On the Twofish Key Schedule

B. Schneier, J. Kelsey, D. Whiting, D. Wagner, C. Hall, N. Ferguson

Fifth Annual Workshop on Selected Areas in Cryptography, Springer Verlag, August 1998, to appear.

ABSTRACT: Twofish is a new block cipher with a 128 bit block, and a key length of 128, 192, or 256 bits, which has been submitted as an AES candidate. In this paper, we briefly review the structure of Twofish, and then discuss the key schedule of Twofish, and its resistance to attack. We close with some open questions on the security of Twofish's key schedule.

[full text - PDF (Acrobat)] [full text - Postscript]

Photo of Bruce Schneier by Per Ervland.

Schneier on Security is a personal website. Opinions expressed are not necessarily those of Co3 Systems, Inc..