DES
More info
- Type
- Block cipher
- Released
- 1977
- Block size
- 64 bits
- Key length
- 56 bits
- Spec
- FIPS 46-3
- Successor
- AES
The standard that encrypted the world's cash machines for twenty years, with a key length the NSA insisted on shortening.
The Data Encryption Standard, adopted as a US federal standard in 1977 and built on IBM's Lucifer. 64-bit blocks, 16 Feistel rounds and a 56-bit key — IBM originally proposed 128, the NSA wanted fewer still, and the compromise was criticised as deliberately weakened the moment it was adopted.
The NSA also altered the S-boxes without explaining why, which fed backdoor suspicions for fifteen years. When Biham and Shamir published differential cryptanalysis in 1990 it turned out the changes made DES stronger against precisely that attack — the agency had known the technique since 1974. The key length, however, really was too short: in 1998 the EFF's Deep Crack machine recovered a DES key in 56 hours for under $250,000. Replaced by AES in 2001.