Chapter 7: The Data Encryption Standard

Chapter 7 of Trappe & Washington: the Feistel structure and the one-line proof that it is invertible for any round function; the book's simplified 12-bit DES worked by hand through its expander, S-boxes and key schedule; differential cryptanalysis on three rounds and why XORing two plaintexts cancels the key; the full DES with its 64-bit block, 56-bit key and eight S-boxes; the twenty-one-year story of how its key length aged; and password hashing with salts.

Subject: Cryptography · 60 slides · diagram-first lesson

Open the interactive version of this deck

What this lesson covers

The lesson, slide by slide

1. The Data Encryption Standard

Title

Cryptography · Chapter 7

Inside a real block cipher: Feistel rounds, S-boxes, differential cryptanalysis, and the day the key got too short

2. What you will be able to do

Objectives

Chapter 6 treated E_K as a black box. This chapter opens one. DES was the world's standard cipher for twenty years, and it is still the clearest example of how a block cipher is actually built.

Figure (svg): The lifetime of DES from standardisation in 1977 to the EFF DES Cracker in 1998.

Twenty-one years, two recertifications after the weakness was acknowledged, and then three breaks in eighteen months.

3. What has to be true of any block cipher's internals?

Warm-up

A block cipher must be invertible — Chapter 6's correctness requirement. Its round function f, however, does not have to be.

Discussion prompt

How can a cipher be invertible when the function doing the work inside it is not?

Hint: Consider keeping a copy of the input alongside the output.

Answer:

The Feistel trick. Split the block in half. Send only the right half through f, XOR the result into the left half, then swap. The right half comes through untouched, so it is still available on the other side to recompute f.

Written out: L_i = R_{i−1} and R_i = L_{i−1} ⊕ f(R_{i−1}, K_i). To undo it you need f(R_{i−1}, K_i), and R_{i−1} is sitting in L_i — you have it.

The consequence is enormous. f can be as messy and non-invertible as the designer likes: it can compress, it can lose information, it can be a lookup table with no structure at all. The Feistel construction hands back invertibility for free.

That freedom is what lets DES's S-boxes take six bits and return four. A cipher built without the Feistel structure would need every component to be a permutation, which is a severe design constraint — one that AES, in Chapter 8, chooses to accept.

Figure (svg): Two rounds of a Feistel system: the right half goes through f with a round key, XORs into the left half, and the halves swap.

Li = Ri−1 and Ri = Li−1 ⊕ f(Ri−1, Ki). The swap is what makes the whole thing invertible without inverting f.

4. Introduction

Section

Section 7.1 · pp. 136-137

5. Where DES came from

Concept

In the early 1970s the US National Bureau of Standards called for a standard encryption algorithm. IBM submitted a design derived from its Lucifer cipher; the NSA was involved in the evaluation; and the result was adopted in 1977.

Two features of that process shaped the next twenty years of argument:

So the same secrecy produced one decision that weakened the cipher and one that strengthened it, and nobody outside could tell which was which. That is the practical cost of departing from Kerckhoffs's principle at the design-process level.

Figure (svg): The lifetime of DES from standardisation in 1977 to the EFF DES Cracker in 1998.

Twenty-one years, two recertifications after the weakness was acknowledged, and then three breaks in eighteen months.

6. What was public and what was not?

Definition probe

Kerckhoffs's principle says the algorithm should be public. DES mostly complied, with one important exception.

Sort into buckets

Sort each item by whether it was published.

Published
The full algorithm, including every permutation table; The contents of the eight S-boxes; The key schedule
Withheld
The design rationale for the S-box contents; The reason the key was 56 bits
pub
Everything needed to implement DES was public, which is what Kerckhoffs's principle requires — anyone could build it, and anyone could attack it.
sec
The rationale was withheld, and that is a subtler thing to withhold. It did not prevent analysis, but it prevented the community from telling a strengthening from a weakening, which is why the S-box question hung open for two decades.

7. Why the 56-bit decision still matters

Real world

IBM proposed a longer key; the standard shipped with 56 bits. The reason was never published.

Discussion prompt

What did that single decision cost, and what does it teach about setting parameters?

Hint: Count the years between the forecast and the machine.

Answer:

It cost the whole deployed lifetime of the cipher. Diffie and Hellman published a correct cost estimate within months. Twenty-one years later the EFF built the machine for a hundredth of that estimate, and every message ever sent under DES became retrospectively readable by anyone with $200 000.

Retrospective is the important word. Ciphertext recorded in 1985 could be decrypted in 1999. A key length has to survive not the deployment but the confidentiality lifetime of the data, which for medical, legal and intelligence material is decades longer.

And the decision was irreversible in practice. Changing a standard's key length means changing every implementation, every stored ciphertext format and every interoperating partner. Triple DES existed precisely because increasing the number was easier than changing the number.

The rule: choose parameters against the hardware of the year the data stops mattering, not the year the system ships — and build in a way to increase them later. Modern protocols carry algorithm identifiers for exactly this reason.

8. A Simplified DES-Type Algorithm

Section

Section 7.2 · pp. 137-140

9. The Feistel System

Concept

The book's simplified algorithm has a 12-bit message written L₀R₀ with six bits each, and a nine-bit key K. Each round uses an eight-bit round key K_i derived from K.

\[ L_i = R_{i-1}, \qquad R_i = L_{i-1} \oplus f(R_{i-1}, K_i) \]

f takes a six-bit input and an eight-bit key and gives six bits back. Run this for n rounds and the ciphertext is L_nR_n.

Any f whatever produces a working cipher. The security comes entirely from the choice of f; the correctness comes entirely from the structure.

Figure (svg): Two rounds of a Feistel system: the right half goes through f with a round key, XORs into the left half, and the halves swap.

Li = Ri−1 and Ri = Li−1 ⊕ f(Ri−1, Ki). The swap is what makes the whole thing invertible without inverting f.

10. Proving that decryption works

Worked example

To decrypt, start from L_nR_n, switch left and right to get R_nL_n, and run the same procedure with the keys in reverse order K_n, …, K₁.

The first decryption step takes R_nL_n to [L_n][R_n ⊕ f(L_n, K_n)]

Why: Applying the same round formula, with L_n now playing the role of the right half.

From encryption we know L_n = R_{n−1} and R_n = L_{n−1} ⊕ f(R_{n−1}, K_n)

Why: These are the two halves of the round definition.

Substitute: R_n ⊕ f(L_n, K_n) = L_{n−1} ⊕ f(R_{n−1}, K_n) ⊕ f(L_n, K_n)

Why: Two f terms have appeared.

