COMIC CLASSROOM

Security FoundationsLesson 2 / 9

AES Comic Classroom: Five Pictures for Modern Encryption

A five-page classroom that explains AES as a repeated encryption workshop: fixed-size data blocks move through substitution, shifting, mixing, and key addition until the plaintext becomes hard to reverse without the key.

8 min read

Think of AES as a strict encryption workshop

AES is easier to read as a repeated workshop process. Data enters in fixed-size blocks, then goes through rounds of substitution, shifting, mixing, and key addition.

The plates explain why the data is scrambled in several different ways instead of only being locked once. Each step makes the relationship between plaintext, key, and ciphertext harder to reverse.

Keep the roles separate: AES protects bulk data, the key controls who can unlock it, and post-quantum cryptography changes public-key tasks rather than replacing AES.

AES Classroom page 1: why encryption matters from Enigma to modern AES
Visual plate 1 from the original classroom sequence.

AES is the modern answer to practical encryption

Data written to an SSD or carried through a VPN should remain unreadable to someone who obtains its bits without the key. AES is a symmetric cipher used for this confidentiality task. Phones, browsers, Wi-Fi and other systems can use AES or AES-based modes at different layers. Establishing who published data and whether it was altered also requires the appropriate authentication and trust checks.

AES is a block cipher. It processes a fixed 128-bit data block, which is 16 bytes, and transforms that block through a sequence of well-defined rounds. The cipher key may be 128, 192, or 256 bits, but the block size remains 128 bits. This separation between block size and key size is one of the first details beginners should keep straight.

The Enigma comparison is useful as history, not as an algorithmic analogy. Enigma showed why encrypted communication can shape real-world outcomes, but AES is a modern public standard designed for rigorous analysis and efficient implementation. Its security does not depend on hiding the design; it depends on the key and on the strength of the standardized transformation.

AES specifies its state, rounds, byte operations and key schedule, with public test vectors for comparison. Engineers can use these rules to organize an RTL data path and its verification. Matching a test vector establishes the result for that case. Formal checks, side-channel hardening and FIPS validation have additional requirements; a correct ciphertext alone does not establish them.

AES Classroom page 2: key expansion, SubBytes, and ShiftRows
Visual plate 2 from the original classroom sequence.

AES prepares the state and the round keys

The second page introduces the AES state. A 128-bit block is arranged as 16 bytes in a 4-by-4 matrix. Many beginner mistakes come from byte order and state mapping, so it is worth treating the state as a real data structure before memorizing formulas.

Key expansion turns the original cipher key into a sequence of round keys. AES-128 uses 10 main rounds plus an initial AddRoundKey step, so the implementation needs enough key material for each stage. The same plaintext block encrypted under a different key should follow a completely different path through the cipher.

SubBytes then replaces each state byte using the S-box. This step is the main source of nonlinearity. Without it, AES would be much closer to a linear transformation, which would be far easier to analyze and attack.

ShiftRows moves bytes horizontally by different offsets. It does not change byte values by itself; it changes where bytes sit in the state. That movement is crucial because the next step, MixColumns, works column by column. ShiftRows makes sure bytes from one column do not stay isolated forever.

An RTL implementation commonly separates key scheduling, S-box lookup, state registers, row shifting and the control FSM. Define the state layout and round counter, then specify when data and round keys are valid and accepted. Misaligned timing can give an incorrect combined result even when individual modules work correctly.

AES Classroom page 3: MixColumns explained with a fixed matrix over AES bytes
Visual plate 3 from the original classroom sequence.

MixColumns creates diffusion across each column

The third page zooms in on MixColumns because it is the AES step that often feels least intuitive. It does not mix bytes randomly. It treats each column as four bytes and multiplies that four-byte vector by a fixed 4-by-4 matrix over the AES finite field.

The result is another four-byte column. Each output byte depends on all four input bytes from the same column. That is diffusion: a change in one byte starts spreading into multiple bytes, and after repeated rounds the influence spreads across the state.

The multiplication symbols in the formula do not mean ordinary integer multiplication. Values such as 02 and 03 are finite-field constants in GF(2^8). In hardware, these operations can be implemented with XOR and conditional reduction logic, which is why AES can be efficient even though the math looks specialized.

Hold one column in view and trace how its four input bytes contribute to each output. Every column uses the same fixed matrix. Then inspect finite-field calculations such as 02 × d4 and 03 × bf, keeping them distinct from integer multiplication. The experiment below lets you stop before and after MixColumns and compare that column’s actual values.

AES Classroom page 4: round operations and AES state transformation
Visual plate 4 from the original classroom sequence.

AddRoundKey ties every round to the secret key

The fourth page should be read as the final piece of a round. SubBytes adds nonlinearity, ShiftRows relocates bytes, MixColumns diffuses within columns, and AddRoundKey XORs the state with the round key. The XOR may look simple, but it is the step that injects secret key material into the state.

