<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 skin-theme-clientpref-day vector-sticky-header-enabled" lang="de" dir="ltr"><head>
<meta charset="UTF-8">
<title>Data Encryption Standard</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://de.wikipedia.org/wiki/Data_Encryption_Standard"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.math.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link href="./_mw_/ext.gadget.citeRef.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.defaultPlainlinks.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonHide.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonLayout.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiCommonStyle.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiDarkmode.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.dewikiResponsive.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.gadget.specialSearch.css" rel="stylesheet" type="text/css">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Data_Encryption_Standard rootpage-Data_Encryption_Standard skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">Data Encryption Standard</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="de" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="de" dir="ltr"><table class="float-right infobox wikitable" style="font-size:90%; margin-top:0; width:23em;">
<tbody><tr>
<th colspan="2" class="hintergrundfarbe6" style="font-size:105%;">DES
</th></tr>
<tr>
<td colspan="2" style="text-align:center;"><small>Eine Feistel-Runde (F-Funktion)</small>
</td></tr>
<tr>
<td>Entwickler
</td>
<td><a href="IBM" title="IBM">IBM</a>
</td></tr>
<tr>
<td>Veröffentlicht
</td>
<td>1975
</td></tr>
<tr>
<td>Abgeleitet von
</td>
<td><a href="Lucifer_(Kryptographie)" title="Lucifer (Kryptographie)">Lucifer</a>
</td></tr>
<tr>
<td>Zertifizierung
</td>
<td>als <a href="Federal_Information_Processing_Standard" title="Federal Information Processing Standard">FIPS</a> PUB 46 durch <a href="National_Bureau_of_Standards" class="mw-redirect" title="National Bureau of Standards">NBS</a>
</td></tr>
<tr>
<td>Schlüssellänge
</td>
<td>56 Bit
</td></tr>
<tr>
<td>Blockgröße
</td>
<td>64 Bit
</td></tr>
<tr>
<td>Struktur
</td>
<td><a href="Feistelchiffre" title="Feistelchiffre">Feistelchiffre</a>
</td></tr>
<tr>
<td>Runden
</td>
<td>16
</td></tr>
<tr>
<th colspan="2" class="hintergrundfarbe6">Beste bekannte Kryptoanalyse
</th></tr>
<tr>
<td colspan="2" style="text-align:center;">Bester analytischer Angriff ist die <a href="Lineare_Kryptoanalyse" title="Lineare Kryptoanalyse">lineare Kryptoanalyse</a> mit 2<sup>43</sup> bekannten Klartextblöcken. <a href="Brute_Force" class="mw-redirect" title="Brute Force">Brute-Force</a>-Angriffe finden den verwendeten Schlüssel nach wenigen Stunden.
</td></tr></tbody></table>
<p>Der <b>Data Encryption Standard</b> (<b>DES</b>; deutsch „Datenverschlüsselungsstandard“) ist ein weit verbreiteter <a href="Symmetrische_Verschl%C3%BCsselung" class="mw-redirect" title="Symmetrische Verschlüsselung">symmetrischer Verschlüsselungsalgorithmus</a>, eine sogenannte <a href="Blockchiffre" class="mw-redirect" title="Blockchiffre">Blockchiffre</a>.
</p><p>Der DES-Algorithmus wurde als offizieller Standard für die US-Regierung (siehe <a href="Federal_Information_Processing_Standard" title="Federal Information Processing Standard">FIPS</a> 46) im Jahr 1977 bestätigt und wird seither international vielfach eingesetzt. Seine Entstehungsgeschichte hat wegen der Beteiligung der <a href="National_Security_Agency" title="National Security Agency">NSA</a> am Design des <a href="Algorithmus" title="Algorithmus">Algorithmus</a> immer wieder Anlass zu <a href="Hypothese" title="Hypothese">Spekulationen</a> über seine Sicherheit gegeben. DES wurde schon kurz nach seiner Veröffentlichung aufgrund der verwendeten <a href="Schl%C3%BCssell%C3%A4nge" title="Schlüssellänge">Schlüssellänge</a> von nur 56 <a href="Bit" title="Bit">Bits</a> als nicht ausreichend sicher erachtet.
</p><p>Die Schlüssellänge kann durch Mehrfachanwendung des DES jedoch auf einfache Weise vergrößert werden. Als Triple-DES, auch als TDES, 3DES oder DESede bezeichnet, wird der DES weiterhin am häufigsten, zum Beispiel von Banken in Chipkartenanwendungen, eingesetzt, obwohl der TDES als offizieller Standard für die USA durch den <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">Advanced Encryption Standard</a> (AES) abgelöst wurde.
</p>
<div class="mw-heading mw-heading2"><h2 id="Geschichte">Geschichte</h2></div>
<p>Zu Beginn der 1970er Jahre war zwar die <a href="Milit%C3%A4r" title="Militär">militärische</a> <a href="Kryptologie" title="Kryptologie">Kryptologie</a> auf einem hohen Niveau, für nichtmilitärische Anwendungen waren jedoch kaum brauchbare Produkte verfügbar. Das <a href="National_Bureau_of_Standards" class="mw-redirect" title="National Bureau of Standards">National Bureau of Standards</a> (NBS) der <a href="Vereinigte_Staaten" title="Vereinigte Staaten">USA</a> – heute <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> (NIST) – sah Bedarf für einen einheitlichen Standard für die behördenübergreifende Verschlüsselung vertraulicher Daten. Nach Beratungen mit der NSA veröffentlichte es am 15. Mai 1973 im <a href="Federal_Register" title="Federal Register">Federal Register</a> eine <a href="Ausschreibung" title="Ausschreibung">Ausschreibung</a>. Insbesondere sollte die Sicherheit des Algorithmus nach <a href="Kerckhoffs%E2%80%99_Prinzip" title="Kerckhoffs’ Prinzip">Kerckhoffs’ Prinzip</a> nur von der Geheimhaltung des <a href="Schl%C3%BCssel_(Kryptologie)" title="Schlüssel (Kryptologie)">Schlüssels</a>, nicht aber von der Geheimhaltung des Algorithmus abhängen. Keiner der eingereichten Kandidaten erfüllte jedoch die gestellten Bedingungen, was zu einer neuerlichen Ausschreibung am 27. August 1974 führte.
</p><p><a href="IBM" title="IBM">IBM</a> lieferte einen vielversprechenden Vorschlag, der auf einer Weiterentwicklung des wenige Jahre zuvor unter der Mitarbeit von <a href="Horst_Feistel" title="Horst Feistel">Horst Feistel</a> entwickelten Algorithmus „<a href="Lucifer_(Kryptographie)" title="Lucifer (Kryptographie)">Lucifer</a>“ beruhte. Dieser Algorithmus zeichnete sich dadurch aus, dass er einfache <a href="Logische_Operatoren" class="mw-redirect" title="Logische Operatoren">logische Operationen</a> auf kleinen Bitgruppen nutzte und dadurch leicht in Hardware implementierbar war. Neben Feistel selbst waren auch Walter Tuchman, <a href="Don_Coppersmith" title="Don Coppersmith">Don Coppersmith</a>, <a href="Alan_Konheim" title="Alan Konheim">Alan Konheim</a>, Carl Meyer, Mike Matyas, Roy Adler, <a href="Edna_Grossman" title="Edna Grossman">Edna Grossman</a>, Bill Notz, Lynn Smith und <a href="Bryant_Tuckerman" title="Bryant Tuckerman">Bryant Tuckerman</a> Mitglieder des IBM-Entwicklungsteams.
</p>
<div class="mw-heading mw-heading3"><h3 id="Die_Rolle_der_NSA">Die Rolle der NSA</h3></div>
<p>NBS und IBM beschlossen eine Kooperation mit Unterstützung der <a href="National_Security_Agency" title="National Security Agency">National Security Agency</a> (NSA). Welchen Einfluss die NSA auf die Entwicklung des Algorithmus hatte, ist umstritten. Vor allem die <a href="Schl%C3%BCssell%C3%A4nge" title="Schlüssellänge">Schlüssellänge</a> von 56 Bits und das Design der für Substitution zuständigen „<a href="S-Box" title="S-Box">S-Boxen</a>“ gab Anlass zu Spekulation über mögliche Hintertüren, die eventuell durch die NSA eingeführt wurden. Nach eigenen Angaben stärkte die NSA die S-Boxen gegen <a href="Differentielle_Kryptoanalyse" class="mw-redirect" title="Differentielle Kryptoanalyse">differentielle Kryptoanalyse</a>, wollte aber gleichzeitig die Schlüssellänge auf 48 Bits beschränken, während IBM 64 Bits wollte. Als Kompromiss einigten sich NSA und IBM auf eine Schlüssellänge von 56 Bits.<sup id="cite_ref-1" class="reference"><a href="#cite_note-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>
</p><p>Am 17. März 1975 wurde der Algorithmus im „Federal Register“ veröffentlicht. Die NBS bat zudem um öffentliche Stellungnahme. Im folgenden Jahr wurden zwei Workshops zum vorgeschlagenen Standard abgehalten. Durch die unklare Rolle der NSA zogen die Veränderungen des Algorithmus von verschiedenen Seiten Kritik auf sich, unter anderem von den Pionieren <a href="Asymmetrisches_Kryptosystem" title="Asymmetrisches Kryptosystem">asymmetrischer Kryptosysteme</a> <a href="Martin_Hellman" title="Martin Hellman">Martin Hellman</a> und <a href="Whitfield_Diffie" title="Whitfield Diffie">Whitfield Diffie</a>. Es wurde gemutmaßt, die NSA habe eine <a href="Hintert%C3%BCr" class="mw-redirect" title="Hintertür">Hintertür</a> eingebaut, welche das Verfahren dergestalt schwächt, dass sie damit verschlüsselte Nachrichten lesen konnte. Alan Konheim, einer der DES-Entwickler, gab an, die S-Boxen nach Washington gesendet und stark verändert wiedererhalten zu haben.<sup id="cite_ref-schneier_2-0" class="reference"><a href="#cite_note-schneier-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>Ein nachrichtendienstliches Komitee des <a href="Senat_der_Vereinigten_Staaten" title="Senat der Vereinigten Staaten">US-Senats</a> untersuchte die Einflussnahme des NSA. In der nicht als <a href="Verschlusssache" title="Verschlusssache">Verschlusssache</a> gehandhabten Zusammenfassung des Berichts gaben sie 1978 an:<sup id="cite_ref-ussenat_3-0" class="reference"><a href="#cite_note-ussenat-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>
</p>
<div class="Vorlage_Zitat" style="margin:1em 40px;">
<div style="margin:1em 0;"><blockquote lang="en" style="margin:0;">
<p>“In the development of DES, NSA convinced IBM that a reduced key size was sufficient; indirectly assisted in the development of the S-box structures; and certified that the final DES algorithm was, to the best of their knowledge, free from any statistical or mathematical weakness. […]<br>
NSA did not tamper with the design of the algorithm in any way. IBM invented and designed the algorithm, made all pertinent decisions regarding it, and concurred that the agreed upon key size was more than adequate for all commercial applications for which the DES was intended.”
