Files
notes/docs/lectures/cryptography/04_data_encryption.md
T
2026-10-04 15:24:17 +01:00

4.8 KiB
Raw Blame History

Data Encryption Standard (DES)

Pseudorandom Permutations

  • A pseudorandom permutation is a function that cannot be distinguished from a random permutation
  • Maps a set of values \{0,1\}^n \times \{0,1\}^s \rightarrow \{0,1\}^n such that:
    • For any key, the function F is a bijection (1:1)
    • The key just changes the mapping
    • There is an efficient algorithm to calculate F(x) for all keys and all messages

1645042514.png

Confusion: Obscure the relationship between plaintext, key and ciphertext

  • Often achieved through substitution operations
    • Using lookup tables

Diffusion: Influence of each plaintext and key bit is distributed throughout the ciphertext

  • Achieved via permutation
    • Swapping or otherwise mixing bits/bytes

Shannon called a cipher like this a product cipher

Feistel Network

  • A Feistel network is one mechanism used to create block ciphers
  • Developed by Horst Feistel while he worked at IBM
  • Underpins DES, GOST, Blowfish, Twofish and numerous others.

1645042957.png

  • To decrypt, we run the encrypted bits through the network again
A Single Feistel Round
  • During each round, only half of the block is encrypted

1645043071.png

Very similar to a stream cipher.

Round i

1645043210.png

Round i+1

1645043312.png

Note - the last round does a final swap so the left and right are in the correct places.

Decrypting

1645043479.png

1645043523.png

Basically the xors cancel themselves out, the most important part is choosing a good function f

About Feistel Networks

  • 1 or 2 rounds are not sufficient
  • Luby and Rackoff show that if f is a cryptographically secure pseudorandom function then:
    • 3 rounds are sufficient to make a pseudorandom permutation
    • 4 rounds are sufficient to make a strong pseudorandom permutation
  • Balanced Feistel networks
    • L and R are equal sizes
  • Unbalanced Feistel networks
    • L and R can be different sizes
    • e.g. skipjack, OAEP

DES

1972: NIST put out a call for a US standard for encryption

1974: IBM propose DES

1976: NIST accepts an altered version of DES following consultation with NSA

  • Feistel network with 64-bit block size
  • 56-bit key
  • The most studied cipher in history
    • Hasn’t been broken for over 46 years

1645044034.png

1645044122.png

This speeds up loading bits into registers

The F function

1645044186.png

S_1, S_2.... are called s-boxes. These substitute 6-bit inputs with 4-bit outputs based on lookup tables. The lookup tables for each s-box are different.

Expansion
  • Adds diffusion
  • Increases from 32 to 48 bits to match the round key

1645044333.png

Half the input bits are connected to two output positions

Substitution Boxes
  • Add confusion
  • The s-boxes map 6-bit inputs to 4-bit outputs
  • There are 8 s-boxes in total, each is different

1645044443.png

  • This s-box is not random, very carefully designed
  • s-boxes need to be highly non-linear: S(a) \oplus S(b) \neq S(a\oplus b)
  • This prevents simple systems of linear equations such as we saw in LFSRs.
    • The formula needed to represent DES is too complicated
  • Key design principles
    1. No output bit should be too close to a linear combination of input bits
    2. 1-bit change input should lead to at least 2-bits output
    3. If you only change the 4 middle bits, each output must occur exactly once
    4. If the first two bits are different but the last two are identical, the output must differ
    5. For any non-zero difference in input, no more than 8 of the 32 inputs exhibiting this difference should share the same output difference
      • We want to limit the number of predictable swaps
    6. A collision (zero difference) is only possible for 3 adjacent s-boxes
Permutation
  • At the end of f() is a permutation
  • This moves bits between s-boxes on the next round

1645044919.png

  • Blue showing how S_1 output bits are diffused

The Avalanche Effect

If you input all 0s, we will see a random cipher text

However, if we change one 0 to a 1, how does this affect the result?

  • On average, if you change one (first) bit in R, one bit will change in the expansion
  • Due to the way the s-boxes are set up, at least 2 of the 4 bits in the output will be different
  • Now when the permutation happens, these two changes are spread to other s-boxes
  • Now next round we’ll get 4 changes, then 8, then 16 …

For DES the worst case scenario when one bit is changed (with 5 rounds) is there will be an effect on every bit on the output.