(Not that this is the only solution but that it motivates the problem of why you can't just naively apply AES to the problem).