A test for weak AES keys was added in #465, citing a TCG document stating that a non-weak key must have at least one upper key bit set.
Is it known from where this claim arises? The linked document does not provide citation or reasoning for the claim, and the claim does not appear to be covered by standards like FIPS 197. Has later work established it? If so, it may be useful to document.