But L_n = R_{n−1}, so those two f terms are identical and XOR to zero

Why: This is the whole proof, and it is one line.

\[ \bigl[L_n\bigr]\bigl[R_n \oplus f(L_n, K_n)\bigr] = \bigl[R_{n-1}\bigr]\bigl[L_{n-1}\bigr] \]

Verify: one step of decryption has undone one step of encryption, with left and right swapped

Why: Repeating gives R₀L₀, and one final swap gives L₀R₀. Sender and receiver use identical machines — the receiver just reverses the inputs. Note this holds for any f, which is the point.

Figure (svg): Two rounds of a Feistel system: the right half goes through f with a round key, XORs into the left half, and the halves swap.

Li = Ri−1 and Ri = Li−1 ⊕ f(Ri−1, Ki). The swap is what makes the whole thing invertible without inverting f.

11. Explain the Feistel trick to a programmer

Explain it

A colleague who writes code but knows no cryptography asks how you can undo an operation built from a function you cannot invert.

Discussion prompt

Explain it in terms they will find obvious, and name the general technique.

Hint: It is the same move as keeping the old value around before you overwrite something.

Answer:

The programming analogy: you want to transform a using a messy function of b, but you must be able to undo it. So you write a ^= f(b) and leave b alone. To undo, you run a ^= f(b) again — b is still there, so f(b) is still computable, and XOR is its own inverse.

That is the whole Feistel construction. Half the block is the a being modified, half is the b being preserved, and the swap at the end just rotates which half plays which role next time.

The general technique is called an involution built from a non-invertible map — and it appears far outside cryptography: in reversible computing, in undo systems that store deltas rather than snapshots, and in the XOR linked-list trick.

The payoff to name: it decouples the security question from the correctness question entirely. The designer of f can pursue confusion and diffusion without ever worrying about invertibility, which is a large amount of design freedom for free.

12. The S-Boxes and the expander

Concept

Now the choice of f, built from three components.

The expander takes six bits to eight, duplicating two of them. The book's example: 011001 expands to 01010101. The first input bit gives the first output bit; the third input bit gives both the fourth and the sixth output bits.

Two S-boxes, each taking four bits and giving three. The first bit picks the row (0 or 1) and the other three, read as a binary number, pick the column. An input of 1010 to S₁ means row 1, column 010 = 2 — the third column — which holds 110.

The round key K_i is eight bits of K starting at position i, wrapping round. With K = 010011001, K₄ = 01100101.

Figure (svg): The two S-boxes of the simplified algorithm, each mapping four input bits to three output bits via a two-row, eight-column table.

Four bits in, three bits out, so an S-box is not invertible on its own — and that is the source of the non-linearity.

13. Computing f(R, K) once

Worked example

Take R = 011001 and K₄ = 01100101.

Expand R: 011001 → 01010101

Why: Six bits to eight, so the round key can be longer than the data — and every key bit gets used.

XOR with the round key: 01010101 ⊕ 01100101 = 00110000

Why: This is where the key enters, and it enters by XOR alone. Remember that for Section 7.3.

Split into two halves: 0011 for S₁, 0000 for S₂

Why: Four bits each.

S₁ on 0011: row 0, column 011 = 3 — the fourth column — giving 110

Why: Reading the table: row 0 is 101, 010, 001, 110, 011, 100, 111, 000.

S₂ on 0000: row 0, column 0 — the first column — giving 100

Why: Row 0 of S₂ is 100, 000, 110, 101, 111, 001, 011, 010.

\[ f(011001, \, 01100101) = 110\,100 \]

Verify: six bits in, six bits out, as the round requires

Why: The expansion to eight and the compression back to six is not wasted motion: it is what lets an eight-bit key act on six bits of data, and the compression is where the S-boxes destroy information.

Figure (svg): The simplified DES round function: six bits expanded to eight, XORed with the round key, split between two S-boxes, and recombined into six bits.

Expand, add key, substitute, recombine. DES's real f is the same four steps with bigger tables.

14. Watch a round execute

Invariant

One Feistel round, with the halves tracked explicitly. This is the loop DES runs sixteen times.

Step through it

Which step would be impossible to undo if the right half had also been modified?

  1. Start with the block split in half.
  2. The right half and the round key go into f. The left half is untouched.
  3. XOR f's output into the left half. Note the right half is still intact — that is what makes this reversible.
  4. Swap. The old right half becomes the new left half, and the round is complete.

The XOR. Undoing it requires recomputing f(R₀, K₁), which requires R₀ — and R₀ survives precisely because the round refuses to touch it.

15. The Feistel round, both directions

Fill the middle

Complete the encryption and decryption formulas.

Fill in the blanks

\textR_{i-1} L_i = reverse, \; R_i = L____ \oplus f(R____, K_i) \qquad \text___ ___ \text___

Why: The left half of the output is simply the previous right half, carried across untouched — that carry is what makes the round invertible, because it preserves the input f needed. Decryption reverses the key order because round i's XOR must be undone by recomputing f with the same round key, and the rounds are undone last-first.

16. What if there were no S-boxes?

Socratic

Suppose f were built from the expander and the key XOR alone, with the S-boxes replaced by a fixed bit permutation.

Discussion prompt

What would the cipher become, and how would you break it?

Hint: Expansion, XOR and permutation are all linear over GF(2). Ask what a composition of linear maps is.

Answer:

Every remaining operation is linear over GF(2). Expansion copies bits, permutation moves bits, XOR adds them mod 2 — all matrix operations. A composition of linear maps is linear, so the whole sixteen-round cipher would be a single affine function of the plaintext and the key.

And a linear cipher falls to linear algebra, exactly as the LFSR did in Chapter 5 and the Hill cipher did in Chapter 6. Enough known plaintext gives a linear system, and solving it recovers the key regardless of the number of rounds.

So the S-boxes carry the entire cryptographic burden. They are the only components that are not linear, and every other part of f exists to move data into and out of them.

Which is also why their design was so contentious. A weak S-box would not merely reduce security a little; it would collapse the cipher onto something close to linear. And it is why Biham and Shamir's discovery — that DES's S-boxes were optimally resistant to differential cryptanalysis — settled a twenty-year argument.

This is the single most important structural fact in the chapter: in a block cipher, look for the non-linear component, because that is the cipher.

17. How many rounds does a Feistel cipher need?

Prediction

The construction works for any number of rounds. DES uses sixteen.

Predict first

Why not three, or four?

  • Three is enough — the proof of invertibility works for any number
  • Each round diffuses a little; too few rounds leave the input-output relation attackable, and Section 7.3 breaks three and four rounds explicitly
  • More rounds make the key longer
  • Sixteen is required by the block size

Correct: Each round diffuses a little; too few rounds leave the input-output relation attackable, and Section 7.3 breaks three and four rounds explicitly

The number sixteen is a design decision with a margin built in: differential cryptanalysis becomes impractical against DES at around fifteen rounds, so sixteen leaves very little room and no more.

