I'm trying to implement AES as practice for my C++ skills, but I've come across a confusing problem that I think belongs here rather than in a programming discussion forum.

Rijndael's finite field is $\displaystyle GF(2^8)$, with reducing polynomial $\displaystyle x^8+x^4+x^3+x+1$

There is a step in the algorithm that takes a polynomial $\displaystyle a(x)=a_3x^3+ a_2x^2+a_1x+a_0$ with coefficients in $\displaystyle GF(2^8)$, and multiplies it by a polynomial $\displaystyle s(x)=s_3x^3+ s_2x^2+s_1x+s_0$ and reduces it modulo $\displaystyle x^4+1$, to get $\displaystyle d(x)=d_3x^3+ d_2x^2+d_1x+d_0$

This operation is equivalent, if a is a constant polynomial, according to the text, to the matrix multiplication:

$\displaystyle \left( \begin{array}{c}

d_0 \\

d_1 \\

d_2 \\

d_3 \end{array} \right)=

\left( \begin{array}{cccc}

a_0 & a_3 & a_2 & a_1 \\

a_1 & a_0 & a_3 & a_2 \\

a_2 & a_1 & a_0 & a_3 \\

a_3 & a_2 & a_1 & a_0 \end{array} \right)

\left( \begin{array}{c}

s_0 \\

s_1 \\

s_2 \\

s_3 \end{array} \right)$

it gives the constant polynomial as $\displaystyle a(x)=\{03\}x^3+\{01\}x^2+\{01\}x+\{02\}$, and the inverse polynomial $\displaystyle a^{-1}(x)=\{0b\}x^3+\{0d\}x^2+\{09\}x+\{0e\}$ (all numbers in curly braces are hexadecimal).

Now, being as I'm using a computer to do this, and proper polynomial handling is hard to do, I'm using the matrix multiplication to do the calculation. Now, if I'm thinking about this properly, then the matrix representations of $\displaystyle a(x)$ and $\displaystyle a^{-1}(x)$ should have a product that is a unit matrix. But, if my calculations (done by my program) are correct, then:

$\displaystyle

\left( \begin{array}{cccc}

\{02\} & \{03\} & \{01\} & \{01\} \\

\{01\} & \{02\} & \{03\} & \{01\} \\

\{01\} & \{01\} & \{02\} & \{03\} \\

\{03\} & \{01\} & \{01\} & \{02\} \end{array} \right)

\left( \begin{array}{cccc}

\{0e\} & \{0b\} & \{0d\} & \{09\} \\

\{09\} & \{0e\} & \{0b\} & \{0d\} \\

\{0d\} & \{09\} & \{0e\} & \{0b\} \\

\{0b\} & \{0d\} & \{09\} & \{0e\} \end{array} \right)

$$\displaystyle =

\left( \begin{array}{cccc}

\{01\} & \{00\} & \{e5\} & \{00\} \\

\{00\} & \{01\} & \{00\} & \{e5\} \\

\{e5\} & \{00\} & \{01\} & \{00\} \\

\{00\} & \{e5\} & \{00\} & \{01\} \end{array} \right)

$

Which is almost a unit matrix, but not quite. And, when I use these polynomials to calculate the function, and then the inverse, I get a different polynomial to my input. I checked my matrix multiplication algorithm, it seems to be working fine.

Two other matrices that should have a unit matrix product (for another step in the algorithm) do. I'm definitely doing finite field arithmetic. I'm using a logarithm table for my multiplication, base three, which I know for a fact is a generator. I can't find anything wrong with the procedure, so I'm asking you guys if you could please tell me why it doesn't work.