Glossary

DES

DES stands for Data Encryption Standard, a symmetric block cipher that encrypts 64-bit blocks with a 56-bit key. It was first published as FIPS 46 and last reaffirmed as FIPS 46-3 on October 25, 1999. NIST withdrew the standard on May 19, 2005, and the 56-bit key is short enough to search exhaustively, so DES must not protect new data.

How it works

A DES key is written as 64 bits, but only 56 are random. The other 8 bits are parity bits, one per byte, set so that every byte has an odd number of 1 bits. That is why the effective key space is 2 to the power 56, which is 72,057,594,037,927,936 keys.

DES is a Feistel cipher. The 64-bit block is permuted, split into a 32-bit left half and a 32-bit right half, and run through 16 rounds. Each round uses a 48-bit subkey taken from the main key and mixes it into one half through eight substitution boxes, then swaps the halves. A final permutation produces the output. Decryption is the same circuit with the 16 subkeys applied in reverse order.

The command below encrypts one block with the classic worked-example key 133457799BBCDFF1, using OpenSSL's legacy provider because OpenSSL 3 disables DES by default.

python3 -c "import sys;sys.stdout.buffer.write(bytes.fromhex('0123456789ABCDEF'))" | openssl enc -des-ecb -provider legacy -provider default -K 133457799BBCDFF1 -nopad | od -An -tx1 | tr -d ' \n'
85e813540f0ab405

What is the key size of DES?

DES uses a 64-bit key field of which 56 bits are the actual key, and it processes 64-bit blocks. Searching 2 to the power 56 keys is practical, and it was shown in public. In 1998 the Electronic Frontier Foundation built a dedicated machine that recovered a key in 56 hours. In January 1999 that machine working with distributed.net found one in 22 hours and 15 minutes (via Wikipedia). The attack is cheap on current hardware.

Triple DES

Triple DES (3DES or TDEA) applies DES three times, with two or three independent keys, to stretch the key length. It keeps the 64-bit block, which causes problems for large volumes of data because identical blocks start to appear. NIST withdrew SP 800-67 Revision 2, the Triple DES recommendation, on January 1, 2024. Treat 3DES as legacy and migrate to AES.

Common pitfalls

  • Assuming 64 key bits means 64 bits of strength: 8 of them are parity, so the strength is 56 bits at most, and brute force is feasible.
  • Using DES because a legacy API still offers it: a 56-bit key gives no real confidentiality. Replace it, and re-encrypt stored data.
  • Calling 3DES safe because it is triple: the 64-bit block and the withdrawn NIST guidance make it a legacy choice. Use AES with a 128-bit block.
  • Using ECB mode: identical 8-byte blocks give identical ciphertext. Any DES code should at least use a chained mode, then be migrated.
  • Hitting a missing cipher error: OpenSSL 3 needs the legacy provider to run DES, and without it the run fails with "Error setting cipher DES-ECB ... unsupported". The fix is to migrate, not to enable the provider in production.

Related terms

  • AES — the standard that succeeded DES, with 128-bit blocks and 128 to 256-bit keys.
  • HMAC — a keyed authentication code that old DES-era systems used for integrity.
  • MD5 — another once-standard primitive that is now considered broken.
  • SHA-1 — a hash deprecated for similar reasons of advancing attack cost.

See also