WEBVTT

1
00:00:00.000 --> 00:00:06.282
These sixteen bytes form one plaintext block,
alongside a sixteen-byte key.

2
00:00:06.282 --> 00:00:13.580
AES one twenty eight begins by exclusive oring
them, then runs ten rounds to produce a block of

3
00:00:13.580 --> 00:00:14.890
the same length.

4
00:00:14.890 --> 00:00:22.022
AES one ninety two and two fifty six use larger
keys and more rounds, with the same block size.

5
00:00:22.022 --> 00:00:29.017
This is a teaching architecture for single-block
encryption, without a claim of RTL or silicon

6
00:00:29.017 --> 00:00:29.979
validation.

7
00:00:29.979 --> 00:00:34.615
Decryption and message modes lie beyond this
path.

8
00:00:34.875 --> 00:00:40.543
Once accepted, the plaintext is stored in state
so the source can move on.

9
00:00:40.543 --> 00:00:47.086
The datapath calculates its next value, the key
path supplies this round's key, and the

10
00:00:47.086 --> 00:00:50.134
controller selects the capturing edge.

11
00:00:50.134 --> 00:00:56.971
Combinational logic responds after the edge
rather than waiting for another clock to start

12
00:00:56.971 --> 00:00:57.974
calculating.

13
00:00:57.974 --> 00:01:00.733
Its output must settle before capture.

14
00:01:00.733 --> 00:01:07.338
The controller still has to track completion; the
byte values cannot tell it which phase comes

15
00:01:07.338 --> 00:01:08.106
next.

16
00:01:08.375 --> 00:01:14.227
Each round writes back to one state register and
reuses the same round circuit.

17
00:01:14.227 --> 00:01:18.337
Ten rounds therefore do not require ten hardware
copies.

18
00:01:18.337 --> 00:01:20.906
This is an iterative architecture.

19
00:01:20.906 --> 00:01:25.188
A round is an algorithmic step; a cycle is a
timing interval.

20
00:01:25.188 --> 00:01:27.771
We choose one round per cycle.

21
00:01:27.771 --> 00:01:34.931
Sharing fewer resources over time, or adding
pipeline registers, requires a revised controller

22
00:01:34.931 --> 00:01:36.067
schedule.

23
00:01:36.333 --> 00:01:42.511
B zero is the most significant input byte, placed
at row zero, column zero.

24
00:01:42.511 --> 00:01:44.150
B one goes downward.

25
00:01:44.150 --> 00:01:48.586
Fill four bytes into a column before moving to
the next.

26
00:01:48.586 --> 00:01:51.768
The index is four times column plus row.

27
00:01:51.768 --> 00:01:56.420
Keep this column-major convention through the
output mapping.

28
00:01:56.420 --> 00:01:59.964
Reading across rows midway changes the packed
order.

29
00:01:59.964 --> 00:02:04.487
Sixteen distinct labels make a misplaced
connection visible.

30
00:02:04.750 --> 00:02:10.154
After loading the plaintext, the initial phase
performs only AddRoundKey.

31
00:02:10.154 --> 00:02:16.009
Rounds one through nine follow SubBytes,
ShiftRows, MixColumns, then AddRoundKey.

32
00:02:16.009 --> 00:02:20.075
Round ten bypasses MixColumns and retains the
other steps.

33
00:02:20.075 --> 00:02:23.778
The controller must select the route and the key
together.

34
00:02:23.778 --> 00:02:29.170
Open the first normal round and follow which
transformations change byte values and which move

35
00:02:29.170 --> 00:02:30.531
their positions.

36
00:02:30.792 --> 00:02:35.810
SubBytes passes each byte through the same
nonlinear S box without moving it.

37
00:02:35.810 --> 00:02:38.998
Hexadecimal fifty three, for example, becomes E
D.

38
00:02:38.998 --> 00:02:45.002
Sixteen combinational S boxes can calculate in
parallel rather than making sixteen sequential

39
00:02:45.002 --> 00:02:45.595
lookups.

40
00:02:45.595 --> 00:02:52.130
A single shared S box needs intermediate storage
and scheduling, changing this one-round-per-cycle

41
00:02:52.130 --> 00:02:53.407
architecture.

42
00:02:53.667 --> 00:03:01.240
ShiftRows leaves row zero fixed and rotates the
other rows left by one, two, and three positions.

43
00:03:01.240 --> 00:03:06.975
Values stay unchanged, but different source bytes
now meet in each column.

44
00:03:06.975 --> 00:03:14.044
This fixed permutation can be wiring, without a
cycle for each movement or a variable shifter.

45
00:03:14.044 --> 00:03:20.967
Follow the labels along those connections before
the final ciphertext hides where each byte came

46
00:03:20.967 --> 00:03:21.739
from.

47
00:03:22.000 --> 00:03:28.866
MixColumns combines the four bytes within each
column, independently across the four columns.

48
00:03:28.866 --> 00:03:31.664
Every output depends on all four inputs.

49
00:03:31.664 --> 00:03:38.248
Its multiplications by two and three use a finite
field, and the transformation is reversible.

