`Théa material may be protected by fimpyright law {Title "E"? US. Eode)
`M, DEPARTMENT 23? czsmaaca, Phi1"Ep “M. Kiutznick, §et:r:=:tary
`Jordan J. Baruch, AssisLant Secretary far Productivity,
`Technology and Innovation
`NAQEONAL BBREAU OF STANBARDS, Ernest Ambler, fiirecror
`The Feéaral Infcrmation Prmcessing Standards Publicatimn Seriea 0f the Natianal Buzeau of
`is tha ufficial pmblicauimn relating to standards ado tad amfi promulgated under
`05 Publie Law B9*3G6 (Braaks Act) and under Para 6 of Title
`15, Code
`Fmderal Regulations.
`These legislative anfi executive manéates have given the Secretary uf
`imprnving the utiiization ané management
`autmmatic data processing in the Federai Gnvarnment.
`carry gut
`the WEB,
`thrmugh its Institute far Csmputer Sciences
`praviflax lwaéership,
`teahnicai guidance and caordinatisn uf Gnvernment efforts
`éu the fiaveingment mf guidelinea and standards in thfififl areas.
`fimmmamfw cmncgrning Fed@ra1 Infnrmatimn Prmcessimg Standards ?ub1ications are welcnmed
`km the flirectmr,
`institute for Computer Sciences
`and Technnlogy,
`Nuiimnak Bureau Q5 8tan&arfls, Washington, DC
`James H. Burraws, Director
`In$titute far Cnmvucar Sciences
`and Technmlagv
`Vnfiwfai %at& Envryptinn Standard (953) {F1?S $6) specifies a cryptagraphic algurithm to
`wand far aha rrywtmgraphic prntectimn nf $EflRiE§U&,
`but unciasgifiafi,
`computer data.
`FE?fi fiufimvs
`fmur mmdos of mperatian fnr the LJS which may be used in a wide variety
`The mwdéa specify haw data wili he annryptwd (cryptographicaily prntect~
`0 {retnrnefi
`Em ariginal
`The mmdég includaé in this standard ara tha
`Anniv ,nd&hwmk {ESE} made,
`thm Cipher Black Chaining (QBC) moda,
`the Cipher Faedback
`1} mmfiw, mnfl {Ha fiurput Ffiadhack {flFB) mafia.
`«water awcurit¥; cryprmgraphw; dflta securitv; HES; encrypaimn; Faderal Enfnr-
`u Srwwdxrdwi mmdma nf ngaratiom.
`Ké{.3nr.§?mu£+ 5V.S.3. V9d.{nfm»?r<CfiSS.S£Mn&~?ubE.{F?PS FUR} SI,
`2% p¢g¢S.
`W3: Twcknémné
`énfarmntimm fivrrisn, V.R. Wvpnrrmumx
`Federal Infnrmmion
`Processing Standards Publiwtion 81
`1930 Dsgecember 2
`Fefleral Information Processing Standards Fublicationfi are issuad by the National Bureau
`St.ndards pursuant
`tn the Federal Prcperty and Administrative Services Act
`amended. Public Law 89~306 (?9 Stat.
`112?), Executive Orfier l1?17 (38 FR 12315, dated May
`11, E973), and Part 6 of Title 15 Cnée sf Feaeral Regulations {CFR).
`1. Name of Standard. DES Mnfie3 of Operation.
`2. Categary of Standard.
`ADP Operations, computer security.
`(F195 46) specifies a crypts"
`The Federal Data Encryptian Standard (DES)
`graphie algnrithm to be used far the cryptngraphic protacticn of sensitive,
`but unclassi-
`computer data.
`This FIPS defines faur modes of operatiwn for the DES which may be
`in a wi&e variety af applications.
`Tha moées specify how data will
`{cryptagraphically pratected)
`and d&cryptafl (returned ta original form).