Modern designs are far more generous. AES-128 uses ten rounds where about six suffice against known attacks; the extra rounds are cheap and buy margin against attacks not yet discovered.

Why: Invertibility holds for any round count, but security does not. After one round only half the block has changed at all; it takes several rounds before every output bit depends on every input bit and every key bit. Section 7.3 attacks the three-round version and then the four-round version, which is exactly how the round count gets justified — you break the small versions and count how fast the attack degrades.

18. Match each component to what it supplies

Translation

Shannon named two ingredients for a strong cipher in 1949. Every block cipher since is an arrangement of them.

Match the pairs

  • l1. The S-boxes
  • l2. The permutation P after the S-boxes
  • l3. The expansion E
  • l4. Sixteen rounds rather than three
  • r1. Confusion — a complicated, non-linear relation between key and ciphertext
  • r2. Diffusion — each input bit's influence spread across the whole block
  • r3. Lets a 48-bit round key act on 32 bits, and makes adjacent S-boxes share inputs
  • r4. Enough repetition for confusion and diffusion to become complete

Why: Shannon's two ingredients are the whole vocabulary for reading a block cipher: confusion obscures the key-to-ciphertext relation, diffusion spreads local changes globally. Neither alone suffices — S-boxes without P would leave each box's effects trapped in its own four bits forever, and P without S-boxes would be a linear map. The round count is how long you run the pair to get avalanche, where flipping one input bit changes about half the output bits.

19. How fast does one bit spread?

Estimation

The avalanche criterion: flipping one plaintext bit should change about half the ciphertext bits.

Predict first

After how many DES rounds does a single flipped input bit affect every output bit?

  • 1 round
  • About 5 rounds
  • About 12 rounds
  • All 16 are needed

Correct: About 5 rounds

This is why attacks on reduced-round versions are the standard measure of a cipher's health: Section 7.3 breaks three rounds easily and four with more work, and the gap to sixteen is the safety margin.

When a paper announces an attack on '7-round AES', it is reporting a shrinking margin rather than a broken cipher — and that distinction is worth holding on to when reading cryptography news.

Why: One flipped bit in R enters one or two S-boxes via the expansion, whose four-bit outputs are then scattered across the block by P, so the affected set roughly quadruples per round. From 1 bit that reaches all 32 in about five rounds, and full avalanche across both halves takes a little longer. DES's sixteen rounds are therefore about three times what diffusion alone requires — the surplus is margin against cryptanalysis, not diffusion.

20. Differential Cryptanalysis

Section

Section 7.3 · pp. 140-145

21. Differential Cryptanalysis: compare two encryptions

Concept

Introduced publicly by Biham and Shamir around 1990, and — as the S-box story shows — known to DES's designers fifteen years earlier.

The idea: encrypt two carefully chosen plaintexts and compare the difference of the ciphertexts. Over GF(2), difference means XOR.

The leverage comes from where the key enters. The round key is XORed with E(R_{i−1}), so taking the XOR of two inputs removes the key at that stage entirely:

\[ \bigl(E(R) \oplus K\bigr) \oplus \bigl(E(R^*) \oplus K\bigr) = E(R) \oplus E(R^*) \]

The randomness the key was supposed to introduce cancels, and what remains is a relation between differences that the attacker can compute — while the S-boxes' difference behaviour is not uniform, which is what leaks key bits back.

Figure (svg): Differential cryptanalysis on three rounds: choosing two plaintexts with equal right halves cancels the first round's f, so the difference propagates predictably.

The key is introduced by XOR, so taking the XOR of two inputs removes it — which is exactly the leverage the attack uses.

22. Three rounds, with the right halves equal

Worked example

The book starts at L₁R₁ and attacks a three-round device by chosen plaintext. Write X′ for X ⊕ X*.

Choose two inputs L₁R₁ and L₁R₁ with R₁ = R₁*

Why: Only the left halves differ. This is the choice that makes everything cancel.

Since R₁ = R₁, we have f(R₁, K₂) = f(R₁, K₂), so those terms XOR to 0

Why: Round two's contribution to the difference vanishes completely — the attacker has cancelled a whole round.

Working through: R₄′ = L₁′ ⊕ f(R₃, K₄) ⊕ f(R₃*, K₄)

Why: The difference at the output depends only on round four's f.

Rearrange: R₄′ ⊕ L₁′ = f(R₃, K₄) ⊕ f(R₃*, K₄)

Why: The left side is entirely known — the attacker chose L₁′ and observed R₄.

And R₃ = L₄, R₃* = L₄, both observed. So R₄′ ⊕ L₁′ = f(L₄, K₄) ⊕ f(L₄, K₄)

Why: Every quantity except K₄ is known.

Verify: one equation, one unknown round key

Why: Now guess the six bits of K₄ that feed each S-box in turn and keep the guesses consistent with the observed difference. Collecting enough pairs leaves one candidate. The attack isolates one round key at a time, which is what makes it feasible.

Figure (svg): Differential cryptanalysis on three rounds: choosing two plaintexts with equal right halves cancels the first round's f, so the difference propagates predictably.

The key is introduced by XOR, so taking the XOR of two inputs removes it — which is exactly the leverage the attack uses.

23. Why non-uniform S-boxes leak

Cost model

The attack needs the S-boxes to behave non-uniformly on differences. Here is the quantity that matters.

Annotate

On: \( \Pr\bigl[S(x) \oplus S(x \oplus \Delta) = \delta\bigr] \)

  • The input difference the attacker arranges. She controls this, because she chooses the plaintexts.
  • The output difference she observes. She does not control it, but she can see it.
  • Every δ equally likely for every Δ, and the observation would tell her nothing. There would be no attack.
  • For any real S-box the table is lumpy — some (Δ, δ) pairs occur far more often than 1/16. Each high-probability pair is a usable clue, and chaining them across rounds is called a differential characteristic.
  • Choose S-boxes minimising the largest entry of this table. DES's S-boxes are near-optimal by this measure, which is what Biham and Shamir discovered — and it is why the modification in 1975 was a strengthening.

This is the first attack in the book where the contents of a lookup table, rather than the structure around it, decide whether a cipher stands.

24. An attack the designers already knew about

Anomaly

The NSA changed IBM's S-boxes in 1975 and refused to say why. For fifteen years this was widely read as a possible back door.

Predict first

What did Biham and Shamir's 1990 paper reveal?

  • A back door, confirming the suspicion
  • That the modified S-boxes were near-optimally resistant to differential cryptanalysis — the change strengthened the cipher
  • That the S-boxes were irrelevant to security
  • That the original IBM S-boxes were stronger

Correct: That the modified S-boxes were near-optimally resistant to differential cryptanalysis — the change strengthened the cipher

Two lessons pull in opposite directions and both are worth holding.

In favour of the process: the design was genuinely good, and better than the public state of the art by fifteen years.