</p>
</blockquote>
<blockquote style="margin:.5em 0 0 0;" lang="de-Latn">
<p>„Während der Entwicklung von DES überzeugte die NSA IBM davon, dass eine reduzierte Schlüssellänge ausreichend sei; half indirekt bei der Konstruktion der S-Boxen; und zertifizierte den entstehenden DES-Algorithmus als nach bestem Gewissen frei von statistischen und mathematischen Schwächen. […]<br>
Die NSA veränderte das Design des Algorithmus in keiner Weise. IBM entwarf und entwickelte diesen, traf alle sachdienlichen Entscheidungen und stimmte darin überein, dass die verkürzte Schlüssellänge mehr als adäquat für die vorgesehenen kommerziellen Verwendungen sei.“
</p>
</blockquote></div></div>
<p>Walter Tuchman, ein weiterer DES-Entwickler, wird mit den Worten zitiert “We developed the DES algorithm entirely within IBM using IBMers. The NSA did not dictate a single wire!” (deutsch: „Wir haben den DES-Algorithmus vollständig innerhalb von IBM unter Nutzung von IBMern entwickelt. Die NSA hat nicht ein einziges Memo diktiert!“).<sup id="cite_ref-kinnucan_4-0" class="reference"><a href="#cite_note-kinnucan-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup>
</p><p>Durch die Veröffentlichung der <a href="Differentielle_Kryptoanalyse" class="mw-redirect" title="Differentielle Kryptoanalyse">differentiellen Kryptoanalyse</a> durch <a href="Adi_Shamir" title="Adi Shamir">Adi Shamir</a> und <a href="Eli_Biham" title="Eli Biham">Eli Biham</a> im Jahr 1990 wurden einige der Befürchtungen einer Hintertür aus dem Wege geräumt. DES zeigte sich durch die Gestaltung der S-Boxen deutlich widerstandsfähiger gegen diese generische Angriffsmethode, als dies bei einer zufälligen Anordnung der Fall gewesen wäre.<sup id="cite_ref-biham_5-0" class="reference"><a href="#cite_note-biham-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> 1994 veröffentlichte Don Coppersmith die ursprünglichen Designkriterien für die S-Boxen.<sup id="cite_ref-coppersmith_6-0" class="reference"><a href="#cite_note-coppersmith-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup> Es zeigte sich, dass IBM die differentielle Kryptoanalyse bereits in den 1970er Jahren entdeckt hatte und nach Umgestaltung der S-Boxen von der NSA zur Geheimhaltung instruiert worden war.
</p><p>Coppersmith erklärte “that was because [differential cryptanalysis] can be a very powerful tool, used against many schemes, and there was concern that such information in the public domain could adversely affect national security.”
(deutsch: „dies geschah, da die [differentielle Kryptoanalyse] ein mächtiges Werkzeug gegen viele Verfahren sein kann und es Bedenken gab, die nationale Sicherheit könne durch eine Veröffentlichung gefährdet werden.“).<sup id="cite_ref-coppersmith2_7-0" class="reference"><a href="#cite_note-coppersmith2-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>
</p><p>Shamir selbst kommentierte “I would say that, contrary to what some people believe, there is no evidence of tampering with the DES so that the basic design was weakened.”
(deutsch: „Anders als manche glauben, sehe ich selbst keine Hinweise auf Manipulation von DES, welche das grundlegende Design geschwächt hat.“)
</p><p>Die Kritik an der Länge des Schlüssels blieb jedoch bestehen und wurde durch die Begründung der NSA, 8 der 64 Schlüsselbits könnten als <a href="Parit%C3%A4tsbit" title="Paritätsbit">Paritätsbits</a> verwendet werden, noch weiter gestützt. Es wird weithin vermutet, dass die Reduzierung der NSA die Möglichkeit eines Angriffs mit der <a href="Brute-Force-Methode" title="Brute-Force-Methode">Brute-Force-Methode</a> schaffen sollte.
</p><p>Heute gilt der DES aufgrund seiner geringen Schlüssellänge als nicht mehr sicher genug. Durch die Mehrfachanwendung des DES mit unterschiedlichen Schlüsseln wie zum Beispiel beim TDES kann die effektive Schlüssellänge erhöht werden.
</p><p>Wissenschaftliche Untersuchungen haben mittlerweile erwiesen, dass DES trotz seiner Schlüssellänge von nur 56 Bits sicherer ist als der Lucifer-Algorithmus mit seinen 128 Bits.<sup id="cite_ref-benaroya_8-0" class="reference"><a href="#cite_note-benaroya-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Standardisierung">Standardisierung</h3></div>
<p>DES wurde als Standard für alle amerikanischen Bundesbehörden zugelassen und am 15. Januar 1977 als <i>FIPS PUB 46</i> publiziert; verpflichtend für sie wurde er sechs Monate später. Der Standard enthielt die Auflage, alle fünf Jahre neu bestätigt werden zu müssen. Weiterhin befasste sich die <a href="Internationale_Organisation_f%C3%BCr_Normung" title="Internationale Organisation für Normung">Internationale Organisation für Normung</a> (ISO) mit dem Algorithmus unter der Bezeichnung Data Encipherment No. 1 (DEA1).
</p><p>1981 wurde der DES-Algorithmus vom <a href="American_National_Standards_Institute" title="American National Standards Institute">American National Standards Institute</a> (ANSI) als <a href="Standard" title="Standard">Standard</a> für den privaten Sektor anerkannt.
</p><p>Bereits Anfang der 1990er Jahre äußerten Kryptographen erste Zweifel, ob der DES-Algorithmus noch als sicher anzusehen sei. Zum einen hatte sich die Hardware im Vergleich zu 1970 stark weiter entwickelt, zum anderen glaubte man auch Schwächen im Algorithmus zu erkennen. 1994 wurde ein theoretischer Angriff mittels <a href="Lineare_Kryptoanalyse" title="Lineare Kryptoanalyse">linearer Kryptoanalyse</a> publiziert.
Mitte 1998 führte die <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">Electronic Frontier Foundation</a> (EFF) einen erfolgreichen Angriff über die <a href="Brute-Force-Methode" title="Brute-Force-Methode">Brute-Force-Methode</a> durch. Die Gesellschaft baute hierzu eine spezielle <a href="Hardware" title="Hardware">Hardware</a> mit insgesamt über 1800 <a href="Mikroprozessor" title="Mikroprozessor">Mikroprozessoren</a><sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup> und konnte mit dieser einen <a href="Schl%C3%BCssel_(Kryptologie)" title="Schlüssel (Kryptologie)">Schlüssel</a> in weniger als drei Tagen brechen. Die Arbeiten am Nachfolgestandard <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">AES</a> hatten zu diesem Zeitpunkt schon begonnen. Am 26. Mai 2002 wurde DES schließlich durch AES ersetzt.
</p><p>Die Einführung von DES gilt als Auslöser einer Vielzahl kryptographischer Studien, besonders solcher, die sich mit dem Angriff auf Blockchiffrierungen befassen. <a href="Bruce_Schneier" title="Bruce Schneier">Bruce Schneier</a> schreibt in seinem Buch <i>Angewandte Kryptographie</i>:
</p>
<div class="Vorlage_Zitat" style="margin:1em 40px;">
<div style="margin:1em 0;"><blockquote style="margin:0;">
<p>„Inoffiziell bezeichnete die NSA den DES als einen ihrer größten Fehler. Hätte die Behörde gewußt, daß die Einzelheiten herausgegeben und Softwareimplementierungen möglich wurden, hätte sie niemals zugestimmt. Mehr als alles andere revolutionierte DES die gesamte Kryptoanalyse. Jetzt gab es einen Algorithmus, den man untersuchen konnte – sogar einen, den die NSA als sicher bezeichnete.“<sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>
</p>
</blockquote>
</div></div>
<div class="mw-heading mw-heading3"><h3 id="Chronologie">Chronologie</h3></div>
<table class="wikitable">
<tbody><tr>
<th colspan="2">Datum
</th>
<th>Ereignis
</th></tr>
<tr>
<td>15. Mai</td>
<td>1973</td>
<td>Das NBS veröffentlicht eine erste Ausschreibung für ein standardisiertes Verschlüsselungsverfahren
</td></tr>
<tr>
<td>27. August</td>
<td>1974</td>
<td>Das NBS veröffentlicht eine zweite Ausschreibung für ein standardisiertes Verschlüsselungsverfahren
</td></tr>
<tr>
<td>17. März</td>
<td>1975</td>
<td>DES wird im „Federal Register“ veröffentlicht
</td></tr>
<tr>
<td>August</td>
<td>1976</td>
<td>Erster Workshop zu DES
</td></tr>
<tr>
<td>September</td>
<td>1976</td>
<td>Zweiter Workshop, welcher die mathematischen Grundlagen von DES behandelt
</td></tr>
<tr>
<td>November</td>
<td>1976</td>
<td>DES wird als Standard zugelassen
</td></tr>
<tr>
<td>15. Januar</td>
<td>1977</td>
<td>DES wird als FIPS-Standard „FIPS PUB 46“ veröffentlicht
</td></tr>
<tr>
<td>Juni</td>
<td>1977</td>
<td><a href="Whitfield_Diffie" title="Whitfield Diffie">Diffie</a> und <a href="Martin_Hellman" title="Martin Hellman">Hellman</a> argumentieren, dass DES per brute force geknackt werden kann<sup id="cite_ref-dh-exh_11-0" class="reference"><a href="#cite_note-dh-exh-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</td></tr>
<tr>
<td></td>
<td>1983</td>
<td>DES wird das erste Mal neu bestätigt
</td></tr>
<tr>
<td></td>
<td>1986</td>
<td>Videocipher II, ein auf DES basierendes Verschlüsselungssystem für Fernsehsatelliten wird von der <a href="Home_Box_Office" title="Home Box Office">HBO</a> verwendet
</td></tr>
<tr>
<td>22. Januar</td>
<td>1988</td>
<td>DES wird als „FIPS 46-1“ revalidiert, welches FIPS PUB 46 ersetzt
</td></tr>
<tr>
<td></td>
<td>1992</td>
<td>Biham und Shamir publizieren den ersten theoretischen Angriff mit gegenüber der Brute-Force-Methode verminderter <a href="Komplexit%C3%A4t_(Informatik)" title="Komplexität (Informatik)">Komplexität</a>: die differentielle Kryptanalyse. Dieser Angriff erfordert jedoch unrealistische 2<sup>47</sup> frei gewählte Klartexte.