`The mudes
`cluded in this stanéard are the Electronic Codebook (ECB) made,
`the Cipher Block Chaining
`(SEC) mfida,
`thm Cipher Feeéback (CF33 mcda, and the Dutput Feedback (OFB) mode.
`The bad? 0f this standard provides specifications of tha recommended muées of operation but
`fleas not specify the necessary and sufficianr nonditicns for their seaure implementation in
`a particular applicatian. This standard specifies the numbering of data bits, haw the bits
`encrypted and decrypted,
`and the data paths and the data precessing necessary
`encrypting and éecrypting data at messages. This standard is based on (and refarences) the
`and provides the max:
`level of detail necessary far providing compatibility among
`standard anticipates the develayfient cf a set of application standards
`which reference it such as cummunicatian security standards, data storage standards, pass-
`woré protactian standards and key management standarés.
`Cryptographic system designers er
`security application designers must select ane or more of the pmssible mdea of operatiwn
`far implemanting and using tha DES in a cryptcgraphic system at sacurity application.
`to this standard provide tutarial informatinn an the modes
`of operation and
`fur validating their correct
`The Appendices are guidaifinwg
`are not m$néatory requirements pf this stanéard.
`4. Approving Authority. Secretary of Cnmmerce.
`Raintenance Agency. U.S. Department of Cammerce, National Bureau cf Standards, Insti-
`tute for Computer Sciences and Technalngy.
`6. Related Dacuments.
`FIPS PUB £6, "Data Encryptian Standard," January 15, 1917.
`(Proposed) Federal Standard 1626,
`Use of
`the Data Encryption Standard," May 26, 1980, draft.
`Interoperability Requirements for
`(Proposed) Federal Standaré 1027,
`1980, draft‘
`the Data Encryption Standard," August 5,
`Security Requirements fur Use
`1 BEST Wi’;%%WNT
`raps ma 3:
`A list wf fiutrently appravefi FIFE may be obtained frem the Standardg Admin1stv*t1on affine,
`Ins:l:ute for Computer Sciences and Technology, Rational Bureau of Standarfia, Washington,
`DC 2%23&.
`This standard shall be uaed by Feéeral departmenta afid agencies when
`7. Applicability.
`procuring equipment or services which implement
`the Data Encryption Standar& and which are
`intended fur use in the cryptngraphic pratectinn of aensitive,
`but unclassifiefi,
`stanflard may
`used by anyone desiring ts
`the Data
`Encryption Standard.
`The selectinn of one of the apecified mudes af operatian will depenfi
`an the particular appliaation being cnnsidered.
`Specifications. Fafieral Informatinn Processing Stanfiard (FIPS 81) 0B5 Hades cf 0para—
`tinn (affixed).
`The DES modes of mperatiun described in this atandard are based upan
`9. Quallficationa.
`in§nrmatlnn pravideé by many saurces within the Fefleral Gavernmant and private
`These modes
`are presently being implemented in cryptugraphic
`cantaining DES
`Hawever, 3 stanaard of this natura must, of necesaity,
`remain flexible enough to
`to advancements and innavations in science and technolagy.
`As such,
`thig standard
`not ha construed as being either exhaustive or static.
`It wi
`be reviewed
`five years
`in order tn incorporate new implementations whnse technig
`" ecnnomic merit
`justify the issuance af a rwvised gtanfiard.
`?IPS A6 requires imp1ema«
`~ of
`the DES
`algcrithm in electrnnic devicas when used by Federal departments and ah
`. The DES,
`itself, must
`therefore be in hardware at firmware far Federal applicatiar
`moées of oparatinn specifiefi
`in this standard may he implemented in softwa a,
`hardware, or
`Export Cuntrnl. Cryptagraphic davices and technical data regaréing them are
`ta Federal Government
`in Titlg 22, Caée
`nf Federal
`Regulations, Parts
`12} through 123. Cryptmgtaphic devices im§1ementing this standard and
`technical data regarding them must comply with thesa Fefieral regulations.