Against it: nobody outside could tell. The identical secrecy that concealed a strengthening would have concealed a weakening, and the community had no way to distinguish them — which is why the 56-bit key, a real weakening made in the same process, was defended by the same people using the same authority.

AES's open competition in Chapter 8 is the direct institutional answer to exactly this.

Why: The changed S-boxes resist differential cryptanalysis about as well as any 6-to-4 bit S-boxes can, which means the designers knew about the attack in 1975 and had optimised against it. Fifteen years of public suspicion was aimed at a decision that had made the cipher better.

25. Why does the attack cancel the key?

Explain it to yourself

Differential cryptanalysis works because the round key is combined with the data by XOR.

Discussion prompt

Explain why that specific choice of combining operation makes the attack possible, and what a designer could do instead.

Hint: Write E(R) ⊕ K and E(R*) ⊕ K, and XOR them.

Answer:

XOR is its own inverse and is associative and commutative, so (E(R) ⊕ K) ⊕ (E(R) ⊕ K) = E(R) ⊕ E(R). The key appears twice and cancels exactly, leaving a relation the attacker can compute without knowing it.

Any group operation has this property. Modular addition would too: (x + K) − (y + K) = x − y. So switching to addition mod 2³² does not remove the attack; it only changes what 'difference' means, and there is a whole literature on differentials modulo addition.

What actually helps is making the key interact non-linearly with the data — key-dependent S-boxes as in Blowfish, or the key-dependent rotations in RC5, so that the difference does not survive in a usable form.

But the standard answer is different: keep the cheap XOR and make the S-boxes' difference distribution as flat as possible, so the surviving relation is uninformative. That is what DES does, and what AES does. The attack is not prevented; it is made to cost more than exhaustive search.

Which is the honest general position in this subject: most defences raise a cost rather than closing a door.

26. Which attack would you fund?

Commit first

It is 1996 and you have a budget to demonstrate DES's weakness. Three approaches are on the table.

Predict first

Which gives the most convincing public demonstration?

  • Distributed volunteer computing across the internet
  • Custom hardware built specifically to search DES keys
  • Programmable logic arrays as a middle path
  • Further research into differential cryptanalysis

Correct: Custom hardware built specifically to search DES keys

The book notes the three approaches explicitly, and that programmable logic arrays received the least attention. In hindsight they became the standard tool: COPACOBANA and its successors are FPGA machines.

Note that option four was a losing bet for a reason worth remembering — twenty years of cryptanalysis never beat exhaustive search on full DES. The design was sound and the parameter was not, so the demonstration had to attack the parameter.

Why: Distributed computing proved it was possible but took months and depended on volunteers, so it was easy to dismiss as a stunt. Custom hardware answered the actual policy argument: the EFF's $200 000 machine showed that a single moderately funded organisation — not a government, not the internet — could recover any DES key on demand. That is what ended the debate.

Figure (svg): The falling cost of a DES key search, from a twenty-million-dollar estimate in 1977 to a two-hundred-thousand-dollar machine in 1998.

A fixed key length against twenty years of Moore's law — the one attack whose cost you can forecast, and DES was forecast correctly in 1977.

27. DES Itself

Section

Section 7.4 · pp. 145-152

28. DES: sixteen rounds on a 64-bit block

Concept

A 64-bit plaintext block. A key of 56 bits, written as 64 bits — every eighth bit is a parity bit, set so each byte has an odd number of ones, for error detection. The ciphertext is 64 bits.

  1. Permute the plaintext by a fixed initial permutation: m₀ = IP(m), split into L₀ and R₀ of 32 bits each
  2. For i = 1 to 16: L_i = R_{i−1}, R_i = L_{i−1} ⊕ f(R_{i−1}, K_i), where K_i is 48 bits derived from K
  3. Swap to get R₁₆L₁₆, then apply IP⁻¹ to obtain the ciphertext

The initial permutation has no cryptographic significance — the book suggests it was there to help the algorithm load efficiently into 1970s chips. And because the final swap is built into step 3, decryption needs no extra swap, unlike the simplified version.

Figure (svg): The full DES structure: initial permutation, sixteen Feistel rounds with 48-bit round keys, a final swap, and the inverse permutation.

Three stages, and the middle one is the only one that does cryptographic work.

29. One S-box lookup in the real DES

Worked example

The round function f(R, K_i) in four steps, with the book's own example.

Expand R from 32 bits to 48 by the table E, duplicating 16 of the bits

Why: The first bit of E(R) is the 32nd bit of R — the expansion wraps around, which is how adjacent S-boxes come to share input bits.

Compute E(R) ⊕ K_i, 48 bits, and split into eight six-bit pieces B₁ … B₈

Why: One piece per S-box. Again the key enters only by XOR.

For B₃ = 001001: the row is b₁b₆ = 01, the second row; the column is b₂b₃b₄b₅ = 0100 = 4, the fifth column

Why: The outer bits pick the row and the inner four pick the column — an unusual arrangement, and it is what makes neighbouring S-boxes overlap usefully.

S₃ holds 3 at that position, and 3 in binary is 0011

Why: Six bits in, four bits out.

Concatenate C₁ … C₈ to get 32 bits, then apply the permutation P

Why: P spreads each S-box's four output bits across the block so they feed different S-boxes next round — this is the diffusion.

Verify: 32 bits in, 32 bits out, as the Feistel round requires

Why: And count the information: 48 bits of key material acted on 32 bits of data, and 48 bits of intermediate value were compressed to 32. That compression is irreversible, which is exactly what the Feistel structure allows.

Figure (svg): The DES round function: 32 bits expanded to 48, XORed with the round key, split into eight six-bit pieces, through eight S-boxes to 32 bits, then permuted.

Expansion makes the key longer than the data it masks, and the S-boxes shrink it back — the compression is where information is destroyed.

30. Reading the DES key figures

Notation

Three numbers get quoted about DES and they are easy to confuse.

Annotate

On: \( 64 \text{-bit key string}, \quad 56 \text{ effective key bits}, \quad 48 \text{-bit round keys} \)

  • How the key is written and stored. Eight of these bits are parity — one per byte, set for odd parity — and carry no key information at all.
  • The actual key size, and the number that decides brute-force cost: 2⁵⁶ ≈ 7.2 × 10¹⁶. This is the number Diffie and Hellman objected to in 1977.
  • The size of each round key K_i, selected from the 56 by the key schedule. Sixteen rounds × 48 bits = 768 bits of round key material, all derived from the same 56.
  • Each round key uses 48 of the 56 bits, so each round omits eight — and which eight rotates round. That is why differential cryptanalysis can isolate round keys and then reassemble the master key.
  • Error detection on key entry, in an era of punched cards and manual key distribution. It is a fair reminder that 8 of 64 bits went to an operational concern rather than a cryptographic one.