</td></tr>
<tr>
<td>30. Dezember</td>
<td>1993</td>
<td>DES wird ein drittes Mal bestätigt, diesmal als „FIPS 46-2“
</td></tr>
<tr>
<td></td>
<td>1994</td>
<td>Die erste experimentelle Kryptoanalyse von DES wird mittels <a href="Lineare_Kryptoanalyse" title="Lineare Kryptoanalyse">linearer Kryptoanalyse</a> durchgeführt (Matsui, 1994)
</td></tr>
<tr>
<td>Juni</td>
<td>1997</td>
<td>Das DESCHALL-Projekt bricht erstmals öffentlich eine mit DES verschlüsselte Nachricht
</td></tr>
<tr>
<td>Juli</td>
<td>1998</td>
<td>Der DES-Knacker „<a href="EFF_DES_Cracker" title="EFF DES Cracker">Deep Crack</a>“ der <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">Electronic Frontier Foundation</a> bricht einen DES-Schlüssel binnen 56 Stunden
</td></tr>
<tr>
<td>Januar</td>
<td>1999</td>
<td>Deep Crack und <a href="Distributed.net" title="Distributed.net">distributed.net</a> brechen in einer Kooperation einen DES-Schlüssel in 22 Stunden und 15 Minuten
</td></tr>
<tr>
<td>25. Oktober</td>
<td>1999</td>
<td>DES wird ein viertes Mal in Gestalt des „FIPS 46-3“ bestätigt. Dieser gibt als bevorzugte Anwendung <a href="3DES" class="mw-redirect" title="3DES">3DES</a> an und erlaubt DES selbst nur für den Einsatz in veralteten Systemen
</td></tr>
<tr>
<td>26. November</td>
<td>2001</td>
<td>Der <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">Advanced Encryption Standard</a> (AES) wird als „FIPS 197“ publiziert
</td></tr>
<tr>
<td>26. Mai</td>
<td>2002</td>
<td>Der AES tritt in Kraft
</td></tr>
<tr>
<td>26. Juli</td>
<td>2004</td>
<td>Im „Federal Register“ wird die Absetzung des FIPS 46-3 und verwandter Standards empfohlen
</td></tr>
<tr>
<td>19. Mai</td>
<td>2005</td>
<td>NIST setzt den FIPS 46-3 außer Kraft
</td></tr>
<tr>
<td>März</td>
<td>2006</td>
<td>Der FPGA-basierte Parallelrechner <a href="Copacobana" title="Copacobana">COPACOBANA</a> kostet weniger als 10.000 Dollar (Materialkosten) und bricht DES in weniger als 9 Tagen
</td></tr>
<tr>
<td>November</td>
<td>2008</td>
<td>Die Weiterentwicklung des FPGA-basierten Parallelrechners COPACOBANA, die RIVYERA, bricht DES erstmals in weniger als einem Tag
</td></tr></tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Funktionsweise">Funktionsweise</h2></div>
<p>Bei DES handelt es sich um einen <a href="Symmetrischer_Verschl%C3%BCsselungsalgorithmus" class="mw-redirect" title="Symmetrischer Verschlüsselungsalgorithmus">symmetrischen Algorithmus</a>, das heißt zur Ver- und Entschlüsselung wird derselbe Schlüssel verwendet. DES funktioniert als <a href="Blockchiffre" class="mw-redirect" title="Blockchiffre">Blockchiffre</a>, jeder Block wird also unter Verwendung des Schlüssels einzeln chiffriert, wobei die Daten in 16 <a href="Iteration" title="Iteration">Iterationen</a> beziehungsweise Runden von Substitutionen und <a href="Transposition_(Kryptographie)" title="Transposition (Kryptographie)">Transpositionen</a> (<a href="Permutation" title="Permutation">Permutation</a>) nach dem Schema von <a href="Feistelchiffre" title="Feistelchiffre">Feistel</a> „<a href="Verw%C3%BCrfelung" title="Verwürfelung">verwürfelt</a>“ werden. Die Blockgröße beträgt 64 Bits, das heißt ein 64-Bit-Block <a href="Klartext_(Kryptographie)" title="Klartext (Kryptographie)">Klartext</a> wird in einen 64-Bit-Block <a href="Chiffretext" class="mw-redirect" title="Chiffretext">Chiffretext</a> transformiert. Auch der Schlüssel, der diese Transformation kontrolliert, besitzt 64 Bits. Jedoch stehen dem Benutzer von diesen 64 Bits nur 56 Bits zur Verfügung; die übrigen 8 Bits (jeweils ein Bit aus jedem <a href="Byte" title="Byte">Byte</a>) werden zum <a href="Parit%C3%A4tsbit" title="Paritätsbit">Paritäts-Check</a> benötigt. Die effektive Schlüssellänge beträgt daher nur 56 Bits. Die Entschlüsselung wird mit dem gleichen Algorithmus durchgeführt, wobei die einzelnen Rundenschlüssel in umgekehrter Reihenfolge verwendet werden.
</p><p>Auf den 64-Bit-Block wird eine initiale Permutation angewandt. Danach wird der Block in zwei Teile aufgeteilt und jeder Teil in ein 32-Bit-Register gespeichert. Die beiden Blockhälften werden in Folge als linke und rechte Hälfte (siehe Skizze) bezeichnet. Auf die rechte Blockhälfte wird die <a href="#Die_Feistel-Funktion">Feistel-Funktion</a> angewandt. Danach wird die rechte Hälfte mit der linken Hälfte XOR verknüpft und das Ergebnis im Register der nächsten Runde für die rechte Hälfte gespeichert. In das linke Register der nächsten Runde wird die ursprüngliche rechte Blockhälfte kopiert. Nach Ende der letzten Runde werden die beiden Hälften vertauscht zusammengeführt und eine finale Permutation durchgeführt. Dabei handelt es sich um die <a href="Inverse_Permutation" class="mw-redirect" title="Inverse Permutation">inverse Permutation</a> zur initialen Permutation.
</p>
<div class="mw-heading mw-heading3"><h3 id="Betriebsmodi">Betriebsmodi</h3></div>
<p>Der DES-Algorithmus beschreibt zunächst nur, wie ein <a href="Datenblock" title="Datenblock">Datenblock</a> mit 64 Bits verarbeitet wird. Zur Verarbeitung einer Nachricht beliebiger Länge lässt sich der DES wie auch jede andere Blockchiffre in verschiedenen <a href="Betriebsmodus_(Kryptographie)" title="Betriebsmodus (Kryptographie)">Betriebsmodi</a> verwenden. Für bestimmte Betriebsmodi, wie zum Beispiel <a href="Electronic_Code_Book_Mode" title="Electronic Code Book Mode">ECB</a> oder <a href="Cipher_Block_Chaining_Mode" title="Cipher Block Chaining Mode">CBC</a>, ist ein Auffüllen des Klartextes auf ein Vielfaches der vollen Blocklänge notwendig (<a href="Padding_(Informatik)" title="Padding (Informatik)">Padding</a>). Dies geschieht, indem die Bitfolge 1000… angehängt wird.
</p>
<div class="mw-heading mw-heading2"><h2 id="Die_Feistel-Funktion">Die Feistel-Funktion</h2></div>
<p>Die <i>F</i>-Funktion von DES arbeitet auf Halbblöcken zu je 32 Bits und besteht aus vier Phasen:<sup id="cite_ref-HoAC_12-0" class="reference"><a href="#cite_note-HoAC-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>
</p>
<ol><li>Die R-Blöcke werden mittels einer geeigneten Permutation <i>E</i> (<i>Expansion</i>) auf 48 Bits Länge expandiert, indem einzelne Bits mehrfach verwendet werden.</li>
<li>Das Ergebnis wird mit einem Teilschlüssel XOR-verknüpft. Für jede Runde wird hierzu nach einer festen Vorschrift ein anderer 48-Bit-Teilschlüssel aus dem Hauptschlüssel generiert.</li>
<li>Die resultierenden Blöcke werden in acht 6-Bit-Stücke zerteilt und diese mittels Substitution durch S-Boxen auf eine Länge von 4 Bits komprimiert. Diese nicht-lineare Transformierung in den S-Boxen stellt das Herzstück der Sicherheit von DES dar, ohne sie wäre DES linear und trivial zu brechen.</li>
<li>Die 32 Bits Ausgabe der S-Boxen werden mittels einer festen Permutation <i>P</i> rearrangiert.</li></ol>
<p>Diese Kombination aus Permutationen und Substitutionen entspricht dem von <a href="Claude_Shannon" title="Claude Shannon">Claude Shannon</a> aufgestellten Prinzip der <a href="Diffusion_(Kryptologie)" title="Diffusion (Kryptologie)">Diffusion</a> und <a href="Konfusion_(Kryptologie)" title="Konfusion (Kryptologie)">Konfusion</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="Die_Expansion">Die Expansion</h3></div>
<p>Um den Halbblock in der Feistel-Funktion von 32 Bits auf 48 Bits zu erweitern, wird der Halbblock in 4-Bit-Gruppen aufgeteilt. Die Bits am Rand jeder 4-Bit-Gruppe werden vorn, beziehungsweise hinten an die benachbarte 4-Bit-Gruppe angehängt.<sup id="cite_ref-schneier2_13-0" class="reference"><a href="#cite_note-schneier2-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Die_Substitution">Die Substitution</h3></div>
<p>Die Substitutionsboxen (<a href="S-Box" title="S-Box">S-Boxen</a>) beim DES sind standardisiert. Um aus den folgenden Tabellen den Ausgabewert zu erhalten, wird der Eingabewert gesplittet. So bildet das erste und letzte Bit zusammen die Zeile, und die Spalte ergibt sich aus den übrigen Bits (siehe <a href="S-Box#Beispiel" title="S-Box">Beispiel</a>).<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
Eine Änderung dieser Boxen reduziert die Sicherheit drastisch! Daher sollten die folgenden Tabellen für die Substitutionsboxen verwendet werden:
</p>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>1</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>1110</td>
<td>0100</td>
<td>1101</td>
<td>0001</td>
<td>0010</td>
<td>1111</td>
<td>1011</td>
<td>1000</td>
<td>0011</td>
<td>1010</td>
<td>0110</td>
<td>1100</td>
<td>0101</td>
<td>1001</td>
<td>0000</td>
<td>0111
</td></tr>
<tr>
<th>01
</th>
<td>0000</td>
<td>1111</td>
<td>0111</td>
<td>0100</td>
<td>1110</td>
<td>0010</td>
<td>1101</td>
<td>0001</td>
<td>1010</td>
<td>0110</td>
<td>1100</td>
<td>1011</td>
<td>1001</td>
<td>0101</td>
<td>0011</td>
<td>1000
</td></tr>
<tr>
<th>10
</th>
<td>0100</td>
<td>0001</td>
<td>1110</td>
<td>1000</td>
<td>1101</td>
<td>0110</td>
<td>0010</td>
<td>1011</td>
<td>1111</td>
<td>1100</td>
<td>1001</td>
<td>0111</td>
<td>0011</td>
<td>1010</td>
<td>0101</td>
<td>0000
</td></tr>
<tr>
<th>11
</th>
<td>1111</td>
<td>1100</td>
<td>1000</td>
<td>0010</td>
<td>0100</td>
<td>1001</td>
<td>0001</td>
<td>0111</td>
<td>0101</td>
<td>1011</td>
<td>0011</td>
<td>1110</td>
<td>1010</td>
<td>0000</td>
<td>0110</td>
<td>1101
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>2</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>1111</td>
<td>0001</td>
<td>1000</td>
<td>1110</td>
<td>0110</td>
<td>1011</td>
<td>0011</td>
<td>0100</td>
<td>1001</td>
<td>0111</td>
<td>0010</td>
<td>1101</td>
<td>1100</td>
<td>0000</td>
<td>0101</td>
<td>1010