`Crypcograghlc equipment
`and fareign patents.
`implementing zhls standard may be cavared by U.S.
`Implementation Scheéule. This standard bacmme$ effemtive an June 2, 1981.
`standard be
`of agencies may request that the requirements nf this
`13. Waivers.
`waiwwd in instances where it can be clearly demnnstrated that there are appreciable perfor«
`mance at cost aévantages to ba gained and when the nverall interests of the Federal Govern»
`are best
`sErv&d by granting the requested waiver.
`Such waiver
`requestg will
`are subject
`tn the approval of
`the Secretary of Commerce.
`The waiver
`raquest must specify anticipated perfnrmanme and cast advantages in tha justificatian for
`the waiver.
`shoulfi be alluwed for review ané response by the Secretary cf Commerce.
`waiver requestg shall be submitted to tha Secretary of Cemmerca, Washington, DC
`20230, ané
`labeled as
`a Request for a waiver ta this ?edera1 lnfarmatinn Processing Standard.
`agency shall taka any actien ta fieviate from this standard prior tn the receipt af 3 waiver
`Exam the Secretary of Cummerce.
`No agency shall implement or procure
`using 3
`DES made nf operatlan net cnnforming to this standard unless a waiver has
`the National
`ta Obtain Copies. Copies of this publication ara far sale by
`lnfutmation Service, U.S. fiepartment uf Commerce, Springfield, VA 22161.
`refer ta Fedmral Infnrmatian Processing Stanfiardfi Publication 81 {FIPS PUB 81),
`and title.
`when microfiche is fiesired,
`this should he apecified.
`Payment may be made by
`check, mnney arder, or deposit account.
`Fwsderal lnfoarmatibn
`Pracessingg Smndards Publication 81
`1930 December fl
`Specificminns for
`hrs puss’:
`’~'.Mfl .3
`KNTEQQUCTIGN uwouoannvqaoaunoummnetumaintainu-groan:cuonwqotwbqunaaauohcnnnnoignu a
`1:1 Dflfinitiflflfi, Abbrfiviatifins, Hfld CUflVQnti0nSa¢0mIInwucuquwuuonuwpuannobnndtamay A
`ELECTRONIC CQDEBUQK (ECB) M0BE.»¢.o......a...R».w....................¢o..onao+an.
`CIPHER BLQCK CHAENKNG (CBC) Manfiaucoaaqonapwavtutuouwnobiauoonu»tmvnuInanIwnvunun 5
`GSPHER FEEDEACK (CFB) Mgnfiuuauannpnuuwouquus~u~nvnatni¢wuiwiinuunusutpnufi-nuances 3
`OUTPHT FEE§BACK (QFB) MBDEQ«insaneuwnasaawnupwannacwulpnnuvtuocumawisoinanonomomu 8
`la Eiafitroflic Cfldébflfik {ECB} ModafltiwifilutiiiififllitlfllQlifidtlknflfllflititllillfl 6
`Figuta 2.
`Cipher Blflflk Chflining (CHE) Mgdefiwwbtlpibinnmotwllsbnunnlllntinmauolutoboo 7
`K-Bit Ciphflf Fafldhaflk (EVE) NQde..................u....».....uaa.a-~...... 9
`Figure 3.
`Figura 4.
