1 / 8100%
Term paper: Data Encryption Standard
Abstract
The Data Encryption Standard (DES) is a block cypher algorithm that was the most
extensively used data encryption technique and the first algorithm officially certified by the
United States government for public usage. While DES was first popular owing to its
capacity to guarantee large-scale secrecy, the algorithm was later deemed unsafe when new
cryptanalysis tools and more powerful computers emerged. It was superseded by a more
secure method called Triple DES or 3DES, followed by the Advanced Encryption Standard
(AES). DES progressively operates as a symmetric critical method, meaning that the same
secret key is used for encryption and decryption. In contrast, an asymmetric key algorithm
utilizes two separate keys--one for encryption and another for decryption. DES has
influenced modern cryptanalysis operations, policies, and the many modes of operation
recognized by the NIST. The study examines the origins and operation of DES until it was
superseded by new and better systems, as well as the emergence and evolution of high-level
encryption for companies dealing with sensitive information. Studying DES and its
descendants enables us to understand how these linked cryptographic techniques constantly
evolve as critical to maintaining data credibility and protecting privacy in the postmodern
world.
Introduction
The Data Encryption Standard was initially developed by IBM researchers, whom Horst
Feistel commanded. This happened in the early 1970s, involving a physicist and
cryptographer born in Germany. He subsequently received recognition for his contributions
by having the Feistel structure named after him. Data encryption using symmetric keys is old-
fashioned, and the Data Encryption Standard, often known as DES, is one such way.
Nevertheless, DES remained the first encryption algorithm the US government authorized for
general use. In 1977 the United States government officially adopted DES as a Federal
Information Processing Standard (FIPS). Sensitive electronic government data and
commercial data that were not classified were encrypted using this standard. Data Encryption
Standards was the primary symmetric key algorithm used to encrypt the bulk of electronic
data.
Definition of Terms
Cryptography refers to securing communications and data extraction using codes and
encryption.
Encryption: Converting plain text into cypher text so only authorized people can access the
material.
Data Encryption Standard (DES): A symmetric-key algorithm for encrypting digital data
evolved in the 1970s and is currently widely used to protect safe communication (sic!).
Symmetric-key Algorithm: This technique utilizes the same key for two opposite purposes:
encryption and decryption.
Ciphertext:7Encrypted data, only readable with the proper key, is indistinguishable from
other data.
Cryptanalysis:7Cryptography aims to make information difficult to interpret by rendering
codes and algorithms indecipherable.
History
The United States adopted the Data Encryption Standard as the first data encryption
technology. The original DES encryption standard replaced the more advanced and secure
one at the start of the twenty-first century. This sophisticated encryption guaranteed
numerous Internet transactions and exchanges. The year 1973 was the when. A
recommendation for crypto algorithms that might be taken into consideration for another
standard of cryptography was sought by the National Bureau of Standards. Following a few
precise tweaks to bring the code shortening within bounds, all the subtleties of the
computation meant to be converted into DES were sent directly to the federal registry in
1975. It was suggested that DES be used in several US unclassified government applications
for equal coded data security during transmissions because of the NBS standards' declaration
and its surveying responsibility. At that time, DES was required for all US budgetary
transactions, including electronic store transfers. The DES decision changed into an
acknowledged standard for the company and the safety and security of its data via standard
affiliations. Coppersmith and colleagues (2010).
The Data Encryption Standard (DES) has revolutionized cryptography with the development
of the triple DES since, upon breaking into the 3DES, it functions as a current concept about
the guaranteed Cipher. Everything is essentially half of the bits that make up the ciphertext.
Generally, the Data Encryption Standard estimate affects Triple DES, also known as 3DES.
As a result, modifying the current code to use the triple DES is relatively easy. It also has the
benefit of the shown quality and a relatively wide key length to exclude a crucial number of
ambushes that may be used to reduce the time fraction needed to break the DES. Even in this
instance, the Data Encryption Standard is a very unexpected variant that must be prepared to
provide data assurance for particular purposes. Below that threshold, the DES calculation has
fled the date and is no longer in use (Carl, 2017).
