AES Candidates: A Survey of Implementations

Rijndael is now the proposed AES, Advanced Encryption Standard, to replace DES as the US cryptographic standard for unclassified data. The current page, created in Summer 1998, was a response to the NIST's appeal to the worldwide research community to make crossanalysis of the AES candidates. It originally contained information about 13 AES candidates (as backuped here), while after the end of the first round, a the version mentioned every (known to me) fast implementation of all the AES finalists (MARS, RC6, Rijndael, Serpent and Twofish). This version is not anymore updated actively, but still available from here. For general information on AES submissions, see links.

NB! I would greatly appreciate any feedbacks to helger(at) On the other hand, please acknowledge me whenever you use the numbers from this table, like I've acknowledged people who've given feedback to me.

Additional information on implementations

A publication by Kazumaro Aoki and Helger Lipmaa, "Fast Implementations of AES Candidates" in AES3 conference gives more information about our Pentium II implementations.(19.03.2000 Note! The data in this paper is slightly oudated, better implementations are available for now. Remark 2: many people have asked me about the availability of our implementations. To avoid unnecessary queries: About Kazumaro's RC6 and Twofish implementations you have to ask himself. My implementations are commercially available.)

Denis Ahrens - Kenneth Almquist - Kazumaro Aoki - Lily Chen - David Crick - Andreas Dandalis - Jim Foti - Brian Gladman - Louis Granboulan - Robert Harley - Rieks Joosten - Chae Hoon Lim -Terje Mathisen - Fabrice Noilhan - Dag Arne Osvik - Richard Outerbridge - Matthew Robshaw - Richard Schroeppel - Serge Vaudenay - Nicholas Weaver - Doug Whiting ...

CAST-256 Crypton DEAL DFC E2 Frog HPC Mars RC6 Rijndael SAFER+ Serpent Twofish