`K_Bit 0UtpUt Feedbaflk (UFB) Mgdfilfithiabhblmtnltnlulflttnfioiwjéifibbmfillliidiiu
`Figure Al
`DES MappingS.....»s............u.-».....m..~......u.....«a..............eI2
`Electrmnic Qndebook (EC3) Made..........................l3
`Cipher Biock chaining {CEO} Made........................15
`lvfiit Cipher Feadback (GEE) Made........................17
`8wBit Ciphar Feedback (CFB) Mode........................18
`&4~Bit Cipher Feedback (CFB) Moda.......................19
`Twfiit Cipher Feedback Alternative Mada...............,..20
`56*Bit Cipher Feadback Alternative Mode.............»...21
`lwflit Output Feeéback (DFB) Mode........................2l
`flwfiit flutput Feafiback {O§B) Mada........................23
`Cipher Blank Chaining (CBC) Made fiat Authen:ic3ti0n.....25
`Cipher Feaéback (CFB) Made for Authenticatian...........2b
`fienaral Infurmation.....................................................ll
`Eiectrnnic Codebuok (KGB) Mode..........................................12
`Cipher Block Chaining {CBC} H9de........................................1é
`Ciyher Faadback (CFB) Mode.......,......................................16
`Output Feedback (DEB) Mode..............................................22
`DES Authantication T Xchnlqufiunouotnuuusuonuoiwownutiauoognpoaiapuuutconoza
`Iutro&uct1¢n. Binary data may be aryptugraphicaliy protected (encrypted) using devicea
`implemanting the &1gar1thm mpecified in th& Bata Encryption Standard (DES) {FIPS PUB 46)
`canjunutian with a Qryptagraphifl key.
`The cryptagraphic key cantruls the ancryptiun pra- ~
`idantical key must also he usad in the dearyptiuu precess
`to obtain the
`original data.
`Since the DES is publicly defined,
`cryptographic aecutity depends on
`sacreuy of the cryptographic key»
`The binary format of a cryptngraphic kay 15:
`(m,B2.... ,3m?1,Ba,....,B3!»,P2.m5,. . . $49,117,350, . . . ,E56,P8)
`where {B1,B2,...,BS6} are the indepenfient bits af a DES hay and {PI,P2,...,P8} are resexved
`§or parity bits computefi on the preneding seven inaepandent bits and set so that the ymrlty
`of the ante:
`la a&&, i.a., there is an odd number of "1" bits in the acten.
`The hexadecimal format mf a cryptagraphic key is:
`(H1H2 H3H& ... Hlfifilfifi
`wlare {Bi,H2,...,H16} are hexadecimal characters frnm the set {G,I,...,9,A,B,C.D,E,F}.
`ambfififlwd blanks in the furmat are nptiunal and lower case letters may be used in place
`ugwer case letters.
`This standard assumas that a cryptographic hay has been enterefi
`into 3 &ES device priar ta encryption or decryptian.
`1.1 Definitiann, Abbreviations, and Conventians. The follawing definitions, abbreviatimns
`ana convention$ shall he used thraughout this standard:
`A binary digit denntea as a "0“ or 3 “I.”
`A saquenca af bits.
`A binary vector censisting mf sixtywfour bits numberefi frum the left as 1, 2, ...,
`6% and denntfifi as (El,B2,...,B54).
`CBC: Ciphar Block Chaining.
`Cipher Feefihack.
`CIFHER TEXT: Encryptefi data.
`A éé*bit parameter cnnsisting of 56 independent bits and fl garity bits
`used in a DES davice ta control
`tha encrypt and dearypt operations.
`is encrypted as an entity sad denotad as
`af K bits that
`A binary vector
`(D1,D2,...,BK) where K m l,2,...,6& and whare Bl,fl2,...,DK represent bits-
`The pffltflfifi nf changing cipher text
`intu plain text.
`(Synnnym: DECI?HER).
`The state nf a DES device exacuting the éeciphering operation specified in
`HES: Data Encryptimn Standard; Epecifiefi
`in FIPS PUB hfi.
`typically an
`the HES algorithm,
`The electronic componant useé to implement
`intflgrated circuit chip or a micro“c0mput&r with the DES algorithm specified in a read*an1y
`memory pragram.
`Semi him ~
`encryption or
`A block that is entered into the DES éavice for either
`The input block shall he flesignateé {1l,I2,..a,I64) whmre Ii,I2,...,I6h repre“
`MP5 PUB 81
`A black that
`tiou af
`01,fi2,...,0fih represent bits.
`E63: Electranic Cadabauk.