The government's support and this publication guaranteed that the industry would widely
embrace DES. Industries with a high need for robust encryption include financial services
and security services. This is the point at which Data Encryption Standards become relevant
and significantly affect the sector. Due to its simplicity, DES has been used widely in many
embedded systems that need to be encrypted, including routers, smart cards, SIM cards, and
network equipment like modems. Because the average computer user or tech enthusiast
would need to be more familiar with this encryption or decryption standard, such devices
were often protected from intrusion attempts. The typical user would need to learn how or
what it meant; they would only be assured that their gadgets were safe with end-to-end
encryption. Previously, DES was used to encrypt data, such as plaintext messages, known as
cypher texts.
The Feistel structure was used in the block cypher known as the Data Encryption Standard.
Instead of applying the cryptographic key and algorithm to each piece of data individually,
they are applied simultaneously to the whole data block. DES uses the same key for both data
encryption and decryption. Messages could not access the file if the sender and the recipient
had the same private key or were unaware of it. Encryption refers to more than simply
utilizing a critical fob that changes your password every few minutes or a strong password.
An asymmetric structure called a Feistel cypher is used to build a block cypher. While the
name suggests a particular cypher, "Feistel cypher" refers to block cypher architecture.
The Data Encryption Standard employed a 56-bit randomly generated key used directly by
the algorithm, with each block consisting of 64 digits alternating between 0s and 1s. There
were sixteen rounds for this kind of encryption, and each round was applied to a single
cypher block. For instance, the string "0123456789ABCDEF" has to be converted from
plaintext to cypher by setting it into binary from left to right. Accordingly, the message
would say "0000 0001 0010 0011 0100 0101 0110 0111" on the left and "1000 1001 1010
1011 1100 1101 1110 1111" on the right. According to the American Psychological
Association (APA), n.d., DES only employed a 56-bit key size, meaning that even though it
worked on a 64-bit key, every eighth bit needed to be utilized.
Understanding how DES steps functioned is crucial since brute force assaults significantly
affected their breakdown. First, the user must create sixteen subkeys, each with 48 bits. A
conventional PC-1 table may be used to permute the key. Thus, the 57th bit in the original
key will be the first bit in the 56-bit key in the table. Encoding the message was the next step
after creating the sixteen keys.
The first stage in encoding any message is applying the initial permutation, commonly known
as IP, to each block of the 64 bits by the table. The Data Encryption Standard, as I said
before, contained sixteen rounds; therefore, we now have to repeat the same processes sixteen
times. One of the sixteen-bit keys from the 48-bit keys that have been utilized before will be
used in each round of the sixteen. Despite how difficult and drawn out this procedure may
seem, it is easy to understand.
Consequently, the Triple Data Encryption Algorithm, or TDEA, was developed subsequently
(Henry J, 2018). However, reports claim 3DES is formally being decommissioned (Henry J,
2018). This is not shocking to me since modern technology makes it much simpler to decrypt
encrypted messages. Therefore, use beyond 2023 is prohibited. In 1998, 3DES was first
unveiled as DES's potential replacement. TDEA was still used in banking, finance, and other
private sectors to encrypt data after DES was phased out in 2005 (Henry J, 2018).
The Triple Data Encryption Algorithm is a more secure form of DES encryption that employs
the same technique three times. While the first key is encrypted, a second key is decrypted,
and a third key is encrypted—it is still a symmetric key block cypher. In 3DES, there is also a
two-key variation in which the first and third keys may be the same (Henry J, 2018). A
vulnerability that led to DES discounting was the strength of the critical size. Because DES
only employed a 56-bit key, brute force attacks could be used against it. A computer that was
developed in 1998 was able to locate the key in 112 hours. However, the code may be
cracked in around ten hours by employing a parallel processing system that attempts a million
keys simultaneously. The Advanced Encryption Standards, or AES, came after the Triple
Data Encryption Standards. The goal of encryption is to make data impenetrable, hence this
was developed in response to DES's short bit key size and 3DES's simple decoding.