When someone says DES has a 64-bit key, they are quoting the storage format. The security number is 56.

31. Which parts of DES do cryptographic work?

Discrimination

Not every component of a cipher contributes to its strength, and DES makes the distinction unusually clear.

Sort into buckets

Sort each component.

Contributes to security
The eight S-boxes; The expansion E; The permutation P after the S-boxes; The XOR of the round key
No cryptographic role
The initial permutation IP; The parity bits in the key
crypto
The S-boxes supply the only non-linearity. E lets a 48-bit key act on 32 bits of data and makes adjacent S-boxes share inputs. P spreads each S-box's output across the block so it reaches different S-boxes next round — that is the diffusion. And the key XOR is how the key enters at all.
none
IP and IP⁻¹ are public, fixed and invertible, so an attacker simply undoes them; the book suggests they were an implementation convenience for 1970s hardware. The parity bits are error detection on key entry and carry no key information.

32. Order these by how much they weakened DES in practice

Ranking

Several criticisms were made of DES over its lifetime. Rank them by actual impact.

Put in order

  1. The 56-bit key length
  2. The 64-bit block size
  3. The unexplained S-box changes
  4. The cryptographically pointless initial permutation

Why: The key length is what actually broke DES, exactly as forecast. The block size is a real second-order problem: with 64-bit blocks, the birthday bound of Chapter 12 makes a repeated ciphertext block likely after about 2³² blocks — 32 GB — which is the Sweet32 attack, and it is why AES uses 128-bit blocks. The S-box changes turned out to be a strengthening. And IP has no effect at all: it is public and invertible, so an attacker simply undoes it.

33. Where does triple DES sit now?

Edge cases

Triple DES gave about 112 bits of security and stayed in use long after single DES died — in payment terminals especially.

Discussion prompt

Why was it eventually retired too, given that 112 bits is beyond exhaustive search?

Hint: Chapter 6 ranked the modes; this is about the parameter that triple encryption does not change.

Answer:

Triple encryption changes the key length and not the block size. 3DES still operates on 64-bit blocks, so the birthday bound still bites at about 2³² blocks under one key.

That is the Sweet32 attack (2016). With 32 GB of traffic under a single key — an afternoon on a long-lived HTTPS connection — a repeated ciphertext block becomes likely, and in CBC mode a repeat reveals the XOR of two plaintext blocks. Session cookies were recovered this way.

So the retirement had nothing to do with the 112-bit key. NIST disallowed 3DES for new applications in 2017 and deprecated it entirely, on block-size grounds.

The general lesson, and it is the chapter's lesson generalised: a cipher has several parameters, and strengthening one does nothing for the others. Multiple encryption addresses key length alone, and the block size travels unchanged into every construction built on top.

Which is why AES specified a 128-bit block from the start, even though nothing then in view required it.

34. Breaking DES

Section

Section 7.5 · pp. 152-155

35. Twenty-one years, and one number that never changed

Concept

DES was the standard for the last two decades of the twentieth century, and the argument about its key length started immediately.

The pattern is not that anyone was wrong about the mathematics. Everyone agreed 2⁵⁶ was searchable eventually. The disagreement was about when, and the standard was recertified twice while the answer approached.

Figure (svg): The lifetime of DES from standardisation in 1977 to the EFF DES Cracker in 1998.

Twenty-one years, two recertifications after the weakness was acknowledged, and then three breaks in eighteen months.

36. Three ways to search 2⁵⁶ keys

Worked example

By 1996 three approaches to attacking a symmetric cipher had been formulated, and DES was the test case for all three.

Distributed computation across many volunteer machines — cheap, and the cost spreads over many people

Why: The 1997 DES Challenge: RSA Data Security offered $10 000. Rocke Verser's program ran on thousands of internet-connected machines, splitting the prize 60/40 with whoever's machine found the key.

The winning key was found by Michael Sanders after five months, with about 25% of the key space searched

Why: The plaintext read: Strong cryptography makes the world a safer place.

DES Challenge II, the following year: 85% of the key space searched, in 39 days

Why: Won by Distributed Computing Technologies; the message was Many hands make light work. More of the space searched, in a fifth of the time — one year of hardware progress.

Custom architecture — the high-end approach, and the one Diffie and Hellman had costed in 1977

Why: In summer 1998 the Electronic Frontier Foundation built the DES Cracker on a $200 000 budget: a PC, software, and a large array of specialised chips exploiting the fact that exhaustive search is perfectly parallel.

Verify: compare the EFF's $200 000 with the 1977 estimate of $20 million

Why: A factor of one hundred over twenty-one years, which is close to what Moore's law predicts. Diffie and Hellman's 1977 analysis was not alarmist; it was a correct forecast that took two decades to come due, and DES was recertified twice in the meantime.

Figure (svg): The falling cost of a DES key search, from a twenty-million-dollar estimate in 1977 to a two-hundred-thousand-dollar machine in 1998.

A fixed key length against twenty years of Moore's law — the one attack whose cost you can forecast, and DES was forecast correctly in 1977.

37. How long would a DES search take today?

Estimation

2⁵⁶ ≈ 7.2 × 10¹⁶. A modern GPU can try on the order of 10⁹ DES keys per second, and a modest cluster might field a thousand of them.

Predict first

Roughly how long?

  • A few years
  • A few months
  • About a day
  • A few minutes

Correct: About a day

Purpose-built FPGA machines such as COPACOBANA have done it in days for a few thousand dollars, and cloud rental makes the marginal cost of a single DES key recovery genuinely small.

This is why triple DES was standardised as a bridge and why AES exists. And it is why 56 bits is not a lesson about DES but about forecasting: a key length must survive not today's hardware but the hardware of the system's whole deployed lifetime.

Why: 10⁹ × 1000 = 10¹² keys per second, and 7.2 × 10¹⁶ / 10¹² ≈ 72 000 seconds, which is about twenty hours. So a rented cluster now does in a day what a $200 000 purpose-built machine did in 1998 — and what Diffie and Hellman costed at $20 million in 1977. The key length was the only thing that never moved.

Figure (svg): The falling cost of a DES key search, from a twenty-million-dollar estimate in 1977 to a two-hundred-thousand-dollar machine in 1998.

A fixed key length against twenty years of Moore's law — the one attack whose cost you can forecast, and DES was forecast correctly in 1977.

38. What each extra key bit buys

Scale up

Key length is the one security parameter whose cost curve is honestly predictable. Watch it move.

Step through it

Why did key sizes stop at 128 rather than continuing upward?

  1. One row per key size, at a rate a modern cluster can actually reach.
  2. Forty bits — the export-restricted size of the 1990s, and effectively no protection at all.
  3. DES. Twenty hours on rented hardware.
  4. Eight more bits multiplies the time by 256 — seven months instead of a day.
  5. AES-128. Ten billion times the age of the universe, and the reason key sizes stopped growing here.

