# Data Encryption Standard (DES) ### Pseudorandom Permutations - A pseudorandom permutation is a function that cannot be distinguished from a random permutation - Maps a set of values $\{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n$ such that: - For any key, the function F is a *bijection* (1:1) - The key just changes the mapping - There is an *efficient algorithm* to calculate $F(x)$ for all keys and all messages ![1645042514.png](img/1645042514.png) **Confusion**: Obscure the relationship between plaintext, key and ciphertext - Often achieved through substitution operations - Using lookup tables **Diffusion**: Influence of each plaintext and key bit is distributed throughout the ciphertext - Achieved via permutation - Swapping or otherwise mixing bits/bytes Shannon called a cipher like this a **product cipher** ### Feistal Network - A Feistal Network is one mechanism used to create block ciphers - Developed by Horst Feistal while he worked at IBM - Underpins DES, GOST, Blowfish, Twofish and numerous others. ![1645042957.png](img/1645042957.png) - To decrypt, we run the encrypted bits through the network again ##### A Single Feistal Round - During each round, only half of the block is encrypted ![1645043071.png](img/1645043071.png) Very similar to a stream cipher. ###### Round $i$ ![1645043210.png](img/1645043210.png) ###### Round $i+1$ ![1645043312.png](img/1645043312.png) Note - the last round does a final swap so the left and right are in the correct places. ###### Decrypting ![1645043479.png](img/1645043479.png) ![1645043523.png](img/1645043523.png) Basically the `xor`s cancel themselves out, the most important part is choosing a good function $f$ #### About Feistal Networks - 1 or 2 rounds is not sufficient - Luby and Rackoff show that if $f$ is a cryptographically secure pseudorandom function then: - 3 rounds are sufficient to make a pseudorandom permutation - 4 rounds are sufficient to make a strong pseudorandom permutation - Balanced Feistal networks - L and R are equal sizes - Unbalanced feistal networks - L and R can be different sizes - e.g. `skipjack`, `OAEP` ### DES 1972: NIST put out a call for a US standard for encryption 1974: IBM propose DES 1976: NIST accepts an altered version of DES following consultation with NSA - Feistal network with 64-bit block size - 56-bit key - The most studied cipher in history - Hasn’t been broken for over 46 years ![1645044034.png](img/1645044034.png) ![1645044122.png](img/1645044122.png) This speeds up loading bits into registers ##### The F function ![1645044186.png](img/1645044186.png) $S_1, S_2....$ are called s-boxes. These substitute 6 bits input to 4 bits output based on lookup tables. The lookup tables for each s-box is different. ##### Expansion - Adds *diffusion* - Increases from 32 to 48 bits to match the round key ![1645044333.png](img/1645044333.png) > Half the input bits are connected to two output positions ##### Substitution Boxes - Add confusion - The s-boxes map 6 bit inputs to 4-bit outputs - There are 8 s-boxes in total, each is different ![1645044443.png](img/1645044443.png) - This s-box is not random, very carefully designed - s-boxes need to be highly **non-linear**: $S(a) \oplus S(b) \neq S(a\oplus b)$ - This prevents simple systems of linear equations such as we saw in LFSRs. - The formula needed to represent DES is too complicated - Key design principles 1. No output bit should be too close to a linear combination of input bits 2. 1-bit change input should lead to at least 2-bits output 3. If you only change the 4 middle bits, each output must occur exactly once 4. If the first two bits are different but the last two are identical, the output must differ 5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference - We want to limit the number of predictable swaps 6. A collision (zero difference) is only possible for 3 adjacent s-boxes ##### Permutation - At the end of $f()$ is a permuatation - This moves bits between s-boxes on the next round ![1645044919.png](img/1645044919.png) - Blue showing how $S_1$ output bits are diffused #### The Avalanche Effect If you input all 0s, we will see a random cipher text However if we change one 0 to a 1, how does this effect the result. - On average, if you change one (first) bit in $R$, one bit will change in the expansion - Due to the way the s-boxes are setup, at least 2 of the 4 bits in the output will be different - Now when the permutation happens, these two changes are spread to other s-boxes - Now next round we’ll get 4 changes, then 8, then 16 … For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.