50
00:03:38.248 --> 00:03:41.597
It does not average or hash away the data.

51
00:03:41.597 --> 00:03:44.025
AES has no separate MixRows step.

52
00:03:44.025 --> 00:03:49.231
Inspect multiplication by two before connecting
the full column.

53
00:03:49.500 --> 00:03:54.023
Xtime shifts left and discards the outgoing high
bit.

54
00:03:54.023 --> 00:03:59.306
If that original bit was one, exclusive or with
hexadecimal one B.

55
00:03:59.306 --> 00:04:05.358
Fifty seven becomes A E without reduction; A E
becomes forty seven using it.

56
00:04:05.358 --> 00:04:11.302
Multiplication by three is xtime exclusive or the
original value.

57
00:04:11.302 --> 00:04:18.627
The column D B, thirteen, fifty three, forty five
should become eight E, four D, A one, B C.

58
00:04:18.627 --> 00:04:21.894
Compare these four output bytes first.

59
00:04:21.894 --> 00:04:28.225
A mismatch can come from the coefficients, field
arithmetic, or byte order, before all four

60
00:04:28.225 --> 00:04:30.115
columns are connected.

61
00:04:30.375 --> 00:04:36.993
AddRoundKey exclusive ors the state and round key
across all one hundred twenty eight bits.

62
00:04:36.993 --> 00:04:39.826
Both operands use the same byte mapping.

63
00:04:39.826 --> 00:04:45.744
Bits operate together without carry or one
hundred twenty eight sequential cycles.

64
00:04:45.744 --> 00:04:49.339
Fifty three exclusive or C A is ninety nine.

65
00:04:49.339 --> 00:04:57.144
The other transformations are public fixed rules;
this step connects key material to the datapath.

66
00:04:57.417 --> 00:05:04.224
The final round sends the ShiftRows result
directly to AddRoundKey, bypassing MixColumns.

67
00:05:04.224 --> 00:05:07.188
The other three steps remain, using K ten.

68
00:05:07.188 --> 00:05:12.863
A selector can bypass the shared circuit without
duplicating the entire round.

69
00:05:12.863 --> 00:05:17.597
A correct route with K nine still gives the wrong
ciphertext.

70
00:05:17.597 --> 00:05:23.724
Check what the counter selects in both paths,
rather than only its numeric value.

71
00:05:24.000 --> 00:05:27.301
Keep original K zero in its own register.

72
00:05:27.301 --> 00:05:31.314
The working key advances through the rounds to K
ten.

73
00:05:31.314 --> 00:05:34.141
Reload K zero for the next plaintext.

74
00:05:34.141 --> 00:05:40.981
Continuing from the previous K ten can leave the
first block correct and the second wrong.

75
00:05:40.981 --> 00:05:48.803
Two consecutive blocks with the same key
therefore test a lifetime boundary that a single

76
00:05:48.803 --> 00:05:51.231
vector cannot exercise.

77
00:05:51.500 --> 00:05:55.489
Split the key into four thirty two bit words.

78
00:05:55.489 --> 00:06:03.580
Rotate the last word's bytes, apply four S boxes
for SubWord, then exclusive or Rcon in the high

79
00:06:03.580 --> 00:06:04.092
byte.

80
00:06:04.092 --> 00:06:05.833
That produces temp.

81
00:06:05.833 --> 00:06:10.646
The first new word combines the old first word
with temp.

82
00:06:10.646 --> 00:06:16.784
Each following word combines its own old value
with the previous new word.

83
00:06:16.784 --> 00:06:20.764
This combinational chain derives the key locally.

84
00:06:20.764 --> 00:06:27.500
There are eleven keys, K zero through K ten, with
Rcon indexed from one through ten.

85
00:06:27.750 --> 00:06:32.231
The initial XOR uses K zero without advancing
working.

86
00:06:32.231 --> 00:06:36.047
At round r, the register still holds K r minus
one.

87
00:06:36.047 --> 00:06:43.306
Combinational expansion generates K r and feeds
it directly into this round's AddRoundKey.

88
00:06:43.306 --> 00:06:47.121
Capture the new state and key together at the
end.

89
00:06:47.121 --> 00:06:54.272
Connecting the old working register directly to
the XOR makes the key one round late; nonblocking

90
00:06:54.272 --> 00:06:57.750
assignments do not correct that connection.

91
00:06:58.000 --> 00:07:04.237
With the key loaded, E zero accepts plaintext and
E one performs the initial XOR.

92
00:07:04.237 --> 00:07:07.300
E two through E ten run the normal rounds.

93
00:07:07.300 --> 00:07:11.715
E eleven completes the final round and makes
output valid.

94
00:07:11.715 --> 00:07:18.649
Earliest transfer is E twelve, followed by input
at E thirteen: eleven cycles to valid and

95
00:07:18.649 --> 00:07:21.872
thirteen between unstalled transactions.

96
00:07:21.872 --> 00:07:26.924
This schedule uses sixteen data S boxes and four
key S boxes together.

97
00:07:26.924 --> 00:07:31.783
Synchronous memories or sharing fewer boxes
change the timing.

