A cryptographic unit includes a first processing unit for determining an
output signal on the basis of the AES algorithm and for determining a
first comparison signal, a second processing unit for determining a
second comparison signal, and a release unit for providing the output
signal, wherein the release unit is designed to perform a defense measure
against an external tapping of the output signal when the first
comparison signal is not related to the second comparison signal in a
predetermined relationship. The first comparison signal is determined in
a different way as compared to the second comparison signal, so that, in
the case of the injection of faults into the cryptographic unit, these
faults may be detected very easily.