Data Encryption Standard (DES).
page maintained by Nicolas T. Courtois
The Data Encryption Standard (DES) is the old Federal Information Processing Standard (FIPS PUB 46). It have been used for over 25 years by the U.S. Government organisations to protect sensitive (unclassified) information. DES was designed in the 70s. Hundreds of researchers tried to break it, and from the practical point of view, nobody really succeeded.
Unfortunately, DES and triple DES remains the most widely used cipher in commercial and financial applications. If it was badly broken, the output could be truly devastating.
The goal of this page is to stimulate research on DES, and to inform the public about any potential or real weakness of DES. External contribution is welcome.
![]()
Main Classical Papers on Attacking DES.
![]()
Recent Developments in The Security of DES, New/Improved Attacks:

Orr Dunkelman, Gautham Sekar, and Bart Preneel: Improved Meet-in-the-Middle Attacks on Reduced-Round DES, To appear in Indocrypt 2007.

Nicolas Courtois, Gregory V. Bard: Algebraic Cryptanalysis of the Data Encryption Standard, to appear in 11-th IMA Conference, Cirencester, UK, 18-20 December 2007, see also eprint.iacr.org/2006/402/. Also be presented at ECRYPT workshop Tools for Cryptanalysis in Krakow, 24-25 September. Available at eprint.iacr.org/2006/402/. The equations exploited in this paper can be downloaded from here.
![]()
Recent Work of Smaller Importance:
![]()
The Security of DES should NOT be taken for granted:
New Ideas and Strange Properties of DES.
![]()
Interesting links:
Crypto Debates: The difficult question of strong cryptography
The AES 1 million dollar challenge (or why there should be such a thing)
Security of important ciphers used in practice: Security of DES
AES: is the new encryption standard already broken ?
New algebraic attacks on encrytion algorithms:
Algebraic attacks on block ciphers and AES
Algebraic attacks applied to stream ciphers
Positive applications of multivariate equations:
promoting/about multivariate cryptography:
The McEliece_based short signature scheme CFS
The HFE cryptosystem home page
The Minrank Zero-knowledge identification scheme
Quartz /Flash /Sflash signature schemes
Nicolas Courtois research page
TTM cryptosystem, GPT cryptosystem,
Open Problems in Multivariate Cryptography (Stork Document)
![]()
Maintained by Nicolas T. Courtois
Last updated on 09th of September 2003.