Because the curve is exponential and the cost of using a longer key is linear. Once the search time passes the age of the universe by a wide margin, further bits buy nothing that any adversary could ever have consumed — so the remaining risk is entirely in attacks that are not exhaustive search.

39. DES was broken, so its design was flawed

Trap

The trap

The trap. DES fell in 1998 and was retired. Therefore its design was bad, and the lesson is to distrust ciphers of that era.

This is the natural reading of any headline about a cipher being broken, and it gets both halves of the story wrong.

The fix

Why it fails. DES was never broken by cryptanalysis. Twenty years of the best public and private effort produced differential and linear cryptanalysis, and neither gave a practical improvement over exhaustive search on the full sixteen rounds. Against the attack that actually matters, the design held completely.

What fell was the key length — a parameter chosen in 1975 against 1975 hardware, and correctly forecast as inadequate within months of publication. That is a specification failure, not a design failure, and the two have completely different remedies.

Indeed the design was better than anyone outside knew: the S-boxes were optimised against an attack that would not be published for fifteen years.

The distinction matters practically. A design flaw means the algorithm must be replaced. A parameter that has aged means the parameter must be increased — which is why triple DES was a usable bridge, and why AES-128 versus AES-256 is a live choice rather than a fix.

The habit to build: when a system is broken, ask which part failed. 'DES is broken' has hidden a correct twenty-year forecast behind a headline.

40. What is missing from "we use DES"?

Missing information

A 1995 system specification reads: "All traffic is encrypted with DES."

Discussion prompt

Using Chapters 5, 6 and 7 together, list what the sentence does not say — and which gap you would chase first.

Hint: Chapter 6 supplies most of the questions; this chapter supplies one more.

Answer:

Which mode? ECB leaks the pattern of equal blocks; CBC needs a random unpredictable IV; CTR needs a non-repeating nonce. The sentence names a primitive and omits everything about how it is used.

Is there integrity protection? None of Chapter 6's modes provides it, and without a MAC the padding check becomes an oracle.

Where do the keys come from? Chapter 5's lesson — a DES key drawn from a time-seeded generator has perhaps 2²⁵ possibilities rather than 2⁵⁶.

How long is a key used? With a 64-bit block, the birthday bound makes block repeats likely after 32 GB under one key, so rekeying is a requirement rather than hygiene.

And the chapter's own question: 56 bits, in what year? In 1995 this was defensible-but-argued; by 1999 it was indefensible. A specification that names an algorithm without a review date has no way to express that.

Which to chase first: the mode. It is the gap most likely to be catastrophic today, whereas the key length was catastrophic on a twenty-year schedule.

41. Salt, pepper, IV, nonce — which is which?

Discrimination

Four public-or-secret values with confusingly similar jobs. The distinctions are worth getting straight once.

Sort into buckets

Sort each by whether it must be secret.

Public — only needs to be unique
A password salt; A CBC initialization vector; A CTR nonce
Secret
A password pepper; A DES round key
pub
Salts, IVs and nonces are all stored or transmitted in the clear. Their job is uniqueness, not secrecy: they exist so that identical inputs produce different outputs, which defeats precomputation and pattern leakage. Note the IV has the extra requirement of being unpredictable, which uniqueness alone does not give.
sec
A pepper is a secret value held outside the password database, so a database leak alone is not enough to mount a dictionary attack. A round key is derived from the master key and is as secret as it is.

42. Password Security

Section

Section 7.6 · pp. 155-157

43. Password Security: never store the password

Concept

A system must check a password without being able to reveal it — including to whoever holds the disk. The answer is to store a one-way function of it.

\[ \text{store } h = H(\text{password}), \quad \text{check } H(\text{offered}) \overset{?}{=} h \]

Early Unix used DES for H, encrypting a constant with the password as key, iterated 25 times. The property required is Chapter 5's one-wayness: cheap forwards, infeasible backwards.

But a hash alone is not enough. If two users choose the same password they get the same hash, so the file leaks which accounts share a password — and an attacker can hash a dictionary once and compare against every account at the same time.

The fix is a salt: a random value stored alongside the hash and mixed in before hashing. Now identical passwords hash differently, and a dictionary must be re-hashed per account.

Figure (svg): Password storage: the password is hashed with a salt, and only the salt and hash are stored.

Verification recomputes the hash from the offered password and the stored salt; a match is the whole test.

44. Why the salt does the work it does

Worked example

Count the attacker's cost with and without one. Suppose a file has 10 000 accounts and the attacker has a 10 million word dictionary.

Without a salt: hash each dictionary word once — 10⁷ hashes total

Why: Then compare each result against all 10 000 stored hashes with a lookup. The comparison is free.

So 10⁷ hashes break every account in the file simultaneously

Why: The work is independent of the number of accounts, which is the disaster.

With a distinct salt per account: each word must be hashed once per salt

Why: 10⁷ words × 10⁴ salts = 10¹¹ hashes — ten thousand times more work.

And a precomputed table is useless, because it would have to be built per salt

Why: This kills rainbow tables outright: the table's whole value is being computed once and reused, and a salt destroys the reuse.

Verify: the salt is stored in the clear and is not secret

Why: It does not need to be. Its only job is to be different per account, which forces the attacker's work to scale with the number of accounts rather than the size of the dictionary. This is the same idea as an IV in Chapter 6 — public, non-secret, and required to be unique.

Figure (svg): Password storage: the password is hashed with a salt, and only the salt and hash are stored.

Verification recomputes the hash from the offered password and the stored salt; a match is the whole test.

45. Find the problems in this password scheme

Error analysis

From a code review.

Annotate

  • One dictionary pass breaks the whole file at once, and precomputed rainbow tables apply directly. The cost of an attack becomes independent of how many accounts there are.
  • A feature built on the leak. The hash file is now explicitly an equality oracle over passwords, which is ECB's failure mode moved to a new context.
  • Exactly backwards. Password hashing should be deliberately slow — bcrypt, scrypt, Argon2 — because the defender hashes once per login and the attacker hashes billions of times. SHA-256 is fast, which serves the attacker.
  • A comparison that returns early leaks, through timing, how many leading bytes matched. Use a constant-time comparison.

The one correct decision — not storing plaintext — is undone by all four of the others.

46. Password storage today

Real world

The book's account is the 1970s Unix scheme. The principles survive; the parameters have moved a long way.

Discussion prompt

What has changed since DES-based crypt, and what is the reason for each change?

Hint: Think about what got cheap, and what defence follows from that.

Answer:

Deliberately slow hashes. bcrypt, scrypt and Argon2 replace a fast hash with a tunable work factor. The defender pays once per login — a hundred milliseconds is invisible to a user — and the attacker pays it per guess, per account.