`ia the final rewult af an encryption at fiecryptiun op§ra~
`autput block ahall
`(0I,G2$...?flfi&) whara
`The pracess uf changing plain taut intu ciwhe: text.
`Varb: ENCRY?T.
`?he state sf a DES dmviae axacuting the wnciphering mwaratiwn spacified in
`Exctustuawon GFERATIQN:
`tun binary vamfiwya af
`Tha bit~hy~b1t mofiuiw~E mfiflitaun mf
`This mperation is rmpresentad by 3 ”0“ in §h1a ataafiarfi.
`input blnuk in the awn and
`A binary vector usad in tha inxtiai
`QFH madeg and as the randomiaing hlouk that
`ta mxa1us£ve-fifiafl with the firmt data black
`the CBC mndg.
`The rightwmmat bitfs) as a binary wectar*
`(fiynonym: Lgw ordar h1t{$}3.
`A lmgical data wntity cmnalating mf a sequence uf flata unitfl {e.g.,
`ME$$AGE (fififilz
`outfits, characters. fixed langth numbars)
`that £3 ancryptefl as an fiflfiifiy.
`The 1aft~mast bit§53 af
`ifiynumym: High urder bit(S§)m
`a binfiry vawtmrm
`K grmmg sf Eight binary digims numbered frum Raft
`tn right: B1,B2,...,BB.
`UFB: Qutput Feadhatk.
`Unancrypted flata.
`éefified as
`The Elmctranic Cndebnnk {EEK} mmde is
`(ECB} Hmde.
`Electrmnic Qudeheok
`a plain text éata black £fl1,D2,...,Dfi&} 13
`(Figure 1}.
`In EQB angryptiun,
`diractiy a3 the DES input black (1l,$E,...,ffi&}.
`The input black is prwcesaed through a
`the encrypt state.
`The resultant autput block
`direct§y as uipher text {Cl,C2,*..,Cfi&} or may be used in auhswquant ADP applicatinna.
`is ugad fiirectly as the DES
`a ciphar text black {C1,C2,...,€fi5)
`ECB dacryptian,
`input biaak is than prmceased through 3 EH3
`fieviam in
`reaultant mutput
`(fllyfig.-«»,D5%} av may he used in munseqwant AB? appliuatiwnsu
`The ECB fiecryption pracess
`the sama ax the ECB encryptinn process axcept
`the daurypt state of the DES devica
`is used rather than thé encrypt stata.
`The Qiphat Kiosk Chaining {CBC} made is definsd a5
`Cipher Elock Chaining {EEC} Nada.
`follmws (Figure 2).
`a mesgaga ta be ancrypte& is divided inks bloaka.
`in CBC encryptinn,
`first DES input block is formed by axclusivewflfiing the first block of a message with a
`inicializatimn veetcr (IV),
`(I1,E2*...,I6&) n
`input block 13 prncessad thrnugh 3 DES deuic$ in thm encrypt state,
`the resulting
`output black is used as the cipher text,
`(£1,C2,...,C6é) =
`text black is than axc1us1ve~GR@d with the Second plain text data block
`secanfi QES input block,
`(Il,t2,...,I6&) w
`1 an& D naw refer to the sacond block.
`Thfi second input
`is procassed
`thraugh the DES fievice in the encrypt state to prnéuce the second cipher text block.
`cmntinues to "chain" successive cipher anfi plain text blmcka
`last plain text block in the message is encrypted.
`If the message
`0? an integral number cf data blacks,
`than tha final partiai data block shauid be
`mmw TEX‘?
`<:wI-am mm"
`(mama, mm *
`ma. «:2,
`T mm mcncx
`ms mcmw
`um, 02.
`{C1, C1,
`..., CIEM)

`ms i}ECR‘a'PT
`(EN, DE,
`DES macaw»?
`:2-as D£CFE‘fP'f
`“~ — 1—
`a manner specified for the application.
`Appendix C of thia standard.