</td></tr>
<tr>
<th>01
</th>
<td>0011</td>
<td>1101</td>
<td>0100</td>
<td>0111</td>
<td>1111</td>
<td>0010</td>
<td>1000</td>
<td>1110</td>
<td>1100</td>
<td>0000</td>
<td>0001</td>
<td>1010</td>
<td>0110</td>
<td>1001</td>
<td>1011</td>
<td>0101
</td></tr>
<tr>
<th>10
</th>
<td>0000</td>
<td>1110</td>
<td>0111</td>
<td>1011</td>
<td>1010</td>
<td>0100</td>
<td>1101</td>
<td>0001</td>
<td>0101</td>
<td>1000</td>
<td>1100</td>
<td>0110</td>
<td>1001</td>
<td>0011</td>
<td>0010</td>
<td>1111
</td></tr>
<tr>
<th>11
</th>
<td>1101</td>
<td>1000</td>
<td>1010</td>
<td>0001</td>
<td>0011</td>
<td>1111</td>
<td>0100</td>
<td>0010</td>
<td>1011</td>
<td>0110</td>
<td>0111</td>
<td>1100</td>
<td>0000</td>
<td>0101</td>
<td>1110</td>
<td>1001
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>3</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>1010</td>
<td>0000</td>
<td>1001</td>
<td>1110</td>
<td>0110</td>
<td>0011</td>
<td>1111</td>
<td>0101</td>
<td>0001</td>
<td>1101</td>
<td>1100</td>
<td>0111</td>
<td>1011</td>
<td>0100</td>
<td>0010</td>
<td>1000
</td></tr>
<tr>
<th>01
</th>
<td>1101</td>
<td>0111</td>
<td>0000</td>
<td>1001</td>
<td>0011</td>
<td>0100</td>
<td>0110</td>
<td>1010</td>
<td>0010</td>
<td>1000</td>
<td>0101</td>
<td>1110</td>
<td>1100</td>
<td>1011</td>
<td>1111</td>
<td>0001
</td></tr>
<tr>
<th>10
</th>
<td>1101</td>
<td>0110</td>
<td>0100</td>
<td>1001</td>
<td>1000</td>
<td>1111</td>
<td>0011</td>
<td>0000</td>
<td>1011</td>
<td>0001</td>
<td>0010</td>
<td>1100</td>
<td>0101</td>
<td>1010</td>
<td>1110</td>
<td>0111
</td></tr>
<tr>
<th>11
</th>
<td>0001</td>
<td>1010</td>
<td>1101</td>
<td>0000</td>
<td>0110</td>
<td>1001</td>
<td>1000</td>
<td>0111</td>
<td>0100</td>
<td>1111</td>
<td>1110</td>
<td>0011</td>
<td>1011</td>
<td>0101</td>
<td>0010</td>
<td>1100
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>4</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>0111</td>
<td>1101</td>
<td>1110</td>
<td>0011</td>
<td>0000</td>
<td>0110</td>
<td>1001</td>
<td>1010</td>
<td>0001</td>
<td>0010</td>
<td>1000</td>
<td>0101</td>
<td>1011</td>
<td>1100</td>
<td>0100</td>
<td>1111
</td></tr>
<tr>
<th>01
</th>
<td>1101</td>
<td>1000</td>
<td>1011</td>
<td>0101</td>
<td>0110</td>
<td>1111</td>
<td>0000</td>
<td>0011</td>
<td>0100</td>
<td>0111</td>
<td>0010</td>
<td>1100</td>
<td>0001</td>
<td>1010</td>
<td>1110</td>
<td>1001
</td></tr>
<tr>
<th>10
</th>
<td>1010</td>
<td>0110</td>
<td>1001</td>
<td>0000</td>
<td>1100</td>
<td>1011</td>
<td>0111</td>
<td>1101</td>
<td>1111</td>
<td>0001</td>
<td>0011</td>
<td>1110</td>
<td>0101</td>
<td>0010</td>
<td>1000</td>
<td>0100
</td></tr>
<tr>
<th>11
</th>
<td>0011</td>
<td>1111</td>
<td>0000</td>
<td>0110</td>
<td>1010</td>
<td>0001</td>
<td>1101</td>
<td>1000</td>
<td>1001</td>
<td>0100</td>
<td>0101</td>
<td>1011</td>
<td>1100</td>
<td>0111</td>
<td>0010</td>
<td>1110
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>5</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>0010</td>
<td>1100</td>
<td>0100</td>
<td>0001</td>
<td>0111</td>
<td>1010</td>
<td>1011</td>
<td>0110</td>
<td>1000</td>
<td>0101</td>
<td>0011</td>
<td>1111</td>
<td>1101</td>
<td>0000</td>
<td>1110</td>
<td>1001
</td></tr>
<tr>
<th>01
</th>
<td>1110</td>
<td>1011</td>
<td>0010</td>
<td>1100</td>
<td>0100</td>
<td>0111</td>
<td>1101</td>
<td>0001</td>
<td>0101</td>
<td>0000</td>
<td>1111</td>
<td>1010</td>
<td>0011</td>
<td>1001</td>
<td>1000</td>
<td>0110
</td></tr>
<tr>
<th>10
</th>
<td>0100</td>
<td>0010</td>
<td>0001</td>
<td>1011</td>
<td>1010</td>
<td>1101</td>
<td>0111</td>
<td>1000</td>
<td>1111</td>
<td>1001</td>
<td>1100</td>
<td>0101</td>
<td>0110</td>
<td>0011</td>
<td>0000</td>
<td>1110
</td></tr>
<tr>
<th>11
</th>
<td>1011</td>
<td>1000</td>
<td>1100</td>
<td>0111</td>
<td>0001</td>
<td>1110</td>
<td>0010</td>
<td>1101</td>
<td>0110</td>
<td>1111</td>
<td>0000</td>
<td>1001</td>
<td>1010</td>
<td>0100</td>
<td>0101</td>
<td>0011
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>6</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>1100</td>
<td>0001</td>
<td>1010</td>
<td>1111</td>
<td>1001</td>
<td>0010</td>
<td>0110</td>
<td>1000</td>
<td>0000</td>
<td>1101</td>
<td>0011</td>
<td>0100</td>
<td>1110</td>
<td>0111</td>
<td>0101</td>
<td>1011
</td></tr>
<tr>
<th>01
</th>
<td>1010</td>
<td>1111</td>
<td>0100</td>
<td>0010</td>
<td>0111</td>
<td>1100</td>
<td>1001</td>
<td>0101</td>
<td>0110</td>
<td>0001</td>
<td>1101</td>
<td>1110</td>
<td>0000</td>
<td>1011</td>
<td>0011</td>
<td>1000
</td></tr>
<tr>
<th>10
</th>
<td>1001</td>
<td>1110</td>
<td>1111</td>
<td>0101</td>
<td>0010</td>
<td>1000</td>
<td>1100</td>
<td>0011</td>
<td>0111</td>
<td>0000</td>
<td>0100</td>
<td>1010</td>
<td>0001</td>
<td>1101</td>
<td>1011</td>
<td>0110
</td></tr>
<tr>
<th>11
</th>
<td>0100</td>
<td>0011</td>
<td>0010</td>
<td>1100</td>
<td>1001</td>
<td>0101</td>
<td>1111</td>
<td>1010</td>
<td>1011</td>
<td>1110</td>
<td>0001</td>
<td>0111</td>
<td>0110</td>
<td>0000</td>
<td>1000</td>
<td>1101
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>7</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>0100</td>
<td>1011</td>
<td>0010</td>
<td>1110</td>
<td>1111</td>
<td>0000</td>
<td>1000</td>
<td>1101</td>
<td>0011</td>
<td>1100</td>
<td>1001</td>
<td>0111</td>
<td>0101</td>
<td>1010</td>
<td>0110</td>
<td>0001
</td></tr>
<tr>
<th>01
</th>
<td>1101</td>
<td>0000</td>
<td>1011</td>
<td>0111</td>
<td>0100</td>
<td>1001</td>
<td>0001</td>
<td>1010</td>
<td>1110</td>
<td>0011</td>
<td>0101</td>
<td>1100</td>
<td>0010</td>
<td>1111</td>
<td>1000</td>
<td>0110
</td></tr>
<tr>
<th>10
</th>
<td>0001</td>
<td>0100</td>
<td>1011</td>
<td>1101</td>
<td>1100</td>
<td>0011</td>
<td>0111</td>
<td>1110</td>
<td>1010</td>
<td>1111</td>
<td>0110</td>
<td>1000</td>
<td>0000</td>
<td>0101</td>
<td>1001</td>
<td>0010
</td></tr>
<tr>
<th>11
</th>
<td>0110</td>
<td>1011</td>
<td>1101</td>
<td>1000</td>
<td>0001</td>
<td>0100</td>
<td>1010</td>
<td>0111</td>
<td>1001</td>
<td>0101</td>
<td>0000</td>
<td>1111</td>
<td>1110</td>
<td>0010</td>
<td>0011</td>
<td>1100
</td></tr></tbody></table>
<table class="wikitable">
<tbody><tr>
<th rowspan="2" colspan="2">S<sub>8</sub></th>
<th colspan="16">Mittlere 4 Bits des Eingabewertes
</th></tr>
<tr>
<th>0000</th>
<th>0001</th>
<th>0010</th>
<th>0011</th>
<th>0100</th>
<th>0101</th>
<th>0110</th>
<th>0111</th>
<th>1000</th>
<th>1001</th>
<th>1010</th>
<th>1011</th>
<th>1100</th>
<th>1101</th>
<th>1110</th>
<th>1111
</th></tr>
<tr>
<th rowspan="4">Äußere Bits
</th>
<th>00
</th>
<td>1101</td>
<td>0010</td>
<td>1000</td>
<td>0100</td>
<td>0110</td>
<td>1111</td>
<td>1011</td>
<td>0001</td>
<td>1010</td>
<td>1001</td>
<td>0011</td>
<td>1110</td>
<td>0101</td>
<td>0000</td>
<td>1100</td>
<td>0111
</td></tr>
<tr>
<th>01
</th>
<td>0001</td>
<td>1111</td>
<td>1101</td>
<td>1000</td>
<td>1010</td>
<td>0011</td>
<td>0111</td>
<td>0100</td>
<td>1100</td>
<td>0101</td>
<td>0110</td>
<td>1011</td>
<td>0000</td>
<td>1110</td>
<td>1001</td>
<td>0010
</td></tr>
<tr>
<th>10
</th>
<td>0111</td>
<td>1011</td>
<td>0100</td>
<td>0001</td>
<td>1001</td>
<td>1100</td>
<td>1110</td>
<td>0010</td>
<td>0000</td>
<td>0110</td>
<td>1010</td>
<td>1101</td>
<td>1111</td>
<td>0011</td>
<td>0101</td>
<td>1000
</td></tr>
<tr>
<th>11
</th>
<td>0010</td>
<td>0001</td>
<td>1110</td>
<td>0111</td>
<td>0100</td>
<td>1010</td>
<td>1000</td>
<td>1101</td>
<td>1111</td>
<td>1100</td>
<td>1001</td>
<td>0000</td>
<td>0011</td>
<td>0101</td>
<td>0110</td>
<td>1011
</td></tr></tbody></table>
<div class="mw-heading mw-heading2"><h2 id="Schwächen"><span id="Schw.C3.A4chen"></span>Schwächen</h2></div>
<p>Weil die Schlüssellänge nur 56 Bit beträgt, konnte DES bereits durch <a href="Brute_Force" class="mw-redirect" title="Brute Force">Brute-Force</a>-Angriffe gebrochen werden, indem systematisch alle möglichen Schlüssel (2<sup>56</sup> = ca. 72 <a href="Billiarde" title="Billiarde">Billiarden</a>) getestet wurden. Es gibt die Vermutung, dass diese kleine Schlüssellänge absichtlich gewählt wurde, weil die <a href="National_Security_Agency" title="National Security Agency">NSA</a> bereits in den 1970er Jahren genug Rechnerkapazität besaß, um diese Verschlüsselung zu brechen.
</p>
<div class="mw-heading mw-heading3"><h3 id="Deep_Crack">Deep Crack</h3></div>
<div class="hauptartikel" role="navigation"><span class="hauptartikel-pfeil" title="siehe" aria-hidden="true" role="presentation">→ </span><i><span class="hauptartikel-text">Hauptartikel</span>: <a href="EFF_DES_Cracker" title="EFF DES Cracker">EFF DES Cracker</a></i></div>
<p>Die <a href="Electronic_Frontier_Foundation" title="Electronic Frontier Foundation">EFF</a> baute 1998 eine etwa 250.000 Dollar teure Maschine mit dem Namen „Deep Crack“. Dieser Superrechner enthielt 1536 spezielle Krypto-<a href="Integrierter_Schaltkreis" title="Integrierter Schaltkreis">Chips</a> und konnte pro Sekunde etwa 88 Milliarden Schlüssel testen. Im Juli 1998 gelang es mit dieser Maschine, einen DES-Code in 56 Stunden zu knacken und damit die „DES Challenge II-2“ zu gewinnen, die von der Firma <a href="RSA_Security" title="RSA Security">RSA Security</a> ausgeschrieben worden war. 1999 gewann die gleiche Maschine die „DES Challenge III“; dazu arbeitete sie mit dem weltweiten Netzwerk von <a href="Distributed.net" title="Distributed.net">distributed.net</a>, bestehend aus etwa 100.000 <a href="Computer" title="Computer">Rechnern</a>, zusammen. Der DES-Schlüssel wurde in 22 Stunden und 15 Minuten gefunden, mehr als 245 Milliarden Schlüssel wurden pro Sekunde getestet.
