Abstract
We describe Constraint Programming (CP) models
to solve a cryptanalytic problem: the chosen key
differential attack against the standard block cipher
AES. We show that CP solvers are able to solve
these problems quicker than dedicated cryptanalysis tools, and we prove that a solution claimed to
be optimal in two recent cryptanalysis papers is not
optimal by providing a better solution