`One auch method
`is described in
`the first cipher text blomk of an encrypted message is used as the input
`In CBC éecryptian,
`block and is pracessed thrnugh a DES fievice in the decrypt state,
`i.e., {I1,I2....,I5h) W
`The resulting nutput black, which equals the original input block to the
`raring encryptiom,
`fig exc1us1ve~0Red with the IV (must be same as that
`use& flaring
`first plain text
`(filfiivl,02&1V2,...,O6&$Iv6&). The secnnd cipher text block is than used aa the input bleak
`is praeessed thruugh the DES in the decrypt state and the resulting autput
`Exclusive-Sfied with the
`first cirher text block ta proéuce the second plair
`block, 1.e.,
`a (Ul%C1,02®C2,...,06&fiC6fi).
`Nafie that again &he U and
`ta the second block.
`The CBC decryption ptmce3a continues in this manna: rntil the
`cnmplete cipher text black has been decrypted.
`Cipher text repw"%enting
`a partial
`data block must he d@crypt@fi
`in a manner as specified fur tha applicatimn.
`(CPR) Hafiz. The Cipher Feedback (CFB) made is definea
`Cipher Feedback
`(Figure 3).
`A messaga ta be encrypted is d§v1ded into data units each containing K bits (K
`in bath the CFB encrypt xnd decrypt operations,
`an initialization vector
`(EV) of length L is useé.
`Tfie IV is placed in the least significant bits af the DES input
`black with the‘unused hits set
`to “0’s,"
`black is processed through the DES device in the encrypt state to
`prwduce an nutput black.
`During encryptinn,
`cipher text is produced by exc1us1ve~ORing 3
`K—bit plain text data unit with the mast significant K hits of the uutput block,
`(Cl,CE,...,CK) m (ni®01,D2%02,..,,DKm0K}. Similarly, during decryption, plain text
`is pro»
`by exc1usive~0Ring a K*bit unit cf cipher text with the most significant K bits
`the autput %Iock, 1.e., (flI,D2,...,DK) = (Ci®0l,C3$Q2,...,CK%DK).
`In both cases the unused
`bits af the DES uutput black are disc gded.
`In bath cases the next
`input block is created
`by discarfling the most significant K bits cf the previous input black,
`shifting the remain
`ning bits
`K wmsitians
`tn the left and than inserting the E bits
`in the encryption oweration or just useé in the decrypt operation intu the
`significant bit positinns, 1.e.,
`(Il,I2,...,I6&) = (IIK+1},I[K+2},...,I64,GI,C2,...,CK).
`input biack is than procassed thfmugh th& DES device in aha encrypt stata to
`the next outnut block. This pracess continues until the antite plain text message has baen
`encrypted nr until the entire cipher taxt messaga has been decrypted‘
`through 64 incluaive. K-bit
`length i
`CFB made may mperata on data unita of
`to be the QFB mmé& nparating an data unita Bf
`length K for K
`aperation of the DES device nae Kwhit unit cf plain text prméuces one K~bit unit
`cipher text or ona K*bit unit 0? cipher text pruduces sue K~bit unit cf plain text.
`acceptahla altarnative for 3~b1t CFB when encipharing 7~bit entities using an 8~bit
`Feedback path is tn insert a "1" bit in bit position fine uf the 8~bit
`feedback path, 1.e.,
`results in 3 "1" always being placeé in hit location 57 of
`DES input bimck. This alternative is called the 7~hit CPB(a) made of operation.
`The Dutput Feedback (OPE) made is defined as
`(OFB) Mode.
`Output Feedback
`(Figure A).
`A message to be encrypted is divided into data units each cantaining K bits {K
`= 1,2,...,6&).
`In both the OPE encrypt and flecrypt operations,
`an initializatimn vectar
`(IV) af
`length L is used.
`Tha IV is placed in the least significant bits of
`the DEE Input
`input black is procéssed thraugh the DES device in the
`encrypt state tn prnduce an autput black.