Memory-hard functions. scrypt and Argon2 also require substantial memory, which specifically defeats GPUs and custom hardware. A GPU has thousands of cores and comparatively little memory per core, so making the function memory-hungry removes the attacker's main hardware advantage.

Longer salts, always unique. 128 bits, random per account, stored in the clear alongside the hash.

A pepper, sometimes: a secret value stored separately from the database — in an HSM or the application config — so that a database leak alone is not enough.

And the reason for all of it: GPUs made hashing thousands of times cheaper without making logins any more frequent. The defence had to become expensive in a way that scales with the attacker's advantage, and the old scheme had no dial to turn.

The through-line from the book's account is intact: never store the password, always salt, and make the attacker pay per guess.

47. Design a password system under real constraints

Constraint

You are storing credentials for 50 million users. Logins peak at 20 000 per second. The database will eventually leak — assume it.

Discussion prompt

Choose a hashing scheme and its parameters, and justify each choice against a specific attack.

Hint: Work out the defender's budget per login first; it bounds everything else.

Answer:

Start from the defender's budget. 20 000 logins per second across the fleet, and a login must feel instant. That allows perhaps 100 ms of hashing on a dedicated core, which sets the work factor — not a security preference, an arithmetic constraint.

Choose a memory-hard function: Argon2id or scrypt. The attacker's advantage is GPUs and custom hardware, both of which have many cores and little memory per core. Requiring 64 MB per hash removes most of that advantage, where a plain iterated SHA-256 does not.

A 128-bit random salt per user, stored in the clear. This forces the attacker to attack accounts one at a time rather than the whole file at once, and it kills rainbow tables. Cost to you: 16 bytes per row.

A pepper held in an HSM or application config, outside the database. Then a database-only leak — the commonest kind — leaves the attacker unable to test guesses at all.

Constant-time comparison, so the check does not leak how many bytes matched.

And a rehash-on-login path, so the work factor can be raised as hardware improves without forcing a password reset. That is the DES lesson applied: build in a way to increase the parameter later, because you will need to.

48. Complete the DES specification

Faded example

Fill in the numbers. These are the ones that get quoted, and misquoted.

Fill in the blanks

DES encrypts a block of 64 bits under a key with 56 effective bits, stored as 64 with the remainder used for parity. It runs 16 Feistel rounds, each using a round key of 48 bits, and each of the eight S-boxes takes six bits to four.

Why: The 64/56 distinction is the one most often garbled: 64 is the storage format and 56 is the security parameter, with one parity bit per byte set for odd parity. The 6-to-4 compression in the S-boxes is what makes them non-invertible, and it is only possible because the Feistel structure does not require the round function to be invertible.

49. Feistel against substitution-permutation

Trade off

Two ways to build a block cipher. Fill the blanks — Chapter 8 takes the other road.

Comparison matrix

Feistel (DES)Substitution-permutation (AES)
Block processed per roundhalfall of it
Must the round function be invertible?noyes — every layer is inverted to decrypt
Encryption and decryption codethe same, with keys reverseddifferent — each layer needs its inverse
Rounds needed for full diffusionmore — half the block is idle each roundfewer — every byte moves every round
Design freedom in the round functiontotalconstrained to permutations

The third row is the practical one: a Feistel cipher needs one piece of hardware for both directions, which mattered enormously in 1975 and much less now. AES pays for two code paths and gets faster diffusion in return.

50. The whole cipher on one slide

Picture it

Three stages, sixteen rounds, and only one of the three stages does cryptographic work. Fix the shape in mind before comparing it with AES.

Figure (svg): The full DES structure: initial permutation, sixteen Feistel rounds with 48-bit round keys, a final swap, and the inverse permutation.

Three stages, and the middle one is the only one that does cryptographic work.

The initial and final permutations are public and invertible, so an attacker peels them off for free. Everything that matters happens between them, one Feistel round at a time.

51. Make the S-boxes linear and watch it collapse

Counterexample

Suppose someone replaced DES's S-boxes with linear ones — each output bit a fixed XOR of input bits — keeping everything else identical.

Discussion prompt

Show that the resulting sixteen-round cipher is breakable with a modest amount of known plaintext, and say how much.

Hint: Compose the operations and ask what kind of function the whole cipher is.

Answer:

Every operation becomes linear over GF(2). Expansion copies bits, permutation moves them, XOR adds them, and now the S-boxes are linear too. A composition of linear maps is linear, so the entire cipher is an affine function of the plaintext and the key.

Write it as a matrix. c = A·m ⊕ B·k for fixed public matrices A and B, since IP, E, P and the S-boxes are all published. The only unknown is the 56-bit key vector k.

So each known plaintext-ciphertext pair gives 64 linear equations in 56 unknowns. One pair over-determines the system, and Gaussian elimination over GF(2) recovers the key in microseconds.

Sixteen rounds do not help at all — a composition of sixteen linear maps is still one linear map. The round count buys nothing against an attack that does not care about depth.

This is why Section 7.3's discovery matters so much: the S-boxes are not one component among many, they are the only thing standing between DES and a linear system. It is the same lesson the LFSR taught in Chapter 5 and the Hill cipher in Chapter 6, arriving for the third time.

52. Which chapter's tool breaks each cipher?

Sorting

Retrieval across the course so far. Every one of these has fallen to a specific technique.

Sort into buckets

Sort each broken system by what broke it.

Language statistics
The Vigenère cipher; A reused one-time pad
Linear algebra
A length-31 LFSR keystream; The Hill cipher
Exhaustive key search
Full DES
Differential cryptanalysis
Three-round simplified DES
stat
Vigenère needs the key length found by coincidence counting first, then per-column frequency analysis. A reused pad reduces to M₁ ⊕ M₂, which is the same language problem with no key in it.
lin
Both are linear in their state or key, so 2m keystream bits or n known blocks give a solvable system. Depth and period are irrelevant to either.
brute
Twenty years of cryptanalysis produced nothing practical against full DES, so the attack that worked was the one the design could not avoid — searching 2⁵⁶ keys.
diff
Chosen plaintext pairs with equal right halves cancel a round's contribution to the difference, isolating one round key. It works on the reduced-round versions and becomes impractical by sixteen rounds.

Four techniques, six systems, and only one fell to brute force — which is Chapter 1's argument, now with six data points behind it.

53. How to read any block cipher

Pattern

DES is the template. Every block cipher you meet — AES in the next chapter, and everything since — answers the same five questions.

  1. What is the non-linear component? DES: the eight S-boxes. Without it the cipher is a linear map and falls to linear algebra, as Chapters 5 and 6 both showed.
  2. How does the key enter? DES: XOR with the expanded half-block, once per round. XOR is the cheapest possible mixing, and it is precisely what differential cryptanalysis cancels.
  3. What provides diffusion? DES: the permutation P after the S-boxes, spreading each box's output into different boxes next round. Without diffusion, a change stays local and can be tracked.
  4. How many rounds, and why that many? DES: sixteen, set so that differential cryptanalysis is impractical — with very little margin.
  5. What is bookkeeping? DES: IP, IP⁻¹, the parity bits. Identify these and stop thinking about them.

