0Pricing
Cryptology Academy · Lesson

AES Structure: Rounds & State Matrix

Walk through SubBytes, ShiftRows, MixColumns, and AddRoundKey.

AES Structure: Rounds & State Matrix is a free Cryptology Academy lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cryptology Academy learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

Welcome

AES is a Substitution-Permutation Network operating on a 4×4 matrix of bytes called the State. Each round applies four operations to transform the state.

The State Matrix

AES loads 16 bytes of plaintext into a 4×4 grid called the State: [b0 b4 b8 b12] [b1 b5 b9 b13] [b2 b6 b10 b14] [b3 b7 b11 b15] All operations transform this matrix.

Number of Rounds

AES-128: 10 rounds. AES-192: 12 rounds. AES-256: 14 rounds. Each round applies SubBytes, ShiftRows, MixColumns, AddRoundKey (except the final round skips MixColumns).

SubBytes: Nonlinear Substitution

SubBytes replaces each byte with its value in the AES S-box — a fixed 256-entry lookup table constructed using GF(2^8) inversion. This is the source of AES nonlinearity and confusion.

AES S-box

The S-box maps 0x00→0x63, 0x01→0x7C, ... Each input byte maps to a unique output byte. Inverse S-box maps back for decryption. No byte maps to itself (0x63 maps to 0x00 in inverse).

ShiftRows: Row Permutation

ShiftRows cyclically shifts each row of the State: Row 0: no shift. Row 1: left 1. Row 2: left 2. Row 3: left 3. This spreads bytes across different columns for the next MixColumns step.

MixColumns: Column Diffusion

MixColumns treats each 4-byte column as a polynomial over GF(2^8) and multiplies it by a fixed matrix. Every output byte depends on all 4 input bytes — providing diffusion.

AddRoundKey

AddRoundKey XORs the State with a 16-byte round key derived from the original key. This is the only step that uses the secret key and the only step that provides secrecy.

Round Structure

Initial: AddRoundKey Rounds 1..N-1: SubBytes → ShiftRows → MixColumns → AddRoundKey Final round: SubBytes → ShiftRows → AddRoundKey (no MixColumns) Decryption applies inverse operations in reverse order.

Wide-Trail Strategy

AES designers used the Wide-Trail strategy to prove resistance to differential and linear cryptanalysis. After 4 rounds, any attack must examine 2^128 possibilities.

AES Hardware Support

Modern CPUs (Intel, AMD, ARM) include AES-NI instructions: AESENC, AESENCLAST, AESDEC. A single CPU instruction does one AES round, making AES extremely fast in hardware.

Quick Check

Which AES operation provides the nonlinearity (confusion) that prevents algebraic attacks?

Recap

You understand AES structure! Next we study key expansion — how a 128-bit key becomes 11 round keys.

Frequently asked questions

Is the “AES Structure: Rounds & State Matrix” lesson free?

Yes — the full text of “AES Structure: Rounds & State Matrix” is free to read here on the web, and the Cryptology Academy course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cryptology Academy course, upgrade to CoddyKit PRO.

What will I learn in “AES Structure: Rounds & State Matrix”?

Walk through SubBytes, ShiftRows, MixColumns, and AddRoundKey. You practise Cryptology Academy with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cryptology Academy?

No prior experience is required. Cryptology Academy on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “AES Structure: Rounds & State Matrix” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cryptology Academy lesson?

Yes. Every Cryptology Academy lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Symmetric Encryption Concepts
  2. AES Structure: Rounds & State Matrix
  3. AES Key Expansion & Key Sizes
  4. Encrypting Files with AES in Practice
← Back to Cryptology Academy