`During emcryptian,
`cipher text
`is pru&mced
`exc1usive—flRing a Kwbit plafin text data unit with the must significant K hing 9f
`the output
`block, 1.a.,
`m fDlBOl,D2$02,...,DK$Ofi3. Similarly, during decryptian, plain
`is prnducaé by exclusive-Dfling a Kwbit unit of cipher tex§ with tha most significant K
`hita nf the autput block,
`(Dl,D2,...,flK) = (Ci®0E,C2wGE§...,€K$0K).
`In both cases
`the unused hits of
`the DES autput block ara discarded.
`In bath cases the gext
`input block
`is created by discarding the most significant K hitg 0f
`the pravieug input black,
`remaining bits K paxitioms tn the left and then inserting the K bits of output
`This input black is then pracessed th$fiaE$Efi¥fit2gg§
` ? FEED Mex
`R 3:15
`Saga 5
`mans gtm-msrrs ‘
`ac. ans
`f PLAIN rem
`K 5115
`mum rem t
`(64-K)B%TS I
`raps we 31
`mm‘: amen:
`(64-mans gxsrrs
`sewer; mscmu 2
`K 8115
`5 £64-K)H'5 F
`K ans
`irzwwmz TEXT
`INPUT max
`{64»K) ans
`U'I'P_UT awn:
`semzx‘ mscmm
`was ‘1
`cwmzn next
`K ans
`’ K
`WPUTE amen mrrmm commms AN lNl‘nAi.lZA‘f|0N vzcmn (IV) a:m~mus'ru=;£n_
`'£‘his process continues until
`the naxt nutpui: block.
`c§ev‘ice in tfie encrypt grace to prc)=:1uc:e«
`the entire plain text messagx; has bean encrypted or untii
`the entire uziphear
`text message
`has been decrypted.
`through 65»
`length 3
`QFB mode may operate on data units; of
`defined to be the DFE mode operatzing on data units of
`length K for K =- 1,2,,...,6é:.
`each Dparatinn of
`the DES device one }(-—bit unit of plain text proéuces mm Va-bit unit mf
`cipher text 0!‘ one K-bit: unis: of cipher text prociuces one K-bit unit of plain text.
`The National Bureau uf Standards issuefi Federal Infarmation ?rocessing Standards Fublicaw
`tion 46 (FI?S PUB $6)
`in 191?. That standard specifies a cryptographic algnrithm, cemmonly
`called the Data Encryption Standard (DES) algorfithm,
`:0 he used within the Federal Gcvern~
`man: for the cryptngraphic protection of gensitive,
`but unclasaifieé,
`ccmputet data. The
`algorithm was develapad by the International Business Machines Carporaticn
`submitted tn the National Bureau cf Standar&s during an NBS public selicitation for crypta~
`graphic algorithmfi
`to he used in a Federal Infarmatian Pracessing Stanfiard.
`Several meth-
`inearporating this algerithm inta a cryptcgraphic system are possible.
`to the DES algorithm,
`have come to be called the "mndas of
`Faur mades,
`the Electrnnic Codehcok (EBB) mafia,
`the Cipher Black chaining
`the Cipher Feedback (CFB) made. anfi
`the Output Feedback (DEB) made. are specified in
`ECB is a direct applicatian cf the DES algorithm :9 encrypt
`and decrypt
`CBC is an enhancefl mmée of ECE which chains together blocks of cipher text; BFB uhes
`pteviausly generated cipher
`text as input
`tn the DES ta generate pseuda-random nufigutfi
`are combined with the plain text
`to prnéuce cipher text.
`thereby chaining fingether
`the resulting cipher text;
`OFB is identical to CFE except that
`the previous eutput af
`ia useé as input
`in DFB while the previous cipher text
`is used as input
`in CFB.
`dues not chain the ciphar text.
`The proyosed FI?S specifies these fuur modes becauae they
`capable of prnvifiing acceptable levels of protaction far all antizipated unclassified
`Feéeral ADP encryption applications.
