Abstract:In this paper,the strength of AES-256 against the related-key impossible differential attack is examined. Firstly,a carefully chosen relation between the related keys is presented,which can be extended to 8-round(even more rounds)subkey differences.Then,a 5.5-round related-key impossible differential is constructed.Finally,an attack on 7-round AES-256 and four attacks on 8-round AES-256 are presented.