The Rijndael book is out !

We finally finished this book. Besides our algorithm, the book also contains a description of all the implementation tricks we know about, a thorough explanation of our design strategy and the underlying motivations, an overview of the cryptanalytic results on reduced versions of Rijndael, an overview of related ciphers, and some more. The book also contains some previously unpublished results on extending Matsui's linear cryptanalysis to ciphers defined in GF(256).

It's published by Springer-Verlag, ISBN 3-540-42580-2.

Rijndael becomes AES

You probably know it already, maybe it's the reason why you're here at this page.

What is Rijndael ?

Rijndael is a block cipher, designed by Joan Daemen and Vincent Rijmen as a candidate algorithm for the AES .
The cipher has a variable block length and key length. We currently specified how to use keys with a length of 128, 192, or 256 bits to encrypt blocks with al length of 128, 192 or 256 bits (all nine combinations of key length and block length are possible). Both block length and key length can be extended very easily to multiples of 32 bits.
Rijndael can be implemented very efficiently on a wide range of processors and in hardware.

The design of Rijndael was strongly influenced by the design of the block cipher Square .


Besides the documents available from this web site, a number of (technical) Rijndael-related papers have been published. We give here an overview.
  1. J. Daemen, V. Rijmen, ``The Block Cipher Rijndael,'' Smart Card Research and Applications, LNCS 1820, J.-J. Quisquater and B. Schneier, Eds., Springer-Verlag, 2000, pp. 277-284.
  2. J. Daemen and V. Rijmen, ``Rijndael, the advanced encryption standard,'' Dr. Dobb's Journal , Vol.~26, No.~3, March 2001, pp.~137--139.
If you are looking for a Rijndael reference, then please use one of these.

Pictures and animations

Being not very at home in the graphical department, we refer you happily to the pictures made by John Savard. Enrique Zabala from Uruguay made a very nice animation (.exe format) showing the operation of Rijndael (error corrected on 29/03/2004).


The following files are available for download: Rijndael is available for free. You can use it for whatever purposes you want, irrespective of whether it is accepted as AES or not.

Other Implementations

Rijndael is used in the digital lecture board, developed at the university of Mannheim. It is also used in a freeware file protection tool called FIVE.

More information and analysis

The NIST AES site contains a multitude of reports covering more topics of the AES/Rijndael than we would have thought possible. Prof. J. von zur Gathen organized two Rijndael seminars at the university of Paderborn (Germany). A lot of interesting material was developed, and is available here.

Rijndael FAQ

  1. How is that pronounced ?
    If you're Dutch, Flemish, Indonesian, Surinamer or South-African, it's pronounced like you think it should be. Otherwise, you could pronounce it like "Reign Dahl", "Rain Doll", "Rhine Dahl". We're not picky. As long as you make it sound different from "Region Deal".
  2. Why did you choose this name ?
    Because we were both fed up with people mutilating the pronunciation of the names "Daemen" and "Rijmen". (There are two messages in this answer.)
  3. Can't you give it another name ? (Propose it as a tweak !)
    Dutch is a wonderful language. Currently we are debating about the names "Herfstvrucht", "Angstschreeuw" and "Koeieuier". Other suggestions are welcome of course. Derek Brown, Toronto, Ontario, Canada, proposes "bob".

