Glossary

3DES

3DES stands for Triple Data Encryption Algorithm, a symmetric block cipher that passes each 64-bit block through DES three times with a 112-bit or 168-bit key. Standards call it TDEA, and it is also written TDES or Triple DES. NIST withdrew SP 800-67 Revision 2, its 3DES guidance, on January 1, 2024, so new designs should use AES instead.

How it works

3DES uses the encrypt-decrypt-encrypt (EDE) sequence. Each block is encrypted with key 1, decrypted with key 2, then encrypted with key 3. The middle step is a decryption so that a bundle with identical keys collapses to a single DES operation, which kept old DES systems compatible.

The key bundle comes in three keying options:

  • Option 1 (3TDEA): three independent 56-bit keys. The bundle is 24 bytes including parity bits and gives 168 key bits on paper.
  • Option 2 (2TDEA): key 3 equals key 1. The bundle is 16 bytes and gives 112 key bits. NIST disallowed it in 2015 (via Wikipedia).
  • Option 3: all three keys equal. The bundle is 24 bytes but the cipher is plain DES.

The 168 figure overstates the strength. A meet-in-the-middle attack cuts three-key 3DES to about 112 bits, and SP 800-57 rates 3TDEA at 112 bits of security. The block size stays at 64 bits, the same as DES, and that is the real weakness today.

The commands below encrypt the block 0123456789ABCDEF three ways. OpenSSL 3 needs the legacy provider only for single DES. With the same key repeated three times, 3DES returns exactly the single DES output.

K=133457799BBCDFF1
openssl enc -des-ecb -provider legacy -provider default -K $K -nopad -in pt.bin | od -An -tx1 | tr -d ' \n'
openssl enc -des-ede3-ecb -K $K$K$K -nopad -in pt.bin | od -An -tx1 | tr -d ' \n'
openssl enc -des-ede3-ecb -K 0123456789ABCDEF23456789ABCDEF01456789ABCDEF0123 -nopad -in pt.bin | od -An -tx1 | tr -d ' \n'
85e813540f0ab405
85e813540f0ab405
f2afd84ee809e2b5

Why was 3DES retired?

3DES was retired because its 64-bit block lets two ciphertext blocks collide after roughly 32 GB of data under one key. The Sweet32 research (CVE-2016-2183 and CVE-2016-6329) used this birthday bound to recover HTTP cookies from TLS sessions after capturing about 785 GB. The same applies to OpenVPN. NIST deprecated 3DES in 2019 and disallowed encrypting new data with it after 2023 (via Wikipedia, citing SP 800-131A Revision 2).

Common pitfalls

  • Counting 168 bits as the strength: the meet-in-the-middle attack leaves about 112 bits, and a two-key bundle is no better. Plan with 112.
  • Encrypting long-lived streams under one key: a 64-bit block hits the birthday bound near 32 GB, which a fast connection can transfer in under an hour. Rekey often or move to a 128-bit block cipher such as AES.
  • Using a repeated key by accident: a bundle of one key three times is single DES with a 56-bit key. Check that the three halves of a 24-byte key differ.
  • Using ECB mode: equal plaintext blocks give equal ciphertext blocks. The example above uses ECB only to show a single block.
  • Leaving 3DES suites enabled in TLS: scanners flag names containing 3DES or DES-CBC3 under CVE-2016-2183. Remove them from server cipher lists and keep only AES-based suites.

Related terms

  • DES — the single-pass cipher that 3DES wraps and stays compatible with.
  • AES — the 128-bit block replacement with 128-, 192- and 256-bit keys.
  • TLS — the protocol where Sweet32 made 3DES cipher suites a finding.
  • HMAC — a keyed integrity check that you pair with any block cipher mode lacking authentication.

See also