Files
notes/docs/lectures/cryptography/05_des2.md
T
2026-10-04 15:24:17 +01:00

5.9 KiB
Raw Blame History

Data Encryption Standard

Key Schedule

  • The DES key schedule simply returns various permutations of k as sub-keys
    • k_1, ... k_{16}
PC-1
  • Permuted Choice 1 (PC-1) selects 56 of the 64 bits
  • The other ‘parity’ bits are discarded: DES only uses a 56-bit key
  • Key bits are spread throughout the initial state of the key schedule
  • Key bits 8, 16, 24,…64 are not used

1645476128.png

Left Rotation

  • Left rotations (often written as <<<) represent a left shift where the leftmost numbers wrap around to the right-hand side
  • In DES, each 28-bit block is rotated left by <<<1 for rounds 1,2,9,16 and <<<2 otherwise
  • The total rotation is 4\cdot 1 + 12\cdot 2 = 28 which means C_0 = C_{16} and D_0 = D_{16}
    • NOTE: C_0 or D_0 is not used
PC-2
  • Permuted Choice 2 selects 48 of the 56 bits to be used as a round key

1645476385.png

Properties of the Key Schedules
  • Is entirely permutation based
  • Doesn’t use xor, addition or any other mixing operation
  • Because C_0 = C_{16} and D_0 = D_{16} we don’t need to write separate encrypt and decrypt functions
    • Useful for writing implementations on low-memory devices (smart cards)

Breaking DES

  • DES has a key length of 56-bits
  • A brute force attack requires no knowledge of the cipher, only a pair (x_0, y_0) of known plain and cipher text

DES^{-1}k_i(y_0) = x_0 for i=0, 1, ... 2^{56}-1

This would take minutes to hours on a cluster.

NOTE: 2^{56}-1 is a very large number

Key Collisions

  • For a 56-bit key but a 64-bit block, it is possible (though unlikely) that a different key would work
  • How likely is this to happen for a 1 bit key and an n bit block cipher
    • \frac{2^l}{2^n} where l is the length of the block and n is the key length
    • \frac{2^{64}}{2^{56}} = 2^8

1645477137.png

  • DES was first brute forced in 1997 and is no longer secure

1645477221.png

(days on y axis)

Double Encryption

1645477338.png

  • Naive brute force suggests 2^{56}\cdot 2^{56} = 2^{112} keyspace
  • However, using a meet-in-the-middle attack, this becomes trivial.
    • Step 1: Calculate encryptions of x_1 for all k_{1...,i} and store intermediate values Z_{1..,i}
    • Step 2: Calculate all decryptions of y_1 for all k_{R, j} to find Z_{R,i}
    • Step 3: Find any value of Z_{R,j} matching existing Z_L,i

1645477760.png

Meet-in-the-middle requires 2^{k+1} attempts rather than 2^{k\cdot 2}

  • This is much better than brute force, but doesn’t make it easy
  • Trades off computation for storage - Petabytes for DES
  • Assumes some kind of O(1) for Z_{L,I}

3DES

  • Triple DES uses three different keys
    • Either enc -> enc -> enc or enc -> dec -> enc
  • Often used in banking, smart cards and other payment systems

1645478048.png

This prevents MITM attacks as one of the attacks will have to compute 2^{112} permutations

Why use enc -> dec -> enc?

This is for compatibility with legacy systems running DES.

This is why banking systems use 3DES as they already have the infrastructure for DES however 3DES is officially not recommended by NSA in 2016

DES-X

  • An alternative construction using a concept called key-whitening

1645478296.png

  • Theoretically this provides a search space of 2^{k+2n} but meet-in-the-middle can be used here, as well as other more advanced attacks
  • In practice, security is 2^{k+n-m} where an attack has 2^m known plain texts

Cryptanalysis

What is a break?

  • In modern cryptography, a cipher is declared broken by essentially any attack that is more efficient than brute force
    • For example, differential cryptanalysis requires 2^{47} operations on DES rather than 2^{56}
  • These are often academic breaks, rather than a practical security concern
    • For example there is a related key attack on AES of 2^{99.5}, compared to brute force of 2^{128}
    • Remember that a 2^{n-1} takes half the time 2^n does
Analytical Attacks
  • Exploit some underlying structural or mathematical weakness in a cipher
    • e.g. meet in the middle attack
    • Derivation of taps in LFSRs
Statistical Attacks
  • Capture statistical patterns between input and output to recover key bits
    • Differential cryptanalysis
    • Linear cryptanalysis
Differential Cryptanalysis
  • Differential cryptanalysis is perhaps now the most important modern method for breaking block ciphers
  • It is a chosen plaintext attack
  • We aim to find predictable changes in output bits caused by known changes in the input bits

1645479017.png

  • Each of these s boxes has 4 bits, 16 possible values
  • This means any input change \Delta x should cause some change \Delta y with probability p=1/16
  • In a poor s-box, the likelihood might be much higher
  • The sum input change resulting in some output change (\Delta x, \Delta y) is called a differential and has some probability of occurring

1645479256.png

  • Tracing differentials through a cipher provides us with differential characteristics e.g.
    • (\Delta x, \Delta y) = (0x80, 0xA0) where p \geq 2^{-3} = 1/8
  • These can be calculated by hand or using automated tools
  • The attack then looks for these expected differentials as you manipulate sub-key bits
Resisting differential cryptanalysis
  • S-boxes must be designed such that the probability of any pair (\Delta x, \Delta y) is as low as possible
    • AES has a maximum likelihood of a differential per s-box of 2^{-6}
    • This is because AES has such good diffusion
  • More rounds make differentials even less likely
  • Good permutation to involve more s-boxes is vital
  • DES was specifically designed to resist this kind of attack