</p>
<div class="mw-heading mw-heading3"><h3 id="COPACOBANA">COPACOBANA</h3></div>
<p>Die einzige andere öffentlich bekannte Maschine zum Brechen von DES ist <a href="Copacobana" title="Copacobana">COPACOBANA</a>. Sie wurde 2006 von zwei Arbeitsgruppen an den <a href="Universit%C3%A4t" title="Universität">Universitäten</a> <a href="Ruhr-Universit%C3%A4t_Bochum" title="Ruhr-Universität Bochum">Bochum</a> und <a href="Christian-Albrechts-Universit%C3%A4t_zu_Kiel" title="Christian-Albrechts-Universität zu Kiel">Kiel</a> gebaut. Im Gegensatz zu Deep Crack besteht eine COPACOBANA aus rekonfigurierbaren Hardware-Bausteinen, sogenannten <a href="Field_Programmable_Gate_Array" title="Field Programmable Gate Array">FPGAs</a>. 120 FPGAs vom Typ <a href="Xilinx" title="Xilinx">Xilinx</a> Spartan-3-1000 sind in einer Maschine auf 20 DIMM-Modulen zusammengefasst, wobei jedes DIMM-Modul sechs FPGAs enthält. COPACOBANA kann 65 Milliarden DES-Schlüssel pro Sekunde testen, woraus sich eine durchschnittliche Suchzeit von 6,4 Tagen für eine DES-Attacke ergibt. Durch den Einsatz rekonfigurierbarer Hardware kann COPACOBANA auch zum Brechen anderer Chiffren wie <a href="A5_(Algorithmus)" title="A5 (Algorithmus)">A5</a> eingesetzt werden. Die Material- und Herstellungskosten von COPACOBANA belaufen sich auf etwa 10.000 Dollar. Der Kostenvorteil gegenüber Deep Crack um einen Faktor 25 ist ein beeindruckendes Beispiel für das <a href="Mooresches_Gesetz" title="Mooresches Gesetz">Mooresche Gesetz</a>. Hiernach wäre ein Kostenvorteil von etwa 32 = 2<sup>5</sup> zu erwarten gewesen, da acht Jahre zwischen dem Bau der beiden Maschinen verstrichen sind (das Mooresche Gesetz sagt eine Halbierung der Kosten digitaler ICs alle 1,5 Jahre voraus, so dass bei acht Jahren etwa 5 Halbierungen stattgefunden haben sollten).
</p><p>Der derzeitige Rekord wurde 2008 von der Firma SciEngines GmbH (einem <a href="Ableger_(Wirtschaft)" class="mw-redirect" title="Ableger (Wirtschaft)">Spin-off</a> der COPACOBANA-Arbeitsgruppen) aufgestellt und auf einem Workshop 2009 erneut verbessert. Mit 128 Xilinx-FPGAs lag der Durchsatz bei über 292 Milliarden Schlüsseln pro Sekunde.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Geringfügige_Schwächen"><span id="Geringf.C3.BCgige_Schw.C3.A4chen"></span>Geringfügige Schwächen</h3></div>
<p>DES besitzt eine Komplement-Eigenschaft, das heißt, es gilt
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K}(m)={\overline {\operatorname {DES} _{\overline {K}}({\overline {m}})}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<mi>m</mi>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mrow>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>K</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>m</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
<mo stretchy="false">)</mo>
</mrow>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K}(m)={\overline {\operatorname {DES} _{\overline {K}}({\overline {m}})}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/2d4c193da71f16d335344e42b78cd229df50b042.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.171ex; width:23.852ex; height:4.009ex;" alt="{\displaystyle \operatorname {DES} _{K}(m)={\overline {\operatorname {DES} _{\overline {K}}({\overline {m}})}}}" loading="lazy"></span> für alle Schlüssel <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>K</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/2b76fce82a62ed5461908f0dc8f037de4e3686b0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.066ex; height:2.176ex;" alt="{\displaystyle K}" loading="lazy"></span> und alle Klartexte <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle m}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>m</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle m}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/0a07d98bb302f3856cbabc47b2b9016692e3f7bc.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.04ex; height:1.676ex;" alt="{\displaystyle m}" loading="lazy"></span>,</dd></dl>
<p>wobei <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle {\overline {x}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mrow class="MJX-TeXAtom-ORD">
<mover>
<mi>x</mi>
<mo accent="false">¯<!-- ¯ --></mo>
</mover>
</mrow>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle {\overline {x}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/9fa4039bbc2a0048c3a3c02e5fd24390cab0dc97.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.445ex; height:2.343ex;" alt="{\displaystyle {\overline {x}}}" loading="lazy"></span> das bitweise Komplement von <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle x}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>x</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle x}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/87f9e315fd7e2ba406057a97300593c4802b53e4.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:1.33ex; height:1.676ex;" alt="{\displaystyle x}" loading="lazy"></span> bezeichnet. Dadurch lässt sich mit einem <a href="Kryptoanalyse#Angriffsszenarien" title="Kryptoanalyse">Chosen-Plaintext-Angriff</a> bei einer vollständigen Schlüsselsuche der Suchraum auf 2<sup>55</sup> Schlüssel halbieren.
</p><p>Es existieren vier <a href="Schwacher_Schl%C3%BCssel" title="Schwacher Schlüssel">schwache Schlüssel</a> <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>K</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/2b76fce82a62ed5461908f0dc8f037de4e3686b0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.066ex; height:2.176ex;" alt="{\displaystyle K}" loading="lazy"></span> mit der Eigenschaft, dass
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K}(\operatorname {DES} _{K}(m))=m}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<mi>m</mi>
<mo stretchy="false">)</mo>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mi>m</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K}(\operatorname {DES} _{K}(m))=m}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/29ef6ae46789848763e46318b973c65f85e34479.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:23.486ex; height:2.843ex;" alt="{\displaystyle \operatorname {DES} _{K}(\operatorname {DES} _{K}(m))=m}" loading="lazy"></span> für alle Klartexte <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle m}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>m</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle m}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/0a07d98bb302f3856cbabc47b2b9016692e3f7bc.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.04ex; height:1.676ex;" alt="{\displaystyle m}" loading="lazy"></span>.</dd></dl>
<p>Des Weiteren gibt es sechs semi-schwache Schlüsselpaare <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle (K_{1},K_{2})}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mo stretchy="false">(</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>,</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo stretchy="false">)</mo>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle (K_{1},K_{2})}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/89f9b8d1ba01f285b39da1ec4c893301edcbc8de.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.838ex; width:8.898ex; height:2.843ex;" alt="{\displaystyle (K_{1},K_{2})}" loading="lazy"></span> mit der Eigenschaft, dass
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K_{1}}(\operatorname {DES} _{K_{2}}(m))=m}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo><!-- --></mo>
<mo stretchy="false">(</mo>
<mi>m</mi>
<mo stretchy="false">)</mo>
<mo stretchy="false">)</mo>
<mo>=</mo>
<mi>m</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K_{1}}(\operatorname {DES} _{K_{2}}(m))=m}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8fb657aa19c5656dc84a538e0c6ec1aa9a26cf6b.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:25.018ex; height:3.009ex;" alt="{\displaystyle \operatorname {DES} _{K_{1}}(\operatorname {DES} _{K_{2}}(m))=m}" loading="lazy"></span> für alle Klartexte <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle m}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>m</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle m}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/0a07d98bb302f3856cbabc47b2b9016692e3f7bc.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.04ex; height:1.676ex;" alt="{\displaystyle m}" loading="lazy"></span>.</dd></dl>
<p>In der Praxis ist dies jedoch kein Problem, da die Wahrscheinlichkeit für einen (semi-)schwachen Schlüssel bei zufälliger Auswahl eines Schlüssels nur 16:2<sup>56</sup> beträgt. Außerdem lässt sich die Verwendung dieser Schlüssel leicht vermeiden, indem sie bei der Erzeugung explizit ignoriert werden.
</p>
<div class="mw-heading mw-heading2"><h2 id="Anwendungen">Anwendungen</h2></div>
<p>Breite Anwendung findet der DES-Algorithmus bei <a href="Geldautomat" title="Geldautomat">Geldautomaten</a>: Mit Hilfe des DES-Algorithmus und eines geheimen <a href="Schl%C3%BCssel_(Kryptologie)" title="Schlüssel (Kryptologie)">Schlüssels</a> wird bereits in der <a href="Encrypting_PIN_Pad" title="Encrypting PIN Pad">Tastatur</a> eine sogenannte PAC berechnet. Diese wird zusammen mit den Daten des <a href="Magnetstreifen" title="Magnetstreifen">Magnetstreifens</a> (<a href="Kontonummer" title="Kontonummer">Kontonummer</a>, <a href="Bankleitzahl" title="Bankleitzahl">Bankleitzahl</a>, Gültigkeitszeitraum, …) zum Host des kontoführenden Instituts geschickt, dort wird die PIN entschlüsselt und verifiziert.
</p><p>In der Anfangszeit der Geldautomaten wurde aus den Daten des Magnetstreifens (Kontonummer, Bankleitzahl, Gültigkeitszeitraum, …) und dem geheimen Schlüssel die <a href="Pers%C3%B6nliche_Identifikationsnummer" title="Persönliche Identifikationsnummer">PIN</a> berechnet und das Ergebnis mit der Eingabe des Benutzers verglichen. Diese sogenannte Offline-PIN-Prüfung wird seit mehreren Jahren nicht mehr verwendet.
</p><p>Bis zum heutigen Tage wird DES für die Sprachverschlüsselung von sicherheitskritischen Sprechfunkaussendungen verwendet. In Deutschland gehören zu den Anwendern diverse polizeiliche
Sondereinheiten sowie die Verfassungsschutzbehörden des Bundes und der Länder.<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> Verbreitet sind zu diesem Zweck Sprechfunkgeräte von Motorola aus den Modellreihen MX3000 und MTS2000.<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> Die Sprache wird mittels Delta-Modulation
digitalisiert und durch ein zertifiziertes Steckmodul im Inneren des Sprechfunkgerätes zur Verschlüsselung geschleust. Das Modul ist gegen Manipulationen geschützt, der Schlüssel ist nicht auslesbar und wird bei Manipulationsversuchen gelöscht. Auch bei Verwendung von Relaisstellen zur Reichweitenerhöhung ist das Konzept dergestalt, dass im Inneren der Relaisstelle das Signal nie unverschlüsselt vorliegt. Die Schlüsselverwaltung erfolgt entweder dezentral im direkten Zugriff auf das Gerät mit einem sog. key variable loader (KVL), oder über Funk zentral von einem key management centre per OTAR, „Over The Air Rekeying“.
Für diese Anwendung ist auch DES nach heutigem Stand der Technik mehr als ausreichend sicher, sofern für jedes Einsatzgeschehen (bzw. regelmäßig während längerer Einsätze) die Schlüssel gewechselt werden, da das gesprochene Wort in solchen Anwendungsfällen nur aktuell für die Gegenseite von Bedeutung ist. Eine mögliche Entschlüsselung nach Stunden oder Tagen ist für den Einsatz in der Regel irrelevant, da dann bereits „alles gelaufen ist“. Sowohl der technisch relativ hohe Aufwand als auch das benötigte Fachwissen senkt zusätzlich die Wahrscheinlichkeit, dass tatsächlich versucht wird, die Funkkommunikation nachträglich zu entschlüsseln.
</p><p>Die US-<a href="Exportbeschr%C3%A4nkung" title="Exportbeschränkung">Exportbeschränkung</a> für den DES mit voller 56-Bit-Schlüssellänge wurde aufgehoben.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading2"><h2 id="Ersatz-Algorithmen">Ersatz-Algorithmen</h2></div>
<p>Aufgrund seiner geringen Schlüssellänge war DES bald nicht mehr ausreichend sicher und es musste ein Ersatz gefunden werden.