`Unencrypted data is called plain text. Encryptimn (also calied encipharing) 15 the prccesa
`transforming plain text
`intu cipher text.
`Decryption {also called deciphering) 13 the
`inverse transfarmation.
`The encryption and flecryptian processes are parformed accnrding £6
`a sat qf rules,
`called an algorithm,
`is typically based on a parameter called a hay‘
`is usually the only parameter that must ha provideé to or by
`the users
`cryptagraphic system ané must be kept secret.
`The pariod af
`time over which a particular
`key is used to encrygt er decrypt data is called itg crypcoperiod.
`tha set of all possible 64wbit vecturg
`DES maps
`including ail
`?igure AE. There are 216% (2 raised tn the 64th pmwer) elements in this set,
`binary numbars from G up ta,
`but nut
`The DES cryptographic key allows a
`user to select any sue uf 2156 pussible invertible mappings, i.e., transfarmatians that are
`Selecting a key selects aha of
`the mappings.
`when using the SE5 in ECB mode
`any particular key,
`each input
`is mappad auto 3 unique output
`in encryhticn and
`is mapped
`back onta the input
`in decryption.
`Tha DES is
`prnduct cipher system (i.e., ancryption algmrithmfi.
`A praduct cipher system mixes transpe~
`aition and suhstitutian operations in an alternating manner.
`Eacause the
`3 &&~h1t
`input block ante a 6fi—hit nutput hlack the BBB is called a
`Iterative rhfers to the usa of
`the mutput af an aperatinn as the input far another
`iteration 0f the sama prnraéure.
`The DES intarnally uges sixteen iterations of a pair of
`transpmsitian and substitution aperations to encrypt or decrypt an input block.
`A cempleta
`specification af the DES algarithm is found in FIFE PUB #6.
`of methads for incarporating the DES in a crypingraphic system are
`and fitream methods.
`In a bfiack methofi,
`tha DES input block 1% (at is
`function of)
`the plain text
`to be anctypted ané the DES autput black is the cipher text.
`stream methhd is based on generating a pseuda~random binary stream of bits,
`and then using
`¢xc}usive~0R binary aperation tn cambine thig pseudo~random sequanue wiflh
`the plaifi
`to produce
`cipher text.
`Since the exc1us£v2~0R aperatsr is
`awn binary
`p3eufio*random binary atream is uaad far both the encryption of plain
`and the dacryptian of cipher text, C.
`If H is the pseudo-randnm hinary stream,
`then C = P 9 O and inver$e}y, P R C 9 0.
`‘ mum? smug
`2“ ELENT5
`The Electtnnic Coéebaok (RC3) mode is a basic, black, crypcngraphic methad which aransforms
`GA bits
`to fié bits cf output as spacified in FIP$ PUB #6.
`gndehonk griaes
`the eama plain text block alwayfi prnéuces the same
`far a given cryptagraphim Ray.
`Yhus a list (or cedabook) of plain text blacks
`corregponding cipher twat blacks theoretically cuulé be constructed For any given Ray.
`electronic implementation the csdebook entrias are calculated each time far the plain text
`to be encrypted and,
`invarsely, Ear
`thv cipher text
`to be decrvpted.
`gash bit 05 an ECE output block is a cmmplex function of all 64 hits 0?
`block and all
`56 independent (non-parity) hitfi 05 the cryntngraphic key, a single bit urrur
`in either a cipher text bleak nr the nanwparity kfiy hits used far decryption wiil cause the
`piain text hiock to have an avarage error rate af fifty percent.
`in one RC8 ciphar text block will net affect
`the decrypxion of other biocks,
`there is no errnr extfinsinn between ECB blocks.
`a bit
`black baundaries are fast between encryptien and decryptian (e.g.,
`synchrmnization between {H9 encryptian and fiecryption aperationg will be last until correat
`The results of all decryptinn operatiuns wiil