98
00:07:31.783 --> 00:07:35.766
Clock frequency remains an implementation result.

99
00:07:36.042 --> 00:07:40.672
The controller starts in NO KEY and enters READY
after loading a key.

100
00:07:40.672 --> 00:07:45.024
It separates initial, normal, final, and
output-holding phases.

101
00:07:45.024 --> 00:07:50.542
A round counter alone cannot express missing key
material or waiting for a receiver.

102
00:07:50.542 --> 00:07:54.199
Busy means the transaction remains unfinished.

103
00:07:54.199 --> 00:08:00.236
Completed ciphertext waiting for acceptance
therefore keeps busy high, until a transfer

104
00:08:00.236 --> 00:08:02.811
returns the controller to READY.

105
00:08:03.083 --> 00:08:10.210
In READY, simultaneous key valid and input valid
cause this interface to accept the key first and

106
00:08:10.210 --> 00:08:11.578
lower input ready.

107
00:08:11.578 --> 00:08:15.939
The plaintext source retains its data for a later
handshake.

108
00:08:15.939 --> 00:08:21.241
That replacement edge cannot quietly accept
plaintext under the old key.

109
00:08:21.241 --> 00:08:27.702
Separate channels still need an explicit priority
contract shared by both sources and the

110
00:08:27.702 --> 00:08:28.930
controller.

111
00:08:29.208 --> 00:08:35.225
Assert output valid when ciphertext is available,
without waiting for ready.

112
00:08:35.225 --> 00:08:39.014
During backpressure, preserve valid and the data.

113
00:08:39.014 --> 00:08:43.068
Do not recompute or accept an input that
overwrites it.

114
00:08:43.068 --> 00:08:49.911
If transfer is delayed to E fourteen, READY is
reached after that edge, and the next input can

115
00:08:49.911 --> 00:08:51.668
be accepted at E fifteen.

116
00:08:51.668 --> 00:08:58.127
Completion of encryption and completion of the
transaction occur at different times.

117
00:08:58.458 --> 00:09:04.351
An active-low synchronous reset clears state,
original key, working key, and counter at a

118
00:09:04.351 --> 00:09:06.448
rising edge, returning to NO KEY.

119
00:09:06.448 --> 00:09:11.316
It cancels an unfinished transaction, with ready
and valid low during reset.

120
00:09:11.316 --> 00:09:13.114
Load a new key after release.

121
00:09:13.114 --> 00:09:16.442
This describes functional register clearing.

122
00:09:16.442 --> 00:09:22.373
Product-level key zeroization and side-channel
certification require additional design and

123
00:09:22.373 --> 00:09:23.381
evidence.

124
00:09:23.667 --> 00:09:26.732
Use the standard key and plaintext shown.

125
00:09:26.732 --> 00:09:33.200
The initial XOR produces the displayed sequence
from zero zero, ten, twenty, thirty through E

126
00:09:33.200 --> 00:09:34.264
zero and F zero.

127
00:09:34.264 --> 00:09:42.331
Compare SubBytes, ShiftRows, MixColumns, K one,
and the round-one result in the same packed

128
00:09:42.331 --> 00:09:42.920
order.

129
00:09:42.920 --> 00:09:46.754
The final ciphertext begins sixty nine C four.

130
00:09:46.754 --> 00:09:52.816
A first mismatch at ShiftRows points to
permutation; matching transformations with a

131
00:09:52.816 --> 00:09:55.608
wrong round result point to K one or the XOR.

132
00:09:55.608 --> 00:09:58.207
Inspect the earliest difference.

133
00:09:58.458 --> 00:10:04.232
Check all two hundred fifty six S-box inputs,
then permutation, field arithmetic, normal

134
00:10:04.232 --> 00:10:06.066
rounds, and the final bypass.

135
00:10:06.066 --> 00:10:09.659
Verify key expansion independently before
integration.

136
00:10:09.659 --> 00:10:15.162
Transactions need consecutive blocks, competing
key input, backpressure, and resets.

137
00:10:15.162 --> 00:10:20.810
Record only handshake edges in the scoreboard,
checking values, counts, and order with timeouts.

138
00:10:20.810 --> 00:10:24.766
One correct ciphertext does not exercise these
control cases.

139
00:10:25.042 --> 00:10:28.474
Replace the sixteen data S boxes with one shared
box.

140
00:10:28.474 --> 00:10:34.350
The controller needs intermediate bytes and a
revised schedule, changing the earlier eleven-

141
00:10:34.350 --> 00:10:36.187
and thirteen-cycle figures.

142
00:10:36.187 --> 00:10:42.706
A functional hierarchy does not require a
separate circuit copy at every level, but sharing

143
00:10:42.706 --> 00:10:43.977
must match timing.

144
00:10:43.977 --> 00:10:50.335
Beyond this block primitive, messages need a
suitable mode, nonce or IV rules, key management,

145
00:10:50.335 --> 00:10:51.368
and integrity.

146
00:10:51.368 --> 00:10:58.204
Decryption, buses, pipelines, fault defense, and
side-channel resistance require further work.