</p>
<div class="mw-heading mw-heading3"><h3 id="Triple-DES">Triple-DES</h3></div>
<p>Der erste Ersatz für DES war <b>Triple-DES</b> (auch <b>3DES</b> oder <b>DESede</b> genannt). Die Idee der mehrfachen Ausführung von DES mit zwei verschiedenen Schlüsseln ist ein Verfahren, das vom DES-Mitentwickler Walter Tuchman beschrieben und <a href="Analyse" title="Analyse">analysiert</a> wurde (siehe FIPS 46-3). <a href="Ralph_Merkle" title="Ralph Merkle">Ralph Merkle</a> und <a href="Martin_Hellman" title="Martin Hellman">Martin Hellman</a> schlugen nach einer weiteren Analyse 1981 die Dreifachverschlüsselung mit drei unabhängigen, voneinander verschiedenen Schlüsseln vor.<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup>
</p><p>Bei der am häufigsten verwendeten Methode wird jeder Datenblock mit einem DES-Schlüssel <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8520077dbcf03c2aabefd98d41a2269ed41a54fa.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.027ex; height:2.509ex;" alt="{\displaystyle K_{1}}" loading="lazy"></span> chiffriert, dann mit <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{2}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/57e1b324cf5b68f2729a8634ff76e396b634b75d.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.027ex; height:2.509ex;" alt="{\displaystyle K_{2}}" loading="lazy"></span> dechiffriert und mit <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{3}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{3}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/10d81c94e20db022da2fc47d34b5473c65c4474c.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.027ex; height:2.509ex;" alt="{\displaystyle K_{3}}" loading="lazy"></span> chiffriert:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {3DES} _{(K_{1},K_{2},K_{3})}:=\operatorname {DES} _{K_{3}}\circ \operatorname {DES} _{K_{2}}^{-1}\circ \operatorname {DES} _{K_{1}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>3DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">(</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>,</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
<mo>,</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
<mo stretchy="false">)</mo>
</mrow>
</msub>
<mo>:=</mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo>∘<!-- ∘ --></mo>
<msubsup>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mrow>
<mrow class="MJX-TeXAtom-ORD">
<mo>−<!-- − --></mo>
<mn>1</mn>
</mrow>
</msubsup>
<mo>∘<!-- ∘ --></mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {3DES} _{(K_{1},K_{2},K_{3})}:=\operatorname {DES} _{K_{3}}\circ \operatorname {DES} _{K_{2}}^{-1}\circ \operatorname {DES} _{K_{1}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/d4d42ff82920bffe9471e8af12a61bc133266491.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.171ex; width:43.868ex; height:3.509ex;" alt="{\displaystyle \operatorname {3DES} _{(K_{1},K_{2},K_{3})}:=\operatorname {DES} _{K_{3}}\circ \operatorname {DES} _{K_{2}}^{-1}\circ \operatorname {DES} _{K_{1}}}" loading="lazy"></span></dd></dl>
<p>Dieses Verfahren wird auch als EDE (Encrypt-Decrypt-Encrypt) bezeichnet. Eine einfache DES-Verschlüsselung ist somit ein Spezialfall von 3DES:
</p>
<dl><dd><span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {3DES} _{(K,K,K)}=\operatorname {DES} _{K}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>3DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mo stretchy="false">(</mo>
<mi>K</mi>
<mo>,</mo>
<mi>K</mi>
<mo>,</mo>
<mi>K</mi>
<mo stretchy="false">)</mo>
</mrow>
</msub>
<mo>=</mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {3DES} _{(K,K,K)}=\operatorname {DES} _{K}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/f80b37a9bd19c64aa3654ad96e0d3e31656959b3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.171ex; width:22.065ex; height:3.009ex;" alt="{\displaystyle \operatorname {3DES} _{(K,K,K)}=\operatorname {DES} _{K}}" loading="lazy"></span></dd></dl>
<p>Ein für die Verschlüsselungsstärke von 3DES wichtiges mathematisches Problem war die Frage, ob die Hintereinanderausführung von DES-Operationen die Sicherheit erhöht; dies wäre nicht der Fall, wenn DES eine <a href="Gruppe_(Mathematik)" title="Gruppe (Mathematik)">Gruppe</a> ist. Campell und Wiener fanden heraus, dass die Menge der DES-Verschlüsselungen <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/6ec8646be3081a0cbf77ac6147c4a18adb6089e3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:6.344ex; height:2.509ex;" alt="{\displaystyle \operatorname {DES} _{K}}" loading="lazy"></span> unter <a href="Komposition_(Mathematik)" title="Komposition (Mathematik)">Hintereinanderausführung</a> nicht <a href="Abgeschlossenheit_(algebraische_Struktur)" title="Abgeschlossenheit (algebraische Struktur)">abgeschlossen</a> ist. Das bedeutet, dass es Schlüssel <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{1}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{1}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/8520077dbcf03c2aabefd98d41a2269ed41a54fa.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.027ex; height:2.509ex;" alt="{\displaystyle K_{1}}" loading="lazy"></span> und <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{2}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{2}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/57e1b324cf5b68f2729a8634ff76e396b634b75d.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:3.027ex; height:2.509ex;" alt="{\displaystyle K_{2}}" loading="lazy"></span> gibt, sodass <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}\neq \operatorname {DES} _{K}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo>∘<!-- ∘ --></mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo>≠<!-- ≠ --></mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}\neq \operatorname {DES} _{K}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/4d6269f84713b16bd79a2fb5a6c980e65d90236e.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:25.599ex; height:2.843ex;" alt="{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}\neq \operatorname {DES} _{K}}" loading="lazy"></span> für alle Schlüssel <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<mi>K</mi>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/2b76fce82a62ed5461908f0dc8f037de4e3686b0.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.338ex; width:2.066ex; height:2.176ex;" alt="{\displaystyle K}" loading="lazy"></span>. Anders ausgedrückt ist die Anzahl der Permutationen von der Form <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>2</mn>
</mrow>
</msub>
</mrow>
</msub>
<mo>∘<!-- ∘ --></mo>
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/e51a829efb1872c1e10826fe18742cda52e406ce.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -1.005ex; width:16.157ex; height:2.843ex;" alt="{\displaystyle \operatorname {DES} _{K_{2}}\circ \operatorname {DES} _{K_{1}}}" loading="lazy"></span> bedeutend größer als die Zahl der <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle \operatorname {DES} _{K}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>DES</mi>
<mrow class="MJX-TeXAtom-ORD">
<mi>K</mi>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle \operatorname {DES} _{K}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/6ec8646be3081a0cbf77ac6147c4a18adb6089e3.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:6.344ex; height:2.509ex;" alt="{\displaystyle \operatorname {DES} _{K}}" loading="lazy"></span>-Permutationen. Damit lässt sich die effektive Schlüssellänge tatsächlich steigern. Dies konnte allerdings erst 1992 gezeigt werden.<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup>
</p><p>Die Schlüssellänge von 3DES ist mit 168 Bits dreimal so groß wie bei DES (56 Bits), die effektive Schlüssellänge liegt aber nur bei 112 Bits. Dies ist bedingt durch die Möglichkeit eines sogenannten <a href="Meet-in-the-middle-Angriff" title="Meet-in-the-middle-Angriff">Meet-in-the-middle-Angriff</a>: Ist der Angreifer im Besitz eines Paares aus Klartext und Chiffre, so kann er die Verschlüsselung von beiden Seiten angreifen. Der Klartext wird mit sämtlichen möglichen Schlüsseln für Stufe 1 verschlüsselt (2<sup>56</sup> Möglichkeiten). Die so entstandenen Texte werden ebenfalls jeweils mit allen möglichen Schlüsseln für Stufe 2 entschlüsselt (2<sup>112</sup> Möglichkeiten). Deren Ergebnisse vergleicht man mit den Ergebnissen der Entschlüsselung des Chiffretextes mit sämtlichen Schlüsseln (2<sup>56</sup>Möglichkeiten). So müssen insgesamt nur 2<sup>112</sup>+2<sup>56</sup>≈2<sup>112</sup> Ver- bzw. Entschlüsselungen durchgeführt werden, anstatt 2<sup>168</sup> bei Verwendung der Brute-Force-Methode.
</p><p>Aufgrund dieses Missverhältnisses zwischen Schlüssellänge und effektivem Sicherheitsniveau wird oft <span class="mwe-math-element mwe-math-element-inline"><span class="mwe-math-mathml-inline mwe-math-mathml-a11y" style="display: none;"><math xmlns="http://www.w3.org/1998/Math/MathML" alttext="{\displaystyle K_{1}=K_{3}}">
<semantics>
<mrow class="MJX-TeXAtom-ORD">
<mstyle displaystyle="true" scriptlevel="0">
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>1</mn>
</mrow>
</msub>
<mo>=</mo>
<msub>
<mi>K</mi>
<mrow class="MJX-TeXAtom-ORD">
<mn>3</mn>
</mrow>
</msub>
</mstyle>
</mrow>
<annotation encoding="application/x-tex">{\displaystyle K_{1}=K_{3}}</annotation>
</semantics>
</math></span><img src="./_assets_/eb734a37dd21ce173a46342d1cc64c92/180dbff74e0fdae0be2c8896d4ea17c8d0bd6ba8.svg" class="mwe-math-fallback-image-inline mw-invert skin-invert" aria-hidden="true" style="vertical-align: -0.671ex; width:9.153ex; height:2.509ex;" alt="{\displaystyle K_{1}=K_{3}}" loading="lazy"></span> gewählt. Dies liefert für eine Schlüssellänge von 112 Bits ein theoretisches Sicherheitsniveau von 112 Bits, da kein Meet-in-the-middle-Angriff möglich ist. Es gibt jedoch weitere Angriffe,<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup> so dass 3DES mit zwei Schlüsseln vom <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> mit einem Sicherheitsniveau von 80 Bits bewertet wird.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="AES">AES</h3></div>
<p>Durch einen Wettbewerb des <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">NIST</a> wurde im Oktober 2000 der <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">Advanced Encryption Standard</a> (AES) gewählt, um DES offiziell zu ersetzen. Das jetzt als AES bezeichnete Verschlüsselungsverfahren, das den Wettbewerb gewann, war von seinen belgischen Entwicklern <a href="Vincent_Rijmen" title="Vincent Rijmen">Vincent Rijmen</a> und <a href="Joan_Daemen" title="Joan Daemen">Joan Daemen</a> unter dem Namen <i>Rijndael</i> zu diesem Wettbewerb eingereicht worden.
</p>
<div class="mw-heading mw-heading2"><h2 id="3DESE_–_Triple_DES_im_Bereich_PPP"><span id="3DESE_.E2.80.93_Triple_DES_im_Bereich_PPP"></span>3DESE – Triple DES im Bereich PPP</h2></div>
<p>Die im RFC 2420<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> definierte Protokollerweiterung 3DESE (Triple-DES Encryption Protocol Extension) ermöglicht über <a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">PPP</a> (Point-to-Point Protocol) die gewohnte Triple-DES-Verschlüsselung.