Compared to triple DES, Advanced Encryption Standard is a quicker and more robust
symmetric key and block encryption. It may be encrypted using one hundred twenty-eight
bits of data or sixteen bytes. You will get 128 bits if you multiply 16 by 8. The bit key size
may be 128, 192, or 256 bits.
In contrast to the Data Encryption Standard, the Advanced Encryption Standard employs a
variable number of rounds based on the length of the key. For a 128-bit key, AES will
employ ten rounds; for 192-bit keys, 12 rounds; and for 256-bit keys, 14 rounds. AES will
use a distinct 128-bit round key in each round, which will be determined using the initial
AES key. A fixed table's sixteen input bytes will produce a matrix with four rows and four
columns. The matrix's rows are then all moved to the left. The first row remains unaltered,
the second row is moved left one place, the third is moved left twice, and the fourth is moved
three times. Following the row shifts, a math function changes the four columns by
exchanging four bytes for new ones. The sixteen bytes are now 128 bits after the round key is
added. If you want more rounds, repeat this operation as often as necessary.
AES is still widely used across many businesses, including WinZip and messaging
applications like Signal and WhatsApp (Ingram-Reid, C et al., 2018). The third encryption
system from DES is AES, which is used today. These standards have given rise to a new
sector of the economy similar to cryptography, where testing and message deciphering are
your duties. The business of testing message security, system integrity, and standard
conformance has expanded. A new encryption standard will ultimately be developed since
AES becomes insufficient.
Importance
This research paper aims to illuminate how these encryption standards have evolved
and their purpose in ensuring the privacy of communication in digital media. DES, the latter
of the two, has undoubtedly led to the advancement of modern cryptographic algorithms,
amongst others (Chalmers, 2019). Using this study, the researcher will demonstrate
particularly mathematical and cryptographic discoveries in security as the best solutions for
possible security concerns in the future. The results of this research will be helpful for
cryptographers, security experts, history lovers, and those interested in information security
development. Apart from DES, we can also learn how7vital7encryption is and how well sight
has helped to establish modern encryption standards that can adapt to the threats of rising
technology.
Modes of DES
Four authorized DES modes are described in FIPS 81: Output Feedback (OFB), Cipher Block
Chaining (CBC), Electronic Codebook (ECB), and Cipher Feedback (CFB). The fifth
technique is Counter (CTR), described in NIST Special Publication 800-38A. Both DES and
Triple DES may be utilized with these modes.
Error propagation and block vs. stream ciphers are crucial distinctions between each style.
The propagation of faults in encryption or decryption, such as a bit flip from 0 to 1, may
lead to more problems in later processes.
A block cypher encrypts a 64-bit data block (ECB and CBC modes).
A stream cipher encrypts from 1 to 64 bits in CFB, OFB, and CTR modes. The modes of
DES, a block cypher, resemble stream cyphers.
Electronic Codebook (ECB) Mode
The DES native mode, or "a direct application of the DES algorithm to encrypt and decrypt
data," is the Electronic Codebook. In this approach, every plaintext block is separately
encrypted into a corresponding ciphertext block. This is accomplished by a Feistel cypher in
honour of Horst Feistel, one of Lucifer's founders. It encrypts the plaintext through sixteen
transformation rounds after generating sixteen subkeys based on the symmetric key. The 16
subkeys are provided in reverse order, but the technique to transform ciphertext back into
plaintext remains the same (using the symmetric key).
Repetitive plaintext blocks give rise to recurrent ciphertext blocks, facilitating ciphertext
cryptanalysis.
This effect is excellently illustrated in the first picture, which shows the SANS logo in bitmap
format and is encrypted using DES ECB mode in the second image. Even if the bitmap data
is encrypted, the original pattern is still easy to see.
The pattern is noticeable because repeated plaintext pixels in the bitmap are encrypted into
repeating blocks of corresponding ciphertext pixels. Errors cannot spread in this mode since
each block is encrypted separately. The term "Codebook" refers to cryptographic code books
that include dictionaries of words or phrases (such as "Attack has begun") and their coded
equivalents ("The Eagle has flown").
