Sbox 
Diffusion layer 
leftmultiplication by the 4×4 circulant MDS matrix cir(2, 3, 1, 1) 
rightmultiplication by the 8×8 circulant MDS matrix cir(1, 1, 4, 1, 8, 5, 2, 9) 