</p>
<div class="mw-heading mw-heading2"><h2 id="Literatur">Literatur</h2></div>
<ul><li><a href="Bruce_Schneier" title="Bruce Schneier">Bruce Schneier</a>: <i>Applied Cryptography. Protocols, Algorithms, and Source Code in C.</i> 2. Auflage. John Wiley and Sons, New York NY 1996, ISBN 0-471-11709-9.</li>
<li>Bruce Schneier: <i>Angewandte Kryptographie. Protokolle, Algorithmen und Sourcecode in C.</i> Addison-Wesley, Bonn u. a. 1996, ISBN 3-89319-854-7, S. 267 (<i>Informationssicherheit</i>).</li>
<li><a href="Klaus_Schmeh" title="Klaus Schmeh">Klaus Schmeh</a>: <i>Codeknacker gegen Codemacher. Die faszinierende Geschichte der Verschlüsselung.</i> 2. Auflage. W3l-Verlag, Herdecke u. a. 2008, ISBN 978-3-937137-89-6, S. 263–274.</li>
<li><i>Dossier Kryptographie.</i> In: <i><a href="Spektrum_der_Wissenschaft" title="Spektrum der Wissenschaft">Spektrum der Wissenschaft</a></i>, 24, 4, 2001, S. 42–47.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Weblinks">Weblinks</h2></div>
<ul><li><a rel="nofollow" class="external text" href="https://csrc.nist.gov/publications/fips/fips46-3/fips46-3.pdf">DES- und TripleDES-Spezifikation.</a> (PDF; 0,4 MB) NIST (englisch).</li>
<li><a rel="nofollow" class="external text" href="http://people.eku.edu/styere/Encrypt/JS-DES.html">DES als JavaScript (inkl. Zwischenwerte des Algorithmus).</a> eku.edu (englisch).</li>
<li><a rel="nofollow" class="external text" href="http://members.chello.at/s.peer/DES/index.html">Einfache Beschreibung von DES mit Grafik.</a> chello.at</li>
<li><a rel="nofollow" class="external text" href="http://www.matheprisma.de/Module/DES/index.htm">Detaillierte Darstellung von DES.</a> matheprisma.de</li>
<li><a rel="nofollow" class="external text" href="https://www.copacobana.org/">COPACOBANA – Eine kostenoptimierte Spezialhardware zum Codeknacken der Universitäten Bochum und Kiel.</a> copacobana.org (englisch).</li>
<li><a rel="nofollow" class="external text" href="http://www.users.zetnet.co.uk/hopwood/crypto/scan/cs.html#DES">Standard Cryptographic Algorithm Naming zu DES.</a> zetnet.co.uk</li></ul>
<div class="mw-heading mw-heading2"><h2 id="Einzelnachweise">Einzelnachweise</h2></div>
<ol class="references">
<li id="cite_note-1"><span class="mw-cite-backlink"><a href="#cite_ref-1">↑</a></span> <span class="reference-text">Tom R. Johnson: <a rel="nofollow" class="external text" href="https://cryptome.org/0001/nsa-meyer.htm"><i>American Cryptology during the Cold War, 1945–1989</i>.</a> Book III: Retrenchment and Reform, S. 232. <a href="National_Security_Agency" title="National Security Agency">NSA</a>, DOCID 3417193, FOIA-Veröffentlichung auf cryptome.org, 18. Dezember 2009; abgerufen am 2. Januar 2010.</span>
</li>
<li id="cite_note-schneier-2"><span class="mw-cite-backlink"><a href="#cite_ref-schneier_2-0">↑</a></span> <span class="reference-text">Bruce Schneier: <cite style="font-style:italic">Applied Cryptography</cite>. Protocols, Algorithms and Source Code in C. 2. Auflage. John Wiley & Sons, New York 1996, ISBN 0-471-11709-9, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>280</span>.<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.au=Bruce+Schneier&rft.btitle=Applied+Cryptography&rft.date=1996&rft.edition=2.&rft.genre=book&rft.isbn=0471117099&rft.pages=280&rft.place=New+York&rft.pub=John+Wiley+%26+Sons" style="display:none"> </span></span>
</li>
<li id="cite_note-ussenat-3"><span class="mw-cite-backlink"><a href="#cite_ref-ussenat_3-0">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20151218082155/http://www.lkn.fe.uni-lj.si/vaje/KK/IEEE%20%C4%8Dlanki/Gersho%20NSA%20DES.pdf"><i>Unclassified Summary: Involvement of NSA in the Development of the Data Encryption Standard.</i></a> (PDF) United States Senate Select Committee on Intelligence, November 1978, <span style="white-space:nowrap;">S. 55</span>, archiviert vom <style data-mw-deduplicate="TemplateStyles:r250917974">
/* start https://de.wikipedia.org/ */
.mw-parser-output .dewiki-iconexternal>a{background-position:center right!important;background-repeat:no-repeat!important}body.skin-minerva .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/OOjs_UI_icon_external-link-ltr-progressive.svg")!important;background-size:10px!important;padding-right:13px!important}body.skin-timeless .mw-parser-output .dewiki-iconexternal>a,body.skin-monobook .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/MediaWiki_external_link_icon.svg")!important;padding-right:13px!important}body.skin-vector .mw-parser-output .dewiki-iconexternal>a{background-image:url("./_mw_/Link.ernal-small-ltr-progressive.svg")!important;background-size:0.857em!important;padding-right:1em!important}
/* end https://de.wikipedia.org/ */
</style><span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=http%3A%2F%2Fwww.lkn.fe.uni-lj.si%2Fvaje%2FKK%2FIEEE%2520%25C4%258Dlanki%2FGersho%2520NSA%2520DES.pdf">Original</a></span> (nicht mehr online verfügbar) am <span style="white-space:nowrap;">18. Dezember 2015</span><span>;</span><span class="Abrufdatum"> abgerufen am 6. August 2010</span>.</span> <small class="archiv-bot"><span class="wp_boppel noviewer" aria-hidden="true" role="presentation"><span typeof="mw:File"><span title="i"></span></span></span> <b>Info:</b> Der Archivlink wurde automatisch eingesetzt und noch nicht geprüft. Bitte prüfe Original- und Archivlink gemäß Anleitung und entferne dann diesen Hinweis.</small><span style="display:none"><a rel="nofollow" class="external text" href="http://IABotmemento.invalid/http://www.lkn.fe.uni-lj.si/vaje/KK/IEEE%20%C4%8Dlanki/Gersho%20NSA%20DES.pdf">@1</a></span><span style="display:none"><a rel="nofollow" class="external text" href="http://www.lkn.fe.uni-lj.si/vaje/KK/IEEE%20%C4%8Dlanki/Gersho%20NSA%20DES.pdf">@2</a></span><span style="display:none">Vorlage:Webachiv/IABot/www.lkn.fe.uni-lj.si</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AData+Encryption+Standard&rft.title=Unclassified+Summary%3A+Involvement+of+NSA+in+the+Development+of+the+Data+Encryption+Standard&rft.description=Unclassified+Summary%3A+Involvement+of+NSA+in+the+Development+of+the+Data+Encryption+Standard&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20151218082155%2Fhttp%3A%2F%2Fwww.lkn.fe.uni-lj.si%2Fvaje%2FKK%2FIEEE%2520%25C4%258Dlanki%2FGersho%2520NSA%2520DES.pdf&rft.publisher=United+States+Senate+Select+Committee+on+Intelligence&rft.date=1978-11&rft.source=http://www.lkn.fe.uni-lj.si/vaje/KK/IEEE%20%C4%8Dlanki/Gersho%20NSA%20DES.pdf"> </span></span>
</li>
<li id="cite_note-kinnucan-4"><span class="mw-cite-backlink"><a href="#cite_ref-kinnucan_4-0">↑</a></span> <span class="reference-text">Paul Kinnucan: <cite style="font-style:italic">Data encryption gurus: Tuchman and Meyer</cite>. In: <cite style="font-style:italic">Cryptologia</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em"> </span>2</span>, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>4</span>, Oktober 1978, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>371–381</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1080/0161-117891853270">10.1080/0161-117891853270</a></span> (<a rel="nofollow" class="external text" href="http://www.informaworld.com/smpp/ftinterface~content=a741902687~fulltext=713240930~frm=content">informaworld.com</a> [PDF; abgerufen am 6. August 2010]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Data+encryption+gurus%3A+Tuchman+and+Meyer&rft.au=Paul+Kinnucan&rft.date=1978-10&rft.doi=10.1080%2F0161-117891853270&rft.genre=journal&rft.issue=4&rft.jtitle=Cryptologia&rft.pages=371-381&rft.volume=2" style="display:none"> </span></span>
</li>
<li id="cite_note-biham-5"><span class="mw-cite-backlink"><a href="#cite_ref-biham_5-0">↑</a></span> <span class="reference-text">Adi Shamir, Eli Biham: <cite style="font-style:italic">Differential cryptanalysis of DES-like cryptosystems</cite>. In: <cite style="font-style:italic">Journal of Cryptology</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em"> </span>4</span>, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>1</span>, Januar 1991, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>3–72</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1007/BF00630563">10.1007/BF00630563</a></span> (<a rel="nofollow" class="external text" href="https://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.31.2000&rep=rep1&type=pdf">psu.edu</a> [PDF]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Differential+cryptanalysis+of+DES-like+cryptosystems&rft.au=Adi+Shamir%2C+Eli+Biham&rft.date=1991-01&rft.doi=10.1007%2FBF00630563&rft.genre=journal&rft.issue=1&rft.jtitle=Journal+of+Cryptology&rft.pages=3-72&rft.volume=4" style="display:none"> </span></span>
</li>
<li id="cite_note-coppersmith-6"><span class="mw-cite-backlink"><a href="#cite_ref-coppersmith_6-0">↑</a></span> <span class="reference-text">Don Coppersmith: <cite style="font-style:italic">The Data Encryption Standard (DES) and its strength against attacks</cite>. In: <cite style="font-style:italic">IBM Journal of Research and Development</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em"> </span>38</span>, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>3</span>, Mai 1994, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>243</span> (<a rel="nofollow" class="external text" href="http://caccioppoli.mac.rub.de/website/teachingmaterial/k1-ws0607/coppersmith.pdf">rub.de</a> [PDF]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=The+Data+Encryption+Standard+%28DES%29+and+its+strength+against+attacks&rft.au=Don+Coppersmith&rft.date=1994-05&rft.genre=journal&rft.issue=3&rft.jtitle=IBM+Journal+of+Research+and+Development&rft.pages=243&rft.volume=38" style="display:none"> </span></span>
</li>
<li id="cite_note-coppersmith2-7"><span class="mw-cite-backlink"><a href="#cite_ref-coppersmith2_7-0">↑</a></span> <span class="reference-text">Don Coppersmith: <cite style="font-style:italic">The Data Encryption Standard (DES) and its strength against attacks</cite>. In: <cite style="font-style:italic">IBM Journal of Research and Development</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em"> </span>38</span>, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>3</span>, Mai 1994, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>247</span> (<a rel="nofollow" class="external text" href="http://caccioppoli.mac.rub.de/website/teachingmaterial/k1-ws0607/coppersmith.pdf">rub.de</a> [PDF]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=The+Data+Encryption+Standard+%28DES%29+and+its+strength+against+attacks&rft.au=Don+Coppersmith&rft.date=1994-05&rft.genre=journal&rft.issue=3&rft.jtitle=IBM+Journal+of+Research+and+Development&rft.pages=247&rft.volume=38" style="display:none"> </span></span>
</li>
<li id="cite_note-benaroya-8"><span class="mw-cite-backlink"><a href="#cite_ref-benaroya_8-0">↑</a></span> <span class="reference-text">Eli Biham, Ishai Ben-Aroya: <cite style="font-style:italic">Differential cryptanalysis of Lucifer</cite>. In: <cite style="font-style:italic">Journal of Cryptology</cite>. <span style="white-space:nowrap">Band<span style="display:inline-block;width:.2em"> </span>9</span>, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>1</span>, März 1996, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>21–34</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1007/BF02254790">10.1007/BF02254790</a></span>.<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Differential+cryptanalysis+of+Lucifer&rft.au=Eli+Biham%2C+Ishai+Ben-Aroya&rft.date=1996-03&rft.doi=10.1007%2FBF02254790&rft.genre=journal&rft.issue=1&rft.jtitle=Journal+of+Cryptology&rft.pages=21-34&rft.volume=9" style="display:none"> </span></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.cryptography.com/resources/whitepapers/DES.html">cryptography.com</a></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><a href="#cite_ref-10">↑</a></span> <span class="reference-text">Bruce Schneier: <i>Applied Cryptography, Protocols, Algorithms, and Source Code in C.</i> 2. Auflage. John Wiley and Sons, New York 1996, S. 267<br> <i>Angewandte Kryptographie, Protokolle, Algorithmen und Sourcecode in C</i>. Pearson Studium, 2006.</span>
