3 ms·
They describe that the attack depends on "minimizing the number of active S-boxes in the key-schedule" and that AES-192 is harder to attack than AES-256 because
by brl 17y ago
They describe that the attack depends on "minimizing the number of active S-boxes in the key-schedule" and that AES-192 is harder to attack than AES-256 because the key schedule has "better diffusion".
I'm guessing that they don't mention AES-128 because the attack simply doesn't work against the 128 bit key schedule for reasons related to the increased difficulty of attacking AES-192 with this technique.