For AES-128, the high-level encryption schedule is: initial AddRoundKey, then nine full rounds of SubBytes, ShiftRows, MixColumns, and AddRoundKey, followed by a final round that omits MixColumns. That missing final MixColumns is not an accident; it is part of the standard structure.

Decryption walks the path back using inverse operations and the proper round keys in reverse order. This is why AES is a reversible keyed permutation: with the correct key schedule, ciphertext returns to plaintext; without it, the output should remain computationally useless.

For implementation, AddRoundKey is usually cheap in gates because it is XOR-heavy. The design questions are more about timing, key availability, state-register placement, and whether the core is iterative, partially unrolled, or fully pipelined.

AES Classroom page 5: AES usage and why AES still matters in the PQC era
Visual plate 5 from the original classroom sequence.

AES still matters after post-quantum cryptography

The final page connects AES to real systems. AES is widely used for HTTPS/TLS data protection, Wi-Fi security, VPNs, disk encryption, secure storage, mobile applications, firmware protection, and embedded devices. In many systems, public-key cryptography helps authenticate identities or establish a session key, while AES encrypts the bulk data using that session key.

Post-quantum cryptography does not make AES obsolete. Quantum computers mainly threaten widely deployed public-key schemes such as RSA and elliptic-curve cryptography. Symmetric cryptography is affected differently; increasing symmetric security strength, such as using AES-256 where appropriate, remains a common conservative strategy.

A system can use PQC for key establishment and signatures, then AES for efficient bulk encryption. The tasks differ, so adopting PQC does not require replacing every primitive. Transition designs must still address interoperability and the security assumptions of each component.

IC and firmware teams encounter AES in storage encryption, authenticated encryption modes, key wrapping and accelerators, as well as firmware protection where confidentiality is required. Boot authorization needs its own authenticity and policy checks. The distinction matters when reading test vectors or certification evidence: the AES computation is one part of the system.

References

  1. NIST FIPS 197: Advanced Encryption Standard: The official AES specification; NIST's 2023 update modernized the document but made no technical change to the algorithm.
  2. NIST SP 800-38A: Block Cipher Modes of Operation: Defines common confidentiality modes such as ECB, CBC, CFB, OFB, and CTR for approved block ciphers like AES.
  3. NIST Post-Quantum Cryptography FIPS approval: Official NIST announcement approving FIPS 203, 204, and 205, useful for understanding why PQC mainly changes public-key tasks while AES remains important for bulk data encryption.
  4. NIST PQC Standardization Process: NIST project page summarizing the post-quantum standardization process and the published FIPS 203, 204, and 205 standards.

MY ACADEMY · RTL LAB

Operate AES: inspect every state transformation

Enter one 128-bit block and key. Stop at Round 1 ShiftRows and compare both matrices. Then reach Round 10 and check that MixColumns is omitted.

Matrices use the column-major layout of FIPS 197. Position [row, column] maps to input byte 4×column + row. Each step shows values before and after an operation. These algorithm microsteps do not claim one RTL clock each.

Evidence scope: a browser functional teaching model. Independent comparison uses browser Web Crypto. No RTL simulation, synthesis, formal proof or side-channel testing is performed.

Independent comparison uses the first Web Crypto CBC block with IV=0: C0=AES_K(P0 XOR 0)=AES_K(P0). We compare only its first 16 bytes; a later padding block does not change the first. This checks single-block AES, rather than implementing a message mode in this lab.

QD

Before operation

After operation

Inspect blocks, schedule and round keys

Output handshake: valid / ready

At OUTPUT, the output remains stable. Set ready, then sample an edge to record acceptance. Changing ready alone does not accept data. This handshake is a separately defined teaching interface.

Transfer exercise: may RTL clear output_valid or overwrite the result before downstream is ready? State the hold rule in plain language: unless reset cancels the transaction, valid and data remain stable until a handshake. SVA syntax is an optional next exercise.

FIPS 197 §5.1 / §5.2

Learning guide

Security Foundations

0 / 9

Open the course outline → · Progress counts published lessons only

Prerequisites

  • Binary data and exclusive OR

What I learned

  • Recognize the AES state and round structure
  • Explain substitution, permutation, mixing, and key addition
  • Place AES correctly beside PQC

Key terms

Open glossary →

Further reading

Knowledge check

1. What is the AES block size?
2. Which step is omitted in the final AES round?
3. Does PQC replace AES?

Thanks for reading.

Take the concept with you, not just the terminology.

#AES#AES-128#FIPS 197#Block Cipher#Encryption#Cryptography#Hardware Security#PQC#Post-Quantum Cryptography#Crypto Accelerator#Comic Classroom