The Security of DESX

Phillip Rogaway · 1996

or specific higher-level tasks such as encryption. The most well-known suggestion to strengthen DES is "triple DES," one version of this being defined by EDE3 k1:k2:k3 (x) = DES k3 (DES \\Gamma1 k2 (DES k1 (x))). That is, the key for EDE3 is 56 \\Theta 3 = 168 bits, and one enciphers a 64-bit block by enciphering under one 56-bit subkey, deciphering under a second, then enciphering under a third. (The reason the second step is DES \\Gamma1 k2 and not DES k2 is for DES-compatibility: set K = k:k:k to make EDE3K = DES k . The reason for using DES three times instead of two is the existence of "meet-in-the-middle" attacks on double DES.) The problem with triple DES is that it i

Read the paper · More papers on PaperTik