</li>
<li id="cite_note-dh-exh-11"><span class="mw-cite-backlink"><a href="#cite_ref-dh-exh_11-0">↑</a></span> <span class="reference-text">Whitfield Diffie, Martin E. Hellman: <cite class="lang" lang="en" dir="auto" style="font-style:italic">Exhaustive Cryptanalysis of the NBS Data Encryption Standard</cite>. In: <cite class="lang" lang="en" dir="auto" style="font-style:italic">Computer</cite>. 10. Jahrgang, <span style="white-space:nowrap">Nr.<span style="display:inline-block;width:.2em"> </span>6</span>, Juni 1977, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>74–84</span>, <a href="Digital_Object_Identifier" title="Digital Object Identifier">doi</a>:<span class="uri-handle" style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://doi.org/10.1109/C-M.1977.217750">10.1109/C-M.1977.217750</a></span> (englisch, <a rel="nofollow" class="external text" href="https://web.archive.org/web/20140226205104/http://origin-www.computer.org/csdl/mags/co/1977/06/01646525.pdf">origin-computer.org</a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> des <span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=http%3A%2F%2Forigin-www.computer.org%2Fcsdl%2Fmags%2Fco%2F1977%2F06%2F01646525.pdf">Originals</a></span> vom 26. Februar 2014 im <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>)).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Exhaustive+Cryptanalysis+of+the+NBS+Data+Encryption+Standard&rft.au=Whitfield%26%2332%3BDiffie%2C%26%2332%3BMartin+E.%26%2332%3BHellman&rft.date=1977-06&rft.doi=10.1109%2FC-M.1977.217750&rft.genre=journal&rft.issue=6&rft.jtitle=Computer&rft.pages=74-84&rft.volume=10.+Jahrgang" style="display:none"> </span></span>
</li>
<li id="cite_note-HoAC-12"><span class="mw-cite-backlink"><a href="#cite_ref-HoAC_12-0">↑</a></span> <span class="reference-text">Alfred H. Menezes, Paul C. van Oorschot, Scott A. Vanstone, „Handbook of Applied Cryptography“, CRC Press, 1996, ISBN 0-8493-8523-7.</span>
</li>
<li id="cite_note-schneier2-13"><span class="mw-cite-backlink"><a href="#cite_ref-schneier2_13-0">↑</a></span> <span class="reference-text">Bruce Schneier: <cite style="font-style:italic">Applied Cryptography</cite>. Protocols, Algorithms and Source Code in C. 2. Auflage. John Wiley & Sons, New York 1996, ISBN 0-471-11709-9, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>274</span>.<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abook&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.au=Bruce+Schneier&rft.btitle=Applied+Cryptography&rft.date=1996&rft.edition=2.&rft.genre=book&rft.isbn=0471117099&rft.pages=274&rft.place=New+York&rft.pub=John+Wiley+%26+Sons" style="display:none"> </span></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><a href="#cite_ref-14">↑</a></span> <span class="reference-text"><span class="cite">Klaus Irmscher: <a rel="nofollow" class="external text" href="https://web.archive.org/web/20091104115444/http://informatik.jaspro.de/downloads/Des.pdf"><i>DES – Data Encryption Standard.</i></a> (PDF; 42 kB) Uni Leipzig, 2009, archiviert vom <span class="dewiki-iconexternal"><a class="external text" href="https://redirecter.toolforge.org/?url=http%3A%2F%2Finformatik.jaspro.de%2Fdownloads%2FDes.pdf">Original</a></span> (nicht mehr online verfügbar) am <span style="white-space:nowrap;">4. November 2009</span><span>;</span><span class="Abrufdatum"> abgerufen am 18. März 2010</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AData+Encryption+Standard&rft.title=DES+%E2%80%93+Data+Encryption+Standard&rft.description=DES+%E2%80%93+Data+Encryption+Standard&rft.identifier=https%3A%2F%2Fweb.archive.org%2Fweb%2F20091104115444%2Fhttp%3A%2F%2Finformatik.jaspro.de%2Fdownloads%2FDes.pdf&rft.creator=Klaus+Irmscher&rft.publisher=Uni+Leipzig&rft.date=2009&rft.source=http://informatik.jaspro.de/downloads/Des.pdf"> </span></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><a href="#cite_ref-15">↑</a></span> <span class="reference-text"><style data-mw-deduplicate="TemplateStyles:r261891140">
/* start https://de.wikipedia.org/ */
.mw-parser-output .webarchiv-memento a{color:inherit}
/* end https://de.wikipedia.org/ */
</style><a rel="nofollow" class="external text" href="https://web.archive.org/web/20100424090931/http://www.sciengines.com/joomla/index.php?option=com_content&view=article&id=99:des-in-1-day&catid=35:newsannounce&Itemid=58">Break DES in less than a single day</a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> vom 24. April 2010 im <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>) sciengines.com, Presseseite zu den Workshop Ergebnissen 2009.</span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><a href="#cite_ref-16">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.klaus-paffenholz.de/bos-funk/index.html?https://www.klaus-paffenholz.de/bos-funk/motorola-sprachverschluesselung.html"><i>Geschichtliche Entwicklung des BOS-Funks.</i></a><span class="Abrufdatum"> Abgerufen am 13. April 2025</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AData+Encryption+Standard&rft.title=Geschichtliche+Entwicklung+des+BOS-Funks&rft.description=Geschichtliche+Entwicklung+des+BOS-Funks&rft.identifier=https%3A%2F%2Fwww.klaus-paffenholz.de%2Fbos-funk%2Findex.html%3Fhttps%3A%2F%2Fwww.klaus-paffenholz.de%2Fbos-funk%2Fmotorola-sprachverschluesselung.html"> </span></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><a href="#cite_ref-17">↑</a></span> <span class="reference-text"><span class="cite"><a rel="nofollow" class="external text" href="https://www.klaus-paffenholz.de/bos-funk/index.html?https://www.klaus-paffenholz.de/bos-funk/MX3000/motorola-mx3000.html"><i>Geschichtliche Entwicklung des BOS-Funks.</i></a><span class="Abrufdatum"> Abgerufen am 13. April 2025</span>.</span><span style="display: none;" class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&rfr_id=info%3Asid%2Fde.wikipedia.org%3AData+Encryption+Standard&rft.title=Geschichtliche+Entwicklung+des+BOS-Funks&rft.description=Geschichtliche+Entwicklung+des+BOS-Funks&rft.identifier=https%3A%2F%2Fwww.klaus-paffenholz.de%2Fbos-funk%2Findex.html%3Fhttps%3A%2F%2Fwww.klaus-paffenholz.de%2Fbos-funk%2FMX3000%2Fmotorola-mx3000.html"> </span></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><a href="#cite_ref-18">↑</a></span> <span class="reference-text"><cite style="font-style:italic">Kryptographie: USA will Exportbeschränkungen lockern</cite>. In: <cite style="font-style:italic">Der Spiegel</cite>. 17. September 1999, <a href="Internationale_Standardnummer_f%C3%BCr_fortlaufende_Sammelwerke" title="Internationale Standardnummer für fortlaufende Sammelwerke">ISSN</a> <span style="white-space:nowrap"><a rel="nofollow" class="external text" href="https://zdb-katalog.de/list.xhtml?t=iss%3D%222195-1349%22&key=cql">2195-1349</a></span> (<a rel="nofollow" class="external text" href="https://www.spiegel.de/netzwelt/web/kryptographie-usa-will-exportbeschraenkungen-lockern-a-42310.html">spiegel.de</a> [abgerufen am 13. April 2025]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Ajournal&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Kryptographie%3A+USA+will+Exportbeschr%C3%A4nkungen+lockern&rft.date=1999-09-17&rft.genre=journal&rft.issn=2195-1349&rft.jtitle=Der+Spiegel" style="display:none"> </span></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><a href="#cite_ref-19">↑</a></span> <span class="reference-text">R. C. Merkle, M. E. Hellman: <i>On the Security of Multiple Encryption</i>. In: <i>Communications of the ACM</i>, Vol. 24, Nr. 7, Juli 1981.</span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><a href="#cite_ref-20">↑</a></span> <span class="reference-text">K.W. Campbell, M.J. Wiener: <i>DES is not a group</i>. In: <i>Advances in Cryptology – CRYPTO ’92 (LNCS 740)</i>. Springer-Verlag, 1993, S. 512–520.</span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><a href="#cite_ref-21">↑</a></span> <span class="reference-text"><a href="Eli_Biham" title="Eli Biham">Eli Biham</a>: <a rel="nofollow" class="external text" href="https://web.archive.org/web/20051210220928/http://www.cs.technion.ac.il/users/wwwb/cgi-bin/tr-get.cgi/1996/CS/CS0884.ps.gz"><i>How to Forge DES-Encrypted Messages in 2<sup>28</sup> Steps</i></a> (<span class="webarchiv-memento"><a href="Webarchivierung#Begrifflichkeiten" title="Webarchivierung">Memento</a></span> vom 10. Dezember 2005 im <i><a href="Internet_Archive" title="Internet Archive">Internet Archive</a></i>) (<a href="PostScript" title="PostScript">PostScript</a>) cs.technion.ac.il, 1996.</span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><a href="#cite_ref-22">↑</a></span> <span class="reference-text">Elaine Barker, William Barker, William Burr, William Polk, Miles Smid: <cite style="font-style:italic">NIST Special Publication 800-57</cite>. Recommendation for Key Management – Part 1: General (Revision 3). Hrsg.: <a href="National_Institute_of_Standards_and_Technology" title="National Institute of Standards and Technology">National Institute of Standards and Technology</a> (= <cite style="font-style:italic">NIST Special Publications</cite>). 2012, Abschnitt 5.6.1 Comparable Algorithm Strengths, <span style="white-space:nowrap">S.<span style="display:inline-block;width:.2em"> </span>64</span> (<a rel="nofollow" class="external text" href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-57p1r2007.pdf">nist.gov</a> [PDF; <span style="white-space:nowrap">535<span style="display:inline-block;width:.2em"> </span>kB</span>; abgerufen am 21. August 2021]).<span class="Z3988" title="ctx_ver=Z39.88-2004&rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Abookitem&rfr_id=info:sid/de.wikipedia.org:Data+Encryption+Standard&rft.atitle=Abschnitt+5.6.1+Comparable+Algorithm+Strengths&rft.au=Elaine+Barker%2C+William+Barker%2C+William+Burr%2C+...&rft.btitle=NIST+Special+Publication+800-57&rft.date=2012&rft.genre=bookitem&rft.pages=64&rft.series=NIST+Special+Publications" style="display:none"> </span></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><a href="#cite_ref-23">↑</a></span> <span class="reference-text"><i><a href="Request_for_Comments" title="Request for Comments">RFC</a>: <span class="dewiki-iconexternal"><a href="https://datatracker.ietf.org/doc/html/rfc2420" class="extiw external" title="rfc:2420">2420</a></span></i> – <i><span lang="en">The PPP Triple-DES Encryption Protocol (3DESE)</span></i>. September 1998 (englisch).</span>
</li>
</ol></div><!--htdig_noindex--><div><div class="zim-footer">
Dieser Artikel wurde von <a class="external text" title="Zuletzt bearbeitet am 2025-11-04" href="https://de.wikipedia.org/wiki/?title=Data_Encryption_Standard&oldid=261241762">Wikipedia</a> herausgegeben. Der Text ist unter <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.de">Creative Commons Attribution-Share Alike 4.0</a> verfügbar, sofern nicht anders angegeben. Für die Mediendateien können zusätzliche Bedingungen gelten.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>
</body></html>