Using a new 4-round impossible differential in AES that allows us to exploit the redundancy in the key schedule of AES-128 in a way more effective than previous work, we present a new impossible differential attack on 7 rounds of this block cipher. By this attack, 7-round AES-128 is breakable with a data complexity of about 2
chosen plaintexts and a time complexity equivalent to about 2
encryptions. This result is better than any previously known attack on AES-128 in the single-key scenario.