The Rijndael key schedule procedure involves RotWord, SubWord, and XOR, which are all supported by
_mm_aeskeygenassist_si128:
X3[31:0] ← SRC [127: 96];
X2[31:0] ← SRC [95: 64];
X1[31:0] ← SRC [63: 32];
X0[31:0] ← SRC [31: 0];
RCON[31:0] ← ZeroExtend(Imm8[7:0]);
DEST[31:0] ← SubWord(X1);
DEST[63:32 ] ← RotWord( SubWord(X1) ) XOR RCON;
DEST[95:64] ← SubWord(X3);
DEST[127:96] ← RotWord( SubWord(X3) ) XOR RCON;
DEST[VLMAX-1:128] (Unmodified)
However, it does not return a complete round key. For example, instead of simply performing
DEST[31:0] <- SubWord(X1),
I guess we should actually perform
DEST[31:0]<-RotWord(SubWord(X3)) XOR RCON XOR X0.
As a result, after _mm_aeskeygenassist_si128, we developers have to do some extra work before the round key is completely generated.
Why don't the SSE provide a complete AES key generation procedure?