Run those five questions over Chapter 8's AES and the comparison writes itself — different answers to every one, and the same five questions.

Figure (svg): The full DES structure: initial permutation, sixteen Feistel rounds with 48-bit round keys, a final swap, and the inverse permutation.

Three stages, and the middle one is the only one that does cryptographic work.

54. DES against what replaced it

Comparison

Fill the blanks. Chapter 8 is the right-hand column.

Comparison matrix

DESAES
Block size64 bits128 bits
Key size56 bits128, 192 or 256 bits
StructureFeistel — half the block per roundsubstitution-permutation — the whole block per round
Non-linear parteight different S-boxes, 6 bits to 4one S-box, 8 bits to 8, from inversion in GF(2⁸)
Design processclosed, rationale withheldopen competition with published rationale

The last row is the one with the longest consequences: DES's closed process produced a good cipher nobody could verify, and cost fifteen years of suspicion over a decision that had helped.

55. Check: why the Feistel structure works

Check

Work it out before you click.

Check your understanding

In a Feistel cipher, what must be true of the round function f?

  • A. It must be invertible
  • B. Nothing — any function gives a working cipher; f decides only the security (correct)
  • C. It must be linear
  • D. It must be a permutation of the half-block

Answer: B

Why: The structure supplies invertibility on its own: the right half passes through untouched, so f's input is still available on the other side to be recomputed. The book states this directly — any f works in the procedures, but some choices give much better security. That freedom is what lets DES's S-boxes take six bits and return four.

Why A tempts people
The commonest misconception, and the Feistel construction exists precisely to remove this requirement. DES's S-boxes are not invertible, and the cipher is.
Why C tempts people
The opposite of what is wanted. A linear f makes the whole cipher linear and breakable by solving a system — the failure mode of the LFSR and the Hill cipher.
Why D tempts people
A stronger form of A, and equally unnecessary. AES does require its components to be permutations, but that is because AES is not a Feistel cipher.

56. Check: the S-box lookup

Check

Use the book's row-and-column convention for the real DES.

Check your understanding

A six-bit input B = 101100 arrives at a DES S-box. Which row and column are used?

  • A. Row 10, column 1100
  • B. Row 10, column 0110 (correct)
  • C. Row 11, column 0110
  • D. Row 1, column 01100

Answer: B

Why: The row is b₁b₆ — the outer two bits, here 1 and 0, giving 10 = row 2. The column is b₂b₃b₄b₅ — the inner four, here 0110 = 6, so the seventh column. Using the outer bits for the row is the unusual part of the convention and the thing to remember.

Why A tempts people
Takes the first two bits for the row and the last four for the column, which is the natural guess and not the convention DES uses.
Why C tempts people
Uses b₁b₂ = 10 for the row... but reads it as 11, and takes the wrong four bits. Two slips.
Why D tempts people
Splits one bit off for the row and five for the column, which does not match a table with 4 rows and 16 columns.

57. Check: what actually broke DES

Check

Separate the design from the parameters.

Check your understanding

Which statement about DES's downfall is correct?

  • A. Differential cryptanalysis broke the full sixteen-round cipher
  • B. A back door in the S-boxes was eventually found
  • C. Exhaustive search of the 56-bit key space became affordable, exactly as forecast in 1977 (correct)
  • D. The initial permutation was found to leak key material

Answer: C

Why: Diffie and Hellman costed the attack within months of the standard's release, and twenty-one years later the EFF built the machine for $200 000. No cryptanalytic attack ever gave a practical improvement over exhaustive search on the full cipher — the design held and the parameter aged.

Why A tempts people
Differential cryptanalysis is a genuine attack and is impractical against the full sixteen rounds; DES's S-boxes were specifically optimised against it.
Why B tempts people
The opposite of what was found. Biham and Shamir showed the modified S-boxes were near-optimally strong, ending a fifteen-year suspicion.
Why D tempts people
IP is public, fixed and invertible, and the book notes it has no cryptographic significance at all — an attacker just undoes it.

58. Draw the cipher you have just taken apart

Connect it up

One page, and you will be able to read Chapter 8 by comparison rather than from scratch.

Draw it

Draw one Feistel round with L, R, f and the key, and write beside it the two formulas and the one-line reason decryption works. Then draw the inside of f as five boxes — expand, XOR key, S-boxes, permute — and label which box supplies non-linearity, which supplies diffusion, and which is bookkeeping. Underneath, write the three numbers 64, 56 and 48 with what each is. Finish with the sentence that separates DES's design from DES's downfall.

Keep the page. Chapter 8's AES answers every one of these questions differently, and the differences are the fastest way to understand it.

59. Exit ticket

Exit ticket

One question, about the distinction the chapter turns on.

Predict first

What is the most important lesson from DES's twenty-one-year lifetime?

  • Ciphers designed in the 1970s cannot be trusted
  • A cipher's design and its parameters age differently — DES's design held for twenty years while its key length was outdated within months
  • Secret design processes always produce weak ciphers
  • Feistel structures are inherently weak

Correct: A cipher's design and its parameters age differently — DES's design held for twenty years while its key length was outdated within months

Why: Two decades of the best available cryptanalysis produced no practical attack better than exhaustive search on the full cipher, and the S-boxes turned out to have been optimised against an attack published fifteen years later. What failed was one number, chosen in 1975 and correctly forecast as inadequate in 1977. Design flaws require a new algorithm; aged parameters require a bigger number, and confusing the two leads to replacing the wrong thing.

60. What to carry into Chapter 8

Recap

The first cipher this course has opened up, and the template for reading the next one.

Chapter 8 next. AES answers all five of the pattern slide's questions differently — no Feistel structure, a single 8-to-8 S-box built from inversion in the field GF(2⁸) of Section 3.11, and a design chosen by open competition with its rationale published.

Figure (svg): The full DES structure: initial permutation, sixteen Feistel rounds with 48-bit round keys, a final swap, and the inverse permutation.

Three stages, and the middle one is the only one that does cryptographic work.

Sources

  1. Introduction to Cryptography with Coding Theory, 3rd edition — Wade Trappe and Lawrence C. Washington — Pearson, 2020 (ISBN 978-0-13-485906-4)
  2. Chapter 7 — The Data Encryption Standard (sections 7.1-7.6) — Trappe & Washington, 3rd edition, pp. 136-159

Want this taught 1-on-1? Alexander tutors Cryptography — $55/session, free consultation.

Book on Wyzant · Text (657) 465-8108