Cipher Block Chaining (CBC) Mode
Cipher Block Chaining Mode is a block cypher that XORs (exclusive OR) each new block of
plaintext with the preceding block of ciphertext (the two are "chained" together). This implies
that repeated blocks of plaintext do not yield repeated blocks of ciphertext.
CBC additionally employs an initialization vector, a random starting block that guarantees
that two identical plaintexts produce distinct ciphertexts (due to different initialization
vectors).
Here is the same SANS logo bitmap data, encrypted using DES CBC mode:
No pattern is discernible. This holds for all DES modes except ECB.
Errors spread in this mode because the encrypted output from the previous phase is XORed
("chained") with the new plaintext block.
Cipher Feedback (CFB) Mode
A stream cypher called Cipher Feedback mode encrypts plaintext by dividing it into X (1 to
64) bit chunks. Bit or byte-level encryption is therefore possible.
In CFB mode, a random initialization vector is used, and ciphertext units are "fed back" to
plaintext by XORing them with successive plaintext units. Similar to CBC, mistakes spread.
Output Feedback (OFB) Mode
Like CFB mode, output feedback mode encrypts plaintext by dividing it into a stream and
encrypting units of X (between 1 and 64) bits. It also utilizes a random initialization vector.
In contrast to CFB mode, OFB mode generates a pseudo-random stream of bits termed
"output," which is "fed back" to the plaintext at each step by XORing with the plaintext.
Errors do not spread because the output is XORed to the plaintext instead of the ciphertext.
Counter (CTR) Mode
Similar to OFB mode, the counter mode is a stream cypher where counter blocks are added.
For every encrypted unit of plaintext, the counter may be concatenated or appended to a
nonce, a once-use random number, and then increased. The first counter block represents the
initialization vector. The counter blocks are XORed with plaintext in each round.
Counterblocks increase performance on compatible hardware by enabling encryption or
decryption to be divided into parallel phases. Errors also do not spread.
DES Mode Summary
Table 1: DES Mode Summary
Triple DES (TDES)
FIPS 46-3 specifies the Triple DES algorithm (sometimes called TDES). It may be used as a
FIPS-approved encryption algorithm until 2030, allowing for the transition to AES. Double
DES is not employed because of a meet-in-the-middle attack, resulting in an adequate key
size of 57 bits.TDES employs three rounds of DES encryption with a key length of 168 bits
(56 * 3). Theoretical attacks may lower TDES's effective key length to around 112 bits,
although brute force assaults are still impractical.
The FIPS-approved TDES implementation employs three rounds of encryption, decryption,
and encryption (EDE). This could seem strange since the second round does not truly
decrypt: Decrypting with a new key scrambles the plaintext even more. EDE order also
provides for backward compatibility with DES (see below).
FIPS 46-3 additionally specifies three keying options: three distinct keys (3TDES EDE), two
different keys (2TDES EDE; the same key is used in rounds one and three), and one key
(1TDES EDE).
Here is 3TDES EDE encryption:
Here is 2TDES EDE encryption:
1. 1TDES EDE works like DES. Assuming “SECRET” plaintext:
2.
3. 1. "SECRET" becomes ciphertext.
4. 2. Ciphertext becomes “SECRET.”
5. 3. "SECRET" becomes ciphertext.
Step three is similar to Step one. Given the same plaintext and key, 1TDES ciphertext equals
DES ciphertext.
3TDES EDE is the most powerful version. 2TDES EDE is widely used in the banking sector,
including standard hardware like the IBM 4758 PCI Cryptographic Coprocessor13. 1TDES
EDE is intended for backward compatibility with DES-based older systems and should not be
used for secure applications.
In addition, non-FIPS-approved modes are employed in the industry. The most prevalent is
3TDES EEE (three-key)—Triple DES in the Encrypt-Encrypt-Encrypt sequence.
References
Coppersmith, D., Holloway, C., Matyas, S M., & Zunic, M. The data encryption
standard.Information Security Technical Report, 2(2), 22–24.
https://www.sciencedirect.com/science/article/abs/pii/S1363412797813258
Students also viewed