[JoGu]

Cryptology

Analysis of the S-Boxes of DES

a7Hzq .#5r<
kÜ\as TâÆK$
ûj(Ö2 ñw%h:
Úk{4R f~`z8
¤˜Æ+Ô „&¢Dø

DES S-box: S1S2 S3S4 S5S6 S7S8
linear potential: 81/2561/41/41/4 25/6449/25681/2561/4
differential potential: 1/41/41/41/4 1/41/41/41/4

It was known since a long time—but if not we would see it now: The designers of DES knew about differential cryptanalysis, as is evident from the uniformly low differential potential. The somewhat chaotic linear potential suggests the they didn't yet know about linear cryptanalysis.

In particular the »bad« value 25/64 = 100/256 for S5 reveals a remarkable weakness.


Author: Klaus Pommerening, 2003-Jan-12; last change: 2005-Jun-06.